Data Processing Terms

Version 1.0, effective 17 August 2026

These are the Data Processing Terms incorporated by reference into the OurNews Subscription Agreement (Schedule 1). The Standard Terms are at /trust/terms.

1. Roles

1.1 For School Content, the School is the controller and the Provider is the processor. The Provider acts only on the School’s instructions and does nothing with School Content for its own purposes.

1.2 For account data (the names, work email addresses and sign-in records of the School’s staff users) and for the details of visitors who pass through a reveal gate on the School’s public page (the step where a reader confirms an email address before a protected story is shown), the Provider is the controller. The Provider will minimise what it collects, keep it only for a limited period (no longer than 12 months for a reveal-gate email address and 90 days for an IP address), and say so in its privacy notice.

1.3 Each party will comply with the privacy law that applies to it. For a School in Australia this includes the Privacy Act 1988 (Cth) and the Australian Privacy Principles; for a School elsewhere, this Schedule applies alongside the privacy law of the School’s jurisdiction, including the GDPR or UK GDPR where they apply.

2. What is held

2.1 The Provider holds, for the School, the content the School uploads to or creates in OurNews (media, story text, published collections, uploaded documents) and the metadata attached to it, including visibility settings and consent flags.

2.2 What the Provider does not and will not do. The Provider does not and will not: use School Content to train any AI model, whether its own or anyone else’s; run facial recognition on School Content, at any time, for any purpose; sell School Content or Personal Information, or share either for advertising; or hold class lists, parent or guardian contact details, student identification numbers, enrolment records, or any feed from a student information system.

2.3 The Provider acknowledges that an image of a child is Personal Information and treats the media library accordingly.

3. Where it is held

3.1 The School picks its region when its account is created: Australia (Sydney), the EU, the UK, the US or Singapore. Australia is the default. The account is pinned to that region when it is created.

3.2 The region covers stored data, backups, replicas, error logs, the content delivery cache for published material, and the email intake service. Regions are separated from each other by construction.

3.3 Changing region after the account is created is possible but is a manual process. The Provider will quote for it before doing it.

3.4 AI processing. OurNews runs no AI processing on School Content. From the release that introduces it, story text may be sent for transient AI processing to a provider endpoint in a region matched to the School’s, under zero-retention terms, and is never used to train any model. Stored data stays in the School’s region. The Provider does not claim that School Content never leaves the School’s jurisdiction; AI processing is the exception.

3.5 If the School chooses a region outside Australia, the School acknowledges that this is an overseas disclosure for the purposes of Australian Privacy Principle 8 and that it has satisfied itself this is appropriate. The Provider will take reasonable steps to ensure the overseas handling meets the Australian Privacy Principles. The sub-processor list at clause 4.6 of this Schedule records, for each sub-processor, where data is stored and where the personnel able to access it are located; for the Australian region, media storage is contracted with Amazon Web Services Australia Pty Ltd.

4. Security

4.1 School Content is encrypted at rest using AES-256 or an equivalent managed key service, and in transit using TLS.

4.2 A protected image is reachable only through an address the Provider controls. On every request, the Provider checks the requester against the story’s visibility setting before it issues a short-lived link to the file. A request the setting does not permit is refused, in the same terms whether the image is withheld or does not exist. Storage buckets are not public and no image is reachable by a direct storage link.

4.3 Every upload is scanned for malware and its file type is checked against its contents rather than its extension. PDF processing runs in a sandbox with no network access.

4.4 The School’s access to its data is through the application and the export in Part B clause 7.4.

4.5 The Provider’s own infrastructure access uses least-privilege credentials, managed secrets and multi-factor authentication, and media access is authorised per story. Support access to a school’s data runs through a single, logged, multi-factor-protected path.

4.6 The Provider will keep a published list of its sub-processors, covering hosting, database, email, error tracking, content delivery, malware scanning and, once it applies, its AI provider. The list is at ournews.school/trust/sub-processors. Where the Provider adds or replaces a sub-processor at its own initiative, it will give the School at least 30 days’ written notice. Where a sub-processor changes its own supply chain, the Provider will pass the change on promptly, stating the notice period that sub-processor gave. In either case the School may object on reasonable grounds.

5. Consent and takedown

5.1 Consent for images of people is the School’s responsibility, as set out in Part B clause 3.2.

5.2 The Provider will act on a takedown request from the School as soon as it can, and in any case within one business day.

5.3 A takedown removes the item from the live service immediately. Encrypted backup copies of the item are held under the “put beyond use” standard (not used to inform any decision, not shared with any other organisation, and secured) until they are purged within the window in clause 5.4.

5.4 Backups. Encrypted backup copies persist until the backup rotation window passes. The Provider’s commitment is that an item is removed from the live service immediately and purged from backups within 7 days. The Provider does not claim instant erasure everywhere.

6. Deletion at the end

6.1 When this agreement ends the School has 30 days to export its content.

6.2 After that, the Provider deletes School Content from the live service, and it is purged from backups within the retention window in clause 5.4.

6.3 The Provider will confirm the deletion in writing if the School asks.

7. Breach

7.1 If the Provider becomes aware of a breach affecting School Content, it will tell the School within 72 hours, with what it knows at the time, and will keep the School updated.

7.2 The Provider will help the School meet its own obligations under the data breach notification law that applies to the School, including the Notifiable Data Breaches scheme and its assessment within the statutory period for Australian schools, and Articles 33 and 34 of the GDPR where they apply.

7.3 Each party will tell the other before making any public statement about a breach affecting School Content, unless the law requires otherwise.

7.4 The Provider publishes its incident response process at ournews.school/trust/incident-response.

8. Audit

8.1 Once a year, on 30 days’ notice, the School may ask the Provider in writing about its security and privacy practices, and the Provider will answer in writing.

8.2 The Provider will make available any security assessment or penetration test summary it holds.

9. Sub-processing

9.1 The Provider may engage sub-processors on terms no less protective than these, and stays responsible for what they do.