Client records, clinical photos, consents and recordings are encrypted, visible only to the people you authorise, logged every time they are opened, and yours to export at any time. ZibaDesk is built by an Australian company and your data is hosted in Australia.
Four layers between a client's record and anyone who should not see it.
Clinic data, including files and backups, is stored in Australian data centres that hold ISO 27001 and SOC 2 Type 2 certification. You always know which country your clients' health records are kept in.
Every connection uses TLS. Clinical photos, signed consents and session recordings live in a separate encrypted store with AES-256 encryption, apart from the operational database, with the keys held separately.
Each staff member signs in with their own identity and role. Opening a client record, changing health information, exporting a file or signing a note is written to the clinic's audit log with who, what and when.
Encrypted backups run nightly with an off-site copy. You can export clients, appointments, sales and clinical records at any time, download a complete record pack per client, and have your data deleted when you leave.
Controls that clinic owners, practice managers and supervising practitioners ask about first.
Every clinic's data is isolated in its own schema. No shared tables, no cross-clinic queries, and a client of one business can never appear in another.
Reports show every view and change of a client record with the user, role, time and the fields touched. Suspicious activity is visible without asking us.
A departing staff member can be suspended and signed out of every device in one action. Front-desk tablets and phones stop working for them immediately.
E-signed consents and pre-visit forms are stored as timestamped records with the signature image, the acknowledgements initialled and the form version, and attach to the client's record pack.
Online deposits and card on file are handled by Stripe; in-clinic terminals by Tyro. ZibaDesk stores references, never card numbers, so PCI scope stays with the payment provider.
The optional AI Assist transcribes recordings on infrastructure we run in Australia, deletes the audio, and only sends a transcript with names and contact details removed to the drafting model. Client data is never used to train models.
ConfigIT Pty Ltd, the Australian company behind ZibaDesk, is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Health information is treated as sensitive information, and the Notifiable Data Breaches scheme applies: affected clinics are told without undue delay.
Your clinic is the custodian of its client records. ZibaDesk uses them only to provide the service: no selling, no advertising use, no analytics on identifiable health information, and no training of AI models.
SMS delivery, transactional email, Stripe and Tyro for payments, and Meta for WhatsApp messages each receive only what that channel needs. A current list is available on request and in your data processing schedule.
Export everything yourself at any time as CSV and JSON, consent forms as PDF and photos as image files. After termination you keep retrieval access for 90 days, then the data is deleted from production and backups on their normal cycle.