GoHiMark is built for privacy-first procurement: clear data-flow evidence, documented controls, teacher-reviewed AI use, and security milestones schools can inspect.
Security isn't a feature we added — it's embedded in every layer of how GoHiMark works.
Australian hosting, sub-processor routing, backups, logs, and AI provider data flows are documented for procurement review.
Encryption and key-management controls are captured as reviewable design evidence before stronger certification claims are made.
Role-based access control ensures teachers only see their own classes, students see only their own data, and administrators have audited elevated access.
Privacy, security, and curriculum governance claims are tracked as evidence packs instead of presented as unsupported badges.
Incident response roles, escalation paths, school communications, and NDB assessment steps are maintained as due-diligence documentation.
Internal reviews, third-party testing, and certification work are tracked as validation milestones until formal evidence is attached.
We believe student data belongs to students and schools — not to technology companies. These commitments are written into our contracts, not just our marketing.
Australian hosting and offshore-transfer boundaries documented for procurement review
Student data advertising and commercial-use restrictions tracked in the DPA evidence pack
AI training-use restrictions documented for model and vendor review
Data export and deletion workflows documented for contract review
Transparent Data Processing Agreement (DPA) available on request
Privacy Impact Assessment (PIA) documentation available for procurement teams
GoHiMark is designed to satisfy the regulatory and contractual requirements of Australian schools.
| Framework | Scope | Status | Notes |
|---|---|---|---|
| Privacy Act 1988 (Cth) | Federal — all Australian organisations | Evidence in progress | APP mapping requires legal and operating-control review |
| ACSC Information Security Manual | Australian Cyber Security Centre guidance | Mapped for review | Control mapping is prepared for IT due diligence |
| NSW NESA Data Governance | NSW schools using NESA-approved tools | Under review | State-specific data governance evidence is being assembled |
| Victorian Education Department | Victorian government and Catholic schools | Mapped for review | Guideline mapping is tracked in the procurement evidence pack |
| Notifiable Data Breaches (NDB) | Federal — mandatory reporting scheme | Workflow documented | NDB assessment and communication steps are documented |
| General Data Protection Regulation (GDPR) | EU — applies where EU residents use the platform | Requirements tracked | International privacy requirements are tracked for legal review |
Common questions from IT teams and procurement officers.
Our team is happy to provide documentation for your IT review, complete your security questionnaire, or join a call with your IT director.