Privacy notice
How this licence portal handles personal data.
Last updated: 3 September 2026
aiEndoscopic AG issues and delivers software licences through this portal. This notice covers the personal data the portal itself processes. Our company-wide policy covers everything else, including the website.
What we process, and why
The portal stores only what it needs to issue, deliver and activate a licence.
- Name and email address — to identify your account, sign you in, deliver your licence and answer support requests.
- Licence record — product key, product, tier, purchase and validity dates, and the distributor that sold it. This is our proof of what was issued to whom, and we have to be able to trace it.
- Device binding — where a licence is locked to one machine, the identifier and name of that device.
- Activation and check-in data — the application version, and a one-way fingerprint of the device identifier, recorded when a licence is activated or verified. We use it to confirm activations, diagnose failures and detect licence abuse. We do not keep the address the request came from, we cannot read the device identifier back out of the fingerprint, and we strip this data from our records well before the licence record itself.
Why we are allowed to process it
We process under the Swiss FADP and, where it applies, the GDPR, on these grounds:
- Performance of our contract with you — issuing, delivering and activating the licence.
- Compliance with legal obligations — medical-device record-keeping and accounting duties oblige us to keep proof of what we issued.
- Our legitimate interest in preventing licence abuse and keeping the service secure.
How long we keep it
We keep personal data only for as long as necessary for the purposes above, unless a longer retention period is required or permitted by law.
We deliberately do not publish a single figure. Record-keeping duties differ between the countries we sell in: one may require us to keep a licence record for years where another requires us to delete it sooner. We apply the period the law applicable to your licence requires, and not longer. Technical activation data goes on a much shorter schedule than the licence record, because nothing obliges us to keep it.
If you want to know the period that applies to your licence, ask us — see Contact below.
Deletion and backups
When we delete your personal data it goes from our live systems straight away. Encrypted backups may still hold a copy for a bounded period afterwards: a backup exists so that we can restore a known-good state after a failure, editing one destroys exactly that property, and the copies are not available for ordinary use.
They are kept for disaster recovery only and age out on a fixed schedule. We record every deletion, so that if a backup ever has to be restored, the same deletion is applied again before the system goes back into service.
Who else sees it
We do not sell, rent or trade personal data. It is shared only with:
- our hosting and email providers, acting on our instructions — the portal and its backups run in the European Union (AWS, Stockholm);
- the distributor that sold your licence, which sees the records of its own customers and nothing else;
- authorities, where the law requires it.
Your rights
You can ask us for access to your data, a copy of it, correction, deletion, or restriction of processing, and you can object to processing. Write to the address below and we will act on it. Where a record-keeping duty forces us to keep something, we will tell you what and why.
How we protect it
Data is encrypted in transit and at rest, backup storage is private and separately encrypted, access is limited to the staff who need it, and administrative actions are written to an append-only audit log.
Changes
We update this notice when our practices or the law change, and post the new version on this page with a new date.
Contact
aiEndoscopic AG, Josefstrasse 219, 8005 Zürich, Switzerland