PART A: TERMS OF SERVICE
These Terms of Service (“Agreement”) are between CPDcheck Pty Ltd (ABN 39 691 680 476) (“CPDcheck”, “we”, “us”, “our”) and the entity that registers for, or uses, the Platform (“Client”, “you”, “your”). If you register for or on behalf of an entity, you represent and warrant that you have authority to bind that entity.
Background
A. CPDcheck Pty Ltd provides software and services to the Australian financial advice industry.
B. CPDcheck Pty Ltd operates the Platform, a cloud platform that uses artificial intelligence to assess content supplied by Clients against continuing professional development (“CPD”) criteria, allocate CPD hours and areas, generate learning outcomes and assessment questions, issue CPD certificates, and help Australian financial services licensees manage the CPD activities of their advisers.
C. The Platform is used by two kinds of Client: Licensees, who manage the CPD of their advisers, and Providers, who supply CPD content. Both upload content to the Platform. The content belongs to the Client that uploads it, and this Agreement sets out the limited rights CPDcheck needs to provide the service.
1. Definitions and interpretation
1.1 In this Agreement, unless the context requires otherwise:
- “Affiliate”
- means, in relation to an entity, a Related Body Corporate of that entity or an entity that Controls, is Controlled by, or is under common Control with it.
- “AI Services”
- means the machine learning and generative artificial intelligence models and services used by the Platform to analyse Client Content and generate Output, including services provided by Sub-processors.
- “Australian Consumer Law”
- means Schedule 2 to the Competition and Consumer Act 2010 (Cth).
- “Business Day”
- means a day that is not a Saturday, Sunday or public holiday in New South Wales.
- “Claim”
- includes any claim, notice, demand, action, proceeding, litigation, investigation or judgment, however arising.
- “Client Content”
- means all documents, files, recordings, transcripts, notes, presentations, URLs, text, course materials, learning content, images, data and other material that the Client or its Users upload to, enter into, link to or otherwise supply to the Platform, including any Personal Information contained in that material.
- “Client Data”
- means Client Content, Output, User account information and other data that the Client or its Users supply to the Platform or that CPDcheck collects or generates in connection with the Client’s use of the Platform, other than Statistical Data.
- “Commencement Date”
- means the date the Client first registers for the Platform or, where there is an Order Form, the date stated in it.
- “Confidential Information”
- of a party means information disclosed by or on behalf of that party that is marked confidential or that a reasonable person would understand to be confidential, and includes Client Data in the case of the Client and the non-public features, pricing and technology of the Platform in the case of CPDcheck, but excludes information that is or becomes public other than through breach of this Agreement, was lawfully known to the recipient before disclosure, or is independently developed without use of the discloser’s information.
- “Control”
- has the meaning given in section 50AA of the Corporations Act 2001 (Cth).
- “CPD”
- means continuing professional development, and where the context requires, the CPD obligations applying to relevant providers under the Corporations Act 2001 (Cth) and the Corporations (Relevant Providers-Education and Training Standards) Determination 2021 (Cth), as amended or replaced.
- “CPDcheck”
- means CPDcheck Pty Ltd.
- “Platform”
- means the CPDcheck cloud platform made available by CPDcheck, including its web applications, application programming interfaces, documentation and any updates, upgrades and replacement versions made available by CPDcheck from time to time.
- “Eligible Data Breach”
- has the meaning given in section 26WE of the Privacy Act.
- “Fees”
- means the fees for the Plan selected by the Client at registration, in an Order Form, or as otherwise agreed in writing, as varied under clause 5.
- “Insolvency Event”
- means, for a person, becoming insolvent, being wound up or made bankrupt, having a liquidator, administrator, receiver, controller or trustee appointed over it or any of its assets, entering any arrangement with creditors, or any similar event under any law, other than as part of a solvent reconstruction approved in writing by the other party.
- “Intellectual Property Rights”
- means all intellectual property rights of any kind anywhere in the world, whether registered or not, including copyright, patents, trade marks, designs, trade secrets and the right to keep information confidential.
- “Licensee”
- means a Client that holds an Australian financial services licence or is an authorised representative of one and uses the Platform to manage the CPD of its Users.
- “Loss”
- means any loss, liability, damage, cost, charge or expense, including reasonable legal costs.
- “Order Form”
- means the order form, quote or proposal for the Platform signed by both parties that incorporates this Agreement.
- “Output”
- means the assessments, CPD hour and area allocations, criteria evaluations, learning outcomes, summaries, quiz and assessment questions, certificates, reports and other material generated by the Platform from or in relation to Client Content, in the form delivered to the Client.
- “Personal Information”
- has the meaning given in the Privacy Act.
- “Plan”
- means the Platform subscription plan, user count and features selected by the Client.
- “Privacy Act”
- means the Privacy Act 1988 (Cth), including the Australian Privacy Principles.
- “Privacy Law”
- means the Privacy Act and any other law that applies to the handling of Personal Information by a party.
- “Privacy Policy”
- means Part B of this document, as updated from time to time under clause 18.
- “Provider”
- means a Client that supplies CPD learning content to the Platform for assessment, publication or distribution to Licensees and Users.
- “Provider Content”
- means Client Content supplied by a Provider that the Provider elects to publish or distribute through the Platform.
- “Quiz Participant”
- means a person who completes a quiz, assessment or activity published through the Platform, whether or not they hold a Platform account.
- “Related Body Corporate”
- has the meaning given in section 9 of the Corporations Act 2001 (Cth).
- “Statistical Data”
- means data derived from the use of the Platform that has been aggregated and de-identified so that it does not identify, and could not reasonably be used to identify, the Client, any User, any Quiz Participant or any other individual, and does not include the substance of any Client Content or Output.
- “Sub-processor”
- means a third party engaged by CPDcheck to host, store, process or transmit Client Data on CPDcheck’s behalf, as listed in the Privacy Policy.
- “Super Admin”
- means the User designated by the Client to manage the Client’s Platform account, including User access levels.
- “Term”
- has the meaning given in clause 15.1.
- “Adviser Record”
- means the CPD record maintained for an individual adviser under clause 4.6 and Part C.
- “User”
- means an individual the Client authorises to access the Platform under the Client’s account, including the Client’s employees, contractors, authorised representatives and advisers.
1.2 In this Agreement: the singular includes the plural and vice versa; “including” and similar words are not words of limitation; headings do not affect interpretation; a reference to legislation includes its amendments, replacements and subordinate instruments; a reference to a party includes its successors and permitted assigns; and no rule of construction applies to the disadvantage of a party because it prepared this Agreement.
1.3 If this Agreement is inconsistent with an Order Form, the Order Form prevails for that Client to the extent of the inconsistency. If there is any inconsistency between this Agreement and the Privacy Policy in relation to the handling of Personal Information, the Privacy Policy prevails to the extent of the inconsistency.
2. Access to the Platform
2.1 Subject to this Agreement and payment of the Fees, CPDcheck grants the Client a non-exclusive, non-transferable right for the Term to access and use the Platform, and to permit its Users to do so, for the Client’s internal business purposes of assessing, recording, managing and delivering CPD (“Purpose”).
2.2 The Client is responsible for its Users and for all activity under its account. The Client must ensure that each User complies with this Agreement, and a breach by a User is treated as a breach by the Client. The Client must keep account credentials secure, use any multi-factor authentication CPDcheck makes available, and notify CPDcheck promptly of any unauthorised access.
2.3 The Super Admin controls which Users can access which Client Data and Output within the Client’s account. CPDcheck acts on the Super Admin’s configuration and is not responsible for access that the Super Admin has granted.
2.4 Sub-entities. A Client may add Affiliates, practices or other entities it is responsible for (“Sub-entities”) to its account where the Plan allows. The Client is responsible for each Sub-entity and its Users as if they were the Client’s own, warrants it has authority to bind each Sub-entity, and must configure access so that each Sub-entity’s Client Data is visible only to the Users the Client intends. CPDcheck may treat instructions from the Super Admin as instructions on behalf of every Sub-entity.
2.5 CPDcheck may provide User-level terms that individual Users must accept on first login. Those terms do not reduce the Client’s obligations under this Agreement.
3. Acceptable use
3.1 The Client must not, and must ensure its Users do not:
- use the Platform other than for the Purpose or in breach of any law, regulation, industry code or third-party right;
- upload Client Content that the Client does not have the right to upload, that is unlawful, defamatory or infringing, or that contains malicious code;
- copy, modify, adapt, translate, reverse engineer, decompile or attempt to extract the source code, prompts, models or assessment methodology of the Platform;
- use the Platform, Output or Statistical Data to build, train or improve a product or service that competes with the Platform;
- resell, sublicense or provide access to the Platform to anyone other than Users, except that a Provider may distribute Provider Content and quizzes to Quiz Participants as the Platform is designed to allow;
- use automated means to access the Platform other than through interfaces CPDcheck publishes for that purpose, or interfere with the security or operation of the Platform;
- misrepresent Output as having been reviewed or approved by CPDcheck, or hold CPDcheck out as having approved any CPD activity.
3.2 CPDcheck may suspend access to the Platform, or to specific Client Content, where it reasonably believes there is a material breach of this Agreement, a security risk, or a legal requirement to do so. CPDcheck will give notice as soon as practicable, limit the suspension to what is reasonably necessary, and lift it when the issue is resolved.
4. The service, availability and support
4.1 CPDcheck will provide the Platform with reasonable care and skill and will target availability of 99.5% in each calendar month, measured at the Platform’s public endpoints and excluding planned maintenance (for which CPDcheck will give reasonable notice where practicable), emergency maintenance, and events outside CPDcheck’s reasonable control. The target is a service objective. Failure to meet it in a month is not a breach of this Agreement and does not give rise to credits or refunds, but persistent failure over three consecutive months is a material breach for the purposes of clause 15.3.
4.2 CPDcheck depends on third-party hosting, email, AI and analytics services. CPDcheck selects those providers with reasonable care and remains responsible to the Client for the Sub-processors it uses to process Client Data, but is not liable for outages or defects in third-party services outside its control beyond the remedies in clause 13.
4.3 CPDcheck provides support during business hours on Business Days. CPDcheck may change features of the Platform from time to time provided it does not materially reduce the core functionality of the Plan during a paid period without the notice required by clause 18.
4.4 Quiz Participants. A Client that publishes a quiz or activity to Quiz Participants is responsible for the content of that quiz and for its own relationship with those participants. Quiz Participants who do not hold an account use the Platform as guests and are subject to the Privacy Policy and to the guest terms displayed to them. The Client must not require Quiz Participants to provide more Personal Information than is needed to record completion. A guest who uploads content for assessment without an account owns that content and the resulting Output on the same terms as clause 8, receives the same no-training commitment in clause 8.5, and acknowledges that guest content and Output are deleted 7 days after upload unless claimed into an account.
4.5 Certificate recipients. Where a Client uses the Platform to issue CPD certificates to advisers or other individuals (“Recipients”), CPDcheck sends those certificates on the Client’s behalf and on the Client’s instruction, as the Client’s service provider. Recipients are the Client’s customers or personnel, not CPDcheck’s. The Client warrants that each Recipient has agreed to receive, or reasonably expects to receive, the certificate and any related transactional message from the Client, and that supplying the Recipient’s name and email address to CPDcheck for that purpose complies with Privacy Law. CPDcheck will use Recipient contact details supplied by a Client only to deliver certificates and related transactional messages on the Client’s behalf, to link the certificate to the Recipient’s CPD record under clause 4.6, and to respond to the Recipient. CPDcheck will not use those contact details to create an account, to send marketing, or for any other purpose, and will not disclose them to any other Client. Certificate emails are sent from a cpdcheck.com address and identify the Client as the party on whose behalf they are sent. The Client authorises CPDcheck to send them as the Client’s authorised sender for the purposes of the Spam Act 2003 (Cth), and is responsible for the accuracy of the Recipient details it supplies.
4.6 Adviser CPD records. Independently of any Client, CPDcheck maintains a CPD record for each relevant provider listed on the ASIC Financial Advisers Register, created from the public register data (name, adviser number, licensee and authorisation details) under the terms on which ASIC publishes that register, so that advisers can hold their CPD results from across the industry in one place. Certificates issued through the Platform are stored against the matching record so that the Recipient can access and download them if they choose to claim that record. A record is not created from, and its existence does not depend on, any contact details a Client supplies. The Client acknowledges that Recipients may access their own certificates in this way, that CPDcheck provides this to Recipients free of charge, and that this does not give CPDcheck any right to market to Recipients beyond delivering certificates and, if a Recipient claims their record, communications the Recipient has agreed to receive.
4.7 Users who leave the Client. When a User ceases to be authorised by or employed by the Client, the Client must remove that User’s access promptly. The Client retains access to the CPD records and Output created for that User during the period of authorisation, for the Client’s own record-keeping obligations. The User retains access to their own certificates and CPD results through their adviser CPD record under clause 4.6. Neither party’s retained access gives it any right to the other’s later data.
4.8 Certificates are final. Once a certificate has been issued to a Recipient it cannot be deleted or altered by the Client or by CPDcheck. If a certificate was issued in error or contains a mistake, the Client may issue a superseding certificate or ask CPDcheck to attach a correction note, and the Recipient will be told. The original remains in the Recipient’s Adviser Record with the note attached. This clause does not limit an individual’s rights under Australian Privacy Principle 13 to have inaccurate Personal Information corrected.
4.9 New features. CPDcheck may add features to the Platform from time to time. Every new feature is governed by this Agreement, including the Client’s ownership of Client Content and Output, the no-training commitment and clause 10. Where a new feature processes recordings or transcripts of meetings or conversations involving people other than the Client’s Users, the Client must, before using it, ensure those people were told that the recording would be made and analysed. CPDcheck will update the Privacy Policy before any new feature that processes Personal Information for a new purpose goes live, and the Client may choose not to enable any optional feature.
5. Fees and payment
5.1 The Order Form, or the Plan selected by the Client at registration, states whether the Client is billed on a subscription basis or a consumption basis, or both. Subscription Fees are payable monthly in advance. Consumption Fees are metered on the Client’s use of the Platform (for example per assessment, per certificate or per active User, as stated in the Order Form) and invoiced monthly in arrears, payable within 14 days of invoice. Fees are stated in Australian dollars and exclude GST unless stated otherwise.
5.2 CPDcheck will make usage records available to the Client through the Platform. The Client must raise any dispute about an invoice within 14 days of its date, giving reasons, and pay the undisputed portion. The parties will resolve invoice disputes in good faith and, failing that, under clause 17.
5.3 CPDcheck may change the Fees by giving at least 30 days written notice. A change takes effect from the first calendar month after the notice period ends. If the Client does not accept the change it may terminate under clause 15.3 before the change takes effect.
5.4 If Fees are unpaid 14 days after the due date, CPDcheck may give notice and, if the Fees remain unpaid 14 days after that notice, suspend access until payment is made. CPDcheck may charge reasonable costs of recovery for amounts that remain unpaid after suspension.
5.5 Refunds. Fees are not refundable except where this Agreement says otherwise. If CPDcheck terminates for convenience under clause 15.4, or the Client terminates for CPDcheck’s uncured breach under clause 15.3, CPDcheck will refund any Fees paid for the period after termination. Nothing in this clause limits the Client’s rights under the Australian Consumer Law.
5.6 GST. Amounts payable under this Agreement are exclusive of GST. If GST is payable on a supply under this Agreement, the recipient must pay the GST amount in addition, subject to receiving a valid tax invoice. Terms used in this clause have the meaning given in the A New Tax System (Goods and Services Tax) Act 1999 (Cth).
5.7 Trials. CPDcheck may offer a time-limited free trial. During a trial: clauses 6 to 11 apply in full, including the Client’s ownership of Client Content and Output and the no-training commitment; CPDcheck provides the Platform without any service commitment under clause 4.1 or warranty under clause 12.2; CPDcheck’s total liability is limited to AUD $1,000; and unless the Client converts to a paid Plan, Client Data is deleted 30 days after the trial ends without the export window in clause 16.2, although the Client may export it during the trial and for those 30 days.
6. AI-generated Output and the Client’s responsibility for CPD decisions
6.1 The Platform uses AI Services to analyse Client Content and produce Output. The Client acknowledges that:
- AI Services are probabilistic. Output may contain errors, omissions or inaccurate CPD allocations, and may differ between runs on the same content;
- Output is generated to assist the Client and is not a substitute for the Client’s own review. The Client must review Output before relying on it or issuing it to Users or Quiz Participants;
- CPDcheck does not provide financial product advice, legal advice, or compliance advice. The Client is solely responsible for determining whether an activity qualifies as CPD, how many hours it represents and which CPD area it falls under, having regard to its CPD policy and applicable law. Output is provided as an input to that determination and does not constitute CPD approval, certification or compliance advice from CPDcheck;
- CPDcheck does not warrant that Output, certificates or records produced by the Platform will be accepted by any regulator, professional association, licensee or auditor;
- The Platform may apply automated redaction to transcripts and documents to reduce Personal Information. Redaction is a best-efforts tool and does not guarantee that all Personal Information is removed. The Client remains responsible for the Personal Information it uploads.
6.2 CPDcheck will disclose in the Privacy Policy the kinds of decisions the Platform makes or assists using automated processing and the kinds of Personal Information used.
7. Client Content: the Client’s obligations
7.1 The Client warrants, for all Client Content, that:
- it owns, or holds all licences and consents needed to upload, the Client Content and to grant the licence in clause 8.3;
- the Client Content and its use through the Platform do not infringe any Intellectual Property Rights, confidentiality obligation or other right of any person and do not breach any law;
- any Personal Information in the Client Content was collected in accordance with Privacy Law, and the individuals concerned have been notified, in accordance with Australian Privacy Principle 5, that their information may be disclosed to service providers such as CPDcheck for CPD assessment purposes;
- the Client has limited the Personal Information in the Client Content to what is reasonably necessary for the Purpose, and where the Client Content includes records of an adviser’s own clients (such as advice documents, file notes or meeting recordings), the Client has considered whether that information should be de-identified before upload;
- the Client Content does not contain sensitive information (as defined in the Privacy Act) unless the Client has obtained the consent of the individual concerned or is otherwise permitted by law to disclose it.
7.2 The Client is responsible for maintaining its own copies of Client Content. The Platform is not a system of record or an archive, and the Client should export Output and records it must retain under law.
7.3 CPDcheck may remove or disable access to Client Content that it reasonably believes breaches clause 3 or 7, and will notify the Client where it does so unless prevented by law.
8. Ownership of Client Content and Output, and licence to CPDcheck
8.1 Client Content. As between the parties, the Client owns all right, title and interest, including all Intellectual Property Rights, in the Client Content. Nothing in this Agreement transfers ownership of any Client Content to CPDcheck.
8.2 Output. As between the parties, the Client owns all right, title and interest, including all Intellectual Property Rights, in the Output generated from its Client Content. To the extent any Intellectual Property Rights in Output vest in CPDcheck on creation, CPDcheck assigns them to the Client on creation, and this clause operates as a present assignment of future rights. The Client’s ownership of Output does not extend to the CPDcheck Materials referred to in clause 8.4, even where they are embedded in or used to generate Output.
8.3 Licence to CPDcheck. The Client grants CPDcheck and its Sub-processors a non-exclusive, worldwide, royalty-free licence during the Term to host, store, copy, transmit, process, analyse, modify (for example to convert formats or apply redaction), display and create derivative works of the Client Content and Output solely to the extent necessary to provide, secure, support and improve the operation of the Platform for the Client and to comply with law. The licence continues after the Term only as needed to retain data under clause 16 and the Privacy Policy.
8.4 CPDcheck Materials. CPDcheck and its licensors own all right, title and interest in the Platform, its software, interfaces, prompts, models, assessment criteria and methodology, question banks and content authored by CPDcheck, documentation, trade marks, and all improvements to them (“CPDcheck Materials”), together with Statistical Data. Nothing in this Agreement transfers any CPDcheck Materials to the Client. The Client receives only the rights expressly granted in this Agreement.
8.5 No training on Client Data. CPDcheck will not use Client Content or Output to train, fine-tune, retrain or otherwise improve any machine learning or AI model, whether its own or a third party’s, and will not permit any Sub-processor to do so. CPDcheck uses AI Services under terms that prohibit the provider using Client Data for training.
8.6 Statistical Data. CPDcheck may create and use Statistical Data during and after the Term to operate, secure, benchmark and improve the Platform and to report on industry CPD trends, provided Statistical Data never identifies the Client, any User, any Quiz Participant or any individual, and never discloses the substance of any Client Content or Output.
8.7 Feedback. If the Client gives CPDcheck suggestions about the Platform, CPDcheck may use them without restriction or payment, provided it does not identify the Client without consent.
9. Provider Content
9.1 A Provider retains ownership of Provider Content. In addition to the licence in clause 8.3, a Provider that elects to publish Provider Content through the Platform grants CPDcheck a non-exclusive licence for the period of publication to display, distribute, stream and make Provider Content available to Licensees, Users and Quiz Participants through the Platform, and to display the Provider’s name, logo and descriptions in the Platform catalogue in connection with that content.
9.2 The Provider may withdraw Provider Content from publication at any time through the Platform. Withdrawal does not affect certificates already issued, CPD records already created for Users, or copies CPDcheck must retain under clause 16.
9.3 The Provider is responsible for the accuracy, currency and legality of Provider Content and for any claims about its CPD value made to Licensees and Users. CPDcheck does not accredit or endorse Provider Content, and any CPD allocation shown for it is Output subject to clause 6.
9.4 Provider fees, revenue share or billing arrangements, if any, are as set out in the Provider’s Plan or Order Form.
9.5 Complaints about Provider Content. If CPDcheck receives a complaint that it reasonably considers credible that Provider Content infringes a third party’s rights, is unlawful, or materially misstates its CPD value, CPDcheck may suspend the content from publication immediately and will notify the Provider the same Business Day with the substance of the complaint. The Provider has 5 Business Days to respond with evidence of its rights or a correction. If the response resolves the complaint to CPDcheck’s reasonable satisfaction, CPDcheck will restore the content. If it does not, or no response is received, CPDcheck may remove the content permanently. Suspension under this clause is not a breach by CPDcheck and does not entitle the Provider to a refund. The Provider remains responsible for the dispute with the complainant and indemnifies CPDcheck under clause 14.1.
10. Data protection and security
10.1 Roles. For Personal Information in Client Data, the Client is the entity that collected it and decides why it is processed, and CPDcheck processes it as a service provider to the Client. Each party must comply with Privacy Law in relation to Personal Information it handles under this Agreement.
10.2 CPDcheck’s obligations. CPDcheck will:
- use and disclose Personal Information in Client Data only to provide, secure and support the Platform, as instructed by the Client through its use of the Platform, as permitted by this Agreement and the Privacy Policy, or as required by law;
- implement and maintain technical and organisational security measures appropriate to the nature of Client Data, including encryption in transit and at rest, access controls, logging, and regular review of those measures;
- ensure that its personnel who access Client Data are bound by confidentiality obligations and access it only as needed;
- host and process Client Data only in data centres located in Australia, and not transfer Client Data outside Australia except under clause 10.6;
- engage Sub-processors only under written terms that protect Client Data to a standard no less protective than this clause 10, list current Sub-processors in the Privacy Policy, and change them only under clause 10.6;
- notify the Client without undue delay, and in any event within 72 hours, after confirming an Eligible Data Breach or any other unauthorised access to Client Data, give the Client the information reasonably needed to assess the breach and meet its own obligations under the Privacy Act, and cooperate with the Client in responding to it. Where the breach affects individuals to whom the Client owes notification obligations, the parties will agree who notifies, and CPDcheck will not notify those individuals or the Office of the Australian Information Commissioner about the Client’s data without consulting the Client first, unless the law requires it to;
- assist the Client, at reasonable cost, to respond to requests from individuals to access or correct their Personal Information held in the Platform, where the Client cannot do so itself through the Platform;
- on request not more than once each year, provide the Client with a summary of CPDcheck’s security measures and any independent security assessment CPDcheck has obtained.
10.3 Client’s obligations. The Client will comply with clause 7.1(c) to (e), configure User access appropriately, and notify CPDcheck promptly if it becomes aware of any unauthorised access to its account or any breach affecting Client Data.
10.4 Retention and deletion. CPDcheck retains Client Data for the Term and the period set out in clause 16, and retains security logs, guest sessions and audit records for the periods stated in the Privacy Policy. The Client may delete Client Content and Output through the Platform at any time, subject to CPDcheck’s backup cycle described in clause 16.4.
10.5 Law enforcement and legal requests. If CPDcheck receives a subpoena, notice or request from a regulator, court or law enforcement body for Client Data, it will, unless prohibited by law, notify the Client promptly and disclose only what the law requires.
10.6 Sub-processor and infrastructure changes. CPDcheck may change the infrastructure, hosting, AI Services and Sub-processors it uses to provide the Platform. For any change that affects where or by whom Client Data is hosted, stored or processed (“Material Change”):
- before implementing the Material Change, CPDcheck will complete a written Change Impact Assessment covering the security controls, privacy impact, data location, business continuity and contractual protections of the new arrangement, and will proceed only if the assessment concludes that Client Data will be protected to a standard at least equivalent to the standard before the change;
- CPDcheck will give the Client at least 30 days written notice before the Material Change takes effect, identifying the new Sub-processor or infrastructure, the location of Client Data after the change, and any change to this clause 10 or the Privacy Policy;
- on request, CPDcheck will provide the Client with a summary of the Change Impact Assessment, and will provide the full assessment to the Client under written confidentiality terms where the Client reasonably requires it for its own compliance obligations;
- if the Material Change would move Client Data outside Australia or, in the Client’s reasonable opinion, materially lower the protection of Client Data, the Client may object by written notice within the 30 day period. If the parties cannot resolve the objection before the change takes effect, the Client may terminate this Agreement on notice and CPDcheck will refund Fees paid for the period after termination. Any other Material Change does not give rise to a termination right;
- where a change is needed urgently to respond to a security incident, a Sub-processor failure or a legal requirement, CPDcheck may implement it before the notice period ends, provided it completes the Change Impact Assessment as soon as practicable, notifies the Client as soon as practicable, and the Client’s rights under paragraph (d) apply from that notice;
- changes that do not affect where or by whom Client Data is hosted, stored or processed do not require notice, and CPDcheck will keep the Sub-processor list in the Privacy Policy current.
10.7 Insurance. CPDcheck maintains cyber liability and professional indemnity insurance with a reputable insurer and will provide a certificate of currency on request.
11. Confidentiality
11.1 Each party must keep the other party’s Confidential Information confidential, use it only to perform this Agreement, and not disclose it except to its personnel, advisers and (for CPDcheck) Sub-processors who need to know it and are bound by equivalent obligations, with the other party’s consent, or as required by law (with prior notice to the other party where lawful).
11.2 Each party is responsible for any breach of this clause by a person to whom it disclosed Confidential Information.
11.3 Each party acknowledges that damages may not be an adequate remedy for breach of this clause and that the other party may seek injunctive relief.
11.4 CPDcheck may describe the Client as a customer of the Platform in its marketing, using the Client’s name and logo, unless and until the Client asks it in writing not to. CPDcheck will not disclose the Client’s CPD results, Client Content or Output in marketing without the Client’s written consent.
12. Warranties
12.1 Each party warrants that it has the capacity and authority to enter into and perform this Agreement.
12.2 CPDcheck warrants that the Platform will be provided with reasonable care and skill and will perform materially as described in the Plan and CPDcheck’s published feature descriptions. The Client’s remedy for breach of this warranty is for CPDcheck to correct the non-conformance within a reasonable time or, if it cannot, for the Client to terminate under clause 15.3 and receive the refund in clause 5.5.
12.3 Except as stated in this Agreement and to the extent permitted by law, CPDcheck excludes all other warranties, conditions and guarantees, including any that the Platform will be uninterrupted or error-free or that Output will be accurate or fit for the Client’s regulatory purposes.
12.4 Australian Consumer Law. Nothing in this Agreement excludes, restricts or modifies any guarantee, right or remedy under the Australian Consumer Law or any other law that cannot be excluded. Where the law permits CPDcheck to limit its liability for breach of a non-excludable guarantee, CPDcheck’s liability is limited, at CPDcheck’s option, to resupplying the services or paying the cost of having the services resupplied.
13. Liability
13.1 Exclusion of consequential loss. To the extent permitted by law, neither party is liable to the other for loss of profit, revenue, business, goodwill or anticipated savings, or for indirect or consequential loss, arising out of or in connection with this Agreement.
13.2 Cap. To the extent permitted by law, each party’s total aggregate liability arising out of or in connection with this Agreement, whether in contract, tort (including negligence), statute or otherwise, is limited to the total Fees paid or payable by the Client under this Agreement in the 12 months before the event giving rise to the liability.
13.3 Carve-outs. Clauses 13.1 and 13.2 do not apply to: (a) a party’s liability for fraud, wilful misconduct or gross negligence; (b) the Client’s obligation to pay Fees; or (c) liability that cannot be limited by law.
13.4 Each party must take reasonable steps to mitigate any Loss it suffers.
14. Indemnities
14.1 By the Client. The Client indemnifies CPDcheck and its Affiliates, officers and personnel against Loss arising from any third-party Claim to the extent that the Claim arises from Client Content, or CPDcheck’s processing of Client Content in accordance with this Agreement, infringing a third party’s Intellectual Property Rights or privacy rights, or breaching applicable law, except to the extent caused by CPDcheck’s breach of this Agreement.
14.2 By CPDcheck. CPDcheck indemnifies the Client and its officers and personnel against Loss arising from any third-party Claim that the Platform or the CPDcheck Materials, used in accordance with this Agreement, infringe a third party’s Intellectual Property Rights, except to the extent the Claim arises from Client Content, the Client’s combination of the Platform with other products, or use in breach of this Agreement. If such a Claim is made, CPDcheck may procure the right for the Client to continue using the Platform, modify it to be non-infringing, or terminate this Agreement and refund prepaid Fees for the unexpired period.
14.3 The indemnified party must notify the indemnifying party promptly of a Claim, allow the indemnifying party to control the defence and settlement (provided no settlement admits fault on behalf of, or imposes obligations on, the indemnified party without its consent), and give reasonable assistance at the indemnifying party’s cost.
15. Term and termination
15.1 This Agreement starts on the Commencement Date and continues month to month until terminated under this clause (“Term”).
15.2 The Client may terminate at any time by written notice. Termination takes effect at the end of the current calendar month. No refund is payable for that month except as stated in clause 5.5, and consumption Fees incurred to the termination date remain payable.
15.3 Either party may terminate on written notice if the other party materially breaches this Agreement and does not remedy the breach within 30 days after receiving notice requiring it to do so, or if the breach cannot be remedied, or if the other party suffers an Insolvency Event. The Client may also terminate on written notice where this Agreement gives it that right in response to a change in Fees, terms, or a Material Change under clause 10.6.
15.4 CPDcheck may terminate for convenience on at least 90 days written notice, in which case it will refund Fees paid for the period after termination.
15.5 CPDcheck may terminate immediately on notice if the Client fails to pay Fees within 30 days after a notice under clause 5.4, or if continued provision of the Platform to the Client would breach law or expose CPDcheck to a security risk that the Client has not addressed within a reasonable period after notice.
15.6 Termination does not affect accrued rights. Clauses 1, 4.5, 4.6, 4.7, 4.8, 5 (in respect of accrued Fees), 6, 7, 8, 9.2, 9.3, 10, 11, 12.4, 13, 14, 16, 17, 19 and 20 survive termination.
16. Effect of termination and data return
16.1 On termination the Client’s and its Users’ access to the Platform ends, other than as set out in clause 16.2, and the Client must pay all Fees accrued to the date of termination.
16.2 Export window. For 90 days after termination CPDcheck will make Client Content and Output available for export by the Client in the formats the Platform supports, and will provide reasonable assistance on request at its then-current rates.
16.3 Deletion. Within 30 days after the export window ends, CPDcheck will delete or de-identify all Client Data in its production systems, except: (a) data CPDcheck must retain to comply with law or a regulatory obligation, which it will retain only for as long as required; (b) certificates and CPD records already issued to individual Users, which those individuals may continue to access through their own Platform accounts; (c) Statistical Data; and (d) backups, which are handled under clause 16.4. On written request CPDcheck will confirm deletion.
16.4 Backups. Client Data in backups is overwritten in the ordinary backup cycle, which is currently 90 days. CPDcheck will not restore Client Data from backups except to recover from a system failure, and clause 10 continues to apply to Client Data held in backups.
17. Dispute resolution
17.1 A party must not start court proceedings about a dispute under this Agreement, other than for urgent interlocutory relief, until it has followed this clause.
17.2 A party claiming a dispute has arisen must notify the other party in writing with details of the dispute. Senior representatives of each party must meet, in person or by video, within 14 days and try in good faith to resolve it.
17.3 If the dispute is not resolved within 21 days after the notice, either party may refer it to mediation by a mediator agreed between the parties or, failing agreement within 7 days, nominated by the President of the Law Society of New South Wales. The mediation will take place in Sydney or by video, in English, and the parties bear the mediator’s costs equally and their own costs.
17.4 If the dispute is not resolved within 30 days after the mediator is appointed, either party may end the mediation and commence proceedings.
18. Changes to this Agreement
18.1 CPDcheck may update this Agreement, including the Privacy Policy. For changes that materially reduce the Client’s rights or increase its obligations, CPDcheck will give at least 30 days notice by email to the Super Admin and by notice in the Platform before the change takes effect. If the Client does not accept a material change it may terminate under clause 15.3 with effect before the change takes effect and receive a refund of Fees paid for the period after termination.
18.2 Changes required by law, changes that add features, and changes that do not materially affect the Client may take effect on posting. Continued use after the effective date of a change is acceptance of it. CPDcheck will keep the current and previous versions of this Agreement available on request.
19. Notices
19.1 Notices under this Agreement must be in writing and sent by email. Notices to CPDcheck must be sent to clayton@cpdcheck.com. CPDcheck will send notices to the Super Admin at the email address recorded in the Platform or the address in the Order Form. This clause does not apply to service of legal process, which must be effected in accordance with law.
19.2 A notice is taken to be received on the Business Day it is sent, or on the next Business Day if sent after 5.00 pm or on a day that is not a Business Day.
20. General
20.1 Force majeure. Neither party is liable for delay or failure to perform (other than a payment obligation) caused by events beyond its reasonable control, provided it notifies the other party and uses reasonable endeavours to resume performance.
20.2 Assignment. Neither party may assign this Agreement without the other’s written consent, not to be unreasonably withheld, except that either party may assign to an Affiliate or to a purchaser of all or substantially all of its business on notice, provided the assignee assumes all obligations under this Agreement.
20.3 Relationship. The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, employment or agency relationship.
20.4 Entire agreement. This Agreement, the Privacy Policy and any Order Form are the entire agreement between the parties about its subject matter and replace all earlier agreements and representations.
20.5 Severability. If a provision is unenforceable it is severed to the extent necessary, and the rest of this Agreement continues.
20.6 Waiver. A waiver is effective only if in writing and only to the extent stated.
20.7 Electronic signature. The Order Form may be signed electronically and in counterparts, and an electronically signed copy is evidence of the Client’s agreement to this Agreement.
20.8 Governing law. This Agreement is governed by the law of New South Wales, Australia. Each party submits to the non-exclusive jurisdiction of the courts of New South Wales and the courts entitled to hear appeals from them.
PART B: PRIVACY POLICY
CPDcheck Pty Ltd (ABN 39 691 680 476) (“CPDcheck”, “we”, “us”) operates the CPDcheck platform (“Platform”). This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with the Platform, and how you can access or correct it or make a complaint. It is made under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Terms defined in Part A have the same meaning here.
This policy covers personal information about: account holders and Users of Licensee and Provider accounts; individuals whose personal information appears in content that a Client uploads (which may include a Client’s own staff and the clients of financial advisers); Quiz Participants, including guests without accounts; and visitors to the Platform websites.
1. What personal information we collect
1.1 Account and profile information: name, email address, phone number, employer or licensee, authorised representative number where provided, job title, profile picture and CPD preferences.
1.2 Client Content: documents, transcripts, recordings, notes, presentations and other material uploaded by Clients and Users. This material may contain personal information about any individual mentioned in it, including advisers, staff, and the clients of advisers. We do not control what a Client chooses to upload, and Part A requires Clients to limit personal information to what is necessary.
1.3 Output and CPD records: assessments, CPD hours and areas, learning outcomes, quiz responses and scores, certificates, and the CPD ledger for each User.
1.4 Quiz Participant information: name, email address, quiz responses and completion records. For guests without an account we also set a temporary guest session identifier.
1.5 Technical and usage information: IP address, browser type, device information, pages visited, actions taken in the Platform, login records, and error logs.
1.6 Billing information: billing contact details, plan and invoice history. Card details are processed by our payment provider Stripe and are not stored by us.
1.7 Communications: emails, support requests and feedback you send us.
1.8 Sensitive information. The only sensitive information we ordinarily hold is professional membership information, which we obtain from the ASIC Financial Advisers Register as described in section 2.5. We do not ask you to provide other sensitive information. Client Content may nevertheless contain sensitive information about individuals. Clients are responsible for having any consent needed before uploading it, and we handle it only as described in this policy.
2. How we collect it
2.1 Directly from you when you register, update your profile, upload content, take a quiz, contact us or pay for a Plan.
2.2 From your Licensee or employer, which may register you as a User, upload content relating to you, and record your CPD.
2.3 From Providers, who may publish content and quizzes that you complete.
2.4 Automatically through your use of the Platform, including through cookies and server logs described in section 9.
2.5 From public sources, including the ASIC Financial Advisers Register, to verify adviser and licensee details where a Licensee has enabled that feature.
3. Why we collect, hold, use and disclose it
3.1 To provide the Platform: create and manage accounts, process Client Content through our AI Services to produce Output, issue certificates, maintain CPD records, and give Licensees reports on the CPD of their Users.
3.2 To operate quizzes and record completion for Quiz Participants and, where the quiz was published by a Licensee or Provider, to report completion to that Client.
3.3 To communicate with you about your account, certificates, CPD alerts and deadlines, invitations, changes to the Platform and this policy, and to respond to support requests.
3.4 To bill for and administer Plans.
3.5 To secure the Platform: rate limiting, fraud and abuse prevention, investigating security incidents and enforcing Part A.
3.6 To improve the Platform using Statistical Data and usage analytics. We do not use Client Content or Output to train AI models (Part A, clause 8.5).
3.7 To comply with law, including record-keeping obligations, responding to lawful requests from regulators and courts, and the Notifiable Data Breaches scheme.
3.8 No marketing. We use email only for service messages: account and security notices, certificates and CPD alerts sent on behalf of a Client, invitations, billing, support, and changes to the Platform or this policy. We do not send marketing email to account holders, certificate recipients, Quiz Participants or individuals identified in Client Content. We comply with the Spam Act 2003 (Cth).
4. Automated processing and AI
4.1 The Platform uses artificial intelligence and automated processing to analyse Client Content and produce Output. This may include assessing whether content meets CPD criteria, estimating CPD hours and CPD areas, generating learning outcomes and generating quiz or assessment questions.
4.2 The kinds of Personal Information that may be used in this automated processing include Personal Information contained in Client Content, together with information identifying the User, adviser or presenter to whom the content relates.
4.3 The Platform’s automated processing may produce Output that is relevant to an adviser’s CPD record and may be considered by a Licensee when determining whether an activity satisfies the Licensee’s CPD requirements. CPDcheck does not make the final determination of an adviser’s CPD compliance. The Licensee is responsible for reviewing Output and deciding whether to accept it for CPD purposes.
4.4 Output is generated using probabilistic AI systems and may contain errors, omissions or inaccurate assessments. CPDcheck does not represent that Output is accurate, complete or suitable for a particular regulatory or compliance purpose.
5. Certificate recipients and adviser CPD records
5.1 If you receive a CPD certificate from a Licensee or Provider through the Platform, that Client chose to send it to you and supplied your name and email address for that purpose. We send the certificate on their behalf as their service provider, from a cpdcheck.com address that names the Client. We use your contact details only to deliver the certificate and related transactional messages for that Client, to store the certificate against your CPD record, and to respond to you. We do not use them to create an account, to send you marketing, or for any other purpose, and we do not share them with other Clients.
5.2 We maintain a CPD record for each financial adviser listed on the ASIC Financial Advisers Register, created from that public register (name, adviser number, licensee and authorisation details) under the terms on which ASIC publishes it. This lets advisers keep CPD results from across the industry in one place. Certificates issued through the Platform are matched to the relevant record so that you can access and download them if you choose to claim it. The record is created from the public register, not from details a Client supplies, and it contains no contact details until you claim it and provide them yourself. If you leave the register and your record is unclaimed, we delete it 12 months after you were last listed. A claimed record is kept until you ask us to delete it, subject to section 8.
5.3 Claiming your record is optional and free. If you claim it, Part C applies and we will use the contact details you give us only to operate your account and send you service messages.
6. Who we disclose personal information to
6.1 Your Licensee or employer, where you are a User under their account: the Super Admin and authorised staff can see your CPD records, Output relating to you, and your activity in the Platform to the extent the Client has configured.
6.2 Providers, where you complete a quiz or activity they published: your name, completion status and score, so they can record it.
6.3 Sub-processors that host and process data on our behalf. Our current Sub-processors are:
- Microsoft Azure (Microsoft Australia Pty Ltd and Microsoft Corporation): cloud hosting, database, file storage and Azure OpenAI Service, in the Australia East region;
- Microsoft 365 and Azure Communication Services: transactional email delivery (certificates, invitations, alerts);
- Stripe (Stripe Payments Australia Pty Ltd): subscription billing and payment processing.
6.4 Professional advisers, insurers, and a purchaser or prospective purchaser of our business, under confidentiality obligations.
6.5 Regulators, courts, law enforcement and other bodies where the law requires or permits it, and we will notify the affected Client where we lawfully can.
6.6 We do not sell personal information.
7. Overseas disclosure
7.1 We store and process personal information in Australia. We do not disclose personal information to overseas recipients. If that ever changes, we will complete a Change Impact Assessment, give Clients at least 30 days notice, update this policy to name the country, and take reasonable steps to ensure the recipient handles the information in accordance with the Australian Privacy Principles.
7.2 Changing our providers. Before changing any provider that hosts, stores or processes personal information, we complete a Change Impact Assessment of the security, privacy and data location of the new arrangement, notify affected Clients at least 30 days in advance, and update the Sub-processor list in section 6.
8. How we hold and secure it, and for how long
8.1 We hold personal information in secured cloud infrastructure with encryption in transit and at rest, role-based access controls, multi-factor authentication for administrative access, logging and monitoring, and regular review of access. Our staff access personal information only as needed to do their jobs.
8.2 Retention:
- Client Content, Output and CPD records: for the life of the Client’s account and for the export and deletion periods in Part A, clause 16. Certificates issued to you remain accessible in your own account so that you can meet your own CPD record-keeping obligations.
- Guest session data for Quiz Participants and guest assessments: 7 days, after which it is deleted unless claimed by an account holder.
- IP addresses recorded for quiz integrity: anonymised after 90 days.
- Login and security audit records: deleted after 12 months.
- Billing records: 7 years, as required by tax law.
- Backups: overwritten within 90 days.
8.3 Notifiable data breaches. If we become aware of a data breach that is likely to result in serious harm to individuals, we will assess it promptly, contain it, notify the affected Client and, where required, the Office of the Australian Information Commissioner and affected individuals in accordance with the Privacy Act.
9. Cookies and similar technologies
9.1 The Platform sets strictly necessary cookies to keep you logged in (authentication and refresh tokens), to protect against cross-site request forgery, and to maintain a temporary guest session for Quiz Participants and guest assessments. These are required for the Platform to work and cannot be disabled while using the service.
9.2 We do not collect precise location data. Our servers record the IP address of requests for security and rate limiting as described above.
10. Access, correction and your choices
10.1 Account holders can view and update most of their personal information in their profile settings. You can request access to, or correction of, other personal information we hold about you by contacting our Privacy Officer. We will respond within 30 days and may need to verify your identity. If we refuse a request we will tell you why and how to complain.
10.2 If your personal information appears in Client Content uploaded by a Licensee or Provider, we will usually refer your request to that Client, because they control that content, and assist them to respond.
10.3 You can close your account at any time. Your Licensee can remove you as a User. Records that the Licensee or we must keep under law will be retained as described in section 8.
10.4 You may deal with us anonymously or under a pseudonym where it is practicable, for example when making a general enquiry, but not when using an account or receiving a CPD certificate.
11. Complaints
11.1 If you have a concern about how we have handled your personal information, contact our Privacy Officer using the details below. We will acknowledge your complaint within 7 days, investigate, and respond within 30 days.
11.2 If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at www.oaic.gov.au or 1300 363 992.
12. Changes to this policy
12.1 We may update this policy from time to time. Material changes will be notified as described in Part A, clause 18. The current version is always available at https://cpdcheck.com/terms.
12.2 A copy of this policy is available free of charge in an alternative form on request.
13. Contact us
Privacy Officer: Clayton Daniel, Chief Executive Officer, CPDcheck Pty Ltd
Email: clayton@cpdcheck.com
PART C: ADVISER RECORD TERMS
These terms apply to you, an individual financial adviser, when you claim the CPD record that CPDcheck Pty Ltd (ABN 39 691 680 476) (“CPDcheck”, “we”) maintains for you (“Adviser Record”). By claiming your Adviser Record you agree to these terms and to the Privacy Policy in Part B. Terms defined in Part A have the same meaning here. Part A does not apply to you unless you are also a User of a Licensee or Provider, in which case that Client’s obligations to you are governed by your relationship with them.
C1 Your record. Your Adviser Record was created from your public listing on the ASIC Financial Advisers Register, not from any information supplied by a Licensee or Provider. It holds CPD certificates and results issued to you through the Platform by any Licensee or Provider, and any external CPD you choose to add. You own the information in your Adviser Record. We hold it for you and use it only as described in Part B.
C2 What we do not do. We do not send you marketing. We send only service messages: certificates and CPD alerts issued through the Platform, security and account notices, and changes to these terms. We do not sell or share your contact details with Licensees, Providers or anyone else, except that a Licensee or Provider that issued a certificate to you already has the details it used to do so.
C3 Your licensee. CPDcheck is not your licensee, employer or CPD provider. Your Adviser Record is a convenience for holding evidence of CPD. Whether an activity counts towards your CPD obligations is decided by your licensee under its CPD policy and the law. We do not certify your compliance and we are not responsible for decisions your licensee makes.
C4 Certificates. Certificates issued to you by a Licensee or Provider are final and cannot be deleted from your Adviser Record. If one is wrong, the issuer may attach a correction note or issue a superseding certificate, and you may ask us to attach a note under Australian Privacy Principle 13. External CPD you add yourself is your responsibility, and you may edit or remove it at any time.
C5 Access from your licensee. While you are authorised by a Licensee that uses the Platform, that Licensee can see the CPD records it created for you and, if you choose to share it, the rest of your Adviser Record. When you leave, the Licensee keeps its own records for its record-keeping obligations and loses access to anything else.
C6 Keeping your account secure. Keep your login details confidential and tell us if you suspect unauthorised access. You are responsible for activity under your account until you tell us.
C7 Closing and deletion. You may close your Adviser Record at any time in your account settings or by contacting us. We will delete it within 30 days, except for records we must keep under law and backups handled under Part B. An unclaimed Adviser Record is deleted 12 months after you cease to be listed on the register. Closing your Adviser Record does not affect records held by a Licensee or Provider that issued a certificate to you.
C8 Free of charge. Your Adviser Record is provided free. We may withdraw or change the free service on 90 days notice, during which you may export your records. We provide it with reasonable care but, to the extent permitted by law and without limiting your rights under the Australian Consumer Law, we exclude other warranties and limit our liability to you to resupplying the service.
C9 Changes and law. We may change these terms on 30 days notice by email. New South Wales law applies. Complaints are handled under Part B, section 11.