Data Handling and Data Location Policy
1. Purpose and Scope
This policy describes how The Change Gym (TCG) manages privacy, data handling, data retention, cookie usage, and data location across its digital platforms, including the TCG website, IRVEY diagnostic system, and RCC Intelligence submission workflows. It applies to all users, clients, coaches, and organisational participants.
2. Data Collection Principles
TCG collects only the minimum data required to deliver diagnostic, readiness, and reporting services. Data collection is limited to:
diagnostic responses
coaching submissions
organisational metadata required for reporting
contact details necessary for account creation or communication
TCG does not collect unnecessary personal information, behavioural tracking data, or marketing profiles.
3. Data Usage
Collected data is used exclusively for:
generating diagnostic reports
supporting coaching workflows
producing readiness and capability insights
fulfilling contractual obligations to client organisations
TCG does not sell, share, or disclose data to third parties for marketing or commercial purposes.
4. Data Storage Location
All data is stored on secure servers located in Australia. No diagnostic, coaching, or organisational data is stored offshore.
Backups are also retained within Australia.
This ensures alignment with government expectations for data sovereignty and jurisdictional control.
5. Data Retention
TCG retains diagnostic and coaching data only for as long as required to:
deliver contracted services
support organisational reporting cycles
meet audit or compliance obligations agreed with the client
Retention periods are defined in client agreements. Data is securely deleted when no longer required.
6. Data Security
TCG maintains a hardened security posture across all platforms, including:
enforced HTTPS
modern TLS configurations
strict security headers (CSP, HSTS, X‑Frame‑Options, X‑Content‑Type‑Options, Referrer‑Policy, Permissions‑Policy)
regular vulnerability scanning
restricted administrative access
secure authentication controls
IRVEY and TCG both maintain A‑grade or higher security ratings on industry‑standard scanning tools.
7. Form Submission Security
All form submissions — including diagnostic responses and RCC Intelligence workflows — are:
transmitted over encrypted channels
protected by server‑side validation
stored in secure Australian‑based databases
monitored for anomalous activity
protected against common web vulnerabilities (XSS, CSRF, injection attacks)
No diagnostic or coaching data is transmitted via email.
8. Cookies and Tracking
TCG uses only essential cookies required for:
session management
authentication
maintaining user access during diagnostic completion
TCG does not use:
advertising cookies
behavioural tracking cookies
third‑party marketing pixels
cross‑site profiling technologies
Cookie usage is minimal and strictly functional.
9. Access and Control
Client organisations may request:
access to stored diagnostic data
correction of inaccurate information
deletion of data no longer required
confirmation of data location and retention practices
Requests are handled promptly and in accordance with contractual obligations.
10. Disclosure and Third‑Party Access
TCG does not disclose diagnostic or coaching data to third parties unless:
required by law, or
explicitly authorised by the client organisation
No external analytics, marketing platforms, or offshore processors have access to IRVEY or RCC Intelligence data.
11. Policy Updates
TCG may update this policy to reflect:
improved security practices
changes in government requirements
enhancements to diagnostic or coaching systems
Clients will be notified of any material changes.