Privacy Policy
Last updated: August 14, 2026
1. Controller and contact
The data controller and service operator is OphTrack. Privacy and DPO-related enquiries can be sent to contact@ophtrack.com.
2. Scope of the service
OphTrack is a professional training logbook. It is not a patient medical record and is not intended for diagnosis, treatment, clinical decision-making, or emergency use. The service uses structured fields designed to prevent the collection of direct patient identifiers. Attachments and narrative clinical notes are not accepted.
3. Data processed
- Account data: name, email address, password hash, account role, access plan, and account timestamps.
- Authentication data: secure session data, verification state, and last-login timestamp.
- Structured logbook data: surgery date, subspecialty, procedure, laterality, status, and predefined clinical categories.
- Security data: HMAC-pseudonymized email/IP-derived rate-limit keys retained for approximately 15 minutes.
- Operational events: signup, login, and case lifecycle events with minimal metadata.
- Support correspondence sent voluntarily to OphTrack.
4. Purposes and legal bases
- Providing accounts, authentication, logbook functions, dashboards, and exports: performance of the service contract.
- Preventing abuse, protecting accounts, maintaining availability, and investigating security events: OphTrack's legitimate interest in operating a secure service.
- Responding to support and data-rights requests: performance of the service contract and compliance with legal obligations.
- Establishing, exercising, or defending legal claims: legitimate interests and applicable legal obligations.
5. Prohibited patient data
OphTrack does not provide a purpose or legal basis for storing identifiable patient information. Users must never enter direct identifiers or identifiable narratives. Structured combinations may still carry re-identification risk in a local professional context; users must therefore record only the minimum training information permitted by their institution and professional obligations. Suspected accidental disclosure should be reported immediately for deletion and review.
6. Recipients and processors
Access is restricted to the account holder and authorized OphTrack personnel where operationally necessary. OVHcloud provides domain, email, VPS, networking, and backup infrastructure in France. PostgreSQL, Supabase services, and Valkey run within OphTrack's private VPS environment. Data may be disclosed to authorities only where legally required.
7. International transfers
OphTrack's production application and primary database are hosted in France. OphTrack does not intentionally transfer application account or logbook data outside the European Economic Area. If a future provider requires such a transfer, this policy will be updated and an appropriate GDPR transfer mechanism will be implemented before use.
8. Retention
- Authentication sessions: no longer than 30 days.
- Rate-limit keys: approximately 15 minutes.
- Structured case records: until the user deletes them or requests account deletion.
- Account data: while the account remains active, then deleted following a valid account-deletion request, subject to legal preservation duties.
- Identifiable operational events: up to 12 months.
- Encrypted logical database backups: 14 days before automatic expiry.
- Support correspondence: for the time needed to resolve the request and up to 12 months afterward, unless a longer period is legally necessary.
9. Cookies and browser storage
OphTrack uses an essential secure authentication cookie and browser storage for theme preference. These are necessary for requested functionality. No advertising cookie, cross-site tracker, or third-party audience-measurement tool is used.
10. Security
Measures include HTTPS, restrictive network rules, private database services, least-privilege database credentials, PostgreSQL row-level security for logbook records, password hashing, rate limiting, encrypted backups, and access controls. No online service can guarantee absolute security.
11. Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or object to certain processing. You may also complain to the CNIL in France. Instructions are available on the GDPR & Data Rights page.
12. Changes
Material changes will be published on this page with a revised update date.