FlexiShiftCreate your account

Privacy Policy

Version 2026-05-16 · Effective from that date. FlexiShift™ is a trademarked product of emedu (ABN 50 651 674 172), Melbourne, Victoria, Australia.

FlexiShift is committed to protecting your privacy. This policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights under the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and, where applicable, the Health Records and Information Privacy Act 2002 (NSW).

This policy applies to both the FlexiShift web application at flexishift.com.au and the FlexiShift Doctor mobile app for iOS and Android.

1. Who we are (APP 1)

FlexiShift™ ("FlexiShift", "we", "us") is a trademarked product of emedu (ABN 50 651 674 172), an Australian entity based in Melbourne, Victoria. FlexiShift is a marketplace connecting AHPRA-registered doctors with hospitals across Australia for locum, casual, and short-term work. Our data-processing operations are hosted in Sydney, NSW for Australian data residency.

FlexiShift is not a healthcare provider. We do not provide medical advice, diagnosis, or treatment. Our platform facilitates workforce connections only; the clinical relationship remains between the doctor and the engaging hospital.

2. What we collect (APP 3 & 5)

Doctor accounts. When you create a doctor account we collect:

  • Identity: title, first name, last name, preferred name.
  • Contact: email address, mobile phone number.
  • Professional registration: AHPRA registration number, specialty, years in practice, and (where you upload it) evidence of AHPRA status such as a screenshot of the AHPRA public register entry.
  • References: the names, positions, and contact details of clinical referees you list on your profile, plus their responses to our attestation form (structured feedback modelled on the NSW Health Referee Report template).
  • Address & location: home street address (or the postcode you choose to share), which we geocode to latitude/longitude for distance-matching shift recommendations.
  • Availability: the dates on which you have declared yourself available for shifts, plus any blackout dates you set.
  • Documents: credentialing documents you upload (e.g. CV, Working With Children Check, Police Check, immunisation history), plus a profile photograph.
  • Financial details (only if you enter them for payment purposes): entity type (ABN/ACN), entity number, entity name, bank account name, BSB, account number. BSB and account number are encrypted at the application layer.
  • Authentication: a password of your choice (never stored in readable form — see "How we protect it" below).
  • Notification preferences: your choices about which channels (email / SMS / push) and which shift types (specialty, distance, availability) trigger a notification for you.
  • Push notification tokens: if you install the FlexiShift Doctor mobile app and grant notification permission, we store the Expo push token issued by Apple/Google so we can deliver shift alerts to your device.
  • Consent records: whether you accepted this Privacy Policy, the policy version at time of acceptance, whether you consented to AI training use, and audit metadata (timestamp, IP address, user agent) for each consent event.
  • Session metadata: IP address and user agent captured on sign-in events, retained for security audit only.

Hospital workforce accounts. If you sign up as a Workforce Admin at a hospital, we collect: name, corporate email, job title, and the hospital details you enter (name, address, ABN, contact phone). We do not collect personal information on behalf of the hospital's clinical patients — FlexiShift never sees patient data.

You must provide the identity, contact, and password fields to create an account. All other fields are optional but not providing them may limit some features (e.g. distance-based matching requires an address).

3. How we use it (APP 6)

We use your personal information to:

  • Create and maintain your doctor or hospital profile.
  • Verify your AHPRA registration.
  • Match you with shifts at hospitals — using your specialty, home location, and declared availability to send only relevant notifications (per your preferences).
  • Communicate about your account, shift applications, contract signing, and platform updates by email, SMS, and (on mobile) push notification.
  • Facilitate reference checks with your nominated referees.
  • Share credentialing evidence with hospitals you apply to, so their Medical Workforce Unit can verify you before accepting your application.
  • Meet legal, regulatory, taxation, and audit obligations.
  • Improve platform security, detect fraud, and investigate incidents.

We do not use your information for third-party marketing, and we do not sell your personal information.

4. AI training (optional consent)

We may use de-identified data (personal identifiers removed) to train AI models that improve platform features — for example: shift matching, credentialing document review, roster optimisation, and scheduling suggestions.

This use is opt-in. When you sign up, a tickbox lets you consent (or not). You can change your decision at any time from your dashboard. Withdrawing consent stops future use immediately; any models already trained on your prior de-identified contributions cannot be reversed, but no further data will be included going forward.

We do not use identifiable personal information for AI training, and we do not use your data to train AI models operated by third parties.

5. Who we disclose it to (APP 6 & 8)

We share the minimum necessary information with the following categories of parties:

  • Hospitals where you apply for shifts — your name, professional credentials, and application-specific documents are shared with the relevant Medical Workforce Unit and Credentialing Committee. Hospitals only see doctors who have applied to their own shifts.
  • Your nominated referees — when you list a referee, we email them a link to complete a structured attestation form. We share only your name and the purpose of the request; referees can decline or ignore the request.
  • Payroll teams at engaging hospitals — receive only the information required to process payment (name, ABN/ACN, bank details) and only after a workforce-verified timesheet or contract is released.
  • Our sub-processors — see Section 6 below for the full list.
  • Regulators, courts, or law enforcement when required by Australian law or a valid court order.

All sub-processors are contractually required to handle your information in accordance with the Australian Privacy Principles or an equivalent standard.

6. Sub-processors and where data is stored (APP 8)

FlexiShift uses the following third-party services to operate the platform. All services are bound by data-processing agreements consistent with the Australian Privacy Principles.

ServicePurposeRegion
NeonPostgres database (all your account and shift data)Sydney, Australia (AWS ap-southeast-2)
VercelApplication hosting + serverless functionsSydney edge + global CDN for static assets
Vercel BlobFile storage (profile photos, credentialing documents)Sydney, Australia (SYD1)
Amazon SESEmail delivery (verification, shift alerts, reminders)Sydney, Australia (AWS ap-southeast-2)
TwilioSMS delivery (OTP verification, shift alerts)United States (SMS routed to Australian carriers)
Google Firebase Cloud MessagingPush notification delivery to Android devicesGlobal (Google infrastructure)
Apple Push Notification ServicePush notification delivery to iOS devicesGlobal (Apple infrastructure)
ExpoMobile-app build service + push-notification proxyUnited States (relays push tokens only)
OpenStreetMap NominatimAddress geocoding (converting your address to coordinates)Germany (public geocoding service)

Primary data (your account, profile, financials, applications, documents, references) is stored exclusively in Sydney, Australia. The overseas sub-processors listed above (Twilio, Firebase, Apple, Expo, Nominatim) only receive the minimum data required to deliver their specific function — e.g. Twilio receives only your mobile number and the message body for each SMS; Firebase receives an anonymous push token and the notification payload.

We do not consider these overseas transfers to constitute cross-border storage of personal information under APP 8; they are transit-only relays for the messaging or geocoding function requested. If this changes we will update this policy and notify affected users.

7. How we protect it (APP 11)

  • In transit: all traffic between your browser or mobile app, our servers, and our database uses TLS 1.3.
  • At rest: Neon Postgres encrypts your database with AES-256. Vercel Blob storage encrypts uploaded files at rest.
  • Application-level encryption: the most sensitive fields — mobile number, AHPRA registration number, BSB, and bank account number — are additionally encrypted with AES-256-GCM at the application layer before they reach the database. A separate encryption key is required to read them; a database dump alone cannot recover these values.
  • Passwords are hashed with bcrypt (cost factor 12). We do not store or transmit passwords in reversible form. We cannot see your password.
  • Session tokens — web sessions use signed JWTs in httpOnly, Secure, SameSite=Lax cookies (14-day expiry). Mobile app sessions use short-lived JWT access tokens (1-hour expiry) with refresh tokens stored in the OS-level secure store (iOS Keychain / Android EncryptedSharedPreferences), which is hardware-backed where the device supports it.
  • Bounce and complaint handling: if an email hard-bounces or the recipient marks it as spam, we automatically suppress future email to that address until you re-verify.
  • Access to production systems is restricted, audited, and requires multi-factor authentication for all administrators.

8. How long we keep it

We retain your account information for as long as you have an active account, plus 7 years after account closure to meet clinical and financial record-keeping obligations (consistent with state health records legislation and the Corporations Act 2001).

Consent audit logs and shift-application records are retained for the same period. After that, all personal information is permanently deleted or fully de-identified.

Push notification tokens are deleted when you sign out of the mobile app, uninstall the app, or when the device becomes unreachable (Expo/FCM/APNs report the token as invalid).

9. Your rights (APP 12 & 13)

  • Access: you can view and export a copy of your profile at any time from your dashboard.
  • Correction: you can update any field directly from your dashboard or the mobile app.
  • Withdrawal of consent: the AI training tickbox is fully reversible. Notification preferences can be changed any time.
  • SMS opt-out: reply STOP to any FlexiShift SMS to immediately unsubscribe from that channel.
  • Push notification opt-out: disable notifications in the mobile app settings, or in your device's system settings for the FlexiShift Doctor app.
  • Deletion: you can close your account and request permanent deletion, subject to any legal retention obligations we've outlined above.
  • Data portability: we can provide a machine-readable export of your account on request.
  • Complaints: if you are unhappy with how we handle your data, please first contact us at privacy@flexishift.com.au. If unresolved, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Notifiable data breaches

Under Part IIIC of the Privacy Act 1988, if a data breach is likely to result in serious harm, we will notify affected users and the OAIC as soon as practicable and in any case within the required timeframe.

11. Cookies and analytics

The web application uses a single, strictly-necessary session cookie (flexishift_session) to keep you signed in. It is httpOnly, Secure (in production), and SameSite=Lax. We do not use third-party advertising, tracking, or analytics cookies.

The mobile app stores its authentication tokens in the operating system's secure store (iOS Keychain / Android EncryptedSharedPreferences); no cookies are involved.

12. Children

FlexiShift is intended for AHPRA-registered doctors and hospital workforce staff, all of whom must be 18 or older. We do not knowingly collect information from children. If you believe a child has provided us with information, please contact privacy@flexishift.com.au and we will delete it.

13. Not a medical service

FlexiShift is a workforce marketplace. It is not a healthcare provider, telehealth service, or clinical decision support tool. Information on the platform relates to employment, credentialing, and scheduling only. If you are seeking medical advice, please consult a qualified health professional or your local emergency service.

14. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email and require you to accept the new version at your next sign-in. You are currently viewing version 2026-05-16.

15. Contact us

Privacy Officer
FlexiShift™ (a product of emedu · ABN 50 651 674 172)
Melbourne, Victoria, Australia
Email: privacy@flexishift.com.au
General enquiries: hello@flexishift.com.au
Postal address: available on request via the addresses above.

Summary in plain English: Your data lives in Sydney. It's encrypted. We don't sell it. We use it only to match you with shifts and let you know when there's one for you. You can see it, correct it, export it, or delete it any time. If we mess up, you can complain to us or to the OAIC.