Custom Surgical logo

  • Home
  • About
  • Hardware
    MicroREC
    MicroREC banner
    The ultimate optical system to digitize your microscope or slit lamp
    MicroREC Ultra
    MicroREC logo
    The best image quality in the market.
    OptiREC
    OptiREC logo
    The slit lamp adapter for your diagnostic pictures
    MicroREC 3D
    MicroREC 3D logo
    Experience the future of surgical visualization
    Software
    Connect logo
    MicroREC Connect
    Manage your medical data anywhere and at any time.
    Business logo
    Business
    Get control of your clinic imagery.
    Smartphone
    MicroREC App logo
    Free App to improve your recordings and organize them
    Accessories
    Accessory
    Accessory logo
    Increase compatibility and improve your workflow.
    Contact
      |  
    Sales Support
  • Blog
Go to Connect

Custom Surgical Logo

  • Home
  • About
  • Products
    Hardware
    MicroRECMicroREC UltraOptiRECMicroREC 3D
    Accessories
    Accessory
    Software
    MicroREC ConnectMicroREC Connect BusinessMicroREC App
  • Blog
  • Privacy Policy

    Version 1.0 · Effective Date: 19.06.2026

    This Privacy Policy explains how Custom Surgical GmbH collects, uses, shares and protects your personal information when you use the MicroREC Data Platform, comprising MicroREC App (iOS and Android), MicroREC Desktop (Windows and macOS), and MicroREC Connect (web application).

    VersionEffective DateContact
    1.019.06.2026data-protection-office@customsurgical.co
    1. Who We Are

    Custom Surgical GmbH ("Custom Surgical", "we", "us", "our") is the data controller responsible for your personal information. We are a medical data management company based in Munich, Germany. Our platform enables healthcare professionals to capture, store and access clinical media and patient case data. It does not perform diagnostic functions and is not classified as a Software as a Medical Device (SaMD).

    Address: Agnes-Pockels-Bogen 1, 80992 Munich, Germany
    Data Protection Officer: Fernando Benito Abad — data-protection-office@customsurgical.co

    If you use the MicroREC Data Platform to upload, store or access patient data, you do so as a data controller under GDPR. In this capacity, Custom Surgical processes patient data on your behalf as a data processor. The terms governing that processing relationship are set out in our Data Processing Addendum (DPA), available at customsurgical.co/data-processing-addendum, which forms part of our Terms & Conditions. The DPA is accepted when you upgrade to a paid subscription or create an organisational account.

    2. Scope and Applicability

    This Privacy Policy applies to all users of the MicroREC Data Platform across all interfaces. Certain sections apply only to specific interfaces or subscription tiers where indicated.

    InterfaceWho uses itAvailability
    MicroREC AppIndividual clinicians capturing clinical media on mobile devicesFree and paid tiers
    MicroREC DesktopClinicians capturing clinical media on Windows or macOS workstationsFree and paid tiers
    MicroREC ConnectSubscribers accessing, managing and sharing cloud-stored clinical cases via browserPaid subscribers only
    3. Information We Collect
    3.1 Information You Provide

    Profile information. When you create an account, you provide us with your full name, email address, country of residence, and profession.

    Account administrator information (Connect Business). If you create or manage an organisational account, we additionally collect your role or title, organisation name, and billing contact details.

    User content. We collect the clinical content you create or manage through the platform, including photographs, videos, audio recordings, patient IDs, session labels, session descriptions, session dates and session locations. This content may constitute health data under Article 9 GDPR. See Section 5 for details on the lawful basis for processing this category of data.

    Billing and payment information. If you subscribe to a paid plan, we collect your name, email address, billing address, and tokenised payment identifiers (last four digits of card, card type and expiry date). Raw payment card data (full card number, CVV) is processed exclusively by Stripe Technology Europe, Limited, acting as an independent data controller under its own privacy policy. We never process or store full payment card details.

    Support and contact information. If you contact us or use the in-app support feature powered by Intercom, we collect the information you provide during the interaction, including your account details and the content of your enquiry.

    3.2 Automatically Collected Information

    Technical information. We automatically collect technical and diagnostic information when you use the Service, including your device model, operating system version, IP address, application version, configuration settings, and the time and date of your use. We also collect service-related performance information including crash reports and performance logs.

    Identifiers. We automatically assign you a device ID and user ID when you use our applications. Where you log in from multiple devices, we use these identifiers to link your activity across devices to provide a seamless experience and for security purposes.

    3.3 Information From Third-Party Platforms

    If you sign in using a third-party platform (Google or Apple), that platform shares information such as your email address, user ID, and public profile information in accordance with your consent and the provider's privacy policy.

    4. How We Use Your Information and Our Legal Bases
    A. Provide and manage your account
    • - Create and manage your account
    • - Enable you to use the platform and its functionalities
    • - Provide customer support and respond to your requests
    • - Communicate with you about the Service

    Legal basis: Performance of contract, Art. 6(1)(b) GDPR.

    B. Improve our services and develop new ones
    • - Understand how users use the services in order to improve them
    • - Ensure quality, security and stability by analysing and correcting failures and bugs
    • - Develop new features and services, including through internal research and development using pseudo-anonymised data (see Section 7)

    Legal basis: Legitimate interests, Art. 6(1)(f) GDPR. Our interest is in continuously improving the Service for the benefit of all users.

    C. Billing and subscription management
    • - Process subscription payments and manage billing
    • - Send transactional emails relating to your account (via MailerSend)

    Legal basis: Performance of contract, Art. 6(1)(b) GDPR.

    D. Ensure legal compliance
    • - Comply with applicable legal requirements
    • - Assist law enforcement where required by law

    Legal basis: Legal obligation, Art. 6(1)(c) GDPR.

    E. Marketing communications
    • - Send newsletters and marketing communications about our products and services, where you have opted in

    Legal basis: Consent, Art. 6(1)(a) GDPR. You may withdraw consent at any time by unsubscribing via the link in any marketing email or by contacting us at data-protection-office@customsurgical.co.

    5. Processing of Health Data (Special Category Data)

    Clinical media and patient information processed through the Service may constitute health data within the meaning of Article 9 GDPR. This is special category data and is subject to enhanced protections.

    Our role as data processor: When you upload patient data through the Service, you do so as a data controller. Custom Surgical processes this data solely on your instructions, in its capacity as a data processor. The terms of this processing are governed by the Data Processing Addendum (DPA), available at customsurgical.co/data-processing-addendum.

    Your responsibility as data controller: You are responsible for ensuring that you have a valid legal basis under Article 9(2) GDPR for processing special category health data through the Service, and for providing appropriate notice to your patients. The applicable basis will typically be Article 9(2)(h) GDPR — processing necessary for the purposes of the provision of healthcare services and the clinical management of patients — in conjunction with a professional secrecy obligation under Article 9(3) GDPR.

    6. Authentication Services
    Firebase Authentication

    We use Google Firebase Authentication, a service of Google Ireland Limited, Gordon House, 4 Barrow Street, D04 E5W5 Dublin, Ireland, to manage secure login and identity across all platform interfaces. Firebase Authentication stores authentication data (user ID, email address, and name if provided by the identity provider) on our behalf.

    Legal basis: Performance of contract, Art. 6(1)(b) GDPR, as authentication is necessary to provide the Service.

    Sign in with Google

    If you sign in using your Google account, Google shares your user ID, first name, last name and email address with us. We use only these fields for account registration and identification.

    Legal basis: Consent, Art. 6(1)(a) GDPR, given at the point of choosing to sign in with Google.

    Sign in with Apple

    If you sign in using your Apple account, Apple may ask whether to share or hide your email address. If you choose to hide your email address and disable email forwarding, we will not be able to send you account communications. We use your Apple user ID, first name, last name and email address (where provided) for account registration and identification.

    Legal basis: Performance of contract, Art. 6(1)(b) GDPR, and legitimate interests, Art. 6(1)(f) GDPR.

    7. How We Share Your Information
    7.1 Service Providers (Subprocessors)

    We share your personal information with the following categories of service providers as necessary to operate the Service. All service providers are contractually required to process data only on our instructions and in accordance with applicable data protection law.

    ProviderEntityPurposeData shared
    Google LLC / Firebase Inc.Google LLC and Firebase Inc. (both US; Firebase Inc. is a Google subsidiary)Cloud infrastructure, authentication, development toolsAccount data, user content, technical data
    Amazon Web ServicesAWS EMEA SARL (EU)Secondary R&D infrastructure (EU data centers only)Pseudo-anonymised clinical media (paid/formerly paid subscribers only)
    IntercomIntercom R&D Unlimited Company (IE)In-app customer support chatName, email, account details, support conversation content
    HubSpotHubSpot Ireland Limited (IE)Internal CRM and marketing automation (not user-facing)Name, email, account tier, interaction history
    Mailchimp / IntuitMailchimp, Inc. (US)Newsletter distribution (opted-in subscribers only)Email address, name
    MailerSendMailerSend, Inc. (US)Transactional email relay (account emails, notifications)Email address, name, account-related content
    StripeStripe Technology Europe, Ltd (IE)Payment processingName, email, billing address, tokenised payment identifiers
    AppleApple, Inc. (US)App distribution (iOS, macOS)As per Apple's App Store terms
    SentryFunctional Software, Inc. dba Sentry (US)Error monitoring and crash reportingSession data, error logs, device and browser metadata
    QonversionQonversion, Inc. (US)Subscription analytics and in-app purchase managementSubscription status, purchase events, app usage data

    A full list of subprocessors with legal entity details and transfer mechanisms is available in our Data Processing Addendum at customsurgical.co/data-processing-addendum.

    7.2 Secondary R&D Processing

    Custom Surgical retains pseudo-anonymised media data (photographs and videos) from paid and formerly paid (downgraded) subscriber accounts in a separate research and development environment hosted by Amazon Web Services EMEA SARL within the European Union. This data is used solely for internal product development purposes — specifically the improvement and development of the Service.

    • - Only accounts that have held a paid subscription are subject to this secondary processing
    • - Free-tier-only users whose media has never been stored in the cloud are not included
    • - Data is pseudo-anonymised before transfer to the R&D environment
    • - Data remains within the European Union at all times
    • - This data is deleted upon account deletion or formal deletion request

    Legal basis: Legitimate interests, Art. 6(1)(f) GDPR. A Legitimate Interests Assessment for this processing is available upon written request.

    For the avoidance of doubt, Custom Surgical acts as an independent data controller for this secondary R&D processing activity, determining the purpose of such processing independently of the Customer's instructions. Customers may exercise the right to object to this processing under Article 21 GDPR on behalf of their patients by contacting data-protection-office@customsurgical.co. Objections will be honoured within 30 days and do not affect the primary service relationship.

    7.3 Law Enforcement and Legal Rights

    We may disclose your information where reasonably necessary: (i) to comply with a legal process such as a court order, subpoena or regulatory requirement; (ii) to assist in the prevention or detection of crime; or (iii) to protect the safety of any person. We may also share information to protect our legal rights, enforce our agreements, or investigate suspected fraud or other wrongdoing.

    8. International Transfers

    Custom Surgical's primary infrastructure is hosted on Google Cloud Platform within the European Union. We do not operate data centers outside the EU and do not directly transfer Customer Data outside the European Economic Area.

    However, certain service providers engaged by Custom Surgical have parent entities established in the United States. Where personal data may be accessible by such US-based parent entities, appropriate safeguards are in place, including:

    • - Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision 2021/914)
    • - Certification under the EU-US Data Privacy Framework (DPF), where applicable

    A full breakdown of transfer mechanisms by service provider is set out in Annex D of the Data Processing Addendum, available at customsurgical.co/data-processing-addendum.

    9. How Long We Retain Your Information

    We retain your personal data for as long as your account remains active, subject to the following:

    • - Active account definition: An account is considered active if you have logged in or captured data within the preceding 36 months, or if you hold an active paid subscription.
    • - Media data (paid and formerly paid subscribers): Photographs and videos stored in the cloud are retained for the duration of your active account. Downgraded subscribers retain access to their existing cloud-stored media as a continued benefit of the platform.
    • - Structured account data (all users): Account profile data, session metadata and patient IDs are retained for the duration of your active account.
    • - Inactivity: If your account has been inactive for 36 consecutive months, we will notify you by email and delete your account and all associated data within 30 days unless you reactivate.
    • - Account deletion: Upon a formal account deletion request, we will delete all your data from both the primary and secondary environments within 30 days and confirm deletion in writing upon request.
    • - Locally stored content: Content stored only on your device and not uploaded to the cloud remains on your device and is not subject to our retention policy.
    10. Security

    We implement appropriate technical and organisational measures to protect your personal information, including TLS encryption for all data in transit across all platform interfaces, hashed passwords, two-factor authentication for employee accounts, role-based access controls with a least-privilege policy, and regular employee security training.

    MicroREC Connect enforces HTTPS exclusively and implements session management controls including automatic session expiry for inactive sessions.

    While we strive to protect your personal data, no method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security but will notify you promptly in the event of a data breach affecting your personal information.

    11. Your Rights

    To exercise any of these rights, please contact us at data-protection-office@customsurgical.co. We may ask you to verify your identity before responding.

    RightWhat it means
    AccessYou can ask us to confirm what data we hold about you and to provide a copy.
    CorrectionYou can ask us to correct inaccurate data. Some corrections can be made through in-app settings.
    DeletionYou can ask us to delete your data. Certain data may be retained where required by law.
    RestrictionYou can ask us to restrict processing in certain circumstances (e.g. while disputing accuracy).
    PortabilityYou can receive your data in a structured, machine-readable format for transfer to another service.
    ObjectionYou can object to processing based on legitimate interests. We will stop unless we have compelling grounds.
    Withdraw consentWhere processing is based on consent, you can withdraw it at any time. Withdrawal does not affect prior processing.
    Lodge a complaintYou have the right to complain to the Bavarian State Office for Data Protection Supervision (BayLDA) or another competent supervisory authority.

    Supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany. www.lda.bayern.de

    12. Cookies and Tracking

    MicroREC Connect (web application) uses cookies and similar technologies for authentication, session management, security, and service functionality. Some of these cookies are set by third-party services integrated into MicroREC Connect, including:

    • - Firebase Analytics — analytics cookies to understand usage patterns and improve the Service
    • - Intercom — functional cookies to enable the in-app support chat widget
    • - Sentry — session cookies for error monitoring and performance tracking
    • - Stripe — cookies related to payment processing and fraud prevention

    Strictly necessary cookies (such as authentication and session management cookies) do not require consent. Non-essential cookies, including analytics and functional cookies from the third-party services listed above, are only set with your consent. MicroREC Connect displays a cookie consent banner on first access through which you can accept or decline non-essential cookies.

    We do not use third-party advertising or tracking cookies. Native applications (MicroREC App and MicroREC Desktop) do not use browser cookies. We use device identifiers and user IDs for the purposes described in Section 3.

    13. Newsletter and Marketing Communications

    We send marketing and newsletter communications only to users who have explicitly opted in. Newsletter subscriptions can be initiated on our website or within the MicroREC App. We use Mailchimp (operated by Intuit, Inc.) to distribute newsletters. Only your email address and name are shared with Mailchimp for this purpose.

    Transactional emails relating to your account (such as password resets, subscription confirmations, and service notifications) are sent via MailerSend regardless of your marketing preferences, as they are necessary for the performance of your contract with us.

    You may unsubscribe from marketing communications at any time by clicking the unsubscribe link in any email or by contacting us at data-protection-office@customsurgical.co.

    14. Children's Privacy

    The MicroREC Data Platform is designed for use by healthcare professionals and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us at data-protection-office@customsurgical.co and we will delete it promptly.

    15. Links to Other Sites

    The Service may contain links to third-party websites or services. We have no control over and assume no responsibility for the privacy practices of any third-party sites. We recommend reviewing the privacy policy of any external site you visit.

    16. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. Where changes are material, we will notify you by email to the address registered on your account and by posting the updated policy on our website with a revised effective date. Continued use of the Service following notification constitutes acceptance of the updated policy.

    Previous versions of this Privacy Policy are available upon request.

    17. Contact Us

    For any questions, concerns or requests relating to this Privacy Policy or the processing of your personal data, please contact us:

    Email: data-protection-office@customsurgical.co
    Post: Custom Surgical GmbH, Agnes-Pockels-Bogen 1, 80992 Munich, Germany
    DPO: Fernando Benito Abad

    Effective date: 19.06.2026 · Version: 1.0

    Custom Surgical logo
    FacebookInstagramLinkedInTwitterYouTubeTikTok
      • Legal
      •  
      • Press
      • Careers
      •  
      • Compatibility
      • Open Source
      • Micro3D
      • MedSHIELD
      • Kohnspirator
      •  
      • Support
      • FAQs
      • Manuals
      • Contact us
    Subscribe to our newsletter and never miss any news!
    Step on top to receive exclusive offers, news in the sector, the next conferences, tips about recordings, and much more!
    Subscribing authorizes newsletter and new content related to news, conferences, recordings, and more to be sent to email.

    ISO certification

    © 2019-2026 Custom Surgical GmbH — Munich, Germany | Impressum

    v.1.0.1