Our commitment. We collect only what is needed to run a school carnival, we never sell or share student data, and every school's records are isolated from every other school's. Below is a factual account of the controls we have in place — not marketing claims — followed by the legal framework we work within and the policies you can rely on.
How we protect your data
Security is layered across the platform — from how data is separated, to who can reach it, to how we detect and respond when something looks wrong.
Tenant isolation
Every record is tied to a school and filtered by an enforced, tenant-scoped query rule. No school can read or reach another school's data — isolation is logical and applied on every query, not left to individual code paths.
Role-based access
Staff only see what their role needs. Admins, marshals, recorders and team managers each get least-privilege permissions, and student personal information is gated behind explicit permission checks.
Two-factor authentication
Time-based one-time-password (TOTP) 2FA with trusted-device support and one-time recovery codes. Both administrator-initiated and self-service resets are available.
Account & password security
Passwords are hashed, sign-in is rate-limited, and sensitive actions require re-entering your password. Temporary onboarding passwords must be changed on first use.
Audit logging
Significant data actions — imports, results changes, exports — are timestamped and recorded, giving your school a traceable history for accountability and compliance.
Application hardening
Every response carries a strict set of security headers: a Content-Security-Policy, HSTS over HTTPS, clickjacking protection (X-Frame-Options / frame-ancestors), MIME-sniffing protection and a restrictive Permissions-Policy.
Administrative controls
The platform administration console can be restricted to an approved IP allowlist, and sensitive administrative events raise real-time security alerts to our team.
No personal data in links
Student information is never placed in URLs — only opaque identifiers are used. Public results and self-nomination pages are reached through revocable tokens, not open access.
All traffic is served over HTTPS/TLS, and sensitive credentials such as 2FA secrets and recovery codes are encrypted at rest. We conduct periodic security reviews of our infrastructure, access controls and code.
Legal & regulatory framework
Privacy Act 1988 (Cth)
We operate under the Australian Privacy Act and the Australian Privacy Principles. Schools remain the owner and controller of their data; SportsOrganised acts as a processor on your behalf and supports access, correction and deletion requests.
Notifiable Data Breaches scheme
We follow the NDB scheme (Part IIIC of the Privacy Act). If an eligible breach occurs we notify the OAIC and affected individuals, and we notify your school administrators regardless of eligibility. Our full response process is set out in the breach policy below.
Our policies
Report a vulnerability
We welcome responsible disclosure from security researchers, staff and school administrators. If you believe you've found a security issue or suspect a data breach, contact us — every report is treated as urgent and acknowledged within 24 hours.
support@sportsorganised.com