Last updated: 9 September 2026
LabPilot ("LabPilot", "we", "us") is an Australian service that helps educational institutions run cloud teaching labs on their own Microsoft Azure subscription. This policy explains what personal information we collect, why we collect it, and how we handle it. We are committed to managing personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Our role and the institution's role
LabPilot is designed for institutional use. The educational institution (the "Institution") that adopts LabPilot decides how it is used and is the primary controller of the personal information involved. LabPilot acts as the Institution's service provider and processor, handling personal information on the Institution's behalf and under its instructions. Where this policy and an Institution's own agreement or privacy notice differ, the Institution's arrangements with its staff and students also apply. Lab compute and the data inside VMs reside in the Institution's own Azure subscription and region, not on LabPilot's servers.
2. Information we collect
- Identity and account information from Microsoft (Entra) single sign-on when teachers and students sign in, such as name, email address or user principal name (UPN), and the Microsoft tenant or object identifier. We do not receive or store Microsoft passwords.
- Azure connection metadata that the Institution connects, such as subscription, resource group, and region identifiers, so LabPilot can provision and manage labs. We do not store the Institution's Azure account passwords.
- Lab and template metadata, such as lab names, VM images and templates, join codes, and enrolment or join records.
- Machine and session state, such as which VMs exist, their power state, and connection sessions to the lab gateway.
- Usage, cost, and telemetry data, such as VM hours used, VM on and off events, schedules, and auto-shutdown activity.
- Activity and audit logs that record actions taken in LabPilot, used for security and troubleshooting.
LabPilot does not need, and does not intend to collect, the coursework content or files that students create inside their VMs. That content stays in the Institution's Azure subscription.
3. How we use information
- To provision, schedule, display, and manage the labs and VMs teachers create.
- To authenticate users through Microsoft SSO and bind an invitation to the correct email so that one sign in gives a student access to their machines.
- To show usage, schedules, and estimated cost information for the Institution's subscription, and to apply quotas and auto-shutdown.
- To secure the service, investigate misuse, and keep audit records.
- To provide support and to communicate with the Institution about the service.
We use personal information for the purposes for which it was collected and related purposes the Institution would reasonably expect, consistent with the APPs.
4. Where data is stored and processed
Virtual machines, disks, networks, and the data inside them are created and stored in the Institution's own Azure subscription, in the Azure region the Institution selects, and are subject to Azure's terms and the Institution's policies. The operational metadata described above, which LabPilot needs to run the control layer, is stored in infrastructure we operate to deliver the service. We select hosting arrangements with appropriate protections for personal information.
5. Sub-processors and disclosure
We do not sell personal information. We disclose it only as needed to operate the service or where required by law. Our key sub-processor is Microsoft Azure, which provides the identity (Entra) and cloud infrastructure that LabPilot orchestrates. We use a small number of additional service providers to run LabPilot, and we require them to protect personal information consistent with this policy and the APPs.
6. Retention and deletion
We keep account and operational metadata for as long as the Institution uses LabPilot and as needed for the purposes above, then delete or de-identify it within a reasonable period, subject to legal record-keeping obligations. Audit logs may be retained longer for security. Deleting a lab or VM removes the associated resources in the Institution's Azure subscription; the Institution should back up anything it needs before deletion. An Institution can request deletion of its LabPilot account data by contacting us.
7. Security
We use industry-standard safeguards to protect personal information, including encryption in transit, access controls, and audit logging. Sign in relies on the Institution's Microsoft identity, so LabPilot does not hold user passwords. No system is completely secure, and the Institution is also responsible for securing its Azure subscription and for how it configures and supervises its labs.
8. Access and correction
Because the Institution is the primary controller, students and staff should usually first contact their Institution to access or correct their information. You may also reach us through our contact form to request access to, or correction of, the personal information we hold about you. We will respond within a reasonable time as required by the APPs. If we cannot give access or make a correction, we will explain why.
9. Data breaches
We maintain procedures to detect and respond to security incidents. If a data breach involving personal information we handle is likely to result in serious harm, we will notify the affected Institution promptly and cooperate with it, and we will comply with our obligations under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth), including notifying the Office of the Australian Information Commissioner where required.
10. Complaints and contact
If you have a question or complaint about how we handle personal information, reach us through our contact form. We will investigate and respond. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date above and, for material changes, provide reasonable notice where we can.