SPHERE

SPHERE OPCO PTY LTD PRIVACY POLICY

How Sphere collects, uses, holds, and discloses personal information. Compliant with the Australian Privacy Principles.

1. Who we are and our commitment

Sphere OpCo Pty Ltd (ABN 31 695 416 981) ("Sphere", "we", "us") operates an Australian healthcare workforce credentialling platform. The platform verifies practitioners' credentials at authoritative sources in real time, with the practitioner's express consent. Sphere has opted in to be bound by the Privacy Act 1988 (Cth) under section 6EA of that Act, and we comply with the Australian Privacy Principles (APPs) in the way we collect, use, hold, and disclose personal information. The platform is currently operating in demonstration phase, with a hospital recruitment pilot planned from 2027; this policy applies to all personal information we handle in any phase.

2. What we collect

We collect personal information that practitioners provide when creating an account and applying for positions, including: name, contact details, and date of birth; professional details such as registration numbers, qualifications, training history, and employment history; identity document details such as passport, driver licence, Medicare card, visa, or ImmiCard details, where identity verification is required; and referee details and reports provided with the referee's participation. We collect information about hospital and health service users (such as recruitment staff) limited to name, role, and work contact details. We collect this information directly from you, or from the authoritative sources described in section 4 with your consent.

2A. Health information

Some of the information we collect, including immunisation records verified through the Australian Immunisation Register, is health information and is treated as sensitive information under the Privacy Act. We collect health information only with your express consent and only to the extent needed for pre-employment credentialling. We do not use or disclose health information for any purpose beyond verification and the credentialling outcome presented to the health service you have applied to.

3. Why we collect it

We collect, use, and hold personal information to: verify practitioners' identity and credentials for pre-employment credentialling, with express consent; present verification outcomes to the health services to which a practitioner applies; operate, secure, audit, and improve the platform; and meet our legal and contractual obligations, including record-keeping and compliance reporting obligations to government verification services. Information collected for identity verification is used only for the purpose of verifying your identity and is not used for any other purpose. We do not use or disclose the information collected for verification for advertising, marketing, profiling, or market research, and we do not sell personal information.

4. Verification at authoritative sources, and government related identifiers

Credential and identity verification works by checking, with your express consent, that the details you provide match the records held by the authoritative source for each credential. Sources may include the Australian Health Practitioner Regulation Agency, the Department of Home Affairs (visa work entitlements), official document issuers and official record holders for identity documents, and other government and professional bodies as the platform's coverage grows. Some identity documents contain government related identifiers (for example passport or Medicare numbers). We use and disclose these identifiers only as reasonably necessary to verify your identity for credentialling purposes, consistent with APP 9. Verification requests return a match result only; the authoritative source's answer is presented without alteration.

5. Your consent, and what happens when you verify

Before any verification is performed, we ask for your express consent, and no collection, use, or disclosure of your identification information for a verification, and no transmission of a verification request, occurs until that consent has been given. Consent to identity verification is sought on its own: it is not bundled with, and is not obtained through, any other agreement, terms of use, or consent. Where verification of an identity document is required, you will be presented with the following consent statement: “I confirm that I am authorised to provide the personal details presented and I consent to my information being checked with the document issuer or official record holder via third-party systems for the purpose of confirming my identity.” The information collected for identity verification is used only for the purpose of verifying your identity and will not be used for any other purpose. Before you consent, you will also be told: what information will be checked; that the check is made against the records of the relevant document issuer or official record holder; that the request and result may pass through the systems of third-party service intermediaries involved in operating the verification service; the legal obligations that apply to our collection and handling of your identification information, and your rights in relation to it; the consequences of declining (a credential may remain unverified, and alternative verification methods will be offered where available); and how to complain, including where you can get information about the operation of the relevant verification service. You may decline consent, and you may transact with us pseudonymously where practicable, although identity verification by its nature requires your real details.

6. Who we disclose to

We disclose personal information to: the health services to which you choose to apply (your application, credentials, and verification outcomes); the authoritative sources described in section 4, to the extent needed to perform a verification you have consented to; our service providers who support the platform under contractual confidentiality and privacy obligations; and government agencies or regulators where required or authorised by law. We do not disclose personal information to overseas recipients. Our platform and data are hosted in Australia.

7. Storage, security, and retention

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security program includes access controls, encryption in transit and at rest, logging and monitoring, and documented security and risk management plans aligned to the Australian Government Information Security Manual. Identity verification match data is not retained once the purpose of the check has been fulfilled, except where retention is required by law or for compliance record-keeping; where required records are kept, they are held securely and destroyed or de-identified when no longer required. Where we conduct nationally coordinated criminal history checks, criminal history check information obtained through the National Police Checking Service is retained securely for a minimum of 12 months from the date it is received, consistent with our obligations to the Australian Criminal Intelligence Commission, and is destroyed or securely disposed of within a further three months after that, unless a longer period is required by law. A nationally coordinated criminal history check is a point in time record. We do not rely on, or provide, a check result more than three months after it was issued; a new check is required after that time.

7A. If something goes wrong

If we experience a data breach involving personal information that is likely to result in serious harm, we will assess and respond in line with our obligations under the Notifiable Data Breaches scheme in the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required.

8. Access, correction, and complaints

You may request access to the personal information we hold about you, and ask us to correct it, by contacting paul@sphere-x.com.au. We will respond within a reasonable period. If you believe we have breached the APPs, contact us first and we will investigate and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992).

9. Changes to this policy and contact

We may update this policy from time to time; the current version is always available at sphere-x.com.au. Questions about this policy: paul@sphere-x.com.au, or Sphere OpCo Pty Ltd, c/- BDO, Floor 18, 360 Queen Street, Brisbane City QLD 4000. Policy version 1.2, 26 August 2026 (v1.1 19 August 2026; v1.0 published 16 August 2026).