Data Processing Agreement
Last reviewed: [PLACEHOLDER: review date]
Lantern is operated by [PLACEHOLDER: Ember Education Pty Ltd] (ABN [PLACEHOLDER: 11-digit ABN]; ACN [PLACEHOLDER: 9-digit ACN]) (“Ember”, “we”, “us”). When your school or education department uses Lantern to draft and check report comments, Ember processes personal information on your behalf. Our Data Processing Agreement (the “DPA”) sets out, in writing, how that processing is governed and the protections we commit to.
This page summarises the key terms. It is a plain-language overview and does not replace the executed DPA, which we make available to schools and departments on request.
Roles: controller and processor
Under the DPA, your school or education department is the data controller — you determine the purposes for which, and the manner in which, student and staff personal information is handled. Ember acts solely as the data processor, processing that information on your behalf and under your authority.
Lantern keeps the teacher as the author and approver of every comment. There are no student accounts, and student data is never used to train AI models.
Processing on documented instructions
Ember processes personal information only on your documented instructions, including with respect to transfers, unless we are otherwise required to act by Australian law — in which case we will inform you of that requirement before processing, unless the law prohibits us from doing so. The scope, nature and purpose of processing, the types of personal information, and the categories of data subjects are set out in a schedule to the DPA.
Confidentiality
Personnel authorised to process your data are bound by enforceable confidentiality obligations and are granted access only on a need-to-know basis to deliver the service. Confidentiality obligations survive the end of their engagement with Ember.
Security measures
Ember maintains appropriate technical and organisational measures to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction or damage. All data is hosted onshore in Australia (AWS Sydney, with disaster recovery in Melbourne), encrypted in transit and at rest, and access is logged in an immutable audit trail. Our controls are described in more detail on our security page.
Sub-processors
Ember engages a limited number of vetted sub-processors to help deliver Lantern. Each is bound by data-protection terms no less protective than those in the DPA. We maintain a current list of sub-processors, including their location and the function they perform, on our sub-processors page. We will give you advance notice of any intended changes so you can object before a new sub-processor begins processing your data.
Assistance with data-subject requests
Taking into account the nature of the processing, Ember will assist you with appropriate measures to fulfil your obligations to respond to requests from individuals exercising their rights of access and correction under the Australian Privacy Principles (APP 12 and APP 13). Where an individual contacts Ember directly, we will refer them to your school or department and assist you in responding.
Breach notification
Ember will notify you without undue delay after becoming aware of an eligible data breach affecting your personal information, and will provide the information you reasonably need to meet your obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth). We will cooperate with you and the Office of the Australian Information Commissioner as required, and assist with containment, assessment and remediation.
Return and deletion of data
On termination or expiry of the service, and at your choice, Ember will return your personal information to you or securely delete it, and delete existing copies unless retention is required by Australian law. We will confirm in writing once deletion is complete.
Audit rights
Ember will make available to you the information reasonably necessary to demonstrate compliance with the DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality and frequency arrangements set out in the DPA.
Education-department vendor assessments
The DPA is designed to support State and Territory education department procurement and vendor risk assessments, including privacy impact assessments and information-security questionnaires. If your department uses a specific assessment template or requires its own paper, we are happy to work through it with you.
Request the DPA
To request a copy of the DPA for review, or to have a countersigned agreement executed for your school or department, please contact our legal team:
- Email: legal@embereducation.com.au
- Download or sign online: [PLACEHOLDER: link to downloadable DPA PDF / DocuSign]
For more on how we handle personal information generally, see our privacy policy.