Privacy Policy
Version 1.0. Last updated 12 August 2026.
1. Who we are
SurgNet is operated by SURGNET PTY LTD (ACN 699 914 924), an Australian company ("SurgNet", "we", "us"). SurgNet connects surgeons with verified surgical assistants for operating lists.
We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We treat ourselves as bound by the APPs regardless of any small-business exemption that might otherwise apply.
2. What we collect
- Identity and contact details: your name, email address and mobile number.
- Professional details: your AHPRA registration number, specialty or specialties, experience level, affiliated hospitals, and an optional short bio.
- Operating list details: the hospital, state, date, times, specialty, number of cases, procedure descriptions and logistics notes a surgeon enters when posting a list.
- Platform activity: who applied to which list and the outcome, delegation of access to rooms staff, and on-call availability you set.
- Notification records: in-app notifications, email and SMS send logs, and push notification subscription endpoints, kept so we can deliver and troubleshoot notifications.
- Technical information: aggregate, cookieless analytics (page views and country-level counts). We do not use advertising trackers, cross-site tracking or session recording.
What we do not collect: patient information
SurgNet is a workforce coordination tool, not a clinical system. We do not collect or hold patient names, identifiers, dates of birth, Medicare numbers, diagnoses, clinical notes or images, and no field in the product is designed to receive them. Our Terms of Use prohibit entering patient-identifying information, and the interface warns against it at the point of entry.
3. Why we collect it
We use your information to:
- operate the matching service: posting lists, applying, and connecting members;
- verify professional registration against the public AHPRA register;
- send service notifications in-app, by email, SMS and push notification;
- respond to support requests and feedback; and
- keep the platform secure and improve how it works.
We do not sell personal information, share it with advertisers, or use it for any secondary purpose.
4. Who we share it with
Other members. Your professional profile is visible to members as needed for matching. You control how much of your contact information other members see: surgeons choose whether their direct details, their rooms' details, or only public details are shown.
Service providers. We use a small number of providers to run SurgNet, and share only what each needs to provide its service:
- Supabase (on Amazon Web Services): database, authentication and server-side functions, hosted in Sydney, Australia.
- Mobile Message: SMS notifications, an Australian provider.
- Resend (via Amazon SES): transactional and authentication emails, a United States provider.
- Cloudflare: hosting and delivery of the web application, and cookieless aggregate analytics.
- Hostinger: hosting of our marketing website (in Sydney, Australia) and our company email.
- Formspree: waitlist and contact forms on the marketing site only, a United States provider.
- Browser push services (Google, Apple, Mozilla): relay push notifications as encrypted payloads they cannot read.
Legal requirements. We may disclose information where the law requires or permits it, for example to comply with a court order.
5. Overseas disclosure
Your account records, operating lists and applications are stored and processed in Australia (Sydney). Some notification and form content leaves Australia: transactional email is sent through a United States provider, marketing-site form submissions go to a United States provider, and our company email is carried on our provider's international mail network. We limit what those channels carry to what the message itself needs.
6. How we protect it
- Access rules are enforced inside the database itself (row level security on every table), so members can only ever see what they are entitled to.
- All traffic is encrypted in transit, and data is encrypted at rest.
- Passwords are hashed and never visible to us, and passwords known to have appeared in public data breaches are rejected.
- Administrative access is restricted to the two founders.
- We run regular automated security checks and versioned, reviewed changes to the database.
7. How long we keep it
We keep your information while your account is active. After an account is closed, we delete or de-identify its personal information within 24 months, unless the law requires us to keep it longer or it is needed for an unresolved dispute. Encrypted database backups are retained for 7 days on a rolling basis. Aggregate, de-identified statistics (for example how many lists were filled) may be kept indefinitely.
8. Your rights
You can view and correct your profile in the app at any time. You can also ask us to access, correct or delete your personal information, including deleting your account entirely, by emailing info@surgnet.com.au. We respond to requests within 30 days.
Complaints. If you believe we have mishandled your information, contact us first at info@surgnet.com.au and we will investigate and respond. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
9. Data breaches
If a data breach occurs, we will contain and assess it immediately, notify affected users promptly, and notify the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires it.
10. Changes
We may update this policy as SurgNet develops. For material changes we will notify account holders before the change takes effect. The current version, with its "last updated" date, is always published on this page.
11. Contact
Questions about privacy? Email info@surgnet.com.au.