Skip to content
Open the app

Data processing agreement

Reference terms, not the signed contract

This page sets out, in plain English, the data-processing terms First Six offers its institutional customers, so a privacy office can assess the posture. The operative document is the signed data processing agreement between First Six and your institution; where the two differ, the signed agreement governs. Some specifics (such as the retention floor) are settled per institution in that agreement. The signable template was reviewed and approved by counsel on 13 July 2026.

This agreement describes how First Six Technologies Pty Ltd (ACN 699 938 817) ("First Six", the processor) handles personal information on behalf of your institution ("you", the controller) when you use First Six. It is framed around the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Roles

You are the controller: you decide why and how student personal information is handled, and you are accountable for it. First Six is your processor: we handle that information only to provide the service and only on your documented instructions, which include your configuration of the app and this agreement. First Six does not use student personal information for its own purposes, and never sells it.

2. Subject matter, duration, and purpose

  • Subject matter: provision of the First Six app (student and staff web apps and the mobile app) to your students and staff.
  • Duration: for the term of your agreement with First Six, plus the limited wind-down in section 9.
  • Purpose: helping students through their first six weeks, including weekly wellbeing check-ins, help and crisis routing, timetable and events, and the staff console that supports them.

3. Types of data and categories of people

  • People: your students, and your staff who use the console.
  • Data: identity from your roster (name, institutional email, program, campus); student-provided profile details; weekly wellbeing check-in responses; help and crisis requests and their conversations; timetable and event activity; private workspace content; and, where enabled, notification tokens and contact points. Wellbeing and help data is treated as sensitive informationA category the Australian Privacy Act protects more strictly, including health and wellbeing information. and given the stricter handling described in the privacy policy and what we collect.

First Six practises data minimisation: it holds no passwords (authentication is delegated to your identity provider), no payment data, and no health records beyond what a student self-reports.

4. Our obligations as processor

First Six will:

  • process personal information only on your documented instructions, and tell you if we believe an instruction breaches applicable privacy law;
  • ensure people authorised to process the data are bound by confidentiality;
  • keep the security measures in section 5;
  • engage subprocessors only under section 6;
  • assist you, taking into account the nature of processing, to respond to requests from individuals exercising their rights (section 7);
  • assist you with security, breach notification, and privacy-impact assessments (sections 5 and 8); and
  • return or delete the data at the end of the service (section 9).

5. Security

Isolation and access controls are enforced in the database, not just in application code:

  • Every tenant-owned row carries your institution_id, and row-level security is enabled on every table, so one institution's data cannot be read by another. A cross-tenant read is structurally prevented.
  • Data is encrypted in transit (TLS, with HSTS) and at rest.
  • An immutable audit log records staff actions, including each deliberate open of an individual student's record.
  • First Six staff have no standing access to your students' records. The operator console is aggregate-only (no names, emails, or message content). The only exception is a break-glass grant that your admin opens for one student, with a reason and an expiry of at most 72 hours, revocable at any time; even then First Six sees only the technical shape of the records, never the words, the name, or the private workspace, and every look is written to your own audit trail.

First Six does not yet hold a SOC 2 or ISO 27001 certification and states so plainly. It is willing to commit to SOC 2 as a contractual milestone for a pilot. Fuller technical detail is in data residency and tenant isolation.

6. Subprocessors

You authorise First Six to engage the subprocessors listed on the Subprocessors page (kept current; also maintained as an engineering source of truth and on the Trust Centre). Each subprocessor is engaged under terms that protect the data consistent with this agreement.

  • Primary data stays in Australia (Supabase on AWS Sydney: database, sign-in, file storage).
  • Some subprocessors are overseas (for example email, mobile push via Expo, error monitoring). Where you enable crisis SMS or Slack alerts, those also carry welfare-relevant content to those providers.
  • First Six gives at least 30 days' notice of an intended new subprocessor, during which you may object.

7. Assisting with individual rights

First Six will help you meet your obligations when a student exercises a right (access, correction, or erasure). Students can see their own check-in history and help requests in the app. On erasure: your institution authorises deletion; First Six carries out a hard delete that cascades across the student's check-ins, help requests, saved items, and timetable. A student who contacts First Six directly at privacy@firstsix.com.au is routed to your privacy contact, since you authorise the deletion. See deleting your data.

8. Personal information breaches

First Six runs a documented incident and breach-response process aligned with the Notifiable Data BreachNotifiable Data Breach scheme. The Australian regime requiring assessment and notification of eligible data breaches. scheme. On becoming aware of a breach affecting your data, First Six will notify you without undue delay and no later than 72 hours after becoming aware, and provide the information you reasonably need to meet your own assessment and notification obligations. Welfare data is treated as high-harm by default in that assessment, so the response errs toward notifying. Notification templates are pre-written so response is execution, not drafting.

9. Return or deletion at the end of the service

When the service ends, First Six will, at your choice, return or delete the personal information it holds for you, except where retention is required by law. These are the standard timeframes; the exact day-counts are confirmed in your signed agreement.

  • Export / return. You may request a full, machine-readable export of your data (your content and the student records you are entitled to, plus stored files). We deliver it within 30 days of the request.
  • Deletion. Unless you direct otherwise, First Six hard-deletes your live records within 30 days of the later of the service ending or the export being delivered. This is a true hard delete, not a soft flag: it cascades across the student's check-ins, help history, and files.
  • Backups. Deleted data then ages out of routine encrypted backups on the standard snapshot rotation, within a 30-day outer bound, after which it is gone from backups too.
  • Certificate of destruction. Available on request once deletion is complete.

When we delete, we keep only what the law requires: records under a legal hold, and any welfare or crisis records subject to a mandatory-reporting minimum. Everything else, including your own activity log, is included in the export we give you and then destroyed. First Six keeps a tamper-resistant record in its own operational log that the deletion took place, which is what a certificate of destruction attests to. Any residual statistics are anonymous counts that never identified an individual.

10. Audit and assurance

First Six will make available the information reasonably needed to demonstrate compliance with this agreement, including its subprocessor list, security posture, and evidence pack (such as the audit-log surfacing and the break-glass records), and will contribute to audits or inspections you conduct or mandate, on reasonable notice and terms. A pre-filled HECVAT-style questionnaire is available.

11. International processing

Primary data is processed in Australia. Where a subprocessor processes data overseas (section 6), First Six takes reasonable steps so the handling stays consistent with the APPs, and discloses each such flow so you can assess it. For some notifications and alerts, that can include welfare-relevant wording.

12. General

This agreement supplements your main agreement with First Six and is governed by the laws of Queensland, Australia. If it conflicts with your signed agreement with First Six, the signed agreement governs, and liability is dealt with under that agreement. If any term here conflicts with a data-protection obligation you are subject to, tell us and we will work in good faith to address it.

Common questions

Is this the contract we sign?

No. This is a plain-English reference to the processor terms. The operative document is the signed data processing agreement between First Six and your institution, which governs if the two differ.

Where is our data processed?

Primary data (database, sign-in, file storage) is in AWS Sydney. Some subprocessors are overseas; the full list and what each can see is on the Subprocessors page, so your privacy office can assess each flow.

Can First Six staff see our students' data?

Not by default, and never without your action. The one path is a break-glass grant your admin opens for a single student, time-boxed to 72 hours, revocable, and even then redacted to the technical shape of the records and logged in your own audit trail.

Was this helpful?
Need more help?

The fastest answer is usually one question away.

Contact us
Edit this page on GitHub