Introduction
This Privacy Policy explains how The Antheon Company ("Antheon", "we","us" or "our") collects, holds, uses, discloses and protects personal information when you access or use Antheon Workspace, including the Antheon Workspace platform and the Antheon products available on it — Antheon Campus, Antheon Study, Antheon Bloom, Antheon Educator, Antheon Guardian, Antheon Classroom and Antheon Pay — together with the websites, applications, APIs and integrations we make available (collectively, the "Service").
We aim to handle personal information consistently with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches Scheme. Where the European Union General Data Protection Regulation or other privacy laws apply to you, we also work to align our practices with those laws.
This Policy forms part of our agreement with you. By using the Service you agree that your personal information may be collected, held, used and disclosed in line with this Policy. If you do not agree, please do not use the Service.
Our role under privacy law
For most customers, Antheon operates the Service on behalf of an educational institution (the "School"). In that context the School determines what information is collected through the Service, how it is used in the School's day to day operations, and how long it is kept. Antheon acts as a processor for that information and follows the School's documented instructions.
For some limited activities — including individual account creation, billing, security, fraud prevention, product analytics, and operational communications about the Service — Antheon is the controller of the information. Where that is the case, the protections described in this Policy apply.
Personal information we collect
We only collect personal information that is reasonably necessary to provide the Service. The categories below describe the kinds of information we may collect and where it comes from.
Information you give us directly
- Account details — your name, email address, role, optional profile photograph, and where you use phone-based features, your phone number.
- Authentication credentials — including hashed passwords, single sign-on tokens, passkey credentials, multi-factor authentication seeds and recovery codes.
- School-supplied identifiers — student or staff identifiers, year level, class membership and emergency contacts where the School chooses to share them.
- Communications you send to us — support tickets, demo requests, and any other messages you send to Antheon staff or other users on the Service.
- Payment information — if you pay for a Antheon subscription or use Antheon Pay, your billing details and payment method metadata. We do not store full card numbers; card processing is handled by our payment processor.
Information generated when you use the Service
- Usage data — pages and features used, in-product actions, configuration changes and times of access.
- Wellbeing inputs — where Antheon Bloom is in use and a user takes part in optional check-ins, those responses. Sensitive information of this kind is treated with extra care and is only visible to the people the School has authorised.
- Class and academic records — submissions, marks, comments, attendance, behaviour entries, calendar events, lesson plans and similar content (collectively, "School Data").
- Device and connection information — IP address, browser, operating system, device identifiers, time zone, referring URL, and basic diagnostic information.
- On-device study state — some study progress and preferences (for example flashcard review progress, note highlights, and study streak counts) are stored locally in your browser to make the study tools work, and can be cleared by clearing your browser's site data.
- Cookies and similar technologies — see the Cookies section below.
Information from third parties
- Identity providers — when you sign in through a third-party identity provider, we receive the verified information necessary to provision your account.
- School information systems — where your School connects an existing system to Antheon, that system may send relevant records to the Service.
- Payment processors — we receive transaction outcomes from the processors that handle your payments.
- Safety and abuse signals — we use anti-bot and anti-abuse services that may return risk signals about a sign-in attempt.
How we use personal information
We use personal information only for the purposes set out below, and for related purposes you would reasonably expect.
- To provide the Service — authenticating users, provisioning accounts, displaying content the user is permitted to see, delivering notifications, syncing calendars and facilitating communication between people on the same School.
- To improve the Service — measuring engagement, debugging errors, improving accessibility and prioritising the product roadmap.
- To protect the Service and its users — detecting and responding to security events, preventing abuse and investigating suspected breaches of our Terms.
- To communicate with you — sending operational notices about availability, incidents, scheduled maintenance and security advisories, responding to support enquiries, and (where you opt in) sending product news.
- For billing and finance — processing payments, issuing invoices, reconciling and handling disputes.
- To comply with our legal obligations — including responding to lawful requests from regulators or courts.
We do not sell personal information. We do not use personal information for behavioural advertising. We do not permit third-party advertising trackers on the Service.
Legal basis for processing
Where the EU GDPR, UK GDPR or equivalent laws apply, we rely on the following bases to process personal information:
- Contract — where processing is necessary to provide the Service you have asked us to provide, or to meet our agreement with your School.
- Legitimate interests — for product analytics, security, fraud prevention, improving the Service and communicating with customers.
- Consent — for optional features that require it (for example, wellbeing check-ins, biometric authentication credentials and marketing communications).
- Legal obligation — where we must process information to comply with applicable law.
- Vital or public interest — in rare circumstances where processing is needed to protect a person's life or to respond to a public emergency.
International data transfers
We aim to keep production data for Australian school customers within Australia. Some of our service providers are headquartered outside Australia and may process information overseas. Where that happens, we take reasonable steps to ensure the transfer is permitted under the Australian Privacy Principles and that the recipient is bound by privacy and security obligations substantially similar to those in this Policy.
If you have specific questions about where a particular category of information is stored, contact us using the details below and we will tell you what we can.
How long we keep personal information
We keep personal information only as long as we reasonably need it to provide the Service or to meet a legal obligation. School Data is kept for the period the School remains a customer, plus the deletion window agreed with the School. Account data is kept while the account is active and for a reasonable period of dormancy afterwards. Authentication and audit logs are kept for the period required to support security, troubleshooting and dispute resolution. Financial records are kept for the period required by Australian taxation and corporations law. Marketing contact details are kept until you unsubscribe, after which they are removed.
Specific retention periods may be agreed in your School's order or service agreement and override the general positions above.
Your rights
Subject to applicable law, you can ask us to:
- Provide you with a copy of the personal information we hold about you.
- Correct personal information that is inaccurate, out of date or incomplete.
- Delete personal information, subject to our retention obligations.
- Restrict or object to certain processing.
- Provide your information in a structured, machine-readable format where the law applies.
- Withdraw consent for any processing that is based on consent. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
Where personal information was provided to Antheon by your School, we will work with your School to action your request. To make a request, contact us using the details below. We will verify your identity before responding and will respond within the timeframe required by applicable law (and otherwise as soon as reasonably practicable).
You also have the right to complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to the data protection authority in your country.
Children's privacy
The Service is designed to be used by children at the direction of their School. We rely on the School to obtain any parental or guardian consent that is required by law for the provision of the Service to children. We do not market to children, do not profile children for advertising, and limit the personal information we collect from children to what is needed to operate the Service in the educational context for which it is provided.
How we keep personal information secure
We use technical and organisational measures designed to protect personal information from misuse, loss and unauthorised access, change or disclosure. These include encryption in transit and at rest, access controls based on the principle of least privilege, logging of administrative actions, and ongoing review of our security practices. More detail is in our Security Policy.
If we become aware of an eligible data breach, we will notify the affected Schools, individuals and regulators in line with the Notifiable Data Breaches Scheme and any other notification laws that apply, and we will provide reasonable assistance to reduce the impact.
Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will let you know by email or by a notice in the Service. The date at the top of the page shows when it was last updated. By continuing to use the Service after a change takes effect, you agree to the updated Policy.
How to contact us
If you have questions, concerns or complaints about this Policy or how we handle personal information, please contact us through the Antheon Support Center, or send us a message from the Contact support form on the support page.
We aim to acknowledge written enquiries within a reasonable time and to substantively respond as soon as practicable. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner.
