Most privacy pages describe what a company promises not to do with your data. Ours describes what the software cannot do, because it was built without the parts that could.
Student work is some of the most personal material an RTO holds. The safest place for it is where it already was. On your machines, under your control, for as short a time as we can manage.
Apollo has no server and no submissions database. There is no copy of a student’s work sitting in our infrastructure, because there is no infrastructure for it to sit in. The batch lives on the assessor’s machine while it is being marked and clears when they sign off. A breach of our systems can’t expose your learners’ work, because there’s nothing there to expose.
Before any text leaves the trainer’s machine, identifiers are stripped, and painted out of scanned pages. Where that cannot be done reliably, as with handwriting, Apollo stops and waits for the assessor’s explicit OK rather than deciding for them. The model reads de-identified work. The person reads the student.
A promise can be broken. An architecture has to be rebuilt.
There’s one data flow, and we’d rather state it plainly than bury it. De-identified text is processed by the AI on your organisation’s own account, outside Australia. That is the fact your privacy officer needs for an Australian Privacy Principle 8 assessment, and it belongs on the front of the page, not in clause 14. Privacy philosophy, for us, is mostly the discipline of making the true sentence the prominent one. The full data-handling detail lives on Your data.