Privacy Policy

Purpose Operations Privacy Policy

Effective Date: 1 October 2025
Last Updated: 1 October 2025

Socially Conscious Group Pty Ltd (ACN 165 313 397) trading as Purpose Operations (“Purpose Operations”, “we”, “us”, or “our”) is committed to protecting your privacy. We collect, use, disclose, and manage personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), the Spam Act 2003 (Cth), and the Notifiable Data Breaches Scheme. Where personal information is transferred outside Australia, we take reasonable steps to ensure it receives appropriate protection.

This Privacy Policy explains how we handle personal information across our enterprise transformation, education, certification, community, and AI-powered services.

1. Introduction

Purpose Operations provides an Enterprise Transformation Operating System that includes online learning, certifications, AI tools, enterprise frameworks, community platforms, assessments, workshops, and digital resources. We respect your privacy and are committed to handling your personal information responsibly and transparently.

We design our products and services with privacy in mind from the outset.

2. Scope

This Privacy Policy applies to personal information collected through:

  • https://purposeoperations.com
  • academy.purposeoperations.com
  • community.purposeoperations.com
  • All mobile applications, learning management systems, AI platforms, certification portals, enterprise customer portals, and digital products

This Privacy Policy also applies to any future websites, applications, products or services operated by Purpose Operations that expressly reference this Privacy Policy.

3. Information We Collect

We collect personal information that is reasonably necessary for our functions and activities. This may include:

  • Identity and contact information (name, email address, phone number, job title, employer, organisation)
  • Billing and payment information (excluding full credit card numbers, which are handled by third-party processors)
  • Professional and certification details (certification records, assessment results, course completion data, learning progress)
  • Account and usage information (login details, community participation, support enquiries, survey responses, feedback)
  • Content you upload or create (documents, images, videos, audio recordings, AI prompts, chat history)
  • Marketing preferences and communication history

We may also collect device and technical information, including IP address, browser type, operating system, device identifiers, approximate location, referral source, session data, and usage statistics.

4. Personal Information We Do Not Intentionally Collect

We do not intentionally collect:

  • Government identification numbers, unless required for a specific service
  • Full payment card details (these are processed and stored by our payment providers)
  • Biometric information, unless expressly disclosed and consented to
  • Health information, unless voluntarily provided by you for a specific purpose
  • Sensitive information, unless reasonably necessary for our services and permitted by law

5. Information Collected Automatically

When you use our services, we automatically collect certain information through cookies, pixels, log files, and analytics tools. This includes performance data, security monitoring information, fraud detection signals, and session management records. This information helps us operate, secure, and improve our platforms.

6. Cookies and Tracking Technologies

We use different types of cookies and tracking technologies:

  • Essential cookies – required for core functionality such as login and security
  • Performance and analytics cookies – help us understand how users interact with our platforms
  • Functional and preference cookies – remember your settings and preferences
  • Marketing cookies – used to deliver relevant content and measure campaign effectiveness

Some cookies are placed by third parties, including Google Analytics, Meta, and LinkedIn. You can manage cookie preferences through your browser settings or our cookie consent tool. Disabling certain cookies may affect the functionality of the services.

7. AI Services

Purpose Operations offers AI-powered tools and features. When you use these services:

  • Your prompts, conversations, and related inputs may be processed by trusted third-party AI providers
  • We may retain AI conversations for security, quality assurance, abuse prevention, and service improvement
  • We do not use customer prompts or conversations to train our own proprietary AI models unless we have obtained your express consent and provided clear disclosure

You should not submit confidential, sensitive, or personal information of third parties into AI tools unless specifically requested by us. We apply technical and organisational measures to protect AI-related data.

We may use automated systems to detect fraud, abuse, spam, plagiarism, account misuse or unauthorised access. Significant decisions affecting individuals will not be made solely through automated processing without appropriate human oversight where required by law.

8. Why We Collect Information

We collect and use personal information for the following purposes:

  • Delivering and managing our services, courses, certifications, and assessments
  • Verifying identity and preventing fraud
  • Providing customer support and responding to enquiries
  • Administering memberships, enterprise accounts, and community features
  • Conducting research, analytics, and product improvement
  • Sending marketing communications (with your consent where required)
  • Ensuring platform security and complying with legal obligations
  • Moderating community content and maintaining certification integrity

9. Lawful Basis for Processing

Depending on your location and the nature of the processing, we process personal information because:

  • It is necessary to perform a contract with you
  • You have provided consent
  • We are required by law
  • We have a legitimate interest in operating, improving, securing, and developing our services

10. Marketing Communications

We may send you emails about new courses, certifications, events, product updates, and resources. You can unsubscribe at any time by clicking the unsubscribe link in our emails or by contacting us directly. We comply with the Spam Act 2003 when sending commercial electronic messages.

11. Community Information

When you participate in community.purposeoperations.com or similar forums, information you post (including your name, profile, and contributions) may be visible to other members. You are responsible for the content you choose to share. We recommend you do not post sensitive personal information in public community areas.

Content posted to community areas may remain visible after your membership ends where necessary to preserve the integrity of discussions, unless removal is required by law or approved by Purpose Operations.

12. Certification Records

We retain certification history, assessment results, and credential records indefinitely to verify qualifications, prevent fraud, and maintain the integrity of our certification programs. This information may be disclosed to employers or third parties where you have authorised verification or where required for legitimate purposes.

Revoked or expired certifications may also be retained to protect the integrity of the certification framework.

13. Enterprise Clients

When an organisation purchases an enterprise licence or subscription, we may provide that organisation with limited administrative information about its authorised users (such as names, email addresses, course progress, and completion status) to enable effective management of the licence. The organisation is responsible for its own handling of this information.

14. Payment Information

Payments are processed by secure third-party providers such as Stripe and PayPal. We do not store full credit card details on our systems. We only retain necessary billing information for transaction records and accounting purposes.

15. Third-Party Service Providers

We engage trusted service providers to help deliver our services. These may include payment processors, cloud hosting providers, analytics platforms, CRM and email systems, learning management software, community platforms, and AI model providers. These providers process personal information only on our instructions and subject to appropriate contractual safeguards.

16. Overseas Disclosure

Some of our service providers are located outside Australia. When we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it in a manner consistent with the APPs, including through the use of standard contractual clauses or other appropriate mechanisms where required.

17. International Users

If you access our services from outside Australia, you acknowledge that your information may be transferred to and processed in Australia and other countries in which our service providers operate.

18. Data Security

We implement technical and organisational measures to protect personal information, including encryption in transit and at rest, access controls, multi-factor authentication, regular security monitoring, secure backups, and periodic security reviews. Employees, contractors, and authorised service providers only have access to personal information where necessary to perform their duties. While we take reasonable steps to protect your information, no system is completely secure.

19. Data Retention

We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by law. Examples include:

  • Certification and assessment records: retained indefinitely for verification purposes
  • Financial and transaction records: retained for at least seven years
  • Marketing data: retained until you unsubscribe or object

Backups may retain information for a limited period following deletion before being overwritten in accordance with our backup retention schedules.

20. Access and Correction

You may request access to, or correction of, your personal information by contacting us. We will respond to reasonable requests within a reasonable time and may require verification of your identity.

21. Your Privacy Rights

Subject to applicable law, you have the following rights:

Access
Request a copy of the personal information we hold about you.

Correction
Request correction of inaccurate or incomplete personal information.

Deletion
Request deletion of your personal information, subject to legal and operational requirements.

Marketing Preferences
Opt out of marketing communications at any time.

Cookie Preferences
Manage or disable cookies through your browser or our consent tool.

Complaints
Submit a privacy complaint to us for investigation.

22. Deletion Requests

You may request deletion of your personal information where permitted by law. We will consider such requests but may need to retain certain information for legal, financial, certification verification, fraud prevention, or security reasons. Where deletion is not possible, we will inform you of the reasons.

23. Children’s Privacy

Our services are intended for adults and are not directed at children under the age of 18. We do not knowingly collect personal information from children without appropriate parental consent.

24. Data Breaches

We maintain procedures to identify, investigate, and respond to data breaches. In the event of an eligible data breach under the Notifiable Data Breaches Scheme, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

25. Disclosure Required by Law

We may disclose personal information where required or authorised by law, including in response to court orders, regulatory requests, law enforcement requests, or to protect our legal rights, property, or the safety of others.

26. Aggregated Data

We may create anonymised or aggregated information that cannot reasonably identify an individual. We may use this information for research, benchmarking, reporting, analytics, and product improvement.

27. Business Transfers

If Purpose Operations is involved in a merger, acquisition, restructure, or sale of assets, personal information may be transferred as part of that transaction, subject to applicable privacy laws.

28. Complaints

If you have a privacy complaint, please contact our Privacy Officer using the details below. We will investigate and respond promptly. If you are not satisfied with our response, you may contact the OAIC.

29. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy on our website with a new effective date. Continued use of our services after changes constitutes acceptance of the updated policy.

30. Contact Us

Purpose Operations
Socially Conscious Group Pty Ltd (ACN 165 313 397)
Privacy Officer
Email: privacy@purposeoperations.com
General Enquiries: info@purposeoperations.com
Website: https://purposeoperations.com

Registered Office
South Australia