1. Who we are
Letts Learn Pty Ltd (ABN 77 683 713 028), trading as Vero Education (Vero, we, us), supplies a school administration and student-movement service to Australian schools.
You can contact our Privacy Officer at [email protected].
2. Scope and roles
For school and user data processed through the Vero service, the school determines the purposes for which that information is handled and Vero acts on the school's documented instructions. For information Vero collects for its own business purposes, such as website enquiries, demo bookings, service administration and security, Vero determines the handling described in this policy. Schools remain responsible for their own collection notices, authority, user access and use of school records.
Vero includes the main application, administration application and teacher web app, together with the providers and optional integrations listed below. Students do not receive Vero accounts or direct Vero support.
3. Information Vero handles
Depending on the school's configuration, Vero may handle student and staff identity and profile information; school, roster, timetable and activity records; and service-generated reports, access, support, audit and technical information.
Important boundary: school-defined movement destinations are location-related records, but Vero does not collect device GPS or geolocation. Vero is not designed to collect health records, payment-card data, government identifiers or unnecessary sensitive information.
Required and optional profile fields depend on the school's source and configuration. Only mapped CSV fields required for Vero are imported. Unexpected personal information supplied in a note, import, upload or support report is not used for a new purpose; if it is not reasonably necessary or lawfully retainable, Vero deletes or de-identifies it as soon as practicable and coordinates with the responsible school.
4. How we collect information
We collect information from the contracting school, an authorised CSV or image upload, a school-authorised Wonde connection, authorised school staff, optional Google Workspace, Microsoft Entra or school-selected OIDC sign-in, people who contact or book with us, and the technical operation of the service and website.
There is no public account sign-up. Schools authorise and manage staff access, and Vero support is provided through authorised school staff rather than directly to students.
5. How information is used
We use information to:
- deliver the contracted school functions, authorised integrations, reporting and exports;
- authenticate users and enforce school and role permissions;
- secure, monitor, troubleshoot, support and recover the service;
- respond to access, correction, deletion, export, complaint and incident requests;
- respond to enquiries, understand website use and send relevant product news or offers with consent;
- communicate service, security, privacy and contractual changes; and
- comply with law and protect people, schools and the service.
Vero does not sell personal information or use school or user data for third-party advertising or to train AI models.
6. Public website, enquiries and cookies
When someone visits vero.education or contacts Vero, we may handle the information they provide together with limited technical, referral and security data needed to operate and protect the website.
We use website analytics, including PostHog, to understand and improve our public website. This excludes the Vero app, student records and form contents. Limited website activity may be linked to enquiries in our CRM. You can turn analytics off below.
Checking analytics preference…
Vero may use contact details to respond to enquiries, provide service communications and send relevant product news or offers. Marketing emails are sent with consent and include a way to unsubscribe.
7. Service providers and countries
Not every provider below receives student information. The sections distinguish providers used for school service data from providers used for the public website and enquiries. All school and student data is stored and processed in Sydney, Australia: the application database, file storage, server functions, the Wonde synchronisation workload, AWS SES email processing and encrypted recovery backups. No student records or application data are stored or processed outside Australia. Limited technical and security metadata about web requests, such as IP addresses and request logs, may be processed globally by infrastructure providers including Netlify and Cloudflare.
A. School service data
These providers operate or support the contracted Vero service, including connections and staff sign-in selected or authorised by a school.
| Provider | Purpose | Information handled | Country or region |
|---|---|---|---|
| Supabase | Database, authentication, storage and server functions | School, staff, student and service data | Sydney, Australia |
| Amazon Web Services | Service, authentication, security and support email; delivery-event processing; encrypted recovery backups | Email and delivery data; encrypted backups | Sydney, Australia |
| Fly.io | SIS synchronisation | Optional school-authorised synchronisation data | Sydney, Australia |
| Wonde | Optional school information-system integration | School-authorised staff, student and timetable data | Australia, subject to the school's arrangement |
| School-selected identity provider, such as Google Workspace, Microsoft Entra ID or an approved OIDC provider | Optional staff sign-in | Staff name, email, sign-in identifier, identity tokens and authentication metadata | Depends on the provider and configuration selected by the school |
| Netlify | Application hosting, TLS and content delivery | Technical request and delivery metadata | Global edge network |
B. Public website and enquiry data
This processing relates to visitors and people who deliberately submit an enquiry or booking request. It does not ordinarily involve school service records or student information.
| Provider | Purpose | Information handled | Country or region |
|---|---|---|---|
| Supabase | Website enquiries, bookings and analytics | Submitted contact and school details; limited website analytics | Sydney, Australia |
| Cloudflare | Public website hosting, bot protection and asset delivery | Public website request, security and performance metadata | Global edge network |
| PostHog | Public website analytics | Limited website usage data and browser identifiers | United States |
Supabase appears in both sections because it supports separate school-service and public-website data flows.
Vero reviews new providers before use and gives notice of material changes as described below.
8. Storage, retention, export and deletion
We retain website and enquiry information for the purposes described in this policy or as required by law. We take reasonable steps to delete or de-identify personal information when it is no longer needed.
Core database records and uploaded files are held for the active school contract or a shorter school-instructed period. After a validated deletion or termination request, active records are targeted for deletion within 30 days.
Recovery copies generally age out 90 days after backup capture or release. Legal holds or agreed records requirements may extend these periods.
Security-relevant logs target 12 months where supported; error records target 90 days; closed support records target 12 months. Provider-supported periods are documented and minimised. Recovery copies are access restricted and encrypted. If deleted data is restored during disaster recovery, Vero re-deletes it before ordinary service resumes.
Schools retain control of their school and user data and remain responsible for their records obligations. Any agreed retention, export, legal-hold or disposal requirements take priority over Vero's default periods.
9. Access, correction, deletion, export and complaints
An individual or authorised school may request access to, correction of, deletion of or a reusable export of personal information by emailing [email protected]. Vero verifies identity and authority, coordinates with the responsible school, explains lawful exceptions and provides written deletion confirmation on request.
Privacy complaints use the same contact. We will acknowledge the complaint, investigate it and aim to provide a written response within 30 calendar days. If more time is reasonably required, we will explain why and provide an updated timeframe. If a complaint remains unresolved and the Privacy Act applies, Australian individuals may contact the Office of the Australian Information Commissioner.
10. Security and incidents
Vero uses access controls, encryption, security monitoring, secure development, backups and incident-response procedures to protect personal information. More information is available in our Security Overview.
If Vero becomes aware of a security or privacy incident affecting personal information, we will investigate and take reasonable steps to contain it. We will notify affected schools without undue delay, and no later than 24 hours after confirming an incident that affects their information. We will notify individuals and regulators where required by law or contract, and provide further information as it becomes available.
11. Notice before material changes
Vero gives affected school administrators at least 30 calendar days' notice before a planned material change to this policy or the School Service Terms, the purposes for handling school or user data, or the service providers and countries used to handle it.
If prior notice is not possible because of law, an emergency or circumstances outside Vero's reasonable control, notice is provided as soon as practicable.
12. Contact
Privacy Officer
Letts Learn Pty Ltd / Vero Education
[email protected]