Privacy

How we handle your data.

This Privacy Policy describes how Big Wella, the sole trader behind WellRead, collects, uses, stores, and discloses personal information. It is written for school staff, students, parents, and visitors to wellreadreader.com. We follow the 13 Australian Privacy Principles set out in the Privacy Act 1988 (Cth) and apply heightened care where children are involved.

Effective 2026-08-16 · Pre-contract draft. The principles, sub-processors, security controls, and retention windows below describe current operations. This wording will be reviewed by an Australian lawyer specialising in edutech before any executable contract is signed with a school. Schools doing due diligence today should treat this page as authoritative for the data we hold and supplement it with the documents listed under §16.

1. Who we are

WellRead is operated by Big Wella, the registered business name of a sole trader based in Queensland, Australia.

OperatorBig Wella (sole trader, registered in Queensland)
ABN77 683 247 003
LocationSunshine Coast, Queensland, Australia
Contact for privacy enquiriesinfo@wellreadreader.com

2. What this policy covers

This policy covers personal information handled by WellRead when:

  • A school enables WellRead for its students and staff (“school data”).
  • A staff member uses the marketing site (wellreadreader.com), including booking a demo or contacting us.
  • A visitor browses the marketing site without identifying themselves.

It does notoverride your school’s own privacy policy. Where a school is acting as the data controller for its students and staff, the school’s policy governs collection from those individuals; we act as data processor on the school’s instructions, as set out in the draft Data Processing Agreement provided to schools during procurement.

3. The information we collect

The categories of personal information we collect, who we collect it from, and why:

Student profile

FromSchool (via librarian or roster import)
WhatName, year level, school email
WhyStudent identity inside the platform; tier-aware book recommendations

Student reading activity

FromGenerated by student use of the app
WhatSaved books, finished books, ratings, reading-streak progress, vibe-quiz answers
WhyPersonal reading recommendations; the student's own bookshelf; aggregate signals to teachers and librarians

Staff profile

FromDirect entry by the staff member or by a school librarian
WhatName, school email, role (teacher / librarian)
WhyAuthentication; access scoping (teacher = own classes; librarian = whole school)

Curation actions

FromGenerated by staff use of the Library Hub
WhatCarousel edits, holiday selections, content-suitability ratings, enrichment edits, withdrawal flags
WhyAudit trail; collaboration between staff; quality control

Demo enquiries

FromDirect entry on the marketing site at /book-demo
WhatName, work email, role, school name, school size, school type, library system, association affiliation
WhyResponding to your enquiry; scoping the demo conversation

Web server logs

FromAutomatic on any request
WhatIP address, requested path, browser/OS string, timestamp
WhyOperating and securing the service. We run no analytics product on either site and set no tracking cookies.

We do not collect: location coordinates, biometric data, health data, behavioural advertising profiles, or third-party social-graph data.

4. How we collect it

  • Directly: when staff enter information, book a demo, or use the Library Hub.
  • From the school: when a school enables WellRead, the librarian provides initial roster data (manually or via CSV import).
  • Automatically: as a student or staff member uses the app (saving a book, finishing a book, answering the vibe quiz, browsing the marketing site).

5. Why we collect it (purposes)

We use personal information to:

  • Provide the WellRead reading-discovery experience to students.
  • Provide the Library Hub and Teacher Dashboard to staff.
  • Generate aggregate signals (popular titles, reading-state breakdowns by year level) for the school’s own use.
  • Respond to enquiries from school staff who book a demo.
  • Improve the platform on the basis of aggregate, de-identified signal, never on identifiable student data.
  • Comply with our legal obligations (audit trails for staff actions, breach notification, financial records).

We do not use student data for advertising, profiling, resale, or any purpose outside the contracted reading and library functions. We do not train third-party AI models on student data.

6. Who we share it with (sub-processors)

The third-party services we use to operate WellRead. Each one processes data only as instructed by us, under back-to-back data-protection terms.

ServiceRegionRoleWhat it sees
NeonAustralia (AWS Sydney, ap-southeast-2)Primary database (Postgres) for all school tenant dataStudent + staff records, reading activity, curation, audit logs. Encrypted at rest, stored in-region.
NetlifyGlobal edge network (US company)Application + marketing site hosting and deliveryStandard web request logs (IP, path, user agent). Records themselves stay in the Sydney database.
TursoManaged cloudBook catalogue database (titles, authors, holdings)No personal information, books only.
BrevoEuropean UnionTransactional email (staff sign-in links, admin notices)Staff names + email addresses only. Students are never emailed.
Google Books APIUnited States / Google-managedCover-image lookup for the catalogue (being replaced by Australian-hosted storage, see §7)Book identifiers (ISBNs, titles); student browser IPs on image loads until the migration completes. No student records.
Google Generative AI (Gemini)United States / Google-managedLibrarian-only catalogue enrichmentBook metadata (titles, themes, suggested levels). No student data.

We do not sell personal information to anyone, and we do not disclose it to third parties for their independent use. Schools can request the current sub-processor list at any time. We will notify schools of any new sub-processor before it begins processing their data, with an opt-out window.

7. Where the data lives

Student and staff records are stored in Australia in a Postgres database operated by Neon on AWS Sydney infrastructure (ap-southeast-2), encrypted at rest. The book catalogue lives in a separate database that holds no personal information. Tenant data is separated by school on every record.

The application is delivered through Netlify’s edge network, so pages load from servers close to the school; the records themselves stay in the Sydney-region database. WellRead is a managed cloud service; schools do not self-host.

Where a sub-processor sits outside Australia (see the table in §6), the safeguards in place are documented in the draft Data Processing Agreement provided during procurement, per Australian Privacy Principle 8. No student personal information leaves Australia in any of those flows.

One current exception worth naming plainly: book cover images are presently loaded from Google Books, which means a student’s browser makes an image request to Google (disclosing an IP address, as any image on the open web does). We are moving covers to Australian-hosted storage to remove even that request.

8. How long we keep it

Active student dataDuration of the student's enrolment with the school
Student data after a student leaves the schoolIdentifying fields anonymised within 12 months; aggregate signals retained
Staff profilesDuration of employment with the school
Audit logs2 years rolling, then anonymised
Demo enquiries (lead data)24 months from last contact, then deleted on request
Web server logsProvider default (weeks, rolling); never joined to student records
Backups90 days rolling

On termination of a school agreement, we return or delete all school data within 30 days at the school’s direction (Data Processing Agreement §9). Deletion is irreversible once executed.

9. How we secure it

We follow the Office of the Australian Information Commissioner’s guidance for securing personal information and apply controls aligned with the Australian Cyber Security Centre’s Essential Eight (Maturity Level 1 baseline, targeting ML2 on multi-factor authentication, patching, and backups within 12 months).

  • In transit. TLS on every connection.
  • At rest. Database encryption by the cloud provider (Neon, AWS Sydney).
  • Access control. Role-based and enforced on the server: students see only their own data, teachers only their own classes, librarians their school. Content tiers are enforced server-side by year level; a student cannot reach older content by editing a link.
  • Sessions. Cryptographically signed session cookies with server-side revocation; signing out invalidates existing sessions.
  • Application security. SameSite cookies, a Content Security Policy enforced on both sites, and rate limiting on authentication and import endpoints.
  • Operator accounts. Multi-factor authentication on the infrastructure accounts we control (database, hosting, source control). Single sign-on and MFA for school users are on the roadmap, not shipped. We say so rather than imply otherwise.
  • Incident response. Documented Data Breach Response Plan; we notify the affected school's primary contact within 72 hours of becoming aware of an incident affecting their data, and the OAIC per the Notifiable Data Breaches scheme (§13).

10. Children's data: heightened care

Most personal information we hold relates to children. We treat that data with extra care, consistent with the OAIC’s expectations and the Children’s Online Privacy Code currently in development.

  • We do not directly collect identifying information from students; the school is the source.
  • Students cannot make their reading activity public to other students. Aggregate signals (e.g. “peer favourites”) are de-identified.
  • We do not show advertising in the student app.
  • We do not use student data for any commercial purpose outside the contracted service to the school.
  • We do not enrol students in marketing or research communications.

11. Your rights

Australian Privacy Principles 12 and 13 give you the right to access the personal information we hold about you and to request correction. You can also request deletion at any time.

For students and staff:the school is the data custodian. Direct your access, correction, or deletion request to your school’s privacy contact. The school will instruct us, and we will action the instruction within 14 days.

For visitors and demo enquirers: email info@wellreadreader.com. We will respond within 14 days. There is no charge for access or correction.

12. Cookies and analytics on the marketing site

Neither the marketing site nor the app runs any analytics service. There are no advertising cookies, no social-media pixels, and no third-party requests. Even fonts are served from our own domain. If we ever adopt a privacy-preserving visit counter for the marketing site, we will update this policy first.

The student app and Library Hub use only the cookies needed to keep you signed in and your session valid.

13. Notifiable Data Breaches

The Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988) requires us to notify the Office of the Australian Information Commissioner and affected individuals when an eligible data breach occurs.

Our commitments:

  • We will notify the affected school’s primary contact within 72 hours of becoming aware of any incident affecting their data, and typically much sooner.
  • We will assess each incident within the statutory 30-day window and, where it is an eligible breach, notify the OAIC and affected individuals as soon as practicable.
  • We maintain a Data Breach Response Plan with a named incident captain, severity rubric, communication tree, and evidence-preservation steps.
  • Schools receive a post-incident report covering root cause, remediation, and any new controls put in place.

14. Complaints

If you think we have mishandled your personal information, please tell us first. Email info@wellreadreader.com with the details. We will acknowledge within 5 business days and provide a substantive response within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):

Schools may also raise concerns under their state or territory information-privacy regulator (NSW IPC, OVIC in Victoria, OIC in Queensland).

15. Changes to this policy

We will update this policy when our practices change or when law requires it. Material changes (sub-processor additions, retention changes, security control changes) will be communicated to schools by email at least 30 days before taking effect, with an opt-out window for sub-processor additions.

The “Last reviewed” date below is updated each time the policy changes.

16. Related documents

  • Data Processing Agreement (draft): the contractual terms governing how we process school data. Provided to schools during procurement, together with the sub-processor list and security overview.
  • Terms of Use: terms governing your use of the marketing site.
  • The school subscription agreement, prepared during procurement.
  • Sub-processor list: the table in this policy is current; a dated copy is provided to schools on request.
  • Security overview and Essential Eight self-assessment, provided to schools on request.

17. Governing law

This Privacy Policy is governed by the laws of Queensland and the Commonwealth of Australia. Disputes are subject to the non-exclusive jurisdiction of the courts of Queensland.

Last reviewed: 2026-08-16. Pre-contract draft awaiting final legal review. Current operations match the practices described above.