Privacy Policy

Effective date: 1 January 2026 · Version 2.5

1. About this policy

eDimensions Pty Ltd (ABN 71 135 191 061), trading as School24 (“School24”, “we”, “us” or “our”) provides digital ordering and related services to schools, parents, carers, students and other authorised users. This Privacy Policy explains how we collect, hold, use and disclose personal information through our websites, mobile applications, school administration portals, customer support channels and associated services (together, the “Services”).

This Privacy Policy applies to schools, school staff, parents, carers, students and other authorised users of the School24 platform and Services.

We handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles, and any other privacy laws that apply to our activities. Where our contract with a school imposes additional privacy or security requirements, we will also comply with those requirements.

2. Personal information we collect

Depending on the Services used, we may collect and hold:

Some order information may reveal sensitive information, such as allergies and dietary requirements. We only collect sensitive information where it is reasonably necessary and we have consent or another lawful basis. Users should provide only the minimum information needed for the relevant service.

3. How we collect personal information

We may collect personal information directly from you when you create or use an account, place or manage an order, contact us, respond to a survey or otherwise use the Services. We may also collect personal information from a school, another authorised account holder, a payment provider, an integration partner or another person where you have authorised the collection or where it is permitted by law.

Where practicable, we provide a collection notice at or before collection. If you provide another person’s information, including a child’s information, you must be authorised to do so and should make them or their parent or guardian aware of this Privacy Policy. If required information is not provided, we may be unable to provide some Services.

4. Information provided by schools

A school may provide us with personal information or enable an integration so that we can deliver the Services to that school community. We use school-provided personal information only to provide, support, secure and administer the contracted Services, comply with the school’s lawful instructions, meet legal obligations, and improve the reliability and safety of the Services.

We do not use identifiable student information provided by a school for third-party advertising, data brokerage or unrelated commercial profiling. We restrict access to school-provided information to personnel and service providers who need it for an authorised purpose and are subject to confidentiality and security obligations. Where required by contract, we assist the school with access, correction, deletion, security and incident-response requests.

5. Children and students

Our Services may be used by parents, carers and schools for the benefit of children and students. We collect only the student information reasonably necessary for the relevant service.

A parent, carer, school or other authorised adult must have authority to provide student information or create or enable a student account. We do not knowingly permit a child to create an independent account where adult or school authorisation is required. Account holders and authorised school personnel may be able to view and manage student orders, balances, limits and account activity, depending on the service configuration.

We do not use student contact details for direct marketing and do not serve targeted advertising based on identifiable student information. Necessary service communications may be sent to operate an authorised account.

A parent, carer or school may request correction, restriction or deletion of student information, subject to identity and authority verification and any legal, accounting, dispute-resolution or security retention requirements. We design child-facing features with privacy-protective defaults and avoid collecting information that is not needed.

6. How we use personal information

We may use personal information to:

We will not use school-provided or identifiable student information for third-party advertising, sale as a data product, or unrelated commercial profiling. A materially different use will occur only with consent or where otherwise authorised by law and appropriately notified.

7. How we disclose personal information

We do not sell or rent personal information. We may disclose personal information where reasonably necessary to:

Service providers may handle personal information only for the services they provide to us or as otherwise permitted by law. We require appropriate contractual confidentiality, privacy and security obligations.

8. Overseas handling and storage

Some of our service providers may be located outside Australia or use infrastructure located outside Australia.

Where we share personal information with overseas service providers, we take reasonable steps to ensure they are required to protect that information in accordance with the Privacy Act 1988 (Cth) and use it only for the purposes for which it is shared.

School24 hosts student personal information on servers located in Australia.

Before disclosing personal information overseas, we take reasonable steps to assess the recipient and require privacy, confidentiality and security protections appropriate to the information and services. We also take steps required by the Privacy Act in relation to overseas recipients. Where a school contract requires nominated data-residency arrangements, those arrangements apply.

9. Payment information

Payments are processed through Stripe or Valpay. School24 does not store full payment card numbers or card security codes. Payment details are transmitted directly to the payment provider using encrypted connections. We may receive and retain limited payment-related information such as payer name, billing contact, transaction amount, status, token or reference, refunds, disputes and fraud indicators. Payment providers handle card information under their own privacy policies and legal obligations.

10. De-identified and aggregated information

We may create and use aggregated or de-identified information for service analytics, capacity planning, security, research and product improvement. We take reasonable steps to ensure that this information does not identify an individual and do not attempt to re-identify it, except where permitted by law to test or maintain de-identification or security controls.

11. Retention and deletion

We retain personal information only for as long as reasonably required for the purposes described in this Privacy Policy, to provide contracted services, meet legal, accounting and taxation obligations, resolve disputes, and maintain security and fraud-prevention records. Retention periods vary according to information type, school contract requirements, account status, legal limitation periods and backup cycles.

When information is no longer required, we take reasonable steps to delete it or permanently de-identify it. Following account closure or termination of a school service, active-system information will be deleted, returned or de-identified in accordance with the applicable contract and our retention schedule, subject to lawful retention needs. Residual backup copies are isolated from ordinary use and expire through controlled backup rotation. A summary of standard retention periods is available at [insert webpage address or schedule].

12. Security

We use reasonable technical and organisational safeguards designed to protect personal information against loss, misuse, interference and unauthorised access, modification or disclosure. Depending on risk, safeguards include encryption in transit and at rest, role-based access, multi-factor authentication for privileged access, logging and monitoring, secure development and change management, vulnerability and patch management, protected backups, personnel confidentiality, security awareness training, provider due diligence and incident-response procedures.

No system is completely secure. We regularly review safeguards having regard to the information, current threats, available technology and practical cost. Users must keep credentials confidential and promptly report suspected unauthorised activity.

13. Data breaches

We maintain procedures to identify, contain, investigate, assess and remediate suspected personal information breaches. Where the Notifiable Data Breaches scheme applies, we will assess suspected eligible data breaches and notify affected individuals and the Office of the Australian Information Commissioner when required.

Where an incident affects personal information handled for a school, we will notify the school without unreasonable delay after becoming aware of the incident, provide available information relevant to the response, take reasonable containment and remediation steps, and cooperate with lawful notification and investigation requirements. Contractual incident terms may provide additional protections.

14. Cookies and similar technologies

We use cookies and similar technologies to operate sessions, remember settings, maintain security, prevent fraud, measure performance and understand how the Services are used. We do not use identifiable student information for cross-site behavioural advertising.

Browser or device settings can manage cookies, although disabling essential cookies may prevent parts of the Services from functioning. Our Cookie Notice at [insert webpage address] identifies the main categories, purposes, typical duration and controls.

15. Third-party services and integrations

The Services may link to third-party websites or connect with services selected by a school or user. This Privacy Policy does not govern a third party’s independent handling. Where a third party acts as our service provider, its handling is governed by contractual requirements; where it acts independently, its own privacy policy and obligations apply.

16. Access, correction and other requests

You may ask us to provide access to personal information we hold about you and to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. You may also ask us to delete information, withdraw consent, or restrict or object to particular handling. These additional requests are considered having regard to applicable law, the relevant school’s authority, our contracts, and legal, security, accounting or dispute-resolution needs.

We may need to verify identity and, for student information, authority. If information is controlled through a school account, we may refer or coordinate the request with the school. We will respond within a reasonable period. If we lawfully refuse a request, we will explain the reason and complaint options unless doing so would be unlawful or unreasonable.

17. Privacy complaints

If you believe we have mishandled personal information or not dealt appropriately with an access or correction request, contact our Privacy Officer and describe the concern. We will acknowledge and investigate the complaint fairly, may request further information, and aim to provide a written outcome within a reasonable period.

Where a complaint concerns information handled for a school, we may coordinate with that school while protecting confidentiality. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner at www.oaic.gov.au.

18. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to law, technology, the Services or our handling practices. The current version will be published with an effective date and version number. For material changes, we will take reasonable steps to provide additional notice through the Services, by email to account holders, or to affected school clients. Contractual notice requirements continue to apply where they provide greater protection.

19. Contact us

Privacy Officer
eDimensions Pty Ltd, trading as School24
Email: info@school24.net.au
Telephone: 1300 067 337

Please use “Privacy Request” in the subject line and include enough information to identify the relevant account or service. Do not send passwords or full payment card details by email.

20. Definitions

Personal information has the meaning given in the Privacy Act 1988 (Cth) and generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Sensitive information has the meaning given in the Privacy Act and includes certain information about health, disability, racial or ethnic origin, religious beliefs and other protected matters.

School includes a school, college, education provider or other organisation that has contracted for or authorised use of the Services.