Apico Privacy & Security

NZ Health Compliance • Last Updated: April 2026

Return to App

Your Data. Your Clinic. Fully Protected.

Apico Systems operates as a service provider under the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020. Your clinic remains the agency in full control of all data it generates on this platform. We do not sell, trade, or rent user data to any third party — ever.

Legal Framework

NZ Privacy Act 2020

Apico Systems complies fully with the New Zealand Privacy Act 2020, which governs how personal information must be collected, stored, used, and disclosed. Staff members retain the right at all times to access and correct their personal information held on the platform.

Health Information Privacy Code 2020

Under the HIPC 2020, Apico's architecture is explicitly isolated from Patient Health Information (PHI). We do not ingest, store, or transmit patient dental records or personal health data. Compliance tracking is strictly limited to equipment, staff credentials, and operational logs.

Agency vs. Service Provider

In the context of both Acts, your clinic is the "agency" — the entity that controls the purpose and use of the data. Apico Systems Ltd is the "service provider" — processing data only on your behalf, under your instruction. This means your clinic retains full data rights, including the right to export or delete records at any time.

Data We Collect

What We Do Collect

  • Clinic staff names and contact email addresses
  • Hardware equipment logs, serial numbers, and service intervals
  • Maintenance timestamps, water test results, and fault reports
  • Staff training logs and compliance certifications
  • Hashed (non-reversible) account passwords — never stored in plain text

What We Never Collect

  • Patient names, NHI numbers, or any personal health records
  • Financial or billing information
  • Clinical treatment notes or dental histories
  • Health Insurance or ACC details

We do not sell, trade, or rent any user data to third parties under any circumstances.

Security Architecture

Encryption In Transit

TLS 1.2+ / SSL

All data transmitted between your clinic's browser and our servers is protected by TLS 1.2+ (SSL encryption). This ensures that every login, data entry, and report generation is invisible to any third-party network observer — the same standard used by online banking.

Encryption At Rest

AES-256 — Bank-Grade

All database records and backups are protected by AES-256 encryption — the same standard used by banks and defence organisations worldwide. Your data is unreadable without the authorised decryption keys, even in the event of a physical hardware breach.

Infrastructure

Tier 4 Data Centres

Apico is hosted on Render / AWS infrastructure, operating within Tier 4 high-security data centres with 24/7 physical monitoring, biometric access controls, and redundant power systems. Tier 4 represents the highest classification in data centre security.

Automated Backups

Daily • 7-Day Retention

We perform automated daily backups of all clinic data with a 7-day rolling retention period. In the event of a system failure or data loss incident, your compliance records can be restored to any point within the retention window.

Role-Based Access Control (RBAC)

Access to data is strictly regulated by a hardcoded three-tier RBAC system: Admin → Manager → Staff. Staff accounts are prevented at the architecture level from viewing or modifying master configurations, other users' data, or administrative settings such as billing and user management. All account passwords are stored as one-way Bcrypt hashes — never in readable plain text — and all sessions are authenticated via short-lived, cryptographically signed JWT tokens.

Data Sovereignty & Your Rights

The subscribing clinic owns 100% of its data unconditionally. Administrators have perpetual, unthrottled access to export their complete compliance dataset at any time — either as a full or as a structured data set. No export is throttled, paywalled, or time-locked.

Export Anytime

Full data export on demand, no fees

Right to Erasure

Request full data deletion at any time

Right to Correction

Staff can request correction of their records

Privacy Requests & Enquiries

To exercise your rights under the Privacy Act 2020 (access, correction, deletion), or to report a privacy concern, please contact our Privacy Officer at notifications@apico.app. We will acknowledge your request within 5 working days in accordance with NZ law.