This page summarises what Korva does if personal information it holds is lost, or is accessed or disclosed without permission (a "data breach"). Korva follows the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988. Our full internal plan is kept by the operator and reviewed at least once a year.
1. Contain
As soon as we suspect a breach, we act to stop it and limit the harm — for example by revoking access, rotating passwords and keys, taking an affected feature offline, or asking a service provider to act.
2. Assess
We work out what information was involved, whose it was, and whether the breach is likely to result in serious harm to anyone. Because Korva is a service for children, we treat any breach involving a child's information with particular care. We complete this assessment promptly, and within 30 days at most, as the Privacy Act requires.
3. Notify
If the breach is likely to result in serious harm (an "eligible data breach"), we notify the Office of the Australian Information Commissioner and the affected parents and guardians as soon as practicable, consistent with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988. We notify parents by email to the account address. The notice says what happened, what information was involved, and what you can do to protect yourself and your child. Children's accounts have no email address, so a child is told through their parent.
4. Review
After every breach, and every suspected breach, we record what happened and what we did, and we change what needs changing so it does not happen again.
Report a problem
If you think Korva has had a data breach, or you have found a security problem, tell us straight away at admin@korvaacademy.com.au or through /privacy-concern.