This Privacy Policy describes how SurfMed ("SurfMed," "we," "us," or "our") handles information in connection with the SurfMed Portal mobile applications for iOS and Android (the "App") and the related web portal and services (together, the "Service"). The App is a companion to the SurfMed web portal and provides the same functionality in a native, installable form.
The SurfMed Portal is a professional tool for authorized users — personnel of healthcare providers, suppliers, and partner organizations that have an account with SurfMed. It is not a general-consumer application and is not intended for use by patients or the public.
Sign-in is handled through Microsoft Azure Active Directory B2C. When you log in, we process identifiers associated with your account, which may include your name, work email address, organization, and the role or group memberships that determine what you may access within the Service. We do not see or store your password; authentication is performed by the identity provider.
To keep you signed in securely, the App stores authentication tokens issued by the identity provider on your device using the operating system's secure storage. If you enable biometric unlock (Face ID, Touch ID, or fingerprint), the device's biometric system is used locally to protect that cached session.
Depending on your role, the Service displays business records such as patients, orders, shipping and tracking details, metrics, and reports. This information is provided by, and managed on behalf of, the provider organizations that use the Service.
We collect limited technical information needed to operate, secure, and improve the Service, such as device and operating-system type, app version, language settings, and diagnostic, performance, and error logs (for example, through Microsoft Azure Monitor). We also use Google Analytics to collect aggregate product-usage events, such as sign-in and feature use, to understand how the Service is used and to improve it. This data is used for reliability, security monitoring, product improvement, and troubleshooting.
If you enable biometric unlock, your fingerprint or facial-recognition data never leaves your device and is never accessible to, transmitted to, or stored by SurfMed. The biometric check is performed entirely by your device's operating system; SurfMed only receives a yes/no result indicating whether the unlock succeeded.
We do not use your information for advertising, and we do not sell or rent personal information. The App does not track you across other companies' apps or websites and does not use advertising identifiers.
We share information only as needed to operate the Service:
| Recipient | Purpose |
|---|---|
| Microsoft Azure (cloud hosting, Azure AD B2C, Azure Monitor) | Hosting, authentication, telemetry, and diagnostics. |
| Brightree | Source-of-record system for patient and order data surfaced in the Service. |
| ShipEngine | Address validation and shipment tracking. |
| Email delivery provider (SendGrid) | Sending transactional and service email. |
| Google Analytics | Aggregate usage analytics to understand feature use and improve the Service. |
| Apple and Google | App distribution and platform services for the iOS and Android apps. |
We may also disclose information:
Service providers act on our instructions under contractual confidentiality and security obligations, including Business Associate Agreements where PHI is involved.
Where the Service involves PHI, SurfMed generally acts as a Business Associate of the provider organizations (which are the Covered Entities), and processes PHI only as permitted by the applicable Business Associate Agreement and HIPAA. If you are a patient and have questions about your health information, please contact your healthcare provider, who controls that information. This Privacy Policy does not replace any notice of privacy practices issued by your provider.
We use administrative, technical, and physical safeguards designed to protect information, including encryption of data in transit (HTTPS/TLS), authentication through Azure AD B2C, secure on-device token storage, optional biometric protection, role-based access controls, and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
We retain information for as long as needed to provide the Service, comply with our legal and contractual obligations, resolve disputes, and enforce our agreements. Business and health records are retained according to the requirements of the provider organization and applicable law. Authentication tokens stored on your device are cleared when you sign out or uninstall the App.
The Service is intended for authorized professional users and is not directed to children. We do not knowingly collect personal information directly from children through the App. Patient information that may relate to a minor is handled on behalf of, and under the direction of, the relevant provider organization.
The App requests only the access it needs to function:
The Service is operated from, and information is processed in, the United States. If you access the Service from outside the United States, you understand that your information may be processed in the United States, where data-protection laws may differ from those in your location.
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy.
If you have questions or requests regarding this Privacy Policy or your information, contact us at:
SurfMed
Email: privacy@surfmed.com
Web: https://www.surfmed.com