We protect it like our physiotherapists protect their patient records.
Last updated: January 1, 2025 • GDPR Compliant • Norwegian Data Protection Authority Registered
We collect health data to provide physiotherapy services. We never sell your data. Video analysis happens in real-time and raw footage is never stored. Your data stays in Europe. You can delete everything anytime.
Why: To create safe, personalized rehabilitation programs
Important: We analyze movement data (skeletal points only). We do NOT store raw video footage of you or your home. Video is processed in real-time and immediately discarded.
Why: To track your progress and adapt your program
Why: To provide continuous, contextual guidance
256-bit encryption in transit and at rest. Bank-level security for all health data.
All data stored in EU data centers. No transfers outside Europe.
Only essential personnel with signed NDAs can access data for support.
Analytics data is anonymized. Personal identifiers are separated from health records.
To exercise any right, email: privacy@capable.health
We use trusted services to operate Capable. All have signed data processing agreements:
For processing health data and movement analysis (special category data under Article 9)
To provide the physiotherapy services you've subscribed to
For safety monitoring and service improvements (with opt-out available)
As long as you use Capable
30 days (for account recovery)
Indefinite (for research)
Video recordings: Never stored • Movement patterns: Until account deletion • Legal records: 5 years (Norwegian law)
We use minimal cookies for essential functions only:
No advertising cookies. No cross-site tracking. No profiling.
Email: support@capablehealth.ai
Response time: Within 72 hours
Capable Health Technologies AS
Organization number: [Your Org Number]
Oslo, Norway
Norwegian Data Protection Authority (Datatilsynet)
Website: datatilsynet.no