Legal

Privacy policy

This policy explains how Magnolia Avenue Pty Ltd trading as Retento (ACN 691 273 426) handles personal information in Australia.

Effective 29 September 2026

1. Scope and our role

Retento provides a student engagement and retention platform to universities, vocational education and training providers, and other education institutions. This policy applies to personal information Retento handles through its platform, website, business operations and support channels.

An education institution will usually decide why and how its student information is handled. In that setting, Retento acts as its contracted service provider and follows the institution's lawful instructions. Students should also read their institution's privacy notices, which explain the institution's own handling practices.

We seek to handle personal information consistently with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where we are bound as a contracted service provider to a Queensland public sector entity, we also comply with applicable contractual obligations under the Information Privacy Act 2009 (Qld) and the Queensland Privacy Principles.

2. Personal information we handle

Depending on how an institution configures Retento, we may handle:

  • student names, identifiers, contact details and enrolment or cohort information;
  • SMS and other communications, response selections and delivery records;
  • support needs, referrals, case notes and engagement outcomes;
  • staff names, work contact details, roles, sign-in records and activity logs;
  • technical information such as device, browser, network, security and usage data; and
  • information sent to us in enquiries, demonstrations, support requests or complaints.

Communications may reveal sensitive information, including health, disability, financial hardship or personal circumstances. We only handle sensitive information where consent has been obtained or another lawful basis applies, and only for the purposes authorised by the relevant institution and applicable law.

3. How we collect and use information

We may receive information from an education institution, directly from a student or staff member, through interactions with the platform, or from our service providers. Institutions are responsible for providing appropriate collection notices and obtaining any consent required for the information they provide to Retento.

We use personal information to:

  • deliver check-ins, receive responses and connect students with appropriate human support;
  • operate, secure, monitor and improve the platform;
  • provide account access, technical support and service communications;
  • produce authorised reporting for institutions, including aggregated insights;
  • meet contractual, legal, audit and incident-response obligations; and
  • respond to enquiries, privacy requests and complaints.

If required information is not provided, Retento or the institution may be unable to provide the relevant communication, support pathway or platform function. We do not sell personal information.

4. AI-assisted processing and human review

Retento uses AI to assist with triage and prepare draft responses. Student message content is minimised before processing. Drafts and escalations are reviewed by authorised staff: Retento's AI does not independently make final decisions about a student's eligibility, enrolment, academic standing, support outcome or legal rights.

Institutions determine the support actions taken in response to Retento's signals. Retento applies access controls and configured geographic restrictions to AI processing as described in the subprocessor table below.

5. When we disclose information

We disclose personal information only where needed to provide the service, on an institution's instructions, with consent, or where required or authorised by law. This may include disclosure to the relevant institution and its authorised staff, the subprocessors below, professional advisers, insurers, regulators, courts or law enforcement where lawfully required.

Subprocessors

These providers support Retento's current service configuration. Exact legal entities and processing locations may depend on Retento's contract and the institution's setup.

Amazon Web Services

Service
Aurora PostgreSQL, Lambda, ECS Fargate, S3, CloudFront, SQS, EventBridge, KMS, Secrets Manager/SSM, CloudWatch, CloudTrail, GuardDuty and Route 53
Purpose
Hosting, storage, computing, security and monitoring.
Data processed
Platform data, including student contact details, conversations, case notes and staff accounts.
Processing location
Sydney (ap-southeast-2). CloudFront may serve static console files from edge locations; those files do not contain student data.

Amazon Cognito

Service
Staff authentication and multi-factor authentication
Purpose
Staff sign-in and account security.
Data processed
Staff names, email addresses and sign-in records.
Processing location
Sydney, Australia.

Amazon Simple Email Service (SES)

Service
Transactional email
Purpose
Email to students and staff, and email-to-ticket escalations.
Data processed
Email addresses, message content and minimum escalation fields.
Processing location
Sydney, Australia.

Amazon Bedrock (Anthropic Claude models)

Service
AI-assisted triage and draft replies
Purpose
Supporting triage and drafting replies that are reviewed by authorised staff.
Data processed
Student message content, minimised in accordance with Retento's data-minimisation controls.
Processing location
Australia-only inference profiles, using Sydney or Melbourne for overflow. Global and Asia-Pacific profiles are blocked by policy.

Sinch (Australian entity, formerly MessageMedia)

Service
SMS REST API and Australian-region messaging
Purpose
Sending and receiving student SMS messages and managing dedicated numbers.
Data processed
Student mobile numbers, message content and delivery receipts.
Processing location
Australian endpoint. Sinch's own data-residency terms and Australian carrier subprocessors may also apply.

Google Workspace

Service
Retento staff email and account management portal sign-in
Purpose
Retento staff email, support inboxes and portal authentication.
Data processed
Retento staff information and information sent to Retento support by an institution or student.
Processing location
Google may process or store this information outside Australia because Workspace does not offer Retento an Australian-only data region.

We review our subprocessor arrangements and may update this list when providers, services or locations change. Material changes will be reflected in this policy.

6. Overseas disclosures

Retento configures its core platform hosting, authentication, transactional email, SMS processing and AI inference for Australia. Google Workspace may process or store Retento staff and support information in countries outside Australia. The particular countries may vary according to Google's infrastructure and service terms and may not be practicable for Retento to specify in advance.

Before disclosing personal information to an overseas recipient, we take reasonable steps required by Australian Privacy Principle 8, including contractual, technical and organisational safeguards where appropriate. When acting for a Queensland public sector customer, we also apply any overseas-transfer restrictions required by contract and the Information Privacy Act 2009 (Qld).

7. Security, retention and data breaches

We use safeguards appropriate to the nature of the information we handle, including access controls, encryption, logging, monitoring, multi-factor authentication, data minimisation and Australian-region controls for core platform services. No method of storage or transmission is completely secure.

We retain personal information only for as long as needed for the purposes described in this policy, the relevant institution's instructions, contractual obligations and legal requirements. We then delete or de-identify it where required and practicable.

We assess suspected data breaches and notify affected institutions, individuals and regulators where required, including under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth) and applicable Queensland requirements.

8. Access and correction

You may request access to, or correction of, personal information Retento holds about you. If the information was provided by or is controlled by your education institution, we may refer the request to that institution or work with it to respond. We may need to verify your identity before acting and may refuse a request where permitted by law. If we refuse, we will generally explain why and the available complaint options.

Send requests to admin@retento.com.au. There is no charge for making a request. If a lawful access charge applies, we will tell you before proceeding.

9. Questions and complaints

Contact our Privacy Officer at admin@retento.com.au with a privacy question or complaint. Please describe the issue and include enough information for us to investigate. We will acknowledge the matter and aim to provide a substantive response within 30 days. If the matter relates to information controlled by an education institution, we may coordinate with or refer you to that institution.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner. For a matter governed by Queensland public sector privacy law, you may also be able to contact the Office of the Information Commissioner Queensland, subject to its complaint requirements.

Privacy contact

Privacy Officer
Magnolia Avenue Pty Ltd trading as Retento
ACN 691 273 426 ยท Queensland, Australia

admin@retento.com.au

This policy is reviewed periodically and may be updated to reflect changes to Retento's services, subprocessors or legal obligations. The effective date above identifies the current version.