// schools — for Victorian government & independent schools

The procurement answers, before you have to ask for them.

Schools do their own Privacy Impact Assessment. Almost nobody wants to chase a vendor for the inputs. So everything a business manager needs — where the data lives, what we collect, who can see it, how it is destroyed — is written down here rather than waiting behind an email.

Data hosted in

Australia — Azure Australia East (Sydney)

Student data

Not required to use the product

Sold to third parties

Never

// data residency

Where your data actually lives.

Every production system that stores or processes school data runs in Microsoft Azure, Australia East (Sydney): the database, file storage, the application servers, and the AI service that drafts content.

One honest exception, because a privacy assessment should not discover it later. Two services used for generating marketing content — writing website copy and producing illustrations — run outside Australia. They receive the business information a school publishes about itself. They do not receive member records, member documents, or anything from the member portal. If your assessment needs that boundary in writing, it is in the privacy pack.

// student data

Whether this touches student records — the precise answer.

DiscoverWorthy does not require any student data. A school runs it on staff and business information: your website, your notices, your calendar, staff logins, and the content the site publishes. That is how it is used today.

It would be misleading to stop there. The platform includes a member register that can hold student records if a school chooses to use it — including a junior flag, documents attached to a named person, and guardian access so a parent can collect them. Nothing switches that on by itself, and nothing populates it without the school entering the data.

So the accurate position for your PIA is: no student data is collected by default; if you choose to keep student records here, the safeguards below apply and should be assessed.

// safeguarding

If you do keep student records, here is what protects them.

  • Documents are private, and checked on every request

    A document attached to a student is never a public link. The file is served through an authorisation check tied to the person asking — the student, or an adult the school has explicitly authorised. Asking for a document you are not entitled to returns nothing at all. Every download is recorded.

  • Guardian access is granted by the school, and revocable

    A parent cannot add themselves. Only the school can authorise an adult to see a named child's documents, and the record keeps who granted it and when. Withdrawing access is a switch rather than a deletion, so the school can still answer “who could see this, and between which dates?” — the question that actually gets asked.

  • Consent for a student story is bound to the exact story

    If a school publishes a student profile, consent for a junior goes to their guardian — and it is tied to that exact version of the text. Edit the story afterwards and the previous approval no longer authorises it. Consent cannot be obtained on a mild draft and spent on a different one.

// security

How it is protected.

At rest

Azure SQL Transparent Data Encryption; encrypted file storage

In transit

HTTPS everywhere, TLS 1.2 minimum

Access

Per-request authorisation; least privilege by role

Monitoring

Continuous health checks with alerting on failure

Backup and restore run on Azure's managed database backups. We would rather tell you the retention window and recovery objective in writing, against your template, than publish a number here that your assessment then has to verify.

// retention & deletion

Getting your data back, and getting it destroyed.

Your content is yours. Ask and we export it. Ask us to delete and we delete the records — and the files behind them, which is the part worth stating plainly: a document about a named child is destroyed, not merely unlinked from the record that described it.

Data is kept while the account is active and for as long as you ask us to keep it. We do not sell data, we do not share it with advertisers, and we do not train anyone else's models on it.

// compliance

How this lines up with your obligations.

DiscoverWorthy is built to support a Victorian school's obligations under the Privacy and Data Protection Act 2014 (Vic) and the Information Privacy Principles — Australian data residency, purpose-limited collection, access controls, and deletion on request.

On the Child Safe Standards: the school remains the responsible entity. Our part is to make the technical controls support your policy rather than undermine it — access that is granted rather than shared, consent that is recorded and version-bound, and an audit trail that answers who could see what.

We are a software supplier and do not attend your site, so a Working with Children Check is not applicable to the service. If a specific engagement ever changed that, we would tell you before it did.

// privacy pack

Attach this to your PIA instead of emailing us.

The privacy pack answers the questions school PIA templates actually ask — hosting location, sub-processors, collection and retention, encryption, access control, deletion, and breach notification — in the order they are usually asked.

Download it as a PDF and attach it, or read it online. The PDF is generated fresh each time from our own records, so what you attach is the current version rather than a copy that quietly went out of date.

// questions

What business managers ask first.

Is our data stored in Australia?

Yes — Azure Australia East (Sydney) for the database, files, application and AI processing of member content. Marketing-copy and image generation run offshore and receive only the business information you publish about the school.

Do you handle student data?

Not unless you choose to. The product does not require it, and a school can run entirely on staff and business information. If you use the member register for students, the safeguards above apply.

Can we get a child safety attestation?

We can put our technical controls in writing against your template. We are a software supplier with no physical access to your school, so a Working with Children Check does not apply to the service itself.

What happens if there is a breach?

We notify you promptly with what we know, what was affected and what we have done, so you can meet your own notification obligations. Systems are monitored continuously and failures alert us rather than waiting to be noticed.

Who else processes our data?

The sub-processor list is in the privacy pack, with what each one does and where it runs. It is short, and we would rather you read it than take a reassurance.

// who you are dealing with

The supplier, on the record.

Entity

DiscoverWorthy — ABN 74 694 878 594

Registered address

140 Keller Road, Essendon North, VIC 3041

Privacy contact

Security & incidents

An Australian entity, governed by Australian law, holding your data in Australia — so there is no offshore parent in the chain for your assessment to work through.

Still need something for your assessment?

Ask for it directly. A specific question answered in writing is faster than a form.