Legal
Stride One — Device and App Privacy Notice
Last updated: 8 September 2026
This notice explains what the Stride One insoles and app record about you, what happens to it, and what control you have.
It is separate from the privacy policy for ceriter.com, which covers only what happens when you visit our website.
Please read this before you start using the device. The data described here says something about your health, so the law treats it as deserving extra protection — and so do we.
1. Who is responsible
Ceriter B.V. François de Veijestraat 8B, 6221 AB Maastricht, The Netherlands KVK 75191326 · info@ceriter.com
We are the controller for the data described in this notice. You buy Stride One from us, your account is with us, and we decide how the data is handled — within the limits this notice sets out.
If you choose to share your data with a clinician, they receive it because you decided to share it. From that point they decide for themselves how they use it in your care, as an independent controller, under the rules that govern their profession. We are not acting on their behalf, and they are not acting on ours. If you want to know how a clinician handles what you have shared, ask them; if you want to stop sharing, email support@ceriter.com and we will remove their access.
2. What the device records
From the insoles
- How load is distributed across the sensing zones of each foot, many times per second while you walk
- How weight is shared between your left and right foot, in force and in timing
- The quality of your step from heel contact through to push-off
- Steps taken, walking time, and periods of movement and rest
- Technical information from the device: battery level, firmware version, connection status, and error logs
From the app
- Your account details: name, email address, and the password you set
- Your size, and any details you give us when ordering or during setup
- Who you have chosen to share your data with
- How you use the app — which screens you open, and when data was last uploaded
What the device does not record
The insoles do not record where you are. There is no GPS, and we do not collect location data. They record how you walk, not where you walk.
3. Why this is health data
Data about how you load and move your feet says something about your physical condition. Under Article 9 of the GDPR that makes it data concerning health — a special category, which may only be processed on specific grounds.
Our ground is your explicit consent under Article 9(2)(a). You give it during setup by ticking a box confirming you have read this notice and agree to your health data being processed as it describes. That box is separate from the box for our terms and conditions — agreeing to one does not agree to the other, and neither is ticked for you in advance.
You can withdraw your consent at any time, and we explain how in section 7.
Where the data is processed as part of your treatment by a clinician, the clinician may rely on Article 9(2)(h) — processing for the purposes of medical diagnosis or the provision of health care — under the conditions their profession imposes.
4. What we do with it, and why
| What we do | Why | Legal basis |
|---|---|---|
| Turn sensor readings into your Stride One Score and the Balance, Roll and Footprint indices, and show them to you | So you can see how you are walking and how it changes | Article 6(1)(b) — performing our contract with you; Article 9(2)(a) — your explicit consent |
| Make your data available to a clinician or another person you have chosen | So the people supporting you can see the same record | Article 6(1)(b) and Article 9(2)(a) — your explicit consent, given per recipient |
| Keep the app and the device working, fix faults, and provide support | So the product works | Article 6(1)(b) and Article 6(1)(f) — our legitimate interest in a working, secure product |
| Improve how the product measures and presents movement, and support research into recovery and mobility | So the product gets better, and so that what we learn is useful beyond one person | Article 6(1)(f) — our legitimate interest in anonymising the data. Once anonymised it is no longer personal data, and data protection law no longer applies to it. See section 8. |
| Meet legal obligations that apply to us | Because we must | Article 6(1)(c) |
We do not use your data for advertising. We do not sell it. We do not share it with insurers, employers, or anyone else, unless you have told us to or the law requires it.
5. Who else sees it
People you choose. Your data is visible to a clinician or family member only if you have chosen to share it with them. You choose each recipient, and you can stop sharing with any of them at any time.
One limit worth understanding. Stopping sharing closes their access from that point on. It does not reach anything they have already downloaded, printed or saved — a report your clinician has put into your medical record is theirs, held under the rules that govern their profession, and we cannot delete it for you. If you want it removed, ask them.
Our service providers. A small number of companies process data on our instructions, under a written agreement, and may not use it for their own purposes.
| Provider | What they do | Where |
|---|---|---|
| Amazon Web Services | Hosts the Stride One platform and stores your data | European Union |
If you write to us about a fault or for support, your message reaches us by email at support@ceriter.com. We do not use any other tool that has access to your measurement data.
Nobody else, unless we are legally required to disclose — for example to a competent authority, or under a product safety obligation.
6. Where your data is stored
Your data is stored in the European Union. It is not transferred outside the European Economic Area.
Data is encrypted in transit and at rest.
7. Your control
See your data. It is in the app, and you can ask us for a copy of everything we hold.
Stop sharing. You can withdraw a clinician's or family member's access at any time. Email support@ceriter.com telling us whose access to remove, and we will do it.
Withdraw your consent. You can withdraw consent to the processing of your health data at any time, by writing to support@ceriter.com. When you do, we stop processing it and delete it, unless we are legally required to keep it. Withdrawing does not affect processing carried out before you withdrew, and it means the product will no longer work.
Correct or delete. Ask us and we will correct what is wrong or delete what we hold, subject to any legal retention obligation. We will also tell anyone we have shared your data with that you have asked for it to be deleted. We cannot make them delete copies they already hold — see section 5.
Take it with you. Ask and we will give you your data in a structured, commonly used, machine-readable format.
Object or restrict. Where we rely on legitimate interests, you may object on grounds relating to your particular situation. You may also ask us to restrict processing in the circumstances Article 18 GDPR sets out.
Write to support@ceriter.com. We respond within one month.
Complain. If you think we are handling your data unlawfully, you can complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or to the supervisory authority where you live. We would rather you came to us first.
8. How long we keep it
| What | How long |
|---|---|
| Your measurement data | Until one year after you tell us you have stopped using the device |
| Your account details | Until one year after you tell us you have stopped using the device |
| Support correspondence | Two years after the matter is closed |
| Records we must keep under product safety or tax law | For the period the law requires |
If you close your account or withdraw your consent, we delete your data rather than waiting for that year to pass.
Anonymised measurements kept for research
When we delete your data, we first remove everything that identifies you — your name, email address, postal address, account details and any free text you have written — and we destroy the code that linked those details to your measurements. Once that code is gone, nothing in our systems connects the measurements to you, and we cannot restore the connection.
We keep those anonymised measurements and use them to understand how feet load and move, to improve how the product measures and presents movement, and to support research into recovery and mobility.
How we make sure they stay anonymous. Alongside the measurements we keep a small amount of context, because without it the data tells us little: the type of procedure, and general details such as weight and shoe size. To make sure that context cannot be used to work out who someone is, we:
- record figures such as weight and age in bands rather than exact values;
- record time as the week of the recovery rather than as calendar dates, so nothing can be tied back to the date of an operation;
- keep no free text, and no details a person typed themselves.
Once data has been through this it is no longer personal data, so data protection law no longer applies to it and we may keep it indefinitely.
What this means for you. Anonymised measurements cannot be traced back to you. That also means they cannot be returned to you or deleted on request — there is nothing left that identifies which measurements were yours. Everything that still identifies you is deleted as set out in the table above, and your rights apply in full to that data for as long as we hold it.
9. Automated decisions
Stride One calculates scores and indices from your measurements, and shows them to you and to anyone you have shared them with. These are measurements presented to help you and your clinician think, not decisions made about you. We do not make any decision about you that is based solely on automated processing and that produces legal effects or similarly significantly affects you.
Your clinician may use the data in decisions about your care. Those are their decisions, made by a person.
10. Children
Where Stride One is used by someone under the age of 16, the consent described in section 3 must be given by a parent or guardian, who is also the person we deal with about that data.
11. Security
We protect your data with encryption in transit and at rest, access controls that limit who can see what, logging, and regular review. If there is ever a breach that is likely to put your rights at risk, we will tell you.
12. If you are in the United States
The rights described above come from European data protection law. If you are in the United States, that law does not apply to you directly — but we apply the same standards to everyone, so in practice you get the same protections. This section sets out what applies specifically to you.
We treat your gait data as consumer health data. Some US states — Washington and Nevada in particular — regulate consumer health data specifically, and they do so regardless of how large a company is. We collect and share your data only with your consent, obtained by the tick box described in section 3, and only with the people you have chosen.
We do not sell your data, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.
Your rights. You may ask us to confirm what we hold about you, give you a copy, correct it, or delete it, including any data shared with a third party. You may withdraw your consent at any time. We will not treat you differently for exercising any of these rights.
To exercise them, write to support@ceriter.com.
HIPAA does not apply to this data. HIPAA covers healthcare providers, health plans and their contractors. When you buy Stride One from us directly, we are none of those things, and the data you generate is not protected health information under HIPAA. It is your data, held by us under this notice. If your clinician adds it to your medical record, HIPAA governs their copy of it, not ours.
13. Changes
If we change how we handle your data, we will update this notice and — where the change requires it — ask for your consent again before making it.
14. Contact
Ceriter B.V., François de Veijestraat 8B, 6221 AB Maastricht, The Netherlands info@ceriter.com