Get In Touch
Room 222-225, Level 2, 38 Gawler Place, Adelaide 5000
[email protected]
Ph: +61 88220 001

Privacy Policy

 

1.                 Introduction

 

This Privacy Policy applies to users (“you”) of the software program (and functionality provided through the software program) provided by Biomorphik (the “Application”) and downloaded and accessed by You on an iPhone or Android smart device, named Biomorphik (the “Service”).

The Service can only be accessed if you have supplied your name and email address to Biomorphik for the purposes of creating an account and password for the Service.

The Service creates silhouettes of your body shape using pictures you take with your smartphone and collects information you input about your height, weight, gender and date of birth.

We use the information above to:

  • calculate statistics including body measurements and body
  • infer your risk of chronic diseases.

We do collect information about your use of the Application and the Service, as described in this Privacy Policy, to help us secure and improve the Application and develop the Service.

Our collection and use of your Personal Data are subject to the data protection laws applicable where you reside, as set out in this Privacy Policy.

Where we collect and process your Personal Data based on your explicit consent, as set out in this Privacy Policy, we will ask for your consent in the Service before we collect any of your Personal Data. You can withdraw your consent at any time by using the contact details provided in this Privacy Policy.

 

2.                 Interpretation & Definitions

 

Capitalised words in this Privacy Policy have the meanings given below. All definitions have the same meaning regardless of whether they are used in singular or plural.

  • Business means the legal entity that determines the purposes and means of processing of Personal Data about residents of California in accordance with the
  • Controller means the legal entity or natural person that determines the means and purposes of processing of Personal Data about individuals in the European Economic Area or the United Kingdom in accordance with the
  • CCPA means the California Consumer Privacy Act, California Civil Code sections 1798.100 et seq, and its implementing
  • GDPR means the General Data Protection Regulation (EU) 2016/679 and, from the point at which the GDPR ceases to apply in the United Kingdom, the UK

 

 

  • LGPD means the Brazilian General Data Protection Law (the Lei Geral de Proteção de Dados Pessoais).
  • Biomorphik means Biomorphik PTY LTD of 38 Gawler Place, Level 2 Rooms 222-225, Adelaide, South Australia 5000.
  • Personal Data means information which can be used directly or indirectly to identify you and which relates to you (and shall be deemed to include “Personal Data” as defined in the GDPR and LGPD and “personal information” as defined in the CCPA and the Australian Privacy Act 1998 (Cth) respectively).
  • Processor means the legal entity or natural person that processes Personal Data on behalf of and in accordance with instructions from a Controller in accordance with the
  • Service Provider means the legal entity that processes Personal Data about residents of California on behalf of a Business in accordance with the
  • UK GDPR means the General Data Protection Regulation (EU) 2016/679 as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act

 

3.                 Body Scan Data

 

When you use the Service, we collect your height, weight and gender when you provide this information to us and also collect photos you take using the Application, as well as silhouettes of your body image created using photos you take using the Application (“Body Scan Data”).

We use the Body Scan Data to calculate digital anthropometric circumference measurements, body composition information (such as your body fat %, for example) and body joint information (the areas where your bones are attached to permit body parts to move), as well as provide user support.

This information is your Personal Data because it is about you and can be used to identify and /   or differentiate you from other individuals using the Service. We collect body scan data with your explicit consent.

We may use your Body Scan Data for statistical, research and business-related purposes, such as improving our products. Where we do so, we will always anonymise your data.

 

4.                 Risk Inference Data

 

Where we infer risk, we collect information you input about your height, weight, gender, and date of birth. In combination with your body measurements and body composition, we use these to infer your risk of chronic diseases / mortality.

Where we infer risk, we provide additional information on how the risk was inferred including, information from risks tables generated from studies by organisations such as The World Health Organisation, and the International Diabetes Federation, and where possible, reference the study,

 

organization that conducted the study, and the risk classification tables generated from the study, so that You can understand how we arrived at the inferred risk result based on the input information, as well as the body measurements and body composition statistics the Service outputs.

Biomorphik risk inference is not intended to replace traditional methods of diagnosis or treatment, it is only intended to provide extra information to You that might be helpful, however does not replace a doctor’s visit.

Where we infer risk, we will create information that relates to your health you may be at risk of, which is your Personal Data. We process these Personal Data with your explicit consent.

 

5.                 Usage Data

 

We collect information about how you use the Service (“Usage Data”) automatically. Usage Data includes information about the device you are using to access the Service (including your IP address, your browser type and version, your operating system, and the type of smartphone used), the pages of the Service that you visit, the time and date of your visit, the time spent on those pages and other diagnostic information.

We use Usage Data to secure and identify problems with the Service, monitor crash reports, and to help us support and improve the Application and to develop the Service.

We collect and process Usage Data based on our legitimate interest to support and secure the Service and the Application and to identify potential improvements.

 

6.                 Sharing Your Personal Data

 

We will share your Personal Data with trusted third parties who provide us with services necessary to enable us to provide the Service to you. Any such third parties are required by a contract between us and them to take appropriate security measures to protect your Personal Data and may only use your Personal Data in line with our instructions and not for their own purposes.

The Service is hosted in the Amazon Web Services (“AWS”) cloud platform and AWS is one of our trusted third-party service providers that will have access to your Personal Data.

Our primary AWS hosting location is in the Singapore and our business operations, including our development and support teams, are based in Australia, and India. This means that your Personal Data will be stored in and accessible by us from Singapore, India, and Australia where the data protection laws may not provide the same level of protection to the country or region in which you live.

If you are located in the EEA or UK or Brazil, we will only transfer your Personal Data outside that region with your explicit consent.

We may also share your Personal Data where required to do so by law or where we believe in good faith that disclosure is necessary to protect the safety of users of the Service or the public,

 

investigate and prevent possible wrongdoing in connection with the Service, to protect and defend our rights and assets and to protect against legal liability.

If we are subject to any merger, acquisition of asset sale, your Personal Data may be transferred to the acquiring or merged entity. We will notify you if this occurs and provide you with details of any arising change to this Privacy Policy.

We may share statistics (and other relevant information) relating to your body scan data with third parties when we are liaising with them about the services and products we provide. Where we do so, we will always anonymise your data so that any third parties cannot link it to you.

 

7.                 Retaining Your Data

 

We will only retain your Body Scan Data, and Risk Inference Data Personal Information for as long as is required to provide you with the Service or as otherwise instructed by you.

We retain Usage Data for as long as is reasonably necessary for the purposes set out above and   to enable us to meet our contractual and legal obligations. If we need to hold it for a longer period, we will anonymise the data by removing identifiers and aggregating it with other diagnostic information.

 

8.                 Protecting Your Data

 

The security of your Personal Data is important to us, and we have implemented organisational and technical security measures in line with good industry practice to ensure that your Personal Data is protected.

Unfortunately, no method of transmission over the internet or method of electronic storage is 100% secure. Whilst we will always take steps to protect your information in line with good industry practice, we cannot guarantee its absolute security.

 

9.                 Children’s Privacy

 

Our Terms of Service prohibit use of the Service by anyone under the age of 13, and we do not knowingly collect Personal Data from anyone under the age of 13.

If You are a parent or guardian and you believe your child is using the Service, please contact us  to delete their Body Scan Data and the Usage Data.

If we become aware that we have collected Personal Data from anyone under the age of 13, we will take steps to delete their Personal Data.

 

10.            Your Rights

 

You have rights in respect of your Personal Data. The specific rights available to you depend on your country of residence. If you are in the European Economic Area or UK, you have the rights

 

 

listed at Section 11 of this Privacy Policy. If you are a resident of California, you have the rights listed at Section 12 of this Policy. If you are a resident of Brazil, you have the rights listed at Section 13 of this Policy.

If you live in Australia, you have the right to request access to or correction of the Personal Data we hold about you and the right to stop receiving unwanted direct marketing. You can also make  a complaint about us to the Office of the Australian Information Commissioner if you think we have mishandled your Personal Data.

You can exercise your rights or complain to us about how we use your data by emailing us at [email protected] or writing to us at the address provided at Section 14, below.

 

11.            GDPR Specific Processing

 

If you reside in the European Economic Area (“EEA”) or the United Kingdom (“UK”), this Privacy Policy applies as follows:

  • Biomorphik is the Controller for your Body Scan Data, Risk Inference Data, and Usage
  • The trusted third parties with whom we share your Personal Data as described in the Privacy Policy are our processors for Body Scan Data, Risk Inference Data, and Usage Data. We enter into data processing agreements that meet the requirements of Article 28 of GDPR with our sub-processors and
  • We only transfer your Body Scan Data, and Risk Inference Data outside the EEA or UK with your explicit consent or where otherwise permitted by law to do
  • We transfer your Body Scan Data, Risk Inference Data, and Usage Data outside the EEA and the UK including to the United States, and Australia where the data protection laws may offer a lower level of protection than in your
  • We may share statistics (and other relevant information) relating to your body scan data with third parties when we are liaising with them about the services and products we provide. Where we do so, we will always anonymise your data so that any third parties cannot link it to
  • We have designated a Data Protection Officer, who can be contacted by emailing [email protected]
  • You have the following rights in respect of your Personal Data:
    • You have the right of access to your Personal Data and can request copies of it and information about our processing of it.
    • If the Personal Data we hold about you is incorrect or incomplete, you can ask us to rectify or add to it.
    • Where we are using your Personal Data with your consent, you can withdraw your consent at any

 

 

  • Where we are using your Personal Data because it is in our legitimate interests to do so, you can object to us using it this
  • Where we are using your Personal Data for direct marketing, including profiling for direct marketing purposes, you can object to us doing
  • You can ask us to restrict the use of your Personal Data if:
    • It is not
    • It has been used unlawfully but you do not want us to delete
    • We do not need it anymore, but you want us to keep it for use in legal claims; or
    • if you have already asked us to stop using your data but you are waiting to receive confirmation from us as to whether we can comply with your
  • In some circumstances you can compel us to erase your Personal Data and request a machine-readable copy of your Personal Data to transfer to another service
  • You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects
  • You can withdraw consent. If you withdraw your consent, we may not be able to provide You with access to certain specific functionalities of the
  • You can also raise a complaint with the data protection supervisory authority in the country in which you
  • To exercise your rights in respect of Body Scan Data, Risk Inference Data, and Usage Data you can contact us using the details set out at Section 10 or Section 14 of this Privacy Policy.

 

12.            California Specific Processing

 

If you are a resident of California, this Privacy Policy applies as follows:

  • To the extent applicable under the CCPA, Biomorphik is the Business for Body Scan Data, Risk Inference Data, and Usage
  • We may share statistics (and other relevant information) relating to your body scan data with third parties when we are liaising with them about the services and products we provide. Where we do so, we will always anonymise your data so that any third parties cannot link it to
  • Biomorphik does not sell your Personal Data within the meaning of the
  • You have the following rights in respect of your Personal Data to the extent required by the CCPA:
    • You have the right to disclosure of specific information to you about the collection and use of your Personal Data over the last 12
    • You have the right to request that your Personal Data is deleted, subject to certain exceptions.

 

 

  • You have the right not to be discriminated against for exercising your rights under the
  • To exercise your rights in respect of Body Scan Data, Risk Inference Data, and Usage Data you can contact us using the details set out at Section 10 or Section 14 of this Privacy Policy.
  • The Service does not respond to ‘Do Not Track’
  • California Business and Professions Code section 22581 allow California residents under the age of 18 who are registered users of online sites, services or applications to request and obtain removal of content or information they have publicly posted. If this applies to you, please contact t us using the details set out at Section 10 or Section 14 of this Privacy Policy. We will action your request to the extent required by
  • California Civil Code Section 1798 (California’s ‘Shine the Light’ law) enables California residents with an established business relationship with us to request information once a year about the sharing of their Personal Data with third parties for direct marketing purposes. If this applies to you, please contact us using the details provided at Section 10 or 14 of this Privacy

 

13.            LGPD Specific Processing

 

If you reside in Brazil, this Privacy Policy applies as follows:

  • Biomorphik is the Controller for your Body Scan Data, Risk Inference Data, and Usage
  • The trusted third parties with whom we share your Personal Data as described in the Privacy Policy are our sub-processors for Usage Data. We enter into data processing agreements with our sub-processors and processors to ensure they only process your Personal Data in accordance with our
  • We only transfer your Usage Data outside of Brazil with your explicit consent or where otherwise permitted by law to do
  • We may share statistics (and other relevant information) relating to your body scan data with third parties when we are liaising with them about the services and products we provide. Where we do so, we will always anonymise your data so that any third parties cannot link it to
  • We have designated a Data Protection Officer, who can be contacted by emailing [email protected]
  • You have the following rights in respect of your Personal Data:
    • You have the right of access to your Personal Data and can request copies of it and information about our processing of it.
    • If the Personal Data we hold about you is incorrect or incomplete, you can ask us to rectify or add to it.
    • Where we are using your Personal Data with your consent, you can withdraw your consent at any

 

 

  • Where we are using your Personal Data because it is in our legitimate interests to do so, you can object to us using it this
  • Where we are using your Personal Data for direct marketing, including profiling for direct marketing purposes, you can object to us doing
  • You can ask us to restrict the use of your Personal Data if:
    • It is not
    • It has been used unlawfully but you do not want us to delete
    • We do not need it anymore, but you want us to keep it for use in legal claims; or
    • if you have already asked us to stop using your data but you are waiting to receive confirmation from us as to whether we can comply with your
  • In some circumstances you can compel us to erase your Personal Data and request a machine-readable copy of your Personal Data to transfer to another service
  • You have the right to review a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects
  • You can withdraw consent. If you withdraw your consent, we may not be able to provide You with access to certain specific functionalities of the
  • You can also raise a complaint with the data protection supervisory authority in the country in which you
  • To exercise your rights in respect of Usage Data you can contact us using the details set out at Section 10 or Section 14 of this Privacy Policy.

 

14.            Our Contact Details

 

You can contact us about this Privacy Policy, to exercise your rights or to complain by writing to: Biomorphik PTY LTD, 38 Gawler Place, Level 2 Rooms 222-225, Adelaide, South Australia 5000.

You can email us about this Privacy Policy at sup[email protected]

 

15.            Updates to this Privacy Notice

 

We will review and update this Privacy Policy from time to time. Please visit this page periodically to check for updates.

This Privacy Policy was last updated on the date shown at the top of this document.

We use cookies to give you the best experience.