Controller and scope
The service provider identified in the central Privacy Policy is the controller for SurgiCrew. Product data is kept in a product-specific boundary and must not be used to grant access to the other application.
Open central Privacy PolicyAccount authentication
SurgiCrew supports e-mail/password and may also use its own Google OAuth/OpenID Connect client. Passwords are stored only as salted, deliberately slow hashes strengthened with a server-only pepper. Short-lived, one-use verification and password-reset tokens are stored only as hashes. The configured e-mail delivery provider receives the recipient and an action link. Google supplies a stable account identifier, verified e-mail, display name and optional avatar only after the user chooses Google sign-in. Secrets remain only in protected server configuration and are never sent to the browser or committed to the repository.
Data and purposes
SurgiCrew processes account, professional profile, workspace membership, organisational procedures, checklists, notes, messages, audit events and private attachments. Patient-identifying data is prohibited.
Legal bases and retention
Service performance, account security, legal obligations and legitimate interests may apply depending on the processing activity. Optional analytics or personalised advertising requires valid consent where applicable. Final legal bases and retention periods require professional review before production. Account data is retained while the account is active and then deleted or anonymised according to the documented deletion flow, legal duties, security needs and backup schedule.
Your GDPR rights
Subject to applicable law, you may request access, rectification, erasure, restriction, objection, portability, withdrawal of consent and lodge a complaint with the competent supervisory authority. Contact us at contact@loginesis.com. Identity verification may be required.
