Privacy Policy
1. Introduction
RollCall Safety Solutions Pty Ltd ("RollCall", "we", "us", or "our") is committed to protecting the privacy of all individuals whose personal information we collect and process. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information in connection with our school bus management platform and related services.
This policy applies to all users of our services, including school administrators, parents and guardians, bus operators, drivers, and supervisors. We comply with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth), the New Zealand Privacy Act 2020, and the UK General Data Protection Regulation (UK GDPR) as applicable.
2. Information We Collect
We collect information that you provide directly to us, including:
- Name, email address, phone number, and contact details
- School or organisation information, including role and position
- Student information (collected on behalf of schools as data processor), including name, year level, and bus route assignments
- Location data from our mobile applications (Driver/Supervisor App and Parent App)
- Device information and usage analytics
- NFC tap-on/tap-off records for student boarding and alighting events
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our school bus management services
- Send real-time notifications about bus locations and student boarding events
- Generate reports on bus utilisation, route efficiency, and student travel patterns
- Communicate with you about service updates, security alerts, and support enquiries
- Ensure the safety and security of students during transit
- Comply with applicable legal obligations and regulatory requirements
4. Lawful Basis for Processing
We process personal information on the following lawful bases:
- Contract performance: Processing necessary to deliver our services under our Master Services Agreement
- Legitimate interests: Processing necessary for the safety and welfare of students, and for improving our services
- Legal obligation: Processing required to comply with applicable laws, including child safety regulations
- Consent: Where required, we obtain consent for specific processing activities such as marketing communications
5. Information Sharing and Disclosure
We do not sell your personal information. We may share your information with:
- Schools and educational institutions (as data controllers under our Data Processing Agreement)
- Authorised bus operators and transport providers engaged by your school
- Cloud infrastructure providers (Amazon Web Services) for secure data hosting
- Service providers who assist in our operations, subject to strict confidentiality obligations
- Law enforcement or regulatory authorities when required by law or to protect the safety of children
6. Data Security
We implement industry-leading security measures to protect your data. RollCall is ISO 27001 certified, demonstrating our commitment to information security best practices. Our security measures include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Multi-factor authentication for administrative access
- Regular security audits and penetration testing
- Data stored in geographically appropriate AWS data centres with regional isolation
- Incident response procedures with defined notification timelines
7. Data Retention
We retain personal information for as long as necessary to provide our services and comply with legal obligations. Upon termination of a school's subscription, personally identifiable data is deleted within 90 days, unless a longer retention period is required by law. Anonymised and aggregated data may be retained for analytical purposes.
8. Your Rights
Depending on your jurisdiction, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Request deletion of your information (subject to legal obligations)
- Object to or restrict certain processing activities
- Data portability (receive your data in a structured, machine-readable format)
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data protection authority
9. Children's Privacy
Our services involve processing information about students on behalf of schools. Schools act as the data controller for student information and are responsible for obtaining any necessary consents from parents or guardians. We process student data strictly in accordance with school instructions and our Data Processing Agreement. Parents can contact their school to access, modify, or request deletion of their child's information.
10. International Data Transfers
We store data in the region appropriate to each customer. Australian customer data is stored in AWS Sydney (ap-southeast-2), New Zealand customer data in AWS Sydney, and United Kingdom customer data in AWS London (eu-west-2). Where international transfers are necessary, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) or equivalent mechanisms.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify affected parties of any material changes by email and by posting the updated policy on our website. The "Last Updated" date at the top of this page indicates when the policy was last revised.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your privacy rights, please contact our Privacy Officer:
Email: privacy@rollcall.com.au
Phone: 1300 821 116
Address: 1/146-148 Thistlethwaite Street, South Melbourne VIC 3205, Australia
