SurgAI

Privacy Policy

Last updated: 2026-09-14

Data Controller

SurgAI is developed as a clinical decision-support tool. The data controller is the respective hospital unit.

Data Collected

We collect only the minimum data necessary to provide the service: user account (email, name, role, hospital ID) and audit logs for security.

No Patient Data

Patient descriptions are sent directly to the AI service and are not stored in our database. AI contexts auto-expire after 30 days.

Your Rights

Under GDPR, you have the right to access, rectify, and delete your personal data. Contact your hospital administrator to exercise these rights.

Cookies

We only use strictly necessary cookies for session authentication. No analytics or marketing cookies are used; our usage statistics are cookieless (see Analytics).

Analytics

We measure how SurgAI is used with Umami, an open-source analytics tool self-hosted by Nordic Surgery Lab on its own server in the EU (analytics.nordicsurgerylab.com, hosted by Hetzner Online GmbH, Germany). It is cookieless: nothing is stored on your device (no cookies, no local storage), there is no cross-site tracking and your IP address is not stored; a visit is identified only by a daily-rotating hash of IP address, browser and website that cannot be reversed. We record page views and anonymous product events such as "consultation started" — never personal data, free text, patient data, email or user ID — and the data is not shared with third parties. Legal basis: legitimate interest in aggregated usage statistics (GDPR art. 6(1)(f)). Because nothing is stored on your device, no cookie consent is required under the Danish cookie rules; you can object by contacting your hospital administrator.