markAtt privacy policy

Last updated

Who this covers

markAtt is used by teachers and administrators at a community Sunday school. Students and parents do not use the app. This policy explains what the app stores, where it is kept, who can see it, and how long it is held.

What the app stores

Teacher and administrator accounts. A username, a display name, and a role. Passwords are handled by Supabase Auth and stored hashed. The app never sees a plain password.

Student records. First and last name, class, a student number generated by the app, whether the student is an Australian citizen, the name of the student's mainstream school, and their mainstream year level. These are entered by the school.

Parent and guardian contacts. Name, relationship to the student, mobile number and email address. A guardian may be linked to more than one student, so that families with several children are held once rather than repeatedly.

Attendance and homework records. One attendance mark and one homework mark per student per session, with the date of that session.

Why citizenship status is collected

The school claims a government rebate that requires it to record whether a student is an Australian citizen. The app stores this because the school needs it for that claim. It is not used for anything else, it is visible only to the school's administrator, and it is not shared outside the school.

What the app does not do

  • No advertising.
  • No analytics and no tracking.
  • No location data.
  • No payments.
  • No selling or sharing of data with third parties.
  • No data is used to train any model.
  • No photographs of students.
  • No health information, and no free-text notes about students.
  • No date of birth, home address, or medical details.

Where data is stored

Data is stored in Supabase, a hosted Postgres service, in the ap-southeast-2 region. That region is in Sydney, so the data stays in Australia.

Who can see it

Access is restricted at the database level using row-level security, not only in the app. A teacher can read and write records only for the classes they teach, and can see the guardian contacts only for students in those classes. A school administrator can see their own school's records. Nobody can see another school's records.

The developer of the app has technical access to the database in order to maintain it.

Children's information

Student records relate to children. The school decides which students are enrolled, and the school is responsible for obtaining consent from parents.

The app is designed to hold as little as it can. It stores what the school needs to mark a roll, contact a parent, and meet its own reporting obligations, and nothing beyond that.

Consent for the school to collect and hold this information is obtained by the school when a student is enrolled.

How long it is kept

A student's records are kept while they are enrolled, and for two years after they leave. After that the record and its attendance history are deleted automatically. Two years is the period the school needs for its rebate reporting.

A parent or guardian's contact details are deleted when the last student they are linked to is deleted.

Correcting or deleting a record

A parent or guardian can ask the school to correct or delete their child's record at any time, and can ask what is held about their child. Requests can go to the school directly, or to support@thepriyakaur.com.

When a student's record is deleted, their attendance and homework marks, their class history, and their link to any guardian are deleted with it. A guardian's contact details are deleted if no other student is linked to them.

If something goes wrong

If data held in markAtt is exposed or accessed by someone who should not have seen it, the school will be told, and affected families will be told where the risk of harm makes that appropriate. Where the law requires it, the Office of the Australian Information Commissioner will be notified.

Questions and requests

Email support@thepriyakaur.com with any question about this policy. This is the same address as the markAtt support page.

Changes to this policy

If this policy changes, the updated version will be posted here with a new last-updated date. Where a change affects what is collected or how long it is kept, the school will be told directly.