Privacy Policy
Effective date: 13 July 2026 · Last updated: 13 July 2026
CentreProof is a reputation and family-sentiment platform for Australian early learning services, operated by Enrolment Boost (referred to in this policy as "CentreProof", "we", "us" or "our"). We take privacy seriously. The families whose words move through our platform are trusting an early learning service with something precious, and we treat the information that comes with that trust accordingly.
This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It applies to our websites at centreproof.com.au and app.centreproof.com.au, the parent-facing pages we host (such as review, check-in and survey links), and our related services (together, the "Service").
1. Who this policy covers
We handle personal information about three groups of people:
- Centre users: owners, directors and staff of early learning services who hold a CentreProof account;
- Parents, guardians and family members of children enrolled at a subscribing centre, whose details a centre provides to us or who interact with pages we host on the centre's behalf; and
- Website visitors to our public pages.
Where a centre provides us with information about its families, we handle that information as a service provider acting on the centre's instructions. The centre remains responsible for having collected that information appropriately, and our agreements with centres require them to warrant that they have done so.
2. What we collect
From centre users: name, work email address, password (stored only as a secure hash), centre name and location details, settings and preferences, and records of your use of the Service.
About families (provided by their centre): parent or guardian name, email address and mobile number, the first name and age or room of their child, enrolment start date, attendance days, and related notes a centre chooses to record.
From parents directly: ratings, feedback messages, survey and check-in responses, and exit survey answers submitted through pages we host. Every such page identifies the centre it belongs to, and responding is always optional.
From Google: where a centre connects its Google Business Profile, we sync the centre's public reviews (reviewer display name, star rating, review text and reply text) as published on Google.
Automatically: standard technical records such as IP address, browser type, pages visited and timestamps, used for security and to keep the Service working. We use only essential cookies required to keep users signed in. We do not run advertising trackers on the Service.
3. Children's information
CentreProof is designed for adults. We do not knowingly collect personal information directly from children, and no page we host is directed at children. Information about children within the Service is limited, is provided by a centre or by a child's own parent or guardian, and typically consists of a first name, age or room placement, and content a parent chooses to include in feedback.
We treat all information relating to children with heightened care: it is used only to deliver the Service to the child's centre, is never sold, is never used for advertising, and is protected by the security measures described in section 8.
4. How we use personal information
We collect, hold and use personal information to:
- provide, operate and secure the Service;
- send review invitations, settling check-ins, surveys and exit surveys to families on a centre's instruction (see section 7 regarding electronic messages);
- analyse feedback and public reviews so a centre can understand family sentiment (see section 5 regarding automated analysis);
- alert a centre to matters its families raise, including safety concerns;
- provide support, billing and account administration;
- improve the Service, using aggregated or de-identified information; and
- comply with our legal obligations.
We do not sell personal information. We do not use family information for our own marketing, and we do not build advertising profiles.
5. Automated analysis (AI)
The Service uses artificial intelligence to read the text of reviews, survey responses and feedback so that themes, sentiment and potential risks can be surfaced to the relevant centre. This processing is performed via Anthropic's commercial API. Under the API terms that apply to our use, submitted content is not used to train Anthropic's models.
Automated analysis produces suggestions for the centre's human review. It does not make decisions about any individual, and centres are instructed that automated alerts are an aid to, not a replacement for, their own professional judgement and statutory obligations.
6. Who we share information with
We disclose personal information only to the service providers we use to run CentreProof, and only to the extent needed for them to perform their function:
- Supabase (database and authentication): our primary database is hosted in the Sydney, Australia region;
- Vercel (application hosting and content delivery), United States and global infrastructure;
- Twilio (SMS delivery), United States;
- Resend (email delivery), United States;
- Anthropic (AI text analysis, as described in section 5), United States; and
- Google (Business Profile integration), where a centre connects its own Google account.
Beyond these providers, we disclose personal information only to the subscribing centre it relates to, where required or authorised by law, or with the consent of the person concerned.
7. Electronic messages and marketing
Messages sent through the Service (review invitations, check-ins, surveys and exit surveys) are sent on behalf of a family's own centre in reliance on the centre's existing relationship with, and consent from, that family. Consistent with the Spam Act 2003 (Cth):
- every SMS includes a functional opt-out ("Reply STOP to opt out");
- every email includes a functional opt-out; and
- opt-outs are honoured for all future messages sent through the Service.
We may send centre users service and account communications relating to their subscription. Where we send marketing to prospective centre customers, it complies with the Spam Act and always includes an unsubscribe facility.
8. Storage and security
Our primary database, including family information and feedback content, is stored in Australia (Sydney region). We protect personal information through measures including encryption in transit, encryption at rest, per-centre data isolation enforced at the database layer, role-restricted credentials, and least-privilege access to production systems.
No system can be guaranteed absolutely secure, but we design for security by default and review our safeguards as the Service evolves.
9. Overseas disclosure
Some of the service providers listed in section 6 process limited personal information outside Australia, principally in the United States (message delivery, application hosting and AI analysis). Before using a provider we consider its security practices and contractual commitments. By using the Service, centres acknowledge these disclosures; APP 8 is addressed through a combination of provider due diligence, contractual safeguards and this disclosure.
10. Retention and deletion
We retain personal information while the relevant centre's account remains active and as needed to provide the Service. When a centre's account is closed, its data is available for export for 30 days and is then deleted from production systems, except where we are required by law to retain it or where it has been aggregated and de-identified. Parents may ask their centre, or us directly, to delete feedback they have submitted.
11. Access, correction and complaints
You may request access to, or correction of, the personal information we hold about you at any time by contacting us using the details in section 13. If your information was provided to us by your centre, we may direct the request to the centre or work with the centre to fulfil it. We respond to requests within a reasonable period and do not charge for making a request.
If you believe we have breached the APPs, please contact us first and we will investigate and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au, 1300 363 992, GPO Box 5218 Sydney NSW 2001.
12. Data breaches
We maintain a data breach response process. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act, and we will notify affected centres promptly so they can meet their own obligations.
13. Contact us
Privacy questions, requests and complaints can be directed to:
CentreProof (Enrolment Boost)
Email: martin@enrolmentboost.com.au
Web: centreproof.com.au
14. Changes to this policy
We may update this policy from time to time. The current version will always be available at centreproof.com.au/privacy with its effective date shown at the top. Material changes affecting centres will be notified to account holders. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy. See also our Terms of Service.