Privacy Policy – Passivhaus HUB

Privacy Policy

Last updated: 26 July 2025

This Policy explains how SMART PLUS FAMILY PTY LTD (ABN 36 644 265 412) trading as Passivhaus HUB collects, uses and safeguards your personal information when you use any Passivhaus HUB website (passivhaushub.com), learning platform (my.passivhaushub.com) or related service (collectively, the “Service”). It also sets out your rights under the Australian Privacy Act 1988, the EU/UK GDPR and the NZ Privacy Act 2020.

1. Key definitions

  • Account – profile you create to access the Service.
  • Cookie – small text file stored in your browser.
  • Data Controller – entity that decides why & how data is processed (Passivhaus HUB for GDPR purposes).
  • Device – any computer, phone or tablet you use.
  • Personal Data – information about an identified or reasonably identifiable individual.
  • Service Provider – third‑party company that helps us run the Service.
  • You / User / Data Subject – the individual using the Service.

2. What we collect

  • Identity & contact – name, email, phone, postal address, country.
  • Account data – username, hashed password, course progress, certificates.
  • Financial – Stripe/PayPal transaction IDs, last 4 digits of card; ID docs for bank transfers.
  • Usage – IP, browser, pages viewed, session times, referral URL.
  • Marketing consents, email preferences, campaign responses.
  • Social‑login – name & email from Google, Facebook, Twitter or LinkedIn.
  • Certification – details required by the Passive House Institute (PHI) for exam booking.
  • Sensitive infonot routinely collected. If you volunteer dietary/accessibility needs we use them only for that purpose and then delete them.

3. How we collect data

  • Directly – forms, checkout, event sign‑in, emails, phone.
  • Automatically – cookies, server logs, pixels, Google Analytics.
  • Third‑party sources – Stripe, social‑login providers, PHI.

4. Cookies & similar tech

We use:

TypePurpose
Essentialsecurity, login sessions.
Preferencesremember language, video settings.
AnalyticsGoogle Analytics, Hotjar.
Advertising / RemarketingMeta pixel, LinkedIn Insight Tag, Google Ads, Bing UET, TikTok pixel.

A cookie‑consent banner appears on first visit. Visitors in the EU/UK can granularly opt‑in and you can change or withdraw consent anytime via Cookie Settings in the footer. See /policies/cookie-policy for full details.

5. Why & on what basis we process your data

Legal basisExamples
Contractcreate Account, deliver courses, process payments, issue certificates.
Legitimate interestimprove Service, prevent fraud, limited marketing of similar products.
Consentnewsletters, non‑essential cookies.
Legal obligationtax records, consumer‑law guarantees.

Direct marketing. You may opt out of email, SMS or targeted‑ad marketing at any time by unsubscribing or emailing [email protected].

6. Who gets access & their policies

PurposeVendor • Privacy link
Hosting / platformGoHighLevel – link
AWS – link
Vimeo – link
AnalyticsGoogle Analytics – link
Hotjar – link
PaymentsStripe – link
PayPal – link
Apple IAP – link
Google Play IAP – link
AdvertisingGoogle Ads – settings
Bing / Microsoft – link
Meta (Facebook/Instagram) – link
LinkedIn Ads – link
TikTok Ads – link
SecurityGoogle reCAPTCHA – link
AccountingXero – link
CertificationPassive House Institute – link

We sign data‑processing agreements or rely on Standard Contractual Clauses (SCCs) where required.

7. International transfers

Data may be stored or processed in Australia, the EU, the UK, the USA or other jurisdictions where our providers operate. For EU/UK users we rely on SCCs or adequacy decisions (e.g. New Zealand) to safeguard transfers.

8. Retention

DataDuration
Invoices & financial records7 years
Marketing consentsuntil withdrawn
Analytics logs26 months
Session recordings (video & chat)24 months then archived/deleted
PHI exam data10 years (PHI requirement)

9. Your rights

RegionRights
Australiaaccess, correction, complaint to OAIC
EU / UKGDPR rights incl. erasure, portability, objection, lodge complaint with DPA
New Zealandaccess, correction, complaint to OPC

To exercise your rights, please email [email protected]. We will respond to all requests within 30 days.

10. Security & breach notification

  • TLS encryption in transit
  • ISO‑27001 compliant hosting
  • Least‑privilege staff access
  • Annual penetration testing

If a data breach is likely to cause serious harm we will comply with Australia’s Notifiable Data Breach (NDB) scheme and, where GDPR/UK GDPR applies, notify authorities and affected users within 72 hours.

11. Behavioural remarketing opt‑outs

You can further control interest‑based ads via industry programmes:

12. Facebook Fan Page & Insights

We operate the Facebook page facebook.com/smartplusacademy1. Facebook Ireland & Passivhaus HUB are joint controllers for aggregated “Insights” statistics. Facebook places a 2‑year cookie to compile de‑identified stats; see Facebook’s Data Policy for details.

13. DMCA / copyright

Send copyright notices to [email protected] or the postal address below.

14. Children

The Service is not directed to children under 16 (or under 13 in the United States). We do not knowingly collect their data.

15. EU / UK representatives

DataRep EU – Rue d’Athènes 12, 75009 Paris, France • +33 1 82 88 39 16
DataRep UK Ltd – 27 Old Gloucester St, London WC1N 3AX, UK

16. Changes to this policy

We may amend this policy; material changes will be announced on the website and emailed to registered users 30 days before they take effect.

17. Contact

  • Email: [email protected]
  • Postal: 70/35 Hastings St, Scarborough WA 6019, Australia
  • Phone: +61 482 082 001

Inspire. Design. Build. Future-Focused Education for All.

Operating in Australia, New Zealand, United Kingdom, Ireland & EU markets

© 2025 SMART PLUS FAMILY PTY LTD trading as Passivhaus HUB

ABN 36 644 265 412 • All rights reserved