Privacy Policy for Surgeonal
Introduction
Welcome to Surgeonal's Terms and Conditions. These terms are intended to guide and inform you about the rules,
responsibilities, rights, and limitations that apply when using the Surgeonal App. They serve as a binding
contract between you, the user, and us, Surgeonal. Please note, whenever "Surgeonal" is mentioned in this document,
it refers to JABIR MOHAMED KHALIF, Nairobi, Kenya.
We have diligently detailed our data handling practices in the sections that follow. While we've endeavored to make
this policy as clear and transparent as possible, should you have any queries or require further clarifications,
please do not hesitate to reach out to us at surgeonal.app@gmail.com.
1.0 User Eligibility and Agreement
Access and utilization of the Surgeonal App are governed by specific user eligibility criteria.
1.1 Age Restriction
The Surgeonal App is designed exclusively for users who are 18 years and older. Minors under the age of 18
are expressly prohibited from accessing or using this application. This restriction ensures that the platform
remains compliant with global data protection regulations and ensures the responsible handling of sensitive
information. By using the app, you are asserting that you meet this age criterion. If it's discovered that a
user is under the age of 18, their account will be terminated immediately.
2.0 Data Categories and Usage
Our commitment to user privacy is unwavering, and as such, data collection and management are conducted with
utmost transparency.
2.1 Personal Data
This is data that can be directly linked to an individual user:
2.1.1 Email Address
Essential for creating your unique user account and facilitating service access. The email address serves as a
primary identification measure. In cases where you use Apple sign-in method and opt not to share your email, the
app does not collect your email. We may choose to contact you via email if nessecary but not all times. We guarantee that this data will not be shared with external third parties, barring
obligatory legal situations where governmental authorities may require access.
2.1.2 Name
While it's optional to provide a name, doing so enhances user experience by personalizing certain app
functionalities, such as report generation. Users have the discretion to use pseudonyms or any other name
they're comfortable with. Again this is not shared with external third parties.
2.1.3 Specialty
Again, this is optional. However, indicating one's surgical specialty allows the platform to tailor specific
features to the user such as prepopulating the surgery logging form fields to achieve the App's overral goal of making the users logging experience as seamless as possible, enhancing the overall user experience. This is not also shared with external third parties.
2.1.4 Surgical Activities
Users are strongly advised against entering any patient-specific details when logging surgical activities. Our
platform is explicitly designed to prohibit the collection of patient information to uphold confidentiality and
adhere to privacy standards. While surgical activity details are recorded for user benefits, they are
programmatically shielded to ensure they remain inaccessible to our developers and any external entities. It is
imperative to ensure that no patient data is ever input or collected. This data is not shared with external third parties too.
Third-Party Services
We use various third-party services to enhance your experience with our app. Below is information about these
services and the data we share with them.
Google
We utilize Google's servers for our application backend. This infrastructure allows us to maintain high
performance and reliability. As part of this service, we may share your unique user ID with Google to ensure
consistent and secure access to your data within our app.
RevenueCat
RevenueCat Inc., 300 Euclid Avenue San Francisco, CA 94118, USA, serves as our in-app purchase partner. To facilitate your subscription and access to our content,
we share your unique user ID(that is anonymous) and purchase history(of the surgeonal App) with RevenueCat. This information is used to manage and
control access to content based on your subscription status, ensuring a seamless user experience.
2.2 Non-Personal Data
These data points are intended to enhance operational efficiency and cannot be directly linked to individual
users:
2.2.1 Crash Reports
Crucial for maintaining the app's performance and rectifying any operational glitches. They provide aggregated
insights into app performance metrics.
2.2.2 Usage Patterns
Insights, such as A/B testing outcomes, help in refining and optimizing the user experience based on collective
user behavior patterns.
3.0 Data Collection, Consent, and Transfers
The relationship between the user and the Surgeonal App is built on trust, and data plays a pivotal role in
this.
3.1 Collection & Consent
Users are required to give explicit consent for data collection at the registration phase. This consent permits
the app to collect and utilize user data for authentication, personalization, and operational enhancement.
3.2 Business Transfers
In the event of a business sale, merger, or acquisition, user data might be transferred to the new business
owner. However, users will receive prior notice detailing the new owner's data handling policies and practices.
This ensures users are always informed about who manages their data and how it's managed.
4.0 Policy Amendments and Notifications
4.1 Updates & Changes
We hold the right to modify or update this Privacy Policy. While minor changes may not always be communicated,
significant policy shifts will always be relayed to users either via the app, through registered email, or both.
4.2 Notifications
Key changes that impact user data management, rights, or app functionalities will be communicated promptly to
ensure users are always in the know.
6.0 Data Retention
5.0 Retention Duration
All user data collected by the Surgeonal App is retained for durations deemed necessary to fulfill the purposes
for which they were collected. This approach ensures that user data is available for user benefits, operational
requirements, and any legal obligations we might have. However, once these requirements are fulfilled or become
inapplicable, we take steps to securely remove or anonymize the data, ensuring that no unnecessary data remains
stored.
6.0 Data Deletion
6.1 User-Initiated Deletion
If you, as a user, decide to terminate your association with the Surgeonal App, you have the autonomy to do so
via the app's settings. The deletion process is immediate and irreversible. Once initiated, it ensures that all data
associated with your account, including personal information and logged surgical activities, are permanently removed
from our databases. This action is final, and data recovery post-deletion is not possible, ensuring the user's data
privacy and security are uncompromised.
7.0 Data Security
7.1 Our Commitment to Security
At Surgeonal, we're unwavering in our dedication to securing your data. We implement robust security
measures to ensure your information is protected against unauthorized access, disclosure, or theft. However, it's
important to understand that while we strive for maximum security, no system can be guaranteed to be 100%
invulnerable.
7.2 Encryption Measures
We employ industry standard encryption algorithm to safeguard your information both
when it's in transit and at rest in our databases.
7.3 Data In Transit
During data transmission over the internet – such as logging surgical activities or updating account details – we
utilize encryption. This ensures that even in the rare instance where data transmissions are intercepted,
your information remains encrypted making it harder to access.
7.4 Data At Rest
Your stored data benefits from the same encryption, bolstering its defense against any potential unauthorized
access or breaches.
8.0 GDPR Compliance
Data Controller for GDPR: Responsible for data processing regarding this app within the meaning of
the General Data Protection Regulation (GDPR) is JABIR MOHAMED KHALIF, Nairobi Kenya.
Phone: +254722200888, Email: surgeonal.app@gmail.com. The person
responsible for the processing of personal data is the natural or legal person who alone or jointly with others
decides on the purposes and means of the processing of personal data.
8.1 Commitment to European Union Users
In adherence to the General Data Protection Regulation (GDPR) set by the European Union, we hold a special commitment
to our EU users. Recognizing the importance of data sovereignty and protection, the Surgeonal team ensures that
all data pertaining to users within the EU is stored and processed exclusively within EU region data centers.
8.2 Data Sovereignty
This commitment to data sovereignty not only underscores our dedication to compliance but also seeks to provide our
EU users with peace of mind, knowing that their data remains within a jurisdiction that upholds stringent data
protection standards.
9.0 Request for Stored Data
9.1 Data Accessible Upon Request
If you, as a user, request to view the data we hold associated with your account, we can provide explicit details
like your email address and name. We strive to uphold transparency while ensuring data privacy.
9.2 Surgical Activities Data
Regarding details of surgical activities, accessing this data requires programmatic fetching. This process demands
authentication through user credentials to ensure data security. It's essential to understand that we do not possess
the rights to these credentials. Hence, while the data exists, we cannot directly retrieve or view surgical activity
details without your active authentication.
9.3 User Autonomy and Privacy
This policy reinforces our unwavering commitment to data privacy. We emphasize user autonomy in controlling their
data and will always ensure that your information remains confidential and is accessed in a manner that upholds your
privacy rights.
10.0 Data Breach
10.1 Commitment to Data Security
We prioritize the security of your data and implement rigorous measures to safeguard it. Despite our efforts, no
system is impervious to potential breaches.
10.2 Breach Detection and Notification
In the event of a data breach, we will take immediate actions to contain and
rectify the situation. Equally vital is our commitment to transparency. If we detect a breach that may compromise
your personal data, we will promptly notify affected users within 72 hours. This notification will detail the nature of the breach,
the data potentially accessed, steps we've taken to address it.
11.0 Contact & Further Inquiries
If you have concerns, questions, or require clarifications regarding this policy or any other aspect of the
Surgeonal App, kindly connect with us at surgeonal.app@gmail.com.
Note: Before accepting the terms of this Privacy Policy, users are advised to seek legal counsel to
ensure they fully comprehend their rights and obligations.