Privacy Policy
1. Introduction
Conexet Pty Ltd (ACN 697 521 912) ("Conexet", "we", "us", or "our") is committed to maintaining the privacy and confidentiality of the personal information of Conexet’s customers in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) (Privacy Act) and in accordance with other applicable privacy laws.
This Privacy Policy describes how we collect, hold, use, disclose, and protect personal information in connection with all Conexet-branded software products and services (each, a "Product"), our website (the "Website"), and related services (collectively, the "Services").
2. Key Terms
"Personal information" has the meaning given in the Privacy Act, and includes information or an opinion about an identified individual, or an individual who is reasonably identifiable.
"Sensitive information" has the meaning given in the Privacy Act and includes information about an individual's health, racial or ethnic origin, political opinions, religious beliefs, or membership of professional or trade associations.
"Customer Data" means data that a Product retrieves from, or processes on behalf of, a Customer, including data drawn from the Customer's third-party systems and configured environments. The categories of Customer Data handled by a particular Product are described in its Product Schedule.
3. Personal Information We Collect
The kinds of personal information we collect depend on how you interact with us and on which Products you use, but will typically include:
3.1 Customer account information
When a Customer subscribes to, evaluates, or makes enquiries about a Product, we may collect:
• school, organisation, or entity name and address;
• names, job titles, business email addresses, and business telephone numbers of representatives, administrators, and billing contacts;
• billing and payment information (note: card details are processed by our payment provider; Conexet does not store full card numbers);
• subscription and licence information, including Licence Keys, plan type, term, and renewal status;
• information identifying the Customer's parent organisation or affiliated bodies (such as a multi-academy trust, diocese, or education department);
• any additional information relating to you that you provide to us directly through our website or Product or indirectly through your use of our website or Product or online presence or through other websites or accounts from which you permit us to collect;
• information collected via electronic communications, which may include internet protocol addresses, the time, date and place of the communication;
• correspondence and support tickets, including the contents of emails or messages you send us; and
• information you provide to us through customer surveys;
• information which is collected through the provision of the services Conexet is engaged by the customer to provide, including information collected for the purposes of web-hosting and providing back-up services; and
• any additional Personal Information you provide to us, or authorise us to collect, as part of your interaction with Conexet.
3.2 Technical and diagnostic information
When a Product is installed, activated, or used, the Product and Conexet's cloud services may automatically collect:
• Product version, build identifier, and configuration;
• operating system version and basic device or machine identifiers required for licence validation;
• IP address and approximate geolocation derived from IP address;
• error logs, crash reports, and stack traces;
• usage statistics, feature interaction events, and performance metrics; and
• licence validation events, including timestamps and the Licence Key used.
3.3 Operational information
To deliver each Product's core functionality, we may collect or store operational information, including:
• configuration data describing how the Product is set up in the Customer's environment;
• task and scheduling information (such as when scheduled operations run); and
• operation outcomes (such as success and failure logs).
The categories of operational information held by a particular Product are described in its Product Schedule.
3.4 Website information
When you visit the Website, we may collect information such as your IP address, browser type and version, referring URL, pages viewed, and the date and time of visits, including through cookies and similar technologies (see clause 11).
3.5 Customer Data passing through the Products
Many of our Products are designed to retrieve, transform, or process Customer Data drawn from systems operated by the Customer. This Customer Data may include personal information about staff, casual employees, contractors, students, parents, or other individuals connected to the Customer's organisation.
In normal operation, Customer Data is processed locally on the Customer's device or within an environment controlled by the Customer, and is not transmitted to Conexet, except where:
• the Customer enables a feature that requires transmission (for example, cloud-based scheduling, hosted services, or off-device logging);
• the Customer voluntarily provides Customer Data to Conexet for support or troubleshooting purposes; or
• limited summary diagnostic information necessary for a Product to function (for example, counts, timestamps, and error codes) is included in telemetry.
The specific data-handling characteristics of each Product (including whether Customer Data is transmitted to Conexet's infrastructure or remains local) are described in the applicable Product Schedule.
3.6 Sensitive information
We do not seek to collect sensitive information. The Customer is responsible for ensuring that any sensitive information processed through any Product is collected and handled in accordance with the Privacy Act and any consents the Customer has obtained from the relevant individuals.
3.7 Information about children
Our Products are supplied to schools and other education-sector organisations, not directly to children. Customer Data may include information about students (including children), such as enrolment, attendance, allocation, or wellbeing information, drawn from the Customer's systems. Conexet does not knowingly collect personal information directly from children, and does not target the Services to children. The Customer is responsible for ensuring that it has the necessary authority and parental or guardian consents (where required) for the processing of student information through any Product.
4. How We Collect Personal Information
Conexet generally collects Personal Information directly from you. We may collect and update your Personal Information over the phone, by email, over the internet or social media, or in person. We may also collect Personal Information about you from other sources.
We may collect personal information:
• directly from you when you contact us, subscribe to a Product, complete a form, or attend a meeting or demonstration;
• from your installation and use of a Product, including through automated collection of technical, diagnostic, and operational information described in clause 3;
• from the Website, including through cookies and analytics tools;
• from third parties, such as referrals from existing Customers, professional service providers, education-sector partners, or publicly available sources; and
• from the Customer, where the Customer provides information about its personnel or operations to us for the purpose of receiving the Services.
You can always decline to give Conexet any Personal Information we request, but that may mean we cannot provide you with some or all of the services you have requested. If you have any concerns about personal information we have requested, please let us know.
5. How We Use Personal Information
Conexet collects Personal Information reasonably necessary to carry out our business, to assess and manage our clients’ needs, and provide the Product and associates support services, including maintenance. We may also collect information to fulfil administrative functions associated with these services, for example billing, entering into contracts with you or third parties and managing client relationships.
The purposes for which Conexet usually collects and uses Personal Information depends on the nature of your interaction with us, but may include:
• to provide, operate, maintain, and support the Products and the Services;
• to validate licences, manage subscriptions, and process payments;
• to deliver software updates, patches, and security fixes;
• to respond to enquiries, support requests, and complaints;
• to monitor, troubleshoot, diagnose, secure, and improve the Products, including by analysing error logs and usage statistics;
• to detect, prevent, and respond to fraud, abuse, security incidents, and breaches of our terms;
• to communicate with Customers about service-related matters, including outages, changes, new releases, and end-of-life notices;
• with the recipient's consent (or where otherwise permitted by law), to send marketing communications about Conexet Products and services. Recipients may opt out at any time by using the unsubscribe link in any marketing message or by contacting us using the details in clause 14;
• to comply with our legal obligations, including under tax law and the Privacy Act; and
• for any other purpose disclosed to you at the time of collection or to which you have consented.
We will not use personal information for a secondary purpose unless you have consented, or the secondary purpose is related to the primary purpose of collection and you would reasonably expect us to use the information for that secondary purpose, or use is otherwise permitted or required by law.
6. Does Conexet use your Personal Information for direct marketing?
We may send you direct marketing communications and information about our services and products. This may take the form of emails, SMS, mail or other forms of communication, in accordance with the Spam Act and the Privacy Act. You may opt-out of receiving marketing materials from us by contacting us using the details set out below or by using the opt-out facilities provided (eg an unsubscribe link).
If you opt-out of receiving marketing material from us, we may still contact you in relation to our ongoing relationship with you.
7. How does Conexet interact with you via the internet?
You may visit our website without identifying yourself. If you identify yourself (for example, by providing your contact details in an enquiry), any personal information you provide to Conexet will be managed in accordance with this Privacy Policy.
Conexet’s websites use cookies. A “cookie” is a small file stored on your computer's browser, which assists in managing customised settings of the website and delivering content. We collect certain information such as your device type, browser type, IP address, pages you have accessed on our websites and on third-party websites. You are not identifiable from such information.
You can use the settings in your browser to control how your browser deals with cookies. However, in doing so, you may be unable to access certain pages or content on our website.
Conexet may also use cookies to enable us to collect data that may include Personal Information. For example, where a cookie is linked to your account, it will be considered Personal Information under the Privacy Act. We will handle any Personal Information collected by cookies in the same way that we handle all other personal information as described in this Privacy Policy.
Conexet’s websites may contain links to third-party websites. Conexet is not responsible for the content or privacy practices of websites that are linked to our website.
8. Use and Disclosure of Personal Information
We do not sell personal information.
The purposes for which we may use and disclose your Personal Information will depend on the services we are providing you. For example, if you have engaged us to deliver a service, we may disclose information about you to service providers where this is relevant to our services.
We may disclose personal information to the following categories of recipients, only to the extent reasonably necessary:
• cloud infrastructure and platform providers — in particular, Microsoft Corporation and its affiliates in respect of Microsoft Azure services used to host Conexet's cloud infrastructure;
• payment, billing, accounting, and tax service providers;
• customer support, ticketing, communications, email, and analytics service providers;
• professional advisers, including lawyers, accountants, auditors, and insurers, where bound by obligations of confidentiality;
• the Customer (and its authorised representatives) in respect of the Customer's own subscription, account, and Customer Data;
• law enforcement agencies, regulators, courts, or other government authorities where required or authorised by law, or where reasonably necessary to investigate suspected unlawful activity, enforce our rights, or protect the safety of any person;
• a successor or acquirer in the event of a sale, merger, restructure, or transfer of all or part of Conexet's business or assets, subject to the recipient being bound by obligations of confidentiality consistent with this Policy; and
• any other person to whom you have consented to the disclosure.
We require our service providers to handle personal information in accordance with the Privacy Act or equivalent standards, and to use personal information only for the purposes for which it was disclosed.
9. Overseas Disclosure
Conexet's primary cloud infrastructure is hosted on Microsoft Azure in Australian regions. However, some of our service providers (including cloud, support, communications, analytics, and security providers) may store or process personal information outside Australia. Recipients may be located in countries including the United States, the United Kingdom, the European Union, Ireland, Singapore, and other jurisdictions in which our service providers operate.
Before disclosing personal information overseas, we take steps that are reasonable in the circumstances to ensure that the overseas recipient does not breach the APPs in relation to that information, unless an exception applies.
10. Data Security
We take reasonable steps to protect personal information from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. Our security measures include:
• hosting on enterprise-grade cloud infrastructure with appropriate physical and network security controls;
• encryption of data in transit using current industry-standard transport-layer protocols (such as TLS);
• encryption of data at rest where supported by the underlying infrastructure;
• role-based access controls and the principle of least privilege for administrative access;
• multi-factor authentication for administrative systems;
• logging, monitoring, and alerting for suspicious activity;
• regular patching and updating of systems and dependencies; and
• internal policies and training for personnel who handle personal information.
Our websites do not necessarily use encryption or other technologies to ensure the secure transmission of information via the internet. Users of our websites are encouraged to exercise care in sending personal information via the internet.
To the maximum extent permitted by law, Conexet will not be liable for any loss, corruption, delay or loss of confidentiality arising from any data or information transmitted electronically.
11. Data Retention
We retain personal information only for as long as is reasonably necessary for the purposes for which it was collected, or as required by law. Indicative retention periods include:
• Customer account and subscription information: for the duration of the subscription, and for up to seven (7) years thereafter for tax, accounting, and legal compliance purposes;
• billing and payment records: at least seven (7) years, in line with Australian tax recordkeeping obligations;
• support correspondence and tickets: for the duration of the subscription, and typically up to three (3) years thereafter;
• error logs, crash reports, and diagnostic telemetry: typically up to ninety (90) days, after which records are deleted or aggregated;
• Website analytics data: typically up to twenty-six (26) months in identifiable form; and
• backups: held in accordance with our backup rotation, typically up to thirty (30) days.
Product Schedules may set out additional or different retention periods for Product-specific data. When personal information is no longer required, we will take reasonable steps to destroy or de-identify it, subject to any legal obligation to retain it.
12. Customer Responsibilities
Where Customers use any Product, the Customer is solely responsible for:
• complying with its own privacy obligations under applicable law, including the Privacy Act and any state-based, sector-specific, or jurisdiction-specific obligations relating to schools, staff, and student data;
• obtaining any necessary consents, authorities, and notices from individuals whose personal information is processed through any Product;
• securely storing outputs produced by any Product on the Customer's devices and networks;
• managing access permissions to each Product and to its outputs within the Customer's organisation;
• maintaining the security of credentials, including Licence Keys, third-party API credentials, and any operating-system accounts used to run a Product; and
• notifying Conexet promptly if the Customer becomes aware of a suspected or actual data breach affecting any Product or Customer Data.
13. Your Rights — Access, Correction, and Complaints
13.1 Access and correction
You have the right to request access to personal information we hold about you, and to request correction of that information if it is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond to your request within a reasonable period (and in any event within thirty (30) days where practicable). We may require verification of your identity before responding to a request. We do not generally charge for access requests, but may charge a reasonable cost-based fee for retrieving and providing the information.
In limited circumstances, we may decline a request for access or correction (for example, where required or authorised by law). If we decline a request, we will provide written reasons and explain the available complaint mechanisms.
13.2 Withdrawal of consent and deletion
You may withdraw your consent to our use of your personal information for marketing purposes at any time. You may also request that we delete personal information we hold about you. We will comply with such requests to the extent required by law, subject to our right to retain information where retention is required or authorised by law (for example, for tax, audit, or legal-defence purposes).
13.3 Complaints
If you have a complaint about how we have handled your personal information, please contact our Privacy Officer using the details in clause 14. We will acknowledge your complaint promptly and aim to provide a substantive response within thirty (30) days. If you are not satisfied with our response, you may make a complaint to the Office of the Australian Information Commissioner (OAIC):
• Website: www.oaic.gov.au
• Phone: 1300 363 992
• Post: GPO Box 5288, Sydney NSW 2001
14. How to Contact Us
You can contact our Privacy Officer using the details below:
Privacy Officer, Conexet Pty Ltd
Email: admin@conexet.com.au
15. Governing Law
This Privacy Policy is governed by the laws of Australia. If a dispute arises under this Privacy Policy, you agree to attempt to resolve the dispute under those laws.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The current version will always be available on the Website, and the "Effective Date" at the top of this Policy indicates when it was last updated. We recommend that you visit our website regularly to keep up to date with any changes.
Conexet Pty Ltd
ACN: 697 521 912 | ABN: 73 697 521 912
This Policy is intended to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It should be read together with the Conexet Master Terms of Service and EULA and the applicable Product Schedule.
Page updated 01/06/2026