Legal
Data security
How your information is stored and protected
Draft for legal reviewThese statements have been prepared to reflect Artia's actual practice and the obligations that apply to it. They are a working draft and must be reviewed by a solicitor before publication. Nothing here is legal advice.
Our obligation
Australian Privacy Principle 11 requires us to take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification or disclosure. Reasonable steps must include both technical and organisational measures. Health information attracts the highest level of protection.
Storage
- All data is hosted in Australia. Health information is not transferred or stored offshore.
- Data is encrypted in transit and encrypted at rest.
- Backups are encrypted, tested, and held under the same controls as production data.
Access controls
- Access is role based and enforced at the data layer, not only in the interface. A club account is technically incapable of retrieving another organisation's data, or any athlete's individual responses.
- Multi factor authentication is required for all clinical and club staff accounts.
- Every access to clinical information is written to an audit log recording who accessed what, and when. Audit logs are retained and reviewable.
- Accounts are created by invitation. Access is removed promptly when a person leaves a club or the clinical team.
Organisational measures
- Every clinician is registered with AHPRA, holds current professional indemnity insurance, and is bound by confidentiality obligations under contract and under the Health Practitioner Regulation National Law.
- Staff and contractors receive privacy and data handling training, and access only the minimum information needed to do their work.
- We hold a documented data breach response plan, tested and reviewed.
- Third party service providers, such as our hosting provider, are bound by written agreements requiring equivalent protection.
Data separation between organisations
Complete isolation between client organisations is a technical and contractual requirement. No club can see, infer, or derive anything from another club's data. Benchmarks shown in reports compare a squad only against published research, never against another client.
Reporting a security concern
If you believe your information may have been compromised, or you have found a vulnerability, please contact [email protected] immediately.