Legal

Privacy Policy

How Orca collects, uses, stores and handles personal information in connection with the Orca activity planning platform and website.

Last updated: [DATE]

1. About this policy

[Company Name] Pty Ltd (ABN [XX XXX XXX XXX]) ("Orca", "we", "us", "our") operates the Orca activity planning platform ("Platform") and website at [URL] ("Website"). We are committed to handling personal information responsibly and in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have in relation to it. It applies to schools and educational organisations that subscribe to Orca ("Schools"), as well as to school staff, students, parents and guardians whose information is managed within the Platform, and to visitors to our Website.

Orca is primarily a business-to-business service. Much of the personal information we hold is provided to us by Schools as part of setting up and operating the Platform — for example, staff and student records uploaded by a school administrator. However, Orca also enables Schools to collect information directly from users (including staff, students and parents) through event forms. In these cases, the personal information is submitted directly by the individual. In all cases, the School determines what information is collected and for what purpose. The School is the data controller for that information. We act as a data processor, handling personal information only to deliver the service the School has contracted us to provide.

If you have questions about this policy or how we handle your information, please contact us at hello@orca.school.

2. What personal information we hold

The personal information we hold falls into the following categories, depending on how the Platform is configured by each School.

School and administrator information

When a School subscribes to Orca, we collect information about the organisation and its nominated administrators, including:

  • School name, address and contact details
  • Name, email address and role of the school administrator and other authorised account contacts
  • Billing and subscription details

Staff information

Schools provide us with information about staff who will use the Platform, which may include:

  • Name and email address
  • Profile photo
  • Role within the Platform (for example, admin, compliancemanager, staff, student, or parenth)
  • Login records and activity within the Platform

Student information

Schools provide us with information about students in connection with activity planning and management. This may include:

  • Name and email address
  • Profile photo
  • Cohorts (year groups or classes)
  • Parent relationships
  • Activity involvement
  • Attendance and absence records associated with activities
  • Student alerts (see below)
  • Login records and activity within the Platform

Parent information

Schools provide us with information about parents in connection with activity planning and management. This may include:

  • Name and email address
  • Profile photo
  • Student relationships
  • Activity involvement
  • Login records and activity within the Platform

Student alerts

Orca allows schools to associate alerts with individual students to support safe and informed activity management. Alerts may include:

  • Medical alerts (for example, allergies, chronic conditions, medication requirements)
  • Behavioural or wellbeing notes relevant to participation in activities
  • Absence or exemption records
  • Any other alert type configured by the School

These alerts are entered and managed entirely by the School. We store and display this information within the Platform solely to support the School's activity management and duty of care responsibilities. Alert information is not used by us for any other purpose and is not shared with third parties other than our infrastructure sub-processors for storage purposes. Access to alert data by Orca staff is limited to what is necessary for the operation, maintenance and troubleshooting of the Platform, as described in Section 4.

Because alerts may include health information and other sensitive information (see Section 7), schools are responsible for ensuring appropriate consents have been obtained from parents or guardians before entering this type of information into the Platform.

Parent and guardian information

Where a School provides contact details for parents or guardians in connection with student activities, this may include name, email address and phone number. This information is used only for the purposes configured by the School within the Platform.

Event forms and user-submitted responses

Orca allows teachers and coordinators to attach forms to events as a way of collecting information from staff, students or parents. Forms may be used for a range of purposes at the School's discretion — for example, collecting permission responses, dietary preferences, emergency contact details, or any other information relevant to an activity or excursion.

Form responses may include:

  • Free text answers to questions set by the School
  • File uploads (for example, signed permission documents, identification, or supporting materials)
  • Any other information that a respondent chooses to provide in answer to a question

Because form content is determined entirely by the School, we cannot predict or limit what categories of information may be submitted through forms. It is possible that form responses will contain sensitive information — for example, health details, dietary requirements or other personal circumstances — depending on the questions a teacher chooses to ask.

Form responses are stored within the Platform and are accessible only to authorised staff at the relevant School. We store this information solely to deliver the forms feature and do not use form response data for any other purpose. Schools are responsible for ensuring that any form questions are appropriate, that respondents have been informed about how their answers will be used, and that any necessary consents have been obtained — particularly where questions may elicit sensitive information or where forms are directed at minors.

Automatically collected information

When you access the Website or Platform, we automatically collect certain technical information including IP address, browser type and version, pages visited and timestamps. This information is used for security monitoring, access logging and improving the performance of the Platform.

3. How we collect personal information

Personal information enters the Platform through two main channels.

The first is information provided by Schools. Schools configure the Platform and upload staff and student records as part of administering the service. This includes account setup, student enrolments, alert information and other administrative data. In these cases the School is providing information on behalf of individuals, and the School is responsible for ensuring it has a lawful basis for doing so.

The second is information submitted directly by users. When a School attaches a form to an event, staff, students or parents may submit responses directly through the Platform. These responses — which may include free text, uploaded files or any other content a respondent provides — are collected directly from the individual completing the form. The content of these forms is determined by the School, not by us.

We also collect information:

  • From staff users, when they register an account, log in or interact with the Platform
  • Automatically, through system and access logs when the Platform or Website is used

Where a School provides information about individuals — including students who are minors — that School is responsible for ensuring it has obtained all necessary consents and has a lawful basis for sharing that information with us.

Where a School creates a form that will be completed by minors or that asks questions likely to elicit sensitive information, the School is responsible for ensuring appropriate consent has been obtained from parents or guardians before the form is issued.

4. Why we use personal information

We use the personal information we hold for the following purposes:

We do not use personal information — and in particular we do not use student information — for advertising, marketing to students, commercial profiling or any purpose unrelated to delivering the Platform to Schools.

We do not sell personal information to any third party under any circumstances.

Where we send marketing communications to school administrators about Orca features or updates, we do so in accordance with the Spam Act 2003 (Cth) and provide an opt-out mechanism in every communication.

5. How we share personal information

We do not share personal information with third parties except in the following circumstances:

Sub-processors: We engage a small number of third-party providers to help us deliver the Platform. These providers act as our sub-processors and may process personal information as part of delivering their services to us. They are listed in Section 6. We require all sub-processors to maintain appropriate data protection standards and they are not permitted to use personal information for any purpose other than delivering services to us.

Professional advisers: We may share information with our lawyers, accountants or auditors where necessary and subject to confidentiality obligations.

Business transfers: In the event of a sale or transfer of our business or assets, personal information may be transferred to a successor entity. See Section 13 for details.

Legal requirements: We may disclose personal information where required by law, court order, or lawful request by a government or regulatory authority. Where legally permitted, we will notify the affected School before making such a disclosure.

Safety: We may disclose personal information where we reasonably believe it is necessary to prevent or lessen a serious and imminent threat to the life, health or safety of any person.

We do not disclose personal information to any other third parties without your consent.

6. Sub-processors

The following third-party providers process personal information on our behalf as part of delivering the Platform. All data is stored and processed in Australia unless otherwise noted.

Provider Location Purpose Data processed
[Managed Hosting Provider] Australia Managed server hosting, server-level security, automated backups and infrastructure management All data stored and processed on the Platform
[Cloud Infrastructure Provider] Australia (Sydney) Underlying cloud compute and storage infrastructure All data stored on the Platform
Postmark (Wildbit LLC) USA Transactional email delivery (account notifications, system alerts, service emails) Name and email address of recipients only

The names of our infrastructure and hosting providers are available to Schools on request as part of security due diligence.

Note on Postmark: Postmark processes name and email address solely to deliver transactional emails on our behalf. This is the only personal data transferred outside Australia. Postmark holds SOC 2 Type II certification and does not use recipient data for any other purpose. Details are available at postmarkapp.com/security. By using the Platform, Schools consent to this limited transfer for transactional email purposes.

We will provide Schools with at least 30 days' notice of any changes to our sub-processors.

7. Sensitive information

Sensitive information — as defined under the Privacy Act 1988 (Cth) — may be collected through the Platform in two ways.

Through student alerts: Schools may associate alerts with individual students to support duty of care and safe activity management. Alerts may include health information such as medical conditions, allergies or medication requirements, as well as behavioural or wellbeing notes. This information is entered and managed entirely by the School.

Through event forms: Because form content is determined by the School, it is possible that form responses submitted directly by staff, students or parents will contain sensitive information. For example, a teacher may ask about dietary requirements, health conditions, cultural considerations or other personal circumstances relevant to an activity. We cannot predict or control what sensitive information may be submitted through forms, as this depends entirely on the questions the School chooses to ask.

In both cases, we store sensitive information only because it has been provided through the Platform for the purpose of supporting the School's activity management. We do not use sensitive information for any other purpose, and we do not share it with any party other than our infrastructure sub-processors for storage.

Schools are responsible for:

  • Ensuring that sensitive information — whether entered as alerts or collected through forms — is gathered only where there is a clear and legitimate purpose
  • Obtaining explicit consent from parents or guardians before collecting sensitive information about students, whether through administrative entry or through forms directed at students or parents
  • Framing form questions in a way that is appropriate to the age of respondents and the nature of the activity
  • Managing access to sensitive information within the Platform using Orca's role-based access controls

If you wish to withdraw consent for sensitive information to be held, please contact your School administrator in the first instance. The School may then contact us to action the request.

8. Data storage and security

All personal information collected through Orca is stored and processed in Australia. We do not transfer data outside Australia except as described in Section 6 in relation to Postmark.

We take reasonable technical and organisational steps to protect personal information from misuse, interference, unauthorised access, modification, disclosure and loss. These measures include:

  • TLS encryption for all data transmitted between users and the Platform
  • Encryption of data at rest at the infrastructure level
  • Role-based access controls ensuring users can only access data relevant to their role
  • Automated backups on a regular schedule
  • Server-level security managed by our certified hosting provider, including firewalls, automated patching and intrusion monitoring

Our hosting infrastructure is provided by certified third-party providers holding independently audited security certifications including SOC 2 Type II and ISO 27001. Full details are available on our Security page.

While we work hard to protect your personal information, no method of electronic storage or internet transmission is completely secure. We cannot guarantee absolute security, but we are committed to managing and minimising security risks on an ongoing basis.

9. How long we keep personal information

We keep personal information for as long as is necessary to fulfil the purposes for which it was collected, and to meet our legal, contractual and reporting obligations.

Our standard retention periods are:

  • Student and staff records: 7 years from the date the relevant School's subscription ends, or as otherwise required by applicable education law or institutional policy
  • School account and billing records: 7 years from account closure, in line with standard Australian record-keeping requirements
  • Security and access logs: [12 months], after which they are deleted or anonymised

When a School's subscription ends:

  • Schools may request a full export of their data before or at the time of account closure
  • Personal information is deleted from live systems within 30 days of account closure
  • Backup copies are purged within 90 days of account closure

Schools may request earlier deletion of specific records at any time by contacting us using the details at the end of this policy.

10. Accessing and correcting your personal information

Under the Privacy Act 1988 (Cth), you have the right to request access to the personal information we hold about you, and to ask us to correct information that is inaccurate, incomplete or out of date.

Because Orca is a school-administered platform, personal information about staff and students is held on behalf of the School as data controller. We recommend that individuals contact their School administrator in the first instance. Schools can then contact us to action requests on their users' behalf.

To make a request directly to us, please contact hello@orca.school with your name and contact details. We may need to verify your identity before actioning a request. We will respond within a reasonable timeframe and in any event within 30 days.

There is no charge for making an access or correction request. In some circumstances we may be unable to provide access to all information we hold — for example, where doing so would unreasonably impact the privacy of another person — and we will explain our reasons if this occurs.

11. Data breach notification

We take data breaches seriously. If we become aware of a data breach involving personal information that is likely to result in serious harm, we will:

  • Act promptly to contain and assess the breach
  • Notify affected Schools without undue delay and within 48 hours of becoming aware of the breach
  • Provide details of the nature of the breach, the information affected, the likely consequences, and the steps we are taking in response
  • Where required under the Notifiable Data Breaches scheme, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals

Schools, as data controllers, are responsible for determining whether to make notifications to individuals under the NDB scheme, and we will cooperate fully with Schools in that process.

12. Cookies

Our Website uses session cookies that are necessary for standard website functionality. We do not use advertising cookies, behavioural tracking cookies or cookies that identify individual users across third-party websites.

The Platform uses session cookies required for authenticated access and core platform functionality. No third-party advertising or tracking cookies are placed within the Platform.

You can configure your browser to refuse or delete cookies, though this may affect your ability to use certain features of the Website.

13. Change of control

If there is a change of control in our business, or a sale or transfer of our business or assets, personal information held in our systems may form part of the assets transferred. Any such transfer would be made subject to confidentiality obligations and the incoming party would be required to handle personal information in a manner consistent with this policy and applicable Australian privacy law. We would notify affected Schools of any such change to the extent that we are legally able to do so.

15. Changes to this policy

We may update this privacy policy from time to time to reflect changes to the Platform, our practices, or applicable law. When we make material changes, we will notify Schools by email and update the date at the top of this page. We encourage you to review this policy periodically.

16. Complaints

If you have a concern about how we have handled your personal information, please contact us in the first instance using the details below. We will acknowledge your complaint promptly and work to resolve it within a reasonable timeframe.

If you remain unsatisfied after contacting us, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Website: www.oaic.gov.au
Phone: 1300 363 992

17. Contact us

For questions about this privacy policy, to exercise your privacy rights, or to make a complaint, please contact:

Privacy Officer

[Company Name] Pty Ltd

ABN [XX XXX XXX XXX]

[Address]

Email: hello@orca.school

Get Started

Ready to bring order
to school life?

See how Orca transforms activity management at your school. Book a personalised demo and we'll walk you through exactly how Orca fits your workflows.

What you get with Orca

One centralised platform for every school activity
Configurable approval workflows aligned to your school's policies
Automated digital risk assessments — PDF generated from your templates
Complete audit trail and revision history for every event
Community calendar, parent permissions, and messaging built-in
API integration with your Student Information System
Personalised onboarding and ongoing support for your team
Personalised demos available now