Privacy Policy
Last Updated: January 2026
1. Introduction
Tech Horizon Academy (operated by Tech Horizon Labs) is committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website, services, and platforms. We encourage you to read this policy carefully to understand our practices.
By using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.
2. Who We Are
- Business Name: Tech Horizon Academy
- Operating Entity: Tech Horizon Labs
- Location: Queensland, Australia
- Website: academy.techhorizonlabs.com
Tech Horizon Academy provides AI training, workshops, business audits, and educational resources for Australian small and medium enterprises (SMEs). We are an APP entity under the Privacy Act 1988.
3. Information We Collect
We collect personal information that is reasonably necessary for our business functions and activities. The types of personal information we may collect include:
3.1 Account Information
- Full name
- Email address
- Organisation/business name
- Job title or role
3.2 Business Profile Information
- Company size
- Industry sector
- AI maturity level
- Current technology stack
3.3 Service-Related Information
- AI Readiness Audit responses and assessment data
- Workshop registrations and attendance records
- Tool stack preferences and selections
- Learning progress and resource interactions
3.4 Payment Information
- Billing address
- Payment card details (processed securely via Stripe - we do not store full card numbers)
- Transaction history
3.5 Technical Information
- IP address
- Browser type and version
- Device information
- Usage data and analytics
Note: We do not collect sensitive information (as defined under the Privacy Act) unless required for a specific purpose and with your explicit consent.
4. How We Collect Information
We collect personal information through various means, including:
4.1 Directly from You
- When you create an account or register for our services
- When you complete the AI Readiness Audit
- When you register for workshops or events
- When you subscribe to our newsletter
- When you contact us via email, phone, or our website
- When you make a purchase or payment
4.2 Automatically
- Through cookies and similar tracking technologies when you visit our website
- Through analytics tools that track website usage patterns
- Through server logs that record technical information
4.3 From Third Parties
- From payment processors (Stripe) for transaction verification
- From authentication providers when you use social login options
- From referral partners with your consent
4.4 Unsolicited Personal Information (APP 4)
If we receive personal information that we did not solicit (unsolicited information), we will determine within a reasonable period whether we could have collected the information under APP 3.
- If we determine we could have collected the information, we will handle it in accordance with this Privacy Policy
- If we determine we could not have collected the information, we will destroy or de-identify it as soon as practicable (unless retention is required by law)
Examples of unsolicited information include CVs sent without a job posting, or personal details included in general enquiries that we did not request.
5. Why We Collect Information
We collect and use your personal information for the following purposes:
5.1 Primary Purposes
- To provide, operate, and maintain our services
- To process workshop registrations and memberships
- To conduct AI Readiness Audits and provide personalised recommendations
- To process payments and manage billing
- To communicate with you about your account, services, and support requests
- To send workshop schedules, recordings, and educational materials
5.2 Secondary Purposes
- To improve our services and develop new features
- To analyse usage patterns and optimise user experience
- To send marketing communications (with your consent)
- To comply with legal obligations
- To protect our rights, property, and safety
We will not use or disclose your personal information for purposes other than those described in this policy unless we have your consent or are required by law.
6. Disclosure to Third Parties
We may disclose your personal information to third parties in the following circumstances:
6.1 Service Providers
We engage trusted third-party service providers to help us deliver our services:
- Supabase: Database hosting and user authentication
- Stripe: Payment processing and billing management
- Google (Gemini AI): AI-powered audit analysis and recommendations
- Google Calendar/Drive: Workshop scheduling and recording storage
- Resend: Transactional email delivery
6.2 Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, prevent fraud, or ensure user safety.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such change.
Important: We do not sell, rent, or trade your personal information to third parties for marketing purposes.
7. Overseas Disclosure
In accordance with Australian Privacy Principle 8, we inform you that your personal information may be disclosed to overseas recipients. We take reasonable steps to ensure these recipients comply with the APPs or similar privacy protections.
Countries Where Data May Be Processed
| Service Provider | Country | Purpose |
|---|---|---|
| Supabase | United States | Database and authentication services |
| Stripe | United States | Payment processing |
| Google (Gemini AI) | United States | AI audit analysis |
| Google Calendar/Drive | United States | Workshop scheduling and recordings |
| Resend | United States | Transactional emails |
All listed service providers maintain robust privacy and security practices. By using our services, you consent to the transfer of your information to these overseas locations.
8. Data Security
We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security measures include:
8.1 Technical Measures
- Encryption of data in transit using TLS/SSL protocols
- Encryption of sensitive data at rest
- Secure authentication mechanisms including magic links and session management
- Regular security updates and patch management
- Firewall and intrusion detection systems
8.2 Organisational Measures
- Access controls limiting data access to authorised personnel only
- Staff training on privacy and data protection practices
- Regular review of security procedures
- Incident response procedures for data breaches
8.3 Payment Security
All payment processing is handled by Stripe, which is PCI DSS Level 1 certified. We do not store complete credit card numbers on our servers.
Note: While we take reasonable precautions, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
9. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
9.1 Retention Periods
- Account information: Retained while your account is active, plus 7 years after account closure
- Transaction records: 7 years for tax and audit purposes
- Workshop and audit data: Retained while your account is active
- Marketing preferences: Until you opt out or update your preferences
- Analytics data: Aggregated and anonymised after 26 months
9.2 Data Disposal
When personal information is no longer required, we will take reasonable steps to destroy or permanently de-identify it. This includes secure deletion of electronic records and destruction of physical documents.
10. Your Rights
Under the Australian Privacy Principles, you have specific rights regarding your personal information:
10.1 Right of Access (APP 12)
You have the right to request access to the personal information we hold about you. We will respond to your access request within 30 days. In most cases, we will provide access free of charge, however, we may charge a reasonable fee for administrative costs in some circumstances.
10.2 Right of Correction (APP 13)
You have the right to request correction of any personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond to correction requests within 30 days.
10.3 How to Exercise Your Rights
To make an access or correction request, please contact us using the details in Section 17. We may need to verify your identity before processing your request.
When We May Refuse Access
We may refuse access in limited circumstances permitted by law, such as when providing access would pose a serious threat to life, health, or safety, or would have an unreasonable impact on the privacy of others. If we refuse, we will provide written reasons.
11. Complaints
If you believe we have breached your privacy or handled your personal information inappropriately, you have the right to make a complaint.
11.1 How to Lodge a Complaint
To make a privacy complaint, please contact us via:
- Email: privacy@techhorizonlabs.com (include "Privacy Complaint" in the subject line)
- Contact Form: academy.techhorizonlabs.com/contact
- Post: Privacy Officer, Tech Horizon Labs, Queensland, Australia
Please include: your name and contact details, a clear description of your complaint, what personal information is affected, and what outcome you are seeking.
11.2 Our Complaint Handling Process
- Acknowledgement: We will acknowledge receipt of your complaint within 7 business days
- Investigation: We will investigate your complaint and gather relevant information
- Response: We will provide a written response within 30 days, including our findings and any actions taken
- Extension: If we need more time to investigate, we will notify you in writing with the expected timeframe and reasons for the delay
11.3 External Complaint (OAIC)
If you are not satisfied with our response, or if we have not responded within 30 days, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
- Post: GPO Box 5288, Sydney NSW 2001
13. Direct Marketing
We may use your personal information to send you direct marketing communications about our services, workshops, and educational content.
13.1 Types of Marketing Communications
- Newsletter updates with AI tips and industry insights
- Workshop announcements and invitations
- New service or feature notifications
- Special offers for members
13.2 Your Choices
You have the right to opt out of marketing communications at any time:
- Email: Click the "unsubscribe" link in any marketing email
- Account settings: Update your communication preferences in your dashboard
- Contact us: Request to be removed from marketing lists
Note: Even if you opt out of marketing communications, we may still send you transactional messages related to your account, purchases, and service updates.
14. Automated Decision-Making
We use automated systems to help provide our services. We are committed to transparency about how these systems work.
14.1 AI Readiness Audit
Our AI Readiness Audit uses Google Gemini AI to analyse your responses and provide personalised recommendations. This automated analysis:
- Assesses your business's current AI maturity level
- Identifies opportunities for AI implementation
- Generates tailored recommendations based on your industry and size
- Provides priority actions for your AI journey
14.2 How It Works
When you complete the AI Readiness Audit:
- Your responses are securely transmitted to Google Gemini AI
- The AI analyses patterns and generates insights
- Results are returned and displayed on your dashboard
- Human review is available upon request
14.3 Your Rights Regarding Automated Decisions
You have the right to:
- Request information about the logic involved in automated decisions
- Request human review of automated decisions
- Contest decisions that significantly affect you
Future Compliance Notice: We are preparing for enhanced automated decision-making transparency requirements under proposed amendments to the Privacy Act, expected to take effect in December 2026. We will update this policy as new requirements come into force.
15. Anonymity & Pseudonymity
In accordance with Australian Privacy Principle 2, we give you the option of not identifying yourself, or using a pseudonym, when dealing with us where it is lawful and practicable.
15.1 When You Can Remain Anonymous
- Browsing our public website content
- Reading our free resources and guides
- General enquiries about our services
15.2 When Identification Is Required
We require identification in certain circumstances to provide our services effectively:
- Creating an account or membership
- Purchasing workshops or services
- Completing the AI Readiness Audit
- Accessing member-only content
- Processing refunds or billing enquiries
16. Government Identifiers (APP 9)
In accordance with Australian Privacy Principle 9, we do not adopt, use, or disclose government-related identifiers as our own identifiers for individuals.
16.1 What Are Government Identifiers?
Government identifiers include:
- Tax File Numbers (TFN)
- Medicare numbers
- Australian Business Numbers (ABN)
- Driver's licence numbers
- Passport numbers
- Centrelink Reference Numbers (CRN)
16.2 Our Approach
Tech Horizon Academy:
- Does not collect government identifiers as part of our standard services
- Does not use government identifiers to identify you in our systems
- Does not require government identifiers for membership or workshop registration
16.3 Exceptions
We may collect an ABN only if you are registering as a business entity for invoicing purposes. In such cases, we will only use the ABN for the purpose for which it was provided (billing and tax compliance) and will not disclose it except as required by law.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
- We will post the updated policy on this page with a new "Last Updated" date
- For material changes, we will notify you by email or through a prominent notice on our website
- We encourage you to review this policy periodically
- Your continued use of our services after changes constitutes acceptance of the updated policy
18. Contact Us
If you have any questions about this Privacy Policy, wish to make a request regarding your personal information, or have a complaint, please contact us:
- Business Name: Tech Horizon Academy (operated by Tech Horizon Labs)
- Location: Queensland, Australia
- Privacy Email: privacy@techhorizonlabs.com
- Website: academy.techhorizonlabs.com
- Contact Page: Contact Us
We aim to respond to all enquiries within 7 business days. For access and correction requests, we will respond within 30 days as required by the Australian Privacy Principles.
This Privacy Policy is governed by Australian law. For more information about your privacy rights, visit the Office of the Australian Information Commissioner.
