Privacy Policy

Raynux Pty Ltd (ABN 38 700 717 166) — data controller and/or processor, as explained in section 2. Version 3.0. Effective date: 30 September 2026. Supersedes the 2018 policy.

1. About this policy and who we are

This Privacy Policy explains how Raynux Pty Ltd (Raynux, we, us) handles personal information in connection with Librarika, our cloud Integrated Library System, and our websites.

  • Address: Level 29, 221 St Georges Terrace, Perth WA 6000, Australia
  • Contact / privacy enquiries: info@raynux.com (or info@librarika.com)
  • EU/UK matters: you can contact us at info@librarika.com. If you are in the EU or UK, you can also contact our appointed representative, Euverify Ltd, at gdpr@euverify.com or through their secure portal — full details are in the contact section below

Librarika is now provided by Raynux Pty Ltd, an Australian company, which has taken over the operation of Librarika from its previous operator. This policy replaces the earlier (2018) Librarika privacy policy.

We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where they apply, the EU General Data Protection Regulation (GDPR) and UK GDPR. We apply APP-level protections to all users regardless of any small-business exemption position under Australian law.

2. Our two roles: controller and processor

  • When we act as a processor (service provider). For patron and member information and other Customer Content that libraries put into Librarika, the library (our Customer) is the data controller and Raynux processes that information on the library's instructions. If you are a patron with questions about your information, contact your library first; our handling in this role is governed by our Data Processing Addendum with the library.
  • When we act as a controller. For information we decide how to use ourselves — such as account administrator and billing details, support correspondence, marketing to our customers, and website-visitor data — Raynux is the controller, and this policy governs that handling.

3. Who this policy covers

  • Website visitors;
  • Account holders and administrators (library staff and librarians);
  • Library patrons and members whose information libraries hold in Librarika (handled mainly as a processor);
  • The library's own staff, where a library records their details in Librarika (handled as a processor); and
  • Children, where school or other libraries use Librarika for young patrons (see clause 11).

4. What we collect, and from whom

From account holders / administrators (we are controller):

  • Account and contact data — name, email, phone, organisation, role, username, and authentication data (credentials are stored securely; where you sign in with a third-party provider such as Google, we receive the basic identity information that provider shares);
  • Billing data — plan, transaction records, and payment method details (card details are collected by our payment providers, not stored by us);
  • Support and correspondence — messages, tickets and feedback;
  • Technical, usage and diagnostic data — IP address, device and browser information, log data and cookie identifiers, product-usage analytics (such as page views, events and feature usage), and crash and error diagnostics.

Patron / member information (we are usually processor, on the library's behalf):

  • Identity and contact data — name, membership number, address, phone, email and (where the library chooses) photo;
  • Library-activity data — loans, holds, reservations, fines, reviews and community/catalogue contributions. This includes borrowing and reading history, which we treat with particular care.
  • Any other fields a library configures — including, where a library uses optional modules such as staff/employee records, information about the library's own staff (which may include identifiers such as a national identity number). We process this only as a processor, on the library's instructions and for the library's own record-keeping.
  • Files and content you or your users upload — such as cover images and attachments — which may themselves contain personal data.

Sources. We collect information directly from you; from the library that manages your record (for patrons); automatically through your use of the Service; and from third parties such as login providers you choose to use and our payment providers.

5. Why we use personal information

We use personal information to: register and manage accounts and authenticate users; provide and operate library services; process payments and manage subscriptions; provide customer support; send service and security notifications; keep the Service secure and prevent fraud and misuse; measure, improve, customise and develop the Service (using de-identified or aggregated data where we can); and, with a lawful basis, send marketing, surveys and product updates to our customers (see clause 12). We do not use your personal information to make decisions by automated means alone that have a legal or similarly significant effect on you; if that changes, we will update this policy and tell you as the law requires.

6. Legal bases (GDPR) and APP framing

Where the GDPR/UK GDPR applies and we are a controller, we rely on: Contract (Art 6(1)(b)) to provide the Service and process payments; Legitimate interests (Art 6(1)(f)) to secure and improve the Service, prevent fraud and carry out limited direct marketing to existing customers; Consent (Art 6(1)(a)) for certain cookies/analytics and some marketing, which you can withdraw at any time; and Legal obligation (Art 6(1)(c)) to meet legal, tax and accounting duties. For patron information processed on a library's behalf, the library is responsible for the lawful basis. Under the Australian Privacy Act, we collect, use and disclose personal information consistently with the APPs and this policy.

7. When we disclose information, and our sub-processors

We do not sell personal information for money, and we do not share it for cross-context behavioural advertising. We share it only as needed to run the Service, with categories of recipients including: (By "sell" we mean giving personal information to a third party for money or other valuable consideration for that party’s own independent use; the disclosures described below are made to run the Service, not sales. Some analytics or single-sign-on technologies may be treated as a "sale" or "share" under some US State laws — see section 14.)

  • Cloud hosting and infrastructure providers (primary hosting in Amsterdam, Netherlands; cloud servers in other locations);
  • Payment processing — our third-party payment providers (merchant of record);
  • Analytics providers (see clause 10);
  • Email-delivery providers and error/crash-diagnostics providers;
  • Login/identity providers you choose to sign in with;
  • Providers and tools that help us operate customer support — including limited AI assistance used only to help draft replies to support messages, always under human review, and applied to support-message content rather than the bulk of customer or patron data;
  • Our support and development personnel, contractors and service providers, who may be located outside your country (including in countries without an EU/UK adequacy decision) and who access production data to develop and support the Service under confidentiality and data-protection terms (see clause 8);
  • Professional advisers, auditors and database administrators, bound by confidentiality;
  • Librarians and patrons within a library's own network, to the extent the library's configuration allows;
  • Authorities and other parties where we must to comply with law, protect rights and safety, or in a business transfer (such as the transfer of the Librarika business to Raynux Pty Ltd).

We use vetted sub-processors bound to protect the information. A current list of our sub-processors and the countries in which they operate is available on request at info@raynux.com; we keep it up to date so that ordinary changes do not require re-issuing this policy.

8. International data transfers and safeguards

Librarika is a global service, so personal information may be processed outside your country. In particular, primary hosting is in Amsterdam, Netherlands; back-up and content-delivery servers may be located in other countries; and our support and development contractors and service providers may access production data from various countries to operate and support the Service. Personal information may be processed in Australia, the Netherlands, the United Kingdom, the United States, Singapore and Bangladesh. The specific recipients and countries are identified in our Sub-processors list.

Some countries in which our recipients operate have not been recognised as providing an adequate level of data protection under the GDPR. Where we transfer personal information from the EEA or UK to a country without an adequacy decision, we put in place appropriate safeguards — the European Commission's Standard Contractual Clauses (2021), together with the UK International Data Transfer Addendum for UK data — plus, where needed, additional technical and organisational measures. Under the Australian Privacy Act (APP 8), we take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. Request more information at info@raynux.com. Where no APP 8.2 exception applies to an overseas recipient's country, Raynux remains accountable under section 16C for how that recipient handles personal information subject to the Australian Privacy Act; the reasonable steps we take are the APP-equivalent security and data-protection terms in our contracts and Data Processing Addenda with those recipients, in addition to the Standard Contractual Clauses for EU/UK data.

9. How long we keep information

  • Patron information is kept for as long as the library maintains the record; the library controls retention and deletion, and we act on its instructions and on account closure.
  • Account and billing records are kept for the life of the account and then as needed to meet legal, tax and accounting obligations (generally up to 7 years in Australia).
  • Support and technical/log data are kept for a reasonable period for security and troubleshooting, then deleted or de-identified.

When information is no longer needed, we delete or de-identify it, subject to back-ups overwritten in the ordinary course.

10. Cookies and analytics

We use cookies and similar technologies to run the site, remember preferences, keep you signed in and understand usage. Some are essential; others (such as analytics) are used with your consent where required. We use analytics and similar tools; the providers we use are identified in our sub-processor list. You can control cookies through your browser and, where we show a cookie banner, through your consent choices. Turning off some cookies may affect how the Service works.

11. Children's and student information

  • We do not knowingly collect personal information directly from children to create our own accounts. Account holders and administrators must be adults acting for a library.
  • Where a school or library uses Librarika for children, that institution is the controller and is responsible for obtaining any required parental or school consent and meeting laws that protect children's data. Children under 13 (or 16 in parts of the EU) should not use the Service without appropriate school or parental consent. Where children’s information is processed, we act in the best interests of the child, apply least-privilege access, and our overseas contractors and service providers access it only under the confidentiality, security and data-protection terms described in section 8.
  • For libraries and schools operating in the United States K–12 context, the institution is responsible for providing or obtaining any parental consent required under COPPA and for its obligations under FERPA; we act as a service provider and a “school official” with a legitimate educational interest, under the institution’s direction and control. For student personal information we do not use or disclose it for targeted advertising, do not sell it, and do not build a profile of a student except to further the school’s educational purposes; we use it only to provide and support the Service, delete or return it at the institution’s direction, and require our sub-processors and personnel to do the same, consistent with applicable student-data-protection laws. We will also comply with Australia’s forthcoming Children’s Online Privacy Code as it takes effect.
  • If you believe a child's information has been provided to us without proper authority, contact us and we will work with the relevant library to address it.

12. Marketing and your choices

We only send you electronic marketing where the law allows — with your consent, or, for existing customers about similar services, on the basis the Spam Act 2003 (Cth) permits. Every marketing message identifies us and includes an unsubscribe option, and we action unsubscribe requests within 5 business days. You can also opt out at any time by contacting info@raynux.com. Where the GDPR/UK GDPR applies, we follow their marketing and consent rules. Service and security messages (such as billing, outage and account alerts) are not marketing and may still be sent while you have an account.

13. Your privacy rights

Depending on where you are and our role, you may have rights to: access the personal information we hold about you; correct information that is inaccurate; and, under the GDPR/UK GDPR, erase, restrict or object to processing, request data portability, and withdraw consent.

How to exercise them. If you are a patron, contact your library first (it controls your record); we will assist as needed. Otherwise, contact info@raynux.com. We will verify your identity and respond within the time the law requires (generally 30 days). If you are a patron and your library cannot or does not help within 30 days, contact us at info@raynux.com and we will action your access or correction request directly, to the extent we hold your information.

Complaints. Please contact us first. You can also complain to a regulator: in Australia, the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au; in the EU, your local supervisory authority; in the UK, the Information Commissioner's Office (ICO) — ico.org.uk.

14. Your United States privacy rights

If you are a resident of a US State that has a consumer-privacy law (such as California), this section explains your rights for personal information where Raynux is the business or controller. If you are a library patron, contact your library first, as it controls your record.

We do not sell your personal information for money, and we do not share it for cross-context behavioural advertising. Some analytics or single-sign-on technologies could be treated as a "sale" or "share" under some State laws; you can opt out through the cookie and privacy controls on our website and by enabling a recognised browser opt-out signal such as Global Privacy Control (GPC), which we honour for the browser or device that sends it.

Subject to verification and legal exceptions, you may ask us to: tell you what personal information we hold about you and how we use and disclose it; give you a copy; correct information that is inaccurate; and delete your information. Where we handle sensitive personal information, you may ask us to limit its use to providing the Service. To make a request, contact info@raynux.com; you may use an authorised agent with proof of authority. We will not discriminate against you for exercising these rights, and we do not knowingly sell or share the personal information of anyone under 16.

California residents may also request the categories of personal information we collected, the sources, our purposes for collecting it, and the categories of third parties to whom we disclosed it, as described in sections 4, 5 and 7, and may appeal a decision by replying to it or contacting info@raynux.com. We keep each category of personal information for the periods described in section 9, and we aim to respond to your request within the time the applicable law requires (generally 45 days for US State requests).

15. How we protect information

We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS/SSL), access controls and authentication, role-based permissions, monitoring, and confidentiality obligations on staff and contractors. No system is completely secure, but we work to protect personal information and to detect and respond to incidents, including notifying affected people and regulators where the law requires (for example, under the Australian Notifiable Data Breaches scheme, the GDPR breach-notification rules, and applicable US State data-breach-notification laws).

16. Changes to this policy

We may update this policy from time to time. If we make a material change, we will give reasonable notice before it takes effect. The effective date above shows the current version.

17. Contact us

Raynux Pty Ltd, Level 29, 221 St Georges Terrace, Perth WA 6000, Australia — info@raynux.com / info@librarika.com.

We have appointed Euverify Ltd as our representative under Article 27 of the GDPR (EU) and the UK GDPR. EU representative: Euverify Ltd, Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork T23 AT2P, Ireland. UK representative: Euverify Ltd, 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom. Email: gdpr@euverify.com. EU/UK data subjects may also submit a request through the representative’s secure portal.