Movari — Privacy Notice

Version: 2026-07-23 Effective date: 23 July 2026 Status: FINAL — reviewed and approved by qualified UK legal counsel and in force. Supersedes version 2026-06-01.


1. Who we are and what this notice covers

Movari is a practice-management platform for independent physiotherapists and small clinics. This Privacy Notice explains what personal data we handle, why, on what legal basis, how long we keep it, and who we share it with.

In this notice:

  • "Movari", "we", "us" means Movari Ltd, a company incorporated in England and Wales with company number 17196208 and registered office at 8 Greenwood Court, Greenwood Mount, Leeds, LS6 4LU. Movari Ltd is the legal entity responsible for the platform.
  • "the platform" or "the Service" means the Movari website, web application, and related services.
  • "you" means whoever is reading the relevant part of this notice — a website visitor, a Movari customer (a practitioner), or a patient of one of our customers. We say which group each section applies to.

We are registered with the UK Information Commissioner's Office (ICO) as a data controller for the data described in this notice for which we are the controller. [ICO registration number to be added once registered.]

This notice is written in plain English on purpose. Where the law uses specific terms ("controller", "processor", "lawful basis"), we use them too, but we explain what they mean.


2. The three groups of people whose data we handle

We deal with three different groups of people, and our role is different for each. This distinction matters because it decides who is legally responsible for the data.

GroupWho they areOur role
VisitorsPeople who browse our marketing website, fill in the contact form, or request an inviteController — we decide why and how this data is used
CustomersThe physiotherapists and clinics who hold a Movari accountController — we decide why and how this data is used
PatientsThe patients of our customers, whose clinical records live in the platformProcessor — the customer (the physio) is the controller; we only act on their instructions

What "controller" and "processor" mean. A controller decides why personal data is collected and what happens to it. A processor handles personal data on a controller's behalf and only does what the controller tells it to.

For patient data, the physiotherapist is the controller and Movari is the processor. We hold and protect patient clinical records, but we do not decide how they are used — the practitioner does, as part of providing care. Our obligations to the practitioner for patient data are set out in our Data Processing Agreement, not in this notice. If you are a patient and you want to exercise your rights over your record, your first point of contact is your physiotherapist (see section 8).

For visitor and customer data, Movari is the controller, and this notice governs how we use it.

A note on people who message a practitioner. Where a practitioner connects a messaging channel (WhatsApp, Instagram, or Facebook Messenger), the people who message them — existing patients, but also prospective patients and general enquirers — have their messages brought into the platform on the practitioner's behalf. For that data the practitioner is the controller and Movari is the processor, in the same way as for patient records. Section 5 explains how this messaging data is handled.


3. Visitor data — Movari is the controller

This section applies to people who visit our website or get in touch before becoming a customer.

What we collect

  • Marketing-site analytics. Aggregate, cookieless usage data (pages viewed, approximate region, device type, referring site). This is collected by Vercel Web Analytics and does not identify you individually or use cookies (see section 9).
  • Contact form. Your name, email address, and the message you send us.
  • Invite-request form. Your name, email address, practice details, and anything else you choose to tell us when asking for access.

Why we use it, and our lawful basis

PurposeLawful basis (UK GDPR Article 6)
Understanding how the website is used and improving itLegitimate interests (Art. 6(1)(f)) — running and improving our website. Because the analytics are aggregate and cookieless, the impact on you is minimal.
Replying to a contact-form enquiryLegitimate interests (Art. 6(1)(f)) — responding to someone who has chosen to contact us; or steps prior to entering a contract (Art. 6(1)(b)) where you are asking about signing up.
Processing an invite request and following upSteps prior to entering a contract (Art. 6(1)(b)) — acting on your request to join.

How long we keep it

  • Analytics: retained in aggregate by our analytics provider; it is not tied to a named individual.
  • Contact-form and invite-request messages: kept for up to 24 months from your last contact, then deleted, unless you become a customer (in which case the relevant details move into your customer record) or we need to keep them longer to deal with a legal claim.

4. Customer data — Movari is the controller

This section applies to our customers: the practitioners and clinics who hold a Movari account. We are the controller for this data because we decide how to run the accounts, billing, and security of our own platform.

What we collect

  • Profile data. Name, professional registration number, practice name, contact details, and account settings.
  • Authentication data. Email address, password (stored only as a secure hash), and multi-factor authentication (MFA) metadata — for example which type of second factor is enrolled. We never store the underlying MFA secret in a readable form.
  • Payment and subscription data. Subscription status, plan, billing history, and the limited payment metadata our payment provider returns to us (for example the card brand and last four digits, and renewal dates). We never see or store full card numbers — these go directly to Stripe (see section 7).
  • Audit log. An append-only record of significant actions taken in your account (for example creating a patient, locking a clinical note, sending an invoice, enrolling or removing MFA), kept for security and accountability.

Why we use it, and our lawful basis

PurposeLawful basis (UK GDPR Article 6)
Creating and running your account; providing the ServiceContract (Art. 6(1)(b)) — performing our agreement with you.
Authenticating you and securing your account (including mandatory MFA)Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) — keeping accounts and the medical data they hold secure.
Taking subscription payments and keeping billing recordsContract (Art. 6(1)(b)) for taking payment; legal obligation (Art. 6(1)(c)) for keeping accounting records.
Keeping an audit log of significant actionsLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) — accountability and security.
Sending service and security emails (e.g. password resets, security notices)Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)).

How long we keep it

  • Profile and authentication data: for as long as your account is open. After account closure, it is deleted at the end of the 30-day holding period described in section 6.
  • Subscription and billing records: retained for 6 years after the end of the relevant financial year, to meet UK accounting and tax record-keeping requirements, even after your account is closed.
  • Audit log: retained for the life of the account; deleted with the rest of the account at the end of the 30-day holding period (subject to any record we must keep to deal with a legal claim or regulatory obligation).

5. Patient data — Movari is the processor

This section explains how we handle patient data so that everyone can see what we do. For this data the physiotherapist is the controller and Movari is the processor. We do not use patient data for our own purposes. We only store, protect, and process it on the practitioner's instructions, under our Data Processing Agreement.

What is held in the platform

On behalf of the practitioner, the platform holds:

  • Clinical records — SOAP notes (subjective, objective, assessment, plan), diagnoses, outcome-measure scores, and clinical files such as scans and photographs.
  • Appointments — dates, times, session types, and attendance history.
  • Exercise plans — rehabilitation plans and the patient's "mark as done" adherence log.
  • Magic-link access — the tokens and session cookie that let a patient open their own current plan, read-only, without an account.
  • Payment receipts — records of charges and payments for sessions in the billing ledger.
  • Voicemail recordings and transcripts — where the practitioner uses the call-management feature, the recording of an inbound voicemail, its transcript, and a short structured summary.

Because clinical records include health data, they are special-category data under Article 9 of the UK GDPR and receive extra protection.

Lawful basis

The practitioner, as controller, is responsible for the lawful basis for processing their patients' data. In practice this is typically:

  • Article 6(1)(b)/(f) — performing the care relationship and the practitioner's legitimate interest in running their practice; and
  • Article 9(2)(h) — provision of health or social care and the management of health-care systems and services, which is the special-category condition that allows health professionals to process health data for treatment.

Movari processes this data only to provide the Service to the practitioner — our basis as processor flows from our contract with the practitioner, not from a direct relationship with the patient.

How long it is kept

  • Clinical records: a minimum of 8 years. UK practice is to retain adult clinical records for at least 8 years from the date of last treatment (and longer for children — typically until the patient's 25th or 26th birthday). This retention duty sits with the practitioner as controller; the platform is built to retain records for as long as the practitioner keeps an active subscription, and the practitioner can export the full record at any time. The platform is not a long-term archive after an account closes (see section 6). See docs/workflows/clinical-notes.md for how the clinical record is locked and preserved.
  • Voicemail recordings and transcripts: kept while the account is active so the practitioner can review and action them, and purged at account closure as part of the deletion described in section 6.
  • All other patient data: retained while the practitioner's account is active and deleted at the end of the 30-day holding period on account closure, unless the practitioner has exported and migrated it elsewhere to meet their own retention duty.

Messaging and inbox data (where the practitioner connects a messaging channel)

Where a practitioner connects WhatsApp, Instagram, or Facebook Messenger, the platform brings the conversations from those channels into a single inbox next to the clinical record, so the practitioner can read and reply within Movari. For this data the practitioner is the controller and Movari is the processor, exactly as for clinical records — we hold and protect it and act on the practitioner's instructions.

Who this affects. The people who message a practitioner on a connected channel include existing patients, but also prospective patients and general enquirers ("leads") who are not — and may never become — patients.

What is held. The text of messages sent and received; a reference to any media a contact sends (we store only the messaging provider's media identifier and file type — never a copy of the media itself); the contact's channel identifier (such as a phone number or account handle) and the display name shown on the channel; and delivery/read status. Message content is not analysed by artificial intelligence.

How messages travel. Messages are sent and received over Meta's platforms (WhatsApp, Instagram, Messenger); Meta acts as a subprocessor for that transport (see section 7). The practitioner's access credential for their connected channel is stored encrypted and is only ever used to send and receive that practitioner's own messages.

How long it is kept — tiered:

  • Lead / prospective-patient conversations that are never linked to a patient and never saved into a clinical note are automatically deleted after 90 days of inactivity, so we do not hold cold enquiry data indefinitely.
  • Conversations linked to a patient follow the same retention as the rest of that patient's record.
  • Anything the practitioner saves into a clinical note becomes part of the clinical record and is retained on that basis; the underlying raw conversation still purges under whichever tier applies to it, because the clinical note is the copy that must survive.

Deletion of a single contact's data. Meta provides a "data deletion request" mechanism for a person to ask for their data to be removed. When Meta passes us such a request, we delete only that contact's conversations and messages — it is a targeted deletion of that one person's data, not a deletion of the practitioner's account or of any other contact's data.


6. Account closure, deletion, and the 30-day holding period

When a customer closes their Movari account:

  1. They are given a full export of their data first (a per-patient PDF of the clinical record plus a zip of attached files, and an aggregate workspace export on request), so they can meet their own retention obligations.
  2. All patients and rehabilitation plans are archived immediately, so patient magic-link access stops at once.
  3. A 30-day holding period runs. During this window the customer can re-open the account or download a fresh export.
  4. At the end of the 30 days, a scheduled job permanently deletes the account: first every stored file (including any voicemail recordings), then every database record owned by the customer, ending with the customer's own login. This deletion is irreversible.

Backups that contain deleted data are overwritten on our normal backup-rotation cycle and are not selectively edited; while they exist they remain encrypted and access-controlled. Billing and accounting records are retained separately for the 6-year period noted in section 4.


7. Who we share data with — our subprocessors

We do not sell personal data and we do not share it for advertising. We use a small number of carefully chosen service providers ("subprocessors") to run the platform. Each is bound by a written contract that requires them to protect the data to a standard no lower than our own, and to use it only to provide their service to us.

SubprocessorWhat they do for usData involvedLocation
SupabaseDatabase, authentication, and file storageAll customer and patient dataUK / EU region (eu-west-2, London)
VercelHosting and running the applicationData passing through the application at request timeApplication functions pinned to the lhr1 (London) region
Vercel AnalyticsFirst-party, cookieless visitor analyticsAggregate, non-identifying website usage (visitor data only)See section 9
StripeSubscription billing, and patient session payments via Stripe ConnectPayment and subscription data; full card details go to Stripe directly and never reach usUK / EU
ResendSending transactional email (magic links, password resets, security and service emails)Recipient email address and email contentsEU / US (under a UK transfer safeguard)
TelnyxTelephony for the call-management feature (inbound numbers, call recording)Caller phone number and voicemail audioUK number, EU/US processing (under a UK transfer safeguard)
Microsoft Azure (UK South)Voicemail call-management AI — speech-to-text (Azure AI Speech) and the short structured summary (Azure OpenAI)Voicemail audio and the resulting transcript and summaryUnited Kingdom (uksouth) — processed and stored in the UK; not used to train models
Meta (WhatsApp, Instagram, Messenger)Sending and receiving messages on the channels a practitioner chooses to connect (via the Meta Graph API)The contact's channel identifier and display name, message content, and media references — only for practitioners who connect a messaging channelMeta platform infrastructure, under a UK transfer safeguard; Meta assets are configured for UK/EU processing where Meta offers it
PhysiaXWhite-label exercise-content provider; patients fetch exercise videos and media from its CDNMedia is fetched from cdn.physiax.com; PhysiaX does not receive patient clinical dataCDN delivery

Microsoft Azure AI is used only for the voicemail call-management feature — it never touches clinical notes, appointments, plans, billing data, or messages (message content is not AI-processed), and voicemail transcription and summarisation are processed in the United Kingdom. If a practitioner does not use call management, no voicemail data is created and this processing does not happen.

International transfers

We store data in the UK and EEA wherever practicable; the primary data store is hosted in a UK region. Where a subprocessor processes data outside the UK in a country without a UK "adequacy" decision, we put an appropriate safeguard in place — typically the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum.

We give customers advance notice before we add or change a subprocessor, as set out in the Data Processing Agreement, and a current list is available on request.


8. Your rights

Under UK data-protection law you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have data deleted ("the right to be forgotten"), where the law allows.
  • Restriction — ask us to limit how we use your data.
  • Portability — receive certain data in a structured, machine-readable format, or have it sent to another provider.
  • Objection — object to processing based on our legitimate interests.

If you are a visitor or a customer, contact us using the details in section 10 and we will respond.

If you are a patient, your record is controlled by your physiotherapist, so please contact your physiotherapist first — they hold the keys to your record and can export, correct, or act on it directly. If you contact us, we will direct you to them, and we will help your physiotherapist respond.

We will respond to a Subject Access Request within 30 days (the period set by Article 12(3) of the UK GDPR). The platform gives practitioners a one-tap per-patient export so they can meet the same deadline for their patients.

You also have the right to complain to the ICO (ico.org.uk) if you are unhappy with how your data has been handled — though we would always prefer the chance to put things right first.


9. Cookies and tracking

We keep tracking to the absolute minimum.

  • Website analytics are cookieless. We use Vercel Web Analytics, which is first-party and does not set cookies or build a cross-site profile of you. Because there are no tracking cookies, our marketing site does not need a cookie consent banner.
  • The application uses cookies only to keep you signed in. When a practitioner logs in, or a patient opens their plan via a magic link, we set a strictly necessary session cookie so the platform knows it is still you. These are essential to the Service and are not used for tracking or advertising.
  • No third-party trackers. We do not use marketing or advertising cookies, social-media pixels, or third-party analytics that profile you across sites.
  • We do not sell your data, and we do not share it for advertising.

10. Contact us

For any privacy question, or to exercise your rights, contact:

privacy@movariapp.com

Mail reaches the Movari founder directly. If you would prefer to write to us, use the registered office address in section 1.

If you are a patient asking about your own clinical record, please contact your physiotherapist first, as explained in section 8.


11. Changes to this notice

If we change this notice, we will publish a new dated version. The version and effective date are shown at the top. Material changes that affect customers will be notified in line with our Terms of Service.


End of Privacy Notice, version 2026-07-23.