Data Processing Addendum
Version 2.1 · Effective Date: 01.06.2026
This Data Processing Addendum ("DPA") forms part of the agreement between Custom Surgical GmbH and the Customer and governs the processing of personal data by Custom Surgical on behalf of the Customer.
| Version | Effective Date | DPO | Jurisdiction |
|---|---|---|---|
| 2.1 | 01.06.2026 | Fernando Benito Abad data-protection-office@customsurgical.co | Munich, Germany |
| Revision | Revised by | Date | Approved by |
|---|---|---|---|
| 1.0 | Fernando Benito Abad | 22.05.2023 | Fernando Benito Abad |
| 2.0 | Fernando Benito Abad | 03.02.2026 | Fernando Benito Abad |
| 2.1 | Fernando Benito Abad | 01.06.2026 | Fernando Benito Abad |
The subject matter of the agreement is the regulation of the rights and obligations of the responsible party (Customer) and the processor (Custom Surgical), insofar as the processing of personal data by Custom Surgical for the Customer within the meaning of the applicable data protection law takes place within the scope of the service provision (according to the Terms & Conditions and other applicable documents).
"Agreement" means Custom Surgical's Terms & Conditions, or other written or electronic agreement, which govern the provision of the Service to Customer, as such terms or agreement may be updated from time to time.
"Customer Data" means any personal data that Custom Surgical processes on behalf of Customer via the Service, as more particularly described in this DPA.
"Data Protection Laws" means all data protection laws and regulations applicable to a party's processing of Customer Data under the Agreement, including, where applicable, European Data Protection Laws and Non-European Data Protection Laws.
"European Data Protection Laws" means all data protection laws and regulations applicable to Europe, including (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; (iii) applicable national implementations of (i) and (ii); (iv) the GDPR as it forms part of UK law by virtue of section 3 of the UK European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 (together, "UK Data Protection Laws"); and (v) the Swiss Federal Data Protection Act of 19 June 1992 and its Ordinance ("Swiss DPA").
"Europe" means, for the purposes of this DPA, the European Economic Area and its member states ("EEA"), Switzerland and the United Kingdom ("UK").
"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data transmitted, stored, or otherwise processed by Custom Surgical or its Subprocessors.
"Service" means the Custom Surgical data management ecosystem, comprising the MicroREC App (iOS and Android), MicroREC Desktop (Windows and macOS), and MicroREC Connect (web application), together with the associated cloud backend infrastructure operated by Custom Surgical.
"Subprocessor" means any processor engaged by Custom Surgical to assist in fulfilling its obligations with respect to providing the Service pursuant to the Agreement or this DPA.
The terms "personal data", "controller", "data subject", "processor" and "processing" shall have the meaning given to them under applicable Data Protection Laws or if not defined thereunder, the GDPR.
The Customer is solely responsible for the assessment of the admissibility of the data processing as well as for the protection of the rights of the Data Subjects. The Customer will take care in their area of responsibility to ensure that the legally required conditions are met (for example, by obtaining declarations of consent), so that Custom Surgical can provide the agreed services in a lawful manner.
Custom Surgical shall process Customer Data, as further described in Annex A of this DPA, only in accordance with Customer's documented lawful instructions as set forth in this DPA, as necessary to comply with applicable law, or as otherwise agreed in writing ("Permitted Purposes"). The parties agree that the Agreement, including this DPA, along with the Customer's configuration of or use of any settings, features, or options in the Service constitute the Customer's complete and final instructions to Custom Surgical in relation to the processing of Customer Data and processing outside the scope of these instructions (if any) shall require prior written agreement between the parties.
Customer will ensure that Custom Surgical's processing of the Customer Data in accordance with Customer's instructions will not cause Custom Surgical to violate any applicable law, regulation, or rule, including, without limitation, Data Protection Laws. Custom Surgical shall promptly notify Customer in writing, unless prohibited from doing so under European Data Protection Laws, if it becomes aware or believes that any data processing instruction from Customer violates European Data Protection Laws.
Where Customer acts as a processor on behalf of a third-party controller, Customer warrants that its processing instructions as set out in the Agreement and this DPA have been authorised by the relevant controller. Customer shall serve as the sole point of contact for Custom Surgical and shall be responsible for forwarding any notifications received under this DPA to the relevant controller, where appropriate.
Custom Surgical will process Customer Data exclusively in accordance with the Terms & Conditions and other applicable documents and this DPA and according to the instructions of the Customer in accordance with clause 3.2. Custom Surgical does not use Customer Data for any other purpose and will not disclose Customer Data it processes to unauthorised third parties. Copies and duplicates are not created without the prior consent of the Customer. This does not include backup copies to ensure proper data processing.
Custom Surgical will assist the Customer in complying with its obligations under applicable law, as contractually agreed, taking into account the nature of the Processing and the information at its disposal.
If the Customer is obliged to provide information on the processing of Personal Data to a governmental body or a data subject, Custom Surgical will assist the Customer in providing this information, provided that such information relates to the contractual Data Processing and if the Customer cannot already comply with the request for information by itself or by appropriate selection of certain product parameters.
To the extent that a person concerned directly applies to Custom Surgical for the purpose of asserting an affected right, Custom Surgical will forward the inquiries of the Data Subject promptly to the Customer. To the extent legally permissible, Custom Surgical will inform the Customer about notifications by the supervisory authorities in connection with the processing of Personal Data according to this DPA. To the extent legally permissible, Custom Surgical shall provide information to third parties, including supervisory authorities, only after written approval by and in consultation with the Customer.
Where a Security Incident involves health data within the meaning of Article 9 GDPR, Custom Surgical will endeavour to notify the Customer within 24 hours of becoming aware of the incident. In all cases, Custom Surgical will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a Security Incident affecting Customer Data. Such notification shall include, to the extent available at the time: (i) a description of the nature of the Security Incident, including the categories and approximate number of data subjects and records affected; (ii) the name and contact details of the Data Protection Officer or other relevant contact point; (iii) a description of the likely consequences of the Security Incident; and (iv) a description of the measures taken or proposed to address the Security Incident.
Custom Surgical shall provide the Customer with sufficient information to enable the Customer to meet its own obligations under applicable Data Protection Laws, including, where required, the obligation to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach under Article 33 GDPR. Custom Surgical will cooperate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of each Security Incident.
The Parties shall assist each other in demonstrating and documenting their accountability with respect to the principles of due processing of Personal Data.
If the Customer conducts a privacy assessment and/or intends to consult the supervisor for a privacy impact assessment, then the parties will agree on the content and scope of any support provided by Custom Surgical as and when requested by the Customer.
Customer Data is retained for the duration of the active account lifecycle. For the purposes of this DPA, an "active account" means an account under which the user has logged in or captured data within the preceding 36 months, or which holds an active paid subscription regardless of recent login activity.
All users upload patient metadata to the cloud backend from the point of account creation. Paid and formerly paid (downgraded) subscribers additionally upload media data (photographs and videos). Both categories of data are retained for the duration of the active account, subject to the tier distinctions described below:
- - All users (including free tier): Patient metadata and structured session data retained for the duration of the active account.
- - Paid and downgraded subscribers: Media data (photographs and videos) additionally retained for the duration of the active account. Downgraded subscribers retain full access to their existing media data on the basis that continued cloud storage relieves local device storage constraints and enables remote access to historical clinical cases.
Where an account has been inactive for 36 consecutive months, Custom Surgical will notify the account administrator by email and proceed to delete the account and all associated Customer Data within 30 days unless the Customer reactivates the account or submits a written request to extend retention.
Upon receipt of a formal written account deletion request, Custom Surgical shall delete all Customer Data from both the primary cloud backend and the secondary research and development environment within 30 days and provide written confirmation of deletion upon request. This requirement shall not apply to the extent Custom Surgical is required by applicable law to retain certain data, in which case such data shall be securely isolated and protected from any further processing until the applicable retention obligation expires.
Custom Surgical may use additional processors (Subprocessors and Sub-subprocessors) to perform the tasks described in this DPA. Commissions that Custom Surgical places with third parties as ancillary services to support the execution of the work assigned to it and that do not involve commissioned processing of Personal Data for the Customer shall not be regarded as a subprocessing relationship within the meaning of this provision.
By accepting the Terms & Conditions at signup, the Customer accepts this DPA in its current version, including the list of approved Subprocessors set out in Annex A. This acceptance constitutes the Customer's general written authorisation for Custom Surgical to engage the Subprocessors listed therein for the purposes described.
Custom Surgical shall notify the Customer in writing of any intended addition or replacement of Subprocessors prior to the change taking effect. Such notification shall be provided with reasonable advance notice — no less than 14 days before the change takes effect — and shall include the name, address, and nature of the services provided by the new or replacement Subprocessor.
If the Customer has legitimate grounds to object to the proposed change on data protection grounds, the Customer must notify Custom Surgical in writing within 14 days of receiving the notification. Custom Surgical and the Customer shall work in good faith to resolve the objection. If no resolution can be reached, the Customer may terminate the relevant services on written notice, without penalty, before the change takes effect.
If the Customer does not object within the 14-day period, the change shall be deemed accepted and Annex A will be updated accordingly. Custom Surgical shall also notify the Customer without undue delay if any Subprocessor loses its certification under the EU–US Data Privacy Framework, if the Standard Contractual Clauses relied upon by a Subprocessor are modified or replaced, or if any transfer mechanism relied upon by a Subprocessor ceases to be valid under applicable Data Protection Laws. In such cases, Custom Surgical shall take prompt steps to implement an alternative valid transfer mechanism and inform the Customer accordingly.
Notifications of Subprocessor changes shall be provided by email to the account administrator registered on the Customer's account, or by publication of an updated version of this DPA on Custom Surgical's website with a corresponding notice to the Customer. Custom Surgical shall maintain a version history of this DPA, including a record of Subprocessor changes, accessible on its website.
Custom Surgical will select Subprocessors who provide reasonable guarantees that the agreed appropriate technical and organisational measures will be performed in such a way that the processing will be carried out in accordance with the requirements of the relevant applicable legal provisions. Custom Surgical will enter into contractual agreements with Subprocessors that comply with the content of the contractual provisions of this DPA.
Custom Surgical shall implement and maintain appropriate technical and organisational security measures that are designed to protect Customer Data from Security Incidents and designed to preserve the security and confidentiality of Customer Data in accordance with Custom Surgical's security standards described in Annex B of this DPA.
Custom Surgical shall ensure that any person who is authorised by Custom Surgical to process Customer Data (including its staff, agents, and subcontractors) shall be under an appropriate obligation of confidentiality (whether a contractual or statutory duty).
Customer is responsible for reviewing the information made available by Custom Surgical relating to data security and making an independent determination as to whether the Service meets Customer's requirements and legal obligations under Data Protection Laws. Customer acknowledges that the Security Measures are subject to technical progress and development and that Custom Surgical may update or modify the Security Measures from time to time, provided that such updates and modifications do not result in the degradation of the overall security of the Service provided to Customer.
Notwithstanding the above, Customer agrees that except as provided by this DPA, Customer is responsible for its secure use of the Service, including securing its account authentication credentials, protecting the security of Customer Data when in transit to and from the Service, and taking any appropriate steps to securely encrypt or backup any Customer Data uploaded to the Service.
Custom Surgical shall, upon written request from the Customer, provide evidence of the sufficient implementation of its obligations under this DPA and applicable Data Protection Laws. Such evidence may include: (i) the technical and organisational measures described in Annex C of this DPA; (ii) relevant third-party audit reports, certifications, or security assessments (such as ISO 27001, SOC 2, or equivalent); and (iii) written responses to reasonable information requests relating to the processing activities covered by this DPA. Custom Surgical shall maintain such documentation and make it available to the Customer or to the relevant supervisory authority upon request.
The Customer may audit at its own expense compliance with the data protection regulations and the obligations stipulated in this DPA by requesting the evidence described in Section 7.1. Where the Customer reasonably considers that such documentary evidence is insufficient, the Customer may, at its own expense and with reasonable prior written notice of no less than 30 days, conduct or commission an on-site inspection of Custom Surgical's data processing facilities and practices. The Customer may perform such inspections itself or commission a qualified third party, provided that such third party is not a competitor of Custom Surgical and is bound by a documented confidentiality obligation prior to the inspection. The Customer shall take due care not to disrupt Custom Surgical's business operations during any such inspection.
Custom Surgical's primary infrastructure is hosted on Google Cloud Platform, with data stored and processed exclusively within data centers located in the European Union. Secondary processing for internal research and development purposes is carried out within AWS data centers located in the European Union, as described in Annex A. Custom Surgical does not operate data centers outside the European Union and does not transfer Customer Data outside the European Economic Area except where this occurs indirectly through the use of approved Subprocessors whose ultimate parent entities are established in third countries. All such transfers are subject to the safeguards described in Section 8.2 and documented in Annex D.
To the extent that Custom Surgical engages Subprocessors whose parent entities are established in countries outside of Europe that are not recognised as providing an adequate level of protection for personal data under applicable European Data Protection Laws, Custom Surgical ensures that appropriate safeguards are in place for any such transfers. These safeguards include, as applicable: (i) reliance on Standard Contractual Clauses (SCCs) as provided by the relevant Subprocessor in their data processing agreements; (ii) reliance on adequacy decisions adopted by the European Commission; or (iii) reliance on certification under the EU–US Data Privacy Framework or equivalent recognised transfer mechanism. Custom Surgical shall ensure that each Subprocessor maintains and, upon request, provides evidence of the applicable transfer mechanism. A summary of the transfer mechanisms relied upon by each approved Subprocessor is set out in Annex D.
The Customer, in its area of responsibility, ensures the implementation of the obligations arising from the relevant applicable legal provisions in the Processing of Personal Data.
The liability regulation from the Terms & Conditions and the other applicable documents applies to this DPA, as far as a limitation of liability in accordance with the relevant applicable legal provisions in favour of Custom Surgical does not apply.
This agreement is valid for the duration of the actual service provision by Custom Surgical. This applies regardless of the terms of any other contracts (in particular the Terms & Conditions and the other applicable documents), which the parties have also concluded with regard to the provision of the agreed services.
The validity of the remaining provisions shall remain unaffected by the invalidity of any provision of this DPA. If a provision proves ineffective, the parties will replace it with a new one that comes closest to that desired by the parties.
All changes to this DPA and ancillary agreements must be in writing (including electronic form). This also applies to the termination of this written form clause itself. Notwithstanding the foregoing, changes to the list of approved Subprocessors in Annex A may be notified via Custom Surgical's website in accordance with the notification procedure set out in Section 5.4, which shall constitute written notice for the purposes of this clause.
It is agreed between the parties that the "General Terms and Conditions" of the Customer do not apply to this DPA.
This DPA is founded on the EU General Data Protection Regulation (EU GDPR).
In the case of contradictions between the provisions of this DPA and provisions of other agreements, in particular the Terms & Conditions and the other applicable documents, the provisions of this DPA shall prevail. Incidentally, the provisions of the Terms & Conditions and the applicable documents remain unaffected and apply accordingly to this DPA.
Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Munich, Germany.
- - End users — individual clinicians or staff members accessing the Service under a personal or organisational account
- - Account administrators — individuals within a customer organisation who manage account settings, user access, and billing on behalf of the organisation
- - Patients — natural persons whose personal data is processed by users of the Service
- - End user profile information (full name, email address, country of residence, profession)
- - Account administrator information (full name, email address, role/title, organisation name, billing contact details)
- - Organisation information (legal name, address, type of clinical setting) — to the extent that this information is linked to or identifies a natural person
- - Billing and payment information (name, email address, billing address, tokenised payment identifiers, last four digits of payment card, card type and expiry date) — note: raw payment card data (full card number, CVV) is processed exclusively by Stripe Technology Europe, Limited acting as an independent data controller and does not fall within the scope of this DPA
- - User content (photographs, videos, audio recordings, patient IDs, session labels, session descriptions, session dates and session locations)
- - Technical information (IP address, device model, operating system version, device ID, user ID, configuration of the app, time and date of the use of the Service)
- - All other personal data as defined in Article 4 no. 1 of GDPR that is transmitted by the customer or stored during use of the product where access by Custom Surgical's system administrators cannot be excluded.
The following categories of sensitive (special category) data within the meaning of Article 9 GDPR are processed in connection with the Service:
- - Clinical media content constituting health data: photographs and videos of ophthalmic procedures and ocular anatomy captured through the Service, including slit-lamp recordings and equivalent clinical imaging
- - Audio recordings associated with clinical sessions (note: audio tracks are stripped of patient-identifying content prior to storage)
- - Session descriptions and clinical notes entered by users that may contain health-related information
- - All other personal data as defined in Articles 4 no. 13–15 of GDPR that is transmitted by the customer or stored during use of the product where access by Custom Surgical's system administrators cannot be excluded.
Lawful basis for processing sensitive data: Custom Surgical processes the above sensitive data in its capacity as a data processor acting on the documented instructions of the Customer. The Customer, as data controller, is solely responsible for ensuring that a valid legal basis under Article 9(2) GDPR exists for processing special category data. The applicable basis will typically be Article 9(2)(h) GDPR — processing necessary for the purposes of the provision of healthcare services and the clinical management of patients — in conjunction with a professional secrecy obligation under Article 9(3) GDPR. The Customer warrants that it has identified and documented a valid Article 9 basis prior to using the Service to process special category data, and that it will maintain such a basis for the duration of the Agreement.
Personal data is processed on a continuous basis for as long as the Customer maintains an active account and uses the Service. Processing occurs automatically in response to actions taken by end users and account administrators within the Service (such as capturing, uploading, or accessing clinical media), as well as through background operations required to maintain, secure, and improve the Service (such as backups, replication, and system monitoring). The frequency and volume of processing is therefore determined by the Customer's usage of the Service, not by a fixed schedule set by either party.
Custom Surgical provides a data management ecosystem for the capture, storage, and remote access of clinical media and patient information, as more particularly described in the Terms & Conditions. The Service comprises multiple interfaces — MicroREC App (iOS and Android), MicroREC Desktop (Windows and macOS), and MicroREC Connect (web application) — which interact with a shared cloud backend hosted on Google Cloud Platform. Data captured or uploaded via any interface is stored in the cloud backend and may be accessed and managed through any other interface by authorised users. Customer Data will be processed in accordance with the Agreement (including this DPA) and may be subject to the following processing activities:
- - Storage and other processing necessary to provide, maintain and improve the Service provided to Customer pursuant to the Agreement; and/or
- - Disclosures in accordance with the Agreement and/or as compelled by applicable law.
Custom Surgical shall only process Customer Data for the Permitted Purposes, which shall include: (i) processing as necessary to provide the Service in accordance with the Agreement; (ii) processing initiated by Customer in its use of the Service; and (iii) processing to comply with any other reasonable instructions provided by Customer (e.g., via email) that are consistent with the terms of the Agreement.
Secondary purpose – product development: Custom Surgical retains pseudo-anonymised media data (photographs and videos) from paid and formerly paid (downgraded) subscriber accounts in a separate research and development environment hosted on Amazon Web Services EMEA SARL infrastructure within the European Union. This data is used for internal product development purposes, including the improvement and development of the Service. The lawful basis for this secondary processing is Article 6(1)(f) GDPR (legitimate interests). This data is subject to the same active account retention policy as the primary service data: it is retained for the duration of the active account and deleted upon account deletion request or following the 36-month inactivity process described in Section 4.7. Custom Surgical's Legitimate Interests Assessment for this processing activity is available upon written request. Free-tier-only users whose media data has never been stored in the cloud are not subject to this secondary processing. For the avoidance of doubt, Custom Surgical acts as an independent data controller for this secondary R&D processing activity, as it determines the purpose of such processing independently of the Customer's instructions. This processing is carried out under Article 6(1)(f) GDPR (legitimate interests) as documented in Custom Surgical's Legitimate Interests Assessment, available upon written request. The Customer, acting in its capacity as data controller for its patients' data, may at any time object to this secondary processing on behalf of its data subjects by submitting a written objection to data-protection-office@customsurgical.co. Custom Surgical will honour such objections and exclude the Customer's data from the R&D dataset within 30 days of receipt. An objection to secondary R&D processing does not affect the primary service relationship or the terms of this DPA.
Customer Data is retained for the duration of the active account lifecycle as defined in Section 4.7. The following retention periods apply by data category:
- - Patient metadata and structured session data — all users: Retained for the duration of the active account. Deleted upon account deletion request or following the 36-month inactivity process described in Section 4.7.
- - Media data (photographs and videos) — primary cloud backend (GCP): Retained for the duration of the active account for all paid and formerly paid (downgraded) subscribers. Not applicable to free-tier-only users who have not held a paid subscription. Deleted upon account deletion request or following the 36-month inactivity process.
- - Pseudo-anonymised media data — secondary R&D environment (AWS): Retained for the duration of the active account for paid and formerly paid subscribers, on the basis of Custom Surgical's legitimate interests in product development (Article 6(1)(f) GDPR). Not applicable to free-tier-only users. Deleted upon account deletion request or following the 36-month inactivity process.
- - All Customer Data: Permanently deleted from both environments within 30 days of a formal account deletion request, subject to any applicable legal retention obligations.
| Subprocessor | Address | Service Type | Parent Company |
|---|---|---|---|
| Firebase, Inc. | 22 4th Street Suite 1000, San Francisco, CA 94103, United States | Computing and development tools | Alphabet, Inc. |
| Google LLC | 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | Cloud infrastructure and data hosting; computing and development tools; software distribution | Alphabet, Inc. |
| Amazon Web Services EMEA SARL (Niederlassung Deutschland) | Marcel-Breuer-Straße 12, 80807 Munich, Germany (Parent HQ: 38 Avenue John F. Kennedy, L-1855 Luxembourg) | Cloud infrastructure for R&D secondary usage; product development — EU data centers only | Amazon.com, Inc. |
| Intercom R&D Unlimited Company | 124 St Stephen's Green, Dublin 2, D02 C628, Ireland | Customer messaging and support platform | Intercom, Inc. |
| HubSpot Ireland Limited | HubSpot House, 1 Sir John Rogerson's Quay, Dublin 2, D02 CR67, Ireland | Customer relationship management (CRM) and marketing automation | HubSpot, Inc. |
| Stripe Technology Europe, Limited | The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland | Payment processing and billing — acting as subprocessor for billing contact data transmitted by Custom Surgical, and as an independent data controller for raw payment card data | Stripe, Inc. |
| Mailchimp, Inc. | 675 Ponce de Leon Ave NE Suite 5000, Atlanta, GA 30308, United States | Email marketing | Intuit, Inc. |
| Apple, Inc. | One Apple Park Way, Cupertino, CA 95014, United States | Computing and development tools; software distribution | N/A |
| MailerSend, Inc. | 228 Park Ave S, PMB 54955, New York, NY 10003, United States | Transactional email relay (account notifications, password resets, service emails) | N/A |
| Functional Software, Inc. (dba Sentry) | 45 Fremont Street, 8th Floor, San Francisco, CA 94105, United States | Error monitoring and crash reporting | N/A |
| Qonversion, Inc. | 1160 Battery Street East, Suites 100, San Francisco, CA 94111, United States | Subscription analytics and in-app purchase management | N/A |
Custom Surgical has partnered with Google Cloud to provide customers and applications with top-in-class security. Google Cloud data centers are protected with several layers of security to prevent any unauthorised access to data:
- - Secure perimeter defense systems
- - Comprehensive camera coverage
- - Biometric authentication
- - 24/7 guard and support staff
- - All databases are kept separate and dedicated to preventing corruption and overlap.
- - Data from different customers is kept separate through security rules and authentication requirements.
- - Data is replicated across multiple Google Cloud availability zones and regularly backed up, with backups stored in geographically separate EU data center locations.
- - Account passwords across all Service interfaces (MicroREC App, MicroREC Desktop, and MicroREC Connect) are hashed. Custom Surgical staff cannot view them. If a password is lost, it cannot be retrieved and must be reset.
- - All login and signup information is securely encrypted in transit through TLS protocol across all interfaces.
- - All communications between Service interfaces and the cloud backend are encrypted in transit through TLS protocol.
- - MicroREC Connect (web application) enforces HTTPS exclusively, with session management controls including automatic session expiry for inactive sessions.
- - Custom Surgical continuously trains employees on best security practices, including how to identify social engineering, phishing, scams and hackers.
- - Access to customer data from Custom Surgical employees is tightly controlled by a least-permission policy.
- - All employees sign a Privacy Safeguard Agreement outlining their responsibility in protecting customer data.
- - All employee accounts use two-factor authentication and secure passwords, updated every 90 days.
Custom Surgical takes the following technical and organisational measures for data security within the meaning of Art. 32 GDPR.
Physical Access Control
Employees working on-site are required to access office spaces using their personal access keys. Additionally, a clean desk policy is enforced where all documents containing personal information must be stored in locked cabinets and shredded when no longer needed.
Technical measures: Security locks; locking system with code lock.
Organisational measures: Key regulations; visitors accompanied by staff members.
System Access Control
Laptops and PCs from both on-site and remote employees must lock after 1 minute of idle time. All passwords must be at least 8 characters long and be changed every 90 days.
Technical measures: Login with username and password; two-factor authentication; anti-virus software clients; automatic screen lock.
Organisational measures: Management of user permissions; secure password policy; clean desk policy; general policy "Data protection and security".
Data Access Control
Regarding access control, Custom Surgical follows a least-permission policy. Only a small number of employees are allowed to delete or move sensitive files. All files use automatic version control to avoid any accidental overwriting of personal data.
Technical measures: Document shredding; access logs.
Organisational measures: Use of authorisation concepts; minimum number of administrators; management of user rights by administrators only.
Separation
Custom Surgical has partnered with Google Cloud to provide services and infrastructure with virtualisation, which allows separation of services through different machines, and multi-regional data separation and redundancy.
Technical measures: Separation of production and test environments. Encryption at rest: all Customer Data stored in the Service is encrypted at rest using AES-256 encryption, implemented through Google Cloud Platform's default server-side encryption. Encryption key management: encryption keys are managed by Google Cloud Key Management Service (Cloud KMS). Custom Surgical does not operate its own key infrastructure. Further information on Google Cloud encryption and key management is available at https://cloud.google.com/security/encryption-at-rest. Enhanced audit logging for health data: access to health-related data (including clinical media and patient metadata) by Custom Surgical personnel is subject to enhanced access controls under the least-privilege policy described in Section 1 (Data Access Control) above. Access events are logged automatically by Google Cloud audit logging infrastructure. Logs are retained for a minimum of 12 months and are available for review upon request in connection with a Customer audit conducted in accordance with Section 7 of the DPA.
Organisational measures: Control via authorisation concept; definition of database rights.
Pseudonymisation and Encryption
Technical measures: In the case of pseudonymisation: separation of the assignment data and storage in a separate and secure system (preferably encrypted).
Organisational measures: Internal instruction to anonymise/pseudonymise personal data as far as possible in the event of disclosure or after expiry of the legal deletion period.
Input Control
Access to all files containing personal information is registered in access logs. Automatic version control is used to avoid any accidental overwriting of personal data.
Technical measures: Technical logging of the entry, modification, and deletion of data; version-controlled documents.
Organisational measures: Overview of programs that can be used to enter, change, or delete data; traceability of data entry, modification, and deletion through individual user names (not user groups); assignment of rights for entering, changing, and deleting data on the basis of an authorisation concept; clear responsibilities for deletions.
Transfer Control
Technical measures: Logging of accesses and retrievals; provision via encrypted connections such as SFTP and HTTPS.
Custom Surgical has partnered with Google Cloud to provide customers with over 99% SLA and infrastructure resilience through multi-regional redundancy. The following measures apply to Google Cloud's infrastructure, on which Custom Surgical's Service is hosted:
Technical measures (Google Cloud infrastructure): Fire and smoke detection systems; physical security and environmental controls within data center facilities; data replication across multiple availability zones; automated failover mechanisms.
Organisational measures (Custom Surgical): Backup and recovery concept (formulated); regular testing of backup restoration procedures; documented incident response and business continuity procedures.
Data Protection Management
Custom Surgical uses centralised software tools to control and define access rights to all systems containing customer data.
Technical measures: Software solutions for data protection management in use.
Organisational measures: Employees trained and obligated to confidentiality/data secrecy; regular employee awareness training (at least once a year); the organisation complies with the information obligations according to Art. 13 and 14 GDPR.
Incident Response Management
Technical measures: Use of spam filter and regular updates.
Organisational measures: Documentation of security incidents and data breaches, e.g., via ticket system.
Privacy-Friendly Default Settings
Technical measures: No more personal data is collected than is necessary for the respective purpose; simple exercise of the right of revocation of the data subject by technical measures.
Order Control (Outsourcing to Third Parties)
Organisational measures: Prior review of the security measures taken by the processor and their documentation; selection of the processor under due diligence aspects (especially with regard to data protection and data security); ensuring the destruction of data after termination of the order.
Custom Surgical's primary infrastructure and data storage is operated within the European Union. However, certain approved Subprocessors are subsidiaries of US-based parent companies. In such cases, Custom Surgical relies on the transfer mechanisms maintained by each Subprocessor in their standard data processing agreements, as summarised below. All Subprocessors whose parent entities are established outside the EU/EEA are required to maintain valid transfer mechanisms as a condition of their engagement.
| Subprocessor | Parent Jurisdiction | Transfer Mechanism | Notes |
|---|---|---|---|
| Firebase, Inc. | United States | SCCs + EU–US Data Privacy Framework | Covered by Google's standard DPA and Data Processing Amendment, which includes Module 2 and Module 3 SCCs and DPF certification. |
| Google LLC | United States | SCCs + EU–US Data Privacy Framework | Covered by Google's standard DPA and Data Processing Amendment, which includes Module 2 and Module 3 SCCs and DPF certification. |
| Amazon Web Services EMEA SARL | Luxembourg (EU subsidiary of US parent) | SCCs + EU–US Data Privacy Framework | Although AWS EMEA SARL is an EU-registered entity, its ultimate parent (Amazon.com, Inc.) is subject to US law including the CLOUD Act and FISA §702. AWS provides SCCs automatically via its GDPR DPA incorporated into its Service Terms, and holds active DPF certification. Data is processed in EU data centers only. |
| Intercom R&D Unlimited Company | Ireland (EU subsidiary of US parent) | EU–US Data Privacy Framework (primary); SCCs as fallback | Although Intercom R&D Unlimited Company is Irish-registered, its ultimate parent (Intercom, Inc.) is subject to US law. Intercom is certified under the EU–US DPF; if the DPF is invalidated, SCCs (Module 2 or 3 as applicable) apply automatically under Intercom's DPA. |
| HubSpot Ireland Limited | Ireland (EU subsidiary of US parent) | EU–US Data Privacy Framework (primary); SCCs as fallback | Although HubSpot Ireland Limited is Irish-registered, its ultimate parent (HubSpot, Inc.) is subject to US law. HubSpot, Inc. is certified under the EU–US DPF; SCCs (Module 2 or 3 as applicable) apply automatically as a fallback under HubSpot's DPA if the DPF is invalidated. |
| Stripe Technology Europe, Limited | Ireland (EU subsidiary of US parent) | SCCs + EU–US Data Privacy Framework | Although Stripe Technology Europe, Limited is Irish-registered, its ultimate parent (Stripe, Inc.) is subject to US law. Stripe provides SCCs via its standard DPA and holds active DPF certification. Raw payment card data is processed by Stripe as an independent data controller under its own transfer mechanisms. |
| Mailchimp, Inc. | United States | SCCs + EU–US Data Privacy Framework | Covered by Intuit/Mailchimp's standard DPA, which includes SCCs and DPF certification. |
| Apple, Inc. | United States | SCCs | Covered by Apple's developer program agreements and data processing addendum, which include SCCs for EU data transfers. |
| MailerSend, Inc. | United States | SCCs | Covered by MailerSend's standard DPA, which includes SCCs for EU data transfers. Data infrastructure hosted within the EEA (Google Ireland, Belgium). |
| Functional Software, Inc. (dba Sentry) | United States | SCCs + EU–US Data Privacy Framework | Covered by Sentry's standard DPA (Functional Software, Inc. d/b/a Sentry), which includes SCCs. Sentry has self-certified under the EU–US Data Privacy Framework. EU data hosting region available. |
| Qonversion, Inc. | United States | SCCs | Covered by Qonversion's standard DPA, which includes SCCs for EU data transfers. Data infrastructure hosted in the UK (Microsoft Azure, London). No DPF certification confirmed. |
Note: The EU–US Data Privacy Framework (DPF) was adopted by the European Commission on 10 July 2023 (Implementing Decision (EU) 2023/1795) and provides a valid adequacy-based transfer mechanism for personal data transferred to DPF-certified US organisations. Custom Surgical monitors the continued validity of this framework and will update its transfer mechanisms accordingly in the event of any material legal change.
Download the full Data Processing Addendum as a PDF.
Download DPA (PDF)







-1675d2368c6531b4186d0c38e40719e5.png)



