You hold sensitive personal data — contact details, financial records, and in some cases medical information. Protecting this data is both a legal obligation and a trust requirement.
Data You Collect and Store
Inventory all personal data: names, addresses, phone numbers, email addresses, payment information, attendance records, medical details, and documents. For each data type, document why you collect it, who has access, and how long you retain it.
Essential Security Measures
Use a platform with bank-grade encryption for data at rest and in transit. Implement role-based access control — staff should only see data relevant to their role. Enable two-factor authentication for admin accounts. Ensure regular automated backups.
Access Control Best Practices
Create distinct roles: admin (full access), branch manager (branch-specific access), instructor (batch-specific access), and front desk (limited access). Review access logs regularly. Revoke access immediately when staff leave.
Privacy Policy and Consent
Have a clear privacy policy that explains what data you collect, why, and how it is protected. Obtain explicit consent at enrollment. Allow members to request their data or deletion. Nxiora provides enterprise-grade security with encrypted storage, role-based access, audit trails, and automated backups at every plan level.