Concord Infiniti Privacy Policy

Last updated: September 2026


1. Introduction

This Privacy Policy describes how Concord Australia Pty Ltd (“Concord”, “we”, “us”, or “our”) collects, uses, and protects personal information in connection with the Concord library management system and related services (the “Services”). This Concord Privacy Policy is incorporated into Concord Terms and Conditions by this reference.

Concord provides the Services to schools, school districts, and educational authorities (“Schools”). In providing the Services, Concord processes personal information on behalf of Schools.


2. Roles and Responsibilities

For the purposes of applicable data protection laws:

    • The School is the data controller (or equivalent under applicable law).

    • Concord acts as a data processor (or “service provider” under Australian law).

Concord processes personal information:

    • only on behalf of and under the instructions of the School, and

    • solely for the purpose of providing and supporting the Services.

    • personal information is processed and stored in data centres to comply with data sovereignty requirements where applicable.

Schools are responsible for:

    • determining the lawful basis for processing personal information, and

    • obtaining any required consents from parents, guardians, or students.


3. Scope

This Privacy Policy applies to personal information processed by Concord in connection with the Services used by Schools in Australia, the United Kingdom, the European Union, the United States, Canada, and other jurisdictions including International Schools.


4. Information We Process

We process personal information as instructed by Schools, which may include:

a. Student Information

    • Name, gender, student ID, year level, class, campus

    • School affiliation

    • Library activity (e.g., borrowing history, reservations)

b. Staff and Parent Information

    • Name, email address, role (e.g., teacher, librarian, guardian, administrator)

c. Technical Information

    • IP address

    • Device type, browser type, operating system

    • Usage and activity logs within the Services

d. Optional Information

    • Profile images or preferences

    • Email addresses

where enabled by the School.

We do not knowingly collect more personal information other than is necessary to provide the Services.


5. Children’s Information

Concord processes personal information of students, including children under 13 (US) and under 16 (elsewhere), solely on behalf of Schools.

    • Schools provide authorization and, where required, consent on behalf of parents or guardians.

    • We do not require students to provide personal information beyond what is necessary for educational use of the Services.

    • We do not use student data for advertising or commercial profiling.

Parents and guardians should contact their School to:

    • access, correct, or delete student information

    • raise any concerns about data processing


6. How We Use Personal Information

We use personal information only to:

    • provide, operate, and maintain the Services

    • authenticate users and manage accounts

    • support library management functions (e.g., lending, cataloguing, reporting)

    • communicate service-related notifications

    • ensure security, integrity, and performance of the Services

    • comply with legal obligations

We may use aggregated and de-identified data to:

    • improve functionality and performance

    • generate statistical insights for Schools

Aggregated data does not identify individuals.


7. Prohibited Uses

Concord does not:

    • sell personal information

    • use personal information for targeted advertising

    • build profiles for non-educational commercial purposes

    • use student data beyond the instructions of the School


8. Cookies and Technical Data

We use cookies and similar technologies to:

    • maintain secure sessions

    • enable core functionality

    • understand system performance

We do not use cookies for advertising purposes.

Where required by law (e.g., EU/UK), Schools or users may be provided with appropriate cookie controls.


9. Disclosure of Information

We disclose personal information only:

    • to the School and its authorized users

    • to subprocessors engaged to provide the Services

    • where required by law or legal process

Sub-processors

    • We use sub-processors to process personal data on behalf of our customers subscribing to and using Infiniti or LibPaths SaaS.

    • We expect our sub-processors to implement appropriate technical and organizational measures ensuring that the sub-processing of personal data is protected to the standards required by applicable data protection laws.

Sub-processor: Amazon Web Services, Inc.

    • Applicable Cloud Products: Infiniti LMS

    • Nature and Purpose of Processing: Hosting of application data, including personal student and teacher data required for service delivery.

    • Categories of Personal Data: personal data required for services delivery including; name, email, academic level, photos, borrowing records

    • Location of processing for Infiniti LMS data aligned to applicable data sovereignty laws for each country:
        • Australian, New Zealand –> Australia

        • Asia, South Asia, India –> Singapore

        • United Kingdom, EU, MEA –> UK

        • United States –> USA

Sub-processor: Freshworks

    • Applicable Cloud Products: Freshdesk CRM

    • Nature and Purpose of Processing: Customer support, help-desk ticket management and support communications

    • Categories of Personal Data: librarian name, email, and support correspondence

    • Location of Processing: USA


10. National and International Data Transfers

Personal information will be stored according to data sovereignty rules applicable in respective countries below and will be processed in each School’s respective country:

    • Australia

    • European Union

    • Singapore

    • United Kingdom

    • United States of America

Information is generally not transferred internationally but if any information needs to be transferred internationally, Concord implements appropriate safeguards, including:

    • Standard Contractual Clauses (SCCs)

    • UK International Data Transfer Addendum (where applicable)

On behalf of the School, all transfers are conducted in accordance with applicable data protection laws and data sovereignty rules of the country in which each school is geographically located, if applicable.


11. Data Retention

Concord retains personal information only for as long as necessary to provide the Services and fulfill contractual obligations.

    • Data is retained for the duration of the School’s use of the Services

    • Upon termination, data is deleted or returned in accordance with contractual terms (refer to Terms & Conditions)

    • Backup data is retained for a minimum 12 months before being securely deleted

Schools may request deletion of data at any time, subject to contractual obligations and legal obligations.


12. Security

Concord implements appropriate technical and organisational measures to protect personal information, including:

    • encryption of data in transit (TLS 1.3 or greater)

    • encryption of data at rest (AES 256 or greater)

    • access controls based on least privilege

    • authentication and account security controls

    • monitoring, logging, and intrusion detection

    • regular security reviews and testing

    • multiple-factor authentication for support staff

Access to personal information is restricted to authorized personnel subject to confidentiality obligations.


13. Data Breach Notification

In the event of a data breach, Concord will:

    • notify the affected School without undue delay

    • provide sufficient information to support the School’s legal obligations

    • cooperate with investigation and remediation efforts


14. Data Subject Rights

Data subject rights (including access, correction, deletion, restriction, and portability) are managed by the School as data controller.

Concord will:

    • assist Schools in responding to requests

    • implement technical measures to support compliance

Individuals should contact their School in the first instance.


15. Third-Party Services

The Services may integrate with third-party systems (e.g., authentication providers, library databases, video streaming providers).

    • Such integrations are enabled at and by the direction of the School

    • Third parties process data under their own privacy policies


16. Compliance with Laws

Concord supports Schools in complying with applicable privacy laws, including:

    • Australian Privacy Principles (APPs)

    • Canada PIPEDA and applicable provincial laws

    • GDPR (EU) and UK GDPR

    • US laws including COPPA and FERPA


17. Changes to This Policy

We may update this Privacy Policy from time to time and will advise customers when this occurs.

    • Material changes will be communicated to Schools

    • Continued use of the Services constitutes acceptance of updates

We will not materially change how personal information is used without appropriate notice and legal basis.


18. Contact Information

For privacy-related inquiries, contact:

Concord Australia Pty Ltd
Email: support@concordinfiniti.com

Where required, Concord will designate appropriate regional representatives.