Now piloting with NHS hospitals
SurgeryAI

Surgery AI is provided to NHS and public sector organisations as a business-to-business service. Clinicians and scheduling staff access the platform under their organisation's authority, and our contractual commitments are made to the organisation. The terms below summarise how data is used across the Surgery AI platform. They reflect the commitments in our Data Processing Agreement, which, together with each customer's contract, governs our processing of data. A copy of our Data Processing Agreement is available to customers and prospective customers on request.

Our role

For all patient-level and operational data processed within the platform, the customer organisation remains the Data Controller at all times. Surgery AI acts solely as a Data Processor under UK GDPR.

What we commit to

  • Customer data is processed only on the customer's documented instructions, and solely to deliver the contracted service.
  • Customer data is never used for any secondary purpose. No customer's data is used to train or improve models or algorithms for the benefit of any other customer.
  • All data is stored and processed exclusively in the United Kingdom (AWS London region), encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Our sub-processor, Amazon Web Services, is disclosed to customers, and no further sub-processors are engaged without notice.
  • Personal data breaches are notified to the affected customer without undue delay.
  • On termination of a contract, all customer data is returned in standard, non-proprietary formats and/or securely deleted at the customer's direction.

Platform user accounts

The limited personal data of platform users themselves (name, work email address and role) is processed to provide secure, authenticated access to the platform. This processing is described in our Privacy Notice.

Assurance

Our handling of data is independently assured through our Data Security and Protection Toolkit submission (Standards Met), completed Digital Technology Assessment Criteria (DTAC), Cyber Essentials Plus certification, and annual independent penetration testing.

For questions about data handling, or to request a copy of our Data Processing Agreement, contact anna@surgeryai.com.