Privacy Policy

Last updated: 2 October 2026

This Privacy Policy explains how Surgy Innovation Labs Private Limited (“Surgy Health”, “we”, “us”) handles personal information when you use the Surgy.health website, our hospital software products, and our mobile applications. Please read it alongside any agreement your organisation has signed with us.

1. Who we are and scope

Surgy Innovation Labs Private Limited provides AI-first healthcare products for hospitals and clinics, including SurgyFrontdesk, SurgyScribe, SurgyCRM, SurgyLearn, SurgySettle, and SurgyInsights, along with the SurgyField mobile app for Android and iOS. This policy covers:

  • our marketing website at surgy.health and its forms;
  • our web applications used by hospital teams;
  • our mobile applications distributed via Google Play and the Apple App Store.

When a hospital or clinic uses our products to process information about their patients or staff, that organisation decides what data is entered and why. In those cases we act as a service provider / processor on their instructions, and their own privacy notice also applies. For our website visitors, marketing contacts, and app users who sign up directly, we act as the controller of the information described below.

Patient and workforce data remains under the control of the hospital or healthcare provider. Surgy Health processes that data only on its documented instructions. The permitted purposes, access, retention, deletion, subprocessors, security obligations, and any cross-border processing are governed by the hospital’s signed service agreement, any applicable data-processing agreement, and applicable law.

2. Information we collect

Information you give us. When you submit a contact or demo request, subscribe to updates, apply for a role, or communicate with our team, we collect the details you provide — typically your name, work email address, phone number (including country code), organisation name, role, and the content of your message.

Account information. If you are given access to one of our products, we process the account details needed to authenticate you and manage permissions, such as name, email address, role, and organisation.

Information collected automatically. When you visit our website or use our apps, we and our infrastructure providers may record technical data such as IP address, approximate country derived from that IP address, device and operating system type, browser type, app version, referring pages, pages viewed, and timestamps. This is used for security, diagnostics, and understanding aggregate usage.

Location data. Some optional features require location. For example, the SurgyField mobile app can record GPS-verified field visits and attendance for staff using it in the course of their work. Location is collected only where the feature is enabled for that user by their organisation and permitted by the device, and it can be revoked at any time in your device settings (which may disable those features).

Communications data. Records of emails, calls, and support conversations with us, including delivery and engagement events for emails we send.

We do not intentionally collect sensitive personal information through our public website forms, and we ask that you do not include patient health details in them.

2A. SurgyScribe for any EHR (Chrome extension)

The SurgyScribe for any EHR Chrome extension helps authorised doctors dictate, transcribe, review, and enter clinical notes into an electronic health record (“EHR”). It operates only on EHR websites where the doctor or hospital has explicitly enabled it through the extension’s per-site control.

Information handled by the extension. Depending on the features used, the extension handles:

  • microphone audio provided for dictation and transcription;
  • authentication credentials and session tokens needed to sign in to SurgyScribe, with the active session stored locally on the user’s device;
  • form-field labels from an EHR page where the doctor or hospital has explicitly enabled the extension; and
  • the doctor’s confirmed field mappings for that EHR screen, stored locally for extension operation and securely synchronised with SurgyScribe’s service.

The extension does not read or transmit content from websites where it has not been enabled, and it does not collect or track browsing history.

Audio processing and retention. Audio is securely sent to SurgyScribe’s service for transcription and clinical-note generation. The extension itself does not retain the recording after the recording session ends. Enterprise speech-to-text and language-model service providers may process audio or generated text solely to provide these functions. Hosted audio, transcripts, notes, and related clinical data are retained or deleted according to the hospital’s instructions and configuration, its signed service agreement, any applicable data-processing agreement, and applicable law.

Hospital control. The hospital or healthcare provider determines why and how patient information is used. Surgy Health processes it on the hospital’s documented instructions and subject to the contractual safeguards agreed with that hospital. Patients should ordinarily direct requests to access, correct, or delete clinical information to their hospital; Surgy Health will assist the hospital in responding as required by those agreements and applicable law.

Your controls. An authorised user can disable SurgyScribe for an EHR site using the extension’s site toggle. Microphone permission can be revoked through Chrome’s extension or site settings. Requests concerning a note, transcript, recording, or account may be sent to info@surgyy.com; where the request concerns patient data, we will act in accordance with the hospital’s instructions.

Hospitals in India, GCC countries, and other markets may be subject to additional local health-data and professional obligations. Use of the extension remains subject to those requirements, the hospital’s policies, and its agreements with Surgy Health.

3. How we use information

  • to provide, operate, secure, and maintain our website, products, and apps;
  • to respond to enquiries, schedule demos, and provide customer support;
  • to authenticate users and manage access and permissions;
  • to detect, investigate, and prevent fraud, abuse, and security incidents;
  • to diagnose faults and improve product performance and usability;
  • to send service and administrative messages, and — where permitted or with your consent — marketing communications you can opt out of at any time;
  • to comply with legal obligations and enforce our agreements.

We do not use information entered by hospital users into our products to train publicly available generative AI models for our own unrelated purposes.

Where applicable law requires a legal basis, we rely on: your consent (for example, marketing messages, optional cookies, or device location permissions); performance of a contract with you or your organisation; our legitimate interests in operating and securing our services; and compliance with legal obligations. You may withdraw consent at any time; this does not affect processing that already took place.

5. Sharing and disclosure

We do not sell your personal information, and we do not share it for cross-context behavioural advertising beyond the analytics and advertising measurement described in section 11.

We share information only in these situations:

  • Service providers. Categories include cloud hosting and database infrastructure, email delivery, error monitoring, web analytics, and communication tools. They may process information only to provide services to us and under confidentiality obligations.
  • Your organisation. If you use our products through a hospital or clinic, administrators of that organisation can access activity and records associated with your account.
  • Legal reasons. Where we believe disclosure is required by law, legal process, or a valid government request, or is necessary to protect rights, safety, or the integrity of our services.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to the transferred information.

6. Retention and security

We keep personal information for as long as needed for the purposes described in this policy, to maintain the service for your organisation, and to meet legal, accounting, or dispute-resolution requirements. When information is no longer needed, we delete it or de-identify it. Retention periods for data held on behalf of a hospital or clinic follow that organisation’s instructions, signed service agreement, any applicable data-processing agreement, and applicable law.

We apply administrative, technical, and organisational safeguards appropriate to the information we handle, including access controls, role-based permissions, encrypted transport for data in transit, logging, and periodic review of access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

7. Your rights and choices

Depending on where you live, you may have the right to request access to the personal information we hold about you, correction of inaccurate information, deletion, a copy in a portable format, restriction of or objection to certain processing, and withdrawal of consent. You may also opt out of marketing emails using the unsubscribe link in any such message.

To exercise a right, email us at info@surgyy.com. We will verify your request and respond within the timeframe required by applicable law. If your information is held in a product on behalf of a hospital or clinic, that organisation controls the data; we will refer your request to it and support its response under our signed agreements.

8. Account and data deletion requests

You can request deletion of your account and associated personal information at any time by emailing info@surgyy.com from the address linked to your account, with the subject line “Account deletion request” and the name of the Surgy Health product or app you use.

  • We confirm receipt and verify your identity before acting on the request.
  • Account credentials and profile data are deleted or irreversibly anonymised once verified, unless we must retain specific records to comply with law or resolve a dispute.
  • Where the data belongs to a hospital or clinic that uses our products, deletion is carried out on that organisation’s instruction and subject to its signed service agreement, any applicable data-processing agreement, and applicable law. We will notify the organisation of your request.
  • Residual copies in routine backups are removed as those backups age out on our normal cycle.

9. Children’s privacy

Our website, products, and apps are intended for healthcare organisations and their staff, and are not directed to children. We do not knowingly collect personal information directly from children through our public website or app sign-up. If you believe a child has provided us information directly, contact us and we will delete it. Information about paediatric patients may be entered by a hospital into our products as part of their own records; that processing is governed by the hospital’s instructions and privacy notice.

10. International transfers

We are based in India and use infrastructure and service providers that may store or process information in other countries. Where information is transferred across borders, we take steps to ensure it remains protected in line with this policy and applicable law, including using contractual protections with our providers.

11. Cookies and tracking

Our website uses cookies and similar technologies that are necessary for the site to work (for example, session and security cookies), plus optional analytics and advertising measurement technologies that help us understand how visitors find and use the site.

Where we run campaigns on advertising platforms such as Meta (Facebook and Instagram) or Google, those platforms may set cookies or receive conversion signals so we can measure ad performance and reach relevant audiences. Those platforms process this data under their own privacy policies. You can control cookies in your browser settings, use platform-level ad settings, and where a consent banner is presented, decline non-essential cookies. Blocking essential cookies may break parts of the site.

We also use OpenAI’s advertising measurement technology to understand which visits and enquiries came from our ads in ChatGPT. When you submit a contact, demo or chat enquiry, we share with OpenAI a measurement event recording that an enquiry was made, the page it came from, the ad click identifier (if your visit came from one of our ads), your IP address and browser user agent. We do not share your name, email address or phone number with OpenAI for advertising measurement. This measurement is not applied to visitors in the European Economic Area, the United Kingdom or Switzerland, and it is switched off for visitors whose location we cannot determine. OpenAI processes this data under its own privacy policy. You can also block these signals with browser or extension-level tracking protection.

Our mobile apps do not use third-party advertising SDKs.

12. Changes to this policy

We may update this policy to reflect changes to our services, technology, or legal requirements. We will revise the “Last updated” date above, and for material changes we will provide additional notice where required — for example by email or an in-product notice.

13. Contact us

For any privacy question or request, reach us at:

Surgy Innovation Labs Private Limited

Email: info@surgyy.com

Phone: +91 70644 65935

91 Springboard (Co-located, 175 & 176, Bannerghatta Rd, Dollar Layout, Phase 4, J. P. Nagar, Bengaluru, Karnataka 560078, India