Privacy, Security & Data Handling
Moveo One is built so that analytics improve user experience without compromising user trust. This page summarizes how we handle data and what controls you have as a developer.
The authoritative, always-current versions live on our website:
Moveo One is operated by Divs Neuroinformatics d.o.o. For any privacy, security, or data-protection request, contact support@moveo.one.
Privacy-first by designDirect link to Privacy-first by design
- Only the minimum data needed to generate insights is collected.
- Moveo One does not collect personally identifiable information unless explicitly required.
- Your data is never sold, and is not used for marketing or unrelated commercial activities.
- The SDKs are open source (GitHub), so you can audit exactly what is captured.
What Moveo One collectsDirect link to What Moveo One collects
| Category | Examples | Purpose |
|---|---|---|
| Behavioral / app interaction | Clicks, taps, scrolls, screen views, navigation, usage and performance metrics | Understanding flow, engagement, and friction |
| Session metadata | Duration, device/locale context | Aggregation and segmentation |
| Predictive signals | Model scores, dwell time, hesitation | Real-time UX insights |
| User-provided details | Email address, configuration settings | Account and service operation |
| Custom properties (optional) | e.g. plan type, experiment ID | Developer-defined attributes for analysis |
What Moveo One does not collectDirect link to what-moveo-one-does-not-collect
- ❌ No raw keystrokes
- ❌ No screenshots or visual screen capture of your users
- ❌ No personal identifiers unless you explicitly provide them
SecurityDirect link to Security
- Encryption — TLS 1.2+ in transit, AES-256 at rest. Secrets and keys are managed with strict rotation policies.
- Access control — Role-based access control across internal systems; MFA enforced for every team member with production access.
- Internal policy — Documented security policy covering access, incident response, vendor review, backups, and employee onboarding/offboarding.
Data residency & deploymentDirect link to Data residency & deployment
Your data stays in the region you choose:
| Region | Availability |
|---|---|
| EU-resident infrastructure | Available |
| US-resident infrastructure | Available |
Deployment options:
- Managed multi-tenant cloud (default)
- Dedicated single-tenant environment
- Fully on-premise, in the customer's own cloud (enterprise)
Compliance statusDirect link to Compliance status
We are transparent about what is in place today versus in progress:
| Standard | Status |
|---|---|
| GDPR | Aligned today — DPA available on request; data export and deletion supported; formal DPIA documentation in progress |
| SOC 2 Type II | In preparation — audit targeted later in 2026 |
| ISO 27001 | In preparation — certification targeted in 2027 |
| HIPAA | On roadmap — BAA and configuration under evaluation |
Available on request (enterprise): security questionnaire (CAIQ-Lite / SIG-Lite), DPA, architecture overview, roadmap timeline, and control-review calls.
Data ownership, retention & deletionDirect link to Data ownership, retention & deletion
- You own your data. Moveo One acts as a data processor, not a data controller.
- Retention — data is kept only as long as necessary. On account termination, your data is deleted within 30 days, unless retention is required by law.
- Your rights — you can request access, correction, deletion, or portability of your data at any time by emailing support@moveo.one.
Self-serve data export and deletion via the dashboard/API are on our roadmap. Until then, email us and we'll process the request.
CookiesDirect link to Cookies
Moveo One uses only essential cookies necessary for the functioning of its services. No marketing or cross-site tracking cookies are used.
Developer privacy controlsDirect link to Developer privacy controls
You decide what reaches Moveo One. Recommended practices:
- Hash or anonymize user IDs unless you genuinely need cross-session identity. Moveo One only needs a stable, unique value — not a raw ID. See hashing guides for Google Tag Manager and PostHog.
- Respect consent — only start a Moveo One session after the user has consented to analytics, and avoid starting one on sensitive screens (e.g. payment).
- Keep PII out of event names and property keys — never encode private data in custom properties.
- Disclose analytics usage in your product's privacy policy.
ContactDirect link to Contact
For compliance, security, or data-protection questions — including DPA requests — contact support@moveo.one.