NZ Health Compliance • Last Updated: April 2026
Apico Systems operates as a service provider under the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020. Your clinic remains the agency in full control of all data it generates on this platform. We do not sell, trade, or rent user data to any third party — ever.
Apico Systems complies fully with the New Zealand Privacy Act 2020, which governs how personal information must be collected, stored, used, and disclosed. Staff members retain the right at all times to access and correct their personal information held on the platform.
Under the HIPC 2020, Apico's architecture is explicitly isolated from Patient Health Information (PHI). We do not ingest, store, or transmit patient dental records or personal health data. Compliance tracking is strictly limited to equipment, staff credentials, and operational logs.
In the context of both Acts, your clinic is the "agency" — the entity that controls the purpose and use of the data. Apico Systems Ltd is the "service provider" — processing data only on your behalf, under your instruction. This means your clinic retains full data rights, including the right to export or delete records at any time.
We do not sell, trade, or rent any user data to third parties under any circumstances.
All data transmitted between your clinic's browser and our servers is protected by TLS 1.2+ (SSL encryption). This ensures that every login, data entry, and report generation is invisible to any third-party network observer — the same standard used by online banking.
All database records and backups are protected by AES-256 encryption — the same standard used by banks and defence organisations worldwide. Your data is unreadable without the authorised decryption keys, even in the event of a physical hardware breach.
Apico is hosted on Render / AWS infrastructure, operating within Tier 4 high-security data centres with 24/7 physical monitoring, biometric access controls, and redundant power systems. Tier 4 represents the highest classification in data centre security.
We perform automated daily backups of all clinic data with a 7-day rolling retention period. In the event of a system failure or data loss incident, your compliance records can be restored to any point within the retention window.
Access to data is strictly regulated by a hardcoded three-tier RBAC system: Admin → Manager → Staff. Staff accounts are prevented at the architecture level from viewing or modifying master configurations, other users' data, or administrative settings such as billing and user management. All account passwords are stored as one-way Bcrypt hashes — never in readable plain text — and all sessions are authenticated via short-lived, cryptographically signed JWT tokens.
The subscribing clinic owns 100% of its data unconditionally. Administrators have perpetual, unthrottled access to export their complete compliance dataset at any time — either as a full or as a structured data set. No export is throttled, paywalled, or time-locked.
Export Anytime
Full data export on demand, no fees
Right to Erasure
Request full data deletion at any time
Right to Correction
Staff can request correction of their records
To exercise your rights under the Privacy Act 2020 (access, correction, deletion), or to report a privacy concern, please contact our Privacy Officer at notifications@apico.app. We will acknowledge your request within 5 working days in accordance with NZ law.