BioSked

Privacy Policy

BioSked websites, the Momentum web application, and the Momentum mobile app

Effective date: 25 June 2026 · Last updated: 25 June 2026

This Privacy Policy explains how BioSked (“BioSked”, “we”, “us”) collects, uses, shares and protects personal data when you visit our websites at biosked.com and biosked.fr, when you use the Momentum web application, and when you use the Momentum mobile app for iOS and Android (together, the “Services”).

Momentum is a workforce-scheduling tool for healthcare organizations. It helps staff view their schedules and manage their shifts. It is not a clinical system and is not used to process patients’ medical records.

1. Who is responsible for your data

The BioSked entity responsible for your personal data depends on where you are:

  • If you are in Europe or Switzerland: Bio-Optronics Sàrl, Nyon (1260), Switzerland.
  • If you are in the United States, Canada or elsewhere: BioSked Inc., Fairport, New York 14450, USA.

Our Data Protection Officer is Jean-Baptiste Cochery, who can be reached at dpo@biosked.com for both Europe and the United States.

When we provide Momentum to a healthcare organization (typically your employer or the organization that gave you access), that organization decides how your scheduling data is used: it is the data controller and the BioSked entity above acts as its processor under our customer agreement. In that case, your organization’s own privacy notice also applies and we handle that data on its documented instructions. For our websites, our marketing and our product analytics, BioSked is the controller.

2. The information we process

When you visit our websites

  • Technical data: your public IP address, connection logs (date and time of visit), browser and device type, and pages viewed.
  • Approximate location derived from your IP address (country/region).
  • Cookies and similar technologies (see “Cookies” below).
  • Form data: when you request a demo or contact us, the name, business and/or personal email, phone number, organization, job role and any message you provide.

When you use the Momentum applications (web and mobile)

Account & authentication — Your instance (site) identifier, username and password, which are stored securely; or, where your organization uses single sign-on, an authentication token issued by your organization’s Microsoft Entra ID. Sign-in tokens are stored in the device’s secure storage.

Scheduling & workforce data — Your name, role or specialty, work location, and (where your organization provides it) a contact number; your shifts and assignments, on-call and standby duties, time-off and absence requests, scheduling preferences (“wishes”), and related notes. This data is provided and controlled by your organization.

Notifications — If you enable notifications, a device push token (via Apple Push Notification service and Google Firebase Cloud Messaging) so we can deliver schedule notifications to your device.

Biometric unlock (mobile) — If you choose to enable it, your device’s Face ID, Touch ID or fingerprint is used to unlock the app. This check happens entirely on your device; we never receive, see or store your biometric data.

Voice and assistant input (mobile) — Where assistant features are enabled for your organization, the text you type and the audio you record (together with its transcription) are processed solely to carry out your request. We do not use your voice to identify you and we do not profile you from it.

Offline cache (mobile) — So that you can view your schedule without a connection, recent schedule and request data is stored in an encrypted database on your device and is removed when you sign out.

Product analytics & diagnostics — We use PostHog, hosted in the European Union, to understand how the applications are used and to detect and fix errors. This includes screen views, feature usage, app and device information (such as app version, operating system and device model), and crash/error reports, linked to a pseudonymous identifier — not your name. We do not use session recording or screen recording.

3. Why we process your data, and our legal bases

Where the GDPR, the Swiss Data Protection Act or equivalent law applies, we rely on the following legal bases:

Provide and operate the Services — Performance of a contract, and the legitimate interests of you and your organization in running the schedule.

Authenticate you and keep accounts and data secure — Performance of a contract, our legitimate interest in security and fraud prevention, and legal obligations.

Deliver schedule and operational notifications — Performance of a contract and our legitimate interest (you can disable notifications at any time).

Maintain, troubleshoot, secure and improve the Services (analytics and crash diagnostics) — Our legitimate interest in a reliable, high-quality product, using pseudonymous data.

Respond to demo, sales and support requests — Steps taken at your request prior to a contract, and our legitimate interest in responding.

Send marketing communications — Your consent, which you may withdraw at any time, or our legitimate interest for existing business contacts where permitted.

Comply with legal obligations and establish or defend legal claims — Compliance with a legal obligation and our legitimate interest.

4. Cookies and similar technologies

On our websites we use cookies and similar technologies in the following categories:

  • Necessary — required for the site to function and to keep it secure.
  • Functional — remember choices you make (such as language).
  • Preferences — store your settings to personalize your experience.
  • Statistics — help us understand how the site is used (audience measurement).
  • Marketing — measure and, where you consent, support our marketing.

Non-essential cookies are set only with your consent. You can give, refuse or withdraw consent at any time through the cookie banner on our website, and you can also control cookies through your browser settings. The Momentum mobile app does not use advertising cookies or third-party ad trackers.

5. What we do not do

  • We do not process patients’ health or medical records through Momentum. Momentum is a staff-scheduling tool, not a clinical or patient-data system.
  • We do not use the Services to monitor, surveil or profile employees’ behaviour, wellbeing or performance, and we do not perform burnout, emotion or health inference.
  • We do not sell or rent your personal data.
  • We do not use your data for third-party advertising or cross-context behavioural advertising.
  • We do not record your screen or your in-app activity for replay.

6. How we share your data

We share personal data only as needed to provide the Services and as described here:

Your organization and its authorized users — So that schedules, requests and related information can be managed.

Service providers — Acting on our instructions under written contracts: cloud hosting and infrastructure (including Google Cloud); Apple and Google for push-notification delivery and app distribution; PostHog for product analytics (hosted in the EU); Microsoft for single sign-on (within your organization’s own Microsoft tenant); our website hosting provider; and, where assistant features are enabled, our cloud and AI processing providers.

Professional advisers and auditors — Such as lawyers, accountants and security auditors, under confidentiality obligations.

Authorities and other parties — Where required by law, to comply with legal process, or to protect our rights, our users or the public.

Corporate transactions — In connection with a merger, acquisition, financing or reorganization, subject to appropriate confidentiality and safeguards.

We require our service providers to protect your data under written agreements. A current list of our service providers is available on request through the support form on our website.

7. Where your data is hosted, and international transfers

We host customer data regionally. For customers in Europe and Switzerland, Momentum data is hosted in Europe. For customers in the United States, Canada and the rest of the world, it is hosted in the United States. Our product analytics are hosted in the European Union.

Where personal data is accessed from another country — for example for technical support or by one of our service providers — we put appropriate safeguards in place, such as the European Commission’s Standard Contractual Clauses or a recognized adequacy decision.

8. How long we keep your data

Website connection logs — Up to 12 months.

Demo, sales and prospect data — For the duration of our relationship and up to 3 years thereafter for commercial prospection.

Momentum account and scheduling data — For as long as your organization maintains its account; we delete or return it on your organization’s instruction or at the end of the contract, subject to any legal retention requirements.

Product analytics and diagnostics — Retained for a limited period in pseudonymous form.

Mobile offline cache — Until you sign out of the app or remove the app from your device.

Support and rights requests — For the time needed to handle them and any applicable limitation periods.

9. How we protect your data

  • Encryption in transit using TLS for all connections to our Services.
  • Encryption at rest, including an SQLCipher-encrypted database for any schedule data cached on your mobile device.
  • Secure storage of sign-in credentials in the device keychain/keystore, with an optional biometric lock.
  • Access controls, least-privilege principles, logging and ongoing monitoring.

No method of transmission or storage is completely secure, but we work to protect your data and to address any incident appropriately.

10. Your rights

Depending on where you live, you may have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to data portability, and to withdraw consent at any time (without affecting prior processing).

To exercise your rights, use the support form on our website, or contact our Data Protection Officer at dpo@biosked.com. We may need to verify your identity. Where your personal data is controlled by your organization within Momentum, please address your request to your organization; we will assist it as its processor.

You may also lodge a complaint with your supervisory authority — in France, the CNIL (cnil.fr); in Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch); in Belgium, the Data Protection Authority (autoriteprotectiondonnees.be); or your local authority.

Account deletion

Momentum accounts are created and managed by your organization. To deactivate or delete an account, contact your organization’s Momentum administrator or use the support form on our website. You can remove the mobile app and the data stored on your device at any time by uninstalling the app.

United States and Canada

If you are a California resident, or a resident of another US state with privacy legislation, you may have the right to know about, access, delete and correct your personal information and to opt out of its “sale” or “sharing.” We do not sell your personal information and we do not share it for cross-context behavioural advertising, and we will not discriminate against you for exercising your rights. In Canada, you may access and correct your personal information and withdraw consent, subject to legal and contractual limits. To make a request, use the support form on our website or contact dpo@biosked.com.

11. Children

The Services are intended for healthcare professionals and other authorized adults and are not directed to children. We do not knowingly collect personal data from children.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new “last updated” date and, where required, notify you or your organization.

13. Contact us

For any question about this Privacy Policy or your personal data, use the support form on our website, or contact our Data Protection Officer, Jean-Baptiste Cochery, at dpo@biosked.com.