To the Zorentia Institutional Agreement
Zorentia Product Studio Pty Ltd - ABN 86 688 343 482
Version: 2026-09-05-v1
Last updated: 5 September 2026
This Schedule forms part of the Institutional Agreement between Zorentia and the Institution.
1. Purpose
This Schedule describes how Zorentia handles information in connection with Institution-provisioned users and the Institution's use of Zorentia.
It is intended to allocate practical responsibilities transparently without displacing obligations that apply directly to either party under law.
2. Data categories
Depending on the Institution's configuration and user activity, Zorentia may process:
2.1 Institution and representative information
- Institution name;
- representative or administrator name;
- work email;
- role/title;
- authority confirmation;
- billing email;
- agreement versions and acceptance times; and
- order, seat, subscription and payment references.
2.2 Student account and membership information
- student email;
- internal user identifier;
- institution membership, role and status;
- optional cohort;
- login/activity information;
- milestone/current-stage information;
- administrative engagement status; and
- credit usage or allowance.
The Institution provisioning flow does not require student name, date of birth, postal address or phone number.
2.3 Student project information
Where a student uses the Service, Zorentia may process:
- project ideas and briefs;
- planning answers and prompts;
- assistant messages;
- technical plans and architecture;
- generated SQL, backend, frontend and related generated files;
- research observations and testing notes;
- publication drafts and published payloads;
- anonymous public-feedback responses; and
- generation, usage and operational metadata.
2.4 Research invitation information
If a user sends direct research invitations, Zorentia may process the recipient email, invitation/delivery metadata, research-contact attestation, a hashed one-time code, temporary email PDF and submitted research feedback.
2.5 Security-scan information
If a user deliberately runs the security scanner, source-code files may be transmitted to Zorentia for analysis. Complete raw scan bundles are processed temporarily; derived findings, redacted context and reports may be retained for limited periods.
3. Roles and instructions
The Institution decides which authorised users it provisions and for what educational or administrative purpose it uses Zorentia.
Zorentia processes Institution-supplied membership information and user project information to provide, secure, support and administer the Service and for the other purposes described in the Privacy Policy and Institutional Agreement.
The Institution's use of Zorentia and its instructions must be lawful. Zorentia is not required to follow an instruction that would breach applicable law, materially compromise security or require a use of the Service outside the agreed scope.
4. Data minimisation
Zorentia will not require the Institution to provide student names, exact ages, dates of birth, phone numbers or postal addresses for ordinary student provisioning unless a future feature legitimately requires additional information and the applicable legal/privacy documentation is updated before collection.
The Institution should not upload unnecessary personal or sensitive information into free-text fields.
5. Institution administrator visibility
Authorised Institution administrators may access only the administrative data exposed through the organisation features, currently including:
- student email;
- cohort;
- access/status information;
- recent login or activity;
- milestone/current stage;
- engagement status; and
- credit usage or allowance.
The organisation dashboard does not provide administrator access to raw student prompts, private project ideas, generated code, private project content, research observations or private feedback merely because the person is an administrator.
6. Public-by-link content
Student projects are private by default.
If a student deliberately publishes a project page:
- the page is available by direct public link while published;
- Zorentia does not provide a public Explore feed or directory;
- known structured student/account identifiers are removed from the public payload;
- Zorentia applies
noindexcontrols intended to discourage search-engine indexing; and - Zorentia can unpublish or remove the page for safety, privacy, legal, security or moderation reasons.
The Institution should educate users not to put personal, confidential or third-party private information into material they publish.
7. Public feedback
New public landing-page feedback is designed not to collect respondent name, email or phone number.
Technical anti-abuse information such as a pseudonymous visitor identifier, text hash or spam state may be held internally but is not shown to the student owner through the feedback interface.
8. AI processing
8.1 Generative processing
Zorentia uses Amazon Bedrock as the production gateway for generative AI. At the date of this Schedule:
- requests originate from AWS Sydney;
- Bedrock account data retention is configured to
none; - Bedrock model invocation logging is disabled; and
- storage is disabled where the relevant Bedrock Responses-compatible route exposes a storage option.
Current model families are provided through Bedrock rather than direct generative APIs from the underlying model vendors.
8.2 Moderation
A limited text-moderation path uses the OpenAI Moderation API directly. It is restricted to the text requiring moderation and is not supplied with student email, institution information or project/code bundles as part of the moderation call.
9. Subprocessors and service providers
Zorentia's current key providers are listed in the Subprocessor List.
Zorentia may update providers where reasonably necessary to operate the Service. Zorentia will update the public/current list and will provide notice of a material new provider where an Order or applicable law requires it.
10. Location and overseas processing
Zorentia's principal application, database, Redis and email infrastructure is located in AWS Sydney. The current Claude Australian geographic inference profile used from Sydney may route AI inference between AWS Sydney and Melbourne.
Some supporting providers may process limited information outside Australia, including OpenAI, Square and Cloudflare. The Privacy Policy and Subprocessor List provide further detail.
11. Security measures
Zorentia maintains safeguards appropriate to the Service, including measures such as:
- encrypted cloud infrastructure and managed AWS services;
- access controls and restricted administrative access;
- server-side sessions and CSRF protection;
- hashing or keyed hashing for access keys, verification/recovery codes and feedback codes;
- rate limiting and bot protection;
- controls to avoid raw prompt/response logging in generic AI logs;
- secret redaction in persistent security findings;
- security-event and abuse controls;
- rolling encrypted database backups; and
- internal breach-response procedures.
The Institution is responsible for securing its administrator credentials and endpoints under its control.
12. Retention
The principal retention rules relevant to Institution data are:
| Category | Current retention approach |
|---|---|
| Student account/project data | While the account/project remains active; subject to deletion/offboarding rules |
| Verification/recovery/session records | Short-lived; generally removed within about 24 hours after the applicable expiry/cutoff |
| Research invitation code | 14-day validity |
| Research recipient contact | Retired about 30 days after use/expiry; anonymous project linkage may remain |
| Research PDF | Normally 1 day after terminal delivery; maximum 7 days |
| Security scan runs | Up to 90 days |
| Derived security reports | Up to 365 days |
| Public-page moderation reports | Up to 365 days unless legitimately required longer |
| Contract acceptance evidence | Generally up to 7 years after the relevant contract/account ends |
| Payment/tax evidence | Generally at least 5 years where required by Australian law |
| RDS rolling backup | 7 days |
A retention period may be extended where reasonably necessary because of litigation, legal hold, fraud/security investigation or another legal requirement.
13. Offboarding and deletion
Removing a student from Institution membership:
- ends the Institution membership/status and institution-funded access or credits as applicable;
- ends Institution administrator visibility associated with that membership; and
- does not automatically destroy the student's independent Zorentia account or student-created project data.
Where the Institution has authority to request deletion of Institution-provided personal information or user data, it may submit a verified request through Zorentia's privacy/contact process. Zorentia will assess and action the request within a reasonable period, subject to user rights, lawful retention, technical dependencies and backup lifecycle.
An eligible student can use the independent account-deletion process once the relevant Institution management context has been removed.
Active-system deletion does not surgically alter historical encrypted backups. Residual backup copies expire with the rolling seven-day backup lifecycle.
14. Individual rights and requests
Zorentia will reasonably assist the Institution and affected individuals with access, correction and deletion requests relating to information held in Zorentia, subject to applicable law, authority verification and reasonable technical limitations.
The Institution should promptly forward to Zorentia any request that materially requires action by Zorentia.
15. Security incidents and data breaches
Zorentia maintains a documented incident-response process.
If Zorentia confirms a material security incident affecting Institution personal information, Zorentia will notify the Institution without undue delay where notification is reasonably necessary, subject to legitimate security, legal and law-enforcement constraints.
The parties will cooperate reasonably to assess the scope, remediation and any legally required notification. If the Notifiable Data Breaches scheme applies, the party with the relevant legal obligation remains responsible for making required notifications, with reasonable assistance from the other party.
16. Confidentiality and staff access
Zorentia restricts access to personal and confidential information to personnel or contractors who need access for legitimate operational, security, support, legal or compliance purposes and who are subject to appropriate confidentiality obligations.
17. Audit and information requests
On reasonable request for a genuine procurement, compliance or incident purpose, Zorentia will provide information reasonably available about its privacy and security controls, subject to confidentiality, security, privilege and third-party restrictions.
Unless separately agreed, this does not create a right to unrestricted on-site audit, penetration testing of production systems or access to another customer's information.
18. No sale or advertising use of student data
Zorentia does not sell student personal information and does not use student project content for third-party targeted advertising.
19. Changes to this Schedule
Zorentia may update this Schedule to reflect changes in law, subprocessors, security controls or the Service. Material changes affecting an active Order will be notified in a reasonable manner, and renewed acceptance may be required where appropriate.