Privacy & Data Handling
Junipa complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). The full privacy policy is published at junipa.com.au/privacy.
Data Processing Relationship
- Data controller: The school determines what data is collected and why
- Data processor: Vast Puddle Pty Ltd processes data on behalf of the school
- Sub-processors: Google Cloud Platform (infrastructure), Wonde (SIS integration, if configured)
Junipa does not determine the purposes of data collection. Schools are responsible for obtaining appropriate consent from parents, guardians, and staff.
What Data Junipa Holds
| Category | Examples |
|---|---|
| Student identity | Name, DOB, gender, student number |
| Student educational | Year level, enrolment, adjustment level, disability category |
| Student health | Medical conditions, wellbeing observations |
| Student support | Case notes, IEPs, evidence records |
| Parent/guardian | Name, email, phone, relationship |
| Staff | Name, email, role, employment status |
| Marketing updates | Name, email, subscription status, unsubscribe status, and basic delivery events |
See the Data Processing page for full details.
Data Residency
Junipa platform and school data is stored in Google Cloud Platform's Sydney region (australia-southeast1).
Cloudflare processes HTTP requests at global edge locations for WAF and CDN purposes but does not store school platform data at edge locations. Website forms, support messages, and product update emails may use email delivery providers to process the contact details needed to send and manage those messages.
Product Updates
Junipa may send product updates, release notes, and practical school workflow information to people who subscribe, request a demo, speak with us about Junipa, or are added by Junipa staff from an approved business contact list.
- Every product update includes an unsubscribe link.
- Unsubscribed addresses are kept as a minimal suppression record so they are not added back by mistake.
- Student records, school platform data, support evidence, and NCCD data are not used for marketing or advertising.
Data Retention
- Active subscription: Data retained for the duration of the school's subscription
- Backups: 30-day automated retention, then automatically purged
- Audit logs: Retained for 7 years
- On termination: Schools can request a full data export. Data is deleted within 90 days of termination, with written confirmation.
- Marketing update contacts: Retained while subscribed, then kept as a minimal unsubscribe/suppression record unless deletion is required by law or requested where practicable.
Data Export and Deletion
Schools can:
- Export all their data at any time in structured format
- Request deletion of individual student records
- Request full deletion of all data upon contract termination
Contact info@junipa.com.au to request an export or deletion.
No Data Selling or Sharing
Junipa does not:
- Sell personal information to third parties
- Use student data for marketing or advertising
- Share data with third parties beyond infrastructure providers
- Use AI or machine learning on student data
- Retain data for its own purposes after a school's contract ends
Privacy Enquiries
For privacy questions, access requests, or correction requests:
Email: privacy@vastpuddle.com.au