Privacy Policy
Last Updated: 26/06/2026 Supersedes: Privacy Policy published at schoolzine.com/privacy-policy (last updated 23/09/2025)
1. Who this policy covers
This Privacy Policy explains how the Schoolzine group collects, uses, stores, discloses and protects personal information.
“Schoolzine“, “we“, “our” and “us” means Schoolzine Pty Ltd (ABN 79 123 804 991, Australia) and Schoolzine Limited (New Zealand), together with their subsidiaries, associated brands and products.
This policy applies to every product, platform, module and feature we provide, whether it existed when this policy was published or was released, acquired or enabled afterwards. That includes, without limitation: Schoolzine Newsletter, Schoolzine Plus, Schoolzine Websites and Website Builder, SZapp, Healthzine, Sports Tracker, Session Keeper, School-Links, School Stream, Gopha, SPARKS, Image Guardian, Enterprise, and any successor or additional product or module.
2. Whose information this policy covers
- End Users — visitors to school websites, newsletters, apps or other content powered by Schoolzine, including parents, guardians and community members.
- Customer Account Holders — school staff, diocesan staff, students or others who hold a Schoolzine login.
- Students — where a school uses a module that records student information.
- Business contacts — the billing, procurement and administrative contacts of our customers.
3. Our role
For most information we hold, the school or organisation decides what is collected and why, and we process that information on their behalf and on their instructions. If you are a parent, student or community member and want to know what your school collects or publishes, contact your school in the first instance.
We act in our own right in relation to our business contacts, billing records, account administration, security logging and our own internal operations.
4. Our legal obligations
We comply with the Privacy Act 1988 (Cth) including the Australian Privacy Principles (APPs), and the Privacy Act 2020 (NZ) including the Information Privacy Principles (IPPs) in respect of our New Zealand operations.
We align our information security practices with ISO/IEC 27001, to which our information security management system is working toward certification. We work with governing bodies on data handling and privacy to ensure safe and secure use for all users and Schoolzine staff.
5. Information collected from End Users (visitors)
When you visit a website, newsletter, app or service powered by Schoolzine, we may collect limited technical and usage information, including:
- Country or region you are located in
- Pages and URLs visited — counted in aggregate, not as detailed browsing histories
- Type of browser or device used
- Accessibility preferences detected from your system (for example text size, contrast)
- Clicks or interactions on websites or newsletters
- Time spent on school web pages or newsletters
We collect this to help schools and communities understand how their content is accessed and engaged with, so they can improve communication and keep parents and community members better informed.
Account Holders described in section 6 may collect information outside this scope using web forms, polls, surveys, bookings and similar features.
6. Information collected from Customer Account Holders
For users who hold accounts in Schoolzine systems (for example school staff, diocesan staff or students) we may collect and process:
- Identity details — name, email address, position or role, school affiliation
- Login and authentication data — username, encrypted password, session activity, single sign-on identifiers
- Usage and audit logs — date, time and details of access or changes made within the system
- User behaviour — frequency of login, newsletter sends, website updates and similar metrics
7. Module-specific collection
Individual products and modules collect additional information for the purposes of that module. What follows describes each module we currently offer. Where a module collects information beyond the categories in sections 5 and 6, that collection is described here or in the module’s own documentation, and — where it involves a new category of personal information or a new legal basis — the module is made available on an opt-in basis.
In every case, the school or organisation decides which modules to enable, what information to collect within them, and who may access it. We process that information on the school’s behalf and on its instructions.
7.1 Sports Tracker
Where schools use Sports Tracker to organise athletic carnivals or similar events, additional data may be collected to support event management, including:
-
- Date of birth — to place a student in an event specific to their age;
- Sex (male, female, other) — to place a student in a male, female, all-comers or other event within the system;
- Year level or grade — to place a student in an event specific to their year level or grade;
- Results — time, distance, weight or height recorded for an athletics event (for example the distance a discus is thrown), together with general participation records.
This data is visible only to authorised school staff. Any user, including Schoolzine staff, accessing this information has their access logged and audited. By policy, Schoolzine staff access this data only when troubleshooting an issue reported by the school.
7.2 School Stream
Where schools use School Stream to communicate with their community, we collect and process:
-
- Contact details of parents, guardians and other community members who register — name, mobile phone number and email address;
- Verification data — we send a one-time code to a phone number or email address to verify identity at registration;
- Student and family information sourced from the school’s student information system, where the school enables an integration (for example Wonde). This may include student name, parent–guardian relationships, contact details and year level, used to place recipients into the correct communication groups automatically;
- Messages sent between the school and members of its community through the app, in both directions, which are recorded and retained as part of the school’s communication record;
- Device identifiers and push notification tokens, required to deliver notifications to a registered device;
- Delivery and engagement metadata — whether a message was delivered, opened or actioned.
Registration is initiated by the community member. Integration data is provided by the school under its own authority and consent arrangements.
Message retention. Messages sent through School Stream form part of the school’s communication record and are retained for as long as the school holds an active subscription. When a school offboards, it may request a copy of its data within 90 days of the subscription ending. Once that copy is provided to the school, it passes out of Schoolzine’s control, and the retention, management and deletion of that copy becomes the school’s responsibility. Data remaining in our systems is deleted in accordance with section 12. Deletion of data will be considered at any time upon request from Schools or users.
7.3 Gopha
Gopha provides the same communication capability as School Stream to unions, associations and other member-based organisations. The categories of information collected are the same as those described in section 7.2, applied to members and their nominated contacts rather than to parents and students. References in this policy to schools, parents and students should be read as references to the relevant organisation, its members and their contacts.
7.4 Newsletters (Newsletter, eNewsletter and SZ Newsletter, including analytics)
For newsletter products we collect and process:
-
- Content uploaded by registered school staff, including text, images, video and documents;
- Recipient email addresses and subscription status;
- Delivery and engagement analytics — whether a newsletter was delivered, opened, and which links were clicked, together with the technical and usage information described in section 5.
Newsletter content is authored and published by the school. The school is responsible for holding the consents required for images and other content depicting identifiable individuals.
7.5 Websites and Website Builder (including analytics)
For website products we collect and process:
-
- Content uploaded and published by registered school staff, including text, images, video and documents;
- Visitor analytics, as described in section 5 — country or region, pages visited in aggregate, browser and device type, accessibility preferences, interactions and time on page.
As with newsletters, website content is authored and published by the school, which is responsible for the consents required for content depicting identifiable individuals.
7.6 Forms
Forms allow a school to collect information directly from its community. The school configures what a form collects. We do not determine the fields, and the information collected varies from form to form.
Depending on the school’s configuration, a form may collect contact details, responses to questions, uploaded files, and electronic signatures.
Schools are responsible for ensuring that the information they collect through Forms is collected in accordance with their own privacy policy and obligations, that they collect only what is reasonably necessary, and that appropriate notice and consent is provided to respondents.
Sensitive information. We actively discourage schools from using Forms to collect sensitive information as defined in section 6 of the Privacy Act 1988 (Cth) — including health information, information about disability, and information about racial or ethnic origin, religious beliefs or cultural background. Forms is not designed or intended as a collection point for this category of information, and schools should use a purpose-built system where such collection is necessary. Where sensitive information is nonetheless collected, we handle it in accordance with our sensitive information handling process and the controls described in section 11.2.
7.7 Session Keeper (parent–teacher interviews)
Session Keeper manages the scheduling of interviews and similar appointments. We collect and process:
-
- Staff availability — teacher names, available time slots and scheduling preferences;
- Booking records — which parent or guardian booked which slot with which staff member, and for which student;
- Attendance records — whether a booked session was attended;
- Contact details used to confirm bookings and issue reminders.
Where a user downloads a booking to a calendar application, that transfer is made to the user’s own device and application, and the information is then held by them.
7.8 Email product
For email delivery services we collect and process:
-
- Recipient email addresses and subscription status, including double opt-in confirmation status;
- Delivery outcomes — including bounces, bounce rate and suppression status;
- Engagement analytics — including open and click-through rates.
Bounce and suppression data is retained to protect deliverability and to ensure we do not continue sending to addresses that have failed or unsubscribed.
7.9 SZapp (the Schoolzine App)
For SZapp we collect and process:
-
- Account and identity information required to authenticate a user and confirm which school or schools they may access;
- Device identifiers and push notification tokens, required to deliver notifications to a registered device;
- App usage, analytics, crash reports and diagnostic logging necessary to operate, support and improve the app.
Our mobile applications use Google Firebase and Firebase Crashlytics for analytics, crash reporting and diagnostics. These services collect device and diagnostic information, including device model, operating system version, app version, crash traces and app-generated identifiers. They are listed in section 16 and are subject to the overseas disclosure position in section 14.
7.10 SZCapture
SZCapture is an application installed on a personal or school device by staff, parents or volunteers, allowing photographs to be taken for a school and sent directly to Schoolzine.
-
- Access to SZCapture requires a login.
- Photographs taken within SZCapture are transmitted directly to Schoolzine and are not written to the device’s camera roll or general photo library. Photos are encrypted on local storage so they cannot be retrieved without the app’s decryption key and the app deletes these encrypted photos upon transmission or within 24 hours, depending on what comes first. This is a deliberate design choice intended to reduce the risk of images of students being retained on personal devices.
- Location metadata (EXIF GPS) is stripped by design. Photographs captured through SZCapture do not carry the geographic coordinates at which they were taken.
- We collect the image, remaining technical metadata, and a record of the account that captured and submitted it.
The school remains responsible for authorising who may use SZCapture on its behalf, for the consents required for the photographs taken, and for compliance with its own photography and child-safety policies.
7.11 Calendar and events
Calendar and events information published by a school may be distributed to registered devices, including by push notification to the school’s app. Only events the school has published are distributed in this way.
7.12 Advertising (Australia and New Zealand only)
Where a school uses a Sponsored Package, we may sell advertising into its newsletters.
-
- Advertisers receive aggregate, de-identified reporting on impressions and clicks for their advertisement.
- No personal information about individual recipients is provided to advertisers. Advertisers do not receive names, email addresses, or any recipient-level data.
- Reporting is provided only where the underlying figures cannot reasonably be used to identify an individual. Where a report could result in identification, we withhold it.
7.13 Image Guardian
Where a school enables Image Guardian, we process images and associated metadata already held in or uploaded to the relevant Schoolzine product, in order to provide image protection and content-safety capabilities.
Processing may include:
-
- generating classifications, labels, confidence scores or flags in relation to an image;
- recording the outcome of that processing and any subsequent action taken by school staff;
- retaining audit records of who accessed, reviewed or actioned a flagged item.
Face detection. Image Guardian detects the presence and position of faces within an image as part of its classification process.
-
- It does not perform facial recognition, biometric matching or identification.
- It does not generate, store or compare biometric templates.
- It does not attempt to determine who a person in an image is, and does not compare faces against any database, watchlist or other image.
Scope of images processed. Images processed by Image Guardian are those already held in the school’s own Schoolzine account. When a school enables Image Guardian, the module is applied to that existing image library as well as to images uploaded afterwards. Image Guardian does not access images belonging to any other school or organisation.
How Image Guardian is enabled. Image Guardian is opt-in and is enabled by the school. It is not enabled by default and is not enabled by Schoolzine without the school’s instruction. Because a school may enable it at any time, schools should ensure their own collection notices and consent arrangements make clear that images provided to the school may be subject to automated content-safety processing.
Image Guardian uses AI Services as described in section 8. Images and metadata processed by Image Guardian are not disclosed to any other subprocessor.
Image Guardian is an assistive control. It supports, but does not replace, the school’s own policies, staff review, consent management and child-safety obligations. Schools remain responsible for obtaining consents and for decisions made in reliance on its outputs.
7.14 Schoolzine Enterprise
Enterprise is provided to dioceses, departments, state bodies and other parent organisations that oversee multiple schools. Where Enterprise is enabled, the parent organisation may receive a consolidated view of the analytics described elsewhere in this policy — engagement, reach and usage information — drawn from the schools within its scope.
-
- Enterprise provides aggregated analytics and reporting. It is not a mechanism for a parent organisation to read the content of a school’s communications with its community.
- Access is configured on the instruction of the parent organisation, which is responsible for holding the necessary authority in respect of the schools within its scope.
- Diocese, departments and state bodies are encouraged to disclose to schools and parents that usage and analytics data is being monitored.
7.15 The Schoolzine Plus platform and data sharing between modules
Schoolzine Plus is the platform through which many of the modules above are delivered. Where a school enables more than one module, information may be shared between those modules within the school’s own account — for example an image uploaded for a newsletter may be available for use on the school’s website, and contact records may be shared across communication modules.
Data is shared only within the school’s own account and only between modules that school has enabled. Enabling a module does not make a school’s data available to any other school or organisation, except where the school’s parent organisation has Enterprise access as described in section 7.14.
Because modules share a common platform, enabling a new module may apply it to information the school already holds in its account. Image Guardian, described in section 7.13, works this way: when a school enables it, it is applied to the school’s existing image library as well as to images added afterwards.
7.16 Future modules
We add modules and features over time. Where a new module collects or uses personal information in a way not already described in this policy, we will update this policy before or at the time the module is made available, and where the change is material we will notify affected customers in accordance with section 19.
8. Artificial intelligence
Some of our products and modules include AI-assisted features, which use artificial intelligence and machine learning to perform tasks such as classifying, detecting, describing and flagging content, in order to enable protection and content-safety capabilities.
8.1 Where the AI runs
The AI services we use for these features are hosted and operated within Australia (Sydney), in an environment controlled by Schoolzine. Data submitted to those services is processed within that Australian environment.
8.2 No onward disclosure
Data submitted to our AI services is not passed on to any other subprocessor and is not shared with any other third party, except where disclosure is required by law or necessary in the circumstances described in section 13.
8.3 No training on your data
Your data is not used to train, fine-tune, retrain or improve any third-party AI model, and is not used to train any model made available to any other customer.
8.4 Retention
Data submitted to our AI services is processed transiently. Inputs are retained only for as long as necessary to return a result. Outputs, classifications and audit metadata are retained for life of the account to support auditability and your review of decisions.
8.5 Consent and opt-in
AI-assisted features are opt-in. They are not enabled by default. Where a school enables a module or feature that uses AI services, the school consents to the processing described in this section on behalf of its organisation, and is responsible for making any disclosures to, and obtaining any consents from, its own community that its privacy obligations require.
If you are a parent, student or community member and have questions about whether your school has enabled an AI-assisted feature, contact your school.
8.6 Our staff and systems
Our staff and systems operate in accordance with our AI Use Policy, which governs how our people may use artificial intelligence in connection with customer data, including restrictions on the use of external or consumer AI tools. Access to AI services and to the data they process is logged and auditable, consistent with our ISO/IEC 27001 certified information security management system.
8.7 Accuracy and human oversight
AI outputs are probabilistic and may be incomplete or incorrect. They support human decision-making and are not a substitute for it. No decision affecting a student, staff member or community member should be made on the basis of an AI output alone.
8.8 Changes
If we materially change how our AI services process personal information — including the hosting location, the categories of data processed, or the positions stated in 8.2 and 8.3 — we will notify affected customers at least 30 days before the change takes effect.
9. How information is used
We use personal information to:
- provide, maintain and improve Schoolzine services;
- enable schools to manage their communication, events, bookings and content delivery;
- operate the system as intended (for example placing students in the correct sporting events based on date of birth);
- provide AI-assisted protection and content-safety features where enabled, as described in section 8;
- ensure system security, integrity and auditing;
- provide support and training;
- administer accounts, billing and our customer relationship;
- meet legal and regulatory obligations.
We do not sell personal information. We do not use personal information for unrelated secondary purposes without consent, unless required or authorised by law.
10. Legal grounds for processing
We collect and process personal information only where reasonably necessary for the operation of our services. The main grounds are:
- Contractual necessity — to deliver services contracted by schools and account holders.
- Legitimate interests — to maintain security, monitor usage, and improve platform reliability and performance.
- Consent — where you actively provide personal information, for example subscribing to a newsletter, completing a survey, registering for an event, or where a school opts in to a module.
11. Student data and high-sensitivity information
11.1 Student information
Several modules collect additional personal information about students to support school operations — for example date of birth, sex and year level in Sports Tracker, family relationships in School Stream, and images across newsletters, websites, SZCapture and Image Guardian.
Much of this information is not “sensitive information” as defined in the Privacy Act 1988 (Cth). However, because it relates to students and can be combined with other identifiers, we treat all student information as high sensitivity:
-
- access is limited to authorised school staff, and every access is logged for audit purposes;
- Schoolzine staff access student information only where necessary to troubleshoot an issue reported by the school, and that access is logged and audited;
- we apply heightened security controls consistent with ISO/IEC 27001.
We do not knowingly collect personal information directly from children. Where information about a student is held, it is provided by, and held on behalf of, their school.
11.2 Sensitive information
Some information may meet the definition of sensitive information under section 6 of the Privacy Act 1988 (Cth) — including health information, information about disability, and information about racial or ethnic origin, religious beliefs or cultural background.
We do not require or request sensitive information in order to provide our services. However, where a school configures a Form (section 7.6) or other free-form field to collect such information, we will hold it on that school’s behalf.
Where sensitive information is collected:
-
- the school is responsible for ensuring it has a lawful basis to collect it, including the consent required under APP 3.3, and for providing appropriate collection notices to respondents;
- we hold it under the same heightened controls described in section 11.1;
- we do not use it for any purpose other than providing the service to the school.
Schools should collect only the information reasonably necessary for their purpose, and should consider whether sensitive information needs to be collected through our platform at all.
12. Storage, security and retention
Personal data is stored securely and protected with technical, administrative and physical safeguards consistent with ISO/IEC 27001.
- Customer content and account data is stored within secure data centres in Australia.
- Data at rest is protected using disk encryption.
- Data in transit is protected using TLS.
- Regular backups are performed.
Some supporting services listed in section 16 — including mobile app diagnostics, support ticketing and monitoring — process limited information outside Australia. This is described in section 14.
Retention. We retain personal information for as long as it is needed for the purposes described in this policy, or as required by law.
Following cancellation of a subscription, customer content remains available for three months after the subscription end date, after which the account and its content are permanently deleted. During that period a school may request a copy of its data. Once a copy is provided to the school, its retention, management and deletion become the school’s responsibility.
Audit logs and records we are required to keep for legal, security or accounting purposes are retained for the applicable statutory period.
13. Disclosure
We may disclose personal information:
- to subprocessors listed in section 16, to the extent necessary to deliver our services;
- to your school or organisation, where you are one of its users or community members;
- where required or authorised by law, including in response to a warrant, subpoena, court order, regulatory request or lawful direction;
- to police, child protection bodies, regulators or government agencies where we reasonably believe it necessary to investigate unlawful activity, serious misconduct, misuse of our products, security incidents, fraud, abuse or threats to safety;
- to protect the rights, safety, property or security of Schoolzine, customers, users, students, parents, staff or the public;
- to professional advisers under a duty of confidentiality, or in connection with a sale or restructure of our business, subject to equivalent protections.
14. Overseas disclosure
Our primary hosting is in Australia. Some subprocessors listed in section 16 store or transit data outside Australia and New Zealand, including:
- Google (Firebase and Crashlytics) — mobile app diagnostic and analytics data, processed primarily in the United States;
- HubSpot — support ticket and customer contact data, processed in the United States and European Union;
- Grafana Cloud and 3CX — technical monitoring metadata and call metadata.
Where that occurs, we take reasonable steps to ensure the recipient handles the information in a manner consistent with the APPs and, where applicable, the IPPs, including through contractual commitments, encryption, TLS and access controls.
Data submitted to our AI services is not disclosed overseas — see section 8.
15. Data breach notification
If we become aware of a data breach that is likely to result in serious harm, we will notify affected customers without undue delay and will assist them to meet their own obligations under the Notifiable Data Breaches scheme (Part IIIC, Privacy Act 1988 (Cth)) or Part 6 of the Privacy Act 2020 (NZ). Where required, we will also notify the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner.
16. Third-party subprocessors
The following providers support delivery of Schoolzine services. They process only the minimum necessary personal data, under contractual agreements requiring them to process data only on our behalf.
| Provider | Purpose | Data types processed | Data location(s) | ISO 27001 | SOC 2 |
|---|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and secure data storage | Account data, content data, technical logs | Primarily Australia | ✅ | ✅ |
| Cloudflare | Security and performance (DDoS, WAF, TLS, caching) | Network traffic, IP addresses, device/browser info | Global transit, AU primary | ✅ | ✅ |
| SparkPost | Bulk email delivery for newsletters and notifications | Recipient email addresses, delivery and engagement metadata, message content | Australia | ✅ | ✅ |
| Kudosity, Sinch, Twilio | SMS delivery for School-Links, verification codes and notifications | Mobile numbers, message content, delivery status | Austraila and New Zealand | ✅ | ✅ |
| Apple (APNs) / Google (FCM) | Push notification delivery to registered devices | Device tokens, notification payload | Global | n/a | n/a |
| Wonde | Student information system integration, where enabled by the school | Student and parent names, contact details, relationships, year level | Australia | ✅ | ✅ |
| Google (Firebase, Firebase Crashlytics) | Mobile app analytics, crash reporting and diagnostics | Device model, OS and app version, crash traces, app-instance identifiers, app usage events | Primarily USA | ✅ | ✅ |
| Xero | Billing and accounting | Customer contact details, invoice and payment info | Australia / NZ | ✅ | ✅ |
| HubSpot | Ticket tracking, customer support and sales | Customer contact info, support tickets, usage data | USA / EU (with safeguards) | ✅ | ✅ |
| Grafana Cloud | System monitoring and log processing | Technical metadata (no sensitive personal data) | Global | ✅ | ✅ |
| 3CX | VoIP telephony for support and customer calls | Caller ID, call metadata (recordings only where explicitly enabled) | EU / Global | ✅ | ✅ |
| Microsoft 365 | Internal communication, email and file storage for Schoolzine | Staff emails, support documents, internal files | Australia and global replication | ✅ | ✅ |
- All subprocessors are contractually bound to process data only on behalf of Schoolzine.
- We require each subprocessor to maintain ISO 27001 and/or SOC 2 compliance where available.
- Data may be stored or transit internationally, but safeguards including encryption, TLS and access controls are in place to ensure compliance with the APPs and IPPs.
- Data processed by our AI services is not passed to any other subprocessor — see section 8.2.
- We will give customers at least 30 days’ notice before adding a new subprocessor that processes customer data.
17. Access, correction and deletion
You may request access to, correction of, or deletion of the personal information we hold about you at any time.
- End Users — contact your school regarding information it collects and publishes. For questions about the information described in section 5, contact Schoolzine Support.
- Account Holders — contact Schoolzine Support.
We will respond within a reasonable timeframe and in accordance with the Privacy Act 1988 (Cth) or Privacy Act 2020 (NZ) as applicable. Where we hold information on behalf of a school, we will refer your request to that school and assist them to respond.
18. Complaints
If you believe we have breached the Australian Privacy Principles or the New Zealand Information Privacy Principles, contact us and we will investigate promptly.
If you are not satisfied with our response, you may contact:
- Australia — Office of the Australian Information Commissioner (OAIC), oaic.gov.au, 1300 363 992
- New Zealand — Office of the Privacy Commissioner, privacy.org.nz, 0800 803 909
19. Changes to this policy
We may change this Privacy Policy from time to time — for example if the law changes, if we release a new product or module, or if we change our business in a way that affects personal data protection.
Where a change is material, we will notify customers at least 30 days before it takes effect. The current version and its date are always published at schoolzine.com/privacy-policy.
20. Contact
To contact us regarding your personal data and data protection, including to make a subject access request:
Schoolzine Pty Ltd — ABN 79 123 804 991 Schoolzine Limited (New Zealand) — NZBN 9429042341369
Phone: 1300 795 503 Email: dpo@schoolzine.com or support@schoolzine.com Post: PO Box 7151, Sippy Downs, Queensland 4556, Australi