GDPR Statement
This is a statement on the alignment of the LinXmart software with the European Union’s General Data Protection Regulation (GDPR).
Protection of personal information
The LinXmart software has been developed by LinXmart Co (ABN 27 678 379 498) in Western Australia. Our company is not bound by the Australian Privacy Act 1988 nor by the Australian Privacy Principles; however, we choose to protect personal data in accordance with these principles. For details, please consult our Privacy Policy.
Data Protection by Design
Built-In Data Protection
The protection of personal data is an essential element of the LinXmart software. Core features enable data protection through restricting the amount of personal data collected by the software, the extent of processing, the period of storage and data accessibility. Key data protection features include:
- Data minimisation: Only a limited set of fields are used in the linkage process. These fields are stipulated at the commencement (definition stage) of each project, with the result that only certain fields are loaded into the linkage event tables. All other fields are kept separate from linkage fields (loaded into separate auxiliary tables).
- Storage safeguards: Each linkage project is separately defined by the software and the data for each project is stored is separate, project-specific tables.
- Data accessibility: Each project has role-specific permissions which restrict the amount of data that software users can see/access (depending on role). Project owners (only) authorise access to project data. Only persons who have been granted appropriate access by the project owner are able to view data for that project. Different types of access exist – some having read-only access on selected tables; others have greater privileges over project data, depending on project-role.
- Auditing: Project roles and permissions are recorded by the software. Audit logs of changes are maintained.
- Data processing controls: Any changes to data are recorded by the software. This includes record deletions or updates, and linkage-related data changes. Audit logs are maintained throughout.
- Data storage and processing controls: Requests by data custodians (data providers) to delete and/or remove data from the system are handled by the software. Audit logs of this activity are also maintained.
- Data extraction processes are fully controlled. Data extractions are fully specified and can only be undertaken by an authorised operator. Audit logs record what data is extracted from project tables.
Data Protection through Licensing Agreements
Evaluation licence for LinXmart software
Organisations or individuals who wish to evaluate the LinXmart software must enter into a limited-scope evaluation license agreement with LinXmart Co. Following execution of that agreement, the organisation or individual are provided with a copy of the software which they install and run within their own IT environment.
LinXmart Co does not operate a Software-as-a-Service solution for the evaluation of LinXmart.
The organisation or individual who is licenced to evaluate LinXmart will be entirely responsible for the ‘data processor’ and ‘data controller’ functions, as set out in the GDPR. LinXmart Co staff do not perform any role as either data processor or data controller.
LinXmart Co may offer technical support for the LinXmart software; however, at no time will any member of LinXmart Co have access to, or be granted access to, personal data stored in the LinXmart system provided under licence to any organisation or individual.
Full licence for LinXmart software
Organisations or individuals who wish to license and use the LinXmart software must enter into a license agreement with LinXmart Co. Following execution of that agreement, the organisation or individual are provided with a copy of the software which they install and run within their own IT environment.
LinXmart Co does not operate a Software-as-a-Service solution for the LinXmart software.
The organisation or individual who is licenced to use LinXmart will be entirely responsible for the ‘data processor’ and ‘data controller’ functions, as set out in the GDPR. LinXmart Co staff do not perform any role as either data processor or data controller.
LinXmart Co may offer technical support for the LinXmart software; however, at no time will any member of LinXmart Co have access to, or be granted access to, personal data stored in the LinXmart system provided under licence to any organisation or individual.
Contact Us
If you have questions or comments about this Statement, please contact us at: info@linxmart.com.au