Privacy statement.
Plain English, in the order a privacy officer reads it. Last revised 5 September 2026. The entity name and ABN will appear here once registered. (founder to confirm)
Plain English, in the order a privacy officer reads it. Last revised 5 September 2026. The entity name and ABN will appear here once registered. (founder to confirm)
Coord (coord.tools) is a software service for university staff in Australia. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Universities are bound by the Commonwealth Act or by state and territory information privacy schemes, and your organisation stays responsible for the student data it brings into Coord; we act as its processor for that data.1
To run the service for your organisation: signing you in, showing you your offerings, sending messages you ask us to send, producing the exports you request, and enforcing plan limits. To keep the service safe: rate limiting, abuse detection and audit logs. To bill paid plans. We do not sell personal information, use it for advertising, or train models on it.
Coord runs on Cloudflare. Primary stores (database, files, live collaboration state) are placed in Cloudflare's Oceania region using location hints. Cloudflare does not offer an Australian jurisdictional restriction for its D1 database or KV store, so we do not claim that every replica, backup or log stays in Australia. Our privacy strategy is data minimisation: what may leave the country is designed not to be personal information.3
Student personal information is purged twelve months after the offering ends by default; your organisation can shorten or lengthen this in its retention policy. Account information is kept while you have an account. Audit logs are kept for as long as the organisation exists, because they are the record your organisation may need. Deleted organisations are removed by a job that also clears files and search indexes, and a receipt is produced.5
You can see and change your account details in Settings, revoke sessions, export everything your organisation holds (JSON, CSV and files) at any time, and delete your account or your organisation. A student who wants to know what a university holds about them should ask the university, which remains the data controller; we will help the university answer within its statutory timeframe.
Transport is encrypted. Student email, phone and notes are encrypted at rest with a key specific to your organisation. Sign-in uses a link and a code rather than a password. Access to student personal information is a permission, not a role, and every change is audited. The full list is on the security page.5
If we become aware of a breach that is likely to cause serious harm, we will notify affected organisations promptly so they can meet their own obligations, and we will notify the Office of the Australian Information Commissioner where the Privacy Act requires it. We keep an incident plan that assumes state-scheme timeframes as well as the Commonwealth ones.6
One cookie, coord_session, keeps you signed in. The marketing site stores your theme and university choice in your own browser's local storage and sends neither to us. There are no tracking cookies.
We will note material changes on the changelog and, for organisations on paid plans, by email. Questions and complaints go to hello@coord.tools; we reply within two working days, and you may also complain to the Office of the Australian Information Commissioner.