1. Who this policy applies to
This policy explains how the Provider collects, holds, uses, discloses, and protects personal information when providing the Service to schools and school systems. It applies to:
- school staff, administrators, contractors, and support personnel who use the Service;
- students whose information is entered, imported, synced, or generated in the Service;
- parents, carers, guardians, and emergency contacts whose information is used for school communications;
- key/access holders, where the keys module is used;
- prospective customers, billing contacts, and support contacts; and
- visitors to Provider websites and product login pages.
Where the Service is supplied to a school, the school usually decides what student, staff, parent, timetable, behaviour, support, and communication information is placed in the Service. In that situation the Provider acts as a service provider handling School Data on the school’s instructions, subject to the School Subscription Agreement and Data Processing Agreement.
2. Our privacy roles
School Data means personal information submitted to, imported into, synced with, or generated in the Service for a school customer — student records, staff records, parent/carer contacts, assessments, levels, timetable data, support allocations, messaging records, keys/access records, and related audit logs. For School Data: the school remains responsible for deciding whether it may collect and use the information and for the notices, permissions, and consents its policies and the law require; the Provider handles School Data only to provide, secure, support, and improve the Service, and otherwise as agreed with the school; and access or correction requests are usually referred to the relevant school unless the Provider is legally required to respond directly.
The Provider also handles personal information for its own business operations (account administration, billing, support, security monitoring, website analytics, sales communications, and legal compliance). For that information the Provider is responsible for its own handling practices.
3. Personal information we collect and hold
The Service is designed for school operations and may handle the following categories of personal information, depending on the modules a school enables:
| Category | Examples |
|---|---|
| School and account data | school name, campus, subscription details, billing email, principal/administrator contacts, module settings, support tickets |
| Staff user data | name, school email, role, access profile, year group or class responsibilities, authentication metadata, notification preferences, audit activity |
| Student data | name, year group, class/form, school record numbers, timetable identifiers and entries, structured support needs/adjustments, funding/NCCD context, SLSO allocations, delivered-support records, follow-up actions; and, where the Levels module is enabled, assessment records, daily outcomes, levels, goals, and score changes. Vantage does not record diagnosis or health information. |
| Parent/carer data | name, email, phone number, relationship to student, communication consent status, message delivery logs |
| Support and wellbeing-adjacent data | structured support needs/adjustments, funded support hours, NCCD adjustment level, SLSO allocations and preferences, delivered-support records, follow-up notes, parent contact status; behaviour support levels and scoring criteria where the Levels module is enabled. No diagnosis or health records are stored. |
| Keys/access module data | access holder name, email, role, key/item assignments, audit campaign responses, declaration records |
| Communications data | email, SMS, push, and in-app notification metadata; message templates; delivery status; unsubscribe/opt-out information where applicable |
| Integration data | timetable identifiers, integration status, sync logs, encrypted API credentials or tokens, webhook metadata |
| Technical and security data | IP address, browser/device information, session data, rate-limit events, audit logs, server logs, error reports, security events, cookie/local-storage identifiers |
| Support and sales data | enquiries, demos, implementation notes, training records, contract contacts, invoices, payment administration records |
Some School Data may be sensitive in context because it relates to children, educational progress, support needs and NCCD funding (which concern students with disability), wellbeing-adjacent indicators, family contact arrangements, or safety operations. Vantage captures support needs as structured adjustments, not diagnosis or health records. Schools should only enter information that is necessary, accurate, and authorised for school functions.
Personal information is held in a managed PostgreSQL database in Australia (see Security and Overseas disclosure).
4. How we collect information
We collect information directly from school staff and authorised users; from school systems the school connects to the Service (timetable, identity, or administration systems); from CSV imports, school configuration, and implementation workbooks supplied by the school; from parents/carers or key holders using school-authorised links or forms; automatically from use of the Service (logs, audit trails, device information, security events); from third-party services used to deliver the Service (authentication, hosting, email, SMS, push, error monitoring); and from direct communications with the Provider (support, billing, sales). The Provider does not intentionally collect student information directly from children for marketing purposes.
5. How we use information
We use personal information to: provide and administer the Service for the school; authenticate users and maintain role-based access control; create and manage school, staff, student, parent/carer, timetable, assessment, level, roster, and keys/access records; generate dashboards, reports, follow-up lists, message previews, level cards, and audit campaigns requested by the school; send school-authorised operational communications; sync with school-authorised integrations; provide support, onboarding, training, billing, and account administration; monitor reliability, troubleshoot, prevent abuse, enforce rate limits, investigate security events, and maintain audit trails; comply with legal obligations and school instructions; produce aggregated or de-identified operational insights that do not identify an individual or school unless authorised; and improve the Service consistently with school instructions and this policy.
6. What we do not do with School Data
Unless expressly agreed in writing with the school, the Provider does not: sell School Data; use student, parent/carer, or staff data for third-party advertising; use School Data to train public or third-party foundation AI models; disclose School Data to another school; contact parents or students for Provider marketing using school contact lists; make disciplinary, suspension, funding, welfare, or educational placement decisions on behalf of the school; or allow Provider personnel to access School Data unless access is needed for support, security, implementation, legal compliance, or another authorised purpose.
7. Communications
The Service supports email, SMS, and push notifications, which may include staff onboarding, scoring reminders, parent/carer updates, keys/access audit messages, roster notifications, and other school operational messages. Schools are responsible for confirming each communication is lawful and appropriate, including any consent, notice, sender-identification, opt-out, or recordkeeping requirements. The Provider will not use school communication lists for unrelated Provider marketing.
8. Disclosure of information
We may disclose personal information to: the school customer and its authorised users; parents, carers, guardians, students, or key holders where the school configures or authorises that access; service providers that host, process, transmit, secure, or support the Service; integration providers authorised by the school; professional advisers, insurers, auditors, and legal representatives; regulators, courts, law enforcement, or government agencies where legally required or reasonably necessary; and another entity involved in a merger, acquisition, financing, reorganisation, or sale of the Provider’s business, subject to confidentiality and applicable law.
Current service providers (sub-processors) include Supabase (database/authentication/storage), Vercel (hosting and platform), Resend (email), Twilio (SMS, if enabled), Upstash (rate limiting/cache, if enabled), Sentry (error monitoring), and Google Analytics (public website analytics only, not loaded inside the authenticated application). The current, authoritative list — with purpose, data types, country, and lawful basis — is in our Sub-Processor list.
9. Overseas disclosure and storage
Primary data residency. School Data is held in a managed PostgreSQL database hosted in Australia (Sydney region). It is not routinely stored outside Australia.
Overseas recipients. To deliver the Service the Provider uses sub-processors, some located overseas, so the Provider is likely to disclose certain personal information overseas — principally to the United States — in these limited ways:
- application hosting, edge delivery, and request/diagnostic metadata (United States-based provider);
- error and performance monitoring — diagnostic data with personal information minimised (United States or European Union);
- transactional email and, if enabled, SMS — recipient address and message content (United States-based providers);
- public website analytics — page-view, device/browser, referrer, and approximate-location analytics for the public marketing site only (Google Analytics);
- rate-limiting metadata; and
- browser push notifications, which route through the recipient’s browser-vendor push service (location depends on the user’s browser vendor).
The authoritative list of sub-processors — each with its purpose, data categories, and hosting country/region — is in our Sub-Processor list. Overseas disclosure is limited to the operational categories above (metadata, contact details, message content, diagnostics); the primary student-record database remains in Australia. Before disclosing personal information to an overseas recipient, the Provider takes the reasonable steps required by Australian Privacy Principle 8 (including contractual controls, due diligence, data minimisation, and security requirements).
10. Security
The Provider uses administrative, technical, and organisational safeguards to protect personal information against misuse, interference, loss, and unauthorised access, modification, or disclosure. These include Supabase authentication and role-based application access; school-level data separation and row-level security in the database; server-side privileged access restricted to backend operations; audit logging for sensitive administrative and student-data actions; HTTPS/TLS in transit; AES-256 encryption at rest and encrypted storage of integration credentials; Content Security Policy and browser security headers; rate limiting for sensitive endpoints; CSRF controls for public forms; environment-secret management; error monitoring; and access restrictions for Provider personnel. More detail is on the Security page. No system is perfectly secure; if we become aware of a suspected or confirmed data breach we act under our Data Breach Response Plan and applicable notification requirements.
11. Retention and deletion
School Data is retained for the period agreed with the school, required by law, or needed to provide the Service. Schools can request export or deletion of School Data under the School Subscription Agreement and Data Processing Agreement. The Provider may retain limited logs, backups, invoices, security records, and legal records for legitimate business, security, archival, dispute, or compliance purposes; where deletion from backups is not immediately practicable, the data is protected and removed on normal backup expiry. When information is no longer needed and is not legally required, the Provider takes reasonable steps to delete, de-identify, or place it beyond use.
12. Access and correction
Students, parents, carers, staff, and other individuals may request access to or correction of personal information held by the Provider, free of charge. For School Data, requests should usually be made to the relevant school, because the school controls the record and can verify identity, family authority, student maturity, and policy requirements; if the Provider receives such a request it may refer the requester to the school or notify the school, unless legally required to respond directly. For Provider account, billing, support, or website data, contact admin@vantageschool.com.au. The Provider may need to verify identity before responding, and aims to resolve requests within three months.
13. Complaints
Privacy complaints can be sent to the Privacy Officer, VANTAGESCHOOL PTY LTD, 71 Wardell Road, Lewisham NSW 2049, admin@vantageschool.com.au. The Provider will acknowledge a complaint within a reasonable period, investigate it, and aim to respond within 30 days unless the matter is complex or another timeframe is required by law or contract. If a complaint relates to School Data, the Provider may need to work with the relevant school. Individuals may also contact the Office of the Australian Information Commissioner (OAIC), a state privacy regulator, or another applicable authority.
14. Children and young people
The Service is intended for use by schools and authorised school communities, and the Provider recognises that children and young people need additional privacy protection. The Provider handles student information only for school-authorised purposes; avoids direct marketing and targeted advertising to students; keeps student-facing and parent/carer-facing access limited to the purpose authorised by the school; supports schools in responding to access, correction, deletion, or complaint requests; and reviews this policy and product settings against the Australian Children’s Online Privacy Code as it comes into force.
15. Analytics, reports, and automated decision support
The Service may generate dashboards, alerts, risk indicators, scoring summaries, level-progression views, follow-up lists, and operational recommendations from School Data. These are decision-support tools for authorised school staff — they are not intended to make final decisions about a student, staff member, parent/carer, or key holder without human review by the school. Schools remain responsible for checking context, accuracy, fairness, and policy requirements before acting. The Provider will review this section before the December 2026 automated-decision-making privacy requirements take effect and whenever materially automated decision features are added.
16. Cookies and local storage
The Service uses cookies, browser storage, and similar technologies for authentication, security, session continuity, admin emulation, CSRF protection, push-notification prompts, PWA installation prompts, and interface preferences. The Service does not use advertising cookies. More detail is in the Cookie and Local Storage Policy, available on request from admin@vantageschool.com.au.
17. Direct marketing
The Provider may contact school business contacts about product updates, contract administration, training, service changes, or related services, complying with applicable spam and electronic-marketing laws. The Provider will not use student, parent/carer, or staff School Data for unrelated marketing.
18. Changes to this policy
The Provider may update this policy when laws, product features, sub-processors, or information-handling practices change. Material changes are notified to school customers in advance — at least 30 days before they take effect — by email, in-product notice, or contract notice, except where an earlier effective date is required by law or to address a security risk. The current version date is shown at the top of this policy, and prior versions are available to customers on request. Schools are responsible for deciding whether they need to notify staff, students, parents, carers, or other community members.