← Back to DynaAdmin

DynaAdmin Privacy Policy

Last updated: 3 October 2026

DynaAdmin is a school administration platform provided by Dyna IT Pty Ltd (“Dyna IT”, “we”, “us”) to schools (“customers”) for use by their staff. This policy explains what information we collect through DynaAdmin, how we use it, where it is stored, and who it is shared with.

Who this applies to

This policy covers staff accounts used to sign in to DynaAdmin (e.g. Site Admins and CRT/relief staff) and the operational data a school enters into the product to run its own administration. It does not create a separate agreement with any individual student, and DynaAdmin is not designed to collect student personal information as a matter of course — see “Content you enter” below for the one area where this depends on what a school chooses to type into the product.

Information we collect

  • Account information — full name, email address, your access level (Site Admin or which group you belong to), and which school you belong to.
  • Sign-in information — your password (stored as a salted hash, never in plain text), or, if your school has enabled it, basic profile information (name and email) shared with us by Google or Microsoft when you sign in with one of those accounts. We do not receive your Google/Microsoft password.
  • Content you enter — the schedules, letter columns/templates, term dates, and similar configuration a school's own staff type into the product. Some of this is freely configurable by each school, so its exact contents depend entirely on what that school chooses to enter — for example, a class or room reference typed into a daily schedule. We do not require any student personal information to operate DynaAdmin, and schools should avoid entering more than is necessary for day-to-day scheduling.
  • Files you upload — for example, a school logo used on generated letters.
  • Feedback you send us — if you use the Feedback button, your message, the feedback type and the page you were on, together with your name, email address and school, so we can understand and follow up on it. Feedback is only visible to Dyna IT.
  • Usage and audit records — a record of certain actions taken in the product (e.g. a user being invited, a person’s access changed, a letter link regenerated, or a Dyna IT support session), including who performed the action and when. Schools use this as their own internal audit trail.

We do not use tracking or advertising cookies, and we do not run analytics scripts that profile individual users. Session cookies are used only to keep you signed in.

How we use this information

We use the information above only to operate DynaAdmin for the school that collected it: authenticating sign-ins, enforcing that each school only ever sees its own data, generating the letters and schedules a school has configured, and maintaining the audit trail described above. We do not use it to train AI models, sell it, or use it for advertising.

Support access by Dyna IT staff

To help schools set up DynaAdmin and to investigate problems they report, authorised Dyna IT staff can access a school’s DynaAdmin console. We call this a support session. Support sessions are deliberately limited:

  • Only authorised Dyna IT staff can start one, and they must record a reason (for example, “helping set up Daily Org columns”) before access is granted.
  • They are time-limited. A session ends automatically after 60 minutes, or sooner if our staff member exits.
  • They are view-only by default. Our staff can see a school’s data but cannot change it unless they take a separate, deliberate step to enable changes. Each session records whether that happened.
  • They are recorded and visible to your school. Your school’s Site Admins can see every support session — who accessed the console, when, why, and whether changes were enabled — under Configuration → Activity. Any change made during a session is attributed to Dyna IT in your school’s audit trail.
  • Our staff act under their own identity. They never sign in as, or impersonate, a member of your school’s staff.

During a support session our staff can see the same information a Site Admin at your school can see. We only use what we see to provide the support requested, and we treat it with the same confidentiality as all other school data under this policy.

Where your data is stored

DynaAdmin’s database, file storage, and the application itself are hosted in Australia, in the Sydney (AWS ap-southeast-2) region. We chose this deliberately so that school data stays onshore.

The one exception is account emails (staff invitations and password resets). These are sent through our email delivery provider, Resend, which processes them in Tokyo, Japan (AWS ap-northeast-1), because it does not currently offer an Australian region. Each email contains only the recipient’s email address and a single-use sign-in link — no schedules, letters, or other school content. Resend keeps a record of sent emails for a limited period for delivery and troubleshooting. We take reasonable steps, in line with Australian Privacy Principle 8, to ensure Resend handles this information consistently with the Australian Privacy Principles, and we will move email delivery onshore if a suitable Australian option becomes available.

Who we share it with

We do not sell personal information, and we do not share it with third parties for their own marketing or advertising purposes. Information is only shared in these situations:

Authorised Dyna IT staff may access school data to provide support, as described in “Support access by Dyna IT staff” above. This is access by us, not sharing with a third party.

  • Infrastructure providers who host and run DynaAdmin on our behalf — currently Supabase (database, file storage, and authentication) and Vercel (application hosting), both configured to process data in the Sydney region, and Resend (delivery of invitation and password-reset emails), which processes those emails in Tokyo, Japan — see “Where your data is stored” above. These providers act as processors under our instruction; they do not use school data for their own purposes.
  • Identity providers you or your school choose to use — if your school enables signing in with Google or Microsoft, that sign-in necessarily involves Google or Microsoft as the identity provider you're authenticating with.
  • Services you or your school choose to connect — if DynaAdmin is ever connected to another system your school uses (for example, a future integration your school opts into), the data necessary for that specific connection is shared with that service. We will always make it clear when a feature involves this kind of connection.
  • Where we're required to by law.

Data retention and deletion

We retain account and configuration data for as long as your school's subscription is active. Audit trail records are kept as an append-only log for accountability and are not user-deletable, consistent with their purpose as a record of what happened and when. If your school stops using DynaAdmin, contact us to discuss deletion of your school's data.

Security

Data is encrypted in transit and at rest. Each school's data is isolated from every other school's at the database level, staff access is controlled per-module through Site Admin and group permissions, and administrative actions are recorded in the audit trail described above. Access by Dyna IT staff to a school’s data happens only through time-limited, recorded support sessions.

Your rights

We handle personal information in line with the Australian Privacy Principles. You can ask us to access, correct, or ask questions about the personal information we hold about you by contacting us using the details below. If you're a government school, your own privacy obligations to your staff and community (for example under Victorian privacy law) are separate from this policy, and we're glad to work with your school on anything needed to support those obligations.

If something goes wrong

If we become aware of a data breach affecting your information, we will notify affected schools without undue delay and take reasonable steps to contain and address it, consistent with our obligations under Australian law.

Changes to this policy

We may update this policy from time to time. We'll update the date at the top of this page when we do.

Contact us

Questions about this policy or your information can be sent to contactus@dynait.com.au.