Privacy Policy — Viden

Data controller: Alex Waugh, sole trader trading as River Wolf Enterprises (ABN 80 950 686 903) ("we", "us") Contact for privacy matters: videnstudy@gmail.com Last updated: 5 July 2026 Version: 1.0

1. Who we are

Viden is a curriculum-aligned study application for Victorian secondary school students, provided to schools under teacher and school administration. We are an Australian sole trader business. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and design to the expectations of the Safer Technologies 4 Schools (ST4S) framework.

2. What we collect

We collect the minimum data needed to operate the service.

Students (accounts created by their teacher — students never self-register): - Display name (as entered by the teacher; may be a first name or alias) - Class join code association - Password (stored only as a salted hash; never in plain text) - Learning activity data: question attempts, scores, XP, streaks, and spaced-repetition scheduling records

We do not collect from students: email address, date of birth, phone number, home address, photographs, location data, or any sensitive information as defined under APP 3 (health, biometric, religious, etc.). An internal system identifier in email format is generated for authentication purposes only; it is synthetic, not a real mailbox, and is never used for communication.

Teachers: - Name and school email address - Password (salted hash only) - Class and student management activity

3. Why we collect it (purpose)

We do not use personal information for advertising, profiling for commercial purposes, or training of third-party AI models. We do not sell personal information. All student personal information is stored and processed within Australia/Oceania. The only overseas processing is the delivery of teacher password-reset emails via our email provider (Brevo, European Union), which involves a teacher's email address and a reset link only; see section 5. No student information is disclosed overseas.

4. How data is stored

All personal information is stored in Australia. Data is stored in the Sydney region (ap-southeast-2) with our database provider, Supabase; application requests are processed in the Sydney region (syd1) by our hosting provider, Vercel; and encrypted off-site backups are held in the Oceania region with Cloudflare. Access is restricted by row-level security so that students can only access their own records and teachers can only access records of students in their own classes. Data is encrypted in transit (TLS 1.2 or above) and at rest (AES-256). The only processing outside Australia is the delivery of teacher password-reset emails (see section 5).

5. Disclosure and sub-processors

We do not disclose personal information to third parties except to the sub-processors listed below (which process data on our behalf), or where required by law.

Sub-processor Role Data types Location Contact
Supabase, Inc. Database, authentication, storage All student and teacher account and activity data Australia (Sydney, ap-southeast-2) supabase.com
Vercel, Inc. Application hosting and serverless compute Data in transit during request processing; no persistent storage of personal data Australia (Sydney, syd1) vercel.com
Cloudflare, Inc. Encrypted off-site database backups Backup copies of the database (student and teacher records) Oceania (Cloudflare R2) cloudflare.com
Brevo (Sendinblue SAS) Outbound transactional email (teacher password-reset messages only) Teacher email address and password-reset link European Union (Belgium, France, Germany) brevo.com

We will notify subscribing schools before adding or changing a sub-processor, or before relocating or expanding data or infrastructure.

Data location and overseas processing. All student personal information, and all live and backup storage of personal information, is held in Australia and the wider Oceania region. Student data never leaves this region. The only overseas processing is by Brevo, our transactional email provider, which is used solely to deliver password-reset emails to teachers; this involves a teacher's own email address and a reset link, and is processed in the European Union. No student information is disclosed overseas. Supabase, Vercel and Cloudflare are United States–incorporated companies but store and process the relevant data within their Australian/Oceania regions.

6. Access, correction and deletion

7. Data breach notification

We comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act. If a breach is likely to result in serious harm, we will notify affected schools, affected individuals (via the school where individuals are students), and the Office of the Australian Information Commissioner (OAIC). See our Breach Notification Process.

8. Cookies and analytics

The application uses only cookies/local storage strictly necessary for login sessions and application function. We do not use third-party advertising or tracking cookies.

9. Children's privacy

The service is designed for school students under 18. Accounts are created and mediated by teachers; students cannot sign up independently, and we collect no direct contact details from students. Consent is managed via the school under its own enrolment and ICT consent processes.

10. Changes to this policy

Material changes will be notified to subscribing schools before taking effect. The current version is always available at https://videnstudy.netlify.app/.

11. Complaints

Contact videnstudy@gmail.com first. If unresolved, you may complain to the OAIC (oaic.gov.au, 1300 363 992).