top of page
logo over dark.png

GD STRIDE Privacy Policy

Effective Date: 02/01/2026
Last Updated: 02/01/2026

GD Stride Ltd. (“GD STRIDE,” “Company,” “we,” “our,” or “us”) respects the privacy of users of our services and is committed to protecting the personal, health-related, biomechanical, and medical information that users may share with us or that may be generated through use of the GD STRIDE platform.

This Privacy Policy (“Policy”) describes how we collect, use, store, share, transfer, and protect information when you use the GD STRIDE mobile application, web platform, docking station, scanning system, insole system, clinician portal, related software, and any related services provided by GD STRIDE (collectively, the “Services”).

This Policy should be read together with our Terms of Use and/or End User License Agreement (“Terms”). If there is any inconsistency regarding privacy or the processing of personal data, this Privacy Policy shall prevail.

1. Your Consent

By accessing, connecting to, or using the Services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, processing, storage, and sharing of information as described in this Policy.

You are not legally required to provide us with personal or health-related information. However, if you choose not to provide certain information, some features of the Services may not be available or may not function properly.

If you use the Services on behalf of another person, including a patient, family member, or minor, you represent that you have the legal authority, permission, and consent required to provide that person’s information and to allow GD STRIDE to process such information in accordance with this Policy.

2. Types of Information We May Collect

2.1 Personal Information

Personal Information is information that identifies, relates to, describes, or could reasonably be linked to an individual.

This may include:

  • Full name

  • Email address

  • Phone number

  • Address

  • Username and password

  • Account details

  • Date of birth

  • Gender

  • User role, such as patient, clinician, administrator, technician, or caregiver

  • Clinic, healthcare provider, or organization details

  • Family member, caregiver, or patient connections

  • Communication details and support requests

2.2 Health, Medical, and Biomechanical Information

The Services may collect or process health-related, medical, and biomechanical information.

This may include:

  • Foot scans

  • Scan history

  • Foot images or related visual data

  • Pressure-distribution data

  • Gait-related data

  • Biomechanical data

  • Insole configuration data

  • Insole adjustment history

  • Treatment-support information

  • Information entered by clinicians

  • Notes, instructions, or messages related to treatment support

  • Wound-related images or observations, if applicable

  • Patient status, progress, or monitoring information

  • External health-related information uploaded or entered into the Services

  • Any other health-related information provided by users, clinicians, or healthcare providers

Some of this information may be considered sensitive personal data, health data, medical information, or protected health information under applicable privacy laws.

2.3 Device, Technical, and Usage Information

When you use the Services, we may automatically collect technical and usage information, including:

  • IP address

  • Device identifiers

  • Mobile device token

  • Bluetooth connection information

  • Docking station or insole device identifiers

  • App version

  • Device type

  • Operating system

  • Browser type and version

  • Screen resolution

  • Language settings

  • Geolocation, if enabled or required for the Services

  • Connection status

  • System logs

  • Error logs

  • Diagnostic logs

  • Clickstream and activity within the Services

  • Time and date stamps

  • Duration of use

  • Interaction with app features

2.4 Non-Personal, Aggregated, or De-Identified Information

We may collect, generate, or use non-personal, aggregated, anonymized, or de-identified information. This information does not identify a specific individual.

If non-personal information is linked to personal information, we will treat it as personal information for as long as such link exists.

3. How We Collect Information

3.1 Information Provided by Users

We may collect information when you:

  • Create or update an account

  • Use the mobile app

  • Use the clinician portal

  • Use the docking station or scanning system

  • Connect an insole or related device

  • Perform a scan

  • Upload or capture images

  • Submit health-related information

  • Communicate with a clinician or healthcare provider

  • Contact customer support

  • Participate in a pilot, study, demo, trial, or service program

  • Submit forms, requests, or feedback

3.2 Information Generated Through Use of the Services

The Services may generate or collect data during normal use, including scan data, insole data, pressure data, gait data, adjustment history, usage logs, and other information created through interaction with the GD STRIDE system.

3.3 Information Provided by Clinicians or Healthcare Providers

Clinicians, healthcare providers, clinics, or authorized administrators may enter, upload, review, or update information in the Services, including treatment-support information, patient notes, scan review data, insole configuration instructions, and other health-related information.

3.4 Information Collected Automatically

We may automatically collect device, technical, diagnostic, and usage information when you access or use the Services.

3.5 Information from Third-Party Systems

The Services may allow users, clinicians, or healthcare providers to upload or connect information from external systems, documents, devices, or medical records. GD STRIDE is not responsible for the accuracy or completeness of information provided from external sources.

4. Images, Scans, and Recording Consent

The Services may allow or require the capture, upload, storage, or transmission of images, scans, foot-related visual data, wound-related visual data, or other materials related to the use of the GD STRIDE system.

By using these features, you acknowledge and agree that such information may be collected, stored, processed, reviewed, and shared as described in this Policy, including with authorized clinicians or healthcare providers.

Unless expressly stated otherwise, GD STRIDE does not provide medical diagnosis or medical treatment. The Services are intended to support healthcare providers and users. Medical decisions remain the responsibility of qualified healthcare professionals.

5. Purposes and Legal Basis for Processing

We may collect, process, and use personal information based on one or more legal bases, including:

  • User consent

  • Performance of a contract

  • Provision and operation of the Services

  • Legitimate business interests

  • Compliance with legal or regulatory obligations

  • Healthcare-related purposes, where applicable

  • Protection of rights, safety, security, and legal interests

We may use information for the following purposes:

  • To provide, operate, maintain, and improve the Services

  • To create and manage user accounts

  • To connect the app, docking station, scanner, and insole system

  • To perform scans and process scan data

  • To store and display foot, insole, and biomechanical information

  • To enable clinicians to remotely monitor users

  • To allow clinicians to review scans and treatment-support information

  • To adjust or support adjustment of insole settings

  • To provide user guidance, notifications, and service updates

  • To provide technical support and customer service

  • To detect incorrect use of the Services and help correct such use

  • To analyze system performance, errors, and usability

  • To improve product functionality and develop new features

  • To conduct research and development using aggregated or de-identified data

  • To create statistical, analytical, or research data

  • To protect against fraud, misuse, unauthorized access, and security incidents

  • To comply with applicable laws, regulations, legal processes, and contractual obligations

  • To respond to or defend against legal claims

We do not sell personal information.

We do not use health-related personal information for advertising purposes.

6. Sharing Information with Third Parties

We do not sell personal information.

We may share or allow access to personal, health-related, medical, or biomechanical information only as necessary for the purposes described in this Policy.

6.1 Legal Compliance and Protection

We may disclose information where required or permitted by law, regulation, court order, subpoena, legal process, governmental request, or regulatory obligation.

We may also disclose information to protect the rights, property, safety, security, or legal interests of GD STRIDE, users, clinicians, healthcare providers, or the public.

6.2 Affiliated Companies

We may share information with our subsidiaries, affiliates, or related companies for the purposes described in this Policy.

If GD STRIDE undergoes a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate protection obligations.

6.3 Service Providers

We may share information with trusted service providers that help us operate, maintain, secure, support, and improve the Services.

These may include:

  • Cloud hosting providers

  • Database and server providers

  • Data storage providers

  • App infrastructure providers

  • Analytics providers

  • Crash reporting and error monitoring providers

  • Cybersecurity providers

  • Remote access or technical support providers

  • Email and SMS communication providers

  • Customer support providers

  • Payment processors, if applicable

  • Professional advisors, including legal, regulatory, financial, and business advisors

  • Software development and maintenance providers

Service providers are required to process information only for authorized purposes and subject to confidentiality and data-protection obligations.

6.4 Clinicians and Healthcare Providers

We may share or allow access to relevant information with clinicians, healthcare providers, clinics, care teams, or authorized medical professionals involved in the user’s care or monitoring.

This may include scan data, foot-related data, pressure-distribution data, gait data, insole settings, images, notes, treatment-support information, and other relevant information.

6.5 Third-Party Medical Professionals

If a clinician or healthcare provider determines that consultation with another medical professional is needed, information may be shared with such professional where permitted by applicable law and clinical practice.

6.6 Multi-Participant Sessions

If the Services allow multi-participant sessions, remote reviews, consultations, demonstrations, or clinical support sessions, information shared during such sessions may be visible to the authorized participants.

6.7 Non-Personal Information

We may use, share, transfer, or disclose non-personal, aggregated, anonymized, or de-identified information at our discretion, provided that such information does not identify an individual.

7. Storage, Transfer, and Retention

Information may be maintained, processed, and stored by GD STRIDE, its affiliates, and authorized service providers in Israel, the United States, the European Union, and other jurisdictions where we or our service providers operate.

The privacy and data-protection laws in these jurisdictions may differ from those in your country of residence. We take reasonable steps designed to protect information in accordance with this Policy and applicable law.

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including:

  • Providing the Services

  • Supporting clinical or treatment-related use

  • Maintaining user accounts

  • Complying with legal and regulatory obligations

  • Supporting product safety and quality

  • Resolving disputes

  • Enforcing agreements

  • Protecting against legal claims

  • Maintaining security and audit records

Health-related, scan, insole, and biomechanical information may be retained for as long as necessary to support healthcare-related use, clinical documentation, regulatory requirements, product safety, research, or legal obligations.

When information is no longer needed, we will delete, anonymize, de-identify, or securely archive it, unless continued retention is required or permitted by law.

8. Updating, Accessing, or Deleting Personal Information

Depending on applicable law, users may have the right to:

  • Request access to personal information

  • Request correction of inaccurate or incomplete information

  • Request deletion of personal information

  • Request restriction or suspension of processing

  • Object to certain processing

  • Withdraw consent, where processing is based on consent

  • Request a copy of personal information in a structured, commonly used, machine-readable format

  • Request information about how personal information is processed

To exercise these rights, users may contact GD STRIDE using the contact details below or, where applicable, contact the healthcare provider, clinic, or organization that provided access to the Services.

We may ask for additional information to verify your identity before processing a request.

Some requests may be limited or denied where retention or processing is required or permitted by law, including for medical, regulatory, legal, security, product safety, archival, or legitimate business reasons.

9. Minors

The Services are not intended for independent use by individuals under the age of 18.

If a minor uses the Services, such use must be authorized and supervised by a parent, legal guardian, clinician, or healthcare provider, as applicable and as permitted by law.

If you provide information on behalf of a minor, you represent that you have the legal authority and required consent to do so.

If we become aware that personal information from a minor was collected without proper authorization, we will take reasonable steps to delete or restrict such information, unless retention is required or permitted by law.

10. Local Storage

The Services may use local storage, temporary cache, device storage, or similar technologies on the user’s mobile device, docking station, scanner, insole, or related hardware.

Local storage may be used to:

  • Enable proper operation of the Services

  • Support device connection

  • Temporarily store scan or device information before upload

  • Maintain session functionality

  • Improve user experience

  • Support offline or interrupted workflows

  • Preserve information until transmission is completed

Where information is stored temporarily before upload or synchronization, it may remain on the local device until the upload or synchronization process is completed.

Except where required for functionality, the Services are not intended to permanently store personal or health-related data locally on a user device unless clearly disclosed or technically required.

11. Direct Marketing

If you provide contact details separately for marketing purposes, we may use those details to send you information about GD STRIDE products, services, updates, events, offers, or news, where permitted by law.

We do not use protected health information or health-related personal data for marketing without appropriate legal basis or consent.

You may opt out of marketing communications at any time by following the unsubscribe instructions in the communication or by contacting us.

Service-related messages, security notices, account notifications, or important operational updates are not considered marketing and may still be sent where necessary.

12. Security

We take reasonable technical and organizational measures designed to protect personal information against unauthorized access, misuse, loss, disclosure, alteration, or destruction.

These measures may include:

  • Encryption

  • Secure transmission protocols

  • Access controls

  • Authentication

  • Role-based permissions

  • Audit logs

  • Network security

  • Monitoring

  • Backup procedures

  • Confidentiality obligations

  • Security policies and procedures

Access to personal information is limited to authorized personnel, clinicians, healthcare providers, service providers, and other parties who require access for legitimate purposes described in this Policy.

No system can be guaranteed to be completely secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.

Users are responsible for maintaining the confidentiality of their login credentials and for using reasonable security measures to protect their devices.

13. Third-Party Websites and Services

The Services may contain links to third-party websites, platforms, services, or resources.

GD STRIDE is not responsible for the privacy practices, content, terms, or security of third-party websites or services. Use of such third-party services is governed by their own privacy policies and terms.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

If we make material changes, we may provide notice through the Services, by email, or by other appropriate means.

Changes will become effective as of the date stated in the updated Policy, unless otherwise stated. Continued use of the Services after the updated Policy becomes effective means that you acknowledge the updated Policy.

15. HIPAA and Healthcare Privacy

Where applicable, GD STRIDE’s privacy practices are intended to comply with obligations that may apply to us as a service provider or Business Associate of a healthcare provider under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and related regulations.

Where GD STRIDE acts as a Business Associate, we will handle protected health information in accordance with applicable Business Associate Agreements and HIPAA requirements.

Users should also review the Notice of Privacy Practices of their healthcare provider, clinic, or healthcare organization, which describes how that provider may use and disclose health information.

16. Notice of Electronic Disclosure

Where applicable, health-related information, medical information, scan data, biomechanical data, images, insole data, or protected health information may be stored, processed, transmitted, displayed, or disclosed electronically.

Electronic disclosure may occur for purposes such as treatment support, healthcare operations, technical support, system operation, security, regulatory compliance, or as otherwise permitted or required by applicable law.

Where separate authorization is required by law for certain electronic disclosures, GD STRIDE or the relevant healthcare provider will seek such authorization.

17. General Information and Governing Law

Depending on the user’s location, this Policy and any related claims may be governed by applicable local privacy laws.

Unless otherwise required by applicable law:

If your primary residence is in Israel or in a territory not otherwise specified, this Policy shall be governed by the laws of the State of Israel, and the competent courts of Tel Aviv, Israel shall have exclusive jurisdiction.

If your primary residence is in the United States, applicable U.S. federal and state privacy laws may apply.

If your primary residence is in the European Economic Area, the United Kingdom, or Switzerland, applicable data-protection laws may provide additional rights and protections.

This Policy was written in English and may be translated into other languages for convenience. If a translated version conflicts with the English version, the English version will prevail, unless prohibited by applicable law.

18. Data Protection Officer, Local Representative, and Contact Information

If you have questions, requests, or concerns regarding this Privacy Policy or the processing of personal information, you may contact us at:

GD Stride Ltd.
Email: info@gdstride.ai
Phone / WhatsApp: +972 50 205 2779
Address: Biet Haarava, Israel

Please do not send sensitive medical information through general customer support channels unless specifically instructed to do so through a secure and authorized channel. Medical information should be shared with clinicians or healthcare providers through the designated secure features of the Services.

bottom of page