Droneit
Help & support

Privacy Policy

How we collect, hold, use and disclose personal information across our websites, training services, AI tools and other operations.

Last updated: 1 September 2026

Droneit Group Pty Ltd ACN 600 504 201, ABN 24 600 504 201 (Droneit, we, us or our) is committed to protecting the privacy of the people who deal with us.

This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with our websites, online stores, student and training systems, products, aviation training, consulting and advisory services, customer support, telephone and video communications, artificial intelligence services, recruitment activities and other operations.

Droneit manages personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

This Privacy Policy explains our information-handling practices and does not limit any rights you may have under applicable law.

Where we ask you to acknowledge this Privacy Policy, that acknowledgement confirms that the policy has been made available to you. Where applicable law requires specific consent for a particular collection, use or disclosure, we will seek that consent separately or in the relevant context.

People located in the European Economic Area or United Kingdom may have additional privacy rights, which are addressed in our separate European and UK Privacy Notice.

Personal information we collect

The personal information we collect depends on the nature of your relationship with Droneit.

Customers and purchasers

If you purchase a product or service from us, we may collect information including:

  • your name and contact details
  • billing and delivery information
  • order and transaction history
  • payment status
  • warranty, repair and return information
  • correspondence and support history

If you choose to use a third-party payment, credit, instalment or finance facility, that provider may separately collect and handle personal information under its own privacy terms.

Students and training participants

If you purchase training or become a student, we may also collect information including:

  • date of birth
  • Aviation Reference Number
  • enrolment and attendance information
  • training history and course progress
  • assessment responses and results
  • examination and quiz results
  • knowledge deficiency reports
  • competency records
  • signatures
  • certificates and licensing information
  • instructor and assessor records
  • communications relating to your training

Certain information must be collected or retained because Droneit operates within a regulated civil aviation environment.

Where an employer or other organisation arranges training or services for you, we may receive personal information from that organisation and may provide it with information reasonably connected with the services it has arranged, subject to applicable law and the circumstances of the engagement.

Consulting and professional services

If you engage Droneit for ReOC assistance, manual preparation, enterprise training, flight planning, tutoring, consulting or other professional services, we may collect business, operational, aviation and contact information necessary to understand and perform the engagement.

Enquiries and support

If you contact us for information or support, we may collect your contact details together with information including:

  • the content and history of your enquiry
  • support tickets
  • emails
  • telephone calls
  • chats and messages
  • escalation information
  • staff responses and notes
  • other communications relevant to your matter

Employment applications

If you apply to work with Droneit, we may collect information including:

  • contact details
  • employment history
  • qualifications
  • licences
  • experience
  • application materials
  • interview information
  • referee details

Website and system information

When you use our websites or online systems, we may collect technical and usage information including:

  • IP address
  • browser and device information
  • login and security information
  • timestamps
  • pages visited
  • course and learning activity information
  • referral information
  • cookies and similar technologies
  • interaction information
  • diagnostic and security data

We do not generally seek sensitive information unless it is reasonably necessary for our functions or activities. Sensitive information may nevertheless be provided to us, for example where a person discloses health, accessibility or welfare information when seeking assistance. Where the Privacy Act requires consent or another lawful basis for the collection of sensitive information, we will handle it accordingly.

How we collect personal information

We usually collect personal information directly from you when you purchase something, enrol, complete training, use our systems, communicate with us, participate in a call or meeting, undertake an assessment, apply for a position or otherwise deal with Droneit.

We may also receive personal information from:

  • employers and corporate customers
  • authorised representatives
  • referees
  • payment or finance providers
  • regulatory bodies
  • training partners
  • other organisations involved in providing a service to you

Some information is collected automatically through websites, student systems, security tools, cookies and similar technologies.

Software and artificial intelligence systems may also create or infer information from material we already hold. For example, a system may classify a support request, summarise a conversation, identify the subject of an enquiry, detect a possible security issue or generate information that assists a staff member to handle a matter.

Information created or inferred in this way is treated as personal information where an individual is identified or reasonably identifiable.

Where practicable, people may make general enquiries without identifying themselves or may use a pseudonym. There are circumstances, however, where identification is necessary or where providing the relevant service anonymously would be impracticable. These include:

  • delivering purchased goods
  • creating or accessing student accounts
  • maintaining regulated training records
  • conducting assessments
  • providing personalised account support
  • dealing with complaints or disputes
  • preventing misuse
  • investigating misconduct
  • meeting legal or regulatory obligations

How we use personal information

We use personal information to operate Droneit and provide the products and services requested from us.

This may include:

  • processing purchases and payments
  • delivering products
  • administering payment arrangements
  • managing accounts and enrolments
  • conducting training and assessments
  • maintaining training and certification records
  • issuing certificates
  • providing tutoring and student support
  • performing consulting and advisory work
  • communicating with customers and students
  • administering warranties, returns and refunds
  • handling complaints
  • preventing fraud, misuse and unauthorised activity
  • maintaining system security
  • meeting aviation, taxation and other legal or regulatory obligations

We may also use information to maintain and improve our services, including by analysing recurring support issues, improving course material, reviewing service quality, identifying operational problems, developing support resources and improving the systems, workflows and artificial intelligence tools used by Droneit.

Where permitted by law, we may use contact information to communicate with you about Droneit products, training, services or offers. Marketing communications will include an appropriate means of opting out.

Recorded calls, meetings, training and assessments

All telephone calls to or from Droneit are recorded and transcribed.

Online meetings, video calls, tutoring sessions, online classrooms, training sessions, assessments and related interactions may also be recorded in audio, video, transcript or other electronic form.

Recorded material may include:

  • voices
  • video and images of participants
  • screen content
  • written messages
  • documents or information displayed during an interaction
  • other information communicated during the interaction

Recordings and transcripts may be used to:

  • provide the relevant service
  • maintain training or assessment evidence
  • provide student or customer support
  • investigate complaints or incidents
  • monitor quality
  • assist or train staff
  • maintain business and regulatory records
  • comply with legal and aviation regulatory obligations
  • resolve disputes
  • improve our systems
  • improve Droneit’s support and AI knowledge

Where notification of recording or transcription is required in the circumstances, Droneit takes reasonable steps to provide that notification.

People may disclose information during a conversation that Droneit did not specifically request. Recorded material may therefore contain personal or sensitive information, and we take this into account when determining how the material is handled, accessed and retained.

Artificial intelligence and automated systems

Droneit uses artificial intelligence and other automated technologies across parts of its operations.

These systems may assist with:

  • education and tutoring
  • student support
  • telephone enquiries
  • customer service
  • analysing support requests
  • preparing draft responses
  • summarising interactions
  • identifying relevant information
  • navigating online services
  • improving knowledge resources
  • identifying recurring issues
  • assisting staff with operational and administrative work

Some telephone interactions may be handled or assisted by artificial intelligence.

AI systems can make mistakes or produce incomplete or inaccurate information. AI-generated information should not be treated as a substitute for official course material, legislation, regulatory material or a formal determination by an appropriately authorised member of Droneit’s staff where one is required.

AI in the student portal

Droneit’s conversational AI study and support assistant is an optional service. Students are not required to converse with the assistant in order to undertake their course.

The assistant operates within an authenticated student environment.

When a logged-in learner accesses a page on which the assistant is available, limited account information may be provided to the AI service for secure identification and personalisation. This may include:

  • the learner’s name
  • email address
  • account identifier

This identity process can occur when the assistant is loaded and does not require the learner to first send a chat message.

The assistant may also receive relevant learning context, including the course, lesson, page or learning activity being viewed, where that information is used to provide relevant assistance or navigation.

Conversations with the assistant are associated with the authenticated learner account and are not an anonymous communication channel.

This enables the assistant to provide personalised assistance and, where requested, to raise or assist with a support request without requiring the learner to provide information Droneit already holds.

Droneit staff may review AI conversations for purposes including:

  • student or customer support
  • quality assurance
  • abuse management
  • staff safety
  • complaint handling
  • troubleshooting
  • service improvement

How interactions improve Droneit’s AI systems

Droneit’s AI systems may analyse support tickets, telephone and video conversations, transcripts, customer and prospective-customer enquiries, staff replies, escalation notes and other service interactions to improve the quality of future support and assistance.

This process may include:

  • extracting the substance of a question and its resolution
  • identifying recurring issues
  • combining or deduplicating similar topics
  • developing reusable knowledge
  • improving instructions, workflows and support resources

Our systems are designed to minimise the inclusion of customer-identifying information in reusable knowledge where that information is not necessary for the knowledge being retained.

Reusable knowledge is intended to preserve the issue and its resolution rather than the identity of the person who originally raised it.

References in this Privacy Policy to AI systems learning or improving generally refer to improving Droneit’s knowledge bases, prompts, instructions, workflows and support systems. They do not necessarily mean that an underlying general-purpose AI model is being retrained using customer personal information.

Personal information contained in the original ticket, call, transcript or communication is nevertheless processed when the system analyses that interaction, and the source record remains subject to this Privacy Policy.

Automated processing and human oversight

Droneit also uses non-AI computer systems to automate or assist parts of its operations.

Routine automated processing may include:

  • marking online quizzes
  • recording course progress or completion
  • processing payment or account status
  • applying system access rules
  • routing support requests
  • detecting technical or security events

AI and other computer systems may also produce scores, recommendations, classifications, flags, summaries or other outputs that assist Droneit staff with decisions.

Personal information used in these systems may include:

  • identity and account information
  • enrolment records
  • transaction and payment information
  • course activity
  • assessment responses and results
  • support history
  • staff notes
  • system and security activity
  • regulatory information
  • relevant recordings or transcripts

Automated systems may assist with decisions concerning:

  • enrolment or service eligibility
  • access to training or accounts
  • formal assessment or examination outcomes
  • refunds or payment arrangements
  • suspected fraud or security concerns
  • account restrictions or suspension
  • regulatory or licensing administration
  • disciplinary or conduct matters
  • escalation or handling of support matters

Droneit retains human oversight for decisions of significance. Where AI or another computer system materially assists with a consequential decision, an authorised person reviews the relevant information and may confirm, reject or override the system’s output.

Formal examination results produced through automated or optical grading systems are subject to human checking. Routine online learning quizzes may be marked automatically within the learning platform.

When we disclose personal information

Droneit does not sell personal information.

We may disclose personal information to organisations that assist us to operate our business and provide our services, including providers of:

  • cloud and hosting services
  • education and learning technology
  • communications systems
  • customer support systems
  • artificial intelligence technology
  • payment and finance services
  • accounting services
  • analytics
  • cybersecurity
  • logistics
  • other business systems

We may also disclose personal information where appropriate to:

  • instructors and assessors
  • contractors and training partners
  • professional advisers
  • insurers
  • employers or corporate customers arranging services
  • other persons you direct or authorise us to deal with

We seek to limit disclosure to information reasonably necessary for the relevant function or purpose.

CASA, regulators and government requests

Droneit operates within Australia’s civil aviation regulatory framework. Certain information must therefore be collected, retained or provided for aviation regulatory purposes.

Depending on the circumstances, records relevant to a regulatory requirement or lawful request may include:

  • student identity information
  • Aviation Reference Number
  • date of birth
  • signatures
  • enrolment and attendance information
  • training records
  • examination and assessment material
  • knowledge deficiency records
  • competency information
  • communications and emails
  • tutoring records
  • classroom, meeting or video recordings
  • other evidence relevant to training or assessment

CASA requires prescribed RePL training records to be retained for seven years after the course ends.

A request from a government agency, regulator or enforcement body does not, merely because it has been made, result in automatic disclosure by Droneit.

We may disclose personal information without your consent where disclosure is:

  • required or authorised by Australian law
  • required by a court or tribunal order
  • required as part of a lawful regulatory obligation
  • otherwise permitted under the Privacy Act

Where appropriate, Droneit will verify the identity of the requesting body, consider the apparent authority and lawful basis for the request and assess the scope of the information sought.

Where practicable, we seek to limit disclosure to information reasonably necessary to comply with the lawful request or obligation.

Where the Privacy Act requires a written record of an enforcement-related use or disclosure, Droneit will make that record.

We cannot guarantee that an affected person will be notified before information is disclosed to a government agency, regulator or enforcement body. Notification may be prohibited by law, inconsistent with a lawful order or inappropriate where it could prejudice an investigation or enforcement activity.

Overseas handling of information

Droneit uses cloud-based, communications, education, payment, artificial intelligence and other technology services to operate its business. Personal information may therefore be stored, processed or disclosed outside Australia.

The overseas countries in which personal information is currently most likely to be stored or processed include:

  • United States
  • Canada
  • Germany
  • Brazil
  • Singapore

Some service providers operate distributed global infrastructure. In those circumstances, it may not be practicable for Droneit to identify every country in which transient or ancillary processing may occur.

Where you independently choose to use an external payment, credit or finance service, additional overseas processing may occur in accordance with that provider’s own privacy policy.

Where the Australian Privacy Principles apply to a disclosure of personal information to an overseas recipient, Droneit will take the steps required by applicable privacy law.

We periodically review our international data-handling arrangements and may update the countries identified in this Privacy Policy when those arrangements change.

Children and young people

Some Droneit products and services are available to people under 18.

There is no general minimum age applying to all remote-pilot training, although individual qualifications or services may have particular age requirements.

We may collect a young person’s date of birth and other information where necessary for training, identity, regulatory or safety purposes.

Droneit requires a parent or guardian to be present for in-person training and assessments involving a student under 18.

A young person’s capacity to make privacy decisions depends on their maturity and ability to understand the nature and consequences of the relevant decision.

Where appropriate, Droneit may involve a parent or guardian when:

  • collecting information
  • providing privacy information
  • obtaining any required consent
  • dealing with a privacy request

Security

Droneit takes reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

Our information is primarily handled through cloud-based business systems rather than being hosted on computers physically located at our premises.

Security measures vary according to the information and systems involved and may include:

  • access controls
  • authentication measures
  • encryption
  • role-based permissions
  • monitoring and audit controls
  • secure credential management
  • staff access restrictions

No internet-connected system is completely immune from security risk.

Users are also responsible for protecting access to their own accounts. You should keep login credentials secure, avoid sharing passwords and log out when using a shared or public device.

If Droneit becomes aware of a data breach, we will assess it in accordance with applicable law. Where notification is required under the Notifiable Data Breaches scheme, we will notify affected individuals and the Office of the Australian Information Commissioner as required.

Further information about our security practices is available on our Data Security page.

How long we keep personal information

Droneit does not apply a single retention period to every category of information.

Some records must be retained for minimum periods under aviation, taxation or other laws. Prescribed RePL training records are retained for at least seven years after the course ends.

Other information may be retained while it remains reasonably necessary for purposes including:

  • ongoing course access or support
  • maintaining certification or training evidence
  • administering transactions or warranties
  • handling complaints
  • preventing fraud
  • maintaining security
  • establishing or defending legal claims
  • meeting regulatory requirements
  • maintaining or improving Droneit’s support and knowledge systems

Some communications, recordings, transcripts and support records may therefore be retained for extended periods where they continue to serve a lawful and reasonably necessary purpose.

Where personal information is no longer required for a purpose for which Droneit may lawfully use or disclose it, and no law or court or tribunal order requires its continued retention, we will take reasonable steps to destroy the information or ensure that it is de-identified in accordance with applicable law.

Access, correction and privacy complaints

You may request access to personal information Droneit holds about you and may ask us to correct information that you believe is inaccurate, out of date, incomplete, irrelevant or misleading.

We may need to verify your identity before providing access or making a correction.

There are circumstances in which the Privacy Act permits or requires us to refuse access or correction. Where that occurs, we will provide any response or reasons required by law.

A request to delete information will be considered having regard to the purpose for which the information is held and any legal, regulatory, contractual, security or evidentiary requirements that require or permit continued retention. Australian privacy law does not provide an unconditional right to require deletion of every record.

If you believe Droneit has not handled your personal information appropriately, you may make a privacy complaint. Please provide sufficient information for us to understand and investigate the matter.

Privacy enquiries, access and correction requests, and complaints should be directed to:

Privacy Officer
Droneit Group Pty Ltd
Suite 4446
29/97 Creek Street
Brisbane City QLD 4000
Australia

Email: digital@droneit.com.au
Telephone: 1800 376 634

We will consider privacy complaints and respond within a reasonable period.

If you are not satisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.

Cookies and similar technologies

Droneit uses cookies and similar technologies across our websites and online services to operate and secure those services, remember preferences, understand how they are used and measure the effectiveness of our advertising.

Cookies are small data files stored on, or accessed from, your browser or device. Some operate only for the current browser session. Others remain for a defined period so that a website can recognise the browser or remember information when you return.

Similar technologies may include local storage, pixels, tags and other browser or device technologies. References to cookies in this section include these similar technologies where appropriate.

Strictly necessary cookies

Strictly necessary cookies support functions required for our websites and online services to operate properly.

They may be used for purposes including:

  • account authentication and login sessions
  • website and account security
  • fraud prevention
  • shopping cart and checkout functionality
  • transaction processing
  • load balancing
  • recording privacy and cookie preferences

These technologies may operate without consent where applicable law permits because they are necessary to provide a service requested by the user or to operate that service securely.

Blocking strictly necessary cookies through your browser may prevent parts of our websites, checkout, student systems or other online services from working correctly.

Functional and preference cookies

Functional cookies allow our websites and online services to remember choices or provide enhanced functionality.

They may remember preferences, settings, location choices or other information so that you do not need to make the same selection each time you use the service.

Some functional technologies may be necessary for a feature you have specifically requested. Others may be optional.

Analytics and performance cookies

Analytics and performance technologies help us understand how our websites and online services are used.

They may collect information about matters such as:

  • pages visited
  • navigation paths
  • traffic and referral sources
  • interactions with website features
  • technical performance
  • errors and diagnostics
  • use of particular website functions

We use this information to understand performance, identify problems and improve our websites and services.

Where applicable law requires consent before these technologies are used, they will not be activated until the required consent has been given.

Advertising and marketing cookies

Advertising and marketing technologies may be used to measure campaign performance, understand whether a browser or device has previously interacted with Droneit and help make advertising more relevant.

These technologies may allow advertising or measurement services to recognise a browser or device across different websites or online services.

Where applicable law requires consent for advertising or marketing technologies, they will not be activated until the required consent has been given.

Rejecting these technologies does not prevent you from using Droneit’s website. It may, however, affect the relevance of advertising you see elsewhere.

Referral and affiliate tracking

Where a person follows an authorised Droneit referral or affiliate link, a cookie or similar technology may be used to record the referral so that it can be attributed if a qualifying transaction later occurs.

Droneit’s affiliate referral period is currently 120 days.

Referral tracking does not change the price paid by the customer.

First-party and third-party technologies

Some cookies and similar technologies are set directly through Droneit’s websites or online services.

Others may be set or accessed by third-party services used in connection with functions such as payments, analytics, advertising, communications, security, embedded content or other website functionality.

Where information collected through these technologies constitutes personal information, we handle it in accordance with this Privacy Policy.

Third-party organisations may also handle information under their own privacy terms where they act independently of Droneit.

Information about overseas handling and the categories of organisations with which we may share personal information is provided elsewhere in this Privacy Policy.

Information about the security measures applying to Droneit’s systems is available on our Data Security page.

How long cookies remain

The period for which a cookie remains on a browser or device depends on its purpose.

A session cookie generally expires when the browser session ends.

A persistent cookie remains for a defined period or until it is deleted.

Individual cookie durations may change as our websites, functionality and service providers change.

Referral and affiliate tracking may remain for up to 120 days as described above.

Cookie consent and preferences

Cookie requirements differ between countries and jurisdictions.

Droneit applies cookie controls according to the legal requirements applicable to the user and the relevant online service.

Where consent is legally required before non-essential cookies or similar technologies are stored on or accessed from a device, users will be provided with controls that allow them to:

  • accept non-essential technologies
  • reject non-essential technologies
  • choose between available categories

Where consent is required, simply continuing to browse the website is not treated as consent to non-essential cookies.

You may change or withdraw a previous cookie choice using the Cookie Settings control available on the website.

Changing a preference affects future use of the relevant technologies. It does not invalidate processing that lawfully occurred before the preference was changed.

Strictly necessary technologies may continue to operate where consent is not legally required for their use.

Users in Australia

Australia does not apply the same general cookie-consent regime that applies in some overseas jurisdictions.

Where information collected through cookies or similar technologies constitutes personal information, Droneit handles that information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and this Privacy Policy.

Droneit may make cookie and preference controls available to Australian users even where consent is not legally required for every category of technology.

European Economic Area and United Kingdom

Where European Economic Area or United Kingdom law applies, Droneit will obtain consent before using cookies or similar technologies where that consent is legally required.

Strictly necessary technologies may be used without consent where permitted by applicable law.

Where consent is required, users will be given a genuine choice about non-essential technologies, including the ability to reject them and withdraw consent later.

Additional information for people in the European Economic Area and United Kingdom is available in our separate European and UK Privacy Notice.

Changes to this Privacy Policy

Droneit’s services, technology and legal obligations change over time. We may update this Privacy Policy from time to time to reflect changes in our operations, information-handling practices or legal requirements.

The current version will be published on our website and identified by its last-updated date.

Where a change materially affects the way we handle personal information, we may take additional reasonable steps to bring the change to the attention of affected people where appropriate.

Updating this Privacy Policy does not remove any requirement to obtain specific consent where applicable law requires it.

Privacy Policy change history

Every revision is date-stamped below, so you always know which version applied when you agreed to it.

  • Added detailed information about strictly necessary, functional, analytics, advertising and referral technologies.
  • Added information about cookie duration, consent and preference controls.
  • Added specific information for users in Australia, the European Economic Area and the United Kingdom.
  • Consolidated the former standalone Cookie Policy into this Privacy Policy.
  • Policy fully rewritten and expanded. Effective date: 1 September 2026.
  • Added detailed sections covering recorded calls and meetings, artificial intelligence (including the student portal AI assistant and how interactions improve AI systems), automated processing and decision-making, and children and young people.
  • Added dedicated sections on CASA and regulatory disclosures, overseas data handling and retention practices.
  • Added transparency statement on automated decision-making in advance of the Australian Privacy Principles requirements commencing 10 December 2026.
  • Policy now expressly states that Droneit does not sell personal information.
  • European and UK Privacy Notice referenced for EEA/UK visitors.
  • Privacy Policy republished at droneit.com.au/privacy as part of the new website launch.
  • No changes to the substance of the policy.
  • Cookie declaration refreshed to reflect analytics and advertising services in use at that time.