Privacy, standards, and clear data boundaries
We build and operate Intelligent Roster with the expectations of health services in mind, and with a clear boundary: workforce data only, no patient data.
Relevant frameworks and posture
| Framework | Scope | Product posture |
|---|---|---|
| Privacy Act 1988 (Cth) | Australian organisations handling personal information | Designed with these obligations in mind |
| Australian Privacy Principles (APPs) | All 13 principles | Mapped to product and operational controls |
| Notifiable Data Breaches (NDB) Scheme | Eligible data breaches | Procedures in place |
| GDPR | EU-based staff | Supported where applicable |
| SOC 2 Type II | Infrastructure security | Inherited — Render & AWS |
| ISO/IEC 27001:2022 | Information security management | Inherited — Render & AWS |
What We Handle — and What We Don't
In Scope — Workforce Data
- • Staff names and contact details
- • Employment and role data
- • Schedules, shifts, and leave
- • Qualifications and skills
- • Availability preferences
Out of Scope — We Don't Store or Process
- • Patient identifiers, MRN, date of birth
- • Clinical notes, diagnoses, treatments
- • Health records or My Health Record data
- • Payment card data or Medicare numbers
- • Any other health information as defined by legislation
Need More Detail?
See our Privacy Policy, Trust Centre, and Data Residency pages — or contact us for procurement and assurance discussions.
See how an ED-first roster platform works.
From emergency departments to whole health services — and the ED-like teams beyond them.