Skip to content
Free Sign Up

Platform

Privacy Policy

How Clear Learning Systems handles personal information in the ClearXP platform on behalf of its customers, and the rights individuals have over that information.

11 min read
Updated August 26, 2026

Clear Learning Systems Pty Ltd (ClearXP, we, us, our) provides the ClearXP learning experience platform to organisations, including employers, training providers and government bodies. This policy explains how we handle personal information held in the platform, and the rights individuals have over that information.

This policy applies to all personal information we process in the ClearXP platform on behalf of a customer, whatever the size or type of that customer. It is written for our customers, and for the learners and administrators who use the platform through them.

It does not cover personal information we collect through our website, our marketing activities, or our direct dealings with prospective customers. That information is covered by our separate website privacy policy.

We handle personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). Where we handle the personal information of individuals in other regions, we also comply with the applicable laws of those regions, as set out in Regional information.

A copy of the Australian Privacy Principles is available from the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Personal information in the platform belongs to people who use ClearXP because their employer or training organisation has bought it. For that information:

  • Our customer is the controller. They decide what personal information is collected, why, and how long it is kept.
  • ClearXP is the processor. We handle that information only on our customer’s documented instructions, and only to deliver the platform to them.
  • Our customer’s own privacy policy governs the collection. This policy explains what we do with the information once we hold it.

If you are a learner or administrator using your organisation’s ClearXP instance, please direct requests about your information to your organisation first. We will support them in responding to you. See Your rights.

The categories depend on what our customer configures. They typically include:

  • Identification and contact data - name, work email address, employee or worker number.
  • Employment data - job title, role, manager, department, work location, cost centre, start date, employment status.
  • Authentication data - single sign-on identifiers, session and credential metadata.
  • Learning records - enrolments, attempts, completions, results, competencies, and certifications or licences and their expiry dates.
  • Technical and usage data - device and browser information, IP address, and activity timestamps.

We receive this information from our customer, from their identity provider or human resources system, or from the individual as they use the platform.

Sensitive information is defined in the Privacy Act to include information about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record, or health information. Similar categories are treated as special category data under European law.

The ClearXP platform is not designed to collect sensitive information, and we do not seek or require it. We do not ask our customers to supply it, and our standard configuration does not collect it.

Where a customer chooses to configure a field that would hold sensitive information, or where an individual volunteers it, we handle it only:

  • for the primary purpose for which it was provided;
  • for a secondary purpose directly related to that primary purpose;
  • with the individual’s consent; or
  • where required or authorised by law.

Recording the completion of a health, safety or first aid course is a training record. It is not health information about the individual.

We use personal information only to provide the platform to our customer. This includes delivering and tracking learning, reporting to the customer, supporting users, keeping the service secure and available, and meeting our legal obligations.

We do not use it for any purpose of our own.

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising.
  • We do not use customer data for our own analytics, benchmarking across customers, or product research beyond what our customer instructs.
  • We do not use customer data to train or fine-tune artificial intelligence models. See Artificial intelligence features.
  • We do not combine personal information held for one customer with personal information held for another. Each customer’s data is held in a separate tenant, and access is restricted to that tenant.

The platform includes assistant features built on third-party foundation models, which we access as a managed service through Amazon Web Services.

  • Your data is not used for training. Prompts and responses are not retained by the model provider after the request, and are not used to train or improve any model. We do not fine-tune models on customer data.
  • Content is screened. Requests and responses pass through automated guardrails that check for unsafe content and for personal information, and block or mask what they detect.
  • Answers are grounded in your organisation’s content. The assistant draws on the learning material and records in your organisation’s own tenant, not on other customers’ data.
  • No automated decisions with legal or significant effect. The assistant supports learning. It does not make or determine decisions about employment, promotion, discipline or pay.

We disclose personal information:

  • to service providers who help us deliver the platform, listed below;
  • to our customer, where we hold the information as their processor;
  • where you have consented to the disclosure; and
  • where required or authorised by law.

We require every service provider to be bound by a written agreement containing confidentiality and privacy obligations, we assess their security and data handling before we engage them, and we review our critical providers at least annually.

Our service providers that may handle personal information are:

ProviderPurpose
Amazon Web ServicesHosting, storage, backup and AI inference
DatadogLogging, monitoring and alerting
Google WorkspaceCorporate email and document storage
LinearSupport and engineering request tracking

We will give our customers advance notice of any new service provider that will handle their personal information.

The platform is hosted on Amazon Web Services infrastructure in the region of your choosing. The hosting region is agreed with each customer and recorded in their contract. We support hosting in:

  • Australia
  • The United States
  • The European Union

We do not move customer platform data between regions. Your organisation’s data stays in its designated region, and is not replicated or migrated elsewhere without instruction.

Our support and engineering personnel are located in Australia and access the platform to operate and support it. A small number of our service providers process operational data, such as system logs, outside the hosting region. Both are covered by contracts requiring protection equivalent to the standard required by the applicable law, including the European Commission’s Standard Contractual Clauses and the United Kingdom International Data Transfer Addendum where those apply.

We keep personal information only while there is a need for it, or while a legal, regulatory or contractual obligation requires it. When it is no longer needed we securely delete or de-identify it.

For information we hold as a processor, retention is governed by our contract with the customer. Our default periods are:

InformationRetention
Customer accounts and platform dataDeleted within 90 days of contract termination
Certification and licence recordsUp to 7 years after a user is deactivated, where evidence of training must be retained
Network flow logs1 year
Security and system event logsRetained while needed for security monitoring and investigation

A customer may agree a different period with us, including a shorter one. We delete personal information on a verified request unless we are required to keep it by law or a legal hold.

We protect personal information against misuse, interference, loss, and unauthorised access, modification or disclosure. Our controls include:

  • Encryption - AES-256 encryption of data at rest, and TLS 1.2 or higher for data in transit.
  • Access control - least privilege and role-based access, multi-factor authentication for privileged access, and access reviews at least quarterly.
  • Separation - each customer’s data is held in a separate tenant.
  • Monitoring - centralised logging, alerting, and annual penetration testing.
  • Assurance - an independently audited SOC 2 programme covering the Security and Availability criteria. Our physical infrastructure is provided by Amazon Web Services, whose data centres hold their own independent certifications.

No method of transmission or storage is completely secure, but we maintain these controls and review them at least annually.

If a data breach occurs that is likely to result in serious harm, we will notify the affected customer without undue delay. As the controller, the customer decides whether individuals and regulators are notified, and we will support them in meeting those obligations, including under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.

Subject to the exceptions in the applicable law, you may ask us to:

  • access the personal information we hold about you;
  • correct it if it is inaccurate, out of date or incomplete;
  • delete it;
  • provide a copy in a portable, machine-readable format;
  • restrict or object to how we use it; and
  • withdraw consent where we rely on it.

Contact your employer or training organisation first. They are the controller for the information held in their ClearXP instance, and they decide how it is handled. Most requests can be actioned by their own administrators directly in the platform.

If you contact us instead, we will refer you to them and let them know you have been in touch. We cannot action a request over a customer’s data without that customer’s instruction.

Once a customer instructs us, we acknowledge the request, may ask for verification of identity before information is released, and complete it within 30 days.

We handle personal information under the Australian Privacy Principles in the Privacy Act 1988 (Cth). If you are not satisfied with our response to a privacy complaint, you may complain to the OAIC at oaic.gov.au.

Where we process the personal data of individuals in the European Union or the United Kingdom, we act as a processor under the GDPR and UK GDPR, and the customer is the controller. Our processing is governed by a data processing agreement that records the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, and our obligations. Restricted transfers are made under the Standard Contractual Clauses or the UK International Data Transfer Addendum.

The controller is responsible for establishing a lawful basis for the processing, and for responding to data subjects. You have the right to lodge a complaint with your local supervisory authority.

Where we process the personal information of United States residents on behalf of a customer, we act as a service provider or processor under laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act, and comparable laws in other states. We process personal information only for the purposes set out in our contract with the customer. We do not sell or share personal information, and we do not retain, use or disclose it outside the direct business relationship with the customer.

The ClearXP platform is a workplace learning system, intended for use by employees, contractors and trainees. It is not directed at children, and we do not knowingly collect personal information from a child other than where a customer enrols a young worker or apprentice as part of their training programme.

We may update this policy from time to time. The current version is always published on this page, with the date it was last updated shown alongside it. Where a change materially affects how we handle personal information, we will notify our customers.

If you are a learner or administrator, contact your employer or training organisation. They are the controller for your information. See How to make a request.

If you are a ClearXP customer, or you have a question or complaint about this policy, contact us at privacy@clearxp.com

We will acknowledge your complaint, investigate it, and respond within 30 days. If you are not satisfied with our response, you may refer the matter to the OAIC at oaic.gov.au, or to your local supervisory authority.