SurfMed Portal — Privacy Policy

Effective date: June 16, 2026  ·  Last updated: July 7, 2026

This Privacy Policy describes how SurfMed ("SurfMed," "we," "us," or "our") handles information in connection with the SurfMed Portal mobile applications for iOS and Android (the "App") and the related web portal and services (together, the "Service"). The App is a companion to the SurfMed web portal and provides the same functionality in a native, installable form.

The SurfMed Portal is a professional tool for authorized users — personnel of healthcare providers, suppliers, and partner organizations that have an account with SurfMed. It is not a general-consumer application and is not intended for use by patients or the public.

Health information. When authorized users access patient or order information through the Service, that information may include protected health information ("PHI"). SurfMed handles such information on behalf of the provider organizations that use the Service, consistent with the Health Insurance Portability and Accountability Act ("HIPAA") and applicable Business Associate Agreements. See "Health Information and HIPAA" below.

1. Information We Collect

1.1 Account and identity information

Sign-in is handled through Microsoft Azure Active Directory B2C. When you log in, we process identifiers associated with your account, which may include your name, work email address, organization, and the role or group memberships that determine what you may access within the Service. We do not see or store your password; authentication is performed by the identity provider.

1.2 Authentication and session data

To keep you signed in securely, the App stores authentication tokens issued by the identity provider on your device using the operating system's secure storage. If you enable biometric unlock (Face ID, Touch ID, or fingerprint), the device's biometric system is used locally to protect that cached session.

1.3 Business and health information accessed in the App

Depending on your role, the Service displays business records such as patients, orders, shipping and tracking details, metrics, and reports. This information is provided by, and managed on behalf of, the provider organizations that use the Service.

1.4 Device and diagnostic information

We collect limited technical information needed to operate, secure, and improve the Service, such as device and operating-system type, app version, language settings, and diagnostic, performance, and error logs (for example, through Microsoft Azure Monitor). We also use Google Analytics to collect aggregate product-usage events, such as sign-in and feature use, to understand how the Service is used and to improve it. This data is used for reliability, security monitoring, product improvement, and troubleshooting.

1.5 Biometric data

If you enable biometric unlock, your fingerprint or facial-recognition data never leaves your device and is never accessible to, transmitted to, or stored by SurfMed. The biometric check is performed entirely by your device's operating system; SurfMed only receives a yes/no result indicating whether the unlock succeeded.

2. How We Use Information

We do not use your information for advertising, and we do not sell or rent personal information. The App does not track you across other companies' apps or websites and does not use advertising identifiers.

3. How Information Is Shared

We share information only as needed to operate the Service:

RecipientPurpose
Microsoft Azure (cloud hosting, Azure AD B2C, Azure Monitor)Hosting, authentication, telemetry, and diagnostics.
BrightreeSource-of-record system for patient and order data surfaced in the Service.
ShipEngineAddress validation and shipment tracking.
Email delivery provider (SendGrid)Sending transactional and service email.
Google AnalyticsAggregate usage analytics to understand feature use and improve the Service.
Apple and GoogleApp distribution and platform services for the iOS and Android apps.

We may also disclose information:

Service providers act on our instructions under contractual confidentiality and security obligations, including Business Associate Agreements where PHI is involved.

4. Health Information and HIPAA

Where the Service involves PHI, SurfMed generally acts as a Business Associate of the provider organizations (which are the Covered Entities), and processes PHI only as permitted by the applicable Business Associate Agreement and HIPAA. If you are a patient and have questions about your health information, please contact your healthcare provider, who controls that information. This Privacy Policy does not replace any notice of privacy practices issued by your provider.

5. Data Security

We use administrative, technical, and physical safeguards designed to protect information, including encryption of data in transit (HTTPS/TLS), authentication through Azure AD B2C, secure on-device token storage, optional biometric protection, role-based access controls, and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

6. Data Retention

We retain information for as long as needed to provide the Service, comply with our legal and contractual obligations, resolve disputes, and enforce our agreements. Business and health records are retained according to the requirements of the provider organization and applicable law. Authentication tokens stored on your device are cleared when you sign out or uninstall the App.

7. Your Choices and Rights

8. Children's Privacy

The Service is intended for authorized professional users and is not directed to children. We do not knowingly collect personal information directly from children through the App. Patient information that may relate to a minor is handled on behalf of, and under the direction of, the relevant provider organization.

9. App Permissions

The App requests only the access it needs to function:

10. International Users

The Service is operated from, and information is processed in, the United States. If you access the Service from outside the United States, you understand that your information may be processed in the United States, where data-protection laws may differ from those in your location.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy.

12. Contact Us

If you have questions or requests regarding this Privacy Policy or your information, contact us at:

SurfMed
Email: privacy@surfmed.com
Web: https://www.surfmed.com