<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=5003644&amp;fmt=gif">
Skip to content
English - Australia
  • There are no suggestions because the search field is empty.

Privacy & Data Protection

Your data is yours. This article covers where it is stored, who can reach it, what individuals can ask for, and how Australian privacy obligations apply.

Privacy & Data Protection

Your data is yours. This article covers where it is stored, who can reach it, what individuals can ask for, and how Australian privacy obligations apply.

Your data is yours

All learning data, performance metrics, user information and organisational content you put into Acorn PLMS remains your property. Acorn does not claim ownership of it, regardless of how much you store, how long you subscribe, or which features you use.

We do not train AI on your data

Your data is not used to develop, improve or refine any AI model — ours or a vendor’s. This covers learner performance data, user interaction patterns, course content and organisational metadata.

Acorn’s AI features run on Amazon Bedrock, which does not use customer inputs or outputs to train its models.

Where your data is stored

You choose the AWS region when your site is set up, and your learning data stays in that country for the life of the site. Backups are replicated to a second region in the same country:

  • Australia — Sydney, backed up to Melbourne
  • Canada — Central, backed up to Calgary
  • United States — N. Virginia, backed up to Ohio
  • Europe or United Kingdom — London, backed up to Dublin (the one case where backups leave the country)

          Two things are processed outside your region regardless of where your site is hosted: platform performance monitoring and, where enabled, product analytics. Both are handled by providers in the United States. For Australian Government customers this is a cross-border disclosure under APP 8 and should be recorded as such. Our sub-processor list names the providers and can be found in our Trust Centre.

          Privacy statements and analytics choices in the platform

          Everyone signing in to Acorn now sees a Platform Privacy Statement setting out what we collect and why, and confirms they have read it. Organisations can add their own statement alongside it. Users on UK and European sites are also asked whether to allow two kinds of optional analytics, both switched off by default. Full detail: Privacy statements and analytics choices.

          Australian privacy obligations

          Does my agency or organisation have privacy obligations?

          The Privacy Act 1988, including the Australian Privacy Principles (APPs), governs how APP entities handle personal information. APP entities include Commonwealth agencies, and organisations that:

          • have an annual turnover above the threshold set in the Privacy Act (check the current threshold with the OAIC).
          • provide a health service, even if that is not their primary activity.
          • trade in personal information.
          • are a contracted service provider under a Commonwealth contract.
          • have voluntarily opted in to the Privacy Act.
          • are related to a larger body corporate that is subject to the Privacy Act.

                      If your organisation is an APP entity, it must comply with the Privacy Act.

                      What do we have to tell people when we collect their information?

                      An APP entity must take reasonable steps to notify individuals of certain matters, or ensure they are aware of them, before or at the time of collection — or as soon as practicable afterwards. You are welcome to adapt this notice:

                      The [system name], on behalf of [agency or organisation], collects your personal information for the purposes of [purpose]. Without this information, we may be unable to [consequence]. Your personal information will be used and otherwise handled in accordance with the Privacy Act 1988. We may disclose your personal information to [entities, including any overseas entities] for this purpose.

                      For further information about the collection and handling of your personal information, and how to access or correct your personal information or make a complaint, please see the [agency or organisation’s] privacy policy: [link].

                      What about data breaches?

                      If the Privacy Act covers you, the Notifiable Data Breaches scheme applies. Where a breach involving personal information is likely to result in serious harm, you must notify both the Office of the Australian Information Commissioner and the affected individuals. Acorn will support you with the facts you need to assess and report a breach affecting your site.

                      What individuals can ask for

                      Under the Privacy Act, GDPR, CCPA and similar frameworks, individuals can ask to see their data, correct it, take it elsewhere, or have it erased. Acorn PLMS supports all four; your organisation decides whether a request is valid and what exceptions apply.

                      • Access — locate and export the personal data held about an individual. Statutory deadlines are typically 30 days under the Privacy Act, and one month under GDPR, extendable in complex cases.
                      • Correction — update records, with an audit trail of what changed.
                      • Portability — export personal data in a structured, machine-readable format.
                      • Erasure, or the right to be forgotten — see below.

                              Verify the requester’s identity before disclosing anything.

                              Right to be forgotten

                              Standard account deletion keeps a record of user activity so administrator reporting stays intact. Where an individual needs to be erased entirely, our technical support team can run an additional step that fully obfuscates their personal information while preserving that reporting. Raise these requests with support rather than handling them in the admin interface.

                              Erasure is not absolute. Retention required by law, data needed for legal claims, and contractual or employment obligations can all override a request. That assessment is yours to make.

                              Retention, deletion and end of contract

                              To comply with Australian government regulation, Acorn retains back-ups of all data for the period required by applicable law — contact support to confirm the current retention period that applies to your organisation. Acorn supports deletion of live data and archiving within that period. Contact support to discuss your specific needs, and we will confirm what is available on your plan.

                              Archiving is the better choice than deletion where a legal hold applies, where a regulator requires long-term preservation, or where records relate to completed contracts. Archived data stays secure and auditable but sits outside routine searches and reports.

                              When a contract ends, you can export your data, we will support the transition to your next system, and we will securely delete your data from Acorn infrastructure on your instruction and confirm when it is done. Start that conversation with your account manager well before expiry.

                              Who else can reach your data

                              Acorn uses a small number of sub-processors for infrastructure, platform monitoring and product analytics. They act only on our instructions under contract and may not use your information for their own purposes. Your Acorn contact can give you the current named list for a due-diligence or procurement review.

                              Any change to who can access customer data goes through formal change control: approved by authorised personnel before it takes effect, scoped to the minimum needed, and recorded. Emergency changes follow the same rule and are reviewed afterwards.

                              Security and incidents

                              Acorn maintains an incident register recording classification, root cause, impact, remediation and resolution for any outage or security incident affecting the platform. Critical incidents get a full root cause analysis, and the corrective actions feed back into the platform.

                              Acorn’s security programme is owned by the Director of Security, working with a dedicated Information Security team, and incident response runs under that function.

                              For our current incident and notification history, see the Trust Centre — it is kept up to date, and this page is not.

                              Questions

                              Contact your account manager or Acorn support. For privacy-specific questions, email privacy@acorn.works.