This Privacy Policy explains how {{ORG_NAME}} (operating as PRISM Assessment, a service of Beacon Star and St Andrew's Anglican College, Queensland) collects, uses, stores, and protects personal information when you or your child participates in the PRISM Assessment.
We are committed to protecting your privacy and complying with Australian Privacy Law, Queensland state law, US federal and state privacy laws, and European privacy regulations.
If you are under 18: Your parent or legal guardian must consent before you take the assessment. This policy applies to both you and your parent.
Our details:
We collect only the information necessary to run the assessment, issue results, and comply with the law.
We collect and use your information to:
We do not use your data for marketing, profiling, or automated decision-making that affects your legal rights.
If you are a student in the EU or UK, we rely on:
All data is stored in Supabase Postgres, hosted in the Sydney region (ap-southeast-2), owned and operated by Supabase (US company, but data residency is Australian). We have chosen Sydney residency specifically to avoid unnecessary cross-border transfer of assessment responses and consent records.
| Party | Role | Location | Justification |
|---|---|---|---|
| Supabase | Database hosting, authentication | Sydney | Contractually obliged; encrypted at rest; no secondary use |
| AWS SES | Email delivery (transactional only) | Sydney | Contractually obliged; encrypted in transit; no secondary use |
| AWS SNS (optional) | SMS code delivery (parental verification only) | Sydney | Contractually obliged; code is single-use, not stored |
| Cloudflare | CDN, DNS, DDoS protection | Global with AU edge | Contractually obliged; no access to assessment data; only proxy |
We do NOT use:
Different data is kept for different periods, balancing accountability with privacy:
| Data | Retention | Reason |
|---|---|---|
| Assessment responses + scores | 5 years (de-identified) | Research aggregate; legal hold |
| Identifiable fields (name, email) | 12 months (under-18); 24 months (adult) | Balances child protection with minimization |
| Consent records (parental attestation, signed form) | As long as the assessment exists, then 7 years | Proof of consent; accountability |
| Audit log | 7 years | Accountability, breach investigation, compliance |
| Access keys (student links) | Expires after 30 days if not used; then purged | Single-use; not needed after student submits |
| IP/User-Agent hashes | Same as identifiable fields | Abuse detection, then purge |
Automatic purge: On the 1st of each month, we automatically purge identifiable fields for all respondents whose retention window has elapsed. The data steward is notified.
Early deletion: You can ask us to delete your data anytime. We will comply within 30 days (or earlier if we can).
We are committed to keeping your data in Australia. However, some limited transfers may occur:
We use Privacy Act Schedule 1 (APP 8.1) and GDPR Standard Contractual Clauses to document these transfers. Any transfer is disclosed in our Records of Processing Activities (available on request).
You have the right to ask us: "What personal information do you hold about me?"
We will provide a copy within 30 days (or sooner). If your request is complex, we will ask for clarification and update the timeline.
If any information is inaccurate (e.g. your email was spelled wrong), tell us and we will correct it.
You (or your parent, for you if under 18) can ask us to delete your data before the retention window ends. We will comply within 30 days, except where the law requires us to keep it (e.g. audit log for accountability).
You can withdraw parental consent, and we will stop processing your data and mark it for deletion. Existing results cannot be "un-sent," but no new processing will occur.
You can ask for a copy of your data in a portable format (CSV, JSON). We will provide it within 30 days.
You can object to processing for direct marketing, profiling, or automated decision-making. We do not do these, so this right is mostly moot, but you have it.
Your parent can exercise all of the above rights on your behalf. They can also:
If you believe we have breached your privacy, you can complain to us first:
Email: {{PRIVACY_OFFICER_EMAIL}}
Write to: {{POSTAL_ADDRESS}}
We will respond within 30 days.
If we don't resolve it, you can escalate to:
Office of the Australian Information Commissioner (OAIC)
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Website: oaic.gov.au
If you are a US resident:
If education records are involved, you may also contact the US Department of Education, Office of Family Policy Compliance (FERPA matters).
If you are in the EU or UK:
We may update this Privacy Policy to reflect changes in the law or our practices. We will notify you by email if there are material changes (e.g. a new third party, a longer retention period).
Current version: {{POLICY_VERSION}}
Last updated: {{POLICY_DATE}}
Privacy Officer: {{PRIVACY_OFFICER_EMAIL}}
Postal Address: {{POSTAL_ADDRESS}}
Website: assessment.beacon-star.com
This Privacy Policy is DRAFT FOR LEGAL REVIEW, do not deploy without qualified legal sign-off.