KINNECT — Creating Health Certainty at Work
Menu
Privacy & Data Security

Consent & Privacy

Here you can find further information consent, the personal information we collect, what we do with it and how we keep it safe and secure.

Pre-Employment Assessments Health Surveillance AssessmentsFAQ about Consent Data Privacy & Security

Quick answers

Most visitors want answers to the same handful of questions. Here they are, in plain English.

  • Your employer never sees your raw health data — only our clinical opinion on whether you can do the job safely.
  • Australian law requires us to keep medical records for 30+ years, so deletion on request isn't possible.
  • Your records are stored on AWS servers in Sydney, protected by ISO 27001 controls and high-grade encryption.
  • Access is limited to KINNECT staff who need it, secured with two-factor authentication and 24/7 monitoring.
  • We only use de-identified, anonymous data for trend analysis — never your personal information without explicit consent.
ISO 27001
Certified
AWS Sydney
Australian hosting
High-grade
Encryption at rest
24/7
Real-time monitoring
2FA
Two-factor access
30+ years
Secure retention
01Information

Why we collect & use your information

What we collect, why it's needed for a safe-to-work assessment, and what we do with the de-identified data afterwards.

Why we collect information

We need to collect your health information in order to assess the risk of you being able to perform a job role safely and provide a report to your prospective employer. It’s important for you to know that your prospective employer is not purchasing your health data, they are purchasing our interpretation of your health information, as far as it relates to your ability to work safely.

Specific Information we collect

We will collect information to confirm your identity (including your name, DOB and contact details) to confirm that it’s really you. Your health information (height, weight, medical history) and the results of tests (blood pressure, urinalysis) will be recorded. We will also collect general/lifestyle information (smoking, alcohol units etc) that is necessary for the accurate interpretation of your specific health information.

Using your de-identified health information

Because we collect your information in a digital format, we can pool the data and use it to analyse trends, improve our health assessments, and to give better advice to our clients to improve the health and safety of Australian workplaces. We only do this with de-identified (anonymous) data – never with your personal information. We will never share or use your personal data for other research purposes without expressing asking for your explicit consent to participate.

What happens if I don’t consent?

Choosing whether or not to give your consent is your choice. If you don’t consent, please note that we cannot provide a report to your prospective employer. There may be consequences to you not going ahead with your assessment which you’ll need to discuss with them.

02Sharing

Sharing & storing your information

What we share with your employer, what stays private, and how long Australian law requires us to keep your records.

Sharing your personal information

We will not share your private health information with your employer. We will only share the outcome of your health assessment with your employer/prospective employer, that is our clinical opinion on the health risks and your ability to work safely in the short term. This information will only be shared with specific people within that organisation. It will not be shared with anyone else.

Storing your personal information

Under the privacy act, health records in Australia must be stored for 30+ years. We take your personal health information very seriously and you can find out more about how we keep you information safe here.

03Security

How we keep your data secure

The certifications, infrastructure and controls that protect your health information at every step.

High grade encryption

Our servers are military-grade servers, provided by Amazon Web Services, located in Sydney. We implement AWS security capabilities to increase privacy and control network access so that all our customer information is protected. In addition, we have an additional level of expertise from an expert cyber security partner that specifically focus on the security of our network and data integrity.

Protecting your data

We are bound by our ISO 27001 certification to ensure that our customer information systems are designed with strong safeguards in place to help protect customer privacy and data. For instance, we use high-grade encryption to keep your information safe with the most sensitive information kept on separate servers. We also conduct regular penetration testing to identify areas for improvement.

Secure & limited access

We implement AWS security capabilities combined with two-factor authentication to increase privacy and control network access so that your information is protected. Access is limited internally to the staff who need to access it. No one can access our systems outside of KINNECT offices without our explicit permission. Partner (for instance our Affiliate) access to KINNECT systems is limited to inputting data, not reviewing or editing.

24/7 real time monitoring

We are proactive with efforts to keep your information safe and employ real time monitoring with an AWS Security Partner, that actively search for suspicious activity or weaknesses 24/7. We reduce the risk of security breaches occurring by spotting issues and resolving problems before they impact our business and your information.

04Further information

Get in touch or browse our consent form FAQ for plain-English answers.

Further information about consent

Unlike requesting a shop delete your customer records, health data is different. By law, KINNECT must keep medical records for 30+ years.

Our consent form

We know our consent form is full of legal terminology. If you’ve got a particular question about our form, you might find the answer here.

Ready to get started?

Talk to our team about how we can help.