SLVR Privacy Policy

Application: SLVR
Google Play developer: Digitus Tec Developer
Legal entity / data processor: Digitus Tec Pty Ltd (ABN [INSERT ABN])
Registered address: Level 2, 25 Ryde Road, Pymble NSW 2073, Australia
Effective date: 17 August 2026  |  Last updated: 17 August 2026

SLVR ("the App") is published on Google Play by Digitus Tec Developer and is developed and operated by Digitus Tec Pty Ltd ("we", "us", "our"), a company registered in Australia. SLVR is a professional clinical documentation tool designed exclusively for qualified vascular surgeons and other authorised medical professionals to record and manage vascular surgery case data. This Privacy Policy explains what information the App collects, how it is used, how long it is retained, and how you can have it deleted.

If you do not agree with this Privacy Policy, please do not use the App. By creating an account and using SLVR, you agree to the collection and use of information as described here.

Not a medical device. SLVR is a record-keeping and documentation tool. It is not a medical device and does not diagnose, treat, cure or prevent any disease or condition. It does not replace the independent clinical judgement of a qualified healthcare professional. All clinical decisions remain the sole responsibility of the treating clinician.

1. Information We Collect

1.1 Account information (clinician/user). When you register for SLVR, we collect:

1.2 Patient and clinical case information. As part of the App's core function, authorised clinicians enter structured clinical data about their patients' vascular surgery cases, including:

This information is entered into the App by the clinician, about their patients, in the course of clinical documentation. It is not collected directly from patients through the App.

1.3 Device permissions. The App requests the following device permissions, only to support the features described:

1.4 What we do not collect. The App contains no advertising SDKs, no analytics or tracking SDKs, and does not collect location data, contacts, or device identifiers for tracking purposes.

2. Who Is Responsible for Patient Data (Controller / Processor)

For the patient and clinical case data described in Section 1.2, the clinician (and/or their healthcare facility) using the App is the data controller. They determine what patient information is recorded and are responsible for obtaining any consent required under applicable healthcare and data protection law before entering a patient's information into the App.

Digitus Tec Pty Ltd acts as a data processor for this information: we provide and operate the technical platform that stores and secures the data on the clinician's behalf, and we do not use patient data for our own purposes beyond providing the App's functionality.

3. How We Use Information

We do not use your information or your patients' information for advertising, and we do not use analytics or tracking SDKs. We do not sell personal or patient data to any third party, under any circumstances.

4. Where and How Data Is Stored & Secured

5. Third-Party Sub-Processors

We use a small number of infrastructure providers to operate the App. We do not use any advertising or analytics SDKs.

ProviderPurpose
MongoDB AtlasCloud database hosting for account and clinical case data
Amazon Web Services (S3)Secure storage of medical images
Email delivery provider (SMTP)Sending password-reset and account notification emails

6. Data Retention — How Long We Keep Your Data

We keep data only for as long as it is needed for the purposes described in this policy. Specific retention periods are set out below.

DataRetention period
Clinician account information (Section 1.1) Kept while your account is active. Deleted within 30 days of a verified deletion request or of you deleting your account in the App.
Patient and clinical case data, including images (Section 1.2) Kept while the associated account is active. Deleted within 30 days of a verified deletion request, subject to the legal retention exception below.
Inactive accounts Accounts with no login activity for [INSERT — e.g. 24] months are notified by email and then deleted, together with their case data.
Encrypted backups Deleted data persists in encrypted rolling backups for up to [INSERT — e.g. 35] days, after which the backups are permanently overwritten.
Server and access logs Retained for [INSERT — e.g. 30] days for security and troubleshooting, then deleted. Logs do not contain patient clinical data.
Support correspondence Retained for [INSERT — e.g. 12] months from the date the enquiry is closed.

Legal retention exception. Where applicable law requires clinical or medical records to be retained for a minimum period — including record-keeping obligations that apply to the clinician or their healthcare facility — we will retain only the minimum data necessary to comply, and will delete or irreversibly anonymise it once that period has passed.

7. How to Delete Your Data

Submit a deletion request on the web. Go to our account deletion page at https://digitus-dev-s3.s3.us-east-1.amazonaws.com/privacy-policy/delete-account.html and submit a request. No login is required, and you do not need the App installed.

Or email us directly. Write to info@digitustec.com.au from your registered email address, stating that you wish to delete your account and data.

You can request deletion of your entire account, or of specific case records only.

Whichever option you use, we verify the request and delete the corresponding account, clinical case data and stored images from our live systems within 30 days. Copies in encrypted backups are removed on the backup cycle described in Section 6. Data we are legally required to retain is handled as described in Section 6.

8. Your Rights

Subject to applicable law, including the Australian Privacy Principles, you may request to:

To exercise any of these rights, contact us at info@digitustec.com.au. We respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

9. Data Breach Notification

We maintain procedures to detect and respond to security incidents. If a data breach occurs that is likely to result in serious harm, we will notify affected users and the relevant supervisory authority — including the OAIC under the Notifiable Data Breaches scheme — without undue delay, and will inform affected clinicians so they can meet their own notification obligations.

10. Children's Privacy

SLVR is intended solely for use by qualified medical professionals in a clinical setting. It is not directed at, marketed to, or intended for use by children, and we do not knowingly collect information from children as users of the App.

11. International Data Transfers

Our infrastructure providers may store and process data in countries other than your own; our cloud infrastructure is currently hosted in [INSERT REGION — e.g. the United States]. Where data is transferred across borders, we rely on the contractual data protection terms of our sub-processors (including AWS and MongoDB Atlas standard data processing agreements) and take reasonable steps to ensure your information continues to be protected in accordance with this Privacy Policy and applicable law.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page, and where appropriate we will notify you in the App. We encourage you to review this page periodically.

13. Contact Us

If you have any questions about this Privacy Policy or how your data is handled, please contact us at:
Digitus Tec Pty Ltd
Level 2, 25 Ryde Road, Pymble NSW 2073, Australia
Email: info@digitustec.com.au