Privacy Notice & Terms of Use

Last updated: March 2026 SurgiCheck · surgicheck.net
SurgiCheck is a Clinical Decision Support System. It does not diagnose, prescribe, or make autonomous clinical decisions. All clinical responsibility remains with the treating clinician.

1. Data Controller and Processor

Under UK/EU GDPR, responsibility for patient personal data is allocated as follows:

Where SurgiCheck determines the purposes of processing (e.g. platform security, product development on aggregated non-identifiable data), it acts as an independent controller for those limited operations.

2. Platform Purpose and Scope

SurgiCheck is a perioperative risk screening and workflow management platform for aesthetic and plastic surgery clinics. The platform covers patient pre-assessment forms, clinician decision support, digital informed consent documentation, and post-operative follow-up modules.

SurgiCheck operates as a Clinical Decision Support System (CDSS). It does not generate autonomous surgical decisions; final clinical responsibility rests entirely with the treating clinician.

3. Personal Data Processed

The platform processes the following personal and special category data:

4. Lawful Basis for Processing (UK GDPR / EU GDPR)

Processing is justified under two required layers: an Article 6 basis for general lawfulness, and an Article 9 condition for special category (health) data.

Article 6 — lawfulness of processing:

Article 9 — condition for special category (health) data:

Patients may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand, nor processing that continues to be required under Art. 9(2)(h) or under records-retention law. Contact: privacy@surgicheck.net

5. Data Storage and Security

All data is stored on Firebase (Google Cloud) infrastructure. Data centre region: Europe (eur3).

TLS encryption in transit Role-based access control Append-only audit trail Audit log

Medical records (cases, consents, follow-up responses) are preserved as an append-only audit trail: the original entry is never overwritten. Corrections are recorded as new, timestamped versions alongside the original, preserving both accuracy and audit integrity. Deletion (where legally required or requested) can only be performed by an administrator via Firebase Console, in accordance with applicable data retention obligations.

Retention periods are determined according to record type, clinic policy, contractual requirements, and applicable national law governing medical records.

6. Data Sharing

Patient data is not shared with third parties for commercial purposes. Data may be accessed or transferred only in the following circumstances:

7. Your Rights (UK GDPR / EU GDPR Art. 15–22)

You have the following rights, exercisable against the data controller (see Section 1):

To exercise your rights: privacy@surgicheck.net (requests are routed to the responsible controller).

8. Terms of Use

By using the SurgiCheck platform, you agree to the following:

9. Contact

For privacy and data processing requests: privacy@surgicheck.net

General enquiries: surgicheck.net