TL
TheatreLink
SecuritySign In

Privacy Policy

Effective Date: 16 May 2026  |  Last Reviewed: 16 May 2026  |  Version: 2.0

TheatreLink Pty Ltd (“TheatreLink”, “we”, “us”, “our”) is committed to protecting the privacy of personal and health information in accordance with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and applicable state-based health record legislation. This policy explains how we collect, use, store, and disclose personal information through our operating theatre management platform.

1. About TheatreLink

TheatreLink is an Australian operating theatre scheduling, coordination, and admissions platform designed for hospitals, surgeons, anaesthetists, practice managers, theatre managers, and admissions officers. The platform facilitates theatre bookings, session scheduling, equipment coordination, workforce management, and — for hospitals that have enabled the optional Admissions & Consent module — digital patient admissions and procedure consent workflows.

TheatreLink is not an electronic health record (EHR) system, is not a system of record for clinical care, and does not participate in or connect to the Australian Government’s My Health Record system. The hospital’s patient administration system (PAS) remains the source of truth for patient care records. TheatreLink captures booking and admissions data at the point of origin and supports the hospital’s existing workflows.

2. Information We Collect

We collect personal information that is reasonably necessary for the operation of the platform. The types of information we may collect include:

Account Information

  • Full name, email address, and mobile phone number
  • Professional role (e.g. surgeon, anaesthetist, theatre manager, practice manager, admissions officer)
  • AHPRA registration number (for practitioner verification purposes only)
  • Hospital affiliations and departmental associations

Authentication & Security Data

  • Hashed passwords (bcrypt, never stored in plaintext)
  • Multi-factor authentication (MFA) secrets
  • WebAuthn/biometric credential identifiers
  • Device trust tokens
  • Login timestamps and session data

Operational Data

  • Theatre booking details (procedure descriptions, scheduling, equipment requirements)
  • Session and roster information
  • Uploaded accreditation documents
  • Communication preferences and notification settings
  • Audit logs of significant actions performed by users in the platform

Patient Personal & Health Information (where applicable)

Where a hospital has enabled the Admissions & Consent module, or where the “Allow Confidential Patient Information” setting has been activated, TheatreLink may collect and process the following categories of patient information on behalf of the hospital:

  • Demographic details: patient name, date of birth, residential address, suburb, state, postcode, mobile phone, email
  • Identifiers: hospital-issued Medical Record Number (MRN), private-health-fund member number
  • Clinical information collected via the admissions booklet: medical history, current medications, allergies, anaesthetic history, social history (smoking, alcohol, occupation), and similar information requested by the hospital’s admission template
  • Family / next of kin: name, relationship, contact number
  • Procedure consent artifacts: typed name, canvas-drawn signature, ticked checkbox responses, witness details where required, and the resulting signed consent PDF
  • Audit and integrity metadata: IP address, browser user agent, device fingerprint hash, and RFC 3161 timestamp tokens collected solely to evidence the validity of the signing event

The schema of the admissions booklet is configured per hospital, may be amended by the hospital, and is frozen at the point an individual patient is invited to complete it (so that mid-process schema changes do not affect any patient already in flight).

Patient personal and health information is held under strict access controls, encrypted at the record level (see Section 6), and is accessed only by authorised users at the patient’s hospital for purposes directly related to the patient’s admission, procedure, and treatment. The hospital remains the data custodian.

Information We Do Not Collect

Except where collected through the Admissions & Consent module described above, users are instructed not to enter identifiable patient information into the platform. Where a hospital has not enabled the module, the platform’s operational data (bookings, sessions, rosters) is intended to contain only procedure descriptions, scheduling details, equipment requirements, and other operational metadata.

TheatreLink does not collect:

  • Tax file numbers, driver licence numbers, or other government identifiers not listed above
  • Medicare numbers or Individual Healthcare Identifiers (IHI) — unless the hospital’s PAS integration is activated and the patient has consented; the integration is currently planned but not yet built
  • Genetic or biometric information beyond the canvas-drawn signature and one-way device fingerprint hash referenced above
  • Personal information about non-users for marketing or research purposes

3. How We Collect Information

We collect personal information directly from individuals when they:

  • Register for a TheatreLink account (or are registered by their hospital administrator)
  • Update their profile or account settings
  • Upload documents (e.g. accreditation certificates)
  • Create or modify theatre bookings and sessions
  • Contact us for support

We do not collect personal information from third parties unless it is provided by an authorised hospital administrator for the purposes of user provisioning.

4. How We Use Your Information

We use personal information for the following purposes:

  • Platform Operation: Managing user accounts, authenticating access, and providing the theatre scheduling service
  • Communication: Sending booking confirmations, session notifications, schedule changes, and system alerts via email and SMS
  • Security: Monitoring for unauthorised access, enforcing rate limits, and maintaining audit logs
  • Professional Verification: Verifying practitioner credentials using AHPRA registration numbers
  • Admissions & Consent (where the module is enabled by a hospital): Receiving completed patient admissions booklets, producing the resulting PDF artifact for the hospital’s admissions officer, capturing patient (and where required, witness) procedure consent, and producing the signed consent envelope
  • Audit & Integrity: Producing tamper-evident hash-chained audit trails of admissions and consent events, anchored quarterly to an external RFC 3161 timestamp authority (FreeTSA in non-production; DigiCert in production)
  • Platform Improvement: Analysing aggregated, de-identified usage data to improve platform features and performance. Patient health information is excluded from analytics payloads.
  • Legal Compliance: Meeting obligations under the Privacy Act 1988, applicable state-based health record legislation, and other applicable laws

We do not use personal information for direct marketing. All communications are operational and directly related to your use of the platform.

5. Disclosure of Information

We do not sell, rent, or trade personal information. We may disclose personal information in the following limited circumstances:

  • Within your hospital network: Theatre managers can see booking details for their hospital. Surgeons and practice managers can see their own bookings and relevant scheduling information.
  • Service providers: We use trusted third-party services to operate the platform (see Section 7 — Cross-Border Disclosure).
  • Legal requirements: Where required or authorised by Australian law, a court order, or to prevent a serious threat to life, health, or safety.

Access within the platform is controlled by role-based access controls — users can only view information relevant to their role and hospital affiliation.

6. How We Protect Your Information

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure. Our security measures include:

  • Encryption in transit: All connections use TLS 1.3 encryption
  • Encryption at rest: Database and file storage are encrypted using AES-256
  • Record-level envelope encryption for patient health information: Where the Admissions & Consent module is enabled, each patient record, booklet answer set, signed consent envelope, and uploaded clinical document is encrypted with a per-record Data Encryption Key (DEK), wrapped by a master key held in a managed Key Management Service. Plaintext patient health information never leaves the encryption boundary except in memory during an authorised access.
  • One-way lookup hashes: Where patient records must be matched (e.g. by name + date of birth), HMAC-SHA256 hashes are used so the platform can identify candidate matches without decrypting the underlying record.
  • Hash-chained audit trail: Admissions and consent events (view, save-step, submit, sign, witness, withdrawal) are appended to a hash-chained audit log so that any tampering is detectable. The chain is anchored quarterly to an external RFC 3161 timestamp authority.
  • Cryptographically-signed consent payloads: At the moment a patient or witness signs a consent form, a canonical representation of the consent is signed using the managed Key Management Service to support non-repudiation.
  • Tokenised patient links with a second factor: Patient-facing admissions and consent invitations are delivered as single-use, short-lived tokenised links protected by a second factor (date of birth + postcode) before any health information is revealed.
  • Tenant scoping with defence-in-depth checks: Every server-side request is checked against the requester’s role and the resource’s owning hospital; document streams additionally verify that the requested document belongs to a patient associated with the calling user’s case before any decryption is performed.
  • Password security: Passwords are hashed using bcrypt with 12 salt rounds and are never stored in plaintext
  • Multi-factor authentication: TOTP-based MFA and WebAuthn/biometric authentication are supported and can be enforced
  • Session management: Configurable session timeouts with automatic expiry
  • Rate limiting: Login attempts are rate-limited to prevent brute-force attacks
  • Role-based access control: Portal-based access segregation ensures users only see data relevant to their role
  • Security monitoring: Error tracking with PII scrubbing, plus security audit tooling, monitor for anomalous activity
  • Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, and strict referrer policies are enforced

7. Cross-Border Disclosure & Third-Party Services

TheatreLink uses the following third-party service providers to operate the platform. Some of these providers may process data outside of Australia:

ServicePurposeData Location
VercelApplication hosting and deploymentSydney (ap-southeast-2)
Neon (PostgreSQL)Primary databaseAWS Sydney
Vercel BlobEncrypted document storageSydney region
ResendTransactional email deliveryUnited States
TwilioSMS notificationsUnited States (processing)
PusherReal-time WebSocket connectionsap-southeast-2
SentryError monitoring (PII scrubbed)United States
AnthropicAI-powered document parsingUnited States (processing)

Where data is processed overseas, we take reasonable steps to ensure the recipient handles information in accordance with the APPs. All connections to third-party services use encrypted channels. We do not disclose identifiable patient information to any third party.

8. Government Identifiers

TheatreLink collects AHPRA registration numbers for the sole purpose of verifying healthcare practitioner credentials. We do not:

  • Use AHPRA numbers as internal identifiers or database keys
  • Disclose AHPRA numbers to other users except where relevant to accreditation processes
  • Collect Medicare numbers, tax file numbers, or other patient government identifiers

9. Data Quality & Retention

We take reasonable steps to ensure personal information is accurate, up-to-date, and complete. Users can update their profile information at any time through their account settings. Where the Admissions & Consent module is in use, the patient enters their own demographic and medical history information directly; the hospital’s admissions officer is responsible for verifying and, where necessary, correcting that information at the time of admission.

We retain personal information for as long as it is needed for the purposes described in this policy or as required by law. When information is no longer needed, we take reasonable steps to destroy or de-identify it. Expired authentication tokens and verification codes are automatically cleaned up.

Retention horizons

  • Account information: retained for the life of the account, then deleted within 30 days of account closure unless a longer retention is required by law
  • Booking and session records: retained for the period required by the hospital’s clinical record policy (typically 7 years) and any longer period required by state-based health record legislation
  • Signed consent envelopes (where the consent module is enabled): retained for the medico-legal record retention period required by the relevant state legislation, which may be 7 to 25 years depending on the procedure and the patient’s state of treatment
  • Patient admissions booklet artifacts (where the booklet module is enabled): retained alongside the patient’s hospital record per the hospital’s clinical record retention policy
  • Audit logs of patient-information access: retained for 7 years for tamper-evidence and regulatory purposes
  • Other audit logs: retained on a tiered schedule (typically 90 days for authentication events, 1 year for non-PHI administrative events)
  • Authentication tokens and verification codes: deleted automatically after expiry (typically 7 days or shorter)

Accounts that have been inactive for an extended period may be flagged for review and deactivation by system administrators.

10. Accessing Your Information

You have the right to request access to the personal information we hold about you. You can:

  • Self-service: View and update your profile information, notification preferences, and uploaded documents through your TheatreLink account
  • Formal request: Submit a written request to our Privacy Officer to receive a copy of all personal information held about you

If you are a patient seeking access to admissions or consent information held about you, the hospital where you received care is the primary point of contact and the data custodian for those records. We will support the hospital’s response to your request. You may also contact our Privacy Officer directly using the details in Section 17.

We will respond to access requests within 30 days. In limited circumstances, we may refuse access where permitted by the Privacy Act (for example, where providing access would unreasonably impact the privacy of other individuals).

11. Correcting Your Information

If you believe any personal information we hold about you is inaccurate, out-of-date, incomplete, or misleading, you may:

  • Update your own profile details through your account settings
  • Contact your hospital administrator to correct booking or scheduling records
  • Submit a formal correction request to our Privacy Officer

If we correct information that was previously disclosed to a third party, we will take reasonable steps to notify them of the correction.

12. Data Breach Notification

In accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act, TheatreLink will:

  • Take immediate steps to contain and assess any suspected data breach
  • Notify the Office of the Australian Information Commissioner (OAIC) and affected individuals of eligible data breaches that are likely to result in serious harm
  • Provide notification as soon as practicable and no later than 30 days after becoming aware of a breach
  • Include in notifications: a description of the breach, the type of information involved, and recommended steps individuals should take

13. Anonymity & Pseudonymity

Under the Privacy Act, individuals have the right to deal with organisations anonymously or using a pseudonym where practicable. Due to the nature of TheatreLink as a healthcare coordination platform, identification is required for:

  • Patient safety and clinical accountability in surgical scheduling, admissions, and consent
  • Professional credential verification (AHPRA)
  • Hospital access control and accreditation compliance
  • The legal validity of an electronically-signed procedure consent under the Electronic Transactions Act 1999 (Cth) and state equivalents

This is permitted under APP 2.2(a) where identification is required by law or where it is impracticable to deal with individuals anonymously.

14. Admissions & Consent Module — Additional Information

Where your hospital has activated the Admissions & Consent module, the following additional information applies in relation to your admissions booklet, your procedure consent, and the way that information flows between you, the hospital, and TheatreLink.

Role of TheatreLink and the hospital

The hospital is the data custodian for your admissions and consent records. TheatreLink processes that information on the hospital’s behalf, in accordance with the hospital’s configured workflows. The hospital’s information governance policies, retention rules, and complaint processes apply alongside this Privacy Policy.

Tokenised links and second factor

You will receive a tokenised link to your admissions booklet and/or consent form by SMS and email. Before any health information can be viewed or entered, you are asked to verify two factors of identity (typically date of birth and postcode). The link is single-use and expires within a short window. If you lose your link, contact the hospital’s admissions team for a fresh link rather than forwarding the original.

Witness signatures

Where the procedure or hospital policy requires a witness, the witness signs on the same device immediately after you do. The witness is asked to type their name and add a canvas signature; the device’s identity factor is retained as evidence that the signing took place on the same device used for your factor verification.

Withdrawal of consent

You may withdraw your consent at any time before the procedure. Contact your hospital’s admissions team as the primary point of contact, or email privacy@theatrelink.com.au. Where a consent envelope has already been signed, the original signed artifact is retained as evidence of the consent state at signing time, with a clearly-recorded withdrawal event appended to the audit chain.

Tamper-evidence and audit trail

Every interaction with the admissions booklet and consent form (view, save-step, submit, sign, witness, withdrawal) is recorded in a hash-chained audit log. The audit chain is anchored to an external Time Stamp Authority (RFC 3161). This means we can demonstrate, to a court if necessary, that an audit record has not been altered since the moment it was recorded.

Independent Privacy Impact Assessment

An independent Privacy Impact Assessment has been prepared for the Admissions & Consent module. Hospitals are not enabled on the module in their production environment until that assessment has been reviewed and signed off by the hospital’s information governance committee.

15. Complaints

If you believe we have breached the Australian Privacy Principles or handled your information inappropriately, you may lodge a complaint with us:

  1. Contact our Privacy Officer using the details below. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
  2. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
    • Website: www.oaic.gov.au
    • Phone: 1300 363 992
    • Post: GPO Box 5288, Sydney NSW 2001

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify registered users of material changes via email or in-app notification. The “Last Reviewed” date at the top of this policy indicates when it was last updated.

17. Contact Us

If you have any questions about this Privacy Policy, wish to make an access or correction request, or want to lodge a complaint, please contact:

Privacy Officer

TheatreLink Pty Ltd

Email: privacy@theatrelink.com.au

Website: www.theatrelink.com.au

TheatreLink — Designed by an Australian Surgeon for Australian Hospitals
theatrelink.com.au | support@theatrelink.com.au