Privacy Policy for Surgeonal


Introduction

Welcome to Surgeonal's Terms and Conditions. These terms are intended to guide and inform you about the rules, responsibilities, rights, and limitations that apply when using the Surgeonal App. They serve as a binding contract between you, the user, and us, Surgeonal. Please note, whenever "Surgeonal" is mentioned in this document, it refers to JABIR MOHAMED KHALIF, Nairobi, Kenya.

We have diligently detailed our data handling practices in the sections that follow. While we've endeavored to make this policy as clear and transparent as possible, should you have any queries or require further clarifications, please do not hesitate to reach out to us at surgeonal.app@gmail.com.


1.0 User Eligibility and Agreement

Access and utilization of the Surgeonal App are governed by specific user eligibility criteria.

1.1 Age Restriction

The Surgeonal App is designed exclusively for users who are 18 years and older. Minors under the age of 18 are expressly prohibited from accessing or using this application. This restriction ensures that the platform remains compliant with global data protection regulations and ensures the responsible handling of sensitive information. By using the app, you are asserting that you meet this age criterion. If it's discovered that a user is under the age of 18, their account will be terminated immediately.

2.0 Data Categories and Usage

Our commitment to user privacy is unwavering, and as such, data collection and management are conducted with utmost transparency.

2.1 Personal Data

This is data that can be directly linked to an individual user:

2.1.1 Email Address

Essential for creating your unique user account and facilitating service access. The email address serves as a primary identification measure. In cases where you use Apple sign-in method and opt not to share your email, the app does not collect your email. We may choose to contact you via email if nessecary but not all times. We guarantee that this data will not be shared with external third parties, barring obligatory legal situations where governmental authorities may require access.

2.1.2 Name

While it's optional to provide a name, doing so enhances user experience by personalizing certain app functionalities, such as report generation. Users have the discretion to use pseudonyms or any other name they're comfortable with. Again this is not shared with external third parties.

2.1.3 Specialty

Again, this is optional. However, indicating one's surgical specialty allows the platform to tailor specific features to the user such as prepopulating the surgery logging form fields to achieve the App's overral goal of making the users logging experience as seamless as possible, enhancing the overall user experience. This is not also shared with external third parties.

2.1.4 Surgical Activities

Users are strongly advised against entering any patient-specific details when logging surgical activities. Our platform is explicitly designed to prohibit the collection of patient information to uphold confidentiality and adhere to privacy standards. While surgical activity details are recorded for user benefits, they are programmatically shielded to ensure they remain inaccessible to our developers and any external entities. It is imperative to ensure that no patient data is ever input or collected. This data is not shared with external third parties too.

Third-Party Services

We use various third-party services to enhance your experience with our app. Below is information about these services and the data we share with them.

Google

We utilize Google's servers for our application backend. This infrastructure allows us to maintain high performance and reliability. As part of this service, we may share your unique user ID with Google to ensure consistent and secure access to your data within our app.

RevenueCat

RevenueCat Inc., 300 Euclid Avenue San Francisco, CA 94118, USA, serves as our in-app purchase partner. To facilitate your subscription and access to our content, we share your unique user ID(that is anonymous) and purchase history(of the surgeonal App) with RevenueCat. This information is used to manage and control access to content based on your subscription status, ensuring a seamless user experience.

2.2 Non-Personal Data

These data points are intended to enhance operational efficiency and cannot be directly linked to individual users:

2.2.1 Crash Reports

Crucial for maintaining the app's performance and rectifying any operational glitches. They provide aggregated insights into app performance metrics.

2.2.2 Usage Patterns

Insights, such as A/B testing outcomes, help in refining and optimizing the user experience based on collective user behavior patterns.

3.0 Data Collection, Consent, and Transfers

The relationship between the user and the Surgeonal App is built on trust, and data plays a pivotal role in this.

3.1 Collection & Consent

Users are required to give explicit consent for data collection at the registration phase. This consent permits the app to collect and utilize user data for authentication, personalization, and operational enhancement.

3.2 Business Transfers

In the event of a business sale, merger, or acquisition, user data might be transferred to the new business owner. However, users will receive prior notice detailing the new owner's data handling policies and practices. This ensures users are always informed about who manages their data and how it's managed.

4.0 Policy Amendments and Notifications

4.1 Updates & Changes

We hold the right to modify or update this Privacy Policy. While minor changes may not always be communicated, significant policy shifts will always be relayed to users either via the app, through registered email, or both.

4.2 Notifications

Key changes that impact user data management, rights, or app functionalities will be communicated promptly to ensure users are always in the know.

6.0 Data Retention

5.0 Retention Duration

All user data collected by the Surgeonal App is retained for durations deemed necessary to fulfill the purposes for which they were collected. This approach ensures that user data is available for user benefits, operational requirements, and any legal obligations we might have. However, once these requirements are fulfilled or become inapplicable, we take steps to securely remove or anonymize the data, ensuring that no unnecessary data remains stored.

6.0 Data Deletion

6.1 User-Initiated Deletion

If you, as a user, decide to terminate your association with the Surgeonal App, you have the autonomy to do so via the app's settings. The deletion process is immediate and irreversible. Once initiated, it ensures that all data associated with your account, including personal information and logged surgical activities, are permanently removed from our databases. This action is final, and data recovery post-deletion is not possible, ensuring the user's data privacy and security are uncompromised.

7.0 Data Security

7.1 Our Commitment to Security

At Surgeonal, we're unwavering in our dedication to securing your data. We implement robust security measures to ensure your information is protected against unauthorized access, disclosure, or theft. However, it's important to understand that while we strive for maximum security, no system can be guaranteed to be 100% invulnerable.

7.2 Encryption Measures

We employ industry standard encryption algorithm to safeguard your information both when it's in transit and at rest in our databases.

7.3 Data In Transit

During data transmission over the internet – such as logging surgical activities or updating account details – we utilize encryption. This ensures that even in the rare instance where data transmissions are intercepted, your information remains encrypted making it harder to access.

7.4 Data At Rest

Your stored data benefits from the same encryption, bolstering its defense against any potential unauthorized access or breaches.

8.0 GDPR Compliance

Data Controller for GDPR: Responsible for data processing regarding this app within the meaning of the General Data Protection Regulation (GDPR) is JABIR MOHAMED KHALIF, Nairobi Kenya. Phone: +254722200888, Email: surgeonal.app@gmail.com. The person responsible for the processing of personal data is the natural or legal person who alone or jointly with others decides on the purposes and means of the processing of personal data.

8.1 Commitment to European Union Users

In adherence to the General Data Protection Regulation (GDPR) set by the European Union, we hold a special commitment to our EU users. Recognizing the importance of data sovereignty and protection, the Surgeonal team ensures that all data pertaining to users within the EU is stored and processed exclusively within EU region data centers.

8.2 Data Sovereignty

This commitment to data sovereignty not only underscores our dedication to compliance but also seeks to provide our EU users with peace of mind, knowing that their data remains within a jurisdiction that upholds stringent data protection standards.

9.0 Request for Stored Data

9.1 Data Accessible Upon Request

If you, as a user, request to view the data we hold associated with your account, we can provide explicit details like your email address and name. We strive to uphold transparency while ensuring data privacy.

9.2 Surgical Activities Data

Regarding details of surgical activities, accessing this data requires programmatic fetching. This process demands authentication through user credentials to ensure data security. It's essential to understand that we do not possess the rights to these credentials. Hence, while the data exists, we cannot directly retrieve or view surgical activity details without your active authentication.

9.3 User Autonomy and Privacy

This policy reinforces our unwavering commitment to data privacy. We emphasize user autonomy in controlling their data and will always ensure that your information remains confidential and is accessed in a manner that upholds your privacy rights.

10.0 Data Breach

10.1 Commitment to Data Security

We prioritize the security of your data and implement rigorous measures to safeguard it. Despite our efforts, no system is impervious to potential breaches.

10.2 Breach Detection and Notification

In the event of a data breach, we will take immediate actions to contain and rectify the situation. Equally vital is our commitment to transparency. If we detect a breach that may compromise your personal data, we will promptly notify affected users within 72 hours. This notification will detail the nature of the breach, the data potentially accessed, steps we've taken to address it.

11.0 Contact & Further Inquiries

If you have concerns, questions, or require clarifications regarding this policy or any other aspect of the Surgeonal App, kindly connect with us at surgeonal.app@gmail.com.

Note: Before accepting the terms of this Privacy Policy, users are advised to seek legal counsel to ensure they fully comprehend their rights and obligations.