Aquatic centres handle information about participants, families and sometimes their health. Swimo (Planitou) addresses that responsibility through strong encryption, controlled access, documented governance and structured internal processes.
A shared responsibility
Security is built together.
Swimo (Planitou) provides a platform designed to protect personal information. Each client organization remains the Controller for its own users and participants. Roles, access and documentation are structured so each side can carry its part.
Client organization: its own privacy policy, obtaining consent, managing its users’ access
Shared documentation: security questionnaires, impact assessments, exchanges with your IT or privacy leads
01
Strong data encryption
All connections to the platform are encrypted with SSL/TLS (https) using 128-bit encryption in transit, and servers are protected by a firewall and 256-bit server-side encryption. Servers are patched on a weekly basis to apply security updates quickly.
Identity check for users attempting to access data
Adequate encryption of data in transit and at rest
Integrity of received data (no loss, no corruption)
Availability of data for authorized users
02
Infrastructure and hosting
Swimo (Planitou) runs on Digital Ocean cloud infrastructure in the Toronto region. The infrastructure is highly scalable and redundant, backed by a 99.9% availability SLA. Digital Ocean facilities meet ISO 9001, ISO/IEC 27001, 27017 and 27018, PCI-DSS level 1, CSA STAR level 1, and SOC 1, SOC 2 and SOC 3 standards. Personal Information is stored on servers located in Europe or the European Union and is encrypted on storage media.
03
Per-organization data segmentation
Each subscribed account has its own dedicated database. This segmentation makes any cross-over between two organizations’ data impossible and strengthens confidentiality. Files are stored on high-capacity off-web SSD drives and are only shown to authorized users, based on the connected user’s role and the groups or records they are attached to.
04
Information handled — and what is never collected
Information added to the platform is entered by subscribers and typically covers what is essential to participant safety: contact details, family context, health record (health-insurance number, allergies, medications, treating physician, special needs), parent contact details, people authorized to pick up the child and relevant documents (photos, videos, attachments).
No social insurance number is ever required or stored
No user banking information is ever required or stored
Online payments are processed by a specialized PCI-DSS compliant provider
05
Password and session policy
Authentication rules are built for professional use and for environments where several people occasionally share a device at the pool deck.
Passwords must be at least 10 characters and combine letters, numbers and special characters
On first login or after a reset, parents must confirm the birth dates of the children linked to the account
A session can be locked at any time, or automatically after 30 minutes of inactivity, for up to 4 hours without losing work in progress, and is then signed out
06
Service resilience and data continuity
We run redundant, continuous backups of our databases. If a server issue occurs, backups can be restored quickly so users can keep working with no data loss. Backup copies are stored in data centres separate from primary servers to limit the impact of any local incident.
07
Limited data retention
Our retention strategy relies on minimization: data is kept for the shortest time possible, only to fulfill the purpose it was collected for, comply with legal requirements or protect our legitimate business interests. Account deletion is completed within 90 days of the request; some non-identifying traces may remain for up to 12 months for technical reasons.
08
Access management
You control access to your data: you decide who sees what and grant permissions. Every invited user creates a unique password. Different permission levels let you limit each user’s privileges based on responsibility, in line with the Terms and conditions.
09
Personal information governance
Cybersecurity is a priority. Swimo (Planitou) maintains several internal policies governing data use, employee roles and subcontractor management.
Personal Information Management Policy — sensitivity-based categorization and record of operations
Information Security Policy — confidentiality, integrity and availability of information and systems
Subcontractor Management Policy — selection criteria and security requirements for third parties
10
How our employees use data
Each employee only accesses data strictly necessary to perform their role, under a confidentiality obligation and subject to sanctions. Internally, server architecture and content management are the sole responsibility of the CTO. Disclosure to any external party requires express authorization from the Personal Information Officer. Mandatory training and an internal documentation centre complement our policies.
11
Incident management
Our incident management process draws on ISO/IEC 27001:2013. The Information Security Incident Management Policy defines responsibilities, recognition criteria, risk classification (low, medium, high), resolution steps and follow-up measures to prevent recurrence. We maintain a register of all confidentiality incidents.
12
Background checks at hiring
Swimo (Planitou) performs a routine criminal-record and background check before confirming each hire. This check is repeated every two (2) years.
13
Physical and material security
Our Physical Access Management Policy defines locking, alarm and visitor management rules. Our computer equipment and software are password-protected; lost or stolen devices can be wiped remotely. Our databases are hosted outside our offices in highly secure data centres.
14
Vendor and subcontractor management
Our vendors and subcontractors only access data that is necessary, for the time necessary, and must adopt security standards that meet our requirements. We assess the scope of data involved and associated risks before any engagement. Online payments are processed by Stripe, which meets PCI-DSS level 1, EMVCo levels 1 and 2, SOC 1 and SOC 2 standards.
15
Cyber-security insurance
Swimo (Planitou) maintains cyber-security insurance of at least one million dollars (CAD $1,000,000) for any claim related to a data-security event.
16
Documentation for organizations
We support IT or privacy leads with appropriate documentation.
Security questionnaires
Privacy impact assessments
Documentation on request
Exchanges with your leads
Applicable policies
See our Swimo pages for the Privacy policy and Terms and conditions.