The studio decides what student and family information to collect and why, and holds the direct relationship with those families. We host and process that information in order to provide, secure and support the service. We do not sell it, mine it, or use it for our own marketing.
Customer resources · Draft
Privacy policy
This is a draft, not legal advice. It describes how PWE Studio actually behaves today, in plain English, so that it can be reviewed against reality. It has not been reviewed by an Australian lawyer. Where it and a signed service agreement differ, the signed agreement prevails. Two sections in particular — consent for children and retention and deletion — should be reviewed by an Australian legal practitioner before this page is relied on commercially.
Last internally reviewed: 1 August 2026 · applies to PWE Studio v10.20.0 and later.
1 · Who we are
PWE GROUP PTY LTD, ABN 55 606 664 546, ACN 606 664 546, trading as PWE Studio, supplies the PWE Studio software to creative studios — art, music, dance, tutoring and similar teaching businesses.
We operate in Australia and handle personal information with reference to the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Whether and how the Act applies to a particular studio depends on that studio’s own circumstances, which is a question for its own adviser.
- Location: Caulfield North, Melbourne, Victoria, Australia
- Privacy enquiries and complaints: info@pwestudio.site
- Privacy contact: Lee L
2 · Who is responsible for what
This matters more than it sounds, because PWE Studio is sold in two forms and the answer differs.
The studio runs the software on its own infrastructure. Student and family information never reaches us, and we hold no copy of it. The studio is responsible for its own hosting, backups, access control and breach response; we can only advise.
Separately from either form, we hold a small amount of information about the studio as our customer: contact names, business email and phone, billing details and support correspondence. That is our own record and this policy governs it directly.
3 · What information the product handles
| Category | Typical contents | Why |
|---|---|---|
| Enquiry and registration | Student given and family name, mobile number, optional email, optional notes and any additional questions the studio configures | Contacting the family and arranging a suitable class |
| Teaching records | Class enrolment, roster placement, attendance, credit balance and adjustments, teacher notes | Running classes and keeping credit records accurate |
| Student work | Photographs of work made in class, titles, dates and teacher comments | Showing progress to the student’s own family |
| Access | A six-digit student access code, staff account and role, session cookies, audit records of material actions | Letting the right person see the right records, and being able to reconstruct what happened |
The product asks families for the minimum it needs. It does not ask for identity documents, government identifiers, health information or payment-card numbers, and none of those should be entered into any field. Enquiry forms carry a collection notice at the point of collection, and the consent a family gives is recorded against the version of the notice they were shown.
4 · Children’s information and publication consent
Most students at a creative studio are children, so this is the part of the product designed most conservatively.
Private by default
Every photograph of student work is private when it is uploaded. It is visible to studio staff with the appropriate role, and to the family that holds that student’s access code — nobody else. Original files are never served publicly; public and family views are generated derivatives, and every request is checked against the owning studio.
Who can see one student’s records
A family unlocks the student area with the student’s name, the registered mobile number and a six-digit code the studio issues. That combination reveals that one student’s credit balance, next class, attendance and work — and nothing about any other student. Attempts are rate-limited and locked temporarily after repeated failures. The weekly schedule export excludes student and guardian identities. A separate daily roster export may contain student names because it is an operational attendance file; it is restricted to staff with data-export permission, is marked private before download and never contains guardian names.
Publication requires a separate, recorded decision
Showing a student’s work on a studio’s public website or in promotional material is a distinct decision, never implied by enrolment. The registration form has a separate optional consent; ticking it requires naming the consenting person and their relationship to the student — the student themselves if an adult, a parent, or another authorised guardian. Each consent event is stored with who gave it, the relationship claimed, the method and the time, so a studio can later show what it was authorised to publish.
Withdrawing consent
Consent can be withdrawn at any time, without giving a reason, by contacting the studio. Withdrawal is recorded as its own event beside the original consent, and the work returns to private. Two honest limits: material a studio has already printed, or that a third party has already copied elsewhere, cannot be recalled by us; and withdrawal removes public display, it does not delete the teaching record, which is handled under section 7.
The studio, not us, is responsible for confirming that the person giving consent actually has authority for that child. The product records the claim; it cannot verify a family relationship.
5 · Where information is held
For subscription customers, data is held in Amazon Web Services’ Sydney region (ap-southeast-2), on the instance that runs the service: PostgreSQL beside the application, and media files on an attached volume. Backups are produced daily and are currently stored on the same instance; an off-instance copy is an open item we disclose rather than imply. Transport is encrypted with TLS, HTTP requests are redirected to HTTPS, and the application is not directly reachable from the internet.
We do not transfer personal information overseas for our own purposes. Support correspondence you send us may pass through the email provider you chose to use.
6 · How information is protected, and what is still missing
Each studio’s data is scoped to its own tenant and every authenticated route carries that context. Staff roles are separated — owner, manager, teacher, front desk — and granted least privilege. Passwords are stored as PBKDF2-HMAC-SHA256 hashes with a per-password salt and 600,000 iterations. Sessions use HttpOnly cookies with same-site controls. Student access attempts are rate-limited and locked. Material administrative actions are audited. Original media is private and access is ownership-checked. Deleting a studio requires an explicit lifecycle state and confirmation.
Multi-factor authentication is not yet enforced for privileged accounts; this is our highest-priority security item. Backup copies currently live on the same instance as the service. There is no uptime or backup-failure monitoring and no on-call roster, so failures are found by operator checks rather than alerts. There is no contractual availability commitment unless a signed order form states one.
We list the gaps because a privacy policy that only lists controls is a sales document. The Australian Cyber Security Centre treats multi-factor authentication, patching and tested backups as core measures for a small business; we treat MFA and an off-instance backup copy as work owed, not optional polish.
7 · Retention and deletion
While a studio is a customer, its records are kept for as long as it needs them to run classes and account for credits. The studio decides what to keep and what to remove, and can correct or delete a student record at any time from within the product.
After a subscription ends we make a standard export available for a limited window, then delete or de-identify the data according to the agreed deletion schedule, except where a law requires longer retention. Backup expiry takes longer than live deletion because a backup is a point-in-time copy; the exact figures belong in the production backup schedule and the signed agreement rather than on this page.
Needs legal review. Retention periods for children’s teaching records, and the interaction between deletion requests and record-keeping obligations, must be set with Australian legal advice before this section is treated as final.
8 · Access, correction and complaints
If you are a student or family member, ask your studio first — it holds the relationship and can act on the record directly. If a studio cannot resolve it, or if your question is about information we hold as the software supplier, email info@pwestudio.site. We will acknowledge the request, confirm who you are by a means that does not create a new risk, and respond within a reasonable period.
We do not publish a response deadline here. Support response targets exist only where a signed order form states them, and they are initial-response targets rather than resolution guarantees. A request under privacy law is answered within the period that law requires, which is not something we shorten by writing a number on this page.
We publish a location rather than a street address, so email is currently the channel for written requests. If you need to correspond by post, ask us and we will supply a postal address for that request.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner. We would rather hear from you first, but that path is yours regardless.
9 · If something goes wrong
On a suspected data incident we contain access and preserve evidence; identify which studios, people and data types are affected; rotate exposed credentials and revoke sessions; assess likely harm; notify the affected studio’s contact without unreasonable delay; agree who leads any notification to families and to the regulator; restore only from verified evidence; and write up cause, decisions and follow-up tests.
Australia’s Notifiable Data Breaches scheme requires covered entities to notify affected individuals and the Commissioner where a breach is likely to cause serious harm. Which entity is covered, and who notifies, must be assessed at the time rather than assumed — the studio usually has the direct relationship with the families.
Breach notifications and security reports reach us at info@pwestudio.site, attention Lee L, Privacy Contact. If you believe student information has been exposed, say so in the subject line and do not include the exposed data itself in the message.
10 · Changes to this policy
Collection notices inside the product carry a version, and a family’s consent is recorded against the version they were shown. If we change this policy in a way that materially affects how information is handled, we will tell subscribed studios in writing before the change takes effect.
Related
The terms of service set out the commercial arrangement, the support policy explains contact and incident priority, the FAQ answers what the product does today, and the release evidence records what has and has not been accepted.
PWE GROUP PTY LTD · ABN 55 606 664 546 · ACN 606 664 546
© 2026 PWE Studio · v10.20.0 · PWE · 天域出品