Record Keeping Policy and Procedure

Edited

Purpose

At Pilates ITC, we take your privacy and information security seriously. This policy outlines how we safely manage your enrolment, assessment, and financial records, while meeting national compliance standards. It also explains how you can access your records and how we protect them using secure systems. This approach ensures we’re aligned with the Standards for RTOs 2025, ASQA guidelines, and the Privacy Act 1988 (Cth).


Definitions

  • Student Management System (SMS) – A secure platform used by Pilates ITC to store and manage enrolment, training, and assessment records

  • Learning Management System (LMS) – The online platform used for accessing course materials, submitting assessments, and tracking learning progress

  • Third-Party Providers – External services used by Pilates ITC for managing payments and data securely (e.g., VT Cloud, Adobe Learning Manager, Stripe)


Who This Policy Applies To

  • All Pilates ITC student, financial, and operational records

  • All third-party platforms used to manage or store records, including:

    • VT Cloud (Ready Student) – SMS for student enrolment and training history

    • Adobe Learning Manager – LMS for course access and delivery

    • Debit Success, Stripe, and Ezidebit – Payment and finance processing systems


Our Policy

Types of Records We Maintain

We keep the following categories of information:

  • Student Records

    • Enrolment details

    • Unique Student Identifier (USI)

    • Assessment results and participation records

    • Course attendance

    • Certification documents (e.g., Statements of Attainment, Diplomas)

  • Financial Records

    • Payment history and invoice details

    • Transactions processed via Debit Success, Stripe, and Ezidebit

    • Fee-related documents, including refunds

  • Operational Records

    • Organisational policies and procedures

    • Staff qualifications and professional development

    • Audit and compliance documentation

How Your Records Are Stored

We use secure digital platforms to keep your data protected:

  • VT Cloud (Ready Student) – Securely manages enrolment, course progress, and outcomes

  • Adobe Learning Manager – Hosts course content and student engagement records

  • Payment providers:

    • Debit Success – For Australian students enrolled in recurring payment plans

    • Stripe – For international transactions and one-off payments

    • Ezidebit – For students enrolled prior to January 2023

We use password-protected systems, encryption, and limited internal access to ensure your data stays safe and confidential.

How Long We Keep Your Records

  • Student Records – Retained for 30 years, as required by national regulation

  • Financial Records – Kept for a minimum of 7 years, in line with taxation requirements

  • Operational Records – Retention time depends on our internal policy and compliance frameworks

Accessing Your Records

You have the right to view your personal records:

  • Submit your request via the Student Management System (SMS)

  • We’ll process your request within 10 business days

  • Only authorised staff can access confidential student records for administrative purposes

Secure Record Disposal

When records are no longer required:

  • Physical documents are shredded securely

  • Digital files are deleted using data-wiping tools that meet secure destruction standards

Monitoring and Review

To ensure we meet all legal and quality obligations:

  • Our management team audits record-keeping practices regularly

  • Policies and systems are reviewed annually or when laws change

  • Any concerns or potential breaches are handled quickly and carefully to minimise risk


Contact

If you have questions or need support, please don’t hesitate to reach out. Our friendly Student Services Team is here for you. Visit our Contact Us page for details.


Compliance

This policy complies with:

Clauses 8.1–8.3 of the Standards for RTOs 2025: Supporting secure, accurate, and transparent record-keeping for students and operational procedures.

Privacy Act 1988 (Cth): Ensuring your personal information is handled lawfully and securely.

ASQA Guidelines: Reinforcing record retention, access, and privacy obligations in the VET sector.

Australian Consumer Law: Ensuring financial records are managed fairly, transparently, and with integrity.


Disclaimer: This Policy / Procedure when printed, this becomes an uncontrolled document. 


Policy# P-COU-030

Version Control Table  

Version Number  

Date  

Owner  

Change / Update  

V12.0  

07 April 2025

Training Manager

Expanded policy and added procedure