At Study Magic Star, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
This policy complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Commonwealth) and the General Data Protection Regulation (GDPR) where applicable.
Information We Collect
Personal Information
We may collect the following types of personal information:
- Contact Information: Name, email address, phone number, postal address
- Educational Information: Current English level, learning goals, course preferences
- Payment Information: Credit card details, billing information (processed securely through third-party providers)
- Technical Information: IP address, browser type, device information, cookies
- Course Data: Progress records, assessment results, attendance information
- Communication Records: Emails, chat messages, support tickets
Automatically Collected Information
When you visit our website, we automatically collect certain information through cookies and similar technologies:
- Browser and device information
- Pages visited and time spent on our site
- Referring website information
- Location data (general geographic location)
- Usage patterns and preferences
How We Use Your Information
We use your personal information for the following purposes:
Service Delivery
- Providing English language courses and educational services
- Processing course enrollments and payments
- Tracking your learning progress and providing feedback
- Scheduling classes and managing attendance
- Providing customer support and responding to inquiries
Communication
- Sending course-related updates and notifications
- Providing information about new courses and services
- Sending newsletters and educational content (with your consent)
- Responding to your questions and support requests
Legal and Business Purposes
- Complying with legal obligations and regulatory requirements
- Protecting our rights and the security of our services
- Preventing fraud and maintaining system security
- Improving our services through analytics and research
Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:
Service Providers
We may share information with trusted third-party service providers who assist us in:
- Payment processing (Stripe, PayPal)
- Email delivery services (Mailchimp, SendGrid)
- Cloud hosting and data storage (AWS, Google Cloud)
- Analytics and website performance (Google Analytics)
- Customer support tools
Legal Requirements
We may disclose your information when required by law or to:
- Comply with legal processes, court orders, or government requests
- Protect our rights, property, and safety
- Protect the rights and safety of our users and the public
- Investigate and prevent fraud or security issues
Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred to the new owner, subject to the same privacy protections.
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience on our website:
Types of Cookies We Use
- Essential Cookies: Required for basic website functionality
- Performance Cookies: Help us understand how visitors use our site
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: Used to deliver relevant advertisements (with consent)
Managing Cookies
You can control cookie settings through:
- Our cookie consent banner when you first visit our site
- Your browser settings
- Third-party opt-out tools for advertising cookies
Data Security
We implement appropriate technical and organisational measures to protect your personal information:
Security Measures
- Encryption: All data transmissions are encrypted using SSL/TLS
- Access Controls: Limited access to personal information based on job requirements
- Regular Updates: Systems are regularly updated with security patches
- Monitoring: Continuous monitoring for security threats and vulnerabilities
- Staff Training: Regular privacy and security training for all staff
Data Retention
We retain your personal information only as long as necessary for the purposes outlined in this policy:
- Account Information: Retained while your account is active and for 7 years after closure
- Course Records: Maintained for 7 years for certification and compliance purposes
- Marketing Data: Retained until you withdraw consent or for 3 years of inactivity
- Support Records: Kept for 3 years to ensure quality service
Your Rights and Choices
Under Australian privacy law and GDPR (where applicable), you have the following rights:
Access and Portability
- Request access to your personal information
- Receive a copy of your data in a portable format
- Request information about how your data is processed
Correction and Updates
- Update your account information at any time
- Request correction of inaccurate information
- Complete incomplete personal data
Deletion and Restriction
- Request deletion of your personal information (subject to legal requirements)
- Restrict processing of your data in certain circumstances
- Object to processing based on legitimate interests
Communication Preferences
- Opt out of marketing communications at any time
- Update your communication preferences in your account settings
- Unsubscribe from newsletters using the link in emails
Exercising Your Rights
To exercise any of these rights, please contact us at:
Children's Privacy
Our services are designed for learners aged 13 and above. We do not knowingly collect personal information from children under 13 without parental consent. If you believe we have collected information from a child under 13, please contact us immediately.
For students aged 13-17, we require parental consent before collecting personal information and may provide additional protections as required by law.
International Data Transfers
As an Australian-based company, your personal information is primarily stored and processed in Australia. However, some of our service providers may process data in other countries with adequate privacy protections.
When we transfer personal information internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by privacy authorities
- Adequacy decisions by the Australian Privacy Commissioner
- Certification under recognised privacy frameworks
Data Breach Notification
In the event of a data breach that poses a risk to your personal information, we will:
- Notify the Office of the Australian Information Commissioner within 72 hours
- Inform affected individuals if the breach poses a high risk
- Take immediate steps to contain and remedy the breach
- Provide updates as the situation develops
Third-Party Links
Our website may contain links to third-party websites, social media platforms, or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:
- Post the updated policy on our website
- Update the "Last Updated" date
- Notify you via email if you have an account with us
- Obtain your consent if required by law
Contact Information
If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, please contact us:
Regulatory Authorities
If you are not satisfied with our response to your privacy concerns, you may lodge a complaint with:
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: [email protected]