Privacy Policy

The Privacy Policy was last updated on April 1, 2025.

Scope

The Privacy Policy sets forth how BitsBody LLC, a Delaware limited liability company ("we," "us," or “our”), collects, uses, and protects information you (“you,” “your,” or “user”) voluntarily provide to us, as well as certain information automatically collected during your interaction with our website at https://bitsbody.com ("Website") and and all of our associated products and services, including our web and mobile applications and any online service platforms (collectively, "Services"). If you have any general questions or concerns about this Privacy Policy, you may contact us using the details provided in the Contact Us section.

Consent

By affirmatively indicating your consent via electronically selecting a designated option (such as clicking a button or checking a box), using any online mechanism, or by accessing or utilizing our Website in any manner—including all associated subdomains and their pages—or Services operated by us, you expressly acknowledge that you have read, understood, and agree to the terms set forth herein, forming a legally binding agreement with us, either personally or as an authorized representative of a legal entity. If you do not agree to any of these terms set forth in this Privacy Policy, you are prohibited from using our Website and Services.

Information We Collect

We collect information falling into two primary categories: voluntarily provided information that includes details you give us directly and automatically collected information that is gathered as you interact with our Website and/or Services. The data we collect may include both Personally Identifiable Information (“PII”), data that can directly identify you, and non-identifiable technical data, which, when analyzed together, could potentially be used to infer your individual identity.

Collection of Personal Information

(a) Information You Provide DirectlyWe collect certain PII that you knowingly and actively volunteer to provide when accessing or using our Website or Services. This may occur through creating an account or user profile, filling out contact or inquiry forms, subscribing to newsletters or marketing communication, purchasing Services, updating or submitting content, files, or project data, participating in surveys, interviews, or other research initiatives, accessing restricted areas of our Website, contacting our support or research teams, or otherwise choose to provide additional information.
(b) Types of Personal Information We CollectThe specific categories of PII we may collect include, but are not limited to: first and last name, email address, mailing address or physical location, phone or mobile number, username and password credentials, job title, employer, professional background, educational or academic information, payment or billing details (processed securely via third-party payment processors), demographic information (e.g., age, gender, language, geographical region, etc.), social media profiles or public online identifiers, content or files you upload or submit to our Website or Services, responses to customer feedback, surveys, or interviews, and contact lists or uploaded information related to your professional or affiliated collaborators (see "Covered Information" below). We may also collect any additional information you choose to provide when contacting us or interacting with our support or research teams.
(c) Demographic InformationWe may collect and analyze demographic information to better understand our user segments, tailor experiences, and optimize our Website and Services. This information may be aggregated and anonymized before use in analytics or reporting.
(d) Personal Information from Children Under 13Our Website and Services are not intended for children under the age of 13. We do not knowingly collect or solicit PII from anyone under 13-year-old. If we learn that a child under 13 has submitted personal information without verifiable parental consent, we will delete it promptly. If you believe we may have received such data, please contact us using the details provided in the Contact Us section so we can take appropriate action.
(e) Covered InformationYou may upload or share contact lists, de-identified medical data, or other datasets (“Covered Information”) for use in conjunction with our Services. This Covered Information is subject to the same protections set forth in this Privacy Policy and will not be used, shared, or disclosed outside of the stated purpose without your explicit consent.
(f) Medical InformationWe collect medical imaging data (e.g., CT scans, MRIs, X-rays, etc.), anatomical data, and other health-related data necessary to provide our Services. This subject or patient data is directly collected from users when they upload or import it to our Service platform and process their data. We also receive and process this data from our contracted third parties as part of our additional Service offerings.

Automatic Collection of Non-personal Information

When you visit our Website or use our Services, we collect certain non-personally identifying information from your browser and device. We use standard web server logs and automatic data collection tools such as cookies and web beacons to do this. This information helps us understand how our Website and Services are used, improve your experience, and tailor our content.
(a) Types of Automatically Collected Data
(i) Log and Usage Data: Our servers automatically record standard log data, including your IP address (used to infer approximate location, such as country, city, or ZIP code), your browser type, version and language settings, referring and exit pages, date, time, and duration of your visits, pages you view and actions you take; and error reports crash diagnostics, and system performance metrics. We may also record technical circumstances associated with software or system errors, crash diagnostics, and system performance metrics to monitor our Website and Services reliability, detect anomalies, and improve service delivery.
(ii) Device Data: We may collect technical details about the device you use to access our Website and/or Services, including your device type and model, operating system and version; unique device identifiers (e.g., UUIDs, advertising IDs); screen resolution and display capabilities, browser configuration and network provider, language preferences and time zone, and mobile device characteristics (if applicable). We may use this information to deliver device-optimized content, such as mobile-friendly layouts or media formats compatible with your system (e.g., HTML5 vs. Flash).
(iii) Inferred Data: Through data analytics and Artificial Intelligence (“AI”) tools, we may derive inferences about user interests and engagement levels, navigation behavior and content preferences, and feature adoption and interaction trends. These insights help us refine our offerings and tailor future updates to user needs.
(iv) Data from Services (if applicable): If you engage with our Services, we may collect and process uploaded medical images (e.g., scans or radiographs), anatomical structures generated by our AI models, de-identified patient reference points, annotations, or metadata, and derived measurements or spatial relationships between anatomical features. This data is handled with strict safeguards and in accordance with applicable medical privacy regulations (e.g., HIPAA, GDPR). We do not use this information for identification unless explicitly authorized and compliant with relevant laws.
(v) Cookies and Tracking Technologies: We may use cookies and similar technologies—including web beacons, pixels, local storage, and device fingerprinting—to improve your experience, analyze usage patterns, and deliver personalized content and advertising. We may also work with advertising partners like Google AdSense and Meta Ads who may display targeted ads when you visit our Website, partner websites, or any website within an ad network we participate in. These technologies, deployed by us or by authorized third-party service providers, may remember your preferences and settings, authenticate sessions, analyze traffic and behavior trends, and serve tailored content or communications. Cookies are small text files stored on your device by your browser. They may contain a unique identifier and are used to recognize your device across sessions and websites.
We use both "persistent cookies" that remain on your device for a set period of time or until manually deleted and are activated each time you visit our Website, and "session cookies," which are temporary and deleted once you close your browser window. We also use both "first-party" cookies and "third-party" cookies. First-party cookies are set directly by our Website. Third-party cookies are cookies set by external services or partners, not directly by our Website. We do not have access or control over third-party cookies. Both the first-party and any third-party cookies used on this Website can be broadly divided into the following categories:(1) Necessary Cookies: These are essential for our Website to function correctly. They enable core functionalities like page navigation and secure access to parts of our Website. (2) Optional Cookies: The optional cookies include: ● Preferences Cookies: These remember your settings and preferences across sessions, making your experience more convenient.● Analytics Cookies: These collect anonymous data to help us understand how visitors interact with our Website and Services, allowing us to improve its performance and usability.● Marketing Cookies: These deliver personalized ads based on your browsing behavior and interests.● E-commerce Cookies: These support shopping cart and checkout features. Unless you configure your browser to reject optional cookies, they may be placed automatically when you visit our Website or use our Services.
(b) How We Use Cookies and Tracking Technologies
(i) User Preferences & Functionality: We may use cookies and third-party services to recognize returning visitors and remember user preferences; monitor page views, track time spent, analyze feature usage; analyze engagement with multimedia content, and customize content based on user’s past interactions (collectively, “Use Information”). These also facilitate shopping cart operations and checkout processes.
(ii) Analytics Services: We may use third-party web analytics services, such as Google Analytics, in order to collect information about your use of our Website and Services. You may opt-out of Google Analytics by using Google's Browser Add-on, available at https://tools.google.com/dlpage/gaoptout.
(iii) Behavioral/Interest-Based Advertising: We may use cookies to customize the content and advertisements we display to you based on your previous use and activities of our Website and Services. This includes:● Retargeted Advertising: We may place ads on third-party websites (e.g., belonging to any of our cross-marketing partners, affiliates or advertising networks) that are targeted to you based on your past visits to our Website or Services. We use cookies and similar tools to identify your device uniquely and link it to your online activity. This allows our advertising partners to serve you advertisements that are more relevant to your interests, based on your usage history. ● Advertising Partners & Interest-Based Ads: We allow our advertising partners and ad services to collect certain Information related to ads displayed on this Website and our Services, including the pages you visit, links you click, ads you view and click on, the categories of search terms you enter, etc. They do this through the use of third-party cookies and other technologies in order to understand your interests and deliver targeted advertisements that are relevant to your interests. These third-parties may combine this data with psychographic, demographic, and geographical data collected from your use of other websites in order to personalize content and ads.
(c) Your Choices Regarding Targeted AdvertisingIf you prefer that we don't track your information on third-party websites to show you targeted ads, you can contact us using the details provided in the Contact Us section, and include "Tracking Targeted Ad Opt-out" in the subject line if using email. Please note that this will opt you out of targeted ads from us and any participating advertising partners. You will still receive general advertising from us on our Website and while using our Services, but it will not be personalized based on your browse history.
You can also explore industry self-regulatory programs: National Advertising Initiative (“NAI”) offers a single location to opt-out for receiving targeted ads from its members on https://www.networkadvertising.org/choices/. In addition, the Digital Advertising Alliance (“DAA”) provides tools to control ads customized based on your online behavior across different websites. Please visit https://www.aboutads.info/consumers to opt-out to learn more.
(d) Key Third-Party Integrations(i) Google AdSense & DoubleClick DART Cookie: We may participate in Google AdSense from time-to-time. Your usage information of our Website and Services is shared with the Google advertising network via the DoubleClick DART cookie, which is a third-party cookie. This helps Google serve and manage ads across the web. To opt-out of this use, please visit https://support.google.com/ads/answer/2662922?hl=en. You can also opt out of some cookies at the NAI opt-out website at https://thenai.org/opt-out/.(ii) Google Maps: Each time you use Google Maps through our Website or Services, your device’s GPS location data and unique device identifiers (including your Google advertising ID (“GAID”) via the Google Maps API) is collected and used by Google according to its privacy policy.
(e) Additional Third-Party IntegrationsWe may utilize various other third-party services and tools to support our operations, including but not limited to analytics, advertising, customer support, and payment processing. The privacy practices of these third parties are governed by their respective privacy policies. We encourage you to review their policies to understand how they collect, use, and share your information.
(f) Managing CookiesYou can manage your cookie preferences through your browser or device settings. You can block our cookies or any third-party cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies), you may not be able to use all or parts of our Website or Services in the manner as intended. Your internet browser allows you to change your cookie settings in the "options" or "preferences" menu. For more information on these settings in various browsers, you can visit resources like: https://www.thewindowsclub.com/disable-enable-cookies-internet-explorer. For even more information about deleting or blocking cookies, please visit: https://www.aboutcookies.org/Default.aspx?page=2

How We Use Your Information

We use the information we collect to operate, maintain, and improve our Website and Services, to communicate with you, and to offer relevant content and products.
(a) Linking (Bundling) Your Use InformationWe may link your PII with certain Use Information or other information we collect from you, often using a unique identifier, like a user anumber within a cookie. This combined information is referred as "Linked Information" that allows us to understand your interactions with our Website and Services more comprehensively and to personalize your experience. The ways we use and share this Linked Information is set forth in this Privacy Policy.
(b) Communication and MarketingWe want to keep you informed about our Services. Here's how we might communicate with you and your options for managing these communications:● Promotional Emails: We may send you periodic promotional e-mails about our Services or any new offerings. You can opt-out of these emails at any time by clicking "unsubscribe" in the email body or by contacting us using the details provided in the Contact Us section. ● Direct Mailers and Newsletters: If you have elected to receive them, we may send periodic newsletters and/or promotional materials to the physical address you provided to us. You can opt-out of receiving these mailers or newsletters by contacting us using the details provided in the Contact Us section.● Text Messages (SMS/MMS): If you provide us with your mobile number, we may send you text messages for promotional or advertising purposes, to communicate necessary information, or to facilitate transaction. You can opt out of receiving text messages at any time by texting "STOP" to the number that sends you messages from us.
(c) SMS Mobile Consent and ComplianceWe collect mobile numbers you provide to send you SMS/MMS messages about our Services. We are committed to complying with all applicable laws and regulations regarding text messaging, including the Telephone Consumer Protection Act ("TCPA"), the Federal Trade Commission Act, all rules and regulations promulgated by the Federal Communications Commission, and the Do-Not-Call (“DNC”) list registry rules (https://www.donotcall.gov). We will always include clear opt-out or unsubscribe information in our text messages and adhere to relevant Consumer Best Practices Guidelines, for example, from the Mobile Marketing Association. Any individual requesting DNC status shall be immediately be placed on our DNC list, and we will not send them further.
(d) Research and Technology DevelopmentWe use de-identified and anonymized Medical Information, as set forth in this Privacy Policy, from both users of our Services and our contracted third parties for research, to improve our existing Services, and to develop new ones. This includes using data to train and refine our AI/ML systems for anatomy-specific modeling & simulation tools.
(e) To Provide Our ServicesThe primary purpose of collecting and processing the PHI you upload/import to our Service platform is to provide you with the services you have requested, including medical image visualization, processing, and the creation of 3D anatomical models.

How We Share Your Information

We share your information only as described in this Privacy Policy to operate our business, provide our Services, and comply with legal obligations.
(a) Service Providers & ContractorsWe share some of the information we collect, including PII, with our third-party independent contractors and other administrative services on our behalf. Their access to your information is limited to what's necessary to perform their services for us. We require these contractors to agree not to use or disclose any PII or any other shared information except as absolutely necessary to perform their duties.
(b) Marketing & Business ConsultantsWe may share Linked Information, Demographic Information (potentially associated with PII), or certain PII with our marketing and business consultants (or partners). This is done strictly to improve our marketing strategies, sales practices, or other business operations. We may also share such information with our third-party services like MailChimp for email marketing campaigns or platforms like Google Ads and Meta Ads for advertising, as well as with our SEO consultants to improve functionality, accessibility, search engine visibility, or web traffic of our Website and Services. Their access is limited to providing these specific services to us. We require all such third-party consultants or partners to commit to securing your PII and other information that we collect through your use of our Website and Services.
(c) Affiliates & ResellersWe may disclose some of your PII, such as your name and/or email address, along with certain Use Information, including a purchase history of which Services you purchase from us, to our affiliates and authorized resellers. This allows them to promote our current or future Services. They may use your email address to notify you about our offerings. We do not grant them permission to use or disclose this information in any purpose other than as set forth herein. We require all our affiliates and resellers protect the privacy of any PII or other personal information we share with them and to use it solely for promoting our Services via email.
(d) Affiliated EntitiesWe reserve the right to share your PII and any other collected information with our subsidiaries or affiliated business entities (entities we legally control). Any such affiliated entity will comply with this Privacy Policy, ensuring your PII is used and protected consistently with this Privacy Policy terms.
(e) Cross-Marketing Partners & Ad NetworksFrom time to time, we may share Linked Information, Demographic Information (potentially associated with PII), or certain PII with our cross-marketing or advertising partners, including ad networks. These third parties may display targeted ads when you visit our Website or use our Services, partner websites, or any website within an ad network we participate in.
(f) Your Opt-Out Option for Information SharingIf you do not want us to share your information with our third parties for the purposes set forth in this Privacy Policy, you can contact us using the details provided in the Contact Us section, and include "Information Opt-out" in the subject line if using email. Be sure to provide your full name and email address when opting-out. Upon receiving your request, we will immediately cease sharing your information as stated above. We require these third parties to agree not to use or disclose your email address for any purpose other than sending emails about their related products and/or services. You can exercise this right by clicking the "Do Not Sell or Share My Personal Information" link provided in the Contact Us section or displayed on our Website.
(g) With Healthcare Providers and Business AssociatesWe may share the subject or patient Protected Health Information (“PHI”) necessary to provide our Services (whether you uploaded it directly to our Service platform or we received it from a contracted third-party) with the healthcare providers and with other Business Associates as necessary to fulfill our contractual obligations. This sharing is governed by a legally binding Business Associate Agreement (“BAA”) to ensure this data remains protected in accordance with the Health Insurance Portability and Accountability Act (“HIPAA”).
(h) Do We Sell Your PII?We prioritize your privacy. We will never sell, license or disclose any of your PII, whether alone or as Linked Information, to any third parties for any purpose not expressly set forth in this Privacy Policy without your explicit written consent. We only share or disclose any PII or other collected information as expressly set forth in this Privacy Policy.

How We Protect Your Information

We take the security of your information seriously, especially your highly sensitive data. We use reasonable, industry-standard security measures to protect all data you provide through our Website and Services. For instance, when you provide any credit card, billing or shipping information during checkout process, we encrypt that data during transmission using Secure Sockets Layer (“SSL”) encryption. We also use reasonable and customary security measures, like using a secured firewall-based database system, to protect against the loss, misuse or alteration of any PII or other data we collect and store, including PHI. Our security protocols align with standards required for handling sensitive medical data.
You are responsible for protecting your account credentials and for ensuring the security of your own information within the bounds of using our Website and Services, including selecting a strong password and keeping it confidential.
While we strive to protect your information, no data transmission over the internet or electronic storage method can be guaranteed to be 100% secure. Therefore, we cannot guarantee, warrant or represent that any information you provide through your use of our Website and/or Services will remain absolutely secure at all times from illegal or unauthorized access by third-parties. You agree that we shall not, under any circumstances, be held responsible or liable to you for any damages of any kind, whatsoever, related to any information or transmissions accessed by third parties, illegally or without authorization, through our Website and/or network. In the event of any unauthorized access to your information, we will report it promptly upon discovery and use our best efforts to remedy any security vulnerability that contributed to the unauthorized access.
(a) Our Data Processors & Sub-processorsTo operate our Website and provide our Services to you, we use third-party data processors. These are external entities that may have access to or process your personal data on our behalf. These data processors may, in turn, use their own sub-processors or other third-party vendors to perform various functions. Their access to your data is strictly limited to provide services to us or to facilitate your transactions. We do not grant them permission or consent to use or disclose your information for any purpose other than what is necessary for these applicable services.
(b) Adhere to GDPR StandardsWe require all of our data processors and sub-processors to satisfy the stringent data protection and usage requirements of the General Data Protection Regulation (“GDPR”), where applicable, including but not limited to the following requirements:(i) Process personal data in accordance with our documented instructions; (ii) Ensure their both internal and external personnel are reliable and subject to a contractually binding obligation to observe data privacy and security; (iii) Provide regular security and data protection training to all personnel who access any personal data; (iv) Implement and maintain appropriate technical and organizational measures consistent with our own commitments; (v) Promptly inform us about any actual or potential data breaches; and(vi) Cooperate with us to handle requests from data controllers, data subjects, or data protection authorities, as applicable.
(c) Key Data ProcessorsHere are some of the data processors we currently use:(i) Infrastructure & Data Storage: We use Google, LLC, to host our Website and store your data on database servers managed by DigitalOcean, LLC.(ii) Billing & Shipping Agents: When you make a purchase from our Website, your PII, credit/debit card or bank account details, and delivery/shipping information are collected by our third-party credit card and payment processors. This disclosure is necessary to complete your specific transaction and will only be used for that strict purpose, unless otherwise stated in this Privacy Policy.
(d) Changes to Data ProcessorsTo provide our Website and Services, we rely on various third-party data processors for functions that may change from time to time. These processors, which may not all be explicitly listed in this Privacy Policy, assist us with cloud computing, data storage, analytics, advertising, customer support, and other business operations. We ensure that any third-party processor we engage is bound by contractual agreements that require them to protect your data in accordance with all applicable laws and our privacy standards.
(e) Data Breach NotificationIn the unlikely event of a data breach, we will investigate the incident and take appropriate action to mitigate the harm. We will notify affected individuals and regulatory authorities in accordance with our legal obligations. Our data breach notification will comply with all applicable laws, including the HIPAA Breach Notification Rule, which requires us to notify affected users within sixty (60) days of the discovery of a breach.

Specific Provisions for Our Services

Our Services are based on two primary business approaches:● Data Acquisition and Processing Offering: In this approach, we acquire and process Medical Information from our contracted third parties (e.g., tissue vendors, healthcare providers, hospitals, etc.).● B2B Offering: This approach is not B2C, as the users of our Services are affiliated with an industry or academia where they work or study. In this approach, users of our Services directly upload and process their Medical Information on our Service platform.
The following provisions apply to how we handle Medical Information and your privacy rights across these business models.
(a) Handling of PHI & HIPAA ComplianceAs a provider of 3D anatomical models based on medical imaging data, our Services involve processing PHI. This includes any data that relates to a subject’s or patient's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare, that can be used to identify them. We are committed to protecting this sensitive data in full compliance with the HIPAA and its implementing regulations.
We do not collect PHI data directly from our Website visitors. Instead, we receive and process this data exclusively in two ways: (1) from our contracted third parties as part of our Data Acquisition and Processing Offering, and (2) from users who upload/import it directly to our Service platform as part of our B2B Offering.
Our role is that of a Business Associate, as we process PHI on behalf of healthcare providers and other covered entities. Our relationship with these organizations is governed by a legally binding BAA, which outlines our responsibilities and safeguards for data we process.
(b) Data De-identification and AnonymizationFor research and technology development purposes, we may de-identify or anonymize PHI in accordance with HIPAA's standards. De-identified data is information from which all identifiers have been removed, so that it cannot reasonably be used to identify an individual. Anonymized data is information from which all identifying details have been removed, making it impossible to identify the individual to whom it relates.
We use this de-identified and anonymized data for the following purposes:● Explanatory Research: To explore and improve the accuracy and functionality of our 3D anatomical modeling simulations and research associated technologies.● Technology Development: To develop new algorithms and train AI models and agents to better analyze anatomical data and create precise 3D digital twins of the anatomy.● Product Improvement and Service Enhancement: To continuously enhance our Services, develop and deploy new technology features, and ensure the quality of our anatomical models and AI systems. (c) Consent for Research and Technology DevelopmentYour personal data, including PHI, will not be used for our research and technology development purposes without a valid legal basis. The necessary consent for this data use is obtained from the subject or patient by our contracted third parties (via our Data Acquisition and Processing Offering) or directly from users (via our B2B Offering) before the data is provided to us for further processing. To revoke your consent, you must contact the party from whom we received your data. Alternatively, you can submit a request to us using the details provided in the Contact Us section, and we will coordinate with the relevant third party to process your request if that third party in is in our contractual network.
(d) User Responsibilities & User Control● User Responsibilities: Any user using our Service platform is responsible for the Medical Information, as defined in this Privacy Policy, they upload, process, and share. This includes ensuring that you have the necessary consent and legal rights to share any medical image data and other PHI with us. Our Privacy Policy governs our handling of your data, but you remain responsible for the lawful collection and transfer of that data. ● User Control: You have full control over the Medical Information you upload to or import into our Service platform. You can access, update, and delete your data at any time through your account dashboard. When you delete data from our Service platform, we will take reasonable steps to ensure it is permanently removed from our Service systems. If you close your account, all your data will be permanently deleted.
(e) International Transfers of Sensitive InformationHealth data is considered a "special category of data" under international privacy laws such as the GDPR. This means it is afforded a higher level of protection. When we transfer your personal information outside of your country of residence, we will ensure that it is protected by appropriate legal and technical safeguards. These may include Standard Contractual Clauses (“SCCs”) or other legally accepted mechanisms to guarantee that your sensitive health data remains secure and protected in accordance with all applicable data protection laws.

Third-party Privacy Practices Disclaimer

(a) Third-party Privacy PracticesOur Website and Services may contain links to or advertisements for third-party websites, content, products, or services. When you click on these links or provide information to these third parties, you are leaving our Website or Services as applicable. By submitting any information to a third-party, you affirmatively consent to have that information shared with them. We are not responsible for the privacy practices of any of third-party websites or sellers. We strongly encourage you to read the privacy policy of any third-party website before you provide any personal or billing information to them. You agree that we shall not, under any circumstances, have any liability to you for any damages resulting from how a third party uses or discloses your information.
(b) Required DisclosuresWe may disclose certain PII if we believe it is necessary to comply with the law. We may also disclose your PII to credit reporting agencies, courts, tribunals, and regulatory authorities if you fail to pay for Services we have supplied, or as required by law. This can occur if: ● We are requested to do so by a subpoena, court order, or a request from local, state, federal or international law enforcement; or ● It is necessary to investigate or help prevent security threats, fraud or other malicious activity; or ● We need to protect our legal rights or property, or the rights and property of our customers or other third parties.
(c) CommunicationsWhen you visit this Website, use our Services or send us e-mails, you are communicating with us electronically. By doing so, you consent to receive electronic communications from us. You agree that all agreements, notices, and communications we provide to you electronically satisfy any legal requirement that such communications be in writing. If you contact us via email, phone or written correspondence, we may create a record and store your email and PII along with notes from our communications with you.
Any PHI transmitted to us through our secure Service platform is treated as strictly confidential and is protected in full compliance with HIPAA. However, we cannot guarantee the confidentiality of general inquiries or information sent to us outside of the secure Service platform (e.g., via unencrypted email). Therefore, you should not transmit any sensitive or confidential information through these unsecure channels.

General Information

(a) Information Storage and International TransferAny PII and all other data we collect on our Website and Services will be stored and processed on our server(s) located in the United States of America (“USA”). If you reside outside the USA, you consent to the collection, transfer, storage, and processing of your information from your country to the USA and other locations where we, our partners, affiliates, and third-party providers have facilities.
Please be aware that the countries where your information is stored, processed, or transferred may not have the same data protection laws as your home country. When we transfer your personal information to third parties in other countries, we will:● Perform those transfers in compliance with all applicable legal requirements.● Protect your transferred personal information in accordance with this Privacy Policy.
(b) How to Update, Change or View Your PIIIf you would like to request any changes or updates to any PII you have provided to us, or if you would like to view any information we have collected from your use of our Website and Services, please contact us using the details provided in the Contact Us section, and include "Personal Information Request" in the subject line if using email. If you make any information requests, we will require that you provide proof of your identity, which may include providing us with a copy of a driver's license, social security card and/or birth certificate. We also reserve the right to require that you sign and provide us with a notarized affidavit verifying your identity before we update or release any information to you.
(c) How Long We Keep Your InformationWe keep your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy. The specific duration for which we retain your information may vary depending on its intended use. For instance, if you create an account, we will keep your information for as long as your account remains active in our system. Once your information is no longer needed, we will either delete it or make it anonymous by removing all identifying details. However, we may retain your personal information for longer periods if required to comply with our legal, accounting, or reporting obligations, or for archiving purposes in the public interest, scientific, historical research, or statistical purposes.
(d) Business Transfers and SuccessorsWe may transfer any PII you have submitted to our Website and Services to our successor in the event of merger, acquisition, sale, or other change of control of our business. This also applies in the event of our bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the application of laws or equitable principles affecting creditors' rights generally. In any such case, your PII would be included among the assets transferred to the acquiring party. By using our Website and Services, you acknowledge that such transfers may occur. The acquiring party will be required to assume our rights and obligations regarding the ownership and use of your information and may continue to use your PII according to this Privacy Policy, as permitted by applicable law.
(e) Modifications to This Privacy PolicyWe reserve the right to modify this Privacy Policy at any time to reflect changes in our data practices, applicable legal requirements, or operational needs. When we make material changes to this Privacy Policy, we will provide notice by updating the “Last Updated” date at the top of this page and, when appropriate, through additional means, such as a prominent announcement on our Website and Service platform or by email notification if you’ve provided one. Where required by law, we will obtain your consent for or provide you with the option to opt-out of any new uses of your personal information.
Your continued access to or use of our Website and Services after any such modifications constitutes your acknowledgment and acceptance of the updated Privacy Policy. We encourage you to regularly review this Privacy Policy periodically to stay informed about our collection, usage, and protection practices of your information.

Your State Privacy Rights for USA Residents

The following provisions apply to USA residents of states with specific data privacy laws, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, New Hampshire, New Jersey, New York, Oregon, Tennessee, Texas, Utah, and Virginia. This section details the specific rights you may have and applies only to residents of the state referenced in the heading or text.
(a) Your Privacy RightsDepending on your state of residence, you may have the following rights regarding the personal information we hold about you:● Right to Know/Access: The right to request that we disclose the personal information we have collected about you, including the categories of data, the purposes for collection, the sources of the data, and the categories of third parties we have shared it with.● Right to Delete: The right to request the deletion of personal information we have collected from you, subject to certain legal exceptions. If you terminate or delete your account, we will delete your personal information within fourteen (14) business days. Please be aware that search engines and other third parties may still retain copies of information that was made public.● Right to Correct: The right to request the correction of inaccurate personal information we maintain about you.● Right to Opt-Out of the Sale or Sharing of Personal Information: The right to opt out of the "sale" of your personal information or its "sharing" for cross-context behavioral advertising. As defined by law, we do not "sell" your personal information in the traditional sense, but we may "share" it with third parties for cross-context behavioral advertising.● Right to Non-Discrimination: The right not to receive discriminatory treatment for exercising your privacy rights.● Right to Appeal: If we deny your request to exercise a privacy right, you may have the right to appeal our decision. We will provide instructions on how to appeal in our response to your request.
To exercise any of these rights, please contact us using the details provided in the Contact Us section. We may need to verify your identity to process your request.
(b) California Privacy RightsCalifornia residents are afforded specific rights under the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), as follows:
(i) Notice of CollectionIn the past twelve (12) months, we may have collected the following categories of personal information from you for the business purposes described in this Privacy Policy:● Identifiers: Name, email address, phone number, account name, and IP address.● Customer Records: Billing and shipping address, and payment data.● Commercial Information: Services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.● Geo-location Data: Information about your general geographical location.● Professional- or Employment-related Information: Job title, employer, and professional background.● Education Information: Educational or academic information.● Inferences: Information derived from your data to create a profile about your preferences, characteristics, and interests.For more details on the types of information we collect and the business purposes for which we use it, please refer to the "Information We Collect" and "How We Use Your Information" sections of this Privacy Policy.
(ii) "Shine the Light" RequestsUnder California Civil Code Section 1798.83, while California residents have the right to request information about the disclosure of personal information to third parties for direct marketing purposes, this right is not applicable to our Website and Services as our relationship with you is not for personal, family, or household purposes.
(iii) Financial IncentivesIn compliance with the CCPA, we may offer certain financial incentives (e.g., a discount or promotion) in exchange for your personal information. Any such incentive will be reasonably related to the value of your personal information. We will provide written terms that describe the program. Participation is voluntary and requires your prior opt-in consent, which you can revoke at any time.
(c) Residents of Colorado, Connecticut, Delaware, Indiana, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas, and VirginiaIf you are a resident of Colorado (under the Colorado Privacy Act), Connecticut (under the Connecticut Data Privacy Act), Delaware (under the Delaware Personal Data Privacy Act), Indiana (under the Indiana Consumer Data Protection Act), Montana (under the Montana Consumer Data Privacy Act), New Hampshire (under the New Hampshire Privacy Act), New Jersey (under the New Jersey Data Privacy Act), Oregon (under the Oregon Consumer Privacy Act), Tennessee (under the Tennessee Information Protection Act ), Texas (Texas Data Privacy and Security Act) or Virginia (under the Virginia Consumer Data Protection Act), you have the following rights:● Right to Access: The right to confirm whether we are processing your personal data and to access that data.● Right to Correction: The right to correct inaccuracies in your personal data.● Right to Deletion: The right to request the deletion of your personal data that you have provided.● Right to Data Portability: The right to obtain a copy of your personal data in a portable and, to the extent technically feasible, readily usable format.● Right to Opt-Out: The right to opt-out of the processing of your personal data for the purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.● Right to Appeal: If we deny your request to exercise a privacy right, you have the right to appeal our decision. To do so, please submit a written request to us using the contact details provided in the Contact Us section. We will review and respond to your appeal within the timeframes required by law.
(d) Residents of IowaIf you are a resident of Iowa, you have the following rights under the Iowa Data Privacy Act:● Right to Access: The right to confirm whether we are processing your personal data and to access that data.● Right to Deletion: The right to request the deletion of your personal data.● Right to Opt-Out: The right to opt-out of the sale of your personal data.
(e) Residents of New YorkThe Stop Hacks and Improve Electronic Data Security (“SHIELD”) Act requires us to adopt and maintain reasonable safeguards to protect the private information of New York residents. In the event of a data breach, we will provide notification to affected New York residents and the appropriate state agencies as required by law.
(f) Residents of UtahIf you are a resident of Utah, you have the following rights under the Utah Consumer Privacy Act:● Right to Access: The right to confirm whether we are processing your personal data and to access that data.● Right to Deletion: The right to request the deletion of your personal data that you have provided.● Right to Data Portability: The right to obtain a copy of your personal data in a portable and readily usable format.● Right to Opt-Out: The right to opt-out of the sale of your personal data.
(g) "Do Not Track" & Global Privacy ControlSome web browsers offer a Do Not Track (“DNT”) feature that allows you to tell websites that you do not want to have your online activities tracked. At this time, we do not respond to DNT signals.
However, we do recognize and respond to the Global Privacy Control (“GPC”) signal, which is a legally recognized mechanism for exercising your right to opt out of the sharing of your personal information for targeted advertising. If we detect a GPC signal from your browser, we will treat it as a valid request to opt out of the sharing of personal information tied to that browser.
(h) How to Exercise Your RightsTo submit a request to exercise any of the rights listed above, please contact us using the details in the Contact Us section. We will need to verify your identity to process your request. We will respond to your request within the time-frame required by applicable law. In the event we deny your request, you may have the right to appeal our decision. We will provide you with a response explaining our decision and any options for appeal in accordance with applicable state law.

Information for Canadian Residents

This section provides additional disclosures required by the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applies to Canadian residents.
(a) Scope of Personal InformationUnder PIPEDA, the definition of personal information is broad and includes any information about an identifiable individual. In this Privacy Policy, any references to PII are intended to be equivalent in scope and meaning. This can include information about your financial data, physical appearance, opinions, or personal correspondence with us.
(b) Consent and Legal BasisWe will only collect and use your personal information with your valid consent. PIPEDA requires that consent is only valid if it's reasonable to expect that you would understand the nature, purpose, and consequences of the data collection, use, or disclosure to which you are consenting.When you engage with our Website and Services, your positive action of contact, such as sending an inquiry, implies your consent for us to use your name and email address to respond.
(c) Withdrawal of ConsentYou can withdraw your consent at any time. However, this will not affect any use of your information that has already taken place. To withdraw your consent, contact us using the details provided in the Contact Us section. Please note that withdrawing consent may impact our ability to provide or continue to provide certain content on our Website and Services.
You cannot refuse the collection, use, or disclosure of your personal information if it is required to meet legal or regulatory obligations or fulfill the terms of any contractual agreement.
(d) Our Commitment to PIPEDA's PrinciplesOur Privacy Policy is built on and complies with PIPEDA's ten (10) fair information principles:● Accountability: We are responsible for the personal information under our control.● Identifying Purposes: We identify the purposes for which we collect personal information before or at the time of collection.● Consent: Your knowledge and consent are required for the collection, use, or disclosure of your personal information, except where otherwise legally permitted.● Limiting Collection: We limit the collection of personal information to what is necessary for our identified purposes.● Limiting Use, Disclosure, and Retention: We will not use or disclose your personal information for purposes other than those for which it was collected, except with your consent or as required by law.● Accuracy: We will keep your personal information accurate, complete, and up-to-date as necessary for the purposes for which it was collected.● Safeguards: We protect personal information with security safeguards appropriate to its sensitivity.● Openness: We make our policies and practices for managing personal information readily available.● Customer Access: We will inform you of the existence, use, and disclosure of your personal information and provide access to it upon request.● Challenging Compliance: You have the right to challenge our compliance with these principles.
(e) Your PIPEDA RightsAs a Canadian resident, you have the following rights regarding the personal information we hold about you:● Right of Access: You have the right to access the personal information we hold about you. We will respond to your written request within thirty (30) calendar days. We may charge a minimal fee to fulfill your request.● Right of Rectification: You can request a correction to any factual errors or omissions in your personal information. If we cannot agree on a correction, you have the right to have your concerns recorded.● Right to Withdraw Consent: As outlined above, you can withdraw your consent for any activities for which you have provided it.
(d) International Transfers of InformationWhile we endeavor to store and process customer data within Canada, we may use service providers located in the USA, the UK, or the EEA. Although we make reasonable efforts to ensure your data receives the same level of protection as it would in Canada, please be aware that privacy protections in other jurisdictions may differ.
(e) Canadian Anti-Spam LegislationOur electronic communications with customers are compliant with Canada’s Anti-Spam Legislation. We do not send unsolicited emails to individuals with whom we have no relationship and do not sell or share email addresses with unrelated third parties for marketing purposes without your express consent. For more information, please refer to the heading, “How We Use Cookies and Tracking Technologies” set forth in this Privacy Policy.
(f) Complaints and InquiriesFor any questions about our Privacy Policy or to report a privacy violation, please contact us using the details in the Contact Us section. If we fail to resolve your concern to your satisfaction, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (“OPC”). You can contact the OPC at: Office of the Privacy Commissioner of Canada 30 Victoria Street Gatineau, QC K1A 1H3. Toll Free: 1-800-282-1376. Website: www.priv.gc.ca

Information for European Union (EU) Residents

This section provides additional disclosures required by the GDPR and applies to residents of the European Economic Area (“EEA”).
(a) Our Role as a Data ControllerThe GDPR distinguishes between organizations that process personal information for their own purposes (data controllers) and those that do so on behalf of others (data processors). We are a data controller with respect to the personal information you provide to us. Our address is located in the Contact Us section of this Privacy Policy.
(b) Legal Grounds for Processing Your DataWe will only collect and use your personal information when we have a legal basis to do so. In these cases, we process your information lawfully, fairly, and transparently. If your consent is required and you are under 16 years of age, we will seek the consent of your parent or legal guardian.Our legal grounds for processing your data include:● Consent: We process your personal information when you have given us explicit consent for a specific purpose. You can withdraw your consent at any time, but this will not affect any processing that has already occurred.● Performance of a Contract: We process your personal information when it is necessary to fulfill a contract with you or to take preparatory steps before entering into a contract (e.g., to respond to an inquiry).● Legitimate Interests: We may process your information when it is necessary for our legitimate interests, which include providing, operating, and improving our Website and Services. Examples of our legitimate interests include research and development, marketing, data analysis, and protecting our legal rights.● Compliance with Law: In some cases, we are legally obligated to use or retain your personal information, such as to comply with a court order, criminal investigation, or other government requests.
(c) International Data TransfersWe ensure that any transfer of personal information from countries within the EEA to countries outside of it is protected by appropriate safeguards. These safeguards may include the use of SCCs approved by the European Commission or other legally accepted mechanisms to ensure your personal information remains protected in accordance with applicable data protection laws.
(d) Your Rights and Controlling Your Personal InformationAs a resident of the EEA, you have the following rights regarding your personal information:● Right to Restrict Processing: You can request that we restrict the processing of your personal information if you have concerns about its accuracy, if you believe it has been unlawfully processed, or if you need us to retain it for a legal claim.● Right to Object to Processing: You have the right to object to the processing of your personal information that is based on our legitimate interests. If you do so, we must provide compelling, legitimate grounds for the processing to continue.● Right to Data Portability: You can request a copy of the personal information we hold about you in a structured, commonly used, and machine-readable format. You may also have the right to request that we transfer this information to a third-party.● Right to Deletion: You have the right to request the deletion of your personal information. If you terminate or delete your account, we will delete your personal information within fourteen (14) business days. However, there may be exceptions to this right for legal reasons, and search engines may still retain copies of information you made public.

Information for United Kingdom (UK) Residents

This section provides additional disclosures required by the GDPR and applies exclusively to residents of the UK.
(a) Our Role as a Data ControllerThe GDPR distinguishes between organizations that process personal information for their own purposes (data controllers) and those that do so on behalf of others (data processors). We are a data controller with respect to the personal information you provide to us. Our address is located in the Contact Us section of this Privacy Policy.
We may indirectly collect personal information about you from third parties who have your permission to share it, such as a business we collaborate with. We may also gather publicly available information, such as from social media and messaging platforms you use.
(b) Legal Grounds for Processing Your DataWe are committed to collecting and using your personal information lawfully, fairly, and transparently. We will only process your personal data when we have a legal basis to do so, which may include:● Consent: Where you have given us consent for a specific purpose. You may withdraw your consent at any time, but this will not affect any processing that has already occurred.● Performance of a Contract: When processing your personal information is necessary to fulfill a contract with you or to take preparatory steps before entering into a contract.● Legitimate Interests: When we determine it is necessary for our legitimate interests, which include providing, operating, improving, and promoting our Website and Services.● Compliance with Law: When we have a legal obligation to use or retain your personal information, such as to comply with a court order or regulatory requirements. For example, we are required to keep financial records for a minimum of seven (7) years.
(c) Data RetentionWe will retain your personal information only for as long as it is necessary to fulfill the purposes set out in this Privacy Policy. If your personal information is no longer required for our stated purposes or if you request its deletion, we will delete it or make it anonymous. We may retain your information for longer periods if required to comply with legal, accounting, or reporting obligations, or for public interest, scientific, or historical research purposes.
(d) International Data TransfersThe personal information we collect is stored and/or processed in the USA. Following an adequacy decision by the UK Government, the USA has been deemed to provide an essentially equivalent level of protection to that ensured under the UK GDPR. When we transfer your personal information to third parties in other countries, we will:● Perform those transfers in accordance with the requirements of the UK GDPR (Article 45) and the Data Protection Act 2018.● Adopt appropriate safeguards, such as SCCs, to protect your transferred data.
(e) Your Data Subject RightsAs a resident of the UK, you have the following rights regarding your personal information:● Right to be Informed: You have the right to be informed about how your data is collected, processed, shared, and stored.● Right of Access: You can request a copy of the personal information we hold about you by submitting a Data Subject Access Request (“DSAR”). We will fulfill your request within thirty (30) calendar days.● Right to Rectification: You have the right to correct, update, or complete any inaccurate, outdated, or incomplete personal data we hold about you.● Right to Erasure: In certain circumstances, you can ask for your personal data to be erased from our records. This right applies if the data is no longer necessary, if you withdraw consent, or if you object to its processing and we have no overriding legitimate grounds to refuse.● Right to Restrict Processing: You can request that we restrict the processing of your personal information if you have concerns about its accuracy or lawfulness, or if you need us to retain it for a legal claim.● Right to Object to Processing: You have the right to object to the processing of your personal information that is based on our legitimate interests.● Right to Portability: You have the right to obtain some of your personal data from us in an accessible and machine-readable format and to request that we transfer it to another organization where technically feasible.
(f) Complaints and InquiriesTo make a privacy inquiry or report a violation, please contact us using the details provided in the Contact Us section. You also have the right to lodge a complaint with the Information Commissioner's Office (“ICO”), the UK supervisory authority for data protection issues. We would appreciate the opportunity to address your concerns first, so please contact us before reaching out to the ICO. You can contact the ICO at: Information Commissioner's Office, Wycliffe House Water Lane, Wilmslow Cheshire, SK9 5AF. Tel: 0303 123 1113 (local rate). Website: https://www.ico.org.uk

Information for Switzerland Residents

This section provides additional disclosures required by the Federal Act on Data Protection (“FADP”) and applies to residents of Switzerland.
(a) Your FADP RightsUnder the FADP, Swiss residents have the following rights regarding their personal information:● Right to Access: You have the right to request access to the personal information we hold about you.● Right to Rectification: You have the right to request that we correct any personal information that you believe is inaccurate, incomplete, or out-of-date.● Right to Erasure: You have the right to request the deletion of your personal data.● Right to Object: You have the right to object to the processing of your personal information.● Data Transfers: We may transfer your personal information outside of Switzerland. We will ensure that your data is protected in accordance with the FADP and that any country it is transferred to has adequate data protection laws.
For more information or to exercise any of these rights, please use the contact details provided in the Contact Us section of this Privacy Policy.

Information for Australian Residents

This section provides additional disclosures required by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”) and applies exclusively to residents of Australia.
(a) Your Rights Under the Privacy ActAs an Australian resident, you have the following rights regarding your personal information:● Right to Access: You have the right to request access to the personal information we hold about you.● Right to Correction: You have the right to request that we correct any personal information that you believe is inaccurate, out-of-date, incomplete, irrelevant, or misleading.
(b) International Data TransfersWhen we disclose your personal information to third parties located outside of Australia, you acknowledge that some of these third parties may not be regulated by the Privacy Act and the APPs. By providing your consent to such transfers, you acknowledge that if an overseas recipient handles your personal information in a way that contravenes the APPs, they will not be held accountable under the Privacy Act, and you will not be able to seek redress under the Privacy Act.
(c) Complaints and InquiriesIf you have a concern or complaint about how we have handled your personal information, please contact us first using the details provided in the Contact Us section. We will promptly investigate your complaint and respond to you in writing. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner. Tel: 1300 363 992. Website: https://www.oaic.gov.au

Contact Us

For any questions or concerns regarding this Privacy Policy, you may contact us using the following details:Address: BitsBody, LLC, 516 W. Shaw Ave #200, Fresno, CA 93704 (USA)Email: moc.ydobstib%40lagelDo Not Sell or Share My Personal Information