Privacy Policy

Last updated: June 2026

Entity: PathIQ Pty Ltd ("PathIQ", "we", "us", "our")

ABN: 91 696 353 152

1. Introduction

PathIQ provides a web-based software-as-a-service application: a career-exploration platform that helps students discover suitable careers through a career-fit quiz, interactive job simulations, and related degree recommendations, offered directly to individuals and through schools and universities. This policy explains what personal information we collect, how we use and protect it, and the choices you have. We are committed to handling personal information in accordance with the Australian Privacy Principles (APPs).

This policy applies to information we collect from users of our application and from the customers (organisations) who licence PathIQ.

2. What personal information we collect

We collect only the information needed to provide the service. This typically includes:

  • Account information: name and email address.
  • Authentication data: credentials (passwords are stored only as salted hashes) and multi-factor authentication (TOTP) enrolment data.
  • Profile information, where provided: your institution, year level, cohort, current status (e.g. student), date of birth, and country/state. For counsellor and staff users this may also include a display name, biography, profile photo, and booking preferences.
  • Assessment and activity data: your responses to the career quiz and job simulations (including free-text answers you submit), the scores and results generated from them, and activity within the application used for the operation, security, and support of the service.
  • Billing reference: a Stripe customer identifier where applicable.

We do not store payment card numbers. Payments are processed by Stripe, which handles card data directly (see Section 6).

We do not knowingly collect sensitive information (as defined in the Privacy Act) and do not handle health information / PHI.

3. How we collect it

We collect personal information directly from you when you create or use an account, and from the customer organisation that provisions your access. We may also collect technical data (such as IP address and log data) automatically when you use the service, for security and operational purposes.

4. Why we collect and use it

We use personal information to:

  • provide, operate, and maintain the application;
  • authenticate users and secure accounts;
  • provide customer support;
  • detect, investigate, and respond to security incidents;
  • comply with our legal obligations.

We do not sell personal information, and we do not use customer or end-user content for advertising.

5. How we store and protect it

  • Data residency: Customer and personal data at rest is stored in MongoDB Atlas hosted on Amazon Web Services in the Asia Pacific (Sydney) region, within Australia. Uploaded files (documents) are stored in Google Cloud Storage in the Melbourne (australia-southeast2) region, within Australia. Application processing runs on Google Cloud Run in the Melbourne (australia-southeast2) region, within Australia.
  • Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Isolation: Each customer organisation's data is stored in a dedicated, isolated database.
  • Access controls: Access is restricted on a least-privilege basis. Multi-factor authentication is available to all accounts and required by default, and customer organisations can make it mandatory for their users. Administrative and security-relevant events are recorded in an audit log.

Further detail is available in our Security Policy, which can be provided on request.

6. Disclosure to third parties (sub-processors)

We use a small number of trusted service providers ("sub-processors") to deliver the service. Each is bound by contractual confidentiality and data-protection obligations:

Sub-processorPurposeData location
MongoDB Atlas (on AWS)Database hostingAustralia (Sydney)
Google Cloud (Cloud Run)Application computeAustralia (Melbourne)
Google Cloud StorageUploaded document/file storageAustralia (Melbourne)
NetlifyFrontend hosting (static assets only)Global CDN
StripePayment processing (card data only)United States / global
AnthropicAI/LLM processing of submitted contentUnited States

We do not disclose personal information to any other parties except where required by law.

7. Overseas disclosure

Some sub-processors process data outside Australia (see Section 6). In particular:

  • Stripe processes payment data overseas. PathIQ does not store or transmit card numbers; these are provided by you directly to Stripe.
  • Anthropic provides our AI evaluation and content-generation features and processes the submitted content in the United States. We send only the content the feature needs to function: a user's free-text simulation responses together with the related task, scenario, and rubric text, and (for staff content tools) job titles. We do not send account identifiers such as your name, email address, or user ID to Anthropic. We do not ask users to include personal information in free-text responses, although a user could choose to enter it. Under Anthropic's commercial terms, content submitted through its API is not used to train its models.

Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, and we remain accountable for that information under APP 8.

8. Data retention

We retain personal information only as long as needed to provide the service and meet legal obligations. In general: account and profile information, and your quiz and simulation results, are retained for the life of your account; security audit logs are retained for 90 days; and on termination of an account or customer contract, personal data is deleted or returned within 30 days, unless we are required to retain it by law.

9. Access, correction, and complaints

You may request access to, or correction of, the personal information we hold about you by contacting us (Section 11). We will respond within a reasonable period.

If you believe we have breached the APPs, you can complain to us and we will investigate. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Changes to this policy

We may update this policy from time to time. The current version is always available on this page. Material changes will be notified to customers.

11. Contact us

Calum Batey

Email: cal@pathiq.com.au