§ · Imprint · Privacy

Privacy statement.

Plain English, in the order a privacy officer reads it. Last revised 5 September 2026. The entity name and ABN will appear here once registered. (founder to confirm)

The statement

1. Who we are and which laws apply

Coord (coord.tools) is a software service for university staff in Australia. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Universities are bound by the Commonwealth Act or by state and territory information privacy schemes, and your organisation stays responsible for the student data it brings into Coord; we act as its processor for that data.1

2. What we collect

Account information
Your name, email address and, if you choose to sign in by text message, your Australian mobile number. Sign-in challenges, session records and the device notice we send when a new device signs in.
Organisation information
The organisation's name, university preset, vocabulary, timezone, plan and billing status. Billing details are held by Stripe, not by us.
Student data your organisation imports
Student number, name, enrolment status, group membership, marks, and the exceptions a coordinator records. Optionally, if imported: email address and mobile number (encrypted at rest), an international-student flag, and an access-plan type. We never collect a diagnosis, Indigenous status, agent details or a student password, and imports that carry them are refused.2
Usage and technical information
Request identifiers, error events and product analytics counts without personal information in them. No advertising or third-party analytics scripts run on the site or in the app.
Correspondence
What you send through the contact form or by email, used to reply to you.

3. Why we use it

To run the service for your organisation: signing you in, showing you your offerings, sending messages you ask us to send, producing the exports you request, and enforcing plan limits. To keep the service safe: rate limiting, abuse detection and audit logs. To bill paid plans. We do not sell personal information, use it for advertising, or train models on it.

4. Where it is

Coord runs on Cloudflare. Primary stores (database, files, live collaboration state) are placed in Cloudflare's Oceania region using location hints. Cloudflare does not offer an Australian jurisdictional restriction for its D1 database or KV store, so we do not claim that every replica, backup or log stays in Australia. Our privacy strategy is data minimisation: what may leave the country is designed not to be personal information.3

5. Who we share it with

  • Cloudflare: hosting, storage, email delivery and AI inference. Student names and identifiers are pseudonymised before any AI model sees them.4
  • Twilio: text messages to Australian mobiles, only for people who opted in; the only external service we use.4
  • Stripe: card payments and invoices for paid plans. We never see or store card numbers.
  • Nobody else, unless the law requires it, in which case we tell your organisation unless we are prohibited from doing so.

6. How long we keep it

Student personal information is purged twelve months after the offering ends by default; your organisation can shorten or lengthen this in its retention policy. Account information is kept while you have an account. Audit logs are kept for as long as the organisation exists, because they are the record your organisation may need. Deleted organisations are removed by a job that also clears files and search indexes, and a receipt is produced.5

7. Your rights and your organisation's

You can see and change your account details in Settings, revoke sessions, export everything your organisation holds (JSON, CSV and files) at any time, and delete your account or your organisation. A student who wants to know what a university holds about them should ask the university, which remains the data controller; we will help the university answer within its statutory timeframe.

8. Security

Transport is encrypted. Student email, phone and notes are encrypted at rest with a key specific to your organisation. Sign-in uses a link and a code rather than a password. Access to student personal information is a permission, not a role, and every change is audited. The full list is on the security page.5

9. Breaches

If we become aware of a breach that is likely to cause serious harm, we will notify affected organisations promptly so they can meet their own obligations, and we will notify the Office of the Australian Information Commissioner where the Privacy Act requires it. We keep an incident plan that assumes state-scheme timeframes as well as the Commonwealth ones.6

10. Cookies

One cookie, coord_session, keeps you signed in. The marketing site stores your theme and university choice in your own browser's local storage and sends neither to us. There are no tracking cookies.

11. Changes and contact

We will note material changes on the changelog and, for organisations on paid plans, by email. Questions and complaints go to hello@coord.tools; we reply within two working days, and you may also complain to the Office of the Australian Information Commissioner.

Notes

  1. Which privacy law binds a university depends on its jurisdiction: the Privacy Act 1988 (Cth) for some, and state schemes such as the Privacy and Personal Information Protection Act 1998 (NSW), the Privacy and Data Protection Act 2014 (Vic) and the Information Privacy Act 2009 (Qld) for others. Regulation and quality research §6.1.
  2. Sensitive information under the Privacy Act and state principles includes health information and racial or ethnic origin; a teaching tool should not store diagnoses or Indigenous status. Privacy Act 1988 s 6; Maiam nayri Wingara principles (2018); Victorian Information Privacy Principle 10.
  3. Cloudflare's documentation states that D1 “Jurisdictional Restrictions (data location / storage) options are not supported today” and likewise for Workers KV; location hints influence primary placement but are not a residency guarantee. Cloudflare, Data Localization Suite compatibility documentation.
  4. Everything runs on Cloudflare; Twilio is the only external service and is used for SMS; AI inputs are pseudonymised. Coord architecture decisions #2, #10, #12.
  5. Retention, encryption, audit, export and deletion behaviour as built. Coord engineering conventions §7; see Security.
  6. The education sector lodged 81 notifiable data breaches in 2025; total notifications reached 1,205. Office of the Australian Information Commissioner, Notifiable Data Breaches report, 2025.