1. Introduction
Data Drift provides a hosted data platform for Australian businesses, together with data engineering and AI services. The platform is built on Snowflake. For each client we provision, configure and administer a dedicated Snowflake account into which the client’s data is loaded, modelled and analysed.
This Policy sets out the types of Personal Information we collect, how that information is used, stored and disclosed, and your rights in relation to it. It applies to:
- the website at datadrift.com.au;
- the client portal at datadrift.com.au/clients (the Portal);
- the Data Drift sign-in service at login.datadrift.com.au (the Login);
- the Platform, being the Snowflake accounts we provision and administer for Clients; and
- the Connections we establish so that a Client’s data can flow from its own systems into its Platform Account.
We handle Personal Information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth) and applicable state and territory health records laws. This Policy does not govern how third parties, including our Clients, handle information they collect independently.
2. Definitions
In this Policy:
- Data Drift, we, us and our mean A.D Schneider & J Schneider (ABN 24 373 363 757), a partnership trading as Data Drift (registered business name DATADRIFT), of Melbourne, Victoria.
- Authorised User means a person whom a Client has nominated, and we have invited, to use the Portal, the Login or the Client’s Platform Account.
- Client means an organisation that subscribes to the Platform or otherwise engages us to provide services.
- Client Data means data belonging to a Client that we host on the Platform or otherwise access, transfer or process in the course of an engagement, including data drawn from the Client’s mailboxes, practice or business management systems and other applications.
- Personal Information has the meaning given in the Privacy Act 1988 (Cth): information or an opinion about an identified individual, or an individual who is reasonably identifiable.
- Platform means the hosted data platform we provide, consisting of the Platform Accounts and the tools we operate around them.
- Platform Account means a Snowflake account that we provision, configure and administer for a single Client.
- Sensitive Information has the meaning given in the Privacy Act 1988 (Cth), and includes health information.
- Services means the website, the Portal, the Login, the Connections, the Platform and the work we perform for Clients.
- Snowflake means Snowflake Inc. and its affiliates, which operate the cloud data service on which the Platform is built.
3. Our role
We handle Personal Information in two capacities.
Information we hold for our own purposes. This includes the details you provide when you make an enquiry, and the account and access records we keep for Authorised Users. We determine how this information is handled, and this Policy applies to it in full.
Client Data we host and process for Clients. When a Client subscribes to the Platform, we load copies of data from the Client’s systems into the Client’s Platform Account and host, model and process it there on the Client’s instructions, for the purposes of the Client’s engagement with us. Client Data remains the Client’s. The Client is responsible for the collection of that data from the individuals concerned and for its own privacy obligations. If you are a patient, customer, employee or contact of one of our Clients, that Client’s own privacy policy governs how it collects and uses your information. Sections 5 to 11 of this Policy describe how we hold and protect Client Data while it is on the Platform.
Platform Accounts are provisioned within Data Drift’s Snowflake organisation under our agreement with Snowflake. Data Drift, not the Client, is Snowflake’s customer for those accounts. Snowflake processes Client Data on our behalf as a sub-processor, subject to Snowflake’s data processing and security terms. Clients do not have a direct relationship with Snowflake.
4. Information we collect
We limit the information we collect to what is reasonably necessary for the purposes described in this Policy.
4.1 Enquiries
The contact form on this website opens your own email application; it does not transmit anything to us directly. We receive what you choose to send, which is typically your name, work email address, organisation and the subject of your enquiry.
4.2 Authorised User accounts
Access to the Portal, the Login and the Platform is by invitation only. For each Authorised User we collect:
- your name, work email address and the Client you represent;
- the identifier and basic profile shared by your sign-in provider (Google or Microsoft) when you sign in: your name, your email address, whether that address is verified and, if you have one, your profile picture;
- your two-factor authentication settings, where the Portal requires them;
- sign-in records: the date and time, IP address, browser and outcome of each sign-in attempt; and
- the roles you hold in your Client’s Platform Account, and the requests made of you through the Portal and their status.
We never receive your Google or Microsoft password. To create your Platform login, we provide your name and email address to Snowflake, which records your sign-ins and activity within the Platform Account as part of operating the service.
4.3 Credentials submitted through the Portal
Some work requires a key or password for one of the Client’s systems, such as a practice management API key. A credential entered in the Portal is delivered directly into the secret store of the Client’s Platform Account, where the Platform uses it to collect data from that system. The Portal does not retain a copy, and the credential is not written to our logs; we record only that a delivery occurred, and when. Within the Platform Account the credential is never displayed, to Data Drift or to anyone else, and it can be used only by the integrations we configure for that purpose.
4.4 Mailbox Connections
Where a Client asks us to load email into its Platform Account, an Authorised User signs in with Microsoft or Google and approves read-only access to one agreed mailbox. Under that approval:
- Historical email. We read the messages in the mailbox for the agreed period, including senders, recipients, dates, subjects, message bodies and attachments, and transfer them into the Client’s Platform Account.
- Ongoing email. The Client may configure a rule in its own email system that sends a copy of the mailbox’s email to a mailbox operated by Data Drift. We transfer each copy into the Client’s Platform Account and then delete it from our mailbox. Copies are retained in our mailbox for no longer than three days.
- Access tokens. Microsoft or Google issues us a time-limited token to read the mailbox. The token is held in encrypted form by our hosting provider and is revoked when the transfer is complete.
Email frequently contains Personal Information about people other than the mailbox owner, and may contain Sensitive Information. See section 6.
4.5 Acting on your behalf within a Platform Account
For some work, an Authorised User may, through the Portal, authorise Data Drift’s systems to act on their behalf within the Client’s Platform Account, for example to load the mailbox history described in section 4.4. Snowflake issues us a time-limited token that operates only within the role assigned to that user for the task. Every action taken under the token is recorded in the Platform Account against that user’s name. The authorisation remains in place until the user or the Client revokes it, and in any case for no longer than 90 days.
4.6 Technical information and cookies
Our hosting provider records standard server logs: IP address, browser type, the pages requested and the time of each request. We use these logs to operate and secure the Services.
The Portal and the Login set only the cookies required to maintain your session and to protect sign-in forms. The public pages of this website set no cookies. We do not use analytics, advertising or tracking cookies anywhere on the Services.
5. Client Data on the Platform
- What we hold. Copies of data drawn from the Client’s systems, such as its practice management system, its mailboxes and its business applications, together with the models, reports and derived data we build from them, for the term of the Client’s subscription.
- Where. Each Platform Account is hosted in Snowflake’s Sydney, Australia region. Client Data on the Platform is not stored or replicated outside Australia.
- Isolation. Each Client has a dedicated Platform Account. Client Data is never combined with, or accessible from, another Client’s account.
- Who can access it. The Client’s Authorised Users, within the roles the Client has agreed. Data Drift personnel, as described in section 5.1. Snowflake, to the limited extent required to operate the service, to provide support we request and to review accounts for abuse or security issues under its terms; Snowflake may also collect usage information about the Platform Account and provide it to us.
- Not a system of record. The Platform holds copies of data whose primary records remain in the Client’s own systems. Clients remain responsible for maintaining those primary records and for any record-keeping obligations that apply to them.
5.1 Data Drift’s access to a Platform Account
While we build a Client’s Platform, we hold the administrative access needed to configure the account, connect the Client’s systems and load and model its data. Once the build is complete, that access is locked. It is unlocked only at the Client’s request, for the purpose and duration of the support or change the Client has asked for, and every action taken while it is unlocked is logged in the Platform Account, where the Client can review it. As the holder of the account we retain the ability to administer it, which we exercise without a request only where necessary to respond to a security incident, to protect the Services or other Clients, or to comply with the law, and in each such case we notify the Client.
6. Sensitive Information
Client systems and mailboxes may contain Sensitive Information, including health information about patients. We handle Sensitive Information only:
- on the Client’s instructions, for the purposes of the engagement;
- within Platform Accounts and supporting systems located in Australia, as described in section 5 and on our Sub-processors page; and
- with access restricted to the people performing the work, and to the minimum they require.
The Client is responsible for ensuring that it has a lawful basis to collect Sensitive Information and to disclose it to us, and for giving any notices the law requires to the individuals concerned.
7. How we use information
We use Personal Information to:
- provide the Platform and perform the work our Clients engage us to do;
- operate the Portal and the Login, and control who may access them and the Platform;
- secure our systems and our Clients’ data, and investigate suspected misuse;
- communicate with you about an enquiry or an engagement; and
- comply with our legal obligations.
We do not sell Personal Information. We do not use it for advertising or marketing, and we do not add you to marketing lists. We do not use Client Data, or any Personal Information within it, to develop, improve or train artificial intelligence or machine learning models.
8. Information received from Google and Microsoft
When you sign in with Google or Microsoft, or a Client connects a Google or Microsoft mailbox, we use the information those services provide only to deliver the feature that was approved.
Data Drift’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We apply the same standard to information received from Microsoft. In particular:
- mailbox data is used only to transfer it into the Platform Account of the Client that authorised the Connection;
- no one at Data Drift reads message content, except where the Client requests it for troubleshooting, where it is necessary for security, or where the law requires it;
- we do not use this data for advertising, and we do not sell it;
- we do not use it to develop, improve or train generalised artificial intelligence or machine learning models; and
- we do not transfer it to any other party, other than the service providers listed on our Sub-processors page where necessary to deliver the feature, or where the law requires it.
You may revoke our access at any time: for Google at myaccount.google.com/permissions; for Microsoft work accounts at myapps.microsoft.com; and for personal Microsoft accounts at account.live.com/consent/Manage. A Client’s administrator may also remove Data Drift’s access.
9. Disclosure and overseas recipients
We disclose Personal Information only:
- to the service providers that host and operate the Services, which are listed with their locations on our Sub-processors page, including Snowflake, which hosts the Platform;
- to the Client whose Client Data it is;
- where you have consented; or
- where the law requires or permits it.
Client Data on the Platform is hosted in Australia, and the Portal’s own database is also hosted in Sydney. Some of the providers that operate the website, the Portal and the Login are based in, or may access information from, countries outside Australia, principally the United States. Before disclosing Personal Information to an overseas recipient we take reasonable steps to ensure it will be handled in accordance with the Australian Privacy Principles, including by relying on the recipient’s contractual commitments and security certifications.
10. Security
We take reasonable steps to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our measures include the following:
- A dedicated Platform Account for each Client, hosted in Australia, with no data shared between Clients.
- Sign-in to the Platform, the Portal and the Login through the Data Drift login, using Google or Microsoft work accounts protected by multi-factor authentication. There is no password-only access to the Platform.
- Role-based access within each Platform Account, so that each Authorised User sees only what the Client has agreed.
- Network restrictions on each Platform Account, and monitoring of sign-ins, including alerts when a sign-in does not match the Client’s approved email domains.
- Encryption of all data in transit and at rest.
- Credentials and tokens scoped to a single task and revoked when the task ends.
- Administrative access by Data Drift personnel locked once a Client’s Platform is built, unlocked only at the Client’s request as described in section 5.1, performed with separate administrative identities and logged.
- Snowflake’s continuous data protection, which retains recoverable copies of Client Data for a limited period so that data can be restored after an error.
- The certified infrastructure of the providers listed on our Sub-processors page.
No method of transmission or storage is completely secure. If you believe your account or a credential has been compromised, contact us immediately at the address in section 17.
11. Retention
We retain Personal Information only for as long as it is needed for the purposes described in this Policy, or as the law requires.
| Information | Retained for |
|---|---|
| Client Data on the Platform | The term of the Client’s subscription. For 30 days after it ends the Client may export its data; we then delete the Platform Account, and residual copies held by Snowflake’s data-protection mechanisms are purged within a further 90 days. A Client may ask us to delete its data sooner. |
| Authorised User accounts and access records | The period of your involvement with a Client’s subscription, then 12 months |
| Sign-in records held by our login provider | Up to 30 days |
| Mailbox access tokens | Until the transfer is complete, then revoked |
| Copies of email in Data Drift mailboxes | Until transferred to the Client’s Platform Account, and no longer than three days |
| Enquiries | For as long as they remain relevant to a prospective or current engagement |
12. Access, correction and your choices
You may ask us to:
- provide access to the Personal Information we hold about you;
- correct information that is inaccurate, out of date or incomplete;
- close your Portal account and delete information we are not required to retain; or
- revoke a mailbox Connection or an authorisation to act on your behalf, as described in sections 4.4, 4.5 and 8.
Requests may be made to the Privacy Officer at the address in section 17. We will respond within 30 days. Where the information is Client Data, we will refer your request to the Client and assist it to respond.
13. Data breaches
If we become aware of a data breach that is likely to result in serious harm to any individual, we will notify the affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme. Where a breach involves Client Data, we will notify the Client as soon as practicable and coordinate with the Client so that the individuals concerned are notified once, and so that the Client can meet its own obligations.
14. Automated decision-making and AI
We do not make decisions about you using automated processing of your Personal Information. Where a Client asks us to enable AI features within its Platform Account, those features operate within Snowflake, are configured to run in Snowflake’s Australian region, and do not use Client Data to train models. The Client decides whether those features are enabled and how they are used.
15. Complaints
If you have a concern about how we have handled your Personal Information, contact the Privacy Officer at the address in section 17. We will acknowledge your complaint, investigate it and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner.
16. Changes to this Policy
We may update this Policy from time to time. We will post the updated version on this page and revise the date at the top. Where a change materially affects our Clients, we will notify them directly.
17. Contact
Privacy Officer
Data Drift
Melbourne, Victoria
info@datadrift.com.au