Data processing agreement
The terms on which we handle the personal information your laboratory collects. This is the document a hospital, a government contractor or a large customer asks for.
1. Which of us is responsible for what
You are the entity that collects the personal information in your account and decides what is done with it. Under the Privacy Act you are accountable for it, and in the language of the GDPR — which some of your customers will use — you are the controller.
We handle it only to provide the service to you, on your instructions. We are the processor. We do not decide what is collected, why, or how long it is kept, except where the law requires us to.
This agreement forms part of the subscription agreement. Where they conflict on the handling of personal information, this one prevails.
2. What we process, and for how long
For as long as your account exists, plus the post-termination period in the subscription agreement:
- Subject matter: providing a calibration laboratory management system.
- Nature and purpose: storing, displaying, computing on and transmitting records so that your laboratory can operate and can evidence its quality system.
- Categories of data subject: your staff; the contacts at your customers; anyone whose name appears on a record — a person who delivered an instrument, a person who signed a certificate.
- Types of personal information: names, business email addresses and phone numbers, business and delivery addresses, job titles, competence and training records, sign-in and activity records.
- Special categories: none are required by the system, and none should be put into it. See clause 2a.
2a. Sensitive information — do not put it here
The Privacy Act treats some information as sensitive: health and medical information, biometrics, racial or ethnic origin, political or religious beliefs, sexual orientation, criminal record, union membership. Collecting any of it generally requires the individual’s consent, and a higher standard of care afterwards.
The system does not need any of it and provides no field for it. Do not enter it. The obvious way it arrives by accident is a note about a person rather than about an instrument — “off with a back injury”, “on restricted duties” — typed into a resourcing or competence note. That is health information about your employee, and typing it into a free-text box does not make it anything else.
If you enter sensitive information despite this, you warrant that you obtained the individual’s express consent first and that you are entitled to disclose it to us, and you indemnify us against any claim arising from it. We have no way to detect it and no basis on which to have consented to it on anybody’s behalf.
One case is deliberately not sensitive information about a person: a laboratory servicing medical devices records the *device*, its owner and its readings. An infusion pump’s serial number is not a patient’s health record, and nothing here prevents that work.
3. Our obligations
We will:
- process personal information only on your documented instructions, which include your use of the service and its settings, unless the law requires otherwise — and if it does, tell you before we act unless we are prohibited from telling you
- ensure the people who handle it are bound by confidentiality
- implement and maintain the security measures described in clause 5
- assist you in responding to requests from individuals for access or correction, using the tools in the application where they exist
- assist you in meeting your own breach notification obligations, as described in clause 6
- make available the information you reasonably need to satisfy yourself that we are complying, and to answer your own customers’ due diligence
- on termination, keep your data available for export for the period in the subscription agreement and then delete it, unless the law requires us to retain it
4. Sub-processors
You authorise us to engage the sub-processors listed below. Each is bound to obligations no less protective than these.
We will give you at least 30 days’ notice before adding or replacing one. In an emergency — a provider failing completely, or suffering a critical security breach — we may replace them immediately to keep the service running and secure, and will tell you as soon as possible.
If you reasonably object to a new sub-processor on legitimate data-protection grounds, tell us within the notice period. We will work with you in good faith to find a way forward. If we cannot resolve your concern, your sole remedy is to cancel your subscription. If you cancel for this reason we will refund any prepaid fees for the remainder of your billing period, and you can export your records.
- Supabase — Database, file storage and sign-in. Sees: Every record in the system — customers, contacts, instruments, readings, certificates, invoices — and the stored PDFs. Located: Sydney, Australia (ap-southeast-2). Supabase Inc is incorporated in the United States.
- Hostinger — Runs the application itself. Sees: Reads records into memory to render pages, certificates and invoices. It does not store or log them to disk, but it can see them in memory. Located: Asia. Hostinger has no Australian data centre; its Sydney presence is a cache for static files.
- The email provider (SMTP) — Delivers recall notices, certificates, quotes and invoices. Sees: Recipient name and address, the subject line, and the message — which for a certificate or invoice includes the customer’s name and the instrument concerned. Located: Depends on the provider configured. Brevo, the first, processes in the European Union.
- Stripe — Takes the laboratory’s subscription payment, and card payments from its customers. Sees: Billing name, email and card details. Card numbers never reach this system — they are entered on Stripe’s own hosted page. Located: United States and Australia.
- Amazon Bedrock — Reads a customer’s written list of instruments into intake lines a person then confirms. Sees: Only the text somebody pastes into the intake screen — typically an instrument list, which may carry a contact name if the customer signed their email. It is sent, read, and answered. No record, reading, certificate or price is sent, and none can be: the extraction is structurally incapable of carrying one (ADR 0018). Located: Sydney, Australia (ap-southeast-2), pinned to the region rather than a cross-region profile. Not yet connected.
5. Security
The measures we maintain:
- Encryption in transit and at rest.
- Tenant isolation enforced by the database rather than by application code, so an application fault cannot expose one laboratory’s records to another. Tested by a script that provisions a second laboratory and asks it for the first’s data.
- Role-based access, evaluated by the database on every statement as a lookup rather than from a token, so revoking access takes effect immediately rather than when a session expires.
- An append-only audit trail of every change, which no user or administrator can edit or delete, with bank details and secrets recorded as changed without recording the value.
- Private file storage with short-lived signed links; certificates held where they cannot be altered or deleted, with a hash checked on every download.
- Backups, and a documented restore procedure that is rehearsed rather than assumed.
6. If there is a breach
We will notify you without undue delay and in any event within 72 hours of becoming aware of a breach affecting your data, with what we know: what happened, what data and how many people are affected so far as we can tell, what we are doing, and who to speak to.
We will not notify your customers on your behalf unless you ask us to in writing. You are the entity they have a relationship with, and a notification from a name they do not recognise is worse than none.
7. Overseas handling
Personal information is disclosed to recipients outside Australia, as identified in clause 4 and in our privacy policy. Where personal information is transferred to a country without comparable protection, we remain accountable for it under APP 8 and take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
Where you require your data to be processed only within Australia, tell us. It is a deployment matter rather than a change to the software, and it is one of the triggers for moving the application to Australian hosting.
8. Audit
On reasonable notice, and not more than once a year unless a breach or a regulator gives cause, you may ask us to demonstrate compliance with this agreement. We will answer a security questionnaire and provide the evidence we hold.
You may also examine your own records at any time without asking us — the audit trail is readable in the application, and everything exports.
9. Getting your data back, and deletion
You can export everything at any time from within the application, in full, whatever the state of your subscription. That is a property of the software rather than a promise in this document.
After termination we keep your data available for export for the period stated in the subscription agreement, then delete it, unless the law requires us to keep it or a legal hold applies. We will confirm deletion in writing if you ask.