Privacy Policy
Last updated: 2026-09-14
SurgAI is developed as a clinical decision-support tool. The data controller is the respective hospital unit.
We collect only the minimum data necessary to provide the service: user account (email, name, role, hospital ID) and audit logs for security.
Patient descriptions are sent directly to the AI service and are not stored in our database. AI contexts auto-expire after 30 days.
Under GDPR, you have the right to access, rectify, and delete your personal data. Contact your hospital administrator to exercise these rights.
We only use strictly necessary cookies for session authentication. No analytics or marketing cookies are used; our usage statistics are cookieless (see Analytics).
We measure how SurgAI is used with Umami, an open-source analytics tool self-hosted by Nordic Surgery Lab on its own server in the EU (analytics.nordicsurgerylab.com, hosted by Hetzner Online GmbH, Germany). It is cookieless: nothing is stored on your device (no cookies, no local storage), there is no cross-site tracking and your IP address is not stored; a visit is identified only by a daily-rotating hash of IP address, browser and website that cannot be reversed. We record page views and anonymous product events such as "consultation started" — never personal data, free text, patient data, email or user ID — and the data is not shared with third parties. Legal basis: legitimate interest in aggregated usage statistics (GDPR art. 6(1)(f)). Because nothing is stored on your device, no cookie consent is required under the Danish cookie rules; you can object by contacting your hospital administrator.