This Agreement forms part of the Provider's subscription and the EduX Terms of Use.
Parties
Operator: EduX Pty Ltd, ABN 13 697 958 777, Melbourne, Australia (“EduX”, “we”, “us”, “our”)
Provider: the organisation identified in the EduX organisation account or order form (“Provider”)
1. Purpose
This Agreement governs the handling of personal information entered into, generated through or otherwise processed using EduX on behalf of the Provider.
2. Definitions
| Term | Meaning |
|---|---|
| Applicable Privacy Law | The Privacy Act 1988 (Cth), the Australian Privacy Principles and any other privacy, data protection or breach-notification law applicable to a party or the processing. |
| Data Controller | A contractual description of the Provider as the party determining the purpose and essential means of processing Provider Data. This term does not displace Australian statutory terminology. |
| Data Processor | A contractual description of EduX as the service provider processing Provider Data on the Provider's documented instructions. |
| Data Breach | Unauthorised access to, disclosure, alteration, loss or misuse of Provider Data, or another incident requiring assessment under Applicable Privacy Law. |
| Provider Data | Personal information and other data submitted by or for the Provider or generated through the Provider's use of EduX. |
| Subprocessor | A third-party service provider engaged by EduX to process Provider Data for the service. |
3. Roles and instructions
The parties acknowledge that:
- the Provider determines why Provider Data is collected and entered into EduX;
- EduX processes Provider Data to provide, secure, maintain and support the contracted services;
- the Provider is responsible for its relationship with students, learners, staff and other individuals whose information is entered into EduX; and
- EduX will process Provider Data only on documented Provider instructions, the Terms and the service configuration, except where otherwise required by law.
For contractual convenience, the Provider may be described as the Data Controller and EduX as the Data Processor. These descriptions do not alter the responsibilities imposed directly on either party by Applicable Privacy Law.
4. Provider obligations
The Provider must:
- ensure it has a lawful basis to collect, use and disclose Provider Data through EduX;
- provide required privacy and collection notices;
- obtain any consent required for personal or sensitive information;
- collect and submit only information reasonably necessary for the relevant service;
- ensure Provider Data is accurate, relevant and appropriately updated;
- configure and manage authorised user access;
- respond to access, correction and privacy complaints, with EduX assistance where required;
- set and comply with applicable retention and recordkeeping requirements;
- make final professional, admission, competency and compliance decisions; and
- comply with the speaking-assessment obligations in clause 7.
5. EduX obligations
EduX will:
- process Provider Data only to provide, secure, maintain and support the services and on documented instructions;
- restrict access to authorised personnel with a legitimate operational need;
- maintain reasonable technical and organisational security measures;
- maintain audit and access records appropriate to the service;
- assist the Provider with access, correction, export or deletion requests where reasonably practicable;
- notify the Provider of a Data Breach affecting Provider Data in accordance with clause 11;
- not sell Provider Data;
- not use Provider Data to train public or general-purpose AI models;
- not use Provider Data for unrelated advertising or profiling; and
- delete or de-identify Provider Data when no longer required, subject to contractual, technical and legal retention requirements.
6. Details of processing
| Processing detail | Description |
|---|---|
| Subject matter | Provision of EduX assessments, surveys, reviews, learning, evidence, reporting, support and related organisation services. |
| Duration | For the subscription period and any applicable retention, export, backup or legal period. |
| Individuals | Provider staff, administrators, students, learners, candidates, respondents, assessors, reviewers and other authorised Users. |
| Data categories | Identity and contact details; organisation and course information; responses; scores; evidence; reports; notes; learning records; billing; audit; device and security information. |
| Special categories | EEPT speaking recordings are collected only through the portal's consent-gated recorder and handled under clause 7. No other audio, video or biometric data may be submitted. Other sensitive information must only be submitted where necessary, lawful and expressly supported by the relevant service. |
| Purposes | Service delivery, account administration, assessment, reporting, evidence analysis, learning integration, security, support, legal compliance and agreed service improvement. |
7. EEPT Speaking Assessment
The EEPT Speaking component uses asynchronous recorded responses. The candidate records audio responses to approved speaking tasks in the EduX portal, behind an explicit consent step. Video is never recorded.
EduX will:
- present the approved consent notice and record the candidate's answer with the wording version and time;
- store recordings encrypted at rest, with playback access within the EduX application restricted to the Provider's authorised assessor through an authenticated playback function, and no routine playback access for EduX personnel;
- log every playback;
- delete recordings automatically when the speaking result is finalised and in any case within 30 days of recording, and log deletions;
- determine the speaking level from the assessor's matrix scores by a deterministic calculation; and
- not transcribe recordings, not apply automated or AI speech scoring, not use recordings for biometric identification or verification, and not create any voiceprint or biometric template. A speaking recording is treated as personal information handled with heightened safeguards, not as biometric information.
The Provider will:
- ensure recordings are assessed only by a suitably qualified or authorised English-language assessor;
- ensure the assessor listens only through the portal's playback function and applies the approved EduX Speaking Assessment Matrix;
- verify the candidate's identity; and
- not extract, download, re-record or otherwise copy recordings out of the portal.
If the candidate declines consent, no recording is made and the report notes that speaking was not assessed. The Provider may also record a decision not to assess speaking; any stored recordings are deleted when that decision is recorded.
EduX provides: the approved speaking tasks; the consent notice and its versioned wording; the CEFR-aligned Speaking Assessment Matrix and rubric; the assessor declaration; and inclusion of the speaking outcome in the final EEPT report.
After deletion, EduX retains only structured speaking-assessment information: assessor identity and authorised role, task set, rubric scores, evidence notes, confidence, review status, declaration, the consent record and the resulting speaking outcome.
8. Audio, video and biometric information
The Provider must not upload to EduX any audio or video recording of a speaking interview, voiceprint, voice template, facial image collected for biometric use, biometric template, biometric identification or verification data, or similar biometric material unless EduX has expressly approved a separate written processing arrangement.
EduX will store only structured speaking-assessment information, which may include:
- interview date and mode;
- assessor identity, qualification or authorised role;
- task set used;
- rubric scores and brief evidence notes;
- assessor confidence and review status;
- assessor declaration; and
- the resulting speaking outcome.
If the Provider independently records an interview, the recording must remain in the Provider's approved systems. The Provider is solely responsible for lawful collection, notice, consent, security, access, retention, deletion, breach management and privacy-rights handling for the recording.
9. Security
EduX will maintain reasonable measures appropriate to the service, which may include:
- encryption in transit and appropriate encryption at rest;
- role-based access and tenant or organisation separation;
- authentication and multifactor-authentication controls;
- administrative-access controls and audit logging;
- backup, recovery, malware and vulnerability controls;
- incident-response procedures;
- staff confidentiality and access restrictions; and
- assessment of relevant service providers.
The Provider remains responsible for its accounts, devices, networks, exports, local records and removal of former-user access.
10. Subprocessors
EduX may engage approved Subprocessors for hosting, security, email, payments, support, analytics, document processing and AI-assisted functions.
EduX will take reasonable steps to ensure each Subprocessor:
- processes Provider Data only for authorised service purposes;
- maintains appropriate confidentiality and security;
- does not sell Provider Data or use it for unrelated purposes;
- does not use Provider Data to train public or general-purpose AI models; and
- returns, deletes or places data beyond use at the end of the service where required.
EduX will maintain a current list or category description of material Subprocessors and will provide it to the Provider on reasonable request. Where a material change creates a reasonable privacy or security concern, the parties will work in good faith to address it.
11. Data breaches
Where EduX becomes aware of a suspected or confirmed Data Breach affecting Provider Data, EduX will:
- take reasonable steps to contain and investigate the incident;
- notify the Provider without unreasonable delay;
- provide available information about the nature, affected data and likely consequences;
- cooperate in assessing serious harm and notification obligations;
- preserve relevant logs and evidence; and
- assist with notices to individuals or regulators where reasonably required.
Unless Applicable Privacy Law requires otherwise, the Provider will coordinate the decision whether to notify affected individuals, the OAIC or another regulator, after consulting EduX. Neither party will make a public statement identifying the other without prior consultation unless legally required.
12. Access, correction and individual rights
The Provider is the primary contact for individuals seeking access to, correction of or deletion of Provider-controlled data. EduX will provide reasonable assistance and may require identity verification and Provider authorisation before acting.
13. Retention, return and deletion
Provider Data will be retained while the account is active and for any agreed export, recovery, audit, backup or legal period. Unless a different period applies, cancelled-account data may be retained for up to six months. Deleted data may remain in database backups held in Australia for up to 90 days, after which it is permanently removed.
On request and subject to payment, security and legal requirements, EduX will provide an available export in a reasonable format. At the end of the retention period, EduX will take reasonable steps to delete or de-identify Provider Data, subject to backup cycles and limited records that must be retained.
14. Overseas processing
EduX will disclose whether material Subprocessors store or process Provider Data outside Australia and will take reasonable contractual and technical steps appropriate to the nature of the information and the service.
15. Confidentiality
EduX will ensure that personnel authorised to process Provider Data are subject to appropriate confidentiality obligations. Each party must protect the other's confidential information from unauthorised use or disclosure.
16. Audit and information requests
EduX will maintain reasonable records concerning relevant privacy and security controls. The Provider may request reasonable information required to assess EduX's compliance with this Agreement.
Any audit or assessment must:
- be proportionate to the risk and service;
- protect other clients' confidential information;
- avoid unreasonable disruption;
- use existing independent reports or questionnaires where reasonably sufficient; and
- be subject to confidentiality and reasonable cost allocation.
17. Liability and responsibility
Each party is responsible for its own breach of this Agreement and Applicable Privacy Law. The Provider is responsible for unlawful collection, disclosure or upload of Provider Data, including any unauthorised audio, video or biometric material, except to the extent caused by EduX's breach.
Liability caps and exclusions are governed by the Terms, service agreement or order form, subject to rights that cannot lawfully be excluded.
18. Term and termination
This Agreement begins when the Provider signs or electronically accepts it or activates an organisation account and continues while EduX processes Provider Data on the Provider's behalf.
19. Order of precedence
If this Agreement conflicts with the general Terms concerning Provider Data, this Agreement prevails to the extent of the conflict. A signed service agreement may prevail where it expressly states that it overrides this Agreement.
20. Electronic acceptance
The Provider agrees that electronic acceptance by an authorised representative has the same effect as a signature. EduX will retain the accepted version, date, time, account, user identity and available technical audit information.
21. Governing law
This Agreement is governed by the laws of Victoria, Australia, unless the applicable service agreement states otherwise.
22. Provider acceptance
Acceptance is confirmed at the time of creating an account with EduX.