Your biology is the most personal data you own. Protecting it is engineered into everything we build.
Health data is encrypted in transit (TLS 1.3) and at rest (AES-256) at all times.
Access, correct, export or delete your data, and revoke consents, whenever you choose.
Annual third-party penetration testing and continuous vulnerability monitoring.
HodieLabs is built around a simple principle: the interface should recede, and your biology should be the only thing that matters, including who can see it. We apply a defence-in-depth approach, layering controls so that no single safeguard is a single point of failure. Security and privacy are considered at the design stage of every feature, not bolted on afterwards.
This page explains, in plain language, the measures we use to protect your information. It complements our Privacy Policy, which sets out our legal obligations and your rights in full.
We host data with reputable cloud infrastructure providers that maintain internationally recognised security certifications (such as ISO/IEC 27001 and SOC 2). Wherever practicable, Australian user data is stored within Australia. Where any processing occurs outside Australia, we ensure comparable protections are in place, in accordance with Australian Privacy Principle 8. We never transfer My Health Record data overseas.
Our environments are segmented, with production data separated from development and testing environments. Test and development environments never use real, identifiable health data.
Genetic information and My Health Record data warrant the highest level of care. These categories are collected only with your explicit, specific consent; are accessed only for the permitted purposes described in our Privacy Policy; and are subject to the same encryption, access control, and audit safeguards described above. We will never use this data for advertising, insurance underwriting, employment decisions, or any purpose you have not authorised.
Technology alone does not keep data safe. All HodieLabs employees and contractors are bound by confidentiality obligations, undergo background checks appropriate to their role, and complete mandatory privacy and security training at onboarding and annually thereafter. Access to sensitive data is granted on a need-to-know basis and revoked promptly when no longer required.
Laboratories, imaging providers, payment processors, and infrastructure vendors are carefully vetted and bound by contractual data processing agreements. These agreements restrict use of your data to providing services to HodieLabs, prohibit unauthorised onward disclosure, require prompt breach notification, and mandate secure deletion or return of data on termination. Payment card data is handled exclusively by PCI-DSS compliant providers. We never store full card numbers.
We maintain a documented incident response plan and a dedicated response team. In the event of a data breach that is likely to result in serious harm, we will act in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act, containing the incident, assessing its impact, and notifying affected individuals and the Office of the Australian Information Commissioner as required by law. Where the My Health Record system is involved, we will also notify the Australian Digital Health Agency.
We keep your data only as long as necessary for the purpose it was collected or as required by law, and then securely delete it in a manner designed to prevent recovery. Detailed retention periods for each data category, including health records, genomic data, and My Health Record data, are set out in our Privacy Policy. You may request deletion of your data at any time, subject to our legal retention obligations, and we can provide written confirmation once complete.
We welcome responsible disclosure from the security community. If you believe you have found a security vulnerability in our platform, please email us at security@hodielabs.com with details so we can investigate. Please act in good faith, avoid accessing or modifying other users' data, and give us a reasonable opportunity to remediate before any public disclosure.