Privacy policy_

Surgical Performance Pty Ltd is very sensitive to the privacy needs of its website visitors and subscribers and is wholly committed to maintaining privacy at the highest level.

Surgical Performance Pty Ltd (“SurgicalPerformance,” “we,” “us”)
Effective date: 1 November 2011
Last updated: 31 July 2026

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our websites, register for or use the SurgicalPerformance platform (including the clinician App, API, PROMS patient surveys, and related services) (the “Services”).

In this policy, “you” means any individual about whom we collect personal information — including website visitors, subscribers (surgeons and practice staff), and, where relevant, patients who interact with PROMS.

We manage personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) (Privacy Act), and, where applicable, other laws that apply to us or to our customers (including US HIPAA when we act as a Business Associate).

  1. A note for US healthcare customers
    If you are a US-based healthcare provider or practice and you (or your patients) submit Protected Health Information (PHI) to the Services, that PHI is governed first by the Business Associate Agreement (BAA) between you and SurgicalPerformance, and by HIPAA.
    This Privacy Policy governs how we handle personal information about you as a website visitor and account holder (for example, name, email, billing details) and how we describe our general practices. It supplements — but does not replace — your BAA.
    When you create a US location, you must accept a BAA before entering patient data for that location. See our HIPAA & Security Policy and sample BAA.

  2. What information we collect
    2.1 Subscriber / account information
    We collect personal information you provide when you register, subscribe, or manage an account, which may include:
    Name, email address, username, and password
    Practice or specialty information, and area of practice
    Billing and payment-related details (payments are processed by Stripe; we do not store full card numbers)
    Communications you send to us (support requests, feedback)
    Optional profile or professional details you choose to provide

    2.2 Patient information (PHI / health information) — by design
    The Services are designed so that clinicians may enter identifiable patient information needed for outcomes tracking, follow-up, and PROMS. Depending on modules and configuration, this may include:
    Patient name
    Patient date of birth
    Patient identifiers (coded IDs, medical record numbers, or other codes you choose to enter)
    Procedure and clinical dates, and related clinical / outcomes data
    Contact details used for PROMS (for example phone number or email), where you enable patient messaging
    Survey responses and other information patients submit through PROMS
    Minimisation (recommended, not required): Where your clinical workflow allows, we encourage using an internal coded patient identifier rather than a widely used external identifier. This is a privacy-enhancing practice; it does not mean the platform requires patient data to be non-identifiable. Name, date of birth, and other identifiers are permitted product fields.
    You (the Subscriber — typically the surgeon or practice that controls the account) are responsible for having a lawful basis and any required patient notices or consents to enter patient information into the Services. For US locations, that includes your obligations as a HIPAA Covered Entity under your BAA.

    2.3 Usage and technical information
    We may collect:
    IP address, browser type, device type, operating system
    Pages visited, approximate location derived from IP, referring URLs
    Cookies and similar technologies (see Cookies below)
    Application logs and diagnostic data (see third-party error monitoring under Disclosures)

    2.4 Research and aggregated data
    We may create de-identified or aggregated datasets from platform data for benchmarking, product improvement, statistics, and research (including publication). Once information is de-identified so that it can no longer reasonably identify a patient, subscriber, or practice, it is no longer treated as personal information / PHI under this policy. See section 6.

  3. How we collect information
    Directly from you — registration, account settings, clinical data entry, support
    From patients — when they open a PROMS survey link (email/SMS) and submit responses
    Automatically — cookies, logs, analytics on websites and apps
    From payment and communication providers — as needed to process subscriptions and messages

  4. Why we collect and use personal information
    We collect and use personal information as reasonably necessary to:
    Provide, operate, secure, and improve the Services
    Authenticate users and manage subscriptions and billing
    Enable outcomes tracking, reporting, benchmarking, and PROMS follow-up
    Contact you about your account, security, and service changes
    Provide customer support
    Detect, investigate, and prevent fraud, abuse, and security incidents
    Comply with law and enforce our agreements
    Conduct de-identified research, audit, and product analytics as described in this policy
    With your consent, send optional marketing communications (you may unsubscribe)
    We do not sell subscriber performance data or patient information for third-party commercial marketing.
    Subscriber performance data confidentiality. Performance data relating to a subscriber will not be disclosed or made available to any party other than that subscriber without the subscriber’s express agreement, except where required by law, necessary to provide the Services (including subprocessors under contract), or as otherwise described in this policy / your BAA. Personnel and contractors are bound by confidentiality obligations. Subscribers remain free to share their own performance data with third parties (for example an employer) as they choose.

  5. Who we disclose personal information to
    We may disclose personal information to:
    Service providers (subprocessors) who help us run the Services — for example cloud hosting, SMS, email, payments, customer support tooling, error monitoring, and (where enabled) AI-assisted features. See the Trust Center for the current list. Where a provider handles PHI on our behalf for US customers, we require appropriate contractual safeguards (including BAAs where required).
    Professional advisers (legal, accounting) under confidentiality
    Regulators, courts, or law enforcement where required or permitted by law
    A buyer or successor in a business transaction (sale, merger), under appropriate confidentiality and, for PHI, subject to HIPAA / contractual constraints
    We do not disclose subscriber information for unrelated third-party commercial advertising.

  6. Overseas disclosure and data location
    Primary clinical databases for the Services are hosted on Amazon Web Services in Asia Pacific (Sydney) / ap-southeast-2, Australia, including the API and PROMS databases.
    That means:
    For Australian customers, primary storage is in Australia, while some service providers outside Australia may still receive limited personal information to operate the Services.
    For US customers, PHI you submit is stored in Australia on our primary systems. HIPAA does not require US data residency; your BAA and our Security Rule safeguards still apply regardless of hosting location.
    In both cases, personal information (and, depending on configuration, PHI) may be disclosed to, and processed by, recipients outside Australia — for example SMS (Twilio), payments (Stripe), customer support tooling, error monitoring, email delivery, edge/CDN services, and (where enabled) AI providers. See the Trust Center.
    By using the Services, you acknowledge that overseas recipients may not be subject to the Privacy Act in the same way, and that remedies under the Privacy Act may differ. We take reasonable steps to ensure overseas recipients handle personal information consistently with our obligations, including contractual protections where appropriate (and BAAs where HIPAA requires them for PHI).

  7. Patient and individual rights requests
    Patients
    If you are a patient and believe your information was entered into SurgicalPerformance by your clinician or practice, please contact your clinician or practice first. They control that information as our customer (under the Australian Privacy Act as an APP entity where applicable, and/or as a US HIPAA Covered Entity where a BAA applies). We will support our customers in responding to access, correction, or deletion requests as required under applicable law and (for US PHI) the BAA.

    Subscribers and website visitors
    You may request access to, or correction of, personal information we hold about you, subject to the Privacy Act and other applicable law. Contact us using the details below.

    US state privacy rights (non-PHI)
    Some US state laws (for example California CCPA/CPRA) provide rights over certain personal information about consumers. Those rights may apply to information we collect from website visitors, marketing contacts, and prospective customers. They generally do not apply to PHI we process as a Business Associate under HIPAA. We do not sell personal information. To exercise applicable rights, contact us below.

  8. Research, benchmarking, and publications
    De-identified outcomes and related data may be used for research, audit, statistical analysis, product improvement, and peer benchmarking. Research outcomes are presented so that patients and, where stated in product features, individual subscribers or groups are not identifiable without authorisation.
    Intellectual property in research and publications produced by SurgicalPerformance remains with Surgical Performance Pty Ltd unless otherwise agreed in writing. Platform users are not entitled to authorship of SurgicalPerformance publications solely by virtue of using the Services. A formal process for third-party requests for de-identified data may apply — contact us.
    Identifiable patient information is not published.

  9. How we hold and protect information
    We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including health information and PHI. For a description of those safeguards and our incident response approach, see the HIPAA & Security Policy.
    We take reasonable steps to destroy or permanently de-identify personal information when it is no longer needed for the purpose of collection, subject to legal retention requirements and (for US PHI) BAA terms on return or destruction at termination.

  10. Cookies
    Our websites may place cookies or similar technologies on your device to operate the site, remember preferences, and understand usage. Marketing-site cookies do not contain clinical patient records. You can configure your browser to refuse cookies; some features may not work if you do.
    We use Google Analytics on our websites. See Google’s partner privacy information. You can control cookies via your browser settings; some features may not work if you decline cookies.

  11. Case Discussion Forum and user-generated content
    If you submit content to forums or shared discussion features, do not include unnecessary identifiers. We may review, alter, or remove content that appears to expose patient identity inappropriately or otherwise violates our Terms.

  12. Children and paediatric patients
    Accounts and marketing. SurgicalPerformance accounts and marketing are directed to healthcare professionals and practice staff (adults). We do not knowingly market the Services to children or allow children to create Subscriber accounts.

    Patient Data may include children. Cases and related clinical / PROMS information entered by Subscribers may relate to paediatric patients (including infants and children). That is an intended clinical use of the platform, not “marketing to children.”

    Where Patient Data or PROMS relates to a child, the Subscriber is responsible for complying with applicable law — including any required notices or consents from a parent or guardian, and rules about contacting or surveying minors. We process that information on the Subscriber’s instructions as described in this policy and (for US locations) the BAA.

  13. Changes to this policy
    We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last updated” date. Where changes materially affect how PHI or health information is handled, we will notify affected customers as required by law and any applicable BAA.

  14. Contact us
    Privacy enquiries: [email protected]
    Security / breach reports: [email protected]
    BAA / PHI contracting: [email protected]
    Surgical Performance Pty Ltd
    ABN 73 139 825 166

    If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner.

Surgical Performance Pty Ltd is very sensitive to the privacy needs of its website visitors and subscribers and is wholly committed to maintaining privacy at the highest level.

Surgical Performance Pty Ltd (“SurgicalPerformance,” “we,” “us”)
Effective date: 1 November 2011
Last updated: 31 July 2026

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our websites, register for or use the SurgicalPerformance platform (including the clinician App, API, PROMS patient surveys, and related services) (the “Services”).

In this policy, “you” means any individual about whom we collect personal information — including website visitors, subscribers (surgeons and practice staff), and, where relevant, patients who interact with PROMS.

We manage personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) (Privacy Act), and, where applicable, other laws that apply to us or to our customers (including US HIPAA when we act as a Business Associate).

  1. A note for US healthcare customers
    If you are a US-based healthcare provider or practice and you (or your patients) submit Protected Health Information (PHI) to the Services, that PHI is governed first by the Business Associate Agreement (BAA) between you and SurgicalPerformance, and by HIPAA.
    This Privacy Policy governs how we handle personal information about you as a website visitor and account holder (for example, name, email, billing details) and how we describe our general practices. It supplements — but does not replace — your BAA.
    When you create a US location, you must accept a BAA before entering patient data for that location. See our HIPAA & Security Policy and sample BAA.

  2. What information we collect
    2.1 Subscriber / account information
    We collect personal information you provide when you register, subscribe, or manage an account, which may include:
    Name, email address, username, and password
    Practice or specialty information, and area of practice
    Billing and payment-related details (payments are processed by Stripe; we do not store full card numbers)
    Communications you send to us (support requests, feedback)
    Optional profile or professional details you choose to provide

    2.2 Patient information (PHI / health information) — by design
    The Services are designed so that clinicians may enter identifiable patient information needed for outcomes tracking, follow-up, and PROMS. Depending on modules and configuration, this may include:
    Patient name
    Patient date of birth
    Patient identifiers (coded IDs, medical record numbers, or other codes you choose to enter)
    Procedure and clinical dates, and related clinical / outcomes data
    Contact details used for PROMS (for example phone number or email), where you enable patient messaging
    Survey responses and other information patients submit through PROMS
    Minimisation (recommended, not required): Where your clinical workflow allows, we encourage using an internal coded patient identifier rather than a widely used external identifier. This is a privacy-enhancing practice; it does not mean the platform requires patient data to be non-identifiable. Name, date of birth, and other identifiers are permitted product fields.
    You (the Subscriber — typically the surgeon or practice that controls the account) are responsible for having a lawful basis and any required patient notices or consents to enter patient information into the Services. For US locations, that includes your obligations as a HIPAA Covered Entity under your BAA.

    2.3 Usage and technical information
    We may collect:
    IP address, browser type, device type, operating system
    Pages visited, approximate location derived from IP, referring URLs
    Cookies and similar technologies (see Cookies below)
    Application logs and diagnostic data (see third-party error monitoring under Disclosures)

    2.4 Research and aggregated data
    We may create de-identified or aggregated datasets from platform data for benchmarking, product improvement, statistics, and research (including publication). Once information is de-identified so that it can no longer reasonably identify a patient, subscriber, or practice, it is no longer treated as personal information / PHI under this policy. See section 6.

  3. How we collect information
    Directly from you — registration, account settings, clinical data entry, support
    From patients — when they open a PROMS survey link (email/SMS) and submit responses
    Automatically — cookies, logs, analytics on websites and apps
    From payment and communication providers — as needed to process subscriptions and messages

  4. Why we collect and use personal information
    We collect and use personal information as reasonably necessary to:
    Provide, operate, secure, and improve the Services
    Authenticate users and manage subscriptions and billing
    Enable outcomes tracking, reporting, benchmarking, and PROMS follow-up
    Contact you about your account, security, and service changes
    Provide customer support
    Detect, investigate, and prevent fraud, abuse, and security incidents
    Comply with law and enforce our agreements
    Conduct de-identified research, audit, and product analytics as described in this policy
    With your consent, send optional marketing communications (you may unsubscribe)
    We do not sell subscriber performance data or patient information for third-party commercial marketing.
    Subscriber performance data confidentiality. Performance data relating to a subscriber will not be disclosed or made available to any party other than that subscriber without the subscriber’s express agreement, except where required by law, necessary to provide the Services (including subprocessors under contract), or as otherwise described in this policy / your BAA. Personnel and contractors are bound by confidentiality obligations. Subscribers remain free to share their own performance data with third parties (for example an employer) as they choose.

  5. Who we disclose personal information to
    We may disclose personal information to:
    Service providers (subprocessors) who help us run the Services — for example cloud hosting, SMS, email, payments, customer support tooling, error monitoring, and (where enabled) AI-assisted features. See the Trust Center for the current list. Where a provider handles PHI on our behalf for US customers, we require appropriate contractual safeguards (including BAAs where required).
    Professional advisers (legal, accounting) under confidentiality
    Regulators, courts, or law enforcement where required or permitted by law
    A buyer or successor in a business transaction (sale, merger), under appropriate confidentiality and, for PHI, subject to HIPAA / contractual constraints
    We do not disclose subscriber information for unrelated third-party commercial advertising.

  6. Overseas disclosure and data location
    Primary clinical databases for the Services are hosted on Amazon Web Services in Asia Pacific (Sydney) / ap-southeast-2, Australia, including the API and PROMS databases.
    That means:
    For Australian customers, primary storage is in Australia, while some service providers outside Australia may still receive limited personal information to operate the Services.
    For US customers, PHI you submit is stored in Australia on our primary systems. HIPAA does not require US data residency; your BAA and our Security Rule safeguards still apply regardless of hosting location.
    In both cases, personal information (and, depending on configuration, PHI) may be disclosed to, and processed by, recipients outside Australia — for example SMS (Twilio), payments (Stripe), customer support tooling, error monitoring, email delivery, edge/CDN services, and (where enabled) AI providers. See the Trust Center.
    By using the Services, you acknowledge that overseas recipients may not be subject to the Privacy Act in the same way, and that remedies under the Privacy Act may differ. We take reasonable steps to ensure overseas recipients handle personal information consistently with our obligations, including contractual protections where appropriate (and BAAs where HIPAA requires them for PHI).

  7. Patient and individual rights requests
    Patients
    If you are a patient and believe your information was entered into SurgicalPerformance by your clinician or practice, please contact your clinician or practice first. They control that information as our customer (under the Australian Privacy Act as an APP entity where applicable, and/or as a US HIPAA Covered Entity where a BAA applies). We will support our customers in responding to access, correction, or deletion requests as required under applicable law and (for US PHI) the BAA.

    Subscribers and website visitors
    You may request access to, or correction of, personal information we hold about you, subject to the Privacy Act and other applicable law. Contact us using the details below.

    US state privacy rights (non-PHI)
    Some US state laws (for example California CCPA/CPRA) provide rights over certain personal information about consumers. Those rights may apply to information we collect from website visitors, marketing contacts, and prospective customers. They generally do not apply to PHI we process as a Business Associate under HIPAA. We do not sell personal information. To exercise applicable rights, contact us below.

  8. Research, benchmarking, and publications
    De-identified outcomes and related data may be used for research, audit, statistical analysis, product improvement, and peer benchmarking. Research outcomes are presented so that patients and, where stated in product features, individual subscribers or groups are not identifiable without authorisation.
    Intellectual property in research and publications produced by SurgicalPerformance remains with Surgical Performance Pty Ltd unless otherwise agreed in writing. Platform users are not entitled to authorship of SurgicalPerformance publications solely by virtue of using the Services. A formal process for third-party requests for de-identified data may apply — contact us.
    Identifiable patient information is not published.

  9. How we hold and protect information
    We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including health information and PHI. For a description of those safeguards and our incident response approach, see the HIPAA & Security Policy.
    We take reasonable steps to destroy or permanently de-identify personal information when it is no longer needed for the purpose of collection, subject to legal retention requirements and (for US PHI) BAA terms on return or destruction at termination.

  10. Cookies
    Our websites may place cookies or similar technologies on your device to operate the site, remember preferences, and understand usage. Marketing-site cookies do not contain clinical patient records. You can configure your browser to refuse cookies; some features may not work if you do.
    We use Google Analytics on our websites. See Google’s partner privacy information. You can control cookies via your browser settings; some features may not work if you decline cookies.

  11. Case Discussion Forum and user-generated content
    If you submit content to forums or shared discussion features, do not include unnecessary identifiers. We may review, alter, or remove content that appears to expose patient identity inappropriately or otherwise violates our Terms.

  12. Children and paediatric patients
    Accounts and marketing. SurgicalPerformance accounts and marketing are directed to healthcare professionals and practice staff (adults). We do not knowingly market the Services to children or allow children to create Subscriber accounts.

    Patient Data may include children. Cases and related clinical / PROMS information entered by Subscribers may relate to paediatric patients (including infants and children). That is an intended clinical use of the platform, not “marketing to children.”

    Where Patient Data or PROMS relates to a child, the Subscriber is responsible for complying with applicable law — including any required notices or consents from a parent or guardian, and rules about contacting or surveying minors. We process that information on the Subscriber’s instructions as described in this policy and (for US locations) the BAA.

  13. Changes to this policy
    We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last updated” date. Where changes materially affect how PHI or health information is handled, we will notify affected customers as required by law and any applicable BAA.

  14. Contact us
    Privacy enquiries: [email protected]
    Security / breach reports: [email protected]
    BAA / PHI contracting: [email protected]
    Surgical Performance Pty Ltd
    ABN 73 139 825 166

    If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner.

Surgical Performance Pty Ltd is very sensitive to the privacy needs of its website visitors and subscribers and is wholly committed to maintaining privacy at the highest level.

Surgical Performance Pty Ltd (“SurgicalPerformance,” “we,” “us”)
Effective date: 1 November 2011
Last updated: 31 July 2026

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our websites, register for or use the SurgicalPerformance platform (including the clinician App, API, PROMS patient surveys, and related services) (the “Services”).

In this policy, “you” means any individual about whom we collect personal information — including website visitors, subscribers (surgeons and practice staff), and, where relevant, patients who interact with PROMS.

We manage personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) (Privacy Act), and, where applicable, other laws that apply to us or to our customers (including US HIPAA when we act as a Business Associate).

  1. A note for US healthcare customers
    If you are a US-based healthcare provider or practice and you (or your patients) submit Protected Health Information (PHI) to the Services, that PHI is governed first by the Business Associate Agreement (BAA) between you and SurgicalPerformance, and by HIPAA.
    This Privacy Policy governs how we handle personal information about you as a website visitor and account holder (for example, name, email, billing details) and how we describe our general practices. It supplements — but does not replace — your BAA.
    When you create a US location, you must accept a BAA before entering patient data for that location. See our HIPAA & Security Policy and sample BAA.

  2. What information we collect
    2.1 Subscriber / account information
    We collect personal information you provide when you register, subscribe, or manage an account, which may include:
    Name, email address, username, and password
    Practice or specialty information, and area of practice
    Billing and payment-related details (payments are processed by Stripe; we do not store full card numbers)
    Communications you send to us (support requests, feedback)
    Optional profile or professional details you choose to provide

    2.2 Patient information (PHI / health information) — by design
    The Services are designed so that clinicians may enter identifiable patient information needed for outcomes tracking, follow-up, and PROMS. Depending on modules and configuration, this may include:
    Patient name
    Patient date of birth
    Patient identifiers (coded IDs, medical record numbers, or other codes you choose to enter)
    Procedure and clinical dates, and related clinical / outcomes data
    Contact details used for PROMS (for example phone number or email), where you enable patient messaging
    Survey responses and other information patients submit through PROMS
    Minimisation (recommended, not required): Where your clinical workflow allows, we encourage using an internal coded patient identifier rather than a widely used external identifier. This is a privacy-enhancing practice; it does not mean the platform requires patient data to be non-identifiable. Name, date of birth, and other identifiers are permitted product fields.
    You (the Subscriber — typically the surgeon or practice that controls the account) are responsible for having a lawful basis and any required patient notices or consents to enter patient information into the Services. For US locations, that includes your obligations as a HIPAA Covered Entity under your BAA.

    2.3 Usage and technical information
    We may collect:
    IP address, browser type, device type, operating system
    Pages visited, approximate location derived from IP, referring URLs
    Cookies and similar technologies (see Cookies below)
    Application logs and diagnostic data (see third-party error monitoring under Disclosures)

    2.4 Research and aggregated data
    We may create de-identified or aggregated datasets from platform data for benchmarking, product improvement, statistics, and research (including publication). Once information is de-identified so that it can no longer reasonably identify a patient, subscriber, or practice, it is no longer treated as personal information / PHI under this policy. See section 6.

  3. How we collect information
    Directly from you — registration, account settings, clinical data entry, support
    From patients — when they open a PROMS survey link (email/SMS) and submit responses
    Automatically — cookies, logs, analytics on websites and apps
    From payment and communication providers — as needed to process subscriptions and messages

  4. Why we collect and use personal information
    We collect and use personal information as reasonably necessary to:
    Provide, operate, secure, and improve the Services
    Authenticate users and manage subscriptions and billing
    Enable outcomes tracking, reporting, benchmarking, and PROMS follow-up
    Contact you about your account, security, and service changes
    Provide customer support
    Detect, investigate, and prevent fraud, abuse, and security incidents
    Comply with law and enforce our agreements
    Conduct de-identified research, audit, and product analytics as described in this policy
    With your consent, send optional marketing communications (you may unsubscribe)
    We do not sell subscriber performance data or patient information for third-party commercial marketing.
    Subscriber performance data confidentiality. Performance data relating to a subscriber will not be disclosed or made available to any party other than that subscriber without the subscriber’s express agreement, except where required by law, necessary to provide the Services (including subprocessors under contract), or as otherwise described in this policy / your BAA. Personnel and contractors are bound by confidentiality obligations. Subscribers remain free to share their own performance data with third parties (for example an employer) as they choose.

  5. Who we disclose personal information to
    We may disclose personal information to:
    Service providers (subprocessors) who help us run the Services — for example cloud hosting, SMS, email, payments, customer support tooling, error monitoring, and (where enabled) AI-assisted features. See the Trust Center for the current list. Where a provider handles PHI on our behalf for US customers, we require appropriate contractual safeguards (including BAAs where required).
    Professional advisers (legal, accounting) under confidentiality
    Regulators, courts, or law enforcement where required or permitted by law
    A buyer or successor in a business transaction (sale, merger), under appropriate confidentiality and, for PHI, subject to HIPAA / contractual constraints
    We do not disclose subscriber information for unrelated third-party commercial advertising.

  6. Overseas disclosure and data location
    Primary clinical databases for the Services are hosted on Amazon Web Services in Asia Pacific (Sydney) / ap-southeast-2, Australia, including the API and PROMS databases.
    That means:
    For Australian customers, primary storage is in Australia, while some service providers outside Australia may still receive limited personal information to operate the Services.
    For US customers, PHI you submit is stored in Australia on our primary systems. HIPAA does not require US data residency; your BAA and our Security Rule safeguards still apply regardless of hosting location.
    In both cases, personal information (and, depending on configuration, PHI) may be disclosed to, and processed by, recipients outside Australia — for example SMS (Twilio), payments (Stripe), customer support tooling, error monitoring, email delivery, edge/CDN services, and (where enabled) AI providers. See the Trust Center.
    By using the Services, you acknowledge that overseas recipients may not be subject to the Privacy Act in the same way, and that remedies under the Privacy Act may differ. We take reasonable steps to ensure overseas recipients handle personal information consistently with our obligations, including contractual protections where appropriate (and BAAs where HIPAA requires them for PHI).

  7. Patient and individual rights requests
    Patients
    If you are a patient and believe your information was entered into SurgicalPerformance by your clinician or practice, please contact your clinician or practice first. They control that information as our customer (under the Australian Privacy Act as an APP entity where applicable, and/or as a US HIPAA Covered Entity where a BAA applies). We will support our customers in responding to access, correction, or deletion requests as required under applicable law and (for US PHI) the BAA.

    Subscribers and website visitors
    You may request access to, or correction of, personal information we hold about you, subject to the Privacy Act and other applicable law. Contact us using the details below.

    US state privacy rights (non-PHI)
    Some US state laws (for example California CCPA/CPRA) provide rights over certain personal information about consumers. Those rights may apply to information we collect from website visitors, marketing contacts, and prospective customers. They generally do not apply to PHI we process as a Business Associate under HIPAA. We do not sell personal information. To exercise applicable rights, contact us below.

  8. Research, benchmarking, and publications
    De-identified outcomes and related data may be used for research, audit, statistical analysis, product improvement, and peer benchmarking. Research outcomes are presented so that patients and, where stated in product features, individual subscribers or groups are not identifiable without authorisation.
    Intellectual property in research and publications produced by SurgicalPerformance remains with Surgical Performance Pty Ltd unless otherwise agreed in writing. Platform users are not entitled to authorship of SurgicalPerformance publications solely by virtue of using the Services. A formal process for third-party requests for de-identified data may apply — contact us.
    Identifiable patient information is not published.

  9. How we hold and protect information
    We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including health information and PHI. For a description of those safeguards and our incident response approach, see the HIPAA & Security Policy.
    We take reasonable steps to destroy or permanently de-identify personal information when it is no longer needed for the purpose of collection, subject to legal retention requirements and (for US PHI) BAA terms on return or destruction at termination.

  10. Cookies
    Our websites may place cookies or similar technologies on your device to operate the site, remember preferences, and understand usage. Marketing-site cookies do not contain clinical patient records. You can configure your browser to refuse cookies; some features may not work if you do.
    We use Google Analytics on our websites. See Google’s partner privacy information. You can control cookies via your browser settings; some features may not work if you decline cookies.

  11. Case Discussion Forum and user-generated content
    If you submit content to forums or shared discussion features, do not include unnecessary identifiers. We may review, alter, or remove content that appears to expose patient identity inappropriately or otherwise violates our Terms.

  12. Children and paediatric patients
    Accounts and marketing. SurgicalPerformance accounts and marketing are directed to healthcare professionals and practice staff (adults). We do not knowingly market the Services to children or allow children to create Subscriber accounts.

    Patient Data may include children. Cases and related clinical / PROMS information entered by Subscribers may relate to paediatric patients (including infants and children). That is an intended clinical use of the platform, not “marketing to children.”

    Where Patient Data or PROMS relates to a child, the Subscriber is responsible for complying with applicable law — including any required notices or consents from a parent or guardian, and rules about contacting or surveying minors. We process that information on the Subscriber’s instructions as described in this policy and (for US locations) the BAA.

  13. Changes to this policy
    We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last updated” date. Where changes materially affect how PHI or health information is handled, we will notify affected customers as required by law and any applicable BAA.

  14. Contact us
    Privacy enquiries: [email protected]
    Security / breach reports: [email protected]
    BAA / PHI contracting: [email protected]
    Surgical Performance Pty Ltd
    ABN 73 139 825 166

    If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner.

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.

SurgicalPerformance is a confidential online platform, built for surgeons by surgeons, to help you ‘know better’.