SurgiMD← Back to site

Privacy Policy

Last updated: September 10, 2026

SurgiMD (“the App”) is operated by Infinion Apps FZ-LLC (“we”, “us”), a company registered in Dubai, United Arab Emirates. Contact: privacy@infinionapps.com.

This policy explains what data the App and this website handle, and how. SurgiMD is a professional tool for licensed clinicians; it is designed around a simple principle — patient data belongs to the treating clinic, and our job is to protect it.

1. Two kinds of data, two roles

Your account data (clinician's email, sign-in identity, subscription status): for this, we are the data controller.

Patient data (photographs, names, medical record numbers, clinical notes, measurements, consents) is entered and controlled by your clinic. The clinic is the data controller / covered entity; we act only as a processor / service provider / business associate on the clinic's instructions. We never use patient data for our own purposes.

2. What we collect

3. Where data lives

4. How patient data is protected

Face ID / passcode app lock · per-clinic access control with per-person permissions · versioned, per-patient consent capture · consent-gated export, sharing, printing and saving · de-identification tools (eye bar / face blur) · a tamper-evident, hash-chained audit log of every significant action · metadata stripping on every saved photo. See Security & Compliance for how these map to GDPR, HIPAA and UAE health data law.

5. Sharing

We do not sell or rent any data. Data leaves our systems only:

6. Retention & deletion

Patient records remain until the clinic deletes them; deleting a patient removes the record and its images from the device and our cloud. Deleting your account removes your sign-in identity; clinic patient data is retained or deleted per the clinic's instruction. Residual copies in encrypted backups clear on backup rotation (30 days).

7. Your rights

Depending on your jurisdiction (GDPR, UAE data protection law), you may have rights of access, correction, deletion, portability and objection. For clinician-account data, contact us directly. For patient data, contact your treating clinic (the controller) — we support clinics in fulfilling such requests. EU/UK-specific processor terms (DPA, SCCs) are available to clinics on request.

8. Who may use SurgiMD

The App is for licensed healthcare professionals aged 18+. It is not directed at children; patient records concerning minors are the clinic's responsibility and require guardian consent per local law.

9. Website

Our website is informational. It sets no tracking cookies.

10. Changes & contact

We will post changes here with a new effective date; material changes are announced in the App. Questions or requests: privacy@infinionapps.com · Infinion Apps FZ-LLC, Dubai, United Arab Emirates.

This policy is a working draft pending review by counsel. It is not legal advice.