
Privacy policy
Explore our privacy policy to understand how Paddl secures and protects your information.
Paddl Co. Pty Ltd (ABN 14 131 952 004) of Level 2, 65 Dover Street, Cremorne, VIC 3121 (Paddl, we, us or our) is committed to protecting the privacy of the personal information we handle in connection with paddl.com and our business generally.
This Privacy Policy explains what personal information we collect, how we use, store and disclose it, and how you can access it, correct it, or make a complaint, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and, where applicable, the GDPR and UK GDPR.
1. How this policy fits with our client agreements
If you access paddl.com as a Member — an employee, worker or contractor of an organisation that has a Business Account with us (your Employer or our Client) — your Employer is generally responsible, as the controller, for the personal information it submits to paddl.com about you in order to deliver and manage your training. Paddl processes that information as a processor, on your Employer’s instructions, under our Master Subscription Agreement (MSA) and Data Processing Addendum (DPA) with your Employer. Those documents, not this Privacy Policy, govern that processing. If you have a question about that information, please contact your Employer in the first instance — we will assist them to respond to you.
This Privacy Policy describes the personal information Paddl handles in its own right, as an independent controller — including Usage Data, account administration and billing records, security monitoring and fraud prevention information, our communications with you, and Profile information we continue to hold after your access to your Employer’s Business Account ends (see “Retained Profiles” below) — together with personal information we collect through our website, marketing and other business dealings generally.
Some terms used in this policy
To keep this policy readable on its own, without needing to open any other document, here's what we mean by some of the words we use in it:
your Employer is the organisation you work for, or are otherwise engaged by, that has an account with us to provide you and your colleagues with training through paddl.com. We may also refer to your Employer as our Client;
the Employer’s Agreement is a contract that your Employer has entered into with Paddl in relation to your access to paddl.com.
a Member is an employee, worker or contractor who accesses paddl.com through their Employer’s account, usually to complete training assigned to them;
a Business Account is the account your Employer uses to manage its use of paddl.com, including inviting Members and assigning training;
your Profile is where your training history sits on paddl.com, and your Completions are records of the training you've finished;
a Sub-processor is a service provider we engage to help us run paddl.com (for example, a hosting or analytics provider), and a Connection is a third-party service — such as a training-content library or HR system — that your Employer has chosen to link to paddl.com.
2. Information we collect
Depending on how you interact with us, we may collect:
contact details, such as your name, email address and phone number;
account and billing information, including the details of our Client’s Admin Users and billing contacts;
Usage Data — information about how paddl.com is used, including authentication, session and device metadata;
support correspondence and other communications you have with us;
for individual Members whose Profile we continue to hold after their Employer’s Agreement ends, their name, work contact details, and training and Completions history; and
for website visitors and prospective clients, your name, business contact details and the details of your enquiry.
We do not seek to collect sensitive information about you (such as health, biometric, genetic or criminal record information, or information about racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation). Our Clients are contractually required not to submit that kind of information to paddl.com.
3. How we collect it
We collect personal information directly from you (for example, through forms, emails, phone calls, or your use of paddl.com); automatically through your use of paddl.com and our website, including cookies and analytics (see “Cookies” below); from your Employer, such as when they invite you as a Member or configure a Connection with a third-party Provider; and, for business contact purposes, from publicly available sources.
4. Why we collect, use and disclose your information
We collect, use and disclose personal information to:
provide, administer and improve paddl.com and the Services, including account administration, billing, security monitoring and fraud prevention;
communicate with you about the Services, respond to your enquiries, and provide support;
send you information about our services and offers that we think may be relevant to you (see “Direct marketing” below);
develop and improve our products and features, including by using Usage Data, and, on an aggregated or de-identified basis, Client Data, to train and improve the machine learning models and features underlying paddl.com (see “Artificial intelligence” below);
maintain your Profile and training and Completions history, including after your access to an Employer’s Business Account ends; and
comply with our legal obligations, resolve disputes and enforce our agreements. Where the GDPR or UK GDPR applies to personal information we handle as a controller, we rely on the following legal bases: performance of a contract, for account administration, billing and providing the Services; our legitimate interests, for security monitoring, fraud prevention, product and feature development on an aggregated or de-identified basis, maintaining a retained Profile, and business contact with prospective clients; your consent, for direct marketing where consent is required and for non-essential cookies; and compliance with a legal obligation, for tax, accounting and record-keeping requirements. Where we rely on our legitimate interests, we have considered whether those interests are outweighed by your rights, and you may object as described under Access and correction below.
5. Retained Profiles
If your Employer’s Agreement with Paddl ends, you may retain your Member Account and Profile, including your record of Completions, but you will lose access to that Employer's Programs. From that point, we handle your Profile as an independent controller, in accordance with this Privacy Policy and our Member Terms of Use, rather than on your former Employer’s instructions. You can ask us to export your Completions record, or to delete your retained Profile entirely, at any time — see “Access and correction” below.
6. Artificial intelligence and machine learning
We may use information submitted to paddl.com, including Client Data, to train, develop or improve the machine learning models and features underlying paddl.com, and to generate aggregated analytics for our Clients — always on an aggregated or de-identified basis. We do not use information that identifies you, a Client or a Client's Site to train, fine-tune or improve any model or feature, whether ours or a Sub-processor's. A Client may ask us not to use its Client Data for this purpose, and we will give effect to that request.
7. Disclosure of your information
We may disclose personal information to:
our related bodies corporate, personnel, and the service providers who help us operate paddl.com and run our business (including hosting, database, analytics, communications, sales and support providers). The Sub-processors that process information submitted to paddl.com are published at trust.paddl.com;
third-party Providers that you or your Employer connect to paddl.com through a Connection — this occurs only in accordance with your Employer’s configuration, and we are not responsible for that Provider's own use of the information it receives;
our professional advisers, regulators and law enforcement agencies, where required or permitted by law; and
a person who acquires all or part of our business or assets.
We do not sell your personal information.
8. Overseas disclosure
Client Data is primarily hosted and processed in Australia. Where we or a Sub-processor store or process personal information outside Australia, we take reasonable steps to ensure the overseas recipient handles it consistently with the Privacy Act and, where the GDPR or UK GDPR applies, using the European Commission's Standard Contractual Clauses, the UK Information Commissioner's International Data Transfer Addendum, or another lawful transfer mechanism, as described in our DPA.
9. Direct marketing
We may send you information about our services, product updates and offers that we think may be relevant to you. You can opt out of these communications at any time via the unsubscribe link in the relevant email, through your Account, or by contacting help@paddl.com. You will continue to receive transactional communications that are required for us to provide the Services, such as billing notices and product usage notifications.
10. Security
We maintain an information security program, having regard to recognised industry frameworks, designed to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Further detail on our security measures and current certification status is published at trust.paddl.com. When personal information is no longer needed for the purposes described in this policy, and we are not required by law to retain it, we take reasonable steps to destroy it or ensure it is de-identified.
11. Data retention
We retain personal information only for as long as necessary for the purposes described in this policy, or as required by law. Client Data is generally retained for the Term of our Agreement with that Client, and deleted or de-identified from our production systems within 30 days of the end of the 30-day period in which the Client may extract its data, and from our database provider's backups when that provider's backup retention period expires, in each case as described in our DPA. Retained Profile information is kept for as long as necessary for the purposes described above, or until you ask us to delete it.
12. Access and correction
You may ask us to access or correct the personal information we hold about you by writing to privacy@paddl.com. We will respond within 30 days and, subject to any applicable exemptions, will provide access or make the requested correction. If we refuse a request, we will notify you in writing, including our reasons and how you can complain about our decision. Where your information forms part of Client Data still governed by an Agreement, we may direct your request to your Employer, who is responsible for responding to it, and we will help them do so. Where the GDPR or UK GDPR applies to personal information we handle as a controller, you also have the right to request erasure of your personal information, to ask us to restrict how we process it, to object to processing we carry out on the basis of our legitimate interests, to receive a copy of the information you have provided to us in a portable format, and to withdraw any consent you have given, at any time. You can exercise any of these rights by writing to privacy@paddl.com, and we will not charge you or treat you differently for doing so. For the purposes of the GDPR and UK GDPR, Paddl Co. Pty Ltd is the controller of the personal information described in this Privacy Policy.
13. Cookies
Our website and paddl.com use cookies and similar technologies — small files stored on your device that let us recognise your browser and remember information about your visit. We use cookies for functionality (such as keeping you signed in), analytics, and, where you consent, marketing purposes. You can control or disable cookies through your browser settings, though this may affect how our website and paddl.com function.
14. Children
paddl.com is intended for use by Members who are employees, workers or contractors of our Clients. Some Members are under 18. Where that is the case, we handle their personal information on the same basis as any other Member, and rely on their Employer to have obtained any consent required from a parent or guardian.
15. Making a complaint
If you have a concern about how we have handled your personal information, or believe we have breached the Australian Privacy Principles, contact us at privacy@paddl.com with details of your complaint. We aim to respond within 30 days.
If you are not satisfied with our response, you may complain to a privacy regulator. In Australia that is the Office of the Australian Information Commissioner. If you are in the European Economic Area or the United Kingdom, you may instead complain to the supervisory authority in your country, or to the UK Information Commissioner's Office. The OAIC can be contacted at:
GPO Box 5218, Sydney NSW 2001
Email: enquiries@oaic.gov.au
Phone: 1300 363 992
16. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always available at paddl.com/privacy-policy, and we will update the date below when we do.
17. Contact us
Paddl Co. Pty Ltd, Level 2, 65 Dover Street, Cremorne VIC 3121.
help@paddl.com
Last updated: 2nd September 2026