1. Controller and contact
The data controller is the service provider identified in Legal Information. Privacy contact: contact@loginesis.com. The complete service-provider address is kept in one place to limit unnecessary duplication.
2. Products and data separation
Loginesis Digital is the parent product brand. SurgiCrew and LookWhoAte use separate product databases, session cookies and secret names. An account or workspace identifier from one product must not grant access to another product’s records.
- SurgiCrew: account, professional profile, workspace membership, organisational procedures, checklists, notes, chat, support and audit events. Patient-identifying data is prohibited; file uploads are disabled while R2 is absent.
- LookWhoAte beta: account, public handle and display name, manually entered restaurants and coordinates, ratings, comments, rating visibility, connection requests, want-to-visit items and deliberately shared review links. It does not use demo records, device location, Google Places or advertising profiles.
- Parent website: language and consent preferences stored on the device; contact form content is not transmitted until a contact endpoint is configured.
3. Purposes and legal bases
Account and workspace data is used to provide the requested service under steps requested before a contract and performance of the service agreement. Security records are used to prevent abuse and protect the service on the basis of legitimate interests, balanced against user rights. Records required by law are processed to meet legal obligations. Optional analytics or personalised advertising remains disabled and would require a separate legal assessment and prior consent where applicable.
- Service delivery: steps requested before a contract and performance of the agreement.
- Security and abuse prevention: legitimate interests, with necessity and balancing documented before production.
- Legal records: compliance with applicable legal obligations.
- Optional analytics and personalised ads: inactive; prior consent where required before activation.
4. Recipients, processors and transfers
Cloudflare Workers and D1 infrastructure are reflected in the current SurgiCrew staging architecture. Exact contracting entity, hosting region, subprocessors, transfer mechanism, DPA and retention must be verified before launch. Google receives OAuth data only after Google sign-in is configured and used. Resend is selected for SurgiCrew transactional verification and recovery e-mail and would receive the recipient, message and one-time action link. The owner reports that mail.loginesis.com is verified in Resend's Ireland (eu-west-1) region; sending remains inactive until the protected staging secret and final protected callback base URL are supplied. No ad, analytics, AI, OCR, maps or Google Places provider is active in this preview.
- [PROCESSOR REGISTER — REQUIRED]
- [EOG / NON-EOG TRANSFER REVIEW — REQUIRED]
- [DPA AND SUBPROCESSOR REVIEW — REQUIRED]
5. Retention and deletion
Retention periods must follow documented necessity and be configured before launch. SurgiCrew includes a technical account-deletion service that invalidates sessions, removes personal records and anonymises shared organisational authorship where documented; file removal remains inactive while R2 is absent. LookWhoAte beta supports password-reauthenticated account deletion: its product session, credentials and social data are deleted, while manually contributed restaurant records may remain with the creator reference removed. Automated LookWhoAte expiry cleanup and a legal retention review are still required before production.
- Account and profile: until deletion, plus only the documented post-deletion records required by law or security.
- Private files: no staging storage while R2 is absent and uploads are disabled.
- Security and audit records: [RETENTION PERIOD — REQUIRED].
- Support/contact requests: target 365 days; live scheduled execution remains to be activated and observed.
6. Your rights
Depending on applicable law, you may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. Withdrawing consent does not affect prior lawful processing. Use the Data controls page or contact contact@loginesis.com. Identity verification may be necessary before a request is completed.
7. Files, user content and moderation
SurgiCrew attachments are intended to remain private and workspace-scoped. Do not upload patient data, unsafe files or material you are not authorised to share. LookWhoAte production reviews and comments require report, block, moderation, notice and appeal operations before launch. File sanitation/malware scanning and moderation staffing remain launch blockers.
8. Children and regulated contexts
SurgiCrew is intended for adult operating-room professionals and authorised adult trainees. The final minimum age and store classification are [OWNER / STORE REVIEW REQUIRED]. LookWhoAte minimum age and guardian flows are [OWNER / LEGAL REVIEW REQUIRED]. Neither product should be presented as medical-record or clinical-decision software.
