Privacy policy
Last updated: 23 April 2026
Who we are
Movalytics is operated by Babon Innovations B.V. (Amsterdam, KvK 90180900). Contact: privacy@babon.eu.
What Movalytics does
Movalytics extracts clinical movement measurements (joint angles, gait parameters, symmetry) from an uploaded video and makes the results available to you in the app. It runs in three configurations, each with its own retention rules:
- Educational: used by students and lecturers in movement-sciences programmes to learn movement analysis. The student keeps the processed video with overlay to review the analysis.
- Research: used by academic researchers who want measurements for a cohort. Video is deleted after analysis; only measurements are retained.
- Clinical: used by physiotherapy practices as part of patient care. Video is deleted after analysis; only measurements are retained.
Your account is set to one configuration at creation. Only the educational configuration is in production today; the research and clinical configurations are not yet in production.
What we collect
- Account data: email, password hash (never plaintext), role, and if you enable two-factor authentication an encrypted authenticator-app secret.
- Uploaded video and the derived measurements computed from it.
- Optional free-text labels you attach to a run (e.g. a patient name or treatment tag). Optional, your choice.
- Operational logs: request timestamps, IP addresses, user-agent strings, HTTP status codes.
What we don't collect
- No behavioural tracking, no advertising IDs, no third-party analytics SDKs.
- No location, microphone, contacts, calendar, or photo-library access.
Where the data lives
Application data is hosted on Scaleway in Paris, France (fr-par). Transactional email is delivered through Hostnet (a Dutch hosting provider). Everything stays in the European Union. Data is encrypted in transit (TLS) and at rest (AES-256 server-side).
How long we keep it
Educational configuration:
- Raw uploaded video: deleted after processing.
- Processed video with overlay: kept while the run exists in the account, so the student can review it. Deleted when the run or the account is deleted.
- Measurements: kept while the run exists.
Research and clinical configurations (planned, not yet live):
- Raw and processed video: both deleted immediately after analysis. We do not retain video.
- Measurements: kept for the duration set in the research or processor contract (typically up to ten years for research; the clinical duration is set by the practice's own retention rules).
All configurations:
- Failed-processing uploads: kept so you can retry, purged within about a month.
- Account data: kept while the account is active.
- Operational logs: kept for security and debugging, typically a few months.
Who can see it
Only you and people you explicitly share runs with can access your analyses through the application. Babon Innovations staff with production-infrastructure access can, in principle, read any data stored in the application; access is limited to a small technical team and is used for troubleshooting and incident response.
Do not enter real patient names or other identifying information in the optional free-text label fields. We do not yet encrypt that field at rest with a separate key, so treat it as low-protection. A future EPD integration will replace the free-text workflow with proper per-field encryption, under a processor agreement signed per clinic.
Sharing and research use
We do not sell, and will not sell, your raw video or any identifying information. Uploaded video is only ever stored and processed on our own hosting infrastructure; it does not pass through the email provider or any other processor. The only third parties involved are the strictly necessary ones needed to run the service: Scaleway for hosting and Hostnet for transactional email (account verification, password reset, admin notifications). Both sit under GDPR Article 28 processor agreements. Email messages contain a recipient address and a short link, nothing more; no video and no derived measurements leave Babon over email. The full processor list is available on request.
Anonymised measurements (joint-angle time series and gait parameters) may be contributed to a research database which Babon intends to license to academic and industrial research partners. Before any recording enters that database we strip every link to your account: account ID, email, session ID, IP address, upload timestamp, and any free-text label you entered are all removed. The measurements enter the database without a pointer back to you, and we do not keep a mapping. Because no one at Babon can re-identify the record and we do not hold the means to re-identify it, we treat it as anonymised data under GDPR Article 4(1) / Recital 26, outside the scope of data-protection law.
Institutional deployments (education, research, clinical) may carve out their data from this use in their own processor agreement. You can opt out at any time by emailing us before a recording is anonymised; once the link to your account is removed we cannot locate your specific record to withdraw it.
Your rights (GDPR / AVG)
You can request a copy of your data (Art. 15), correction (Art. 16), deletion (Art. 17), an export (Art. 20), or restriction of / objection to processing (Art. 18, 21). Email privacy@babon.eu and we reply within 30 days. In-app you can delete any run and change your password. Disagree with our response? Lodge a complaint with the Dutch data-protection authority (autoriteitpersoonsgegevens.nl).
Data-breach handling
If we become aware of a personal-data breach that is likely to risk your rights, we notify affected users without undue delay and, where required, the Dutch data-protection authority within 72 hours (GDPR Art. 33 and 34).
Cookies and third-party resources
The web application uses strictly necessary authentication cookies only (an HttpOnly access token and refresh token). No tracking, advertising, or analytics cookies, so no consent banner is required under the ePrivacy Directive and Dutch Telecommunicatiewet art. 11.7a. Fonts are loaded from Google Fonts (fonts.googleapis.com); when your browser fetches the font, Google receives your IP and user-agent. No other data is sent. The privacy-policy page you are reading does not load the font, so visiting this page does not trigger that request.
Mobile app permissions
The Movalytics mobile app requests only the camera permission, to record the video you upload. It does not request the microphone, location, photo library, contacts, or any other device content. Video is written to the app's private storage and deleted from the device as soon as upload is confirmed.
Users under 18
Movalytics is a professional tool and is not intended for self-service use by people under 18. Where a minor is filmed in an educational or clinical context, the supervising professional or institution is the controller of the resulting data.
Changes to this policy
Updates are published at app.babon.eu/privacy. We notify active account holders by email of material changes. Minor wording changes may be made without separate notification.
Babon Innovations B.V. · Amsterdam, Nederland · KvK 90180900. Vragen kunnen in het Nederlands worden gestuurd naar privacy@babon.eu.