Legal

Privacy Policy

Version 1.0 ·Updated 2026-08-31

Next reviewed by 2027-02-28.

Written for parents, students and staff whose information a school holds, and the schools answering to them.

Who holds your information

Kestrel is a student information system published by Seraco Pty Ltd (ABN 36 673 560 757), a company registered in Victoria, Australia. Schools use it to hold the records of the people connected to them.

Two organisations are involved in any record Kestrel holds, and they answer for different things. The school decides what to collect about a person and why. It is the organisation a family or a member of staff has a relationship with, and it is the one that owns the record. Seraco Pty Ltd runs the software and holds that record on the school's behalf.

If you are a parent, a student or a member of staff, the school is usually the quickest place to start, because the school knows who you are and we do not. This policy covers what Seraco does with the information while it is in Kestrel, and every way of reaching us directly is on this page.

We hold ourselves to the Australian Privacy Principles in everything set out below.

What Kestrel holds

This is the whole of it. A school types some of it in and generates the rest by using the software.

A person on a school's record
Their name, and any earlier name the school has recorded. Their date of birth, their gender, and the date of death where the school has recorded one. The language to write to them in. Every affiliation they hold with the school: enquiry, applicant, student, staff, volunteer, contractor or board member. For each one, the dates it ran between and the reason it ended.
A member of staff who signs in
Their name and email address. The public key of each passkey registered to the account, and the kind of device it came from. A record of each sign-in session, which is what keeps them signed in from one page to the next. Each session record includes the network address and the browser it started from.
Nobody at all
No password is stored for anyone, because Kestrel has no password sign-in to store one for. There is no password to leak, reuse or phish.

The list above is the record as it stands. If Kestrel starts to hold a new kind of information about a person, this policy changes first to describe it, and the version and date at the top of the page change with it.

Why it is held

  • To give a school a working record of the people connected to it, so the office can tell one person from another.
  • To hold a former name against the person it belongs to, which is often the only thing connecting an adult to their own student record.
  • To sign a member of staff in, keep them signed in, and let them remove a passkey from a device they no longer have.
  • To write to a person in the language they read.
  • To meet the record-keeping obligations a school is under, which set how long several kinds of record have to be kept.

What we do not do with it

  • No advertising, and no advertising network is contacted.
  • No analytics, no product telemetry and no session recording. The content policy the browser enforces blocks every external origin, so a script of that kind could not run even if one were added.
  • No profiling, scoring or ranking of any person.
  • No sale, rental or exchange of personal information with anyone.
  • No model training. Kestrel runs no model at all: the question box on the enrolment board matches keywords against the board in front of it.

Who else sees it

Everyone outside Seraco Pty Ltd who touches any part of this is listed below, with what reaches each of them. Nothing else receives anything. The security page shows the same list, because both pages read it from one place.

The hosting provider

Runs the virtual machine that hosts the application and its database.

Receives All of it, as the operator of the host.

In Australia

Let's Encrypt

Issues the TLS certificate that secures the connection to the site.

Receives The domain name. No personal information.

In United States

Resend

Delivers the one-time code that signs a member of staff in by email.

Receives The email address the code goes to, and the code. No student information.

In United States

We disclose a school's records to nobody else. Where a court order, a warrant or a law compels us to hand something over, we tell the school before we do it, unless the order itself forbids us from telling them.

Where it is held, and what leaves Australia

Every school record Kestrel holds is in Australia, on one virtual machine, in one PostgreSQL database, with each school's records in their own schema inside it. The backups are encrypted and kept on that same machine, so they are in Australia too. The test environment holds invented data and no real person's record.

One thing leaves the country. When a member of staff asks for a sign-in code by email, the address that code goes to reaches Let's Encrypt in United States, Resend in United States. No student information is in that message. Signing in with a passkey sends nothing to anyone: the key never leaves the device it was made on.

Government identifiers

Kestrel identifies a person by a random identifier its own database generates. It does not adopt a government-related identifier as its own way of identifying anyone, and it holds no such identifier for any person. That covers a tax file number, a Medicare number and a student number issued by a government.

Getting a copy of your information, or correcting it

You can ask for a copy of what is held about you, and you can ask us to correct anything in it that is wrong. Both are rights you hold, and neither costs anything.

Ask the school first. The school holds the relationship with you and can answer most requests from the screen in front of them. If the school cannot, or if you would rather come to us, write to privacy@seraco.io and tell us which school's record you are asking about.

  • We acknowledge your request within 5 business days, and we answer it within 30 days.
  • We have to be sure who you are before we hand anything over, so we may ask you to confirm your identity through the school.
  • If we correct something, we tell you what changed. If we do not agree that a record is wrong, we tell you why in writing, and we tell you how to complain about that decision.
  • If we refuse a request, we give you our reason in writing. There are requests we have to refuse, such as one that would disclose another person's information or breach a court order about a child.

Making a complaint

Write to privacy@seraco.io and say that you are making a privacy complaint. We acknowledge it within 5 business days and answer it within 30 days, in writing, with what we found and what we did about it.

If our answer does not satisfy you, you can take the complaint to the Office of the Australian Information Commissioner, the regulator for privacy in Australia. The OAIC takes complaints at oaic.gov.au and on 1300 363 992. You do not need our permission to go to them, and you can go to them at any point.

How long it is kept

A school record has a retention class rather than a delete button, because a student's file outlives their enrolment by decades and an attendance register is evidence. Child-safety records are kept for 45 years, counted from the child's date of birth. Attendance registers are kept for 7 years. An enquiry that never became an application is kept for 2 years and is then disposed of. A record under legal hold is kept whatever its age.

Taking a record out of the working set and disposing of it are two separate acts. The security page lists every class and the obligation behind each one.

How it is protected

Each school's records are in their own database schema, reached through a database role with privileges on that schema and no other. PostgreSQL itself refuses a crossing between two schools, so the refusal does not depend on our code getting a query right. Sign-in is by passkey, with a one-time email code as the fallback, and every route that serves student data checks the session on the server.

The security page sets out every protection and what each one stops.

If something goes wrong

If we find that someone has reached a school's data without authorisation, we contact that school's nominated privacy contact directly, in writing, with what we know and what we do not. Australia's Notifiable Data Breaches scheme requires an assessment within 30 days, and notification to the people affected and to the OAIC where serious harm is likely. The school is the organisation with the relationship to those families, so our job is to give the school what it needs to make that assessment quickly.

Changes to this policy

The version and the date at the top of this page tell you which edition you are reading, and the page tells you when its review date has passed.

We write to every school before a change to this policy takes effect, and the letter tells them what changed. A change to what Kestrel holds about a person is published here before the software starts holding it.

How to reach us

The privacy officer for Seraco Pty Ltd is Andrew Todd. Write to privacy@seraco.io for anything on this page: a copy of your information, a correction, a complaint, or a question this policy does not answer.

To report a security vulnerability, write to security@seraco.io instead, which reaches the same people faster.