Privacy

What we collect, and what we do not

This website asks for personal details in exactly one place — the contact form. Two things involve a company outside ours, and this policy explains both: Google Tag Manager, which we use to run Google Ads conversion measurement (telling us which of our adverts brought you here) and Google Analytics (telling us how visitors use the site), and which loads nothing at all unless you accept it; and a Cloudflare security check that runs on the contact form itself to keep automated abuse out of it.

Last updated: 4 September 2026

What we collect

The contact form, and nothing else you have to fill in

There is no account to create on this site, no login, and no newsletter to sign up to. The only form is on the contact page, and it asks for:

  • your name;
  • your email address, so that we can reply;
  • the hospital, institution or company you are with;
  • your country or region, so that the right regional specialist answers you;
  • your phone number — optional, and the form works without it;
  • what your enquiry is about, and optionally which products interest you;
  • your message; and
  • the fact that you ticked the box agreeing to this policy.

Our web server also keeps the standard access log that every web server keeps: the IP address a request came from, the date and time, the page or file requested, and the browser identification string your browser sends. We use it to keep the site running and to investigate abuse, not to build a profile of you.

One more technical detail, because it involves your IP address. To stop automated spam, the form allows five messages an hour from the same connection. To count them we write nothing but timestamps to a temporary file whose name is a one-way cryptographic hash of your IP address. The IP address itself is never written down, and the hash cannot be turned back into it.

Please do not send us patient information. The contact form is for business enquiries. If you need to discuss a specific case, say so in your message and we will arrange a proper channel with your institution.

This site is aimed at healthcare professionals, educators and the institutions they work for. It is not directed at children, and we do not knowingly collect personal information from anyone under 16.

How we use it

To answer you — that is the whole list

We use what you send to read your enquiry, to reply to it, and to follow up on the demonstration, quotation or technical question you asked about. If your enquiry is better handled by our US subsidiary or by a distributor in your country, we will tell you before passing it on.

We do not sell, rent or trade your details. We do not add you to a marketing list because you asked us a question. There is no profiling and no automated decision-making of any kind on this site.

If you are in the European Union or the United Kingdom and want the legal wording: we rely on your consent, which is the box you tick before sending the form, and on our legitimate interest in answering a business enquiry that was addressed to us. You can withdraw consent at any time — see Your rights below.

Who sees it

Our staff, our email provider, and no one else

Your message arrives as an email in a company mailbox. The people who read it are the Surglasses staff who handle enquiries, at our headquarters in Taichung, Taiwan and at our subsidiary in California.

  • Our email provider. Company email is delivered and stored through Google Workspace, so your message passes through and is held on Google’s systems in the same way as any email you send us directly.
  • Our web hosting provider, which operates the server this site runs on and therefore holds the access log described above.
  • Our internal alert channel, but only if sending fails. If the mail server cannot deliver your enquiry, the website posts an alert — including what you wrote — to a private internal chat channel used by the small team who run this website. We do this deliberately: when delivery fails, that alert is the only surviving copy of your enquiry, and without it your message would simply vanish and we would not even know you had written.
  • Google, but only if you accepted advertising and analytics measurement. If you pressed Accept on the cookie notice, Google receives the fact that you opened certain pages on this site and, more generally, how visitors move around it, together with your IP address and the identifiers in the cookies it sets. That is a separate thing from your enquiry: your name, message and the rest of the form are never sent to Google. If you pressed Decline, or have not answered yet, Google receives nothing, because nothing of Google’s is loaded at all. The Cookies and tracking section explains this in full.
  • Cloudflare, if you use the contact form. The form carries an automated security check supplied by Cloudflare, which is what stops it being used to send us advertising. Running that check means your browser contacts Cloudflare, which receives your IP address and technical information about your browser and device in order to judge whether you are a person rather than a script. It happens on the contact page only, and unlike the Google measurement above it runs without asking you first, because the form cannot be protected after the fact. What comes back to us is a pass or a fail and nothing else: Cloudflare does not receive your name, your message or any other field, and we do not receive any information about you from Cloudflare. The Cookies and tracking section explains this in full.

No data broker receives anything from this site, and apart from the two companies named above — Google for advertising and analytics measurement, Cloudflare for the security check on the contact form — no other third party is connected to it.

We are a Taiwanese company with a subsidiary in the United States, so if you write to us from anywhere else, your details are transferred to and read in Taiwan and, where relevant, the United States. Data-protection law in Taiwan is not identical to the law where you live. We keep enquiries to the minimum needed to answer you, and you can ask us to delete yours at any time.

Cookies and tracking

One cookie notice, and one security check

We advertise on Google, and we want to know which of those adverts actually bring people to this site; we also want to understand, in general terms, how visitors use the site once they arrive. Both are run through Google Tag Manager, which loads Google Ads conversion tracking and Google Analytics, and it is the only tracking of any kind on this website. There is no session recording, no fingerprinting, no advertising network beyond Google, and no data broker.

Nothing loads until you press Accept

The first time you arrive, a notice appears at the foot of the page with two buttons, Decline and Accept. Until you press one of them, no Google code has been loaded, no request has been made to Google, and no cookie has been set. This is worth stating precisely, because it is stronger than what most sites do: many load the advertising or analytics code immediately and merely instruct it not to use cookies yet, which still tells the advertiser that you were here. We do not do that. If you press Decline, or simply never answer, your visit is never reported to anyone.

The two buttons are the same size and either one takes a single press. Declining is not made harder than accepting, and nothing on this site is withheld from you if you decline — every page works exactly the same either way.

What we store, either way

Whichever button you press, we remember your answer so we do not ask again on every page. That answer is kept in your own browser’s local storage, on your device, under a single name (surglasses-consent) holding one word: whether you accepted or declined. It is not a cookie, it is never sent to our server or anyone else’s, and it is the only thing this site stores on your device if you decline. Clearing your browsing data removes it, and the notice will then ask you again.

What Google receives if you accept

If you accept, your browser loads Google Tag Manager from googletagmanager.com. Two things then happen. Google is told when you open certain pages — the home page, the contact page and three product pages — when you click one of our info@surglasses.com email links, and when a contact form is successfully sent, which is how we measure advertising conversions. Separately, Google Analytics records, in the ordinary way any site using it does, which pages you view and how you move around the site, so we can understand how it is used. Either way, Google receives your IP address and the identifiers in the cookies it sets. Google acts as an independent controller of that data under its own privacy policy; its cookies are set from Google’s own domains and typically last up to two years unless you clear them.

What is never sent to Google is the content of your enquiry. Your name, email address, phone number, organisation and message go into an email to us and nowhere else. The conversion report says that a form was sent, not what was in it.

Changing your mind

Clear this site’s stored data in your browser and the notice will appear again on your next visit, so you can choose the other answer. To remove the cookies Google has already set, use your browser’s own controls, or Google’s advertising settings. Declining or clearing does not delete measurements already reported to Google; write to us at info@surglasses.com if you want us to help with a request to Google about that.

The security check on the contact form

The contact form carries an automated security check supplied by Cloudflare, called Turnstile. It is there for one reason: without it the form is used to send us advertising, which is not a hypothetical — it began happening as soon as this site went live. The check looks at your browser and decides whether you are a person or a script, usually without asking you to do anything.

We have to be straight with you about how this one differs from the Google measurement above, because the difference matters. It loads without asking you first. We cannot put it behind the Accept button, because a check that only runs after you have agreed to it is no protection at all — the automated senders would simply decline. It is limited instead: it runs on the contact page and nowhere else on this site, so no other page you read contacts Cloudflare at all.

Running the check means your browser contacts Cloudflare, which receives your IP address and technical information about your browser and device, and may store a short-lived value in your browser for the purpose of that check. What comes back to us is a pass or a fail and nothing more. Cloudflare is not sent your name, your message or any other field on the form, we receive no information about you from Cloudflare, and none of this is used for advertising or shared with Google. If you would rather not use the form at all, email us at info@surglasses.com and no check is involved.

Everything else on this site is still served by us

Apart from the Google tag and the Cloudflare check described above, every font, image, video, stylesheet and script on this site comes from our own domain. There is no content delivery network, no embedded map, no embedded video player and no social media widget. The YouTube, LinkedIn, X and Facebook icons in the footer are ordinary links: nothing is sent anywhere until you choose to click one, and then you are on that company’s site under its own privacy policy.

One further cookie exists and it is not about visitors at all. When a member of our staff signs in to the news or events editor to publish something, that sign-in sets a single session cookie, which is strictly necessary for the sign-in to work and is discarded when they log out. It is never set for you.

How long we keep it

The website itself stores nothing

The program that receives the contact form does not write your enquiry to a database or to a log file. It formats your message into an email, sends it, and finishes. The only thing it writes to disk is the anti-spam timestamp file described above, which holds no readable personal data and stops counting after an hour.

Because of that, the copy that lasts is the email in our mailbox. We keep enquiries for as long as we are dealing with them and for a reasonable period afterwards as a record of the conversation, and we delete them when they are no longer needed, or sooner if you ask.

Server access logs are kept for a limited period for security and diagnostics and are then discarded.

Your answer to the cookie notice stays in your browser until you clear this site’s data. If you accepted, Google’s own cookies last for as long as Google’s policy says — typically up to two years — and are removed by clearing your browser’s cookies. Neither is on our server, so neither is something we can delete for you.

Note that we do not email you a copy of what you submitted. If you want a record of your own message, save it before you leave the form.

Your rights

Ask us, and we will do it

Write to info@surglasses.com from the address you contacted us with, or use the details in Contact and changes below, and you can:

  • ask what we hold about you and get a copy of it;
  • have anything inaccurate corrected;
  • have your enquiry and our correspondence deleted;
  • withdraw the consent you gave when you sent the form;
  • change your answer to the cookie notice at any time — see Changing your mind; and
  • object to us using your details, or ask us to restrict what we do with them.

We will answer within 30 days. We do not charge for any of this, and we will not ask you why.

Depending on where you live, these may also be rights you hold under a specific law — the GDPR in the European Union, the UK GDPR, or the Personal Data Protection Act in Taiwan, among others. You do not need to tell us which one you are relying on: we handle every request the same way. If you are not satisfied with how we have handled yours, you can complain to the data-protection authority for your country.

Security

Less stored means less to lose

The single biggest protection on this site is architectural: it is a set of static files with no visitor database behind it, so there is no store of visitor records to be stolen. Alongside that:

  • the form program stores nothing itself, and hashes IP addresses rather than recording them;
  • no password or mail credential exists anywhere in the website’s files — they are held in a configuration file outside the website directory entirely;
  • the browser is instructed by a strict content security policy to load nothing from any website other than our own, with two named exceptions and no others: Google Tag Manager, which loads our advertising and analytics measurement and then only if you accepted it, and Cloudflare’s security check on the contact page — which is also why an injected script could not run here; and
  • the form is protected against the classic mail-header injection attack, along with rate limiting and a hidden field that only automated bots fill in.

No system is perfectly secure, and we will not pretend otherwise. That is the other reason for the request above: please do not send patient-identifiable information through a website contact form — not ours, and not anyone else’s.

This policy covers this website. It does not cover data handled inside our medical devices and software when they are in use at a hospital or a teaching institution: that is governed by the agreement between us and that institution, and by the clinical and regulatory rules that apply there.

Contact and changes

Who is responsible, and how to reach us

The company responsible for the personal data described here is Taiwan Main Orthopaedic Biotechnology Co., Ltd., trading as Surglasses, of 2F., No. 41, Keya Rd., Daya Dist., Taichung City 428, Taiwan (R.O.C.), together with its US subsidiary Surglasses, LLC, of 10373 Trademark St., Suite K, Rancho Cucamonga, CA 91730, USA.

For anything on this page — a question, a request about your own details, or a complaint — email info@surglasses.com, or call +886 4 2565 2818 in Taiwan or +1 (888) 836-7198 toll-free within the United States. Both addresses and both numbers are listed on our locations page.

If we change this policy we will change the date at the top of the page. If a change materially affects what we do with details you have already sent us, we will say so here rather than quietly editing the text.