Legal

Privacy Policy

How Orca collects, uses, stores and handles personal information in connection with the Orca activity planning platform and website.

Last updated: [DATE]

1. About this policy

Lennix Pty Ltd (ABN 36 156 631 631) (“Orca”, “we”, “us”, “our”) operates the Orca activity planning platform (“Platform”) and website at [URL] (“Website”). We are committed to handling personal information responsibly and in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have in relation to it. It applies to schools and educational organisations that subscribe to Orca (“Schools”), as well as to school staff, students, parents and guardians whose information is managed within the Platform, and to visitors to our Website.

Orca is primarily a business-to-business service. Much of the personal information we hold is provided to us by Schools as part of setting up and operating the Platform — for example, staff and student records uploaded by a school administrator. However, Orca also enables Schools to collect information directly from users (including staff, students and parents) through event forms. In these cases, the personal information is submitted directly by the individual. In all cases, the School determines what information is collected and for what purpose. The School is the data controller for that information. We act as a data processor, handling personal information only to deliver the service the School has contracted us to provide.

If you have questions about this policy or how we handle your information, please contact us at hello@orca.school.

2. What personal information we hold

The personal information we hold falls into the following categories, depending on how the Platform is configured by each School.

School and administrator information

When a School subscribes to Orca, we collect information about the organisation and its nominated administrators, including:

  • School name, address and contact details
  • Name, email address and role of the school administrator and other authorised account contacts
  • Billing and subscription details

Staff information

Schools provide us with information about staff who will use the Platform, which may include:

  • Name and email address
  • Profile photo
  • Role within the Platform (for example, admin, compliancemanager, staff, student, or parenth)
  • Login records and activity within the Platform

Student information

Schools provide us with information about students in connection with activity planning and management. This may include:

  • Name and email address
  • Profile photo
  • Cohorts (year groups or classes)
  • Parent relationships
  • Activity involvement
  • Attendance and absence records associated with activities
  • Student alerts (see below)
  • Login records and activity within the Platform

Parent information

Schools provide us with information about parents in connection with activity planning and management. This may include:

  • Name and email address
  • Profile photo
  • Student relationships
  • Activity involvement
  • Login records and activity within the Platform

Student alerts

Orca allows schools to associate alerts with individual students to support safe and informed activity management. Alerts may include:

  • Medical alerts (for example, allergies, chronic conditions, medication requirements)
  • Behavioural or wellbeing notes relevant to participation in activities
  • Absence or exemption records
  • Any other alert type configured by the School

These alerts are entered and managed entirely by the School. We store and display this information within the Platform solely to support the School’s activity management and duty of care responsibilities. Alert information is not used by us for any other purpose and is not shared with third parties other than our infrastructure sub-processors for storage purposes. Access to alert data by Orca staff is limited to what is necessary for the operation, maintenance and troubleshooting of the Platform, as described in Section 4.

Because alerts may include health information and other sensitive information (see Section 7), schools are responsible for ensuring appropriate consents have been obtained from parents or guardians before entering this type of information into the Platform.

Parent and guardian information

Where a School provides contact details for parents or guardians in connection with student activities, this may include name, email address and phone number. This information is used only for the purposes configured by the School within the Platform.

Event forms and user-submitted responses

Orca allows teachers and coordinators to attach forms to events as a way of collecting information from staff, students or parents. Forms may be used for a range of purposes at the School’s discretion — for example, collecting permission responses, dietary preferences, emergency contact details, or any other information relevant to an activity or excursion.

Form responses may include:

  • Free text answers to questions set by the School
  • File uploads (for example, signed permission documents, identification, or supporting materials)
  • Any other information that a respondent chooses to provide in answer to a question

Because form content is determined entirely by the School, we cannot predict or limit what categories of information may be submitted through forms. It is possible that form responses will contain sensitive information — for example, health details, dietary requirements or other personal circumstances — depending on the questions a teacher chooses to ask.

Form responses are stored within the Platform and are accessible only to authorised staff at the relevant School. We store this information solely to deliver the forms feature and do not use form response data for any other purpose. Schools are responsible for ensuring that any form questions are appropriate, that respondents have been informed about how their answers will be used, and that any necessary consents have been obtained — particularly where questions may elicit sensitive information or where forms are directed at minors.

Automatically collected information

When you access the Website or Platform, we automatically collect certain technical information including IP address, browser type and version, pages visited and timestamps. This information is used for security monitoring, access logging and improving the performance of the Platform.

3. How we collect personal information

Personal information enters the Platform through two main channels.

The first is information provided by Schools. Schools configure the Platform and upload staff and student records as part of administering the service. This includes account setup, student enrolments, alert information and other administrative data. In these cases the School is providing information on behalf of individuals, and the School is responsible for ensuring it has a lawful basis for doing so.

The second is information submitted directly by users. When a School attaches a form to an event, staff, students or parents may submit responses directly through the Platform. These responses — which may include free text, uploaded files or any other content a respondent provides — are collected directly from the individual completing the form. The content of these forms is determined by the School, not by us.

We also collect information:

  • From staff users, when they register an account, log in or interact with the Platform
  • Automatically, through system and access logs when the Platform or Website is used

Where a School provides information about individuals — including students who are minors — that School is responsible for ensuring it has obtained all necessary consents and has a lawful basis for sharing that information with us.

Where a School creates a form that will be completed by minors or that asks questions likely to elicit sensitive information, the School is responsible for ensuring appropriate consent has been obtained from parents or guardians before the form is issued.

4. Why we use personal information

We use the personal information we hold for the following purposes:

We do not use personal information — and in particular we do not use student information — for advertising, marketing to students, commercial profiling or any purpose unrelated to delivering the Platform to Schools.

We do not sell personal information to any third party under any circumstances.

Where we send marketing communications to school administrators about Orca features or updates, we do so in accordance with the Spam Act 2003 (Cth) and provide an opt-out mechanism in every communication.

5. How we share personal information

We do not share personal information with third parties except in the following circumstances:

Sub-processors: We engage a small number of third-party providers to help us deliver the Platform. These providers act as our sub-processors and may process personal information as part of delivering their services to us. They are listed in Section 6. We require all sub-processors to maintain appropriate data protection standards and they are not permitted to use personal information for any purpose other than delivering services to us.

Professional advisers: We may share information with our lawyers, accountants or auditors where necessary and subject to confidentiality obligations.

Business transfers: In the event of a sale or transfer of our business or assets, personal information may be transferred to a successor entity. See Section 13 for details.

Legal requirements: We may disclose personal information where required by law, court order, or lawful request by a government or regulatory authority. Where legally permitted, we will notify the affected School before making such a disclosure.

Safety: We may disclose personal information where we reasonably believe it is necessary to prevent or lessen a serious and imminent threat to the life, health or safety of any person.

We do not disclose personal information to any other third parties without your consent.

6. Sub-processors

The following third-party providers process personal information on our behalf as part of delivering the Platform. All data is stored and processed in Australia.

Provider Location Purpose Data processed
[Managed Hosting Provider] Australia Managed server hosting, server-level security, automated backups and infrastructure management All data stored and processed on the Platform
[Cloud Infrastructure Provider] Australia (Sydney) Underlying cloud compute and storage infrastructure All data stored on the Platform
SMTP2GO Australia (Sydney) Transactional email delivery (account notifications, system alerts, service emails) Name and email address of recipients only

The names of our infrastructure and hosting providers are available to Schools on request as part of security due diligence.

We will provide Schools with at least 30 days’ notice of any changes to our sub-processors.

7. Sensitive information

Sensitive information — as defined under the Privacy Act 1988 (Cth) — may be collected through the Platform in two ways.

Through student alerts: Schools may associate alerts with individual students to support duty of care and safe activity management. Alerts may include health information such as medical conditions, allergies or medication requirements, as well as behavioural or wellbeing notes. This information is entered and managed entirely by the School.

Through event forms: Because form content is determined by the School, it is possible that form responses submitted directly by staff, students or parents will contain sensitive information. For example, a teacher may ask about dietary requirements, health conditions, cultural considerations or other personal circumstances relevant to an activity. We cannot predict or control what sensitive information may be submitted through forms, as this depends entirely on the questions the School chooses to ask.

In both cases, we store sensitive information only because it has been provided through the Platform for the purpose of supporting the School’s activity management. We do not use sensitive information for any other purpose, and we do not share it with any party other than our infrastructure sub-processors for storage.

Schools are responsible for:

  • Ensuring that sensitive information — whether entered as alerts or collected through forms — is gathered only where there is a clear and legitimate purpose
  • Obtaining explicit consent from parents or guardians before collecting sensitive information about students, whether through administrative entry or through forms directed at students or parents
  • Framing form questions in a way that is appropriate to the age of respondents and the nature of the activity
  • Managing access to sensitive information within the Platform using Orca’s role-based access controls

If you wish to withdraw consent for sensitive information to be held, please contact your School administrator in the first instance. The School may then contact us to action the request.

8. Data storage and security

All personal information collected through Orca is stored and processed in Australia. We do not transfer personal information outside Australia.

We take reasonable technical and organisational steps to protect personal information from misuse, interference, unauthorised access, modification, disclosure and loss. These measures include:

  • TLS encryption for all data transmitted between users and the Platform
  • Encryption of data at rest at the infrastructure level
  • Role-based access controls ensuring users can only access data relevant to their role
  • Automated backups on a regular schedule
  • Server-level security managed by our certified hosting provider, including firewalls, automated patching and intrusion monitoring

Our hosting infrastructure is provided by certified third-party providers holding independently audited security certifications including SOC 2 Type II and ISO 27001. Full details are available on our Security page.

While we work hard to protect your personal information, no method of electronic storage or internet transmission is completely secure. We cannot guarantee absolute security, but we are committed to managing and minimising security risks on an ongoing basis.

9. How long we keep personal information

We retain different categories of information for different periods, based on the legal, safety and operational purpose each category serves.

Business records

Order Forms, invoices, contracts and support correspondence are retained for 7 years from account closure, in line with ATO requirements and standard Australian record-keeping obligations.

All platform data

All information stored within the Platform — including student and staff profiles, parent-student relationships, cohort membership, profile photos, activity records, attendance, risk assessments, student alerts, permission form responses, approval trails and any other data entered or submitted through the Platform — is retained for 7 years from the date of account closure.

We retain complete platform records for this period to maintain the integrity of safety, attendance and duty-of-care records that may be required in the event of legal proceedings, coronial inquiries, insurance claims or regulatory audit. Because relational data such as profiles, cohort membership and parent-student relationships provides the context that makes activity records meaningful and identifiable, we retain all platform data as a complete set rather than selectively deleting individual categories.

Security and access logs

Login records, authentication events and IP address logs are retained for 12 months on a rolling basis, after which they are deleted or anonymised.

Operational logs

Application logs, error logs and performance data are retained for 30 to 90 days on a rolling basis, after which they are deleted. These logs do not ordinarily contain personal information in any meaningful form.

Data export

Schools may request a full export of their Platform data at any time during their subscription, and within 30 days of account closure, by contacting hello@orca.school.

Deletion requests

Schools may submit deletion requests at any time by contacting hello@orca.school. We handle deletion requests as follows, depending on the nature of the record.

Permanent deletion (hard delete): Where a record has no associated activity history — for example, an account created in error, a duplicate profile, or a record that was never linked to any event — we will permanently delete it from our systems within 10 business days of a written request from the School.

Removal from active use (soft delete): Where an individual has associated activity records within the Platform, we will soft-delete their profile within 10 business days of a written request. A soft-deleted record is immediately and permanently removed from active use — it no longer appears anywhere in the Platform and is invisible to all school users. However, the underlying data is retained in our database for the 7-year period described above, to preserve the integrity of safety and duty-of-care records that may be needed for legal proceedings, coronial inquiries or insurance claims.

Where a soft deletion is applied, we will inform the School in writing and explain what this means. If an individual asks whether their data has been deleted, the honest and accurate response is: “Your personal information has been removed from active use in the platform and is no longer visible to any user. A record of your participation in school activities is retained for 7 years in accordance with our legal obligations, after which it is permanently deleted.”

End of subscription

When a School’s subscription ends, the 7-year retention period for platform data commences from the account closure date. Schools may request a full data export within 30 days of closure. At the end of the 7-year period, all remaining platform data is permanently deleted. Written confirmation of deletion is available on request.

10. Accessing and correcting your personal information

Under the Privacy Act 1988 (Cth), you have the right to request access to the personal information we hold about you, and to ask us to correct information that is inaccurate, incomplete or out of date.

Because Orca is a school-administered platform, personal information about staff and students is held on behalf of the School as data controller. We recommend that individuals contact their School administrator in the first instance. Schools can then contact us to action requests on their users’ behalf.

To make a request directly to us, please contact hello@orca.school with your name and contact details. We may need to verify your identity before actioning a request. We will respond within a reasonable timeframe and in any event within 30 days.

There is no charge for making an access or correction request. In some circumstances we may be unable to provide access to all information we hold — for example, where doing so would unreasonably impact the privacy of another person — and we will explain our reasons if this occurs.

11. Data breach notification

We take data breaches seriously. If we become aware of a data breach involving personal information that is likely to result in serious harm, we will:

  • Act promptly to contain and assess the breach
  • Notify affected Schools without undue delay and within 48 hours of becoming aware of the breach
  • Provide details of the nature of the breach, the information affected, the likely consequences, and the steps we are taking in response
  • Where required under the Notifiable Data Breaches scheme, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals

Schools, as data controllers, are responsible for determining whether to make notifications to individuals under the NDB scheme, and we will cooperate fully with Schools in that process.

12. Cookies

Our Website uses session cookies that are necessary for standard website functionality. We do not use advertising cookies, behavioural tracking cookies or cookies that identify individual users across third-party websites.

The Platform uses session cookies required for authenticated access and core platform functionality. No third-party advertising or tracking cookies are placed within the Platform.

You can configure your browser to refuse or delete cookies, though this may affect your ability to use certain features of the Website.

13. Change of control

If there is a change of control in our business, or a sale or transfer of our business or assets, personal information held in our systems may form part of the assets transferred. Any such transfer would be made subject to confidentiality obligations and the incoming party would be required to handle personal information in a manner consistent with this policy and applicable Australian privacy law. We would notify affected Schools of any such change to the extent that we are legally able to do so.

15. Changes to this policy

We may update this privacy policy from time to time to reflect changes to the Platform, our practices, or applicable law. When we make material changes, we will notify Schools by email and update the date at the top of this page. We encourage you to review this policy periodically.

16. Complaints

If you have a concern about how we have handled your personal information, please contact us in the first instance using the details below. We will acknowledge your complaint promptly and work to resolve it within a reasonable timeframe.

If you remain unsatisfied after contacting us, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Website: www.oaic.gov.au
Phone: 1300 363 992

17. Contact us

For questions about this privacy policy, to exercise your privacy rights, or to make a complaint, please contact:

Privacy Officer

Lennix Pty Ltd

ABN 36 156 631 631

[Address]

Email: hello@orca.school

Get Started

Ready to bring order
to school life?

See how Orca transforms activity management at your school. Book a personalised demo and we’ll walk you through exactly how Orca fits your workflows.

What you get with Orca

One centralised platform for every school activity
Configurable approval workflows aligned to your school’s policies
Automated digital risk assessments — PDF generated from your templates
Complete audit trail and revision history for every event
Community calendar, parent permissions, and messaging built-in
API integration with your Student Information System
Personalised onboarding and ongoing support for your team
Personalised demos available now