Privacy Policy
Effective date: 19 August 2026
Last updated: 19 August 2026
This Privacy Policy explains how MEDICAL-AI SA (“Surge-ID”, “we”, “us”, “our”) handles personal datain connection with the Surge-ID application and dashboard (the “Platform”). We are committed toprotecting personal data in accordance with the Swiss Federal Act on Data Protection (nFADP / nLPD)and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Scope and who this policy is for
The Platform is a professional tool for surgeons and other healthcare professionals (“Users”) torecord surgical activity, maintain a digital logbook and surgical identity, and analyze clinical data.
This policy primarily describes how we handle the personal data of Users. It also explains,transparently, how patient data is processed through the Platform and the respective responsibilitiesinvolved (see Section 3). The Platform is intended for use by healthcare professionals andinstitutions, and is not directed at the general public or at children as Users.
2. Who we are (identity and contact)
MEDICAL-AI SA
Rue du Marché 28 c/o Radvice SA, 1204 Genève
Company registration no.: CHE-302.786.040
Email: contact@surge-id.com
Website: www.surge-id.com
Data protection contact / DPO: contact@surge-id.com
3. Our role: controller and processor
Our responsibilities depend on the type of data:
User data (controller). For data about Users — such as account details, professional profile, surgical logbook, and usage — MEDICAL-AI SA acts as the data controller and this policy governs that processing.
Patient data (processor). When a User or healthcare institution enters or connects patient data through the Platform, the healthcare institution (and/or the treating clinician) is the data controller, and MEDICAL-AI SA acts as a data processor on their behalf. That processing is governed by a Data Processing Agreement (DPA) between us and the institution, and by the institution’s own privacy notice to patients — not by this policy. We process patient data only on documented instructions from the controller
4. Data we process
4.1 User (healthcare professional) data — we are controller
• Identity and contact: name, email address, and similar contact details.
• Professional profile: role/seniority, specialty, institution/establishment, certifications, and training/logbook records (procedures, operative techniques, surgical exposure, complications, operative time, skill progression).
• Usage, device and analytics data: features used, session data, device type, operating system, and diagnostic/performance data, to operate, secure and improve the Platform.
4.2 Patient data — we are processor (on behalf of the institution)
Depending on how the controlling institution configures the Platform, this may include health data such as: patient clinical metadata, diagnoses, surgical/operative details, implanted device data, medical imaging (PACS/DICOM), complications, and patient-reported outcome measures (PROMs).
This is special-category (sensitive) health data. It is processed strictly on behalf of, and under the instructions of, the controlling institution, under a DPA and appropriate safeguards.
5. Legal bases for processing
For User data (controller):
• Performance of a contract (Art. 6(1)(b) GDPR / corresponding nFADP basis) — to provide the Platform and manage your account and logbook.
• Legitimate interests (Art. 6(1)(f)) — to secure, maintain and improve the Platform, where not overridden by your rights.
• Consent (Art. 6(1)(a)) — for optional features such as location access, which you can withdraw at any time.
For patient (health) data (processor): the applicable legal basis and, for special-category data, the Article 9 GDPR condition (e.g. explicit consent, or provision of healthcare / management of health-care systems under Art. 9(2)(h), and the equivalent nFADP conditions) are determined by the controlling institution, not by us.
6. How we use data
We use User data to provide, operate, secure, and improve the Platform; manage accounts and the digital logbook/surgical identity; deliver analytics and dashboards; support training, certification and recertification workflows; and comply with legal obligations. We process patient data only to provide the contracted services to the controlling institution.
We do not sell personal data and do not use it for third-party advertising.
7. Sharing, sub-processors and disclosure
We share data only as needed to run the Platform and as permitted by law or by the relevant controller’s instructions:
• Sub-processors / infrastructure providers operating strictly on our behalf under data-processing terms. Our data is hosted in Swiss data centers. Our principal sub-processor is Apptitude SA (Switzerland), which develops, operates and maintains the Platform on our behalf under a data-processing agreement, together with its Swiss data-center hosting provider.
• Healthcare institutions you are affiliated with, in accordance with the applicable arrangements and controller instructions.
• Multicentric collaborations, research and registries, and medtech/device studies (CE/FDA, PMCF): where data is used for research or certification studies, it is shared under appropriate agreements and, wherever possible, in anonymized or pseudonymized form, subject to the controller’s authorization and any required ethics approval and consent.
• Legal requirements: where required by law, court order, or a valid request from a competent authority.
• Business transfers: in a merger, acquisition or asset sale, with appropriate protections and notice.
8. Research, registries and secondary use
Where data is used to build prospective registries, multicentric studies, outcome tracking, or MedTech-ready datasets, such secondary use is subject to the controlling institution’s authorization and to applicable law — which in Switzerland may include the Human Research Act (HRA) and the requirement for ethics-committee approval and/or patient consent, and equivalent rules in other jurisdictions. Data used for research is anonymized or pseudonymized wherever feasible.
9. International data transfers
Where personal data is transferred outside Switzerland or the EEA, we ensure an adequate level of protection through appropriate safeguards, such as an adequacy decision or the European Commission’s / FDPIC’s Standard Contractual Clauses.
10. Data retention
We retain personal data only as long as necessary for the purposes above and as required by applicable law and by controller instructions:
• User account and logbook data: retained while the account is active and for 24 months afterwards. Note: logbook/traceability records may need to be retained to serve as proof of clinical activity for certification/recertification. Logbook and traceability records may therefore be retained for up to 10 years after account closure, unless the User requests earlier deletion and no legal or certification requirement prevents it.
• Usage/analytics data: 12 months
• Patient data: retained per the controlling institution’s instructions and applicable medical record-retention law.
11. Security
We apply appropriate technical and organizational measures to protect personal data, including end-to-end encryption (RSA), cryptographic signatures for data integrity, hosting in Swiss data centers, access controls, and encryption at rest, audit logging, a documented data-breach response procedure, and confidentiality undertakings binding all staff and contractors. A Data Protection Impact Assessment (DPIA) has been conducted for the Platform. No system is perfectly secure, but we work continuously to protect your data.
Recovery key and irreversible loss of access. The Platform is designed so that the cryptographic keys protecting your data are generated on your device and are never transmitted to us in a form we can read. We hold no copy of these keys and operate no key escrow. When your account is created, you are shown a recovery key once and asked to store it securely; it is the only means of restoring access to your encrypted data on a new or reset device. Because we cannot read, reset, reissue or reconstruct that key, its loss means that data already encrypted under it becomes permanently unreadable — by you, by your institution and by us. This is a deliberate consequence of the confidentiality guarantee described above, not a defect of the service. Users are responsible for retaining their recovery key, and healthcare institutions acting as controllers should take this characteristic into account in their own record-retention, business-continuity and clinical-governance arrangements. Where an institution requires continuity of access independent of any individual User, this must be arranged contractually in advance, as it cannot be provided retroactively.
12. Your rights
Under the nFADP and, where applicable, the GDPR, individuals have the right to access, rectify, erase,
restrict, or object to processing of their personal data, to data portability, and to withdraw consent at
any time (without affecting prior processing).
• Users may exercise these rights by contacting us at contact@surge-id.com.
• Patients should generally direct requests to the healthcare institution acting as controller; where we receive such a request, we will refer it to, or handle it under the instructions of, that controller.
You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch, or, in the EU/EEA, with your local supervisory authority.
13. Children
The Platform is not directed at children as Users. Patient data processed through the Platform may relate to minors (e.g. paediatric surgery); such data is handled by the controlling institution under the applicable legal basis and safeguards for children’s health data.
14. Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date and, for significant changes, notify Users in the Platform or by email.
15. Contact
MEDICAL-AI SA
Email: contact@surge-id.com
Rue du Marché 28 c/o Radvice SA, 1204 Genève
Data protection contact / DPO: contact@surge-id.com