Data Handling and Data Location Policy

1. Purpose and Scope

This policy describes how The Change Gym (TCG) manages privacy, data handling, data retention, cookie usage, and data location across its digital platforms, including the TCG website, IRVEY diagnostic system, and RCC Intelligence submission workflows. It applies to all users, clients, coaches, and organisational participants.

2. Data Collection Principles

TCG collects only the minimum data required to deliver diagnostic, readiness, and reporting services. Data collection is limited to:

  • diagnostic responses

  • coaching submissions

  • organisational metadata required for reporting

  • contact details necessary for account creation or communication

TCG does not collect unnecessary personal information, behavioural tracking data, or marketing profiles.

3. Data Usage

Collected data is used exclusively for:

  • generating diagnostic reports

  • supporting coaching workflows

  • producing readiness and capability insights

  • fulfilling contractual obligations to client organisations

TCG does not sell, share, or disclose data to third parties for marketing or commercial purposes.

4. Data Storage Location

All data is stored on secure servers located in Australia. No diagnostic, coaching, or organisational data is stored offshore.

Backups are also retained within Australia.

This ensures alignment with government expectations for data sovereignty and jurisdictional control.

5. Data Retention

TCG retains diagnostic and coaching data only for as long as required to:

  • deliver contracted services

  • support organisational reporting cycles

  • meet audit or compliance obligations agreed with the client

Retention periods are defined in client agreements. Data is securely deleted when no longer required.

6. Data Security

TCG maintains a hardened security posture across all platforms, including:

  • enforced HTTPS

  • modern TLS configurations

  • strict security headers (CSP, HSTS, X‑Frame‑Options, X‑Content‑Type‑Options, Referrer‑Policy, Permissions‑Policy)

  • regular vulnerability scanning

  • restricted administrative access

  • secure authentication controls

IRVEY and TCG both maintain A‑grade or higher security ratings on industry‑standard scanning tools.

7. Form Submission Security

All form submissions — including diagnostic responses and RCC Intelligence workflows — are:

  • transmitted over encrypted channels

  • protected by server‑side validation

  • stored in secure Australian‑based databases

  • monitored for anomalous activity

  • protected against common web vulnerabilities (XSS, CSRF, injection attacks)

No diagnostic or coaching data is transmitted via email.

8. Cookies and Tracking

TCG uses only essential cookies required for:

  • session management

  • authentication

  • maintaining user access during diagnostic completion

TCG does not use:

  • advertising cookies

  • behavioural tracking cookies

  • third‑party marketing pixels

  • cross‑site profiling technologies

Cookie usage is minimal and strictly functional.

9. Access and Control

Client organisations may request:

  • access to stored diagnostic data

  • correction of inaccurate information

  • deletion of data no longer required

  • confirmation of data location and retention practices

Requests are handled promptly and in accordance with contractual obligations.

10. Disclosure and Third‑Party Access

TCG does not disclose diagnostic or coaching data to third parties unless:

  • required by law, or

  • explicitly authorised by the client organisation

No external analytics, marketing platforms, or offshore processors have access to IRVEY or RCC Intelligence data.

11. Policy Updates

TCG may update this policy to reflect:

  • improved security practices

  • changes in government requirements

  • enhancements to diagnostic or coaching systems

Clients will be notified of any material changes.