Privacy notice
Who is responsible
DASH is a staff-only student pastoral dashboard used by Mt Aspiring College. Under the New Zealand Privacy Act 2020, the school that uses DASH is the agency responsible for the personal information in it and holds the relationship with students and their families. DASH's developer operates the tool on the school's behalf and is the contact for questions about the tool itself: kiaora@dash.org.nz.
What information DASH holds
- Student identifiers: name, National Student Number, the school's student ID, date of birth, school email address and school photo.
- Attendance, effort and punctuality records, and NCEA results and progress.
- Pastoral records, including notes and incident descriptions written by staff.
- Caregiver names, email addresses, phone numbers and postal addresses.
- Demographic and status information the school records, such as ethnicity, gender and learning-support or language-support flags.
- A record of which staff member viewed or changed what, and when.
Where it comes from
Almost all of this information is collected from the school's own KAMAR student-management system, not from students or caregivers directly. The Privacy Act asks an agency that collects information indirectly to take reasonable steps to make people aware of it; the school does this through its enrolment notice, which tells students and caregivers that their information is used in staff-facing analysis and reporting tools.
What it is used for
One purpose: supporting attendance, effort, pastoral care and academic-progress monitoring by school staff. The information is not sold, not used for advertising, and not used for any purpose unrelated to student wellbeing.
Who can see it
Only staff the school has authorised, signed in with their school Google Workspace account. Each staff member sees only what their role and responsibility allow, and every request is checked on the server. Information is not disclosed outside the purpose above, except to the service providers below, who process it only to run the service.
Where it is held
The information is held on managed infrastructure in Sydney, Australia, under processor terms that bind the provider, and the New Zealand Privacy Act 2020 applies wherever the data sits. The service providers involved are:
- DigitalOcean: hosting, the managed database and encrypted storage, in Sydney, Australia.
- Amazon Web Services (Amazon SES): delivery of the email DASH sends, from its Sydney region.
- Google Workspace: staff sign-in, using the school's own accounts.
How long it is kept
A student's information is kept while they are enrolled and for up to seven years after they leave, then deleted. Backups are kept for up to 30 days and then age out. A deletion applied to the live systems reaches the backups as they age out.
Your rights
You can ask to see the personal information held about you or your child, and ask for it to be corrected if it is wrong. You can also ask for it to be deleted; where the school must keep a record by law, it will tell you.
Email from DASH
DASH sends a small number of transactional emails on the school's behalf: to staff, to currently enrolled students, and to the caregivers of those students about that student. Every address comes from the school's enrolment records. There is no marketing email, no mailing list, and no way to subscribe. Messages are sent from dash.org.nz through Amazon SES in Sydney and are authenticated with DKIM, SPF and DMARC aligned to dash.org.nz. Replies go to the member of staff who wrote them. An address that hard-bounces or registers a complaint is automatically added to the email provider's suppression list and is not emailed again, and the operator is notified of every bounce and complaint.
How it is protected
- Sign-in only with a school Google Workspace account. DASH holds no passwords.
- Every request is checked on the server against the staff member's role and responsibility.
- Encrypted in transit and at rest: the connection, the database, the storage volume and the backups.
- Hosted in a single region, Sydney, with a named provider. The hosted service runs on managed infrastructure, not on school devices.
- Multi-factor sign-in on every account that can administer the service.
- Staff access to student records is logged.
- An incident-response plan is in place. If a privacy breach is likely to cause serious harm, the school notifies the Office of the Privacy Commissioner and the people affected, as the Privacy Act requires.
Changes to this notice
This notice is reviewed when the service changes. The date at the top is the date of the last review. Questions about it: kiaora@dash.org.nz.