Custom Surgical logo

  • Home
  • About
  • Hardware
    MicroREC
    MicroREC banner
    The ultimate optical system to digitize your microscope or slit lamp
    MicroREC Ultra
    MicroREC logo
    The best image quality in the market.
    OptiREC
    OptiREC logo
    The slit lamp adapter for your diagnostic pictures
    MicroREC 3D
    MicroREC 3D logo
    Experience the future of surgical visualization
    Software
    Connect logo
    MicroREC Connect
    Manage your medical data anywhere and at any time.
    Business logo
    Business
    Get control of your clinic imagery.
    Smartphone
    MicroREC App logo
    Free App to improve your recordings and organize them
    Accessories
    Accessory
    Accessory logo
    Increase compatibility and improve your workflow.
    Contact
      |  
    Sales Support
  • Blog
Go to Connect

Custom Surgical Logo

  • Home
  • About
  • Products
    Hardware
    MicroRECMicroREC UltraOptiRECMicroREC 3D
    Accessories
    Accessory
    Software
    MicroREC ConnectMicroREC Connect BusinessMicroREC App
  • Blog
  • Data Processing Addendum

    Version 2.1 · Effective Date: 01.06.2026

    This Data Processing Addendum ("DPA") forms part of the agreement between Custom Surgical GmbH and the Customer and governs the processing of personal data by Custom Surgical on behalf of the Customer.

    VersionEffective DateDPOJurisdiction
    2.101.06.2026Fernando Benito Abad
    data-protection-office@customsurgical.co
    Munich, Germany
    Change History
    RevisionRevised byDateApproved by
    1.0Fernando Benito Abad22.05.2023Fernando Benito Abad
    2.0Fernando Benito Abad03.02.2026Fernando Benito Abad
    2.1Fernando Benito Abad01.06.2026Fernando Benito Abad
    1. General

    The subject matter of the agreement is the regulation of the rights and obligations of the responsible party (Customer) and the processor (Custom Surgical), insofar as the processing of personal data by Custom Surgical for the Customer within the meaning of the applicable data protection law takes place within the scope of the service provision (according to the Terms & Conditions and other applicable documents).

    2. Definitions

    "Agreement" means Custom Surgical's Terms & Conditions, or other written or electronic agreement, which govern the provision of the Service to Customer, as such terms or agreement may be updated from time to time.

    "Customer Data" means any personal data that Custom Surgical processes on behalf of Customer via the Service, as more particularly described in this DPA.

    "Data Protection Laws" means all data protection laws and regulations applicable to a party's processing of Customer Data under the Agreement, including, where applicable, European Data Protection Laws and Non-European Data Protection Laws.

    "European Data Protection Laws" means all data protection laws and regulations applicable to Europe, including (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; (iii) applicable national implementations of (i) and (ii); (iv) the GDPR as it forms part of UK law by virtue of section 3 of the UK European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 (together, "UK Data Protection Laws"); and (v) the Swiss Federal Data Protection Act of 19 June 1992 and its Ordinance ("Swiss DPA").

    "Europe" means, for the purposes of this DPA, the European Economic Area and its member states ("EEA"), Switzerland and the United Kingdom ("UK").

    "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data transmitted, stored, or otherwise processed by Custom Surgical or its Subprocessors.

    "Service" means the Custom Surgical data management ecosystem, comprising the MicroREC App (iOS and Android), MicroREC Desktop (Windows and macOS), and MicroREC Connect (web application), together with the associated cloud backend infrastructure operated by Custom Surgical.

    "Subprocessor" means any processor engaged by Custom Surgical to assist in fulfilling its obligations with respect to providing the Service pursuant to the Agreement or this DPA.

    The terms "personal data", "controller", "data subject", "processor" and "processing" shall have the meaning given to them under applicable Data Protection Laws or if not defined thereunder, the GDPR.

    3. Rights and Obligations of the Customer
    3.1 Lawfulness of the Data Processing

    The Customer is solely responsible for the assessment of the admissibility of the data processing as well as for the protection of the rights of the Data Subjects. The Customer will take care in their area of responsibility to ensure that the legally required conditions are met (for example, by obtaining declarations of consent), so that Custom Surgical can provide the agreed services in a lawful manner.

    3.2 Purpose Limitation

    Custom Surgical shall process Customer Data, as further described in Annex A of this DPA, only in accordance with Customer's documented lawful instructions as set forth in this DPA, as necessary to comply with applicable law, or as otherwise agreed in writing ("Permitted Purposes"). The parties agree that the Agreement, including this DPA, along with the Customer's configuration of or use of any settings, features, or options in the Service constitute the Customer's complete and final instructions to Custom Surgical in relation to the processing of Customer Data and processing outside the scope of these instructions (if any) shall require prior written agreement between the parties.

    3.3 Lawfulness of Customer's Instructions

    Customer will ensure that Custom Surgical's processing of the Customer Data in accordance with Customer's instructions will not cause Custom Surgical to violate any applicable law, regulation, or rule, including, without limitation, Data Protection Laws. Custom Surgical shall promptly notify Customer in writing, unless prohibited from doing so under European Data Protection Laws, if it becomes aware or believes that any data processing instruction from Customer violates European Data Protection Laws.

    Where Customer acts as a processor on behalf of a third-party controller, Customer warrants that its processing instructions as set out in the Agreement and this DPA have been authorised by the relevant controller. Customer shall serve as the sole point of contact for Custom Surgical and shall be responsible for forwarding any notifications received under this DPA to the relevant controller, where appropriate.

    4. Rights and Obligations of Custom Surgical
    4.1 Data Processing

    Custom Surgical will process Customer Data exclusively in accordance with the Terms & Conditions and other applicable documents and this DPA and according to the instructions of the Customer in accordance with clause 3.2. Custom Surgical does not use Customer Data for any other purpose and will not disclose Customer Data it processes to unauthorised third parties. Copies and duplicates are not created without the prior consent of the Customer. This does not include backup copies to ensure proper data processing.

    4.2 Support for Obligations of the Customer

    Custom Surgical will assist the Customer in complying with its obligations under applicable law, as contractually agreed, taking into account the nature of the Processing and the information at its disposal.

    4.3 Support for Checks and Requests for Information

    If the Customer is obliged to provide information on the processing of Personal Data to a governmental body or a data subject, Custom Surgical will assist the Customer in providing this information, provided that such information relates to the contractual Data Processing and if the Customer cannot already comply with the request for information by itself or by appropriate selection of certain product parameters.

    To the extent that a person concerned directly applies to Custom Surgical for the purpose of asserting an affected right, Custom Surgical will forward the inquiries of the Data Subject promptly to the Customer. To the extent legally permissible, Custom Surgical will inform the Customer about notifications by the supervisory authorities in connection with the processing of Personal Data according to this DPA. To the extent legally permissible, Custom Surgical shall provide information to third parties, including supervisory authorities, only after written approval by and in consultation with the Customer.

    4.4 Incident Reporting

    Where a Security Incident involves health data within the meaning of Article 9 GDPR, Custom Surgical will endeavour to notify the Customer within 24 hours of becoming aware of the incident. In all cases, Custom Surgical will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a Security Incident affecting Customer Data. Such notification shall include, to the extent available at the time: (i) a description of the nature of the Security Incident, including the categories and approximate number of data subjects and records affected; (ii) the name and contact details of the Data Protection Officer or other relevant contact point; (iii) a description of the likely consequences of the Security Incident; and (iv) a description of the measures taken or proposed to address the Security Incident.

    Custom Surgical shall provide the Customer with sufficient information to enable the Customer to meet its own obligations under applicable Data Protection Laws, including, where required, the obligation to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach under Article 33 GDPR. Custom Surgical will cooperate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of each Security Incident.

    4.5 Proof and Documentation

    The Parties shall assist each other in demonstrating and documenting their accountability with respect to the principles of due processing of Personal Data.

    4.6 Privacy Impact Assessment

    If the Customer conducts a privacy assessment and/or intends to consult the supervisor for a privacy impact assessment, then the parties will agree on the content and scope of any support provided by Custom Surgical as and when requested by the Customer.

    4.7 Return or Deletion of Data

    Customer Data is retained for the duration of the active account lifecycle. For the purposes of this DPA, an "active account" means an account under which the user has logged in or captured data within the preceding 36 months, or which holds an active paid subscription regardless of recent login activity.

    All users upload patient metadata to the cloud backend from the point of account creation. Paid and formerly paid (downgraded) subscribers additionally upload media data (photographs and videos). Both categories of data are retained for the duration of the active account, subject to the tier distinctions described below:

    • - All users (including free tier): Patient metadata and structured session data retained for the duration of the active account.
    • - Paid and downgraded subscribers: Media data (photographs and videos) additionally retained for the duration of the active account. Downgraded subscribers retain full access to their existing media data on the basis that continued cloud storage relieves local device storage constraints and enables remote access to historical clinical cases.

    Where an account has been inactive for 36 consecutive months, Custom Surgical will notify the account administrator by email and proceed to delete the account and all associated Customer Data within 30 days unless the Customer reactivates the account or submits a written request to extend retention.

    Upon receipt of a formal written account deletion request, Custom Surgical shall delete all Customer Data from both the primary cloud backend and the secondary research and development environment within 30 days and provide written confirmation of deletion upon request. This requirement shall not apply to the extent Custom Surgical is required by applicable law to retain certain data, in which case such data shall be securely isolated and protected from any further processing until the applicable retention obligation expires.

    5. Subprocessors
    5.1 Authorization

    Custom Surgical may use additional processors (Subprocessors and Sub-subprocessors) to perform the tasks described in this DPA. Commissions that Custom Surgical places with third parties as ancillary services to support the execution of the work assigned to it and that do not involve commissioned processing of Personal Data for the Customer shall not be regarded as a subprocessing relationship within the meaning of this provision.

    5.2 Acceptance of Current Subprocessors

    By accepting the Terms & Conditions at signup, the Customer accepts this DPA in its current version, including the list of approved Subprocessors set out in Annex A. This acceptance constitutes the Customer's general written authorisation for Custom Surgical to engage the Subprocessors listed therein for the purposes described.

    5.3 Changes to Subprocessors

    Custom Surgical shall notify the Customer in writing of any intended addition or replacement of Subprocessors prior to the change taking effect. Such notification shall be provided with reasonable advance notice — no less than 14 days before the change takes effect — and shall include the name, address, and nature of the services provided by the new or replacement Subprocessor.

    If the Customer has legitimate grounds to object to the proposed change on data protection grounds, the Customer must notify Custom Surgical in writing within 14 days of receiving the notification. Custom Surgical and the Customer shall work in good faith to resolve the objection. If no resolution can be reached, the Customer may terminate the relevant services on written notice, without penalty, before the change takes effect.

    If the Customer does not object within the 14-day period, the change shall be deemed accepted and Annex A will be updated accordingly. Custom Surgical shall also notify the Customer without undue delay if any Subprocessor loses its certification under the EU–US Data Privacy Framework, if the Standard Contractual Clauses relied upon by a Subprocessor are modified or replaced, or if any transfer mechanism relied upon by a Subprocessor ceases to be valid under applicable Data Protection Laws. In such cases, Custom Surgical shall take prompt steps to implement an alternative valid transfer mechanism and inform the Customer accordingly.

    5.4 Notification Method

    Notifications of Subprocessor changes shall be provided by email to the account administrator registered on the Customer's account, or by publication of an updated version of this DPA on Custom Surgical's website with a corresponding notice to the Customer. Custom Surgical shall maintain a version history of this DPA, including a record of Subprocessor changes, accessible on its website.

    5.5 Selection of Subprocessors

    Custom Surgical will select Subprocessors who provide reasonable guarantees that the agreed appropriate technical and organisational measures will be performed in such a way that the processing will be carried out in accordance with the requirements of the relevant applicable legal provisions. Custom Surgical will enter into contractual agreements with Subprocessors that comply with the content of the contractual provisions of this DPA.

    6. Security
    6.1 Security Measures

    Custom Surgical shall implement and maintain appropriate technical and organisational security measures that are designed to protect Customer Data from Security Incidents and designed to preserve the security and confidentiality of Customer Data in accordance with Custom Surgical's security standards described in Annex B of this DPA.

    6.2 Confidentiality of Processing

    Custom Surgical shall ensure that any person who is authorised by Custom Surgical to process Customer Data (including its staff, agents, and subcontractors) shall be under an appropriate obligation of confidentiality (whether a contractual or statutory duty).

    6.3 Updates to Security Measures

    Customer is responsible for reviewing the information made available by Custom Surgical relating to data security and making an independent determination as to whether the Service meets Customer's requirements and legal obligations under Data Protection Laws. Customer acknowledges that the Security Measures are subject to technical progress and development and that Custom Surgical may update or modify the Security Measures from time to time, provided that such updates and modifications do not result in the degradation of the overall security of the Service provided to Customer.

    6.4 Customer Responsibilities

    Notwithstanding the above, Customer agrees that except as provided by this DPA, Customer is responsible for its secure use of the Service, including securing its account authentication credentials, protecting the security of Customer Data when in transit to and from the Service, and taking any appropriate steps to securely encrypt or backup any Customer Data uploaded to the Service.

    7. Audits and Proofs
    7.1 Proof from Custom Surgical

    Custom Surgical shall, upon written request from the Customer, provide evidence of the sufficient implementation of its obligations under this DPA and applicable Data Protection Laws. Such evidence may include: (i) the technical and organisational measures described in Annex C of this DPA; (ii) relevant third-party audit reports, certifications, or security assessments (such as ISO 27001, SOC 2, or equivalent); and (iii) written responses to reasonable information requests relating to the processing activities covered by this DPA. Custom Surgical shall maintain such documentation and make it available to the Customer or to the relevant supervisory authority upon request.

    7.2 Checks and Inspections

    The Customer may audit at its own expense compliance with the data protection regulations and the obligations stipulated in this DPA by requesting the evidence described in Section 7.1. Where the Customer reasonably considers that such documentary evidence is insufficient, the Customer may, at its own expense and with reasonable prior written notice of no less than 30 days, conduct or commission an on-site inspection of Custom Surgical's data processing facilities and practices. The Customer may perform such inspections itself or commission a qualified third party, provided that such third party is not a competitor of Custom Surgical and is bound by a documented confidentiality obligation prior to the inspection. The Customer shall take due care not to disrupt Custom Surgical's business operations during any such inspection.

    8. International Transfers
    8.1 Data Center Locations

    Custom Surgical's primary infrastructure is hosted on Google Cloud Platform, with data stored and processed exclusively within data centers located in the European Union. Secondary processing for internal research and development purposes is carried out within AWS data centers located in the European Union, as described in Annex A. Custom Surgical does not operate data centers outside the European Union and does not transfer Customer Data outside the European Economic Area except where this occurs indirectly through the use of approved Subprocessors whose ultimate parent entities are established in third countries. All such transfers are subject to the safeguards described in Section 8.2 and documented in Annex D.

    8.2 European Data Transfers

    To the extent that Custom Surgical engages Subprocessors whose parent entities are established in countries outside of Europe that are not recognised as providing an adequate level of protection for personal data under applicable European Data Protection Laws, Custom Surgical ensures that appropriate safeguards are in place for any such transfers. These safeguards include, as applicable: (i) reliance on Standard Contractual Clauses (SCCs) as provided by the relevant Subprocessor in their data processing agreements; (ii) reliance on adequacy decisions adopted by the European Commission; or (iii) reliance on certification under the EU–US Data Privacy Framework or equivalent recognised transfer mechanism. Custom Surgical shall ensure that each Subprocessor maintains and, upon request, provides evidence of the applicable transfer mechanism. A summary of the transfer mechanisms relied upon by each approved Subprocessor is set out in Annex D.

    9. Liability and Indemnity
    9.1 Area of Responsibility of the Customer

    The Customer, in its area of responsibility, ensures the implementation of the obligations arising from the relevant applicable legal provisions in the Processing of Personal Data.

    9.2 Liability

    The liability regulation from the Terms & Conditions and the other applicable documents applies to this DPA, as far as a limitation of liability in accordance with the relevant applicable legal provisions in favour of Custom Surgical does not apply.

    10. Term and Termination

    This agreement is valid for the duration of the actual service provision by Custom Surgical. This applies regardless of the terms of any other contracts (in particular the Terms & Conditions and the other applicable documents), which the parties have also concluded with regard to the provision of the agreed services.

    11. Miscellaneous
    11.1 Validity of the Agreement

    The validity of the remaining provisions shall remain unaffected by the invalidity of any provision of this DPA. If a provision proves ineffective, the parties will replace it with a new one that comes closest to that desired by the parties.

    11.2 Changes to Agreement

    All changes to this DPA and ancillary agreements must be in writing (including electronic form). This also applies to the termination of this written form clause itself. Notwithstanding the foregoing, changes to the list of approved Subprocessors in Annex A may be notified via Custom Surgical's website in accordance with the notification procedure set out in Section 5.4, which shall constitute written notice for the purposes of this clause.

    11.3 General Terms and Conditions

    It is agreed between the parties that the "General Terms and Conditions" of the Customer do not apply to this DPA.

    11.4 Applicable Law

    This DPA is founded on the EU General Data Protection Regulation (EU GDPR).

    11.5 Precedence

    In the case of contradictions between the provisions of this DPA and provisions of other agreements, in particular the Terms & Conditions and the other applicable documents, the provisions of this DPA shall prevail. Incidentally, the provisions of the Terms & Conditions and the applicable documents remain unaffected and apply accordingly to this DPA.

    11.6 Jurisdiction

    Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Munich, Germany.

    ANNEX A
    Details of Data Processing
    (a) Categories of Data Subjects
    • - End users — individual clinicians or staff members accessing the Service under a personal or organisational account
    • - Account administrators — individuals within a customer organisation who manage account settings, user access, and billing on behalf of the organisation
    • - Patients — natural persons whose personal data is processed by users of the Service
    (b) Categories of Personal Data
    • - End user profile information (full name, email address, country of residence, profession)
    • - Account administrator information (full name, email address, role/title, organisation name, billing contact details)
    • - Organisation information (legal name, address, type of clinical setting) — to the extent that this information is linked to or identifies a natural person
    • - Billing and payment information (name, email address, billing address, tokenised payment identifiers, last four digits of payment card, card type and expiry date) — note: raw payment card data (full card number, CVV) is processed exclusively by Stripe Technology Europe, Limited acting as an independent data controller and does not fall within the scope of this DPA
    • - User content (photographs, videos, audio recordings, patient IDs, session labels, session descriptions, session dates and session locations)
    • - Technical information (IP address, device model, operating system version, device ID, user ID, configuration of the app, time and date of the use of the Service)
    • - All other personal data as defined in Article 4 no. 1 of GDPR that is transmitted by the customer or stored during use of the product where access by Custom Surgical's system administrators cannot be excluded.
    (c) Sensitive Data Processed

    The following categories of sensitive (special category) data within the meaning of Article 9 GDPR are processed in connection with the Service:

    • - Clinical media content constituting health data: photographs and videos of ophthalmic procedures and ocular anatomy captured through the Service, including slit-lamp recordings and equivalent clinical imaging
    • - Audio recordings associated with clinical sessions (note: audio tracks are stripped of patient-identifying content prior to storage)
    • - Session descriptions and clinical notes entered by users that may contain health-related information
    • - All other personal data as defined in Articles 4 no. 13–15 of GDPR that is transmitted by the customer or stored during use of the product where access by Custom Surgical's system administrators cannot be excluded.

    Lawful basis for processing sensitive data: Custom Surgical processes the above sensitive data in its capacity as a data processor acting on the documented instructions of the Customer. The Customer, as data controller, is solely responsible for ensuring that a valid legal basis under Article 9(2) GDPR exists for processing special category data. The applicable basis will typically be Article 9(2)(h) GDPR — processing necessary for the purposes of the provision of healthcare services and the clinical management of patients — in conjunction with a professional secrecy obligation under Article 9(3) GDPR. The Customer warrants that it has identified and documented a valid Article 9 basis prior to using the Service to process special category data, and that it will maintain such a basis for the duration of the Agreement.

    (d) Frequency of Processing

    Personal data is processed on a continuous basis for as long as the Customer maintains an active account and uses the Service. Processing occurs automatically in response to actions taken by end users and account administrators within the Service (such as capturing, uploading, or accessing clinical media), as well as through background operations required to maintain, secure, and improve the Service (such as backups, replication, and system monitoring). The frequency and volume of processing is therefore determined by the Customer's usage of the Service, not by a fixed schedule set by either party.

    (e) Subject Matter and Nature of the Processing

    Custom Surgical provides a data management ecosystem for the capture, storage, and remote access of clinical media and patient information, as more particularly described in the Terms & Conditions. The Service comprises multiple interfaces — MicroREC App (iOS and Android), MicroREC Desktop (Windows and macOS), and MicroREC Connect (web application) — which interact with a shared cloud backend hosted on Google Cloud Platform. Data captured or uploaded via any interface is stored in the cloud backend and may be accessed and managed through any other interface by authorised users. Customer Data will be processed in accordance with the Agreement (including this DPA) and may be subject to the following processing activities:

    • - Storage and other processing necessary to provide, maintain and improve the Service provided to Customer pursuant to the Agreement; and/or
    • - Disclosures in accordance with the Agreement and/or as compelled by applicable law.
    (f) Purpose of the Processing

    Custom Surgical shall only process Customer Data for the Permitted Purposes, which shall include: (i) processing as necessary to provide the Service in accordance with the Agreement; (ii) processing initiated by Customer in its use of the Service; and (iii) processing to comply with any other reasonable instructions provided by Customer (e.g., via email) that are consistent with the terms of the Agreement.

    Secondary purpose – product development: Custom Surgical retains pseudo-anonymised media data (photographs and videos) from paid and formerly paid (downgraded) subscriber accounts in a separate research and development environment hosted on Amazon Web Services EMEA SARL infrastructure within the European Union. This data is used for internal product development purposes, including the improvement and development of the Service. The lawful basis for this secondary processing is Article 6(1)(f) GDPR (legitimate interests). This data is subject to the same active account retention policy as the primary service data: it is retained for the duration of the active account and deleted upon account deletion request or following the 36-month inactivity process described in Section 4.7. Custom Surgical's Legitimate Interests Assessment for this processing activity is available upon written request. Free-tier-only users whose media data has never been stored in the cloud are not subject to this secondary processing. For the avoidance of doubt, Custom Surgical acts as an independent data controller for this secondary R&D processing activity, as it determines the purpose of such processing independently of the Customer's instructions. This processing is carried out under Article 6(1)(f) GDPR (legitimate interests) as documented in Custom Surgical's Legitimate Interests Assessment, available upon written request. The Customer, acting in its capacity as data controller for its patients' data, may at any time object to this secondary processing on behalf of its data subjects by submitting a written objection to data-protection-office@customsurgical.co. Custom Surgical will honour such objections and exclude the Customer's data from the R&D dataset within 30 days of receipt. An objection to secondary R&D processing does not affect the primary service relationship or the terms of this DPA.

    (g) Duration of Processing and Retention Period

    Customer Data is retained for the duration of the active account lifecycle as defined in Section 4.7. The following retention periods apply by data category:

    • - Patient metadata and structured session data — all users: Retained for the duration of the active account. Deleted upon account deletion request or following the 36-month inactivity process described in Section 4.7.
    • - Media data (photographs and videos) — primary cloud backend (GCP): Retained for the duration of the active account for all paid and formerly paid (downgraded) subscribers. Not applicable to free-tier-only users who have not held a paid subscription. Deleted upon account deletion request or following the 36-month inactivity process.
    • - Pseudo-anonymised media data — secondary R&D environment (AWS): Retained for the duration of the active account for paid and formerly paid subscribers, on the basis of Custom Surgical's legitimate interests in product development (Article 6(1)(f) GDPR). Not applicable to free-tier-only users. Deleted upon account deletion request or following the 36-month inactivity process.
    • - All Customer Data: Permanently deleted from both environments within 30 days of a formal account deletion request, subject to any applicable legal retention obligations.
    (h) Approved Subprocessors
    SubprocessorAddressService TypeParent Company
    Firebase, Inc.22 4th Street Suite 1000, San Francisco, CA 94103, United StatesComputing and development toolsAlphabet, Inc.
    Google LLC1600 Amphitheatre Parkway, Mountain View, CA 94043, United StatesCloud infrastructure and data hosting; computing and development tools; software distributionAlphabet, Inc.
    Amazon Web Services EMEA SARL (Niederlassung Deutschland)Marcel-Breuer-Straße 12, 80807 Munich, Germany (Parent HQ: 38 Avenue John F. Kennedy, L-1855 Luxembourg)Cloud infrastructure for R&D secondary usage; product development — EU data centers onlyAmazon.com, Inc.
    Intercom R&D Unlimited Company124 St Stephen's Green, Dublin 2, D02 C628, IrelandCustomer messaging and support platformIntercom, Inc.
    HubSpot Ireland LimitedHubSpot House, 1 Sir John Rogerson's Quay, Dublin 2, D02 CR67, IrelandCustomer relationship management (CRM) and marketing automationHubSpot, Inc.
    Stripe Technology Europe, LimitedThe One Building, 1 Grand Canal Street Lower, Dublin 2, IrelandPayment processing and billing — acting as subprocessor for billing contact data transmitted by Custom Surgical, and as an independent data controller for raw payment card dataStripe, Inc.
    Mailchimp, Inc.675 Ponce de Leon Ave NE Suite 5000, Atlanta, GA 30308, United StatesEmail marketingIntuit, Inc.
    Apple, Inc.One Apple Park Way, Cupertino, CA 95014, United StatesComputing and development tools; software distributionN/A
    MailerSend, Inc.228 Park Ave S, PMB 54955, New York, NY 10003, United StatesTransactional email relay (account notifications, password resets, service emails)N/A
    Functional Software, Inc. (dba Sentry)45 Fremont Street, 8th Floor, San Francisco, CA 94105, United StatesError monitoring and crash reportingN/A
    Qonversion, Inc.1160 Battery Street East, Suites 100, San Francisco, CA 94111, United StatesSubscription analytics and in-app purchase managementN/A
    ANNEX B
    Security Measures
    Data Center Security

    Custom Surgical has partnered with Google Cloud to provide customers and applications with top-in-class security. Google Cloud data centers are protected with several layers of security to prevent any unauthorised access to data:

    • - Secure perimeter defense systems
    • - Comprehensive camera coverage
    • - Biometric authentication
    • - 24/7 guard and support staff
    Protection from Data Loss and Corruption
    • - All databases are kept separate and dedicated to preventing corruption and overlap.
    • - Data from different customers is kept separate through security rules and authentication requirements.
    • - Data is replicated across multiple Google Cloud availability zones and regularly backed up, with backups stored in geographically separate EU data center locations.
    Application Level Security
    • - Account passwords across all Service interfaces (MicroREC App, MicroREC Desktop, and MicroREC Connect) are hashed. Custom Surgical staff cannot view them. If a password is lost, it cannot be retrieved and must be reset.
    • - All login and signup information is securely encrypted in transit through TLS protocol across all interfaces.
    • - All communications between Service interfaces and the cloud backend are encrypted in transit through TLS protocol.
    • - MicroREC Connect (web application) enforces HTTPS exclusively, with session management controls including automatic session expiry for inactive sessions.
    Internal Protocol and Education
    • - Custom Surgical continuously trains employees on best security practices, including how to identify social engineering, phishing, scams and hackers.
    • - Access to customer data from Custom Surgical employees is tightly controlled by a least-permission policy.
    • - All employees sign a Privacy Safeguard Agreement outlining their responsibility in protecting customer data.
    • - All employee accounts use two-factor authentication and secure passwords, updated every 90 days.
    ANNEX C
    Technical and Organisational Measures

    Custom Surgical takes the following technical and organisational measures for data security within the meaning of Art. 32 GDPR.

    1. Confidentiality

    Physical Access Control

    Employees working on-site are required to access office spaces using their personal access keys. Additionally, a clean desk policy is enforced where all documents containing personal information must be stored in locked cabinets and shredded when no longer needed.

    Technical measures: Security locks; locking system with code lock.

    Organisational measures: Key regulations; visitors accompanied by staff members.

    System Access Control

    Laptops and PCs from both on-site and remote employees must lock after 1 minute of idle time. All passwords must be at least 8 characters long and be changed every 90 days.

    Technical measures: Login with username and password; two-factor authentication; anti-virus software clients; automatic screen lock.

    Organisational measures: Management of user permissions; secure password policy; clean desk policy; general policy "Data protection and security".

    Data Access Control

    Regarding access control, Custom Surgical follows a least-permission policy. Only a small number of employees are allowed to delete or move sensitive files. All files use automatic version control to avoid any accidental overwriting of personal data.

    Technical measures: Document shredding; access logs.

    Organisational measures: Use of authorisation concepts; minimum number of administrators; management of user rights by administrators only.

    Separation

    Custom Surgical has partnered with Google Cloud to provide services and infrastructure with virtualisation, which allows separation of services through different machines, and multi-regional data separation and redundancy.

    Technical measures: Separation of production and test environments. Encryption at rest: all Customer Data stored in the Service is encrypted at rest using AES-256 encryption, implemented through Google Cloud Platform's default server-side encryption. Encryption key management: encryption keys are managed by Google Cloud Key Management Service (Cloud KMS). Custom Surgical does not operate its own key infrastructure. Further information on Google Cloud encryption and key management is available at https://cloud.google.com/security/encryption-at-rest. Enhanced audit logging for health data: access to health-related data (including clinical media and patient metadata) by Custom Surgical personnel is subject to enhanced access controls under the least-privilege policy described in Section 1 (Data Access Control) above. Access events are logged automatically by Google Cloud audit logging infrastructure. Logs are retained for a minimum of 12 months and are available for review upon request in connection with a Customer audit conducted in accordance with Section 7 of the DPA.

    Organisational measures: Control via authorisation concept; definition of database rights.

    Pseudonymisation and Encryption

    Technical measures: In the case of pseudonymisation: separation of the assignment data and storage in a separate and secure system (preferably encrypted).

    Organisational measures: Internal instruction to anonymise/pseudonymise personal data as far as possible in the event of disclosure or after expiry of the legal deletion period.

    2. Integrity

    Input Control

    Access to all files containing personal information is registered in access logs. Automatic version control is used to avoid any accidental overwriting of personal data.

    Technical measures: Technical logging of the entry, modification, and deletion of data; version-controlled documents.

    Organisational measures: Overview of programs that can be used to enter, change, or delete data; traceability of data entry, modification, and deletion through individual user names (not user groups); assignment of rights for entering, changing, and deleting data on the basis of an authorisation concept; clear responsibilities for deletions.

    Transfer Control

    Technical measures: Logging of accesses and retrievals; provision via encrypted connections such as SFTP and HTTPS.

    3. Availability and Resilience

    Custom Surgical has partnered with Google Cloud to provide customers with over 99% SLA and infrastructure resilience through multi-regional redundancy. The following measures apply to Google Cloud's infrastructure, on which Custom Surgical's Service is hosted:

    Technical measures (Google Cloud infrastructure): Fire and smoke detection systems; physical security and environmental controls within data center facilities; data replication across multiple availability zones; automated failover mechanisms.

    Organisational measures (Custom Surgical): Backup and recovery concept (formulated); regular testing of backup restoration procedures; documented incident response and business continuity procedures.

    4. Procedures for Regular Review, Assessment and Evaluation

    Data Protection Management

    Custom Surgical uses centralised software tools to control and define access rights to all systems containing customer data.

    Technical measures: Software solutions for data protection management in use.

    Organisational measures: Employees trained and obligated to confidentiality/data secrecy; regular employee awareness training (at least once a year); the organisation complies with the information obligations according to Art. 13 and 14 GDPR.

    Incident Response Management

    Technical measures: Use of spam filter and regular updates.

    Organisational measures: Documentation of security incidents and data breaches, e.g., via ticket system.

    Privacy-Friendly Default Settings

    Technical measures: No more personal data is collected than is necessary for the respective purpose; simple exercise of the right of revocation of the data subject by technical measures.

    Order Control (Outsourcing to Third Parties)

    Organisational measures: Prior review of the security measures taken by the processor and their documentation; selection of the processor under due diligence aspects (especially with regard to data protection and data security); ensuring the destruction of data after termination of the order.

    ANNEX D
    International Transfer Mechanisms

    Custom Surgical's primary infrastructure and data storage is operated within the European Union. However, certain approved Subprocessors are subsidiaries of US-based parent companies. In such cases, Custom Surgical relies on the transfer mechanisms maintained by each Subprocessor in their standard data processing agreements, as summarised below. All Subprocessors whose parent entities are established outside the EU/EEA are required to maintain valid transfer mechanisms as a condition of their engagement.

    SubprocessorParent JurisdictionTransfer MechanismNotes
    Firebase, Inc.United StatesSCCs + EU–US Data Privacy FrameworkCovered by Google's standard DPA and Data Processing Amendment, which includes Module 2 and Module 3 SCCs and DPF certification.
    Google LLCUnited StatesSCCs + EU–US Data Privacy FrameworkCovered by Google's standard DPA and Data Processing Amendment, which includes Module 2 and Module 3 SCCs and DPF certification.
    Amazon Web Services EMEA SARLLuxembourg (EU subsidiary of US parent)SCCs + EU–US Data Privacy FrameworkAlthough AWS EMEA SARL is an EU-registered entity, its ultimate parent (Amazon.com, Inc.) is subject to US law including the CLOUD Act and FISA §702. AWS provides SCCs automatically via its GDPR DPA incorporated into its Service Terms, and holds active DPF certification. Data is processed in EU data centers only.
    Intercom R&D Unlimited CompanyIreland (EU subsidiary of US parent)EU–US Data Privacy Framework (primary); SCCs as fallbackAlthough Intercom R&D Unlimited Company is Irish-registered, its ultimate parent (Intercom, Inc.) is subject to US law. Intercom is certified under the EU–US DPF; if the DPF is invalidated, SCCs (Module 2 or 3 as applicable) apply automatically under Intercom's DPA.
    HubSpot Ireland LimitedIreland (EU subsidiary of US parent)EU–US Data Privacy Framework (primary); SCCs as fallbackAlthough HubSpot Ireland Limited is Irish-registered, its ultimate parent (HubSpot, Inc.) is subject to US law. HubSpot, Inc. is certified under the EU–US DPF; SCCs (Module 2 or 3 as applicable) apply automatically as a fallback under HubSpot's DPA if the DPF is invalidated.
    Stripe Technology Europe, LimitedIreland (EU subsidiary of US parent)SCCs + EU–US Data Privacy FrameworkAlthough Stripe Technology Europe, Limited is Irish-registered, its ultimate parent (Stripe, Inc.) is subject to US law. Stripe provides SCCs via its standard DPA and holds active DPF certification. Raw payment card data is processed by Stripe as an independent data controller under its own transfer mechanisms.
    Mailchimp, Inc.United StatesSCCs + EU–US Data Privacy FrameworkCovered by Intuit/Mailchimp's standard DPA, which includes SCCs and DPF certification.
    Apple, Inc.United StatesSCCsCovered by Apple's developer program agreements and data processing addendum, which include SCCs for EU data transfers.
    MailerSend, Inc.United StatesSCCsCovered by MailerSend's standard DPA, which includes SCCs for EU data transfers. Data infrastructure hosted within the EEA (Google Ireland, Belgium).
    Functional Software, Inc. (dba Sentry)United StatesSCCs + EU–US Data Privacy FrameworkCovered by Sentry's standard DPA (Functional Software, Inc. d/b/a Sentry), which includes SCCs. Sentry has self-certified under the EU–US Data Privacy Framework. EU data hosting region available.
    Qonversion, Inc.United StatesSCCsCovered by Qonversion's standard DPA, which includes SCCs for EU data transfers. Data infrastructure hosted in the UK (Microsoft Azure, London). No DPF certification confirmed.

    Note: The EU–US Data Privacy Framework (DPF) was adopted by the European Commission on 10 July 2023 (Implementing Decision (EU) 2023/1795) and provides a valid adequacy-based transfer mechanism for personal data transferred to DPF-certified US organisations. Custom Surgical monitors the continued validity of this framework and will update its transfer mechanisms accordingly in the event of any material legal change.

    Download the full Data Processing Addendum as a PDF.

    Download DPA (PDF)
    Custom Surgical logo
    FacebookInstagramLinkedInTwitterYouTubeTikTok
      • Legal
      •  
      • Press
      • Careers
      •  
      • Compatibility
      • Open Source
      • Micro3D
      • MedSHIELD
      • Kohnspirator
      •  
      • Support
      • FAQs
      • Manuals
      • Contact us
    Subscribe to our newsletter and never miss any news!
    Step on top to receive exclusive offers, news in the sector, the next conferences, tips about recordings, and much more!
    Subscribing authorizes newsletter and new content related to news, conferences, recordings, and more to be sent to email.

    ISO certification

    © 2019-2026 Custom Surgical GmbH — Munich, Germany | Impressum

    v.1.0.1