Intelligent RosterIntelligent Roster®

Privacy, standards, and clear data boundaries

We build and operate Intelligent Roster with the expectations of health services in mind, and with a clear boundary: workforce data only, no patient data.

Relevant frameworks and posture

FrameworkScopeProduct posture
Privacy Act 1988 (Cth)Australian organisations handling personal informationDesigned with these obligations in mind
Australian Privacy Principles (APPs)All 13 principlesMapped to product and operational controls
Notifiable Data Breaches (NDB) SchemeEligible data breachesProcedures in place
GDPREU-based staffSupported where applicable
SOC 2 Type IIInfrastructure securityInherited — Render & AWS
ISO/IEC 27001:2022Information security managementInherited — Render & AWS

What We Handle — and What We Don't

In Scope — Workforce Data

  • Staff names and contact details
  • Employment and role data
  • Schedules, shifts, and leave
  • Qualifications and skills
  • Availability preferences

Out of Scope — We Don't Store or Process

  • Patient identifiers, MRN, date of birth
  • Clinical notes, diagnoses, treatments
  • Health records or My Health Record data
  • Payment card data or Medicare numbers
  • Any other health information as defined by legislation

Need More Detail?

See our Privacy Policy, Trust Centre, and Data Residency pages — or contact us for procurement and assurance discussions.

See how an ED-first roster platform works.

From emergency departments to whole health services — and the ED-like teams beyond them.

Or email us at [email protected]