Legal

Privacy Policy

Version 1.5 ·Updated 2026-09-19

Next reviewed by 2027-02-28.

Written for parents, students and staff whose information a school keeps, and the schools answering to them.

Who holds your information

Kestrel is a student information system published by Seraco Pty Ltd (ABN 36 673 560 757), a company registered in Victoria, Australia. Schools use it to hold the records of the people connected to them.

Two organisations are involved in any record Kestrel holds, and they answer for different things. The school decides what to collect about a person and why. It is the organisation a family or a member of staff has a relationship with, and it owns the record. Seraco Pty Ltd runs the software and holds that record on the school's behalf.

If you are a parent, a student or a member of staff, the school is usually the quickest place to start. The school knows who you are, and we do not. This policy covers what Seraco does with the information while it is in Kestrel. All the ways to reach us directly are on this page.

We commit to the Australian Privacy Principles in everything set out below.

What Kestrel holds

This is the whole of it. A school types some of it in and generates the rest by using the software.

A person on a school's record
Kestrel holds their name and any earlier name the school has recorded, and their date of birth and gender. It holds the date of death where the school has recorded one, and the language to write to them in. It holds each affiliation they have with the school: enquiry, applicant, student, staff, volunteer, contractor or board member. For each affiliation, it holds the dates it ran between and the reason it ended.
A member of staff who signs in
Kestrel holds their name and email address. It holds the public key of each passkey registered to the account, and the kind of device it came from. It holds a record of each sign-in session, which keeps them signed in from one page to the next. Each session record includes the network address and the browser it started from. While Kestrel is open in front of them, the session record also keeps the address of the page on screen and the time it was last reported, which an administrator at that school reads to see who is working in the console. Each identifier in that address is replaced with a marker before it is stored, so the record names the screen and never the person or the record on it. One report replaces the one before it, and the whole of it goes when the session ends. It stores the photo they add to their account as a copy 256 pixels square, and discards the image they uploaded.
No-one at all
No password is stored for anyone, because Kestrel has no password sign-in and so no password to leak, reuse or phish.

The list above is the record as it stands. If Kestrel starts to hold a new kind of information about a person, this policy changes first to describe it. The version and date at the top of the page change with it.

Why it is held

  • To give a school a working record of the people connected to it, so the office can tell one person from another.
  • To keep a former name with the person it belongs to, which is often the only thing connecting an adult to their own student record.
  • To sign a member of staff in, keep them signed in, and let them remove a passkey from a device they no longer have.
  • To show a school's administrators who is signed in at this moment and the page each of them has open, so the school knows who is working before it changes a setting everyone there relies on.
  • To show the photo a member of staff adds to their account beside their name, to the staff at each school they work at.
  • To write to a person in the language they read.
  • To meet the record-keeping obligations a school is under, which set how long several kinds of record have to be kept.

What we do not do with it

  • There is no advertising, and no advertising network is contacted.
  • There is no analytics, no product telemetry and no session recording. Nothing sends Kestrel what a person typed, clicked or read on a page. The content policy the browser enforces blocks all external origins, so a script of that kind could not run even if one were added.
  • There is no tracking of where a member of staff is. The page an open console reports is the screen it has drawn, kept for as long as that screen is the current one, and Kestrel keeps no history of the screens anyone visited. The browser tab remembers the last few pages opened in it, by their titles, so its back button and its list of recent pages work. That list stays in the tab and is never sent to Kestrel. It is emptied at sign-out, and the browser discards it when the tab closes.
  • There is no profiling, scoring or ranking of any person.
  • There is no sale, rental or exchange of personal information with anyone.
  • There is no model training. Kestrel runs no model: the question box on the enrolment board matches keywords against what the board shows.

Who else sees it

Everyone outside Seraco Pty Ltd who handles any part of this information is listed below, with what reaches each of them. Nothing else receives anything. The security page shows the same list, because both pages read it from one place.

The hosting provider

Runs the virtual machine that hosts the application and its database.

Receives All of it, as the operator of the host.

In Australia

Let's Encrypt

Issues the TLS certificate that secures the connection to the site.

Receives The domain name. No personal information.

In United States

Resend

Delivers the one-time code that signs a member of staff in by email.

Receives The email address the code goes to, and the code. No student information.

In United States

We disclose a school's records to no-one else. Where a court order, a warrant or a law compels us to hand something over, we tell the school before we do it, unless the order itself forbids us from telling them.

Where it is held, and what leaves Australia

All school records Kestrel holds are in Australia, on one virtual machine, in one PostgreSQL database. Each school's records are in their own schema inside it. The backups are encrypted and kept on that same machine, so they are in Australia too. The test environment contains invented data and no real person's record.

One thing leaves the country. When a member of staff asks for a sign-in code by email, the address that code goes to reaches Let's Encrypt in United States, Resend in United States. No student information is in that message. Signing in with a passkey sends nothing to anyone: the key never leaves the device it was made on.

Government identifiers

Kestrel identifies a person by a random identifier its own database generates. It does not adopt a government-related identifier as its own way of identifying anyone, and it holds no such identifier for any person. That covers a tax file number, a Medicare number and a student number issued by a government.

Getting a copy of your information, correcting it, or asking us to delete it

You can ask for a copy of what is held about you. You can ask us to correct anything in it that is wrong, and you can ask us to delete it. The first two are rights you hold, and we answer the third as far as the law lets us. None of them costs anything.

Ask the school first. The school has the relationship with you and can answer most requests directly in Kestrel. If the school cannot, or if you would rather come to us, write to privacy@seraco.io and tell us which school's record you are asking about.

Your request is recorded from the day it arrives, with a reference you can quote back to us and the two dates below on it. That way the school and we can both see what is owed to you, and when.

  • We acknowledge your request within 5 business days, and we answer it within 30 days.
  • We have to be sure who you are before we hand anything over, so we may ask you to confirm your identity through the school. If you are asking about a child, we check that you are entitled to their record.
  • If we correct something, we tell you what changed. A correction keeps the earlier version on the record, with the dates it applied over. A school is often asked what it held on a date in the past.
  • If we do not agree that a record is wrong, we tell you why in writing, and we tell you how to complain about that decision.
  • Deletion is limited by how long records have to be kept. Where you ask us to delete something a school is obliged to hold, we take it out of everyday use, we tell you which parts are being kept, which obligation keeps them and when that period ends, and it is disposed of when the period ends. The section on how long it is kept sets out those periods.
  • If we refuse a request, we give you our reason in writing. There are requests we have to refuse, such as one that would disclose another person's information or breach a court order about a child.

Making a complaint

Write to privacy@seraco.io and say that you are making a privacy complaint. We acknowledge it within 5 business days and answer it within 30 days, in writing, with what we found and what we did about it.

If our answer does not satisfy you, you can take the complaint to the Office of the Australian Information Commissioner, the regulator for privacy in Australia. The OAIC takes complaints at oaic.gov.au and on 1300 363 992. You do not need our permission to go to them, and you can go to them at any point.

How long it is kept

A school record has a retention class rather than a delete button, because a student's file outlives their enrolment by decades and an attendance register is evidence. Child-safety records are kept for 45 years, counted from the child's date of birth. Attendance registers are kept for 7 years. An enquiry that never became an application is kept for 2 years and is then disposed of. A record under legal hold is kept whatever its age.

Taking a record out of the working set and disposing of it are two separate acts. The security page lists each class and the obligation behind it.

How it is protected

Each school's records are in their own database schema, reached through a database role with privileges on that schema and no other. PostgreSQL itself stops one school's role from reaching another school's schema, so that protection does not depend on our code getting a query right. Sign-in is by passkey, with a one-time email code as the fallback. Each route that serves student data checks the session on the server.

The security page sets out each protection and what it stops.

If something goes wrong

If we find that someone has reached a school's data without authorisation, we contact that school's nominated privacy contact directly, in writing, with what we know and what we do not. Australia's Notifiable Data Breaches scheme requires an assessment within 30 days, and notification to the people affected and to the OAIC where serious harm is likely. The school has the relationship with those families, so our job is to give it what it needs to make that assessment quickly.

Changes to this policy

The version and the date at the top of this page tell you which edition you are reading. The page also tells you when its review date has passed.

We write to each school before a change to this policy takes effect, and the letter tells them what changed. A change to what Kestrel holds about a person is published here before the software starts holding it.

How to reach us

The privacy officer for Seraco Pty Ltd is Andrew Todd. Write to privacy@seraco.io for anything on this page: a copy of your information, a correction, a complaint, or a question this policy does not answer.

To report a security vulnerability, write to security@seraco.io instead, which reaches the same people faster.