Nova 5 · VETos
Automated Decisions Register
Version 2026-09-21 · archived copy · permanent address
This register describes every automated system in Nova 5 that uses personal information to make a decision, or to do something substantially and directly related to a decision, affecting an individual. It is published to meet the transparency requirements of Australian Privacy Principle 1.7 (Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024, commencing 10 December 2026) and is maintained automatically as the Service changes. Nova 5 is provided by Supahuman Limited as part of VETos, the AI Operating System for Vocational Education.
1. Purpose and scope
This register covers automated decision-making within Nova 5 (the Service). It describes the kinds of personal information used by automated systems, the kinds of decisions made solely by those systems, and the kinds of decisions to which they substantially and directly contribute. It is written in plain language so the people affected — learners and the staff of training organisations — can understand and question what the Service automates.
- Maintained automatically: when the Service changes, this register is rewritten to match, and every version is archived at a permanent address.
- The register describes the Service as it is — never planned or future capability.
2. Design stance
Nova 5 is deliberately built so that decisions with significant consequences for a person are made by people. The Service provides formative practice, teaching materials, evidence tooling and, where an organisation enables it, record-keeping tooling for assessment. Competency, assessment, enrolment and recognition decisions remain with the training organisation's qualified staff: where the assessment features are enabled, every outcome is decided by a named human assessor, and the Service's AI never marks or suggests an assessment outcome. Automated systems in the Service are engineered to inform and record those decisions, not to make them.
- Learner identity is pseudonymous by default — most automated processing operates on a pseudonymous visitor identifier, not a name.
- Personal information use is minimal by design: no street addresses, no precise location, no raw IP addresses stored against learner activity.
3. Kinds of personal information used by automated systems
The following kinds of personal information are used in the operation of the automated systems described in this register.
- A pseudonymous visitor identifier and, where a learner or their organisation chooses, a display name.
- Learning activity events: starts, steps, answers, completions, time engaged, and scores within practice activities.
- Where an organisation turns on the learner_electives setting for a learning space: the electives each learner selects for that space (their elective plan), used to measure that learner's own progress. Where the setting is off, the space uses the designer's elective selection for everyone and no learner plan is held.
- A summary signal derived from the learner's own practice-question history, used at the moment of a coaching conversation turn to tailor the coach's guidance to that learner. Conversation transcripts are not stored; the signal is keyed to the pseudonymous visitor identifier.
- Work a learner chooses to upload for formative feedback, where their organisation has enabled that feature.
- Learning-management-system identity (name and email as supplied by the organisation's LMS), where the organisation connects Nova via LTI.
- Where an organisation turns on Nova LMS learner management (the Learner tracking, Hybrid or Full setting): the roster entries and invitations the organisation creates for its learners, the Learners page that lists them, and per-space tracking of those learners' activity. With the setting Off, the Service does not operate these learner-management areas.
- Where an organisation enables the assessment features: work a learner submits for assessment, the outcome a named human assessor records for each unit, when it was decided and by whom, and the retained history of those decisions.
- Where an organisation enables the assessment features: the learner's name, email address and Unique Student Identifier (USI), as supplied by the organisation, included in assessment-record exports the organisation downloads for its own student management system. The Service passes the USI through for the organisation's use; it does not use the USI for any other purpose.
- Cohort (group) labels from the organisation's roster, used to group assessment views; learners who submit without a roster group are shown as ungrouped rather than hidden.
- Coarse, city-level location derived from network routing at the time of access (never an address, precise coordinates or a stored IP address).
- Self-reported learning context, keyed to the pseudonymous visitor identifier and never to a name: prior experience with the topic, confidence before and after, and — optionally and only if the learner chooses — where they study, why, and whether extra language support would help. Only ever reported as group counts, with groups smaller than seven learners suppressed.
- Problem reports submitted to support, including what the reporter wrote and the resolution log the Service writes as it handles the report (triage verdict and reason, repairs made, and whether the reporter was told).
- For training organisation staff using the provider portal: name, email address, role and workspace activity.
4. Decisions made solely by automated systems
The following decisions are made by computer programs without human involvement in the individual decision. None of them determines competency, certification, enrolment or any comparable right; each states its effect and how to question it.
- Access control on learning links: the Service automatically serves or declines a learning link based on its status, expiry and the organisation's subscription standing. Effect: a learner may be unable to open a learning space until the organisation resolves the link. To question it: contact the training organisation that issued the link.
- Self-enrol join and access-code gates: where an organisation uses a self-enrol join card or an access code for a learning space, the Service automatically admits a learner who presents a valid link or code and declines one who does not. The gate is shown in the organisation's own branding. Effect: whether the learner can enter that space. To question it: contact the training organisation that runs the space.
- Access control on portal features: the Service automatically shows or withholds portal areas based on a staff member's assigned role and the organisation's settings — the assessment marking desk and records are available only to staff in the owner or assessor role, and only where the organisation has enabled the assessment features. Effect: which portal areas a staff member can use. Roles are assigned by the organisation; to question an assignment, contact the workspace owner.
- Nova LMS learner-management gating: the organisation chooses one Nova LMS setting (Off, Learner tracking, Hybrid or Full). Where it is Off, the Service automatically withholds the learner-management areas — rosters, invitations, the Learners page and per-space tracking — from staff; otherwise it shows them. Effect: which learner-management areas staff can use. The setting is the organisation's; to question it, contact the workspace owner.
- Practice scoring and instant feedback: activities mark answers, award points in live class games, and generate formative feedback automatically, including the debrief shown after a role-play. Effect: the learner sees scores, streaks and feedback in the moment. These results are formative practice signals only and do not decide any outcome about the learner. To question one: raise it with the trainer, who can escalate to us from the portal.
- Practice-support selection: the Service automatically selects reminders, refresher questions and study suggestions from a learner's own activity, including the scheduling of quick-fire practice questions and the tracking of practice streaks. Effect: which nudge or practice item a learner sees next, and when. No access or outcome depends on it.
- Coach personalisation: when a learner talks to the coach, each turn is tailored using a summary signal derived from that learner's own practice-question history at the time of the turn. Effect: the guidance, hints and questions the coach chooses for that learner. The coach follows a Socratic contract — it supports practice and does not mark, grade or decide any outcome. Conversation transcripts are not stored. To question it: raise it with the trainer, who can escalate to us from the portal.
- Learning-path suggestion: at the start of a learning space, the learner's self-reported prior experience and confidence pick a suggested ordering of the same activities (supported, standard or experienced). Effect: the order things are suggested in — nothing is hidden, gated or graded by it, and the learner can change the setting at any time. To question it: change it in place ('Tune your path').
- Learner-chosen electives: where an organisation turns on the learner_electives setting for a learning space, the space offers every elective the qualification packages, each learner selects their own, and the Service measures that learner's progress against their own selection. Effect: which electives count in the progress shown to that learner. Nothing is graded or gated by it; the learner can change the selection. To question it: contact the organisation that runs the space.
- Automated support triage: when a problem report is submitted, an automated resolver triages it, may make repairs, and can close the report as solved by AI. Each step — the triage verdict and reason, the repairs made and whether the reporter was told — is written to a resolution log administrators can read. Effect: whether and how the report is resolved without a person. To question it: raise it with your organisation's administrator, who can escalate to us from the portal.
5. Automated systems that substantially contribute to human decisions
The following systems do not make the decision, but do something substantially and directly related to a decision made by a person at the training organisation. In each case the deciding human is identified and the system's contribution is recorded.
- Assessment marking desk (where an organisation enables the assessment features): the Service automatically assembles each learner's submissions for marking, including cohort-level views of who has submitted and what remains unmarked. Every assessment outcome is decided and recorded by a named human assessor at the organisation; the Service's AI never marks a submission or suggests an outcome.
- Assessment records: the Service keeps a ledger of the outcomes assessors record — one row per learner and unit, showing the current outcome (the newest decision, with the full history retained) and the assessor who decided it. The record reflects human decisions; it does not make or alter them.
- Assessment-record export: the Service compiles recorded outcomes into a file (learner, email, USI, unit, outcome, decision date, assessor, learning space, submissions) that the organisation can download into its own student management system. The Service never submits AVETMISS or VET Information Standard data itself, in any mode; what the organisation reports, and any decision drawing on the export, is the organisation's own under its own policies.
- Learner tracking (where an organisation turns on Nova LMS learner management): the Service shows staff the roster, who has been invited, and each rostered learner's activity in a learning space. Any decision a trainer or manager takes about a learner from that view is their own; the Service records activity, it does not judge it.
- Grade signals to a connected LMS: where an organisation connects Nova to its learning management system via LTI, activity scores and completion signals are written to the LMS gradebook automatically. Any assessment decision drawing on those signals is made by the organisation's staff under its own assessment policy — the Service passes practice signals, it does not assess.
- Recognition of prior learning (RPL) evidence mapping: where enabled, the Service drafts a map of a candidate's self-assessment and evidence against unit requirements. The draft is an input for a qualified human assessor, who makes the recognition decision; drafts are marked as drafts and the assessor's decision is their own.
- Insights and reports: the Service aggregates learning activity into dashboards, weekly reports and delivery records that inform trainers' and managers' decisions about teaching. The records identify what was automated; sign-off of delivery records is a human act.
- Support resolution log: where an administrator reviews a problem report the automated resolver has handled or closed, the resolution log shows what was decided, what was repaired and whether the reporter was told. Any further action the administrator takes on the report is their own decision.
6. What automated systems never decide
For the avoidance of doubt, no automated system in the Service makes any of the following decisions about an individual.
- Whether a learner is competent, passes a unit, or receives any qualification, statement of attainment or certification. Where an organisation enables the assessment features, the Service assembles submissions, records the outcomes human assessors decide, and exports those records — that contribution is disclosed in section 5. The decision itself is always the human assessor's; no algorithm marks, scores or suggests an assessment outcome.
- Whether a person may enrol, continue in, or be excluded from a course.
- Any decision about a training organisation staff member's employment, performance or pay.
- Any pricing, credit or eligibility decision about an individual.
7. Human oversight and contestability
Every consequential pathway in the Service has a human checkpoint, and every automated action that matters is recorded.
- Delivery records are confirmed by a named trainer before they stand as evidence; RPL maps await a human assessor; assessment obligations remain with the organisation.
- Every assessment outcome is recorded against a named human assessor, with the date of the decision and the full history retained — a later decision supersedes an earlier one on the record, but the earlier decision remains visible.
- Where a learning space covers accredited units but the organisation has not enabled the assessment features, the Service tells the learner that assessment is not offered in that space and why, rather than leaving the area blank.
- An auditable log records automated actions (including automated content changes and report runs) and is available to each organisation for its own workspace.
- Where the automated support resolver handles a problem report, it writes each step to a resolution log as it happens — the triage verdict and reason, the repairs made and whether the reporter was told — so an administrator can see what was decided and act on it.
- A learner who believes an automated result is wrong should raise it with their trainer or training organisation, which can escalate to Supahuman from the portal; we review and respond.
- Questions about this register: hello@supahuman.ai.
8. Content automation (not individual decision-making)
The Service also automates decisions about content — quality checks on generated materials, regulatory currency checks that can update material when legislation changes, and scheduled rewrites of public documents such as this one. It automatically generates printable study guides for training organisations — one guide per unit, with teaching prose, a chapter-opener illustration generated by the Service's image pipeline, and the copyright attributions required by Australian training-package licences and New Zealand provider rules; each guide's cover carries a QR code and the address of the learning space's main learner link, and each generated guide is rendered as a file and published onto its learning space by default. When an organisation uploads an assessment document, the Service reads and structures it automatically; the reader's own notes about the document (warnings, summary, task titles and section labels) are clipped to length rather than causing the import to fail, and the document's own wording is not altered. Generated teaching packages default to the unit-mapped ('masterclass') shape, with the case-first design available as an option. Where an imported programme's module write-up stops before completion, the Service keeps the modules already written, resumes from where it stopped on re-run (matching modules by code and rewriting only those whose plan has changed) and tells the designer where it stopped. Where an organisation designs its own (non-accredited) programme, the Service helps capture, shape and specify the design and keeps its history and ownership with that organisation; the design's level and language labels accept a framework's full name, a failed design pass is reported to the designer in Capture rather than left silent, and the design desk counts only live designs; approval and revision of the design are the organisation's staff's acts. A newly created learning space is never served the generic library orientation; orientation content is aligned to that space's own course and hosts before it is shown. The Service also automates parts of programme lifecycle management: when an administrator archives a programme, the Service first compiles an impact report of where that programme is in use, and, once archived, automatically prevents new learning spaces being created on it (existing spaces and links are not taken down). Showcase learning content is automatically tailored with industry-specific material, and product update emails automatically include a spotlight on an established capability alongside recent changes. These systems act on teaching content, programmes and marketing material, not on personal information about an individual, and are listed here for completeness and honesty. Content changes made automatically are recorded in the audit log; archiving and programme approval are human administrators' decisions.
9. For training organisations: your own privacy policy
If your organisation uses Nova 5 and is an APP entity, your privacy policy must describe automated decision-making that uses personal information about your learners and staff, including processing performed by service providers such as Supahuman Limited. The provider portal generates suggested wording that reflects your workspace's actual configuration; this register is the supporting detail that wording refers to.
10. Document control
This register is reviewed and rewritten automatically as the Service changes, and every version is archived at a permanent address so a copy referenced on any date remains retrievable. The current version is always published at this address. Where an agreement references this register, the agreement's terms prevail to the extent of any inconsistency.
