Skip to main content

Privacy & Data Handling

Junipa complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). The full privacy policy is published at junipa.com.au/privacy.

Data Processing Relationship

  • Data controller: The school determines what data is collected and why
  • Data processor: Vast Puddle Pty Ltd processes data on behalf of the school
  • Sub-processors: Google Cloud Platform (infrastructure), Wonde (SIS integration, if configured)

Junipa does not determine the purposes of data collection. Schools are responsible for obtaining appropriate consent from parents, guardians, and staff.

What Data Junipa Holds

CategoryExamples
Student identityName, DOB, gender, student number
Student educationalYear level, enrolment, adjustment level, disability category
Student healthMedical conditions, wellbeing observations
Student supportCase notes, IEPs, evidence records
Parent/guardianName, email, phone, relationship
StaffName, email, role, employment status
Marketing updatesName, email, subscription status, unsubscribe status, and basic delivery events

See the Data Processing page for full details.

Data Residency

Junipa platform and school data is stored in Google Cloud Platform's Sydney region (australia-southeast1).

Cloudflare processes HTTP requests at global edge locations for WAF and CDN purposes but does not store school platform data at edge locations. Website forms, support messages, and product update emails may use email delivery providers to process the contact details needed to send and manage those messages.

Product Updates

Junipa may send product updates, release notes, and practical school workflow information to people who subscribe, request a demo, speak with us about Junipa, or are added by Junipa staff from an approved business contact list.

  • Every product update includes an unsubscribe link.
  • Unsubscribed addresses are kept as a minimal suppression record so they are not added back by mistake.
  • Student records, school platform data, support evidence, and NCCD data are not used for marketing or advertising.

Data Retention

  • Active subscription: Data retained for the duration of the school's subscription
  • Backups: 30-day automated retention, then automatically purged
  • Audit logs: Retained for 7 years
  • On termination: Schools can request a full data export. Data is deleted within 90 days of termination, with written confirmation.
  • Marketing update contacts: Retained while subscribed, then kept as a minimal unsubscribe/suppression record unless deletion is required by law or requested where practicable.

Data Export and Deletion

Schools can:

  • Export all their data at any time in structured format
  • Request deletion of individual student records
  • Request full deletion of all data upon contract termination

Contact info@junipa.com.au to request an export or deletion.

No Data Selling or Sharing

Junipa does not:

  • Sell personal information to third parties
  • Use student data for marketing or advertising
  • Share data with third parties beyond infrastructure providers
  • Use AI or machine learning on student data
  • Retain data for its own purposes after a school's contract ends

Privacy Enquiries

For privacy questions, access requests, or correction requests:

Email: privacy@vastpuddle.com.au