Student Data Privacy Policy
Version 2026-10-01
How Teacher's Buddy handles student information in school-authorised student profiles, support files, group membership and related learning-support features.
Read how we protect student information when using AI for a plain-English explanation of the process.
1. Who we are and when this policy applies
Teacher's Buddy is operated by Teachers Buddy Pty Ltd (ABN 69 686 840 424), based in Victoria, Australia. This policy supplements our general Privacy Policy. For information handled within the school-authorised student-data features, this policy takes priority if the two policies conflict. Account, billing and ordinary teaching-resource services remain subject to the general Privacy Policy.
The school determines why student information is collected and who may use it. We process it to provide the services the school authorises and to meet our own applicable legal obligations. Students do not need a Teacher's Buddy account. A paid school plan alone does not authorise student-data processing.
2. Information we handle and where it comes from
Depending on the enabled features, information may include student names and identifiers, learner-group membership, observations, learning needs, adjustments, support plans, evidence, review notes and school-approved AI drafts. It may include health or disability information, family circumstances and other sensitive information. We apply the student-data safeguards to the entire support file rather than asking teachers to decide whether each note is legally a health record.
Information is supplied by authorised school staff or through an integration expressly enabled for this purpose. Staff may include information the school has lawfully obtained from a student, parent, guardian or professional. We also record who created, accessed or changed records, relevant timestamps, permissions, school authorisations and security events. Supporting files and extraction are available only where expressly enabled in the school's processing schedule.
Provide only information needed for the educational support purpose. Do not include passwords, payment details or unrelated information about students, families or other people. If the necessary information is not supplied, the relevant support or AI feature may not be available.
3. How we use student information
We use student information to maintain the school's student profiles and support files, organise permitted group membership, support authorised staff collaboration, deliver separately authorised AI assistance, and carry out controlled access, correction, export, retention and disposal. We also process the information necessary to secure these services, investigate incidents, respond to lawful requests and meet legal obligations.
We do not sell student information, use it for advertising or marketing, or use student content to train or fine-tune foundation models. Student-record content is not sent to general product analytics or session replay. Operational audit records are separate from student notes and use the identifiers and events needed to enforce and investigate access.
4. School authorisation, notices and consent
An authorised school owner or administrator must read and accept the Student Data Terms and Conditions, acknowledge this policy, and declare their role and authority before enabling the service. We record their signed-in identity, declarations, document versions and selected processing permissions. A platform role or a verified email does not independently prove authority to represent a school.
The school must establish the lawful basis for collecting, using and disclosing each type of information, provide appropriate notices to students and families, and obtain and record consent where required. A school administrator's acceptance is not parental or student consent. Consent requirements depend on the information, purpose, applicable law and the student's capacity; this policy does not assume that one form of consent works for every student or school.
5. Who can access or receive information
Student files are available only to signed-in school members with the required permissions. School membership alone does not grant access to every support file. Schools must keep membership and permissions current and promptly remove access when roles change or staff leave.
Teacher's Buddy personnel and service providers may handle information only as necessary for authorised service delivery, security, support, legal obligations and controlled records management. Operational access is restricted and subject to access controls and audit records. Schools control onward disclosures and exports that they make. We may disclose information where required or authorised by applicable law, and notify the school where legally permitted.
6. Providers and processing locations
The processing and retention schedule presented with the school agreement identifies the enabled student-data services, providers, processing countries and relevant storage and retention arrangements. That schedule forms part of the school's authorisation. Our general sub-processor list describes the wider platform; it does not permit every listed provider to receive student support files.
Student-record storage and processing are separate from account, authentication, billing and organisation administration. A student-record processing country is not a promise that every account system, provider support function or legal disclosure occurs in that country. The schedule must disclose relevant differences and any overseas handling before the school authorises it. We do not silently send student content to a different provider or country when an approved service is unavailable.
7. AI processing, minimisation and human review
AI processing requires a separate school choice and an enabled purpose in the school's processing schedule. The school remains responsible for the authority, notices and any consent needed for this processing, including where learning, disability, health or family information is involved.
Before sending supported student information to an AI provider, we apply automated data minimisation within our student-data service. This reduces identifying details while keeping relevant educational context. It includes replacing known names with a label such as Student A and removing common patterns for contact details, numeric dates and labelled student identifiers. Source labels such as Source 1 let us link a draft to the original records without sending the internal record identifiers as citations. The original school records are not rewritten by this process.
These measures are pseudonymisation, not a guarantee of anonymity. Automated checks can miss names, addresses, dates or other identifying details, and combinations of events, learning needs, family circumstances or locations may still identify someone. Relevant educational and health information may remain in the request. We continue to treat the material as protected student information. Staff should supply only what is needed and remove unnecessary details about the student or other people.
For Individual Education Plans and supported goal revisions, staff select or confirm the source information and review the minimised outgoing brief before sending it. A request includes the selected notes, evidence statements and relevant planning fields; it does not automatically include the complete student file or the bytes of attached resources. Source and permission changes may require a fresh review. Generated plans are drafts: staff must check them against the sources before explicitly saving them, and saving a draft is separate from approving a plan.
Where automatic support summaries are enabled under the school's AI authorisation, saving or editing supported notes or evidence can trigger a summary refresh without a separate review of each outgoing request. The service applies the same minimisation before sending the supported source text and automatically stores the resulting summary separately from authored records. A summary is an AI-generated aid, not a staff-approved statement or a replacement for the original evidence. Staff must check it before relying on it. Refreshes may be delayed or fail, so a displayed summary may not yet reflect the latest records.
Student AI requests use the separately authorised student-data service and approved provider route. They do not use the general resource-generation agent or automatically fall back to another provider or country. We check current school and record permissions before sending information and before making a result available. Revocation can stop further processing but cannot recall information already transmitted.
Approval identifies the provider and processing country rather than an individual model. Models may change within that scope without renewed school acceptance only while the authorised purposes and data-handling terms remain unchanged. Changes to the provider, processing country, purposes or material data-handling terms require renewed acceptance before the changed processing starts.
Provider retention, abuse monitoring and support handling depend on the service and configuration identified in the schedule. Disabling stored completions or conversation history is not a promise of zero retention. We require arrangements that prohibit using student content to train foundation models. Do not assume that all provider personnel are located in the processing country. The service must not be used for autonomous diagnoses, disability or funding eligibility, discipline or other significant decisions about a student.
8. Security and accuracy
Our safeguards include authenticated access, checks of school and record permissions, separation of student-content processing, encrypted service connections, restricted operational access and audit records. Hosting, backup and recovery arrangements are specified for the enabled service. No system can guarantee absolute security.
Schools must keep information accurate and relevant, distinguish observations from opinions, review AI output and protect any exported copies. Do not put identifiable support records into ordinary resource-generation prompts, public sharing, general uploads or other integrations merely because those features are available in the account.
9. Retention, withdrawal and deletion
The school-specific retention schedule, applicable recordkeeping obligations and any preservation hold determine how long records are kept. There is no universal retention period for every student file, school sector or jurisdiction. Closing a file, removing a group link, cancelling a subscription or withdrawing authorisation does not itself delete the file.
Withdrawal blocks ordinary student-data access and new processing. Restricted records management may remain available for authorised export, preservation, review and disposal. Deletion requires the applicable retention conditions and approvals to be met, and must not override a legal or safeguarding hold.
Deleting an active database record is distinct from expiry of backups and removal of provider copies. The applicable schedule must identify those arrangements. We do not describe primary deletion as deletion of every copy. Authorisation receipts and necessary audit evidence may need to be retained separately to demonstrate lawful handling and meet legal obligations.
10. Access, correction and privacy requests
Students, parents, guardians and other authorised representatives can contact their school about access to or correction of school-managed information. You can also contact privacy@teachersbuddy.com. We will verify identity and authority as appropriate and coordinate with the school where it manages the record. Contacting us does not require a student account.
We assess requests under applicable law, including any limits needed to protect other people, preserve required records or respect a student's own rights and capacity. Parents do not automatically have access to every record in every circumstance. Where a request cannot be met, we explain the applicable reason and available complaint options, to the extent permitted by law. We do not promise deletion where the school or we are required to preserve information.
11. Incidents and complaints
Report suspected unauthorised access, loss or disclosure to security@teachersbuddy.com or privacy@teachersbuddy.com. We investigate and take containment and remedial steps, inform the affected school without undue delay after becoming aware of a breach affecting its student information, and provide available information needed for its response. We and the school remain responsible for our respective statutory notification duties.
Send privacy complaints to privacy@teachersbuddy.com with the issue and the outcome you seek. We will acknowledge and investigate the complaint and normally respond within 30 days. If more time is needed, we will explain why and provide an updated timeframe. Depending on the matter and applicable law, complaints may also be made to the Office of the Australian Information Commissioner, the Victorian Health Complaints Commissioner or the Office of the Victorian Information Commissioner. Their jurisdiction depends on the information and organisation involved.
12. Changes to this policy
We keep versioned copies and record which version the school accepted. Material changes are notified through an administrator notice, email or an equivalent service communication. Changes that expand the authorised provider, location, purpose or material data-handling terms require renewed school acceptance before that processing begins. A new principal or authorised representative can renew the authorisation using their own account; earlier receipts remain part of the acceptance history.