Data security · Patient privacy

Your clients' health information, encrypted and under your control.

Client records, clinical photos, consents and recordings are encrypted, visible only to the people you authorise, logged every time they are opened, and yours to export at any time. ZibaDesk is built by an Australian company and your data is hosted in Australia.

Start Free Trial Talk to Sales

How it works

Four layers between a client's record and anyone who should not see it.

1

Hosted in Australia

Clinic data, including files and backups, is stored in Australian data centres that hold ISO 27001 and SOC 2 Type 2 certification. You always know which country your clients' health records are kept in.

2

Encrypted in transit and at rest

Every connection uses TLS. Clinical photos, signed consents and session recordings live in a separate encrypted store with AES-256 encryption, apart from the operational database, with the keys held separately.

3

Access by role, logged every time

Each staff member signs in with their own identity and role. Opening a client record, changing health information, exporting a file or signing a note is written to the clinic's audit log with who, what and when.

4

Backed up, portable, deletable

Encrypted backups run nightly with an off-site copy. You can export clients, appointments, sales and clinical records at any time, download a complete record pack per client, and have your data deleted when you leave.

What you get

Controls that clinic owners, practice managers and supervising practitioners ask about first.

One business, one database schema

Every clinic's data is isolated in its own schema. No shared tables, no cross-clinic queries, and a client of one business can never appear in another.

Audit log you can read

Reports show every view and change of a client record with the user, role, time and the fields touched. Suspicious activity is visible without asking us.

Suspend a user, end their sessions

A departing staff member can be suspended and signed out of every device in one action. Front-desk tablets and phones stop working for them immediately.

Consent that holds up

E-signed consents and pre-visit forms are stored as timestamped records with the signature image, the acknowledgements initialled and the form version, and attach to the client's record pack.

Card data never touches us

Online deposits and card on file are handled by Stripe; in-clinic terminals by Tyro. ZibaDesk stores references, never card numbers, so PCI scope stays with the payment provider.

AI without exposing clients

The optional AI Assist transcribes recordings on infrastructure we run in Australia, deletes the audio, and only sends a transcript with names and contact details removed to the drafting model. Client data is never used to train models.

Built for these businesses

Privacy commitments

Australian law applies

ConfigIT Pty Ltd, the Australian company behind ZibaDesk, is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Health information is treated as sensitive information, and the Notifiable Data Breaches scheme applies: affected clinics are told without undue delay.

You own the data, we process it

Your clinic is the custodian of its client records. ZibaDesk uses them only to provide the service: no selling, no advertising use, no analytics on identifiable health information, and no training of AI models.

Sub-processors, named

SMS delivery, transactional email, Stripe and Tyro for payments, and Meta for WhatsApp messages each receive only what that channel needs. A current list is available on request and in your data processing schedule.

Leaving is straightforward

Export everything yourself at any time as CSV and JSON, consent forms as PDF and photos as image files. After termination you keep retrieval access for 90 days, then the data is deleted from production and backups on their normal cycle.

Frequently asked

Where is my clinic's data stored?
In Australia, in ISO 27001 and SOC 2 Type 2 certified data centres, including files, clinical photos and backups. Support staff work in Australia and access is logged.
Who can see a client's health record?
Only users of your clinic with a role that allows it. Clinical records, photos and consents are for Admin and Manager roles by default, staff see what they need for their day, and every view is written to the audit log.
Is ZibaDesk HIPAA compliant?
HIPAA is United States law and applies to US healthcare providers. ZibaDesk is operated by an Australian company and is designed around the Australian Privacy Act 1988 and the Australian Privacy Principles, which are the obligations our Australian clinics actually carry. If your clinic is outside Australia, check which privacy law applies to you.
How are before and after photos protected?
Photos are uploaded straight into an encrypted clinical store, stripped of camera metadata, encrypted with AES-256 and served only to signed-in users of your clinic through short-lived links. They are never on the public booking site.
Do you keep card numbers?
No. Card payments are processed by Stripe online and by Tyro terminals in the clinic. ZibaDesk keeps payment references and results, not card details.
Can we get our data out?
Yes, at any time and without asking us: clients, appointments, sales and clinical records as CSV and JSON, consents as PDF, photos as files, and a complete record pack per client. Nothing is locked in.

See also

Run your clinic on software that treats health records like health records.

Try ZibaDesk free with your own data, or ask us for the security overview and data processing schedule before you migrate.

Start Free Trial