Zanda Staff Access to Your Account and Client Data
Understand when a member of the Zanda team can access your account, what they can see, and the controls that apply.
Your client records, including clinical notes, belong to your practice. Zanda staff do not browse customer accounts, and no one at Zanda reads your notes as part of normal operation.
There are two situations where a member of the Zanda team works with your data. Both are limited, controlled, and happen only with your involvement: a support investigation you have asked us to carry out, and a data import.
In this article:
- Support access to your account
- Access during a data import
- The controls that apply
- What you can see in your own account
- Frequently Asked Questions
- Related Articles
Support access to your account
Some issues cannot be diagnosed from the outside. When that happens, a member of the Zanda team may need to sign into your account to reproduce the problem and investigate it.
This happens only with your authorisation, and only for the purpose of providing support or resolving the issue you have raised. We ask first.
While signed in, the team member is working inside your account as one of your users, so they see the account the way that user sees it. If that user can open client profiles and clinical notes, those are within reach during the session. What we commit to is scope: the team opens only what the issue requires.
If you would prefer that client records were not opened at all, say so when you raise the issue. The team will tell you what they can check without that access, and work through it with you.
Access during a data import
A data import is the other case, and it works differently. Clinical and Admin Notes are one of the data types we bring across, and a Data Import Specialist converts your source files by hand before they are loaded into your account. That access exists to cleanse, transform, and load your data, the specialists are not reviewing the clinical content, and your source data is permanently removed 60 days after the import.
See Importing your Data - FAQ for the full detail, including how to keep notes out of the files you send us.
The controls that apply
- Every Zanda team member with potential access to customer data is screened and background checked before being hired, and is bound by a signed confidentiality agreement.
- Signing into a customer account is restricted to specific team members who have been granted that access. They sign in with their own credentials, and where two-step verification is enabled on their account they must also enter a verification code. Repeated failed sign-in attempts lock the account.
- Zanda is ISO 27001 certified, maintains an externally audited privacy program, and has a dedicated Data Protection Officer.
- For Australian accounts, we meet Australian Privacy Principle (APP) 8 requirements before any access from outside Australia. See Australian Data Residency and Access.
What you can see in your own account
The Log File (Tools > Log File) shows activity by the users in your own account. Sessions where a Zanda team member signed in to investigate an issue are not listed there, so the Log File is not the place to check for Zanda access.
If you need confirmation of when your account was accessed by Zanda and why, contact Zanda Support at support@zandahealth.com with the date range and the reason for your request.
Frequently Asked Questions
❓ Can Zanda staff see my clinical notes?
Not as part of normal operation. Nobody at Zanda opens your account to read notes, and there is no routine or background access to your clinical records. Notes are only ever in view in the two situations above: a support investigation you have authorised, and a data import you have asked us to carry out.
❓ Outside of a data import, can Zanda see my client notes?
Only if you ask us to investigate something and authorise us to sign into your account. In that session the team member works as one of your users, so notes are reachable, and the team opens only what the issue requires. Outside that, no.
❓ Do you need my permission first?
Yes. We do not access your account unless you have authorised it, and it is always for the purpose of providing support or resolving an issue you have raised.
❓ Can I say no?
Yes. Tell the team when you raise the issue. They will work through what can be checked without account access. Some issues take longer to resolve that way, and a few need account access to diagnose at all.
❓ Where is this written down?
Our Security and Privacy Policy pages cover our data handling practices, and Australian Data Residency and Access covers residency and overseas access for Australian accounts. For a written, account-specific statement to give an insurer, funder, or oversight body, see Responding to Security and Data Residency Audits.
Related Articles
- Importing your Data - FAQ - How your data is handled during a migration, including clinical notes.
- Australian Data Residency and Access - Where Australian account data is stored and when it may be accessed from overseas.
- Recording and Reviewing the User Activity Log File - How to review activity by the users in your own account.
- User Permissions For Practitioners - What your own practitioners can see and do in your account.
- Responding to Security and Data Residency Audits - Where to find security and privacy evidence for questionnaires and audits.