Privacy policy
This Privacy Policy explains how PhysioScan GmbH collects, uses, stores, and protects personal data in connection with its website, software platform, live demos, and corporate posture services. We are committed to processing personal data transparently, lawfully, and securely in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
PhysioScan is an AI-powered posture analysis platform that assesses posture, movement, and related biomechanical patterns through image-based analysis. Based on three smartphone photos, it provides a detailed posture assessment for use in both health and performance settings.
Founded by Alexander Srokovskyi, PhysioScan AI grew out of his broader work in physiotherapy, posture analysis, and AI-supported structural assessment.
PhysioScan works with more than 600 medical partners, including physician practices and physiotherapy clinics, as well as more than 300 fitness studios across Germany. The platform is used in both clinical and performance settings.
PhysioScan AI is operated by ScienceMed GmbH in Baden-Baden, Germany. The company’s address is Schwarzwaldstraße 133, 76532 Baden-Baden. Andreas Philippi is listed as a managing director.
Introduction
PhysioScan GmbH provides AI-powered posture analysis technology designed for physiotherapy practices, clinics, and corporate wellness programs. Through our platform, users can perform real-time posture analysis based on image captures and generate detailed AI-based posture reports and customized exercise plans.
In order to deliver these services, we process certain personal data of:
- Website visitors
- Healthcare professionals
- Business partners
- Corporate clients
- Patients and individuals undergoing posture scans
This Privacy Policy describes how and why we process such data.
Categories of Personal Data We Collect
Data Provided Directly by You
When you interact with our website or request a live demo, we may collect:
- First and last name
- Email address
- Phone number
- Clinic or company name
- Professional title or role
- Country and region
- Information submitted through contact or demo booking forms
- Communication content
Practitioner Account Data
When healthcare professionals create and use a PhysioScan account:
- Login credentials
- Account settings
- Usage history
- Billing-related information
- Support communications
Posture Analysis and Patient Data
When PhysioScan is used for posture assessments, the following may be processed:
- Three posture image captures per scan
- Body alignment measurements
- Postural deviation metrics
- AI-generated posture reports
- Practitioner-entered notes
Such data may qualify as health-related data and is processed strictly for therapeutic and analytical purposes within the platform.
Automatically Collected Technical Data
When visiting our website or using our platform, we automatically collect:
- IP address
- Device type
- Operating system
- Browser type
- Access timestamps
- Pages accessed
- Log files
This data is necessary to ensure system security, functionality, and optimization.
Legal Basis for Processing
We process personal data on the following legal grounds:
- Performance of a contract (Article 6(1)(b) GDPR)
- Consent (Article 6(1)(a) GDPR)
- Legitimate interests (Article 6(1)(f) GDPR), including service improvement and system security
- Compliance with legal obligations (Article 6(1)(c) GDPR)
- Processing of health data based on explicit consent or healthcare service provision (Article 9(2)(a) or (h) GDPR)
Purposes of Processing
We use personal data to:
- Deliver real-time posture analysis services
- Generate AI-based posture reports
- Provide customized exercise recommendations
- Enable practitioners to optimize treatment plans
- Organize and conduct corporate posture days
- Respond to demo requests and inquiries
- Provide technical support
- Improve product functionality and performance
- Ensure cybersecurity and fraud prevention
- Fulfill legal and regulatory obligations
- Send marketing communications where legally permitted
Data Sharing and Processors
We do not sell personal data.
We may share data with:
- Cloud hosting providers located within the European Union
- IT infrastructure and analytics providers
- Payment processing providers
- Authorized personnel within clinics using PhysioScan
- Corporate clients solely for coordination of posture day events (excluding individual health results unless explicit consent is provided)
- Public authorities where legally required
All third-party service providers are contractually bound by data processing agreements and must implement appropriate security safeguards.
Data Retention
We retain personal data only as long as necessary for the purposes stated in this Privacy Policy.
Retention depends on:
- Duration of contractual relationship
- Legal retention obligations
- Healthcare documentation requirements
- User account activity
Posture analysis data is retained according to practitioner settings or applicable medical documentation laws.
Data Security Measures
PhysioScan GmbH implements robust technical and organizational measures, including:
- End-to-end encrypted data transmission (TLS encryption)
- Secure EU-based cloud infrastructure
- Role-based access control
- Multi-factor authentication for administrative access
- Regular security audits and vulnerability testing
- Data minimization and pseudonymization where possible
- Encrypted storage of image data
While we apply high security standards, absolute protection against all cyber risks cannot be guaranteed.
International Data Transfers
As a rule, data is processed within the European Union. If transfers outside the EU occur, they are protected through:
- Secure EU-based cloud infrastructure
- Adequacy decisions
- Equivalent legal safeguards
Updates to This Privacy Policy
We may update this Privacy Policy to reflect legal, technical, or operational changes. The updated version will always include the revised effective date and will be published on our website.
Contact
If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact: privacy@physioscan.io
.png)