Data Security
Our security practices protect personal information, student records and business data from misuse, loss and unauthorised access, consistent with our obligations under the Privacy Act 1988 (Cth).
Last updated: 1 September 2026
Droneit takes the security of personal information, student records and business information seriously.
Our security practices are designed to protect information from misuse, interference, loss and unauthorised access, modification or disclosure, consistent with our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Security is an ongoing process. No internet-connected system can be guaranteed to be completely secure, and our controls are reviewed and adapted as our systems, risks and legal obligations change.
Cloud-based systems
Droneit's core business systems are primarily operated using established cloud-based services rather than locally hosted production databases.
Different systems are used for functions such as:
- student and training records
- communications
- customer and sales records
- payments
- documents and business records
- artificial intelligence and support services
- accounting and administration
The providers of those systems are responsible for the security, availability, redundancy and backup arrangements applicable to their infrastructure.
Droneit remains responsible for taking reasonable steps in relation to the personal information that it controls, including information held on our behalf by cloud service providers.
Information may be processed or stored outside Australia as described in our Privacy Policy.
Identity and access controls
Access to Droneit's core business systems is restricted to authorised users.
Security controls include:
- multi-factor authentication for core business systems
- individual user accounts
- access permissions based on role and operational need
- restrictions on administrative privileges
- controlled access to personal and student information
- prompt revocation of access when a person's employment or authorised access ends
Access is not provided merely because a person works for Droneit. Permissions are intended to reflect the information and systems required for that person's responsibilities.
Staff access and information handling
Staff and contractors are expected to handle personal and confidential information only for authorised business purposes.
Access to bulk information and databases is restricted. Staff are not permitted to download or extract databases or large collections of personal information unless specifically authorised for a legitimate business purpose.
Where available, administrative and audit records may be used to identify or investigate unusual or unauthorised activity.
Droneit may investigate suspected inappropriate access, copying, disclosure or use of information and may take disciplinary, contractual, technical or legal action where appropriate.
Data transmission and credentials
Droneit uses secure authentication and encrypted connections where supported by the systems through which information is transmitted.
Passwords, authentication credentials and access tokens should not be shared between users.
Administrative credentials and other privileged access are restricted to personnel who require that level of access.
Users of Droneit's services are also responsible for protecting their own accounts. Passwords should be kept confidential, devices should be appropriately secured, and users should log out when using shared or public computers.
Third-party service providers
Droneit relies on third-party technology providers to operate significant parts of its business.
The use of a third-party provider does not remove Droneit's obligations in relation to personal information that remains under our control.
We take reasonable steps appropriate to the circumstances when selecting, configuring and using services that handle business or personal information.
Individual technology providers are not listed publicly as part of our security architecture.
Our handling of disclosures, overseas processing and personal information is addressed separately in our Privacy Policy.
Monitoring and security events
Security-related activity may be recorded or monitored by Droneit or by the systems we use.
Logs and other technical information may be used to:
- identify unauthorised access
- investigate suspicious activity
- troubleshoot security incidents
- investigate misuse
- establish what occurred during an incident
- protect accounts and information
The level and type of logging varies between systems.
Security incidents and data breaches
Droneit maintains procedures for identifying, investigating and responding to suspected security and privacy incidents.
Where an incident involves personal information, we assess the circumstances and potential impact in accordance with applicable privacy law.
If a breach is an eligible data breach under Australia's Notifiable Data Breaches scheme, Droneit will notify affected individuals and the Office of the Australian Information Commissioner as required by law.
Our response may include actions to:
- contain the incident
- protect affected accounts or systems
- preserve relevant evidence
- investigate the cause and scope
- reduce the likelihood of recurrence
- assess whether notification is legally required
Retention and secure disposal
Security includes ensuring that personal information is not retained without an appropriate reason.
Droneit retains information where it remains reasonably necessary for purposes including service delivery, regulated training records, support, security, complaints, legal claims and other lawful business or regulatory requirements.
Where personal information is no longer required for a purpose for which it may lawfully be retained, Droneit takes reasonable steps to destroy it or ensure that it is de-identified where required by applicable law.
Further information about retention is provided in our Privacy Policy.
Your responsibility for account security
Customers and students should take reasonable steps to protect their accounts and devices.
In particular, you should:
- use a strong, unique password
- keep passwords and authentication codes confidential
- protect access to your email account
- avoid leaving an authenticated session open on a shared or public computer
- log out when using a device that is not exclusively under your control
- notify Droneit promptly if you believe your account or information has been compromised
Droneit will never require you to provide another person with your password in order to receive ordinary support.
Reporting a security concern
If you believe you have identified a security vulnerability, unauthorised disclosure, compromised account or other security issue affecting Droneit, please report it promptly and privately.
Email: digital@droneit.com.au
Please provide enough information for us to understand and investigate the issue.
Do not deliberately access, alter, download, destroy or disclose information that does not belong to you in order to demonstrate a suspected vulnerability.
Relationship with our Privacy Policy
This page explains Droneit's general approach to information security.
Our Privacy Policy explains how we collect, use, disclose, retain and otherwise handle personal information and should be read together with this page.
Data Security change history
Every revision is date-stamped below, so you always know which version applied when you agreed to it.
- Data Security page substantially revised to reflect Droneit's current security practices and information-handling environment.
- Replaced previous version (which referenced specific third-party vendor names and infrastructure details) with a vendor-neutral, principle-based description of security controls.
- New sections added: Identity and access controls, Staff access and information handling, Data transmission and credentials, Monitoring and security events, Security incidents and data breaches, Retention and secure disposal, Your responsibility for account security.
- Reporting a security concern section updated with current contact details.
