Privacy Policy

Last updated · 30 June 2026

Road to Australia (operated by Road to Australia Pty Ltd, ABN 19 815 632 311, hereafter "we") is committed to protecting your personal data. This policy describes how we collect, use and protect your information in accordance with the EU General Data Protection Regulation (GDPR) and the Australian Privacy Principles (APP) under the Privacy Act 1988 (Cth).

1. Data Controller

Road to Australia Pty Ltd (ABN 19 815 632 311), located at Sydney, NSW 2000, Australia.

Contact: hello@roadtoaustralia.fr. No formal Data Protection Officer is appointed at this stage. All data-related requests should be sent to the email above.

2. Data we collect

When you interact with roadtoaustralia.fr, we collect:

Information you provide: name, email, WhatsApp/phone, Australia migration plans, intended professional sector, declared English level, certifications (RSA, Barista, White Card), expected arrival date.

Payment data: we do not store any bank or card data. Payments are processed exclusively by Stripe Payments Australia Pty Ltd. We keep only a Stripe customer ID and transaction history (amount, currency, pack, date).

Technical data: IP address, browser user-agent, server logs (via Vercel Analytics and Sentry for security and performance).

3. Purposes and legal bases

Performing the service contract (Discovery, Settle, Professional packs) — legal basis: contract performance (Art. 6.1.b GDPR).

Contacting you via WhatsApp, phone or email for service delivery — legal basis: contract performance.

Sending transactional emails (payment confirmation, magic-link, status updates) — legal basis: contract performance.

Analysing site usage anonymously — legal basis: legitimate interest in improving the service (Art. 6.1.f). You may opt out via cookie preferences.

Fraud detection — legal basis: legitimate interest.

Complying with legal obligations (invoice retention, AML) — legal basis: legal obligation (Art. 6.1.c).

4. Recipients and processors

Your data is shared only with technical sub-processors bound by confidentiality and GDPR commitments:

Stripe Payments Australia Pty Ltd (payments) — Australia/Ireland.

Supabase Inc. via Ireland region (database, authentication) — GDPR DPA signed.

Resend via Ireland region (transactional email).

Sentry GmbH via EU-Germany region (error monitoring, PII-scrubbed).

Vercel Inc. (site hosting, multi-region edge cache).

HubSpot Inc. (marketing CRM, limited to opted-in contacts).

We do not sell or share your data for third-party commercial purposes.

5. International transfers

Our primary databases (Supabase) and emails (Resend) are hosted in Ireland, within the European Union. No transfer outside the EU occurs for these.

Stripe Australia processes payments in Australia, a jurisdiction with recognised privacy protections under the Privacy Act 1988. Transfers are governed by Standard Contractual Clauses (SCC).

Sentry hosts data in Germany (EU). HubSpot processes data in the United States under the EU-US Data Privacy Framework (DPF).

6. Retention periods

Contact data and client profile: kept for the duration of the contract + 3 years.

Payment data: 10 years from transaction date, per accounting and tax obligations.

Technical logs and analytics: maximum 13 months.

Quiz data: 24 months if not converted to paying client.

Audit logs: 5 years (traceability obligations).

7. Your rights

Under GDPR you have the following rights:

Right of access to a copy of your personal data.

Right to rectification of inaccurate or incomplete data.

Right to erasure (the "right to be forgotten"), subject to legal retention obligations.

Right to restriction of processing in certain cases.

Right to portability in a structured machine-readable format.

Right to object to legitimate-interest-based processing.

Right to withdraw consent at any time when processing is based on it.

To exercise these rights, email hello@roadtoaustralia.fr from the address associated with your account. We respond within 30 days.

If you believe your rights are not respected, you may complain to the CNIL (https://www.cnil.fr) in France, or the Office of the Australian Information Commissioner (OAIC) (https://www.oaic.gov.au) in Australia.

8. Cookies

We use strictly necessary cookies (session, security, language preferences) and, with your consent, anonymised analytics (Vercel Analytics).

Manage your cookie preferences via the "Cookie preferences" link at the bottom of each page.

9. Security

We implement appropriate technical and organisational measures: TLS encryption in transit, at-rest encryption on Supabase, role-based access control (RBAC), audit logging.

In the event of a breach affecting your rights, we will notify you within 72 hours per Article 34 GDPR.

10. Changes to this policy

This policy may be updated to reflect legal or technical changes. The current version is published on this page with its last-updated date. Material changes will be notified by email.

11. Contact

Road to Australia Pty Ltd — ABN 19 815 632 311

Email: hello@roadtoaustralia.fr

Sydney, NSW 2000, Australia