moovv.fit for physios
  • Back to home
  • Terms
  • Login
get started — free

Privacy Policy

For physiotherapists and clinics. Last updated: 14 August 2026.

This explains how the Moovv practice platform handles data, and — just as important — which of us is responsible for what.

You are responsible for your patients' privacy. You decide what patient data to collect, you tell them about it, and you obtain their consent. We are responsible for keeping that data safe once it reaches us — storage, encryption, backups and access control.

Your patients have their own privacy policy at moovv.fit/privacy, which covers the moovv.fit app they use.

1. The two roles, and why the distinction matters

Under the Digital Personal Data Protection Act, 2023 and comparable data protection law, there are two roles in play:

  • You are the Data Fiduciary (elsewhere called the controller) for your patients' personal and health data. You decide which patients to enter, what to record about them, what to upload, and why. The law places the duty of notice, consent and patient rights on whoever makes those decisions — which is you, not us.
  • We — Ryoshigo Technologies Private Limited, which operates Moovv — are a Data Processor. We hold and process that data on your instructions, to provide the Platform to you. We do not decide what goes in, we do not use it for our own purposes, and we do not sell it.

This is not a way of shifting blame; it follows from who is in the room with the patient. We have never met your patients and cannot obtain their consent, explain your clinical reasoning, or judge what is appropriate to record. You can.

2. What we hold

2.1 About you and your practice

We collect this directly from you, and we are the Data Fiduciary for it:

Account Name, designation, phone number, email, profile photo
Professional Qualifications, registration and licence details, specialisations, clinic and organisation affiliations
Practice Clinic names and addresses, availability, session pricing, team and receptionist accounts
Billing Subscription status, invoices, GST details. Card and payment credentials are handled by our payment provider and never reach our servers.
Technical Login events, IP address, device and browser information, and error logs — used to keep the Platform secure and working

2.2 About your patients

We hold this on your behalf. You put it there, and you are the Data Fiduciary for it:

Identity Name, phone number, age, and contact details you enter
Clinical Pain profiles, body part and diagnosis, severity and triggers, clinical notes, session notes
Plans Prescribed exercises, dosage, your notes, adherence and pain logs recorded by the patient
Media Videos you record or upload for a specific patient, and images derived from them
Communications Messages exchanged with the patient through the Platform, and telehealth session records

3. What we do with it

We process data to run the Platform for you: authenticating logins, storing and retrieving records, generating exercise plans and PDF exports, delivering plans to the patient's app, running telehealth sessions and messaging, sending appointment and reminder notifications, issuing invoices, and providing support when you ask for it.

We also use aggregated, de-identified information to understand how the Platform is used and to improve it. This never identifies a patient.

We do not sell personal data, and we do not use your patients' data to market to them.

4. AI and automated processing

Some features send data to third-party AI providers — for example, generating a draft exercise plan, transcribing the audio of a video into written instructions, or selecting still frames from a video for a printable plan.

Where content may identify a patient, the Platform asks you to declare two things before anything is sent: whether the patient is identifiable in that content, and whether you hold their consent for it to be processed. If you indicate the patient is identifiable and you do not hold consent, the content is not sent to any AI provider. It is stored and made available to that patient, and nothing is derived from it.

That declaration is recorded with the content, along with the exact wording you were shown when you made it. It is a formal statement by you, and we act on it. Obtaining the underlying consent from the patient remains your responsibility.

Automated output is a draft for your review, never a prescription. See section 3 of the Terms of Service.

5. How we protect it

This is our side of the arrangement:

  • Encryption in transit. All traffic between your browser, the patient app and our servers uses TLS.
  • Encryption at rest. Databases and stored files, including patient videos, are encrypted on disk.
  • Private storage. Patient media is held in private storage with public access blocked. It is reached only through short-lived links issued to the specific physiotherapist or patient entitled to it.
  • Separation. Content recorded for a patient is bound to that physiotherapist–patient pair, and is not visible to other physiotherapists or other patients.
  • Backups. Automated backups are taken regularly and retained so data can be restored after a failure.
  • Access control. Internal access is limited to the minimum personnel needed to operate and support the Platform.
  • Breach notification. If we become aware of a breach affecting your data, we will tell you without undue delay and share what we know, so you can meet your own obligations to your patients and to the authorities.

No system is perfectly secure. These measures reduce risk; they do not eliminate it, and they do not cover what happens to data after you or your staff have legitimate access to it — an exported PDF left on a shared computer is outside our control.

6. Who else sees the data

We share data only where it is needed to run the Platform:

  • Cloud infrastructure — hosting, storage, databases and backups.
  • Communications — SMS for one-time passcodes and reminders; video infrastructure for telehealth sessions.
  • Payments — our payment provider, for subscription billing.
  • AI providers — only as described in section 4, and only for content you have cleared for processing.
  • Legal — where we are required by law, court order, or a valid request from a public authority.

Data is primarily stored in India. Where a provider processes data outside India, we require appropriate contractual protections.

7. How long we keep it

Your account and practice data is kept while your account is active, and for a period afterwards to meet tax and legal obligations. Invoices are retained for the statutory period.

Patient records are kept while you use the Platform, so they remain available to you. Videos recorded for a patient are retained while relevant to that patient's care and for a defined period afterwards, then deleted.

You can delete a patient's video at any time, and the file itself is removed from storage — not merely hidden. Patients cannot delete content you recorded for them; they ask you, and you act on it. That is deliberate: the clinical record is yours to manage, and so is the obligation to honour a reasonable request.

Retention that your professional obligations require is your responsibility. If your regulator requires you to keep records for a set number of years, do not rely on the Platform alone — export and retain your own copies.

8. Rights

Your patients' rights are exercised through you. When a patient asks to access, correct, or erase their data, or withdraws consent, they will come to you, and you must respond. The Platform gives you the access and the tools to act on such a request. If you need our help to fulfil one, contact us and we will assist.

Your own rights in respect of your account data — access, correction, erasure, grievance redressal — can be exercised by writing to us at the address below.

9. Cookies

The portal uses only what is necessary to keep you logged in and to remember your preferences. This marketing site uses analytics to understand which pages are useful.

10. Changes

We may update this policy. Where changes are material we will notify you through the Platform or by email before they take effect.

11. Contact

Privacy questions, or help with a patient request: hello@moovv.fit.

Ryoshigo Technologies Private Limited
CIN: U72900PN2018PTC177785
Pune, Maharashtra, India

[Name and contact details of the Grievance Officer to be inserted. The DPDP Act requires a published point of contact for grievances; "hello@moovv.fit" alone does not satisfy it.]

Moovv for Physios. Grow your practice, keep patients moving.

Moovv

Product

Features Pricing Physio login

For patients

moovv.fit

Contact

hello@moovv.fit

Legal

Privacy Terms