Privacy Policy
Secure Schools’ Privacy Policy
Updated May 2025
Secure Schools Pty Ltd ACN 668 052 266 (we, us, our) is a leading cyber security provider for the education sector and complies with the Australia Privacy Principles (APPs) in the Privacy Act 1988 (Cth) (Privacy Act). We understand the importance of, and are committed to, protecting your personal information. This Privacy Policy explains how we manage your personal information (that is, information or an opinion, whether true or not, about an individual who is identified or is reasonably identifiable), including our obligations and your rights in respect of our dealings with your personal information.
Please take a moment to read our Privacy Policy as it describes what happens to your personal information that is collected in the course of our business,
This privacy policy is provided in a layered format so you can click through to the specific areas set out below. Please also use the Glossary to understand the meaning of some of the terms used in this privacy policy.
1. How we collect your personal information
We will collect and hold your personal information in a fair and lawful manner, and not in an intrusive way. Where it is reasonably practical to do so, we will collect your personal information directly from you. We may collect the personal information you give us directly through some of the following means:
- when you place an order for our goods or services, including via our Website;
- when you make an inquiry through our Website, or otherwise correspond with us or contact us;
- through any mobile applications, platforms, or other software applications provided by our organisation;
- if you submit a form to sign up to our mailing list;
- when you engage with our staff at any of our premises;
- if you enter any competitions that we conduct;
- if you attend or otherwise participate in any events that we stage;
- while conducting customer satisfaction and market research surveys; and
- where we otherwise deal with you in the course of our business.
As you interact with our Website, we will automatically collect technical data about your equipment, browsing actions and patterns. We collect this personal information by using cookies and other similar technologies. We may also receive technical data about you if you visit other websites employing our cookies. Please see our cookie policy for further details.
However, in certain cases we may collect personal information from publicly available sources and third parties, such as suppliers, recruitment agencies, contractors, our clients and business partners.
This may include:
- technical data from analytics providers, advertising networks and search information providers;
- contact, financial and transaction data from providers of technical, payment and delivery services;
- identity and contact data from data brokers or aggregators;
- identity and contact data from publicly available sources such as government registers.
If we collect personal information about you from a third party we will, where appropriate, request that the third party inform you that we are holding such information, how we will use and disclose it, and that you may contact us to gain access to and correct and update the information.
2. Types of personal information we collect
The type of personal information we may collect can include (but is not limited to), your name, username or similar identifier, marital status, title, date of birth, gender, postal address, email address, phone numbers, billing information, bank accounts, payment card details, and, if applicable, employment information.
We may also collect other data that may or may not be personal information, for example:
- technical data, such as your internet protocol address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website;
- profile data, such as your purchases or orders, your interests, preferences, feedback and survey responses;
- usage data, for example, information about how you use our website, products and services; and
- marketing and communications data, such as your preferences in receiving marketing from us and third parties, and your communication preferences.
We also collect aggregated data such as statistical or demographic data, which we may use for any purpose. Aggregated data could be derived from your personal information but is not generally considered personal information in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect aggregated data with your personal information so that it can directly or indirectly identify you, we treat the combined data as personal information which will be handled in accordance with this privacy policy.
Where you do not wish to provide us with your personal information, we may not be able to provide you with requested goods or services.
We are generally unlikely to collect sensitive information about you, such as:
- health or genetic information;
- your racial or ethnic origin;
- your sexual orientation;
- your religious beliefs or affiliations;
- your membership of a trade union, or professional or trade association; or
- biometric information.
If collection of sensitive information is reasonably necessary for one or more of our functions or activities, we will only collect sensitive information about you with your consent, or otherwise in accordance with the Privacy Act.
3. Our purposes for handling your personal information
As a general rule, we only process personal information for purposes that would be considered relevant and reasonable in the circumstances.
We collect, hold, use and disclose personal information to:
- offer and provide you with our goods and services, including to perform our contract with you;
- manage and administer those goods and services, including account keeping procedures;
- communicate with you, including (but not limited to), emailing you tax invoices;
- comply with our legal and regulatory obligations; and
- otherwise manage our business.
We may disclose personal information between our organisations or to third parties such as our suppliers, organisations that provide us with technical and support services, or our professional advisors, where permitted by the Privacy Act. If we disclose information to a third party, we generally require that the third party protect your information to the same extent that we do.
We will not use or disclose your personal information for any other purpose unless you have consented to that use or disclosure, or the relevant use or disclosure is otherwise permitted by the APPs or some other law.
4. Protection of personal information
We will hold personal information as either secure physical records, electronically on our intranet system, in cloud storage, and in some cases, records on third party servers, which may be located overseas.
We maintain appropriate physical, procedural and technical security for our offices and information storage facilities so as to prevent any loss, misuse, unauthorised access, disclosure, or modification of personal information. This also applies to disposal of personal information.
We further protect personal information by restricting access to personal information to only those who need access to the personal information to do their job. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. Physical, electronic and managerial procedures have been employed to safeguard the security and integrity of your personal information.
We also have put in place procedures to deal with any suspected data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
We will destroy or de-identify personal information once it is no longer needed for a valid purpose or required to be kept by law.
5. Direct marketing
Like most businesses, marketing is important to our continued success. We believe we have a unique range of products and services that we provide to customers at a high standard. We therefore like to stay in touch with customers and let them know about new opportunities. We may provide you with information about new products, services and promotions either from us, or from third parties which may be of interest to you.
Provided that you have not unsubscribed or otherwise opted out, we may use your information for direct marketing:
- where you have agreed to receive direct marketing from us; or
- where you have engaged with us directly, and we believe that you would reasonably expect to receive direct marketing from us.
We may utilise the services of third parties to assist us with undertaking our direct marketing activities. We will not otherwise disclose your personal information to third parties for marketing purposes without your consent.
You may opt out at any time if you no longer wish to receive commercial messages from us. You can make this request by contacting our Privacy Officer.
Note that if you opt-out of direct marketing messages from us, we may still communicate with you from time to time for other purposes, including where we:
- respond to any correspondence you send us;
- provide you with invoices or updates in respect of any orders you have placed with us;
- engage with our contractors and suppliers; or
- are legally required to provide you with notice of certain matters.
6. Accessing and correcting your personal information
You may contact our Privacy Officer to request access to the personal information that we hold about you and/or to make corrections to that information, at any time. On the rare occasions when we refuse access, we will provide you with a written notice stating our reasons for refusing access. We may seek to recover from you reasonable costs incurred for providing you with access to any of the personal information about you held by us.
We are not obliged to correct any of your personal information if it does not agree that it requires correction and may refuse to do so. If we refuse a correction request, we will provide you with a written notice stating our reasons for refusing.
We will respond to all requests for access to or correction of personal information within a reasonable time.
7. Overseas transfers of personal information
As at the date of this Privacy Policy, we are not likely to disclose your personal information to overseas recipients.
If in future we do propose to disclose personal information overseas, we will do so in compliance with the requirements of the Privacy Act. We will, where practicable, advise you of the countries in which any overseas recipients are likely to be located.
If you do not want us to disclose your information to overseas recipients, please let us know.
8. Personal information about employees
We may collect personal information about our employees and prospective employees, as part of their application and during the course of their employment, either from them or in some cases from third parties such as recruitment agencies.
This may include information about the employee’s health, their right to work in Australia, or other sensitive information. For some roles, employees may need to obtain a security clearance or provide a criminal history search.
Under the Privacy Act, personal information about our current or former employees may be held, used or disclosed by us in any way that is directly connected to the employment relationship. We handle information about our employees in accordance with legal requirements and our applicable policies in force from time to time.
9. Resolving personal information concerns
If you have any questions, concerns or complaints about this Privacy Policy, or how we handle your personal information, please contact our Privacy Officer:
The Privacy Officer
204/3 Spring Street, Sydney NSW 2000
Email: support@secureschools.com
We take all complaints seriously, and will respond to your complaint within a reasonable period.
If you are dissatisfied with the handling of your complaint, you may contact the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner
GPO Box 5288
Sydney NSW 2001
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au
10. Changes
We reserve the right to change the terms of this Privacy Policy from time to time, without notice to you. An up-to-date copy of our Privacy Policy is available on our Website.
The last update to this document was Aug 2024.