Privacy Policy
Version 1.0 · Effective Date: 19.06.2026
This Privacy Policy explains how Custom Surgical GmbH collects, uses, shares and protects your personal information when you use the MicroREC Data Platform, comprising MicroREC App (iOS and Android), MicroREC Desktop (Windows and macOS), and MicroREC Connect (web application).
| Version | Effective Date | Contact |
|---|---|---|
| 1.0 | 19.06.2026 | data-protection-office@customsurgical.co |
Custom Surgical GmbH ("Custom Surgical", "we", "us", "our") is the data controller responsible for your personal information. We are a medical data management company based in Munich, Germany. Our platform enables healthcare professionals to capture, store and access clinical media and patient case data. It does not perform diagnostic functions and is not classified as a Software as a Medical Device (SaMD).
Address: Agnes-Pockels-Bogen 1, 80992 Munich, Germany
Data Protection Officer: Fernando Benito Abad — data-protection-office@customsurgical.co
If you use the MicroREC Data Platform to upload, store or access patient data, you do so as a data controller under GDPR. In this capacity, Custom Surgical processes patient data on your behalf as a data processor. The terms governing that processing relationship are set out in our Data Processing Addendum (DPA), available at customsurgical.co/data-processing-addendum, which forms part of our Terms & Conditions. The DPA is accepted when you upgrade to a paid subscription or create an organisational account.
This Privacy Policy applies to all users of the MicroREC Data Platform across all interfaces. Certain sections apply only to specific interfaces or subscription tiers where indicated.
| Interface | Who uses it | Availability |
|---|---|---|
| MicroREC App | Individual clinicians capturing clinical media on mobile devices | Free and paid tiers |
| MicroREC Desktop | Clinicians capturing clinical media on Windows or macOS workstations | Free and paid tiers |
| MicroREC Connect | Subscribers accessing, managing and sharing cloud-stored clinical cases via browser | Paid subscribers only |
Profile information. When you create an account, you provide us with your full name, email address, country of residence, and profession.
Account administrator information (Connect Business). If you create or manage an organisational account, we additionally collect your role or title, organisation name, and billing contact details.
User content. We collect the clinical content you create or manage through the platform, including photographs, videos, audio recordings, patient IDs, session labels, session descriptions, session dates and session locations. This content may constitute health data under Article 9 GDPR. See Section 5 for details on the lawful basis for processing this category of data.
Billing and payment information. If you subscribe to a paid plan, we collect your name, email address, billing address, and tokenised payment identifiers (last four digits of card, card type and expiry date). Raw payment card data (full card number, CVV) is processed exclusively by Stripe Technology Europe, Limited, acting as an independent data controller under its own privacy policy. We never process or store full payment card details.
Support and contact information. If you contact us or use the in-app support feature powered by Intercom, we collect the information you provide during the interaction, including your account details and the content of your enquiry.
Technical information. We automatically collect technical and diagnostic information when you use the Service, including your device model, operating system version, IP address, application version, configuration settings, and the time and date of your use. We also collect service-related performance information including crash reports and performance logs.
Identifiers. We automatically assign you a device ID and user ID when you use our applications. Where you log in from multiple devices, we use these identifiers to link your activity across devices to provide a seamless experience and for security purposes.
If you sign in using a third-party platform (Google or Apple), that platform shares information such as your email address, user ID, and public profile information in accordance with your consent and the provider's privacy policy.
- - Create and manage your account
- - Enable you to use the platform and its functionalities
- - Provide customer support and respond to your requests
- - Communicate with you about the Service
Legal basis: Performance of contract, Art. 6(1)(b) GDPR.
- - Understand how users use the services in order to improve them
- - Ensure quality, security and stability by analysing and correcting failures and bugs
- - Develop new features and services, including through internal research and development using pseudo-anonymised data (see Section 7)
Legal basis: Legitimate interests, Art. 6(1)(f) GDPR. Our interest is in continuously improving the Service for the benefit of all users.
- - Process subscription payments and manage billing
- - Send transactional emails relating to your account (via MailerSend)
Legal basis: Performance of contract, Art. 6(1)(b) GDPR.
- - Comply with applicable legal requirements
- - Assist law enforcement where required by law
Legal basis: Legal obligation, Art. 6(1)(c) GDPR.
- - Send newsletters and marketing communications about our products and services, where you have opted in
Legal basis: Consent, Art. 6(1)(a) GDPR. You may withdraw consent at any time by unsubscribing via the link in any marketing email or by contacting us at data-protection-office@customsurgical.co.
Clinical media and patient information processed through the Service may constitute health data within the meaning of Article 9 GDPR. This is special category data and is subject to enhanced protections.
Our role as data processor: When you upload patient data through the Service, you do so as a data controller. Custom Surgical processes this data solely on your instructions, in its capacity as a data processor. The terms of this processing are governed by the Data Processing Addendum (DPA), available at customsurgical.co/data-processing-addendum.
Your responsibility as data controller: You are responsible for ensuring that you have a valid legal basis under Article 9(2) GDPR for processing special category health data through the Service, and for providing appropriate notice to your patients. The applicable basis will typically be Article 9(2)(h) GDPR — processing necessary for the purposes of the provision of healthcare services and the clinical management of patients — in conjunction with a professional secrecy obligation under Article 9(3) GDPR.
We use Google Firebase Authentication, a service of Google Ireland Limited, Gordon House, 4 Barrow Street, D04 E5W5 Dublin, Ireland, to manage secure login and identity across all platform interfaces. Firebase Authentication stores authentication data (user ID, email address, and name if provided by the identity provider) on our behalf.
Legal basis: Performance of contract, Art. 6(1)(b) GDPR, as authentication is necessary to provide the Service.
If you sign in using your Google account, Google shares your user ID, first name, last name and email address with us. We use only these fields for account registration and identification.
Legal basis: Consent, Art. 6(1)(a) GDPR, given at the point of choosing to sign in with Google.
If you sign in using your Apple account, Apple may ask whether to share or hide your email address. If you choose to hide your email address and disable email forwarding, we will not be able to send you account communications. We use your Apple user ID, first name, last name and email address (where provided) for account registration and identification.
Legal basis: Performance of contract, Art. 6(1)(b) GDPR, and legitimate interests, Art. 6(1)(f) GDPR.
We share your personal information with the following categories of service providers as necessary to operate the Service. All service providers are contractually required to process data only on our instructions and in accordance with applicable data protection law.
| Provider | Entity | Purpose | Data shared |
|---|---|---|---|
| Google LLC / Firebase Inc. | Google LLC and Firebase Inc. (both US; Firebase Inc. is a Google subsidiary) | Cloud infrastructure, authentication, development tools | Account data, user content, technical data |
| Amazon Web Services | AWS EMEA SARL (EU) | Secondary R&D infrastructure (EU data centers only) | Pseudo-anonymised clinical media (paid/formerly paid subscribers only) |
| Intercom | Intercom R&D Unlimited Company (IE) | In-app customer support chat | Name, email, account details, support conversation content |
| HubSpot | HubSpot Ireland Limited (IE) | Internal CRM and marketing automation (not user-facing) | Name, email, account tier, interaction history |
| Mailchimp / Intuit | Mailchimp, Inc. (US) | Newsletter distribution (opted-in subscribers only) | Email address, name |
| MailerSend | MailerSend, Inc. (US) | Transactional email relay (account emails, notifications) | Email address, name, account-related content |
| Stripe | Stripe Technology Europe, Ltd (IE) | Payment processing | Name, email, billing address, tokenised payment identifiers |
| Apple | Apple, Inc. (US) | App distribution (iOS, macOS) | As per Apple's App Store terms |
| Sentry | Functional Software, Inc. dba Sentry (US) | Error monitoring and crash reporting | Session data, error logs, device and browser metadata |
| Qonversion | Qonversion, Inc. (US) | Subscription analytics and in-app purchase management | Subscription status, purchase events, app usage data |
A full list of subprocessors with legal entity details and transfer mechanisms is available in our Data Processing Addendum at customsurgical.co/data-processing-addendum.
Custom Surgical retains pseudo-anonymised media data (photographs and videos) from paid and formerly paid (downgraded) subscriber accounts in a separate research and development environment hosted by Amazon Web Services EMEA SARL within the European Union. This data is used solely for internal product development purposes — specifically the improvement and development of the Service.
- - Only accounts that have held a paid subscription are subject to this secondary processing
- - Free-tier-only users whose media has never been stored in the cloud are not included
- - Data is pseudo-anonymised before transfer to the R&D environment
- - Data remains within the European Union at all times
- - This data is deleted upon account deletion or formal deletion request
Legal basis: Legitimate interests, Art. 6(1)(f) GDPR. A Legitimate Interests Assessment for this processing is available upon written request.
For the avoidance of doubt, Custom Surgical acts as an independent data controller for this secondary R&D processing activity, determining the purpose of such processing independently of the Customer's instructions. Customers may exercise the right to object to this processing under Article 21 GDPR on behalf of their patients by contacting data-protection-office@customsurgical.co. Objections will be honoured within 30 days and do not affect the primary service relationship.
We may disclose your information where reasonably necessary: (i) to comply with a legal process such as a court order, subpoena or regulatory requirement; (ii) to assist in the prevention or detection of crime; or (iii) to protect the safety of any person. We may also share information to protect our legal rights, enforce our agreements, or investigate suspected fraud or other wrongdoing.
Custom Surgical's primary infrastructure is hosted on Google Cloud Platform within the European Union. We do not operate data centers outside the EU and do not directly transfer Customer Data outside the European Economic Area.
However, certain service providers engaged by Custom Surgical have parent entities established in the United States. Where personal data may be accessible by such US-based parent entities, appropriate safeguards are in place, including:
- - Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision 2021/914)
- - Certification under the EU-US Data Privacy Framework (DPF), where applicable
A full breakdown of transfer mechanisms by service provider is set out in Annex D of the Data Processing Addendum, available at customsurgical.co/data-processing-addendum.
We retain your personal data for as long as your account remains active, subject to the following:
- - Active account definition: An account is considered active if you have logged in or captured data within the preceding 36 months, or if you hold an active paid subscription.
- - Media data (paid and formerly paid subscribers): Photographs and videos stored in the cloud are retained for the duration of your active account. Downgraded subscribers retain access to their existing cloud-stored media as a continued benefit of the platform.
- - Structured account data (all users): Account profile data, session metadata and patient IDs are retained for the duration of your active account.
- - Inactivity: If your account has been inactive for 36 consecutive months, we will notify you by email and delete your account and all associated data within 30 days unless you reactivate.
- - Account deletion: Upon a formal account deletion request, we will delete all your data from both the primary and secondary environments within 30 days and confirm deletion in writing upon request.
- - Locally stored content: Content stored only on your device and not uploaded to the cloud remains on your device and is not subject to our retention policy.
We implement appropriate technical and organisational measures to protect your personal information, including TLS encryption for all data in transit across all platform interfaces, hashed passwords, two-factor authentication for employee accounts, role-based access controls with a least-privilege policy, and regular employee security training.
MicroREC Connect enforces HTTPS exclusively and implements session management controls including automatic session expiry for inactive sessions.
While we strive to protect your personal data, no method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security but will notify you promptly in the event of a data breach affecting your personal information.
To exercise any of these rights, please contact us at data-protection-office@customsurgical.co. We may ask you to verify your identity before responding.
| Right | What it means |
|---|---|
| Access | You can ask us to confirm what data we hold about you and to provide a copy. |
| Correction | You can ask us to correct inaccurate data. Some corrections can be made through in-app settings. |
| Deletion | You can ask us to delete your data. Certain data may be retained where required by law. |
| Restriction | You can ask us to restrict processing in certain circumstances (e.g. while disputing accuracy). |
| Portability | You can receive your data in a structured, machine-readable format for transfer to another service. |
| Objection | You can object to processing based on legitimate interests. We will stop unless we have compelling grounds. |
| Withdraw consent | Where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect prior processing. |
| Lodge a complaint | You have the right to complain to the Bavarian State Office for Data Protection Supervision (BayLDA) or another competent supervisory authority. |
Supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany. www.lda.bayern.de
MicroREC Connect (web application) uses cookies and similar technologies for authentication, session management, security, and service functionality. Some of these cookies are set by third-party services integrated into MicroREC Connect, including:
- - Firebase Analytics — analytics cookies to understand usage patterns and improve the Service
- - Intercom — functional cookies to enable the in-app support chat widget
- - Sentry — session cookies for error monitoring and performance tracking
- - Stripe — cookies related to payment processing and fraud prevention
Strictly necessary cookies (such as authentication and session management cookies) do not require consent. Non-essential cookies, including analytics and functional cookies from the third-party services listed above, are only set with your consent. MicroREC Connect displays a cookie consent banner on first access through which you can accept or decline non-essential cookies.
We do not use third-party advertising or tracking cookies. Native applications (MicroREC App and MicroREC Desktop) do not use browser cookies. We use device identifiers and user IDs for the purposes described in Section 3.
We send marketing and newsletter communications only to users who have explicitly opted in. Newsletter subscriptions can be initiated on our website or within the MicroREC App. We use Mailchimp (operated by Intuit, Inc.) to distribute newsletters. Only your email address and name are shared with Mailchimp for this purpose.
Transactional emails relating to your account (such as password resets, subscription confirmations, and service notifications) are sent via MailerSend regardless of your marketing preferences, as they are necessary for the performance of your contract with us.
You may unsubscribe from marketing communications at any time by clicking the unsubscribe link in any email or by contacting us at data-protection-office@customsurgical.co.
The MicroREC Data Platform is designed for use by healthcare professionals and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us at data-protection-office@customsurgical.co and we will delete it promptly.
The Service may contain links to third-party websites or services. We have no control over and assume no responsibility for the privacy practices of any third-party sites. We recommend reviewing the privacy policy of any external site you visit.
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. Where changes are material, we will notify you by email to the address registered on your account and by posting the updated policy on our website with a revised effective date. Continued use of the Service following notification constitutes acceptance of the updated policy.
Previous versions of this Privacy Policy are available upon request.
For any questions, concerns or requests relating to this Privacy Policy or the processing of your personal data, please contact us:
Email: data-protection-office@customsurgical.co
Post: Custom Surgical GmbH, Agnes-Pockels-Bogen 1, 80992 Munich, Germany
DPO: Fernando Benito Abad
Effective date: 19.06.2026 · Version: 1.0








-1675d2368c6531b4186d0c38e40719e5.png)



