Skip to content

Privacy Policy

Last updated: 2026-07-13

1. Introduction

PhysioSense ("we", "our"), operated by PhysioSense d.o.o., Vladimira Rolovića 2a, 85000 Bar, Montenegro (Tax ID / PIB: 04409175), operates the website physiosense.net. PhysioSense is an educational reference tool — it is NOT a medical device, clinical decision support system, or diagnostic tool. This policy describes how we collect, use, and protect your personal data in accordance with the GDPR, the Montenegrin Law on Personal Data Protection, and applicable data protection laws.

PhysioSense is intended for users aged 16 and older. If you are under 16, you may only use PhysioSense with the consent of a parent or legal guardian.

2. Data We Collect

Account data:

  • Email address (for authentication)
  • Name (for profile display)
  • Role (e.g., physiotherapist, student)
  • Professional license number (optional)
  • Subscription tier selection
  • Payment data (card payments are processed by our bank's secure payment gateway — we do not store or have access to your full card number)

Health data (GDPR Article 9 — special category):

  • Health assessment data (diagnosis, recovery phase, symptom duration, pain level, functional status, patient age, sex, comorbidities, equipment, goals, clinical setting)
  • Patient-reported outcomes (pain scores, functional scores, clinical progress, adherence data)
  • Generated reports (evidence-based educational reference content, PDF documents)

Health Data Processing

Health data you enter (diagnosis, pain scores, comorbidities, functional assessments) is processed solely to generate educational evidence references. This data is classified as Special Category under GDPR Article 9 and is never used for clinical decision-making.

Health data is retained for the duration of your account. Archived plans are anonymized after 90 days and permanently deleted after 2 years. You may delete your data at any time via Settings > Profile.

You have the right to access, rectify, export, or delete your health data at any time. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal. Contact privacy@physiosense.net for any data protection inquiries.

Legal basis for health data

When you create an evidence-based report, we collect health-related information that constitutes "special category data" under GDPR Article 9. We process this health data based on your explicit consent (Article 9(2)(a)), which you provide when creating a report. You may withdraw this consent at any time by deleting your reports or your account in Settings.

Health assessment data refers to clinical scenario parameters entered by the user to generate evidence-based reports. This data describes a clinical scenario and may or may not correspond to an actual patient. PhysioSense does not collect direct patient identifiers (name, date of birth, address, or national ID number).

Clinician users (physiotherapists, physicians, etc.) may optionally enter a patient's email address and phone number during intake. In this case PhysioSense acts as a data processor on behalf of the clinician, who is responsible for obtaining the patient's consent. This contact data is stored alongside the clinical record and deleted with it.

3. How We Use Your Data

  • To provide and operate the platform — Contract, Art. 6(1)(b); Explicit consent for health data, Art. 9(2)(a)
  • To process subscriptions and payments — Contract, Art. 6(1)(b)
  • To send transactional emails (account confirmation, password reset) — Contract, Art. 6(1)(b)
  • For platform security and error tracking — Legitimate interest, Art. 6(1)(f)
  • To improve the platform based on aggregated usage (with consent) — Consent, Art. 6(1)(a)
  • To generate pseudonymized, aggregate insights from outcome data for research and platform improvement. Applied only to pseudonymized data without direct identifiers. Users can opt out via Settings > Consent Management — Legitimate interest, Art. 6(1)(f)

3b. Anonymized Statistics and Research

Two separate mechanisms process outcome-related data in aggregated form. Both operate on grouped data (by condition and care setting) and never include names, contact details or free-text notes.

  • Platform improvement snapshots: pseudonymized plan parameters are processed under Legitimate Interest (Art. 6(1)(f)) with an account-level opt-out in Settings → Data & Privacy.
  • Per-plan research participation: outcome data (scores and adherence values) from a specific plan is included in anonymized aggregate statistics and scientific research datasets only with explicit opt-in consent for that plan (Art. 9(2)(a)), given at intake or on the plan page.

Aggregates are published only in groups of at least 20 plans (k-anonymity, k≥20), so no individual can be identified.

Per-plan consent can be withdrawn at any time on the plan page (Art. 7(3)); withdrawal stops future use, while already published anonymized aggregates cannot be recalled.

4. Data Storage & Security

  • Database and authentication: Supabase (EU — Ireland). Row-Level Security (RLS) on all tables.
  • Application hosting: Vercel (EU — Paris, cdg1). HTTPS/TLS encryption, HSTS with 2-year duration.
  • Passwords: hashed via bcrypt (Supabase Auth). We never store passwords in plain text.
  • Security headers: Content-Security-Policy, X-Frame-Options (DENY for API, SAMEORIGIN for pages), X-Content-Type-Options: nosniff, CSRF protection on all mutations.
  • Outcome backups: encrypted and stored in Supabase Storage (daily backup).

5. Sub-Processors

We use the following sub-processors to process your data:

ServicePurposeLocationTransfer Safeguard
SupabaseAuthentication and databaseEU (Ireland)EU adequacy — no transfer
VercelApplication hosting and CDNEU (Paris)EU adequacy — no transfer
Vercel AnalyticsAggregate website analyticsEU (Frankfurt)EU adequacy — no transfer
Partner bank (card payments)Card payment processingMontenegroProcessed on the bank's PCI-DSS systems; PhysioSense does not receive or store full card numbers.
ResendTransactional emailsUSStandard Contractual Clauses (SCCs). Email addresses only.
SentryError trackingEUEU adequacy — no transfer

We do not sell, rent, or share your personal data with third parties for marketing purposes. Data Processing Agreements (DPAs) are in place with all sub-processors.

5b. Cookies

For information about cookies we use, see our Cookie Policy.

5c. International Data Transfers

Your data is stored in the EU: database in Ireland (Supabase), hosting in Paris (Vercel). The only transfer outside the EU is your email address sent to Resend (US) for transactional email delivery, protected under Standard Contractual Clauses (SCCs) pursuant to GDPR Article 46(2)(c). No health data is transferred outside the EU.

6. Your Rights (GDPR)

  • Access (Art. 15)view your data in Settings
  • Rectification (Art. 16) update your data in Settings
  • Erasure (Art. 17)request account deletion in Settings > Profile
  • Data Portability (Art. 20) download all your data in JSON format via Settings > Export Data
  • Restriction (Art. 18) contact privacy@physiosense.net
  • Withdraw Consent (Art. 7(3)) withdraw your consent to health data processing at any time via Settings > Consent Management. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
  • Objection (Art. 21) contact privacy@physiosense.net
  • Complaint (Art. 77) you have the right to lodge a complaint with a supervisory authority. For Montenegro: AZLP, www.azlp.me. For EU residents: your local DPA.

7. Automated Decision-Making

PhysioSense does not make automated decisions about you. Report generation filters published evidence based on your input but does not constitute automated decision-making or profiling under GDPR Article 22. All decisions remain with the clinician.

8. Data Retention

  • Account data: while account is active. Deletion on request via Settings.
  • Health data: while consent exists. Withdrawing consent triggers deletion.
  • Generated reports: removed from user view upon deletion. Pseudonymized data (without direct patient identifiers) may be retained for quality assurance and aggregate research. Email address and certain account data remain linked to the account and are deleted with it. Upon account deletion, all personally identifiable data is permanently deleted within 30 days.
  • Payment records: 7 years (legal obligation).
  • Error logs: 90 days (Sentry automatic deletion).

8b. Exercise Library — HD Video Requests

If you request a high-definition video from our public exercise library, we collect the email address you provide, the content locale, a hashed representation of your IP address (SHA-256), and your user-agent string. No account is required.

Legal basis: your explicit consent (GDPR Article 6(1)(a)) given via the consent checkbox on the request form.

Purpose: to email you the HD link once and to prevent abuse through a simple rate limit (3 requests per hour per hashed IP). The email is not used for marketing.

Retention: records are automatically purged 90 days after the email is delivered, or 30 days if delivery fails. We do not store the raw IP address — only a salted hash used for rate limiting.

Your rights: to access or delete your record before automatic purge, contact privacy@physiosense.net with the email address you used.

9. Policy Changes

If we make material changes to this policy, we will notify you via email at least 14 days before they take effect.

10. Contact

For privacy inquiries, contact us at: privacy@physiosense.net

We have not appointed a Data Protection Officer (DPO) as our processing does not meet the thresholds under GDPR Article 37.

We respond within 30 days in accordance with GDPR requirements.

PhysioSense d.o.o., Vladimira Rolovića 2a, 85000 Bar, Montenegro — Tax ID (PIB): 04409175