zorentia.
  • Office Hours
  • Customers
  • Pricing
  • Contact
LoginSign Up

Legal · 2026-09-05-v1

Institutional Data & Privacy Schedule

Data handling and privacy terms for institutions using Zorentia.

ON THIS PAGE

  1. 011. Purpose
  2. 022. Data categories
  3. 033. Roles and instructions
  4. 044. Data minimisation
  5. 055. Institution administrator visibility
  6. 066. Public-by-link content
  7. 077. Public feedback
  8. 088. AI processing
  9. 099. Subprocessors and service providers
  10. 1010. Location and overseas processing
  11. 1111. Security measures
  12. 1212. Retention
  13. 1313. Offboarding and deletion
  14. 1414. Individual rights and requests
  15. 1515. Security incidents and data breaches
  16. 1616. Confidentiality and staff access
  17. 1717. Audit and information requests
  18. 1818. No sale or advertising use of student data
  19. 1919. Changes to this Schedule

RELATED DOCUMENTS

Institutional AgreementPrivacy PolicySubprocessor List

To the Zorentia Institutional Agreement
Zorentia Product Studio Pty Ltd - ABN 86 688 343 482
Version: 2026-09-05-v1
Last updated: 5 September 2026

This Schedule forms part of the Institutional Agreement between Zorentia and the Institution.

1. Purpose

This Schedule describes how Zorentia handles information in connection with Institution-provisioned users and the Institution's use of Zorentia.

It is intended to allocate practical responsibilities transparently without displacing obligations that apply directly to either party under law.

2. Data categories

Depending on the Institution's configuration and user activity, Zorentia may process:

2.1 Institution and representative information

  • Institution name;
  • representative or administrator name;
  • work email;
  • role/title;
  • authority confirmation;
  • billing email;
  • agreement versions and acceptance times; and
  • order, seat, subscription and payment references.

2.2 Student account and membership information

  • student email;
  • internal user identifier;
  • institution membership, role and status;
  • optional cohort;
  • login/activity information;
  • milestone/current-stage information;
  • administrative engagement status; and
  • credit usage or allowance.

The Institution provisioning flow does not require student name, date of birth, postal address or phone number.

2.3 Student project information

Where a student uses the Service, Zorentia may process:

  • project ideas and briefs;
  • planning answers and prompts;
  • assistant messages;
  • technical plans and architecture;
  • generated SQL, backend, frontend and related generated files;
  • research observations and testing notes;
  • publication drafts and published payloads;
  • anonymous public-feedback responses; and
  • generation, usage and operational metadata.

2.4 Research invitation information

If a user sends direct research invitations, Zorentia may process the recipient email, invitation/delivery metadata, research-contact attestation, a hashed one-time code, temporary email PDF and submitted research feedback.

2.5 Security-scan information

If a user deliberately runs the security scanner, source-code files may be transmitted to Zorentia for analysis. Complete raw scan bundles are processed temporarily; derived findings, redacted context and reports may be retained for limited periods.

3. Roles and instructions

The Institution decides which authorised users it provisions and for what educational or administrative purpose it uses Zorentia.

Zorentia processes Institution-supplied membership information and user project information to provide, secure, support and administer the Service and for the other purposes described in the Privacy Policy and Institutional Agreement.

The Institution's use of Zorentia and its instructions must be lawful. Zorentia is not required to follow an instruction that would breach applicable law, materially compromise security or require a use of the Service outside the agreed scope.

4. Data minimisation

Zorentia will not require the Institution to provide student names, exact ages, dates of birth, phone numbers or postal addresses for ordinary student provisioning unless a future feature legitimately requires additional information and the applicable legal/privacy documentation is updated before collection.

The Institution should not upload unnecessary personal or sensitive information into free-text fields.

5. Institution administrator visibility

Authorised Institution administrators may access only the administrative data exposed through the organisation features, currently including:

  • student email;
  • cohort;
  • access/status information;
  • recent login or activity;
  • milestone/current stage;
  • engagement status; and
  • credit usage or allowance.

The organisation dashboard does not provide administrator access to raw student prompts, private project ideas, generated code, private project content, research observations or private feedback merely because the person is an administrator.

6. Public-by-link content

Student projects are private by default.

If a student deliberately publishes a project page:

  • the page is available by direct public link while published;
  • Zorentia does not provide a public Explore feed or directory;
  • known structured student/account identifiers are removed from the public payload;
  • Zorentia applies noindex controls intended to discourage search-engine indexing; and
  • Zorentia can unpublish or remove the page for safety, privacy, legal, security or moderation reasons.

The Institution should educate users not to put personal, confidential or third-party private information into material they publish.

7. Public feedback

New public landing-page feedback is designed not to collect respondent name, email or phone number.

Technical anti-abuse information such as a pseudonymous visitor identifier, text hash or spam state may be held internally but is not shown to the student owner through the feedback interface.

8. AI processing

8.1 Generative processing

Zorentia uses Amazon Bedrock as the production gateway for generative AI. At the date of this Schedule:

  • requests originate from AWS Sydney;
  • Bedrock account data retention is configured to none;
  • Bedrock model invocation logging is disabled; and
  • storage is disabled where the relevant Bedrock Responses-compatible route exposes a storage option.

Current model families are provided through Bedrock rather than direct generative APIs from the underlying model vendors.

8.2 Moderation

A limited text-moderation path uses the OpenAI Moderation API directly. It is restricted to the text requiring moderation and is not supplied with student email, institution information or project/code bundles as part of the moderation call.

9. Subprocessors and service providers

Zorentia's current key providers are listed in the Subprocessor List.

Zorentia may update providers where reasonably necessary to operate the Service. Zorentia will update the public/current list and will provide notice of a material new provider where an Order or applicable law requires it.

10. Location and overseas processing

Zorentia's principal application, database, Redis and email infrastructure is located in AWS Sydney. The current Claude Australian geographic inference profile used from Sydney may route AI inference between AWS Sydney and Melbourne.

Some supporting providers may process limited information outside Australia, including OpenAI, Square and Cloudflare. The Privacy Policy and Subprocessor List provide further detail.

11. Security measures

Zorentia maintains safeguards appropriate to the Service, including measures such as:

  • encrypted cloud infrastructure and managed AWS services;
  • access controls and restricted administrative access;
  • server-side sessions and CSRF protection;
  • hashing or keyed hashing for access keys, verification/recovery codes and feedback codes;
  • rate limiting and bot protection;
  • controls to avoid raw prompt/response logging in generic AI logs;
  • secret redaction in persistent security findings;
  • security-event and abuse controls;
  • rolling encrypted database backups; and
  • internal breach-response procedures.

The Institution is responsible for securing its administrator credentials and endpoints under its control.

12. Retention

The principal retention rules relevant to Institution data are:

CategoryCurrent retention approach
Student account/project dataWhile the account/project remains active; subject to deletion/offboarding rules
Verification/recovery/session recordsShort-lived; generally removed within about 24 hours after the applicable expiry/cutoff
Research invitation code14-day validity
Research recipient contactRetired about 30 days after use/expiry; anonymous project linkage may remain
Research PDFNormally 1 day after terminal delivery; maximum 7 days
Security scan runsUp to 90 days
Derived security reportsUp to 365 days
Public-page moderation reportsUp to 365 days unless legitimately required longer
Contract acceptance evidenceGenerally up to 7 years after the relevant contract/account ends
Payment/tax evidenceGenerally at least 5 years where required by Australian law
RDS rolling backup7 days

A retention period may be extended where reasonably necessary because of litigation, legal hold, fraud/security investigation or another legal requirement.

13. Offboarding and deletion

Removing a student from Institution membership:

  • ends the Institution membership/status and institution-funded access or credits as applicable;
  • ends Institution administrator visibility associated with that membership; and
  • does not automatically destroy the student's independent Zorentia account or student-created project data.

Where the Institution has authority to request deletion of Institution-provided personal information or user data, it may submit a verified request through Zorentia's privacy/contact process. Zorentia will assess and action the request within a reasonable period, subject to user rights, lawful retention, technical dependencies and backup lifecycle.

An eligible student can use the independent account-deletion process once the relevant Institution management context has been removed.

Active-system deletion does not surgically alter historical encrypted backups. Residual backup copies expire with the rolling seven-day backup lifecycle.

14. Individual rights and requests

Zorentia will reasonably assist the Institution and affected individuals with access, correction and deletion requests relating to information held in Zorentia, subject to applicable law, authority verification and reasonable technical limitations.

The Institution should promptly forward to Zorentia any request that materially requires action by Zorentia.

15. Security incidents and data breaches

Zorentia maintains a documented incident-response process.

If Zorentia confirms a material security incident affecting Institution personal information, Zorentia will notify the Institution without undue delay where notification is reasonably necessary, subject to legitimate security, legal and law-enforcement constraints.

The parties will cooperate reasonably to assess the scope, remediation and any legally required notification. If the Notifiable Data Breaches scheme applies, the party with the relevant legal obligation remains responsible for making required notifications, with reasonable assistance from the other party.

16. Confidentiality and staff access

Zorentia restricts access to personal and confidential information to personnel or contractors who need access for legitimate operational, security, support, legal or compliance purposes and who are subject to appropriate confidentiality obligations.

17. Audit and information requests

On reasonable request for a genuine procurement, compliance or incident purpose, Zorentia will provide information reasonably available about its privacy and security controls, subject to confidentiality, security, privilege and third-party restrictions.

Unless separately agreed, this does not create a right to unrestricted on-site audit, penetration testing of production systems or access to another customer's information.

18. No sale or advertising use of student data

Zorentia does not sell student personal information and does not use student project content for third-party targeted advertising.

19. Changes to this Schedule

Zorentia may update this Schedule to reflect changes in law, subprocessors, security controls or the Service. Material changes affecting an active Order will be notified in a reasonable manner, and renewed acceptance may be required where appropriate.

ZORENTIA.
Sydney, Australia
Est. 2025

LEGAL

Terms of UsePrivacy Policy

ACKNOWLEDGEMENT OF COUNTRY

Zorentia acknowledges the Gadigal People of the Eora Nation, the Traditional Custodians of the land on which we work in Sydney. We pay our respects to Elders past, present, and emerging.

COMPANY

© 2025 Zorentia
Product Studio Pty Ltd

ABN 86 688 343 482

ZORENTIASYDNEY, AUSTRALIAEST. 2025