Legal

Privacy policy

Last updated 21 August 2026


What this page covers

This policy describes the waitlist site at surgireport.io. That is all this site is at the moment: a description of a product being built, and a form that lets a surgeon ask to be told when it is ready. It does not describe the SurgiReport product, which does not exist yet.

Controller

The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:

Omer Boshara
Bergrather Str. 36
52249 Eschweiler
Germany
contact@surgireport.io

What we collect when you join the waitlist

Nothing that identifies you is collected until you decide to fill in the form. When you do, we store:

  • Your email address — required, because it is the only way we can tell you that SurgiReport has launched.
  • Your specialty and your country of practice — required, because they decide which procedures and which language we build for first.
  • The optional answers in the second step — where you are in your career, roughly how many operations you do per week, how your reports get written today, the languages you write them in, whether you would dictate from a phone, the most annoying part of writing your reports, and what you consider fair pricing. Every one of these is optional and the form can be skipped entirely.
  • A small amount of technical bookkeeping — two random tokens that make the confirmation link, the optional second step and the one-click unsubscribe link work; your position on the list and your referral code once you confirm; the referral code of the member whose link you followed, if you followed one; any utm parameters that were in the link you arrived through; and the times at which you signed up and confirmed.

Legal basis: your consent, Art. 6(1)(a) GDPR, given by submitting the form and completed by clicking the confirmation link. Purpose: to contact you about the launch of SurgiReport, and to decide what gets built first and in what order. Giving us this data is voluntary; there is no obligation to provide it, and the only consequence of not providing it is that we cannot put you on the list.

Anonymous funnel counters

We count how the page is used, so that we know whether it explains the product or not. Each counter row holds three things: a fixed event name from a short list we defined in advance (for example a page view, a click on the join button, or a completed signup step), the path of the page it happened on, and any utm parameters in the link you followed. The time is recorded with it.

There is no identifier in these rows. No cookie, no device fingerprint, no IP address, no user agent, no session id, and no link of any kind to a waitlist entry. They are counts, and they cannot be traced back to you or joined to anything about you. Because they contain no personal data, the GDPR does not apply to the stored result; to the extent that producing them is regarded as processing at all, it rests on our legitimate interest in knowing whether this page works, Art. 6(1)(f) GDPR.

What this site does not do

  • No cookies. Nothing is written to or read from document.cookie.
  • No local storage and no session storage.
  • No tracking pixels, no beacons that identify you, no fingerprinting.
  • No advertising networks, no social plugins, no third-party scripts loaded from other companies’ servers. The fonts are bundled with the site itself, so opening this page contacts no font provider.
  • No profiling, no scoring, and no automated decision-making of the kind described in Art. 22 GDPR.
  • No selling, renting or sharing of your data with anyone other than the processors named below.

Because nothing is stored on or read from your device, §25 TDDDG — the rule that requires consent for storing or accessing information on terminal equipment — does not apply here. That is why this site has no consent banner: there is nothing to consent to.

Double opt-in, and the email we send

When you submit the form your entry is stored as unconfirmed, and exactly one email goes out: a short message with a confirmation link. Until you click that link nothing further happens — no other email is sent, no position on the list is issued, and the entry does nothing but sit there. If the link is never clicked, the unconfirmed entry has no purpose, and we delete unconfirmed entries at the latest three months after signup.

Once you confirm, you get one welcome email with your position and your referral link, and after that only occasional messages about the launch. Every one of those carries an unsubscribe link and the matching List-Unsubscribe header, so leaving needs no login and no account. The link opens a page with a single button rather than removing you on sight: mail security systems follow every link in an incoming message, and a link that unsubscribed on being fetched would drop you from the list without your ever having pressed anything. The confirmation email itself carries no unsubscribe link, because until you confirm there is nothing subscribed — ignoring it is what removes you.

IP addresses

We do not store your IP address. It is not in the database, it is not in the waitlist entry, and it is not in a log we keep.

The signup form does have to be protected from scripts hammering it. To do that, the server takes the connecting address as forwarded by our hosting provider, combines it with a fixed label, puts it through a one-way hash and keeps only a truncated fragment of the result. That fragment is held in the memory of the server instance and counts requests against a limit. It stops counting when its window ends — ten minutes for the signup form, one minute for the anonymous counters — and the entry itself is discarded the next time that store is swept, or whenever the instance is recycled, whichever comes first. It is never written to disk, never written to the database, and never sent anywhere. The address itself is never stored at any point. Legal basis: our legitimate interest in keeping the form usable and free of abuse, Art. 6(1)(f) GDPR.

Delivering a page to you is not possible without your IP address reaching a server. Our hosting provider processes it for that purpose and for the security of its own network, under the agreement described below. The site is served over an encrypted connection.

Processors

Four services process data on our behalf. Each acts only on our instructions, and a data processing agreement under Art. 28 GDPR is in place with each of them.

  • Vercel — hosting and delivery of this site, and Vercel Web Analytics for aggregate page-view figures. The analytics set no cookie and store nothing on your device; to avoid counting the same visit twice, Vercel derives a short-lived, non-reversible hash from the request itself and discards it within a day.
  • Neon — the Postgres database that holds the waitlist entries and the anonymous counters, hosted in an EU region.
  • Resend — delivery of the transactional email: the confirmation message, the welcome message, and later notices about the launch.
  • Hostinger — the domain and the mailbox behind contact@surgireport.io, so anything you write to us is stored there.

Where one of these providers may process or transfer data outside the EU or the EEA, that transfer is covered by the European Commission’s Standard Contractual Clauses under Art. 46 GDPR, together with the additional safeguards those clauses require.

How long we keep things

  • Unconfirmed entries — deleted at the latest three months after signup.
  • Confirmed waitlist entries — kept until the launch of SurgiReport and for a reasonable period after it, so that founding members can be told the product is live and given their access. They are deleted sooner if you ask.
  • After you unsubscribe — your entry is marked as unsubscribed and no further email is sent to you. If you want the entry erased rather than deactivated, write one line to contact@surgireport.io and we will delete it.
  • Anonymous counters — kept as statistics. They hold no personal data, so there is nothing in them to delete.

Your rights

You have all of the following, and exercising them costs you nothing:

  • Access, Art. 15 GDPR — to be told whether we hold data about you and to receive a copy of it.
  • Rectification, Art. 16 GDPR — to have anything incorrect corrected or anything incomplete completed.
  • Erasure, Art. 17 GDPR — to have your data deleted.
  • Restriction, Art. 18 GDPR — to have processing limited instead of deleted, for example while a correction is being checked.
  • Notification, Art. 19 GDPR — to have any correction or deletion passed on to anyone we disclosed your data to.
  • Portability, Art. 20 GDPR — to receive what you gave us in a structured, machine-readable format, or to have it sent to another controller.
  • Objection, Art. 21 GDPR — to object to processing based on legitimate interest, on grounds relating to your particular situation.
  • Withdrawal of consent, Art. 7(3) GDPR — to withdraw your consent at any time, with effect for the future. Withdrawing does not make what happened before it unlawful.

To exercise any of them, write to contact@surgireport.io — one line is enough, and no particular form is required. Withdrawing consent is also a single click on the unsubscribe link at the bottom of any email we send. We answer within one month, as Art. 12(3) GDPR requires.

Complaints

You can complain to a data protection supervisory authority about how we handle your data, under Art. 77 GDPR. The authority competent for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (www.ldi.nrw.de). You may also complain to the authority where you live or work.

Changes to this policy

This version describes a waitlist and nothing else. When SurgiReport launches, it will be replaced by a policy that covers the product itself — what a surgeon puts into it, where that is processed, and for how long. The date at the top of this page always says when the text last changed.