Privacy Policy
How we collect, hold, use and disclose personal information across our websites, training services, AI tools and other operations.
Last updated: 1 September 2026
Droneit Group Pty Ltd ACN 600 504 201, ABN 24 600 504 201 (Droneit, we, us or our) is committed to protecting the privacy of the people who deal with us.
This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with our websites, online stores, student and training systems, products, aviation training, consulting and advisory services, customer support, telephone and video communications, artificial intelligence services, recruitment activities and other operations.
Droneit manages personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
This Privacy Policy explains our information-handling practices and does not limit any rights you may have under applicable law.
Where we ask you to acknowledge this Privacy Policy, that acknowledgement confirms that the policy has been made available to you. Where applicable law requires specific consent for a particular collection, use or disclosure, we will seek that consent separately or in the relevant context.
People located in the European Economic Area or United Kingdom may have additional privacy rights, which are addressed in our separate European and UK Privacy Notice.
Personal information we collect
The personal information we collect depends on the nature of your relationship with Droneit.
Customers and purchasers
If you purchase a product or service from us, we may collect information including:
- your name and contact details
- billing and delivery information
- order and transaction history
- payment status
- warranty, repair and return information
- correspondence and support history
If you choose to use a third-party payment, credit, instalment or finance facility, that provider may separately collect and handle personal information under its own privacy terms.
Students and training participants
If you purchase training or become a student, we may also collect information including:
- date of birth
- Aviation Reference Number
- enrolment and attendance information
- training history and course progress
- assessment responses and results
- examination and quiz results
- knowledge deficiency reports
- competency records
- signatures
- certificates and licensing information
- instructor and assessor records
- communications relating to your training
Certain information must be collected or retained because Droneit operates within a regulated civil aviation environment.
Where an employer or other organisation arranges training or services for you, we may receive personal information from that organisation and may provide it with information reasonably connected with the services it has arranged, subject to applicable law and the circumstances of the engagement.
Consulting and professional services
If you engage Droneit for ReOC assistance, manual preparation, enterprise training, flight planning, tutoring, consulting or other professional services, we may collect business, operational, aviation and contact information necessary to understand and perform the engagement.
Enquiries and support
If you contact us for information or support, we may collect your contact details together with information including:
- the content and history of your enquiry
- support tickets
- emails
- telephone calls
- chats and messages
- escalation information
- staff responses and notes
- other communications relevant to your matter
Employment applications
If you apply to work with Droneit, we may collect information including:
- contact details
- employment history
- qualifications
- licences
- experience
- application materials
- interview information
- referee details
Website and system information
When you use our websites or online systems, we may collect technical and usage information including:
- IP address
- browser and device information
- login and security information
- timestamps
- pages visited
- course and learning activity information
- referral information
- cookies and similar technologies
- interaction information
- diagnostic and security data
We do not generally seek sensitive information unless it is reasonably necessary for our functions or activities. Sensitive information may nevertheless be provided to us, for example where a person discloses health, accessibility or welfare information when seeking assistance. Where the Privacy Act requires consent or another lawful basis for the collection of sensitive information, we will handle it accordingly.
How we collect personal information
We usually collect personal information directly from you when you purchase something, enrol, complete training, use our systems, communicate with us, participate in a call or meeting, undertake an assessment, apply for a position or otherwise deal with Droneit.
We may also receive personal information from:
- employers and corporate customers
- authorised representatives
- referees
- payment or finance providers
- regulatory bodies
- training partners
- other organisations involved in providing a service to you
Some information is collected automatically through websites, student systems, security tools, cookies and similar technologies.
Software and artificial intelligence systems may also create or infer information from material we already hold. For example, a system may classify a support request, summarise a conversation, identify the subject of an enquiry, detect a possible security issue or generate information that assists a staff member to handle a matter.
Information created or inferred in this way is treated as personal information where an individual is identified or reasonably identifiable.
Where practicable, people may make general enquiries without identifying themselves or may use a pseudonym. There are circumstances, however, where identification is necessary or where providing the relevant service anonymously would be impracticable. These include:
- delivering purchased goods
- creating or accessing student accounts
- maintaining regulated training records
- conducting assessments
- providing personalised account support
- dealing with complaints or disputes
- preventing misuse
- investigating misconduct
- meeting legal or regulatory obligations
How we use personal information
We use personal information to operate Droneit and provide the products and services requested from us.
This may include:
- processing purchases and payments
- delivering products
- administering payment arrangements
- managing accounts and enrolments
- conducting training and assessments
- maintaining training and certification records
- issuing certificates
- providing tutoring and student support
- performing consulting and advisory work
- communicating with customers and students
- administering warranties, returns and refunds
- handling complaints
- preventing fraud, misuse and unauthorised activity
- maintaining system security
- meeting aviation, taxation and other legal or regulatory obligations
We may also use information to maintain and improve our services, including by analysing recurring support issues, improving course material, reviewing service quality, identifying operational problems, developing support resources and improving the systems, workflows and artificial intelligence tools used by Droneit.
Where permitted by law, we may use contact information to communicate with you about Droneit products, training, services or offers. Marketing communications will include an appropriate means of opting out.
Recorded calls, meetings, training and assessments
All telephone calls to or from Droneit are recorded and transcribed.
Online meetings, video calls, tutoring sessions, online classrooms, training sessions, assessments and related interactions may also be recorded in audio, video, transcript or other electronic form.
Recorded material may include:
- voices
- video and images of participants
- screen content
- written messages
- documents or information displayed during an interaction
- other information communicated during the interaction
Recordings and transcripts may be used to:
- provide the relevant service
- maintain training or assessment evidence
- provide student or customer support
- investigate complaints or incidents
- monitor quality
- assist or train staff
- maintain business and regulatory records
- comply with legal and aviation regulatory obligations
- resolve disputes
- improve our systems
- improve Droneit’s support and AI knowledge
Where notification of recording or transcription is required in the circumstances, Droneit takes reasonable steps to provide that notification.
People may disclose information during a conversation that Droneit did not specifically request. Recorded material may therefore contain personal or sensitive information, and we take this into account when determining how the material is handled, accessed and retained.
Artificial intelligence and automated systems
Droneit uses artificial intelligence and other automated technologies across parts of its operations.
These systems may assist with:
- education and tutoring
- student support
- telephone enquiries
- customer service
- analysing support requests
- preparing draft responses
- summarising interactions
- identifying relevant information
- navigating online services
- improving knowledge resources
- identifying recurring issues
- assisting staff with operational and administrative work
Some telephone interactions may be handled or assisted by artificial intelligence.
AI systems can make mistakes or produce incomplete or inaccurate information. AI-generated information should not be treated as a substitute for official course material, legislation, regulatory material or a formal determination by an appropriately authorised member of Droneit’s staff where one is required.
AI in the student portal
Droneit’s conversational AI study and support assistant is an optional service. Students are not required to converse with the assistant in order to undertake their course.
The assistant operates within an authenticated student environment.
When a logged-in learner accesses a page on which the assistant is available, limited account information may be provided to the AI service for secure identification and personalisation. This may include:
- the learner’s name
- email address
- account identifier
This identity process can occur when the assistant is loaded and does not require the learner to first send a chat message.
The assistant may also receive relevant learning context, including the course, lesson, page or learning activity being viewed, where that information is used to provide relevant assistance or navigation.
Conversations with the assistant are associated with the authenticated learner account and are not an anonymous communication channel.
This enables the assistant to provide personalised assistance and, where requested, to raise or assist with a support request without requiring the learner to provide information Droneit already holds.
Droneit staff may review AI conversations for purposes including:
- student or customer support
- quality assurance
- abuse management
- staff safety
- complaint handling
- troubleshooting
- service improvement
How interactions improve Droneit’s AI systems
Droneit’s AI systems may analyse support tickets, telephone and video conversations, transcripts, customer and prospective-customer enquiries, staff replies, escalation notes and other service interactions to improve the quality of future support and assistance.
This process may include:
- extracting the substance of a question and its resolution
- identifying recurring issues
- combining or deduplicating similar topics
- developing reusable knowledge
- improving instructions, workflows and support resources
Our systems are designed to minimise the inclusion of customer-identifying information in reusable knowledge where that information is not necessary for the knowledge being retained.
Reusable knowledge is intended to preserve the issue and its resolution rather than the identity of the person who originally raised it.
References in this Privacy Policy to AI systems learning or improving generally refer to improving Droneit’s knowledge bases, prompts, instructions, workflows and support systems. They do not necessarily mean that an underlying general-purpose AI model is being retrained using customer personal information.
Personal information contained in the original ticket, call, transcript or communication is nevertheless processed when the system analyses that interaction, and the source record remains subject to this Privacy Policy.
Automated processing and human oversight
Droneit also uses non-AI computer systems to automate or assist parts of its operations.
Routine automated processing may include:
- marking online quizzes
- recording course progress or completion
- processing payment or account status
- applying system access rules
- routing support requests
- detecting technical or security events
AI and other computer systems may also produce scores, recommendations, classifications, flags, summaries or other outputs that assist Droneit staff with decisions.
Personal information used in these systems may include:
- identity and account information
- enrolment records
- transaction and payment information
- course activity
- assessment responses and results
- support history
- staff notes
- system and security activity
- regulatory information
- relevant recordings or transcripts
Automated systems may assist with decisions concerning:
- enrolment or service eligibility
- access to training or accounts
- formal assessment or examination outcomes
- refunds or payment arrangements
- suspected fraud or security concerns
- account restrictions or suspension
- regulatory or licensing administration
- disciplinary or conduct matters
- escalation or handling of support matters
Droneit retains human oversight for decisions of significance. Where AI or another computer system materially assists with a consequential decision, an authorised person reviews the relevant information and may confirm, reject or override the system’s output.
Formal examination results produced through automated or optical grading systems are subject to human checking. Routine online learning quizzes may be marked automatically within the learning platform.
When we disclose personal information
Droneit does not sell personal information.
We may disclose personal information to organisations that assist us to operate our business and provide our services, including providers of:
- cloud and hosting services
- education and learning technology
- communications systems
- customer support systems
- artificial intelligence technology
- payment and finance services
- accounting services
- analytics
- cybersecurity
- logistics
- other business systems
We may also disclose personal information where appropriate to:
- instructors and assessors
- contractors and training partners
- professional advisers
- insurers
- employers or corporate customers arranging services
- other persons you direct or authorise us to deal with
We seek to limit disclosure to information reasonably necessary for the relevant function or purpose.
CASA, regulators and government requests
Droneit operates within Australia’s civil aviation regulatory framework. Certain information must therefore be collected, retained or provided for aviation regulatory purposes.
Depending on the circumstances, records relevant to a regulatory requirement or lawful request may include:
- student identity information
- Aviation Reference Number
- date of birth
- signatures
- enrolment and attendance information
- training records
- examination and assessment material
- knowledge deficiency records
- competency information
- communications and emails
- tutoring records
- classroom, meeting or video recordings
- other evidence relevant to training or assessment
CASA requires prescribed RePL training records to be retained for seven years after the course ends.
A request from a government agency, regulator or enforcement body does not, merely because it has been made, result in automatic disclosure by Droneit.
We may disclose personal information without your consent where disclosure is:
- required or authorised by Australian law
- required by a court or tribunal order
- required as part of a lawful regulatory obligation
- otherwise permitted under the Privacy Act
Where appropriate, Droneit will verify the identity of the requesting body, consider the apparent authority and lawful basis for the request and assess the scope of the information sought.
Where practicable, we seek to limit disclosure to information reasonably necessary to comply with the lawful request or obligation.
Where the Privacy Act requires a written record of an enforcement-related use or disclosure, Droneit will make that record.
We cannot guarantee that an affected person will be notified before information is disclosed to a government agency, regulator or enforcement body. Notification may be prohibited by law, inconsistent with a lawful order or inappropriate where it could prejudice an investigation or enforcement activity.
Overseas handling of information
Droneit uses cloud-based, communications, education, payment, artificial intelligence and other technology services to operate its business. Personal information may therefore be stored, processed or disclosed outside Australia.
The overseas countries in which personal information is currently most likely to be stored or processed include:
- United States
- Canada
- Germany
- Brazil
- Singapore
Some service providers operate distributed global infrastructure. In those circumstances, it may not be practicable for Droneit to identify every country in which transient or ancillary processing may occur.
Where you independently choose to use an external payment, credit or finance service, additional overseas processing may occur in accordance with that provider’s own privacy policy.
Where the Australian Privacy Principles apply to a disclosure of personal information to an overseas recipient, Droneit will take the steps required by applicable privacy law.
We periodically review our international data-handling arrangements and may update the countries identified in this Privacy Policy when those arrangements change.
Children and young people
Some Droneit products and services are available to people under 18.
There is no general minimum age applying to all remote-pilot training, although individual qualifications or services may have particular age requirements.
We may collect a young person’s date of birth and other information where necessary for training, identity, regulatory or safety purposes.
Droneit requires a parent or guardian to be present for in-person training and assessments involving a student under 18.
A young person’s capacity to make privacy decisions depends on their maturity and ability to understand the nature and consequences of the relevant decision.
Where appropriate, Droneit may involve a parent or guardian when:
- collecting information
- providing privacy information
- obtaining any required consent
- dealing with a privacy request
Security
Droneit takes reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Our information is primarily handled through cloud-based business systems rather than being hosted on computers physically located at our premises.
Security measures vary according to the information and systems involved and may include:
- access controls
- authentication measures
- encryption
- role-based permissions
- monitoring and audit controls
- secure credential management
- staff access restrictions
No internet-connected system is completely immune from security risk.
Users are also responsible for protecting access to their own accounts. You should keep login credentials secure, avoid sharing passwords and log out when using a shared or public device.
If Droneit becomes aware of a data breach, we will assess it in accordance with applicable law. Where notification is required under the Notifiable Data Breaches scheme, we will notify affected individuals and the Office of the Australian Information Commissioner as required.
Further information about our security practices is available on our Data Security page.
How long we keep personal information
Droneit does not apply a single retention period to every category of information.
Some records must be retained for minimum periods under aviation, taxation or other laws. Prescribed RePL training records are retained for at least seven years after the course ends.
Other information may be retained while it remains reasonably necessary for purposes including:
- ongoing course access or support
- maintaining certification or training evidence
- administering transactions or warranties
- handling complaints
- preventing fraud
- maintaining security
- establishing or defending legal claims
- meeting regulatory requirements
- maintaining or improving Droneit’s support and knowledge systems
Some communications, recordings, transcripts and support records may therefore be retained for extended periods where they continue to serve a lawful and reasonably necessary purpose.
Where personal information is no longer required for a purpose for which Droneit may lawfully use or disclose it, and no law or court or tribunal order requires its continued retention, we will take reasonable steps to destroy the information or ensure that it is de-identified in accordance with applicable law.
Access, correction and privacy complaints
You may request access to personal information Droneit holds about you and may ask us to correct information that you believe is inaccurate, out of date, incomplete, irrelevant or misleading.
We may need to verify your identity before providing access or making a correction.
There are circumstances in which the Privacy Act permits or requires us to refuse access or correction. Where that occurs, we will provide any response or reasons required by law.
A request to delete information will be considered having regard to the purpose for which the information is held and any legal, regulatory, contractual, security or evidentiary requirements that require or permit continued retention. Australian privacy law does not provide an unconditional right to require deletion of every record.
If you believe Droneit has not handled your personal information appropriately, you may make a privacy complaint. Please provide sufficient information for us to understand and investigate the matter.
Privacy enquiries, access and correction requests, and complaints should be directed to:
Privacy Officer
Droneit Group Pty Ltd
Suite 4446
29/97 Creek Street
Brisbane City QLD 4000
Australia
Email: digital@droneit.com.au
Telephone: 1800 376 634
We will consider privacy complaints and respond within a reasonable period.
If you are not satisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.
Changes to this Privacy Policy
Droneit’s services, technology and legal obligations change over time. We may update this Privacy Policy from time to time to reflect changes in our operations, information-handling practices or legal requirements.
The current version will be published on our website and identified by its last-updated date.
Where a change materially affects the way we handle personal information, we may take additional reasonable steps to bring the change to the attention of affected people where appropriate.
Updating this Privacy Policy does not remove any requirement to obtain specific consent where applicable law requires it.
Privacy Policy change history
Every revision is date-stamped below, so you always know which version applied when you agreed to it.
- Policy fully rewritten and expanded. Effective date: 1 September 2026.
- Added detailed sections covering recorded calls and meetings, artificial intelligence (including the student portal AI assistant and how interactions improve AI systems), automated processing and decision-making, and children and young people.
- Added dedicated sections on CASA and regulatory disclosures, overseas data handling and retention practices.
- Added transparency statement on automated decision-making in advance of the Australian Privacy Principles requirements commencing 10 December 2026.
- Policy now expressly states that Droneit does not sell personal information.
- European and UK Privacy Notice referenced for EEA/UK visitors.
- Privacy Policy republished at droneit.com.au/privacy as part of the new website launch.
- No changes to the substance of the policy.
- Cookie declaration refreshed to reflect analytics and advertising services in use at that time.
