Effective date: April 1, 2026
SynaptoNex (“we”, “us”, “our”) operates SynaptoFlow, a pre-operative patient compliance tracking service. This policy applies to the SynaptoFlow website (synaptoflow.vercel.app) and the underlying service. Contact: synaptonex@gmail.com.
SynaptoFlow is offered to surgical practices in Pakistan. This policy is written to Pakistani law. Pakistan has no personal data protection statute in force as of this writing; the Personal Data Protection Bill remains in draft. We nonetheless apply the obligations set out below as binding on ourselves, and we will update this policy when the Bill is enacted.
The surgical practice determines what patient information is collected and why, and is therefore the controller. SynaptoNex acts only on the practice's instructions and is the processor. A written Data Processing Agreement between the practice and SynaptoNex governs this relationship and must be signed before any patient information is entered.
Surgeon-entered data:
Patient-entered data:
System-generated data:
We do not collect: insurance information, payment information, full clinical history, free-text clinical notes other than what the surgeon provides, location data, biometric data, or any data from cameras or microphones.
We do not use your information for advertising, marketing to third parties, or training third-party AI models on your data.
Row-level security is enforced at the database layer: a surgeon's queries cannot return another surgeon's patients.
SynaptoFlow uses the following third-party processors. Each receives only the data it needs for its specific function.
We will update this list when we change sub-processors. Material changes will be communicated to active surgeon accounts by email.
Our infrastructure providers currently store and process data outside Pakistan. We do not knowingly transfer Protected Health Information to a jurisdiction without an equivalent safeguard in place, and we will notify each affected practice in advance if that changes.
No internet-connected service is perfectly secure. Where we discover a breach of unsecured Protected Health Information we will notify the affected covered entity without unreasonable delay and within the window set out in our Business Associate Agreement with that practice, so the practice can meet its obligations under the its own obligations to affected patients. There is no statutory breach notification deadline in Pakistan at present; we commit contractually to notifying the practice without unreasonable delay and in any event within 72 hours of discovery. We will notify the relevant data controller (the surgeon) without undue delay and within 72 hours where required by GDPR.
Patient records are retained for as long as the practice maintains an active account and for as long as the practice is required to keep medical records under Pakistan Medical Commission requirements and its own institutional policy. The audit trail and signed surgical safety checklists cannot be deleted, by anyone, including us. That is deliberate: a record its owner can erase after an adverse event is not a record. Where an entry was made in error it is voided with a written reason and both the original and the correction remain visible. Clinical detail on a patient record can be deleted by the practice from the dashboard, and the audit entry showing that a deletion occurred remains. On account closure, patient data is deleted within 30 days except the audit trail, which is retained for the statutory medical records period and isolated from active use.
Subject to applicable law, you have the right to:
For patients: most rights are exercised through the surgeon (the data controller). For surgeons: contact us at synaptonex@gmail.com. We respond within 30 days.
We use the minimum technical state required to keep you logged in (Supabase authentication tokens) and to remember consent within a browser session. We do not use advertising cookies, third-party analytics that build user profiles, marketing pixels, or cross-site tracking.
SynaptoFlow may be used in paediatric surgical care. Where the patient is under 18, the surgical practice is responsible for obtaining consent from a parent or legal guardian and for complying with applicable state law on the confidentiality of minors' health information. We do not knowingly collect information directly from a child.
The surgical practice is the controller of the patient information it enters. SynaptoNex processes that information only on the practice's instructions and only for the purposes set out in this policy.
We may update this Privacy Policy as the Service evolves. The effective date above will be updated. Material changes will be notified to active surgeon accounts by email. Continued use of the Service after changes constitutes acceptance.
Privacy questions, sub-processor list updates, and data subject requests: synaptonex@gmail.com
We aim to respond within 5 working days and complete formal requests within 30 days.