Security
Last updated: September 2026
WHapp takes the security of your personal information seriously. This page outlines the technical and organisational measures we implement to protect data on the WHapp platform, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Our security commitment
WHapp is committed to protecting personal information from misuse, interference, loss, unauthorised access, modification, and disclosure, as required by Australian Privacy Principle 11 (APP 11) under the Privacy Act 1988 (Cth). We apply a risk-based approach to information security, continuously reviewing and improving our controls as the platform evolves.
2. Technical security measures
We implement the following technical controls to protect data on the WHapp platform: • Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). • Encryption at rest: personal information stored on our systems is encrypted at rest. • Access controls: access to personal information is restricted to authorised personnel on a need-to-know basis, enforced through role-based access controls. • Secure infrastructure: our platform is hosted on reputable cloud infrastructure providers with industry-standard physical and network security certifications. • Vulnerability management: we conduct regular security assessments and apply security patches in a timely manner. • Logging and monitoring: system access and activity logs are maintained and monitored for suspicious behaviour.
3. Organisational security measures
In addition to technical controls, WHapp implements the following organisational measures: • Security policies: we maintain internal information security policies governing the handling, storage, and disposal of personal information. • Staff training: personnel with access to personal information receive training on privacy and security obligations under Australian law. • Third-party due diligence: we assess the security practices of third-party service providers before engaging them and require contractual commitments to handle personal information securely. • Data minimisation: we collect only the personal information necessary for the purposes described in our Privacy Policy.
4. Notifiable data breaches
WHapp complies with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). In the event of an eligible data breach, one that is likely to result in serious harm to one or more individuals, we will: • Contain the breach and assess the risk of harm as quickly as practicable. • Notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable. • Provide affected individuals with recommendations on steps they can take to protect themselves. We maintain an internal data breach response plan to ensure a timely and effective response.
5. Health information
As a healthcare technology platform, WHapp recognises that health information is sensitive information under the Privacy Act 1988 (Cth). We apply heightened security controls to any health-related data and will only collect sensitive information with your explicit consent, as required by APP 3.3. Where the platform integrates with health records or clinical systems, we will comply with applicable requirements under the My Health Records Act 2012 (Cth) and any relevant state or territory health records legislation.
6. Cross-border data security
Where personal information is transferred to overseas recipients, we take reasonable steps to ensure those recipients maintain security standards consistent with the Australian Privacy Principles, as required by APP 8. Our cloud infrastructure providers operate under internationally recognised security frameworks including ISO 27001 and SOC 2.
7. Destruction and de-identification
When personal information is no longer required for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we take reasonable steps to destroy or permanently de-identify that information in accordance with APP 11.2. Secure deletion procedures are applied to both digital and physical records.
8. Reporting a security concern
If you believe you have discovered a security vulnerability in the WHapp platform, or if you suspect your personal information has been compromised, please contact us immediately at: [email protected] We take all security reports seriously and will investigate promptly. Please do not publicly disclose any potential vulnerability before giving us a reasonable opportunity to address it.
9. Regulatory oversight
WHapp's privacy and security practices are subject to oversight by the Office of the Australian Information Commissioner (OAIC). If you have concerns about how we handle your personal information that we have not resolved to your satisfaction, you may contact the OAIC: Website: www.oaic.gov.au Phone: 1300 363 992 Post: GPO Box 5218, Sydney NSW 2001
10. Updates to this page
We will update this Security page as our platform and security practices evolve. The date of the most recent revision is shown at the top of this page.
Found a security issue or have a concern? Contact us at [email protected]