OH Consultant

HIRA-4D Data Residency Information

Last updated: 16 March 2026

Where Is My Data Stored?

All customer data is stored in Supabase PostgreSQL in Zurich, Switzerland (AWS eu-central-2 region). This includes all database records, all file attachments, all backups, and all audit logs. Your data does not leave the Zurich region for storage or backup purposes.

Why Switzerland?

Switzerland provides: the Swiss Federal Act on Data Protection (FADP) — one of the strongest data protection regimes globally; EU adequacy recognition; political neutrality and legal stability; no mass surveillance programmes; strong bank-grade data confidentiality traditions; physical security (underground data centres in Alpine infrastructure).

For Australian Customers

Australia does not have a blanket data localisation law requiring data to be stored within Australia. The Privacy Act 1988 and APP 8 permit cross-border disclosure of personal information provided the overseas recipient handles it consistently with the APPs.

Our Data Processing Agreement (DPA) at /data-processing establishes the contractual framework required by APP 8. Switzerland's FADP is recognised as providing data protection substantially similar to the Australian Privacy Principles.

Health monitoring data: Our platform stores occupational health monitoring dates and outcomes (spirometry values, X-ray dates, fitness-for-duty status). These are employer-held occupational records, not clinical health records. However, we treat all health-related data with the highest level of protection regardless of legal classification.

For Swiss and EU Customers

Data stored in Zurich complies with Swiss FADP data residency expectations, EU GDPR adequacy (Switzerland has EU adequacy decision), and involves no transfer outside Switzerland for storage or backup.

Future Regions (Planned)

APAC: Singapore (ap-southeast-1) — for Australian and Singapore customers who require APAC residency. North America: Canada (ca-central-1) — for US and Canadian customers. Regions will be activated based on customer demand. Tenant data region is set at onboarding and is immutable.

Can I Get My Data?

Yes. You can export all your data at any time: risk assessments (CSV/PDF), CAPAs (CSV/PDF), incidents (CSV/PDF), worker records (CSV), SWR export (SafeWork NSW format CSV), audit logs (CSV), full database export (JSON, on request).

Questions: info@ohconsultant.com.au