Privay Policy

Last revised 6/15/24

1. Introduction

At Biosum, we take your privacy seriously. This Privacy Policy explains how we collect, use, and safeguard your data on biosum.com and my.biosum.com, both owned and operated by Biosum LLC.
This Privacy Notice explains how we handle personal data across our website, digital platforms, mobile applications, social media channels (collectively, “Site”), and through our services, including body composition scans, nutrition consultations, metabolic tests, and other offerings (collectively, “Services”).

Reasons for Data Collection

We collect and store your data for the following purposes:

  • To provide, analyze, and improve our services.
  • To comply with laws and regulations, including those related to marketing and advertising.
  • To ensure the security and safety of our company, employees, customers, and others.

We will never sell, share, lease, or rent your individual-level information (such as health, personal contact, or other characteristics) to any third party without your explicit consent. We respect the sensitive nature of your information and strive to be transparent about our practices. We will always seek your explicit consent before sharing sensitive information with third parties.

By using our Site or Services, you agree to the terms described in this Notice.

2. Data Collection

Information You Provide Directly to Us

  • Contact Information: This includes your name, email address, postal address, and phone number, used for account creation, service delivery, and correspondence.
  • Health Data: We gather health assessments, fitness test outcomes, medical histories, and related data to tailor our services to your unique health and wellness goals.
  • Demographic and Lifestyle Details: Insights into your ethnicity, lifestyle preferences, and demographic characteristics help us fine-tune our services to better align with your needs.

Information Collected During Services

  • Biological Data: Testing devices, such as DEXA scans or metabolic tests, collect information related to your body composition and breath metrics. This data is stored on our secure, HIPAA-compliant systems to enable tracking changes over time.

Information Collected Through Technology Providers

  • Information Collected by Our Servers: Our servers (which may be hosted by a third-party service provider) collect information such as your browser type, operating system, IP address, domain name, and date/time stamp for your visit. We do not use your sensitive information for targeted advertising.
  • Log Files: We automatically gather information such as IP addresses, browser type, Internet Service Provider (ISP), referring/exit pages, operating system, date/time stamp, data typed into the site, and clickstream data.
  • Mobile Services: If you access the Site from a mobile device, we may collect non-personal data such as your geographic location and device type to deliver the most relevant information.
  • Analytics Services: Third-party analytics services, such as Google Analytics, may set their own cookies or similar tools to help analyze how users use the Site. These services provide us with reports on user activity, which we use to improve the Site. These services are governed by their respective terms of use and privacy policies.
  • Log In Providers. You may use certain social media site (“SNS”) credentials to log into the Site. In such case, we collect personal data from the social media website. For example, when you log in with your Google credentials, we may collect the personal data you have made publicly available in Google, such as your email address, name, and profile picture or logo, phone number and gender if available. You agree that you are solely responsible for your use of an SNS and that it is your responsibility to review the terms of use and privacy policy of such SNS. Any information that we collect from an SNS account will depend on the privacy settings you have with that SNS, so please consult the SNS’ privacy and data practices. We will not be responsible or liable for: (a) the availability or accuracy of such SNS; (b) the content, products or services on or availability of such SNS; or (c) your use of any such SNS. You can revoke our access to this information anytime by amending the appropriate settings from within your account settings on the applicable SNS.
  • Cookies: We use cookies to collect information. Cookies are small pieces of information that a website sends to your computer’s hard drive. We use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer until you delete them).
  • Pixels: We use pixel tags (web beacons and clear GIFs) to track user actions on the Site. These tags help us measure the success of marketing campaigns and compile usage statistics. The information collected through pixel tags is generally not linked to personal data, except for the Facebook Pixel, which may gather information about your activities on the Site for tailored ads as per Facebook’s Privacy Policy. https://www.facebook.com/policy.php
  • Facebook Pixel:The Facebook pixel gathers information about your activities on the Site to provide tailored ads. Facebook’s use of this information is governed by its Privacy Policy. https://www.facebook.com/policy.php

3. How We Use Your Data

We're committed to using information responsibly to enhance your experience and improve our services.

We utilize your personal information to fulfill your requests for services, manage your account, handle transactions, and respond to your inquiries. Specifically, your information may be used as follows:

Google User Data

Your contact and profile data, including name, profile photo, email address, gender and phone number when available as obtained through the use of Google or other social media login provider services SNS will be used to facilitate login and access to our Site and and provide acess to our services as described in this privacy policy.

Service Delivery

Host our website, authenticate your visits, provide personalized content and information, and track your usage of our Site and Services.

Processing and Delivery

Process and deliver your results, nutrition consultations, and other offered services.

Communication

Reach out to you regarding service administration, updates on services, and send account notifications (including alerts for expiration and renewal).

Security and Compliance

Process your data to protect user interests, ensure operational integrity, and comply with legal obligations.

Support

Link your personal information with your data to efficiently address and resolve support tickets or technical assistance requests.

Use of Anonymized Information

We use anonymous information to:

  • Enhance our services.
  • Drive innovation.
  • Improve platform features.
  • Conduct research and development.
  • Gain marketing insights.

Additionally, we may use collected data to customize advertisements, potentially shaping the content you see according to advertiser targeting.

Data Retention

We retain your personal information only for the duration necessary to achieve the outlined purposes, fulfill our legal obligations, resolve disputes, and fulfill our commitment to you. The retention period varies based on the nature of the information:

Account Information

Maintained for the duration of your account's lifespan and a reasonable period thereafter for backup, archival, and/or audit purposes.

Health and Service-Related Information: Retained according to legal, regulatory, and professional standards governing health data and service provision.

Transactional Data: Stored for the duration necessary to meet contractual obligations and in compliance with relevant tax and accounting laws.

Upon the expiration of retention periods, your data will be securely deleted or anonymized.

4. Electronic Communication

When you provide us with your contact details, you consent to receive electronic communications from us, including emails and text messages. These communications may include promotional messages, updates about our products or services, transactional information, and other relevant content.

Consent to Receive Communications

By providing your contact information or using our services, you agree to receive electronic communications from us. You understand and agree that these communications may be sent automatically and that your consent is not a condition of using our services.

Opting Out

If you wish to stop receiving promotional emails or other non-essential communications from us, you can opt out by following the unsubscribe instructions provided in the email or text message. You may also contact us directly at privacy@biosum.com. Please note that you may still receive transactional or essential communications related to your account or our services even if you opt out of promotional communications.

Security of Communications

While we take reasonable measures to ensure the security and confidentiality of electronic communications sent from our end, please be aware that no method of electronic transmission or storage is entirely secure. We cannot guarantee the absolute security of your communications, and you acknowledge and accept this inherent risk.

Third-Party Communication

We may use third-party services to facilitate our electronic communications, such as email marketing platforms or messaging services. These third parties may have access to your contact information to deliver communications on our behalf, but they are obligated not to use it for any other purpose.

5. Sharing Your Information

We strongly oppose the sharing of information. We will not share or sell your personal information to third parties for marketing or any other purpose except as provided in this privacy policy.

Legal and Regulatory Compliance

We may need to disclose your information in response to legal processes, government requests, or public health mandates to protect our rights and safety and ensure compliance with regulations.

Medical Authorizations

Your health and contact information will be shared with our Physician to perform assessment and consultations for services as required by public health regulations for the provision of our services to you.

Website Tracking and Third-Party Integrations

Our website uses cookies and similar technologies for various purposes. Interactions with third-party platforms linked to our website are subject to their privacy policies.

We use Stripe, a third-party payment processor, to process payments. In connection with such payments, we do not retain any personally identifiable information or any financial information such as credit card numbers. All such information is provided directly to Stripe, whose use of your personal data is governed by their privacy policy, which can be viewed at [Stripe Privacy Policy](https://stripe.com/us/privacy).

Corporate Events

If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be sold or transferred as part of such a transaction. We cannot control how such entities may use or disclose such information.

We respect your privacy preferences, including your right to limit certain uses of your information. If you wish to opt out of targeted advertising or other communications, please contact us at privacy@biosum.com.

6. Changing or Deleting Your Data

We are committed to maintaining the accuracy of your Personal Information. You can review and update certain details directly within your client area on our website. For assistance or modifications not available online, please contact us at support@biosum.com.

Deletion of Your Information

You have the right to request the deletion of your Information. While we strive to fulfill your request promptly, legal and regulatory obligations may necessitate retaining your information for a specified period. Your Personal Information will be removed from our active databases upon deletion, though it may persist in backups and archives for a limited period to support our internal processes.

Retention of Anonymized and Aggregate Information

Even after deleting your Personal Information, we may continue to use anonymized and aggregated data derived from your information for analytical, research, and operational purposes, in accordance with this Privacy Policy and relevant laws.

7. Protecting Your Information

We take the protection of your personal information seriously and adhere to strict guidelines for collecting, storing, and handling your data. Our measures include encryption and other security protocols to safeguard your information from unauthorized access, alterations, leaks, or deletion.

Limitations of Data Security

Despite employing advanced security measures, no online transmission or electronic storage method is completely secure. We strive to provide the best possible protection for your information.

Your Role in Protecting Your Information

You play a crucial role in safeguarding your information. Please exercise caution with your login credentials and promptly report any suspicious activity to us.

8. Your Rights

At Biosum, we respect your rights regarding your personal information and provide tools to manage and protect it.

  • Access and Copies: You have the right to request access to your Personal Information. To review or obtain a copy, please contact us using the details provided below. We may require identity verification before fulfilling your request.
  • Withdraw Consent: If our processing of your information relies on your consent, you can withdraw it at any time by contacting us.

9. Changes to Our Privacy Policy

Biosum reserves the right to revise or modify this Privacy Policy at any time to reflect changes in our practices or service offerings. When updates are made, we will revise the "Last Modified" date at the beginning of this document to indicate when the changes were implemented.

Significant changes will be communicated via email or by notice before they take effect. We encourage you to regularly review this Privacy Policy to stay informed about how we protect your Personal Information. By continuing to use our services after these updates, you acknowledge and consent to the revised policy.

10. Persons Under the Age of 18

Biosum’s Services are intended for adult users only. We are committed to protecting the privacy of minors and do not knowingly collect or solicit Personal Information from individuals under the age of 18 without verifiable parental or guardian consent. If we discover that we have inadvertently collected Personal Information from a child under 18 without proper consent, we will take prompt measures to delete that information.

If you believe we may have collected information from or about a child under 18 without appropriate consent, please contact us using the details provided below.

11. Users Located Outside the United States of America

Biosum primarily serves clients within the United States of America, tailoring our platforms and services to meet specific local needs and regulatory requirements. While we strive to maintain privacy and security standards consistent with global best practices, our operations are primarily focused on the U.S. audience.

For individuals accessing our services from outside the United States, please note that your interaction with our platforms involves the transfer of data to the U.S., where data protection laws may differ from those in your home country or other jurisdictions.

12. Storing Your Data

Biosum’s websites, platforms, and mobile applications are hosted in the United States of America. Any information we collect and store is housed within the United States, which may have different data protection laws than the country where you reside.

13. Privacy Questions

If you have any questions or concerns about your data or our practices, please contact our Privacy Department at privacy@biosum.com.