Privacy Policy

This policy explains what personal data Foot Camera handles, why, and on whose behalf — for practitioners who use the app, for the clinics and laboratories that hold accounts, and for the patients whose feet are scanned.

Last updated 26 July 2026

1. Who we are

Foot Camera is operated by Novansa OÜ, a company registered in Estonia under registry code 17445226, with its registered address at Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia. In this policy “we”, “us” and “our” mean Novansa OÜ.

Foot Camera consists of an iOS app used by clinicians to capture 3D scans of patients’ feet, a web application used by clinics and laboratories to manage orders, and the backend service that connects them.

For any privacy question, or to exercise your rights, contact us at privacy@foot.camera. We have not appointed a Data Protection Officer; privacy enquiries are handled by our management.

2. Two roles: controller and processor

We handle personal data in two distinct capacities, and it matters which one applies to you.

We are the controller

For the data we decide the purposes of ourselves: the accounts of the practitioners, clinic staff and laboratory staff who use the service, our correspondence with them, technical diagnostics, security logging, and visitors to this website. Section 5 sets out our legal bases for that processing.

We are a processor

For patient data — including the foot scans themselves — the clinic is the controller. The clinic decides which patients are scanned, what is recorded about them, which laboratory receives the order, and how long the record is kept. We process that data only on the clinic’s documented instructions, as set out in our data processing terms. A data processing agreement is available to account holders on request from privacy@foot.camera.

If you are a patient: the clinic that scanned your foot is responsible for your record and is the right first point of contact for access, correction or deletion. You may still contact us at privacy@foot.camera and we will assist the clinic in responding.

3. What data we handle

Account data (we are the controller)

  • Name and work email address.
  • Role within the service (practitioner, clinic staff or laboratory staff) and the clinic or laboratory the account belongs to.
  • Sign-in codes sent by email, session tokens, and the timestamps of account activity.
  • Any correspondence you send us — by email, or through the contact form on this website. The form collects your name, email address, optionally your clinic or laboratory, and your message; it is delivered to us as an email and is not stored in a database.

Patient and order data (we are a processor)

  • Patient identity and contact details entered by the clinic: first and last name, date of birth and sex where recorded, phone number, email address, and the clinic’s own patient reference.
  • Order details: which feet are being scanned, the ordering practitioner, the selected laboratory, order dates and status, and any clinical notes the practitioner adds to the order.

Scan data (we are a processor)

  • The 3D geometry of the foot — roughly 100,000 measured surface points, expressed in metres — together with the colour of the foot surface, which includes any marks a clinician has drawn on the skin.
  • A rendered image of the finished 3D model, used as a quick reference by the laboratory.
  • Scan measurements: which foot, capture duration, point count, working distance and bounding dimensions.
The app uses the front TrueDepth camera as a depth sensor. It does not access Face ID, and it does not store photographs or video of the patient. The colour camera feed is used only to colour the 3D model of the foot and is discarded otherwise.

Technical and diagnostic data (we are the controller)

  • A diagnostic record saved with each scan: device model, operating system build, app version, capture settings in force, frame and tracking counts, timings and thermal state. It contains no patient identifiers.
  • Crash reports and performance traces from the app and web application, generated when something goes wrong. These are intended to contain technical information only.
  • Server access logs from our hosting, which include IP addresses and request metadata, kept for security and troubleshooting.

This website

This website sets no advertising or analytics cookies and runs no tracking of any kind. If you choose a light or dark appearance, that preference is saved in your browser’s local storage on your own device; nothing is sent to us. Our hosting provider records standard server access logs.

4. Health data and special categories

A foot scan captured in a clinical setting is data concerning health under Article 9 of the GDPR. We process it solely as the clinic’s processor. The clinic is responsible for establishing the Article 9 condition it relies on — typically the provision of health care under Article 9(2)(h), or the patient’s explicit consent — and for informing the patient before the scan is taken.

The 3D geometry we capture is not used, and cannot be used by us, to identify a person by their physical characteristics. We therefore do not treat it as biometric data for the purpose of uniquely identifying a natural person within the meaning of Article 9(1).

6. Who we share data with

We use a small number of service providers to run Foot Camera. Each is bound by a data processing agreement and may use the data only to provide the service to us.

ProviderWhat it handlesWhere
Hetzner Online GmbHHosting for the backend service, the admin web application and the databaseGermany (EU)
Cloudflare, Inc.Object storage for scan files, and network delivery for our sitesEU-restricted storage jurisdiction
Postmark (ActiveCampaign, LLC)Delivery of transactional email — sign-in codes, and messages sent through this website’s contact form — being the recipient address and message content onlyUnited States
Functional Software, Inc. (Sentry)Crash reports and performance tracesEuropean Union region
Apple Inc.Distribution of the iOS app through the App Store and TestFlight. Apple receives no patient or scan data from usUnited States / global

Laboratories

The purpose of the service is to get a scan to the laboratory that will manufacture the orthotic. When a clinic sends an order, the selected laboratory receives the order details and scan files it needs to fulfil it. The clinic chooses which laboratory that is, and the link between a clinic and a laboratory is established by the clinic. The laboratory is an independent controller of the data it receives for that purpose.

Other disclosures

We may disclose data where we are legally required to, or to establish or defend legal claims. If our business is transferred, data may pass to the acquirer subject to this policy. We do not disclose data for advertising, and we never sell it.

7. International transfers

Foot Camera is built to keep clinical data in the European Union. The application, database and scan files are hosted in the EU, and crash reporting uses an EU-region service.

Two exceptions apply. Transactional email, which carries only a recipient address and the message itself, is delivered by a provider in the United States under the European Commission’s Standard Contractual Clauses. And if a clinic chooses a laboratory outside the EEA, the resulting transfer is one the clinic directs and is responsible for; we will act on that instruction.

8. How long we keep data

  • Patient and scan data is kept for as long as the clinic’s account is active, or until the clinic instructs us to delete it. On a documented deletion instruction we delete the records and the underlying files within 30 days, backups included in the normal backup rotation.
  • Account data is kept while the account is active and for up to 12 months after it is closed, so that access can be restored and questions answered.
  • Scan diagnostics are retained with the scan record; the technical fields may be kept in aggregate after the scan itself is deleted.
  • Crash reports and server logs are kept for up to 90 days.
  • Data we must keep for accounting or legal reasons is kept for the period the law requires.

Scans also exist temporarily on the capturing device until they have uploaded successfully, and are removed from the device thereafter.

9. Security

  • All traffic between the app, the web application and our servers is encrypted in transit (TLS).
  • Scan files and database contents are encrypted at rest by our hosting and storage providers.
  • Access is enforced by the backend, not just the interface: clinic accounts can reach only their own clinic’s patients and orders, and a laboratory can reach only the orders sent to it.
  • Sign-in uses a one-time code sent to a work email address — there are no shared passwords. On the device, session tokens are held in the iOS Keychain.
  • Administrative access to production systems is limited to the people who need it to operate the service.

No system is perfectly secure. If we become aware of a personal data breach affecting patient data, we will notify the affected clinics without undue delay so they can meet their own obligations, and we will notify the supervisory authority where the law requires it.

10. Your rights

Under the GDPR you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and to withdraw consent where processing rests on consent. Withdrawing consent does not affect processing already carried out.

To exercise these rights over an account with us, write to privacy@foot.camera. We respond within one month, and will tell you if we need longer. For a patient record, contact the clinic that holds it — we will pass on requests we receive and support the clinic in answering them.

You also have the right to complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), and you may instead complain to the authority in your own country of residence.

11. Children

Foot Camera is a professional tool and is not directed at children. Accounts are held by clinicians and by clinic and laboratory staff. A clinic may of course treat and scan a child patient; where it does, the clinic is responsible for consent and for informing the child’s parent or guardian under its own clinical framework.

12. Changes to this policy

We will update this policy as the service changes. The date at the top always reflects the current version. Where a change materially affects account holders, we will tell them by email or in the application before it takes effect.

13. Contact us

Novansa OÜ, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia. Registry code 17445226.

Privacy enquiries: privacy@foot.camera · General support: support@foot.camera

See also our Terms of Use.