Legal

Privacy Policy

Last updated: 31 August 2026

This Privacy Policy explains how The Trustee for BLS Co Unit Trust, ABN 21 817 251 461, trading as Builders Licence Success, collects, holds, uses and discloses personal information.

In this policy, we, us, our and BLS mean that entity. You means a website visitor, prospective client, client, portal user, referee or another person who deals with us.

This policy covers our public website, customer portal, forms, communications and licence, registration, RPL and application support services.

Website: https://builderslicencesuccess.com.au
Email: info@builderslicencesuccess.com.au
Phone: 0407 960 270

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply, and otherwise in accordance with this policy.

1. Personal Information We Collect And Hold

Depending on how you deal with us, we may collect and hold:

  • your name, email address, phone number, address and business contact details;
  • your suburb, state, postcode and general location;
  • your current role, trade, employment history, project history and relevant experience;
  • the licence, registration, mutual recognition or RPL outcome you are seeking;
  • qualifications, transcripts, training history and RPL information;
  • application details, previous lodgements, regulator correspondence and application status;
  • referee, supervisor, employer and project contact details;
  • documents, photographs, plans, records and other evidence you upload or ask us to review;
  • identity information and government-related identifiers where required for an application;
  • business names, ABNs, company, trust, partnership, director and nominee information;
  • billing details, payment status, invoices, receipts and transaction references;
  • records of calls, emails, SMS messages, portal activity, consultations and support requests;
  • feedback, complaints and any other information you choose to provide; and
  • technical, analytics and advertising information described below.

2. Sensitive Information And Government Identifiers

A licence, registration or RPL process may require information about matters such as health, criminal history, professional memberships, financial circumstances or suitability. We only collect sensitive information with your consent or where collection is required or authorised by law. Where practical, we will explain why the information is needed before collecting it.

We may collect government-related identifiers, such as licence, registration or identity document numbers, where reasonably necessary for the service or required for an application. We do not adopt these identifiers as our own identifiers.

Do not send sensitive information or identity documents unless we request them or they are directly relevant to the service.

3. How We Collect Information

We may collect information when you:

  • visit or use our website or customer portal;
  • complete an enquiry, application check, booking, contact or onboarding form;
  • create or use a portal account;
  • call, email, SMS or otherwise communicate with us;
  • book or attend a consultation;
  • accept a proposal, pay an invoice or use a payment link;
  • upload documents or provide information for review; or
  • subscribe to marketing or otherwise interact with us.

We may also collect relevant information from people you nominate and from payment providers, referral partners, RTOs, advisers, publicly available registers and state or territory regulators where lawful and reasonably necessary for the service.

You may browse the public website without identifying yourself. We cannot provide most personalised pathway, application or portal services anonymously because we need to connect the information and documents to the correct person and matter.

4. How We Hold Information

We use a combination of Australian-hosted systems and specialist service providers. Portal database and authentication services are provided through Supabase and configured in Australia. Documents uploaded through the BLS portal are stored in Amazon S3 in the Sydney region. Those document uploads use server-side encryption and access-controlled, time-limited links.

Information may also be held in our customer relationship management, workflow automation, email, payment, communications, backup and business administration systems. Some providers and their support personnel or subprocessors may operate outside Australia, as explained in section 11.

5. Why We Collect, Hold, Use And Disclose Information

We may handle personal information to:

  • respond to enquiries and provide preliminary pathway information;
  • assess licence, registration, RPL or application support needs;
  • create and manage portal access and client matters;
  • review qualifications, experience, referees, project history and supporting evidence;
  • prepare checklists, summaries, evidence plans, forms and application materials;
  • coordinate with regulators, RTOs, referees and advisers where authorised;
  • provide support and communicate about services;
  • issue proposals and invoices, process payments and maintain financial records;
  • send administrative, transactional and permitted marketing communications;
  • improve our website, portal, forms, content and services;
  • measure advertising and website performance;
  • detect misuse, fraud, technical faults and security threats;
  • resolve complaints and enforce or defend legal rights; and
  • meet legal, regulatory, insurance and record-keeping obligations.

6. Website Analytics, Cookies And Session Recordings

Our website uses necessary storage for security, site functions and remembering your privacy choices. With your choice, we may also use cookies, pixels, tags and similar technologies for analytics or marketing.

Depending on your choices, these tools may include:

  • Google Tag Manager and Google Analytics 4;
  • Google Ads conversion measurement and remarketing;
  • Meta Pixel;
  • PostHog product analytics and session recordings; and
  • Cloudflare security, delivery and performance services.

These tools may receive online identifiers, IP address, approximate location, device and browser information, pages viewed, interactions, referral source, campaign information and conversion events. We do not intentionally send names, phone numbers, email addresses or document contents to website analytics events.

PostHog session recordings help us understand usability and form drop-off. They may capture page views, clicks, navigation and the visible page layout. All form inputs are configured to be masked in recordings. Session recording runs only when analytics cookies have been accepted.

Google consent settings default analytics and advertising storage to denied before you make a choice. Where Google Tag Manager is enabled, Google may still receive limited cookieless measurement signals, such as consent state and basic request information, while storage remains denied. Optional analytics storage, advertising storage and advertising personalisation remain denied unless you accept the relevant category.

You can change your choices at any time using Cookie settings in the footer. You can also control cookies through your browser, although some website functions may not work properly.

7. AI-Assisted Tools

BLS may use AI-assisted tools to help authorised staff prepare drafts such as evidence plans, reference statements, checklists or internal summaries. Selected information relevant to the task may be processed by an AI service provider. This can include a name, qualification details, official competency requirements or material contained in a template selected for processing.

We aim to minimise the personal information included, limit use to the service or an internal business purpose, and require human review before relying on an output. AI tools do not decide licence eligibility, RPL competency, application approval or any regulator outcome.

Website forms may use your answers to provide preliminary pathway guidance and help BLS prioritise follow-up. These rules do not determine whether you may buy a service, the price of a service, your legal eligibility, or any regulator or RTO outcome.

8. Marketing Communications

We send electronic marketing only where we have consent or are otherwise permitted by law. Marketing consent is separate from the consent needed for us to respond to an enquiry or provide a requested service.

Marketing messages will identify BLS and provide a way to unsubscribe. You can unsubscribe at any time using the facility in the message or by contacting us. We will action unsubscribe requests within the period required by law. We may still send non-marketing communications about your enquiry, payment, account or service.

9. Payments

Payments may be processed by Stripe or another payment provider. We do not store full card numbers in BLS systems. The payment provider handles card information under its own terms and privacy policy.

We may receive information such as your name, email address, billing details, amount, payment status, invoice or receipt information and transaction reference.

10. When We Disclose Information

We may disclose relevant personal information to:

  • authorised staff, contractors and professional advisers;
  • hosting, database, document storage, authentication, CRM and automation providers;
  • email, SMS, booking, analytics, advertising, payment, AI and support providers;
  • regulators, RTOs, referees, accountants, lawyers and application-related third parties where you authorise us or disclosure is reasonably necessary for the service;
  • courts, law enforcement, regulators or government bodies where required or permitted by law;
  • insurers, debt recovery and dispute-resolution providers where reasonably necessary; and
  • a purchaser or successor if the business or relevant assets are sold or restructured.

We do not sell personal information.

11. Overseas Processing And Disclosure

Our primary portal database and uploaded-document storage are configured in Australia. However, some analytics, advertising, email, payment, communications, support and AI providers may process or allow access to limited information outside Australia. These locations may include the United States and other countries in which a provider or its subprocessors operate.

Where the Australian Privacy Principles apply, we take reasonable steps appropriate to the circumstances before disclosing personal information to an overseas recipient. Provider locations and subprocessors can change, so you may contact us for current information about a material provider used for your service.

12. Security And Data Breaches

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include encryption, access controls, multi-factor authentication, audit records, secure links, provider due diligence, backups and staff access restrictions.

No online service can be guaranteed completely secure. You should protect your portal login details and take care when sending confidential information by email or SMS.

If we suspect a data breach, we will assess and respond to it. We will notify affected individuals and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme.

13. Retention

We retain personal information for as long as reasonably necessary for the purposes described in this policy, including providing services, maintaining application and business records, meeting tax and legal obligations, resolving disputes and protecting legal rights. Retention periods vary according to the information and the matter.

When personal information is no longer required, we take reasonable steps to destroy or de-identify it. Deletion from backups and third-party systems may occur on their normal secure deletion cycles.

14. Access, Correction And Deletion Requests

You may ask to access or correct personal information we hold about you. You may also ask us to delete information, although we may need to retain some records for a permitted purpose or where required by law.

Send requests to info@builderslicencesuccess.com.au. We may need to verify your identity. If we refuse access or correction where permitted by law, we will generally explain why and the available complaint process.

15. Privacy Complaints

Send a privacy complaint to the BLS Privacy Officer at info@builderslicencesuccess.com.au and include enough detail for us to investigate. We will acknowledge the complaint and aim to respond within a reasonable period.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.

16. Information About Other People

If you give us personal information about a referee, supervisor, employee, director, client or another person, you confirm that you are authorised to provide it and that providing it is lawful. Where practical, you should tell that person that BLS holds their information and direct them to this policy.

17. Changes To This Policy

We may update this Privacy Policy when our services, systems or legal obligations change. The current version will be posted here with its updated date. Material changes may also be communicated through the website, portal or email where appropriate.