Privacy policy
Pending legal review. This is a working draft written to the structure of Australian Privacy Principle 1. It is not yet in force and may change before the beta opens.
SonoCred is a logbook for clinicians. It holds your account and your de-identified scan entries. It is built so that it cannot hold information that identifies a patient.
Contents
- 1. Who we are
- 2. The short version
- 3. What we collect
- 4. What we never collect
- 5. Why we collect it
- 6. Who sees it
- 7. Where it is stored
- 8. How it is protected
- 9. How long we keep it
- 10. Access, correction and deletion
- 11. Data breaches
- 12. Educational purpose
- 13. Users outside Australia
- 14. Age
- 15. Complaints
- 16. Changes to this policy
- 17. Contact
1. Who we are
SonoCred and this website are operated by Taylor Med Pty Ltd, an Australian company. In this policy "we", "us" and "our" mean Taylor Med Pty Ltd. "The app" means the SonoCred apps for iPhone, Android and the web. "You" means the clinician who holds an account, or a visitor to this website.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy is written to the structure of APP 1. Questions go to [email protected].
2. The short version
- We collect your name, email, role and hospital so that you can sign in and your supervisors can find you.
- We store your logbook entries. They describe scans by age band, gender at birth, module, views and findings. They do not identify the patient.
- We never store a patient's name, MRN, date of birth, IHI or Medicare number. The database has no fields for them and rejects them if they appear in free text.
- If you choose to keep an MRN or date of birth for your own follow-up, it lives in an encrypted vault on your phone. We cannot read it and it is never sent to us.
- Everything is hosted in Sydney, Australia.
- We do not sell data, run advertising, or use analytics trackers.
- You can see, correct and delete your data at any time.
3. What we collect
3.1 Your account
When you create an account we collect your name, email address, your role as trainee, supervisor or ultrasound lead, your hospital or department, and your country. Sign-in credentials are handled by our authentication provider. We store a hashed password or a sign-in token, never the password itself.
3.2 Your logbook entries
Each entry records the date of the scan, the patient's age band and gender at birth, the module, the views obtained and whether each was adequate, the findings and your interpretation, a short clinical history in free text, the follow-up result and your reflection, whether the scan was proctored and by whom, and your supervisor's review. Formative and summative assessment records hold the module, the date, the assessor's name, the checklist answers and the outcome.
Free text is screened on your phone before upload, and again by the database when it is written. Text that looks like an MRN, a UR number, a date of birth or a phone number is refused. This is described in section 4.
3.3 The beta interest list
If you fill in the form on this website we collect your name, email, role, hospital, country and any message you write. We use it only to invite you to the beta.
3.4 Support email
When you email us we keep the correspondence so that we can help you and so that we have a record of what was agreed. Please do not include patient identifiers or ultrasound images in support emails. If you do, we will delete them.
3.5 Technical information
This website sets no cookies and uses no analytics. The app contains no advertising or analytics software. Our hosting provider keeps standard server logs, which include the IP address, time and address of each request, for security and fault finding. These logs are kept for 30 days. The app keeps a local copy of your logbook on your device so that it works without signal.
4. What we never collect
The app is designed so that patient identifiers cannot enter the cloud.
- There are no database fields for a patient's name, MRN or UR number, date of birth, address, phone number, Individual Healthcare Identifier or Medicare number.
- A database trigger reads every free-text field before it is written. If it finds a pattern that looks like one of these identifiers, the write is refused and you are asked to remove it. The app runs the same screen on your device before anything uploads.
- The date of birth you enter on the phone is converted to an age band on the phone. Only the band, for example 60 to 69, is uploaded.
- The web version of the app has no fields for an MRN or a date of birth at all.
- No ultrasound images or video loops are collected in this version of the app.
If you choose to record an MRN or a date of birth on your phone so that you can find the patient for the 48-hour follow-up, that information is stored in an encrypted vault on the phone, using the iOS Keychain or the Android Keystore. It is not synced to us, it is excluded from cloud backups run by us, and we have no way to read it. You hold it, not us. Your employer's policies about patient information on personal devices apply to it, and the app prompts you to purge it once the module is signed off.
If, despite these controls, identifying information reaches us, we treat it as unsolicited personal information under APP 4. We will destroy it or de-identify it as soon as we find it, and we may suspend the account that supplied it.
5. Why we collect it
We collect and use your information to:
- run your logbook and sync it between your devices;
- show your entries to the supervisors you nominate and to your department's ultrasound lead, so that they can review, assess and sign them off;
- count your entries against the ACEM and ASUM module thresholds and produce summaries for your department's credentialling committee;
- invite you to the beta and tell you about changes to the app that affect you;
- answer your support requests;
- keep the service secure and find faults;
- meet our legal obligations.
We do not use your information for advertising. We do not sell it or rent it. We do not build profiles for marketing. We will not use it for research without asking you first, and any research would use de-identified, aggregated data only.
6. Who sees it
- Your supervisors and department. Supervisors you nominate can see your entries and sign them. Your department's ultrasound lead can see the progress of every trainee in the department and the sign-off queue. Other trainees cannot see your entries. Leaderboard features, if enabled by your department, show only your display name, rank and counts.
- Service providers. Our database, authentication and file hosting run on Supabase in its Sydney region, which runs on Amazon Web Services in Sydney. Transactional email is sent by an email provider on our behalf. These providers process data only on our instructions. We do not use any provider that would take data outside Australia.
- Where the law requires. We will disclose information if a court, regulator or law requires it. We will tell you if we are allowed to.
- A change of ownership. If Taylor Med Pty Ltd sells or transfers the app, your information may be transferred to the new operator under this policy. We would tell you before it happened.
7. Where it is stored
Your account and logbook data are stored in Sydney, Australia. We do not disclose personal information to overseas recipients and we do not intend to. If that ever changes, we will update this policy before it does and comply with APP 8. Our hosting providers have parent companies in the United States; the data itself stays in the Sydney region.
8. How it is protected
- Data is encrypted in transit and at rest.
- Row-level security in the database means each account can read only its own entries and those it has been granted, and supervisors only the trainees who nominated them.
- Multi-factor authentication is available for every account and required for supervisor and ultrasound lead accounts.
- Access by our staff is limited to what is needed to run the service and is logged.
- Identifier screening runs on the device and in the database, as described in section 4.
- Nothing that identifies a patient is written to our logs, error reports or backups, because none of it reaches our systems.
- The on-device vault is protected by your phone's own hardware-backed encryption and by your device passcode or biometrics.
No system is perfectly secure. Section 11 describes what we do if something goes wrong.
9. How long we keep it
- Account and logbook data. Kept while your account is open. When you close your account we delete it within 30 days. Encrypted backups roll off within a further 30 days.
- Signed attestations. A department that has relied on your signed entries for a credentialling decision keeps its own record of that decision. We do not keep a copy for the department once you delete your account.
- Beta interest list. Deleted when the beta ends or when you ask, whichever is sooner.
- Support email. Kept for two years after the matter is closed.
- Server logs. 30 days.
Before you close your account, export your logbook. Your hospital may require you to keep credentialling evidence for a set period, and that is your responsibility.
10. Access, correction and deletion
You can see and correct your account details and your entries in the app at any time. You can delete an entry, and you can delete your whole account from Settings. If you would rather email, write to [email protected]. We will confirm your identity, then act within 30 days. There is no charge.
If we refuse a request, which we expect to be rare, we will tell you why in writing and how to complain.
11. Data breaches
We are part of the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If we suspect a data breach that is likely to cause serious harm, we will assess it within 30 days, contain it, notify the Office of the Australian Information Commissioner, and notify the people affected, telling them what happened and what to do.
Because the cloud holds no patient identifiers, a breach of our systems would expose clinician account details and de-identified logbook entries. It would not expose a patient's identity.
12. Educational purpose
The app is a training logbook. It records what you scanned, what you found and what your supervisor attested, for the purpose of credentialling. It does not analyse a patient's images, it does not give diagnostic feedback about a patient, and it must not be used to make decisions about a patient's care. It is not a medical device within the meaning of section 41BD of the Therapeutic Goods Act 1989 (Cth), and it is not intended to be one in any other country. If a future feature would change that, we will say so and seek the appropriate approvals first.
13. Users outside Australia
The Privacy Act follows us wherever our users are. In addition:
- New Zealand. If you use the app from New Zealand, the Privacy Act 2020 (NZ) also applies to us. The rights in section 10 are the same. Complaints can go to the Office of the Privacy Commissioner, privacy.org.nz.
- United Kingdom and European Union. If you use the app from the UK or the EU, we act as the controller of your account data. Our lawful basis is the contract with you and our legitimate interest in running the service. You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your supervisory authority. During the beta we have not appointed a UK or EU representative; we will before offering the app there generally.
- Everywhere. Patient data is your hospital's responsibility under your local law. The app is designed so that no patient identifier reaches us from any country.
14. Age
The app is for medical practitioners and trainees. You must be at least 18 to hold an account. We do not knowingly collect information from anyone younger, and we will delete it if we learn that we have.
15. Complaints
If you think we have mishandled your information, email [email protected] with the word Privacy in the subject. We will acknowledge your complaint within seven days and respond within 30. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
16. Changes to this policy
We will update this policy as the app changes. The version and date are at the top. If a change affects how we use your information, we will email account holders at least 14 days before it takes effect.
17. Contact
Taylor Med Pty Ltd, Australia
[email protected]