How DLYTE Protects Study Data
Last Update 11 hours ago
At a platform level, DLYTE applies the following protections:
- Data is encrypted in transit using TLS 1.2 or higher
- Data is encrypted at rest using AES-256
- Study access is controlled by account and role-based permissions
- Participants can only access the specific studies they have been matched to and approved for
- Business users only access studies linked to their own account or approved team membership
- Sensitive participant information is minimised wherever possible
- Research outputs are structured to avoid unnecessary exposure of personal information
DLYTE is hosted on cloud infrastructure whose providers maintain SOC 2 Type II and ISO 27001 compliance. This means the underlying systems that store and process your data meet established standards for security, availability and confidentiality.
DLYTE’s approach follows data minimisation principles. We collect what is needed to run and interpret the study, avoid collecting unnecessary personal information, and provide clear pathways for data access, export and deletion.
DLYTE maintains supporting platform documentation that explains how customer data, participant information, account access and moderated research assets are handled.
Security & Data Protection — https://dlyte.io/security
Covers the platform’s approach to encryption, access control, session protection, infrastructure security, DDoS mitigation, secrets management, automated patching and secure handling of research assets.Privacy Policy — https://dlyte.io/privacy-policy
Covers customer data ownership, data minimisation, the types of participant information collected, how participant information is used for study matching, how tester information is presented to businesses, and rights relating to data retention, export and deletion.DLYTE’s privacy approach is designed around applicable privacy obligations, including Australian Privacy Act requirements and other relevant privacy frameworks.
User Agreement — https://dlyte.io/user-agreement
Covers account-based access, role separation between Owner, Admin and Member users, acceptable platform use, prohibited access, confidentiality expectations, and responsibilities relating to moderated studies.