Privacy Policy

Organization: Play Loud Music Academy

Document Number: PLMA-POL-007-V2

Effective Date: 21 May 2026

Compliance Framework: Privacy Act 1988 (Cth); Australian Privacy Principles (APPs); Child

Safe Organisations Act 2024 (QLD).

1. Objective & Scope

Play Loud Music Academy ("the Academy") is committed to protecting the privacy and personal

information of our students, parents, guardians, and staff. As a third-party service provider

operating within school premises and care facilities, the Academy collects and holds sensitive

information, including records relating to minors. This policy outlines how we collect, use,

disclose, store, and secure your personal information in accordance with the Privacy Act 1988

(Cth) and the Australian Privacy Principles (APPs).

2. Types of Information We Collect

The Academy collects personal and sensitive information necessary to deliver music tuition

safely and manage business operations. This includes:

● Student Information: Full name, date of birth, year level, school/facility attended, musical

proficiency, internal pedagogical recordings, and attendance logs.

● Parent/Guardian Information: Full name, relationship to student, residential address,

email address, and telephone contact details.

● Billing & Financial Data: Credit/debit card details, transaction history, and billing tokens

managed securely via our third-party payment processor (Stripe).

● Sensitive & Compliance Records: Incident and disclosure reports, medical/health alerts

relevant to student safety during lessons, Working with Children Checks (Blue Cards),

and staff compliance training records.

3. Methods of Collection

We collect personal information directly from individuals or their authorized legal guardians

through:

● Digital enrollment forms and account registration on our designated payment and student

portals.

● Direct electronic or verbal correspondence (emails, phone calls, text messages).

● Internal documentation completed by Academy staff, such as lesson logs and Incident &

Disclosure Report Forms.

4. Use of Personal Information

The Academy uses collected data strictly for the following purposes:

● Administering and delivering music tuition and managing student scheduling.

● Processing automated monthly tuition fees and managing billing accounts via Stripe.

● Ensuring child safety, medical management, and complying with site-specific duty of care

obligations.

● Communicating operational updates, emergency notifications, and student progress

reports to parents/guardians.

● Internal staff performance tracking and training reviews.

5. Disclosure of Information & Dual-Reporting

Mandates

The Academy does not sell, rent, or trade personal information to third parties. Information is

only disclosed under the following strictly defined conditions:

Recipient Entity Scope & Purpose of Disclosure

Host Facility Administration Student names, schedules, and urgent

safety/medical details are shared with school

administration/principals to coordinate on-site

operations and emergency fire rolls.

Statutory & Legal Authorities In accordance with QLD legislation (including

the Reportable Conduct Scheme), serious

behavioral incidents, child safety disclosures,

or suspicions of significant harm will be legally

reported to the Queensland Police Service,

Child Safety Services, or the Queensland

Family and Child Commission (QFCC).

Payment Gateways (Stripe) Encrypted financial data is securely

transmitted directly to Stripe to process

recurring direct debits. The Academy does not

store raw credit card numbers on its internal

servers.

6. Data Security and Storage Protocols

The Academy implements robust administrative and digital security measures to safeguard

information against unauthorized access, loss, or misuse:

● Digital Storage: All student files, contact details, and logs are housed in secure cloud

environments featuring multi-factor authentication (MFA) and restricted user permissions.

● Restricted Folders: Sensitive data, such as completed Incident & Disclosure Reports,

are stored in standalone, password-protected directories accessible exclusively by the

Academy Director.

● Physical Material: Any hardcopy documentation (e.g., printed arrival manifests or

hand-written emergency notes) must remain under direct staff supervision while on-site

and be securely shredded or transferred to digital storage immediately thereafter.

7. Two-Tiered Media Consent Framework

To respect family privacy preferences while preserving the operational tools required for

high-quality music education, the Academy enforces a strict two-tiered media consent model:

1. Internal Educational Use (Mandatory): By enrolling in the Academy, parents/guardians

grant absolute permission for staff to record audio and video of the student during

lessons. This is a non-negotiable condition of enrollment used strictly for internal

pedagogical analysis (e.g., posture correction, sound quality review, and technical

assessments). These recordings are confidential, handled with high security, and are

never shared publicly or externally.

2. Promotional Marketing Use (Optional / Opt-In): The use of a student's photograph,

video footage, or likeness for external marketing purposes—including the Academy’s

official social media channels, website, brochures, posters, and flyers—is entirely

optional. This material will only be used if the parent/guardian proactively ticks the

promotional consent section on the enrollment form. This consent can be withdrawn in

writing at any time with 14 days' notice.

8. Access, Correction, and Contact Details

Under the APPs, individuals have the right to request access to the personal information the

Academy holds about them, or to request corrections to inaccurate data. To make an inquiry,

lodge a privacy complaint, or request a data update, please contact the Director:

Email: chris@playloudmusicacademy.com

Phone: 0411 359 671