GDPR, HDS hosting and data security

Nextmotion publishes a SaaS platform used by aesthetic medicine and surgery clinics to manage their patients, consultations and medical documents. As such, protecting the health data we host on behalf of our customers is at the heart of what we do.

This page details our commitments regarding GDPR compliance, hosting certified as a Health Data Host (HDS, the French health-data hosting certification), and technical and organizational security. It is primarily intended for Data Protection Officers (DPOs), clinic directors, healthcare lawyers and partners of practice companies who wish to understand our practices in detail.

This page supplements the Personal Data Protection Addendum attached to the General Terms and Conditions of Sale signed by each Subscriber, as well as the MCP compliance page (in French), which specifically details the framework of the MCP connector and the AI interoperability features.

Last updated : April 22, 2026

1. Legal qualification of the parties

As part of the Nextmotion services (clinic management platform, capture application, connectors), each client clinic acts as the data controller within the meaning of Article 4(7) of the GDPR, while Nextmotion SAS acts as a processor within the meaning of Article 4(8) of the GDPR.

This qualification is formalized by the Personal Data Protection Addendum (DPA) attached to the General Terms and Conditions of Sale signed upon subscription, in accordance with Article 28 of the GDPR.

2. HDS-certified hosting

Personal health data processed via the Nextmotion platform is hosted in accordance with Article L.1111-8 of the French Public Health Code and Decree No. 2018-137 of 26 February 2018 relating to the hosting of personal health data.

Infrastructure hosting provider

The data is hosted by Amazon Web Services (AWS), certified as a Health Data Host by the French Digital Health Agency (Agence du Numérique en Santé), in the Frankfurt (Germany) and Paris (France) datacenters.

The current status of AWS's HDS certification, including the scope of the activities covered and the version of the standard (v1.1 or v2.0), can be consulted on the official directory of the French Digital Health Agency: esante.gouv.fr/offres-services/hds/liste-des-herbergeurs-certifies

Nextmotion's HDS certification

Nextmotion SAS is itself certified as a Health Data Host for application outsourcing activities (activity 5 of the HDS standard). This certification covers the development, maintenance and administration of the Nextmotion platform containing health data.

The current status of Nextmotion's HDS certification, including the scope of the activities covered and the version of the standard, can be consulted on the official directory of the French Digital Health Agency: esante.gouv.fr/offres-services/hds/liste-des-herbergeurs-certifies

Transition to HDS version 2.0

The HDS version 2.0 standard, introduced by the French Digital Health Agency in 2024, strengthens the security and sovereignty requirements applicable to health data hosts. All certified hosts must have migrated to this new standard by 16 May 2026 at the latest.

Nextmotion SAS, together with its hosting providers, is engaged in this transition. The up-to-date status is available on the ANS directory mentioned above.

3. Technical and organizational measures

Nextmotion implements a set of technical and organizational measures in compliance with Article 32 of the GDPR and the requirements of the HDS standard.

Technical security

  • Encryption of data at rest
  • Encryption of communications in transit (TLS 1.2 minimum)
  • Strong user authentication
  • Granular access rights management
  • Logging and traceability of access to data
  • Regular and tested backups
  • Business continuity plan and disaster recovery plan

Organizational security

  • Regular training of teams on security and the GDPR
  • Confidentiality commitment from all employees
  • Security incident management procedure
  • Data breach notification procedure
  • Regular internal and external audits

Governance

  • Appointment of a Data Protection Officer
  • Maintenance of a record of processing activities
  • Data protection impact assessments (DPIA) for high-risk processing
  • Periodic review of sub-processors

4. Interoperability with artificial intelligence

Nextmotion offers features that allow the platform to be connected to third-party artificial intelligence assistants, in particular via the MCP connector (Model Context Protocol) and the orchestration nodes published for n8n.

Using these features with patient data requires a specific configuration on the client clinic's side: subscription to a Claude Team or Enterprise plan, or equivalent, signing of a Data Processing Addendum (DPA) with the chosen AI provider, activation of data residency in the European Union, and updating of the GDPR record and impact assessment (DPIA).

These requirements are detailed on Nextmotion's MCP compliance page (in French), as well as in Article 11.5 of the General Terms and Conditions of Sale.

5. Data breach notification

In accordance with Article 33 of the GDPR, Nextmotion undertakes to notify each affected client clinic of any personal data breach within a maximum of 24 hours of its discovery, with the information necessary for the CNIL notification within 72 hours that is incumbent on the data controller.

Data breaches are also notified to the French Digital Health Agency where the HDS standard requires it.

Incident contact: dpo@nextmotion.net

6. International data transfers

The health data processed via the Nextmotion platform is hosted exclusively within the European Union (AWS Frankfurt and Paris datacenters).

Some of Nextmotion's sub-processors may process data from countries outside the European Union. In such cases, Nextmotion frames these transfers by signing Standard Contractual Clauses approved by the European Commission, in accordance with Article 46 of the GDPR, and applies additional safeguards where required.

The list of sub-processors and associated safeguards is set out in the Personal Data Protection Addendum attached to the GTCS. It is also available on signed request at dpo@nextmotion.net.

7. Rights of data subjects

The patients of clinics using Nextmotion have all the rights provided for by the GDPR (access, rectification, erasure, restriction, objection, portability).

The client clinic, in its capacity as data controller, is the patient's main point of contact for the exercise of these rights. Nextmotion, in its capacity as processor, provides technical assistance to the clinic in responding to requests, in accordance with Article 28.3(e) of the GDPR.

If a patient contacts Nextmotion directly, their request is forwarded to the responsible clinic without delay.

8. Audit and documentation

Nextmotion makes the following documents available to customers who request them, under a confidentiality agreement:

  • Information systems security policy
  • HDS certification report (AWS and Nextmotion)
  • List of sub-processors
  • Incident management procedures
  • Impact assessment (DPIA) template
  • Data Processing Addendum (DPA)

Requests are sent to: security@nextmotion.net or dpo@nextmotion.net

9. Contact and questions

Data Protection Officer
dpo@nextmotion.net

Security contact
security@nextmotion.net

Legal contact
legal@nextmotion.net

Postal address
Nextmotion SAS, DPO
8 avenue Dorian
75012 Paris, France

Competent supervisory authority
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 place de Fontenoy, 75007 Paris
Website: www.cnil.fr

This page reflects the commitments of Nextmotion SAS at the time of its publication. It does not constitute personalized legal advice for a specific clinic or DPO. For an analysis of your specific situation, consult your DPO or a lawyer specializing in digital and health law.

This English version is a translation provided for convenience. In the event of any discrepancy, the French version available on nextmotion.net prevails.