Security

Security and data protection

How Movalytics handles data: where it lives, who can access it, and what happens when something goes wrong. This page answers the questions healthcare organisations and research partners ask us most often.

Data stays in the EU

All application data is processed and stored in a data centre in Paris (Scaleway); transactional email (verification, password reset) is delivered through Scaleway Transactional Email, also in Paris. Everything stays within the European Union; no data leaves the EU.

Encrypted, in transit and at rest

All traffic to and from the platform travels over an encrypted connection (HTTPS). Stored data and backups are encrypted at rest (AES-256); passwords are only ever stored hashed. Keys and other secrets are never kept in source code.

Pseudonyms, not names

Subjects and patients are registered under a pseudonym (for example P001); the application never asks for a name. The key list linking pseudonyms to people stays with the healthcare or research organisation and is never stored at Babon.

Access is limited and logged

Logging in always requires a second step beyond a password (two-factor authentication). A recording is visible only to the uploader and to anyone it is explicitly shared with. Access to clinical data is logged; operational logs stay within our EU infrastructure and are kept for a few months.

Every analysis runs isolated

Each video analysis runs in its own sealed environment with no access to data from other recordings. That environment is cleaned up automatically afterwards.

Retention and deletion

Raw video is automatically deleted at most 30 days after upload in the educational configuration, and directly after analysis in the research and clinical configurations. Derived results (angles, parameters, reports) remain available per the project or processor agreement; users can delete their own recordings. At project end we delete all project data on request.

Backups and recovery

Databases have continuous, encrypted backups within the same EU region, with restore to any point in the past seven days. Stored files (video, reports) deliberately have no second copy: what is deleted there is gone. That is a privacy choice, not an omission. All configuration is under version control, so every change is traceable.

When something goes wrong

In case of a data breach we inform the data controller within 24 hours and, where required, the Dutch Data Protection Authority within 72 hours. Every incident is documented and evaluated.

Found a vulnerability?

Tell us right away and we will fix it. Our reporting point is listed insecurity.txt,or email us directly atsupport@babon.eu.

Live availability of our systems is atstatus.babon.eu.

Documentation for procurement

For procurement and privacy reviews we provide on request: our data-processing and security description, a data processing agreement, the full processor list, and the security certificates of our infrastructure provider.

Our privacy statement is atapp.babon.eu/privacy.

Questions about security or procurement?

Request documentation