Information Security
Last updated: August 2026
Timing Solutions is committed to protecting the security, confidentiality and integrity of the information entrusted to us.
We recognise that sporting organisations, athletes, members, parents and guardians rely on us to handle their information securely. We maintain an Information Security Management System and continually review our security practices to address changing technology and security risks.
Our security framework
Our approach includes technical, organisational and operational controls across areas such as:
- information security governance and policies;
- access control and authentication;
- role-based permissions;
- secure cloud infrastructure;
- system monitoring;
- vulnerability management and security testing;
- staff security and privacy practices;
- incident and data breach response;
- third-party provider management; and
- secure deletion and de-identification of information when it is no longer required.
Our systems and internal processes are designed to align with the principles and controls of the ISO/IEC 27001 information security standard.
Cloud infrastructure
Our production environment is hosted using Amazon Web Services (AWS) infrastructure in Australia.
AWS maintains internationally recognised security certifications and controls. Timing Solutions is responsible for implementing appropriate security controls within the services and environments that we operate.
We regularly review our technology and infrastructure arrangements to ensure they remain appropriate for the information we hold and the services we provide.
Access security
Access to Timing Solutions systems is controlled through authenticated user accounts and role-based permissions.
Users are only provided access to the information and functionality required for their role and authorised by the relevant Organisation.
Staff and contractors are subject to appropriate confidentiality, security and access requirements, with access to customer information restricted according to business need and role.
Security testing
We undertake security testing and work with appropriately qualified external providers to identify vulnerabilities and assess our security controls.
This may include application penetration testing and other security assessments.
Findings from security testing and security incidents are used to identify opportunities to strengthen our systems and processes.
Data breaches
We maintain a formal process for identifying, assessing, containing and responding to suspected data breaches.
Our response process is designed to:
- contain and investigate suspected incidents;
- assess the information involved and potential impact;
- determine whether notification obligations apply;
- notify affected parties and the OAIC where required; and
- investigate the underlying cause and implement appropriate corrective actions.
Our detailed data breach response procedures are maintained internally.
Data retention and secure deletion
Security includes ensuring that personal information is not retained unnecessarily.
We periodically review information held within our systems and take reasonable steps to securely destroy or de-identify information when it is no longer required, subject to applicable legal, contractual or other retention requirements.
Further information is available in our Data Retention & Deletion policy.
Third-party providers
Timing Solutions uses selected third-party technology and service providers to support the operation, security and delivery of our products and services.
We assess and manage relevant providers as part of our information security and privacy processes.
Where third parties handle personal information on our behalf, we take reasonable steps to ensure appropriate security and privacy arrangements are in place.
Security concerns
If you believe you have identified a security vulnerability affecting a Timing Solutions product or service, please contact:
privacy@timingsolutions.com.au
Please provide sufficient information for us to investigate the issue and do not access, modify, copy or disclose information that you are not authorised to access.
Contact
Questions about our information security practices can be directed to:
privacy@timingsolutions.com.au
Last updated: August 2026
Comments
0 comments
Article is closed for comments.