Acceptable Usage Policy
KAMAR's Limited's Acceptable Usage Policy
Last updated: August 2026
1. Purpose
This Acceptable Use Policy ("AUP") sets out the requirements for acceptable use of KAMAR's products and services.
KAMAR provides Student Management System software and related services to schools and other educational organisations. KAMAR is designed to help authorised users manage student information and support the administration and operation of schools.
This AUP is intended to help protect KAMAR, our customers, their users and the information held within KAMAR from misuse, unauthorised access and security threats.
This AUP forms part of the terms under which KAMAR's products and services are provided.
2. Scope
This AUP applies to all customers (schools) and users who access or use KAMAR products and services.
The school is responsible for ensuring that its users comply with this AUP.
For the purposes of this AUP, "user" includes teachers, administrators, support staff, contractors and any other person who is authorised by a school to access KAMAR.
3. Authorised Use
KAMAR may only be used for legitimate educational, administrative and operational purposes connected with the customer's activities.
Users must:
- Use KAMAR only for purposes for which they have been authorised.
- Access only the information and functionality necessary for their role.
- Keep their account credentials secure.
- Comply with applicable laws and regulations.
- Comply with the school's own policies and procedures relating to privacy, information security and appropriate use.
Schools are responsible for determining which individuals should have access to KAMAR and for assigning appropriate permissions.
4. Prohibited Use
Schools and users must not use KAMAR to:
- Access, collect, use or disclose information without appropriate authorisation.
- Access another person's account or credentials.
- Attempt to gain unauthorised access to KAMAR or any associated systems.
- Circumvent or interfere with security or access controls.
- Probe, scan or test the vulnerability of KAMAR systems without KAMAR's prior written authorisation.
- Introduce malware, viruses, malicious code or other harmful material.
- Interfere with or disrupt the operation of KAMAR or its underlying infrastructure.
- Attempt to reverse engineer, decompile, disassemble or otherwise derive the source code of KAMAR software, except where expressly permitted by law.
- Use automated means to access KAMAR in a manner that could adversely affect its performance or availability, unless expressly authorised by KAMAR.
- Use KAMAR to store or transmit material that is unlawful, fraudulent, threatening, defamatory, harassing or otherwise unlawful.
- Use KAMAR to facilitate or engage in fraudulent, deceptive or illegal activity.
- Use KAMAR to infringe another person's intellectual property, privacy or other legal rights.
- Resell, sublicense or provide access to KAMAR to an unauthorised third party, unless expressly permitted under the school's agreement with KAMAR.
- Use KAMAR in a way that could reasonably be expected to damage KAMAR's systems, reputation or ability to provide services to other customers.
5. Personal and Confidential Information
KAMAR contains personal and confidential information about students, whānau and staff, as members of the school community.
Schools are responsible for ensuring that their collection, use, storage, disclosure and management of information through KAMAR complies with applicable privacy and information-management requirements.
Users must only access and use personal information for legitimate purposes and in accordance with their role and the school's policies.
Schools must take reasonable steps to ensure that personal information accessed through KAMAR is not disclosed to unauthorised people.
6. Account Security
Schools are responsible for the security of accounts issued to their users.
Schools and users must not:
- Share account credentials between users.
- Allow another person to use their account.
- Attempt to obtain another user's credentials.
- Use credentials belonging to another person.
- Leave an authenticated KAMAR session accessible to an unauthorised person.
Schools should promptly disable or remove access for users who no longer require access to KAMAR.
KAMAR may require additional security measures for certain products or services where reasonably necessary to protect the service or customer information.
7. Data and Content
Schools remain responsible for the information and other content they or their users enter into KAMAR.
Schools must ensure that information entered into KAMAR:
- Is collected and used lawfully.
- Is appropriate for the intended purpose.
- Does not knowingly contain malicious code or other harmful material.
- Does not unlawfully infringe the rights of another person.
KAMAR does not generally review customer data or content for compliance with this AUP. However, KAMAR may investigate suspected misuse where reasonably necessary to protect its services, customers (schools) or users.
8. Third-Party Services and Integrations
Schools must not connect KAMAR to third-party systems in a way that:
- Bypasses KAMAR's security controls.
- Places unreasonable demands on KAMAR systems.
- Accesses information beyond the permissions granted.
- Breaches applicable law or the school's obligations relating to personal information.
- Circumvents restrictions imposed by KAMAR.
Where KAMAR provides an integration capability, schools must use it in accordance with any applicable technical documentation and conditions provided by KAMAR.
9. Artificial Intelligence and External Services
Schools and users must take appropriate care when using KAMAR information with artificial intelligence tools or other external services.
Unless expressly authorised by the school and permitted under the applicable terms and privacy requirements, users must not copy, export or submit personal or confidential information obtained from KAMAR to external AI systems, websites or applications.
Customers are responsible for ensuring that their use of third-party services with KAMAR information complies with applicable privacy and security requirements.
10. Security Testing and Research
Schools must not conduct penetration testing, vulnerability scanning, load testing or other security testing against KAMAR systems without KAMAR's prior written authorisation.
Security concerns or suspected vulnerabilities should be reported to KAMAR through the appropriate support or security reporting channel.
KAMAR encourages responsible reporting of suspected security vulnerabilities and asks that customers do not exploit or publicly disclose a vulnerability before KAMAR has had a reasonable opportunity to investigate and respond.
11. Intellectual Property
KAMAR software, documentation, interfaces, branding and other materials provided by KAMAR remain subject to the intellectual property rights applicable to those materials.
Nothing in this AUP grants a school or user any rights to KAMAR's intellectual property other than those expressly provided under the school's agreement with KAMAR.
12. Monitoring and Investigation
KAMAR may monitor service activity and technical information where reasonably necessary to:
- Maintain the security, availability and performance of its services.
- Detect or prevent misuse, fraud or security threats.
- Investigate suspected breaches of this AUP.
- Meet legal or regulatory requirements.
- Protect KAMAR, its customers and users.
KAMAR will handle customer (school) information in accordance with its applicable contractual and privacy obligations.
13. Reporting Concerns
Schools should promptly notify KAMAR if they become aware of:
- Unauthorised access to a KAMAR account.
- A compromised user account or password.
- A suspected security vulnerability.
- Unauthorised access to customer information.
- Malicious activity affecting KAMAR.
- Any other activity that may materially compromise the security or operation of KAMAR.
Prompt reporting helps KAMAR investigate and respond to potential security incidents.
14. Enforcement
If KAMAR reasonably believes that a school or user has breached this AUP, KAMAR may take appropriate action to protect its services, customers and users.
Depending on the circumstances, this may include:
- Requesting that the customer stop or remedy the activity.
- Restricting particular functionality or access.
- Temporarily suspending affected accounts or services.
- Taking technical measures to prevent or limit harmful activity.
- Taking further action available under the school's agreement with KAMAR.
Where reasonably practicable, KAMAR will work with the school to resolve suspected breaches before restricting access. However, KAMAR may take immediate action where necessary to address an urgent security, legal or operational risk.
15. Customer Responsibility
Schools are responsible for the actions of their users and for ensuring that their use of KAMAR complies with this AUP and their agreement with KAMAR.
Nothing in this AUP removes or limits any responsibility assigned to the customer under its agreement with KAMAR or applicable law.
16. Changes to This AUP
KAMAR may update this AUP from time to time to reflect changes to its services, technology, security practices or applicable requirements.
The current version of this AUP will be made available through the KAMAR website.
17. Contact
Questions about this AUP or reports of suspected misuse should be directed to KAMAR through the usual KAMAR support or security contact channels.