Data Processing Agreement

Last reviewed: [PLACEHOLDER: review date]

This is a draft pending review by an Australian solicitor experienced in privacy and edtech law. It is provided for information only and is not legal advice. The countersigned Data Processing Agreement executed between your school or department and Ember Education governs in all cases.

Lantern is operated by [PLACEHOLDER: Ember Education Pty Ltd] (ABN [PLACEHOLDER: 11-digit ABN]; ACN [PLACEHOLDER: 9-digit ACN]) (“Ember”, “we”, “us”). When your school or education department uses Lantern to draft and check report comments, Ember processes personal information on your behalf. Our Data Processing Agreement (the “DPA”) sets out, in writing, how that processing is governed and the protections we commit to.

This page summarises the key terms. It is a plain-language overview and does not replace the executed DPA, which we make available to schools and departments on request.

Roles: controller and processor

Under the DPA, your school or education department is the data controller — you determine the purposes for which, and the manner in which, student and staff personal information is handled. Ember acts solely as the data processor, processing that information on your behalf and under your authority.

Lantern keeps the teacher as the author and approver of every comment. There are no student accounts, and student data is never used to train AI models.

Processing on documented instructions

Ember processes personal information only on your documented instructions, including with respect to transfers, unless we are otherwise required to act by Australian law — in which case we will inform you of that requirement before processing, unless the law prohibits us from doing so. The scope, nature and purpose of processing, the types of personal information, and the categories of data subjects are set out in a schedule to the DPA.

Confidentiality

Personnel authorised to process your data are bound by enforceable confidentiality obligations and are granted access only on a need-to-know basis to deliver the service. Confidentiality obligations survive the end of their engagement with Ember.

Security measures

Ember maintains appropriate technical and organisational measures to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction or damage. All data is hosted onshore in Australia (AWS Sydney, with disaster recovery in Melbourne), encrypted in transit and at rest, and access is logged in an immutable audit trail. Our controls are described in more detail on our security page.

Sub-processors

Ember engages a limited number of vetted sub-processors to help deliver Lantern. Each is bound by data-protection terms no less protective than those in the DPA. We maintain a current list of sub-processors, including their location and the function they perform, on our sub-processors page. We will give you advance notice of any intended changes so you can object before a new sub-processor begins processing your data.

Assistance with data-subject requests

Taking into account the nature of the processing, Ember will assist you with appropriate measures to fulfil your obligations to respond to requests from individuals exercising their rights of access and correction under the Australian Privacy Principles (APP 12 and APP 13). Where an individual contacts Ember directly, we will refer them to your school or department and assist you in responding.

Breach notification

Ember will notify you without undue delay after becoming aware of an eligible data breach affecting your personal information, and will provide the information you reasonably need to meet your obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth). We will cooperate with you and the Office of the Australian Information Commissioner as required, and assist with containment, assessment and remediation.

Return and deletion of data

On termination or expiry of the service, and at your choice, Ember will return your personal information to you or securely delete it, and delete existing copies unless retention is required by Australian law. We will confirm in writing once deletion is complete.

Audit rights

Ember will make available to you the information reasonably necessary to demonstrate compliance with the DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality and frequency arrangements set out in the DPA.

Education-department vendor assessments

The DPA is designed to support State and Territory education department procurement and vendor risk assessments, including privacy impact assessments and information-security questionnaires. If your department uses a specific assessment template or requires its own paper, we are happy to work through it with you.

Request the DPA

To request a copy of the DPA for review, or to have a countersigned agreement executed for your school or department, please contact our legal team:

For more on how we handle personal information generally, see our privacy policy.