Privacy and information governance

Privacy Policy

Core Education Design respects the privacy of its clients, professional partners, website visitors and the educational communities with which it works. This policy explains how we collect, use, protect and manage personal information.

Effective July 2026 Zenith Creative Solutions Pty Ltd ABN 72 698 843 471

Our privacy commitment

We seek to collect only the information reasonably required to provide our services, communicate with clients and operate our business. We do not sell personal information. Identifiable educational information is not shared or processed through public artificial intelligence services without specific authorisation and appropriate safeguards.

About this policy

This Privacy Policy applies to Zenith Creative Solutions Pty Ltd (ABN 72 698 843 471), trading as Core Education Design, referred to in this policy as “Core Education Design”, “we”, “us” or “our”.

It applies to personal information collected through our website, enquiries, consultation bookings, optional newsletter subscriptions, client communications and the delivery of consultancy services.

We are an Australian educational consultancy and may also consider international engagements individually. We aim to manage personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. Where those laws do not legally apply to a particular activity, this policy describes the privacy practices we have voluntarily adopted.

Additional contractual, governmental, school-system or jurisdictional privacy requirements may apply to a particular engagement. Where appropriate, those requirements will be documented separately and will operate alongside this policy.

Personal information we may collect

The information collected depends on how you interact with us. It may include:

  • your name, role, organisation and professional contact details;
  • information submitted through website contact or enquiry forms;
  • consultation booking details and meeting preferences;
  • correspondence, meeting notes and information provided during consultancy discussions;
  • information about an institution’s priorities, systems, operational context and service requirements;
  • newsletter subscription details where you have separately opted in;
  • records necessary to manage proposals, agreements, services, invoicing and other business relationships; and
  • technical or usage information generated when you use our website, including anonymous or aggregated analytics.

We do not intentionally collect sensitive information through the public website. Please do not place identifiable student, parent or staff information, health information, confidential school records or other sensitive material in a website form.

If unnecessary personal or sensitive information is provided without being requested, we may delete, de-identify or securely restrict that information where lawful and practicable.

How we collect information

We generally collect personal information directly from you when you:

  • submit an enquiry through our website;
  • request or book a consultation;
  • subscribe to an optional newsletter or update;
  • communicate with us by email, telephone, video conference or in person;
  • enter into, negotiate or administer a consultancy engagement; or
  • provide information while participating in an approved project.

We may also receive professional contact or project information from an organisation that employs or engages you, a project partner, a referral source or another person authorised to provide it.

Where practical, you may make a general enquiry without providing more identifying information than is necessary. Some services cannot be provided anonymously because we need to identify the client, understand the institutional context or communicate about the requested work.

How we use personal information

We may use personal information to:

  • review, respond to and follow up enquiries;
  • assess whether a proposed engagement is an appropriate strategic fit;
  • arrange consultations, meetings, presentations and project activities;
  • develop proposals, scopes, agreements and consultancy deliverables;
  • provide, support, evaluate and improve our professional services;
  • manage client relationships and authorised project communication;
  • maintain appropriate financial, contractual and business records;
  • protect our systems, intellectual property and legal interests;
  • comply with applicable laws, professional obligations and lawful requests;
  • improve our website, communications and service design; and
  • send newsletters or promotional updates only where the recipient has separately opted in.

We do not use personal information for an unrelated purpose unless authorised by the individual or permitted or required by law.

Educational and institutional information

Most Core Education Design services can be delivered without receiving identifiable student, parent or staff information.

On rare occasions, an authorised consultancy engagement may require limited access to identifiable information within a school or client system. We will not seek or access that information without specific permission from the relevant institution and a legitimate project need.

Where such access is authorised, we will seek to:

  • limit access to the minimum information necessary;
  • work within the client’s approved systems wherever practicable;
  • follow applicable contractual, departmental and institutional requirements;
  • avoid creating unnecessary copies or extracts;
  • restrict use to the authorised purpose;
  • apply appropriate access controls and confidentiality safeguards;
  • not disclose the information to another party unless specifically authorised or legally required; and
  • return, delete or securely dispose of information when it is no longer required, subject to legal and contractual obligations.

Identifiable educational information is not used for independent marketing, sold, published as a case study or disclosed as evidence of project outcomes without the institution’s authority and any additional permissions required by law or agreement.

Artificial intelligence and automated tools

Core Education Design may use artificial intelligence and technology-assisted tools to support activities such as research, drafting, analysis, resource development, coding and service design. Human professional judgement remains central to our consultancy work.

We will not knowingly enter confidential or identifiable student, parent, staff or client information into a publicly accessible artificial intelligence service without:

  • specific authority from the relevant client;
  • a legitimate and documented purpose;
  • appropriate privacy, security and contractual safeguards;
  • consideration of data storage, retention and model-training settings; and
  • compliance with applicable institutional and legal requirements.

Where suitable, information used with AI tools will be de-identified, minimised or replaced with representative information. We do not treat removal of a name alone as sufficient de-identification where a person could reasonably be identified from the remaining context.

Client responsibility

Clients should not provide personal, sensitive or confidential information for AI-supported processing unless that use has been expressly discussed and authorised as part of the engagement.

Newsletters and marketing communication

Submitting an enquiry or booking a consultation does not automatically subscribe you to marketing communication.

We will send newsletters, service announcements or promotional material only where you have separately opted in or where another lawful basis permits the communication.

Marketing messages will include a practical method of unsubscribing. You may also withdraw your consent at any time by contacting darren@coreeducation.com.au .

Withdrawing from marketing communication will not prevent us from sending essential correspondence about an active enquiry, booking, agreement or consultancy engagement.

Disclosure and service providers

We do not sell or rent personal information. We may provide limited information to third-party service providers where reasonably necessary to operate the website, communicate, analyse website performance or deliver an authorised service.

Current website-related providers include:

  • Squarespace, which provides website hosting, forms and related website functionality; and
  • Google Analytics, which provides website traffic and usage analytics.

These providers operate under their own terms and privacy practices. The information processed by them may include contact-form information, technical identifiers, device or browser information, approximate location information and website interaction data, depending on the service and configuration.

We may also disclose information:

  • to professional advisers where reasonably necessary;
  • to contractors or project partners specifically authorised for an engagement and bound by appropriate confidentiality requirements;
  • where required or authorised by Australian law;
  • in response to a valid court, tribunal or regulatory requirement;
  • to investigate suspected fraud, misuse or security incidents; or
  • where reasonably necessary to lessen or prevent a serious threat to a person’s life, health or safety, where permitted by law.

Overseas processing and international clients

Some technology providers used by Core Education Design are international organisations. Personal information or technical data may therefore be processed, stored or accessed outside Australia, including in jurisdictions where those providers or their subcontractors operate.

Because cloud-service infrastructure and subcontractor locations may change, it may not be practicable to identify every country in which information could be processed. Relevant locations and safeguards will be considered more specifically where an engagement involves identifiable or sensitive educational information.

Before an international consultancy engagement is accepted, we may need to consider the privacy, data-protection, contractual and information-governance requirements of the relevant jurisdiction. Acceptance will be determined according to the individual circumstances and our capacity to meet those requirements.

Where the Australian Privacy Principles apply to an overseas disclosure, we will take reasonable steps to address the applicable cross-border disclosure requirements.

Website analytics and cookies

Our website may use cookies and similar technologies required for website operation, security, performance measurement and anonymous or aggregated analytics.

Google Analytics may collect information about how visitors use the website, such as:

  • pages viewed and navigation pathways;
  • session duration and general interaction information;
  • browser, device and operating-system information;
  • referring websites or campaign sources; and
  • general geographic information derived from technical data.

We use this information to understand website performance and improve content and services. We do not use website analytics to intentionally identify individual students or build profiles of educational users.

You can manage or block cookies through your browser settings. Doing so may affect the operation of some website features. Where legally required, additional consent controls may be presented to website visitors.

Information security and retention

We take reasonable administrative, contractual and technical measures appropriate to the nature of the information and the risks involved. These measures may include:

  • access controls and authentication safeguards;
  • restricted access to client and project information;
  • the use of reputable technology and hosting providers;
  • confidentiality provisions in relevant agreements;
  • data minimisation and de-identification where practicable;
  • secure deletion or disposal practices; and
  • review and response processes for suspected data incidents.

No internet transmission, cloud platform or storage system can be guaranteed to be completely secure. We cannot promise absolute security, but we will respond proportionately to identified risks and incidents.

Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to maintain appropriate business and project records, to meet contractual commitments, or to comply with legal, taxation, insurance and professional obligations.

Retention periods may therefore differ according to the type of information and engagement. When information is no longer reasonably required, we will take reasonable steps to delete or de-identify it, unless continued retention is required or authorised.

Data incidents

If we become aware of a suspected loss, unauthorised access, disclosure or misuse of personal information, we will assess and respond to the incident. Where the Notifiable Data Breaches scheme or another applicable law requires notification, we will take the required notification steps.

Access, correction and deletion requests

You may contact us to request access to personal information we hold about you or to ask that inaccurate, incomplete or out-of-date information be corrected.

You may also request deletion of information. We will consider the request subject to applicable legal, contractual, evidentiary and legitimate business record-keeping requirements.

We may need to verify your identity before acting on a request. In some circumstances, access or deletion may be refused or limited where permitted by law. If this occurs, we will generally explain the reason and available complaint options.

Requests should be sent to darren@coreeducation.com.au .

Privacy enquiries and complaints

If you have a privacy concern or believe we have mishandled personal information, please contact us with:

  • your name and preferred contact details;
  • a clear description of the concern;
  • relevant dates, communications or project details; and
  • the outcome you are seeking.

We will acknowledge the matter and seek to investigate and respond within a reasonable period. More complex matters may require additional information or time.

Where the Privacy Act applies and you are not satisfied with our response, you may be entitled to contact the Office of the Australian Information Commissioner .

Changes to this policy

We may update this Privacy Policy when our services, technology providers, legal obligations or information-handling practices change.

The current version will be published on this page with its effective date. Material changes may also be communicated directly where appropriate.