Privacy Policy
Last updated: 15 May 2026. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what personal information we collect, why, how we use it, and your rights.
1. Who we are
The passamc.org website is operated by Passmed Pte. Ltd. ("Passmed", "we", "us"), a company registered in Singapore. For all data protection matters, contact us at support@passmed.com. "Personal information" has the meaning given to it in the Privacy Act 1988 (Cth).
2. What we collect
When you create an account: your name, email address, password (stored hashed - we never see your actual password), and (optionally) profession, country of medical qualification, and target exam sitting date.
When you use the service: your question attempts, scores, time spent, flagged questions, performance analytics, and progress data. This is necessary for the platform to function.
When you subscribe: your billing email and subscription details. Your card details are collected and processed by Stripe (our payment processor); we never receive or store full card numbers.
Automatically: your IP address, browser type, device type, referring page, and pages visited on our site. We use this for security, fraud prevention, and to understand which features are used.
If you contact us: the contents of any email, message, or support ticket you send us.
3. Why we use it
To provide the service: serving questions, saving your progress, showing analytics, processing payments, sending transactional emails (account, subscription, refund).
To improve the service: anonymised, aggregated usage statistics to understand what's working and what isn't.
To communicate with you: transactional emails (account, subscription, trial ending, payment receipts) and, if you have opted in or purchased a paid plan, occasional product update emails about features and content. You can unsubscribe from product update emails at any time via the link in any email or from your account settings.
For security and fraud prevention: detecting unauthorised account access, credential sharing, or fraudulent payments.
To comply with legal obligations: including retention of payment and tax records under Australian tax compliance requirements.
4. Lawful handling under the Australian Privacy Principles
We collect, hold, use, and disclose your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth):
(a) Collection (APP 3-5): We collect only personal information that is reasonably necessary for our functions and activities, and we notify you at the time of collection about how the information will be used.
(b) Use and disclosure (APP 6): We use and disclose personal information only for the primary purpose for which it was collected, or for related secondary purposes you would reasonably expect.
(c) Direct marketing (APP 7): We may send you direct marketing about Passmed services. You can opt out at any time.
(d) Cross-border disclosures (APP 8): See section 6 below.
(e) Security (APP 11): We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. See section 9.
(f) Access and correction (APP 12 & 13): You can request access to and correction of your personal information at any time. See section 8.
5. Who we share with
We share your personal information only with service providers necessary to operate Passmed, including:
(a) Stripe - payment processing
(b) Brevo - transactional email delivery
(c) Google Cloud / AWS - hosting and infrastructure
(d) Cloudflare - DDoS protection, CDN, and security
(e) Analytics providers - aggregated usage statistics (with IP anonymisation)
Each provider is bound by a data processing agreement and processes your data on our instructions only.
We may also disclose personal information where required by law, court order, or regulatory authority, or where reasonably necessary to protect our rights, your safety, or the safety of others.
We never sell your personal information to third parties.
6. Cross-border disclosures (APP 8)
Passmed is operated from Singapore, and our service providers are based in multiple countries including Singapore, the United States, the European Union, and Australia. Where we disclose personal information overseas, we comply with Australian Privacy Principle 8 by taking reasonable steps to ensure the overseas recipient does not breach the APPs in relation to your information, or by ensuring you have consented to the disclosure with full understanding of the reduced protections.
7. How long we keep it
Account data: while your account is active, plus 12 months after closure (for support and legal purposes).
Question attempt data: while your account is active, plus 6 months.
Anonymised aggregate data: indefinitely.
Payment records: 5 years (in line with Australian tax compliance requirements under the A New Tax System (Goods and Services Tax) Act 1999).
Support correspondence: 3 years from last contact.
8. Your rights under the Australian Privacy Principles
You have the right to:
(a) request access to the personal information we hold about you (APP 12);
(b) request correction of inaccurate, out-of-date, incomplete, or misleading personal information (APP 13);
(c) opt out of direct marketing at any time;
(d) request anonymity or use of a pseudonym where lawful and practicable;
(e) lodge a complaint about how we have handled your personal information.
To exercise any of these rights, email support@passmed.com. We aim to respond within 30 days. We may need to verify your identity before acting on access or correction requests. In limited circumstances we may decline requests that are unlawful, frivolous, vexatious, unreasonably repetitive, or that would unreasonably impact the privacy of others.
If you are not satisfied with our handling of your personal information, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These include encryption in transit (TLS 1.2+) and at rest, hashed password storage, access controls and audit logging on our systems, and ongoing security testing. However, transmission over the internet is not completely secure - we cannot guarantee absolute security and you transmit information at your own risk.
10. Notifiable data breaches
If a data breach occurs that is likely to result in serious harm to any data subject, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required by Part IIIC of the Privacy Act 1988 (the Notifiable Data Breaches scheme).
11. Cookies & local storage
We use cookies and similar technologies for:
(a) Essential cookies - keeping you logged in, remembering your subscription state. These cannot be disabled without breaking the service.
(b) Functional cookies - remembering your preferences (theme, last-viewed topic).
(c) Analytics cookies - understanding aggregate site usage (via Google Analytics with IP anonymisation). Only set after you give consent.
You can manage your consent at any time via the cookie settings link in the footer. We may also use browser local storage to cache content for offline access.
12. Children
Our service is not directed at and we do not knowingly collect personal information from anyone under 18. By creating an account, you confirm you are 18 or older. If you believe we have collected information from someone under 18, please contact support@passmed.com immediately and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to all account holders at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact us
Questions about your data, or to exercise any of your rights? Email our privacy team at support@passmed.com.