... Skip to content

Privacy Policy

Last update on the 12/06/2021

WHO WE ARE

Our website address is: https://eips.com

WHAT PERSONAL DATA WE COLLECT AND WHY WE COLLECT IT

COMMENTS

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

MEDIA
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
CONTACT FORMS
If you submit a form on our site, your name, email address and phone number maybe be saved in our database.
COOKIES

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you have an account and you log in to this site, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

EMBEDDED CONTENT FROM OTHER WEBSITES

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

ANALYTICS

HOW LONG WE RETAIN YOUR DATA

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

WHAT RIGHTS YOU HAVE OVER YOUR DATA

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us.

You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

WHERE WE SEND YOUR DATA

Visitor comments may be checked through an automated spam detection service.
PLUGIN: SMUSH

Note: Smush does not interact with end users on your website. The only input option Smush has is to a newsletter subscription for site admins only. If you would like to notify your users of this in your privacy policy, you can use the information below.

Smush sends images to the WPMU DEV servers to optimize them for web use. This includes the transfer of EXIF data. The EXIF data will either be stripped or returned as it is. It is not stored on the WPMU DEV servers.

EIPS VIRTUAL CONSULTATION APP

Last updated: 8 August 2026

EIPS Limited (“we”, “us”) operates the EIPS Virtual consultation service — the EIPS Virtual mobile app and the website at virtual.eips.com. We are the data controller for the personal data described below.

EIPS Limited, Severis Building, Floor 3, 9 Archiepiskopou Makareiou III, Nicosia 1065, Cyprus. Contact: [email protected]

What we collect

  • Account and contact details — your name, email address, phone number, country, date of birth and preferred language.
  • Health information — the procedure you are interested in, your main concern, previous surgeries, current medications, smoking status, the photographs and any video you upload for assessment, and the messages you exchange with the surgeon. Under the GDPR this is special-category data and we treat it accordingly.
  • Payment records — the amount, status and reference for the consultation fee. Card details are entered directly with our payment provider and never reach our systems.
  • Technical data — your account identifier, a device token used to send you notifications, the app version, and diagnostic data if the app encounters an error.

Why we process it

  • To create and operate your account and provide the consultation you have asked for (performance of our contract with you, GDPR Article 6(1)(b)).
  • To provide health care. Your clinical information is processed for the purpose of a consultation given by a licensed surgeon bound by professional secrecy (GDPR Article 9(2)(h)).
  • To take payment for the consultation fee (Article 6(1)(b)).
  • To keep the service secure and working, including crash diagnostics (legitimate interests, Article 6(1)(f)).
  • To meet legal obligations, including medical record-keeping (Article 6(1)(c)).

Automated processing and artificial intelligence

We use AI to support the service. You should know exactly where:

  • Photo quality check. When you upload a photograph it is analysed automatically to judge whether it is usable — lighting, framing and focus. This is a technical check only. It does not diagnose anything and makes no clinical assessment.
  • Message translation. If you choose to translate a message, that message is processed to produce the translation.
  • Draft replies for the surgeon. The surgeon can generate a suggested draft reply, which draws on your consultation details and conversation. The draft is only ever a starting point: the surgeon reviews and edits it, and nothing is sent to you unless the surgeon sends it.

These features are provided by Anthropic acting as our processor. Your data is not used to train AI models. No decision producing legal or similarly significant effects about you is made by automated means. Every clinical judgement is made by the surgeon.

Who processes your data

We do not sell your data. We share it only with providers who process it on our instructions:

  • Supabase — database, file storage and authentication — Switzerland
  • Anthropic — photo quality check, translation, draft replies — United States
  • Stripe — payment processing — United States / EU
  • Google (Firebase) — push notifications and website hosting — United States
  • Google Drive — encrypted backups — United States
  • Sentry — crash and error diagnostics — United States
  • Resend — notification emails — United States

Switzerland is recognised by the European Commission as providing an adequate level of data protection. Transfers to providers in the United States are made under the Standard Contractual Clauses included in each provider’s data processing terms.

How your data is protected

Data is encrypted in transit and encrypted at rest. Consultation photographs and video are held in private storage that is not publicly accessible; they are served only through short-lived links to you and to the treating surgeon. Backups are encrypted before they leave our systems. Access to your consultation is limited to you and the treating surgeon.

Please note: the service is not end-to-end encrypted. Your consultation is readable by the treating surgeon, which is necessary for the surgeon to advise you. An earlier version of this policy described the service as end-to-end encrypted; that description was inaccurate and has been corrected.

How long we keep it

We keep your consultation records for as long as your account is open, and afterwards for as long as we are required to retain medical records. Backups are kept as a rolling set of the most recent 14 daily snapshots; deleted data disappears from backups as those snapshots age out.

Deleting your data

You can delete your account at any time from Profile → Delete Account in the app. This permanently erases your account, consultations, messages, uploaded photographs and video, and notification records. You can also ask us at [email protected]. Some records may be retained where we are legally required to keep them.

Your rights

You have the right to access your data, correct it, have it erased, restrict or object to how we use it, and receive a copy in a portable format. Where we rely on your consent, you may withdraw it at any time. To exercise any of these, contact [email protected].

If you believe we have handled your data improperly, you may complain to the Office of the Commissioner for Personal Data Protection (Cyprus), or to the supervisory authority where you live.

Children

The service is intended for adults aged 18 or over. We do not knowingly provide consultations to children.