You are on CAQA WHS
CAQA WHS - Part of CAQA GroupsCall 1800 266 160  |  info@caqa.com.au
Home / Data Processing and Security Notice

Data Processing and Security Notice

How CAQA WHS processes, secures, backs up and returns the safety data client organisations enter into the platform.

This Data Processing and Security Notice explains how CAQA WHS, part of CAQA Groups and Career Calling International Pty Ltd (ABN 53 162 651 238), handles the data that client organisations and their users enter into the CAQA WHS platform, and the security practices that apply to this website and the platform. It should be read together with our Privacy Policy, which covers personal information collected through this website, and our WHS Platform Terms.

1. The data we process on your behalf

When your organisation subscribes to CAQA WHS, your users enter safety records into the platform. Depending on your configuration this may include incident and near-miss reports, injury details, hazard and risk register entries, induction and training records, inspection and checklist results, corrective actions, and contractor, chemical and asset registers. These records frequently contain personal information about workers, contractors, visitors and other people - names, roles, contact details and, in the case of incident records, information about injuries or health.

2. Roles and responsibilities

Client platform records remain the records of the client organisation. Your organisation decides what is collected, is responsible for collecting it lawfully and fairly, for telling workers how their information will be used, for keeping records accurate, and for meeting its own obligations under the Privacy Act 1988 (Cth), applicable health records legislation and WHS legislation. CAQA processes this data on your organisation's behalf to provide, support and maintain the platform, and does not use client platform records for any other purpose.

3. Data collected through this website

This public website collects only the information you submit through the contact form, demonstration requests and newsletter subscription, plus standard analytics data such as pages visited, browser type and approximate location. No payments are taken through this website, so no payment card details are collected or stored by this site.

4. Hosting and storage

Platform environments are hosted with reputable cloud infrastructure providers, with client data logically separated per organisation. Details of hosting regions and any offshore support access applicable to your subscription are set out in, or available on request under, your subscription agreement.

5. Access controls

Access to client platform data is restricted to the client's own authorised users and to the limited CAQA personnel who need access to provide support, maintenance or implementation services. Administrative access is role-based, individually accountable and reviewed. Client administrators control user roles and permissions within their own environment and should revoke access promptly when people leave.

6. Backups and continuity

Platform data is backed up on a scheduled basis to support recovery from failure or corruption. Backups are retained on a rolling cycle and are protected with the same care as live data. Backup and recovery objectives applicable to your organisation are described in your subscription agreement.

7. Security incidents and data breach reporting

We maintain procedures for identifying, containing and assessing security incidents. If a data breach involving your organisation's platform data is likely to result in serious harm, we will notify your nominated administrator without undue delay and provide the information your organisation reasonably needs to meet its own obligations, including any obligations under the Notifiable Data Breaches scheme. Clients should report suspected security issues to us immediately using the contact details below.

8. Retention, return and deletion

Client platform data is retained for the duration of the subscription. When a subscription ends, your organisation may export its records during the wind-down period described in the subscription agreement, after which data is deleted or de-identified from production systems and expires from backup cycles in the ordinary course. Website enquiry records are retained only as long as needed for the purposes described in our Privacy Policy.

9. Your organisation's configuration choices

Some security-relevant settings are configurable by client administrators, such as user roles, permissions and notification rules. Your organisation is responsible for the choices it makes in configuration and for the accuracy of the data its users enter.

10. Contact

Questions about this notice, requests for security documentation, or reports of suspected incidents can be sent to info@caqa.com.au, raised by phone on 1800 266 160, or submitted through our contact page.

Newsletter Subscription

To Receive Updates And Offers