The 3A Toolkit is built to hold as little personal information as possible. This page explains what we keep, where, and how it is protected, for clients, clinicians and the organisations that review us.
What someone writes in the program is saved on the phone, tablet or computer they use. It is not stored on 3A servers, and neither 3A nor a clinician can read it.
A mobile number for sign-in, the plan and its end date, and, for clients of a clinician, which code was used so a seat can be counted. For clinicians: name, practice, contact and billing details.
Seat counts and whether each code has been used. Never names, phone numbers, activity or reflections.
Clinicians never send us client information. Clients sign themselves in.
People sign in with their mobile number and a one-time code sent by text, with an automated check that blocks bots. There is no password to steal or reuse.
Every page and request uses HTTPS, and browsers are told to use only secure connections to 3atoolkit.com.
Each signed-in person can reach only their own account. Clinician and client records are reached only through functions that check who is asking.
Program videos and files are kept in private storage and opened with short-lived links after sign-in. Content is watermarked.
Paddle is our merchant of record. Card and bank details go to Paddle, never to 3A.
Account data is stored with our database provider in [hosting region].
3A uses a small number of established providers. Each publishes its own security and compliance information.
Database and sign-in.
Website hosting.
Payments, invoices and sales tax, as merchant of record.
The automated bot check at sign-in.
If we become aware of a breach that affects personal information, we notify the people affected and the relevant regulators as the law requires. To report a security concern, write to sales@3atoolkit.com with "Security" in the subject.
See also our privacy policy.