Privacy Policy - BodyPark
Privacy Policy
Last Updated: July 9, 2026
This Privacy Policy is issued by ATOMIC AI TECHNOLOGY (HONG KONG) LIMITED. and its affiliates (collectively, "BodyPark", "we", "us", and "our") and is addressed to individuals outside our organization with whom we interact, including customers, visitors to our Sites, users of our Applications and Products, and recipients of any of our services (together, "you" and "your").
Defined terms used in this Privacy Policy are explained in Section 17 below.
This Privacy Policy applies to all of BodyPark's platform, including any specific product, website, or application that references or links to this Privacy Policy.
We may update this Privacy Policy to reflect changes to our information practices. If we make any material changes, we will notify you by email (sent to the e-mail address specified in your account) or by means of a notice on BodyPark's Applications or Sites you used prior to the change becoming effective. All changes shall be effective from the date of publication, unless otherwise provided. We encourage you to periodically review this page for the latest information on our privacy practices.
If you are a resident of the United States, European Economic Area and the United Kingdom, Singapore, or Australia, please pay particular attention to Annex Ⅲ - Supplement Terms – Jurisdiction-Specific, which provides additional information highly relevant to your personal information and specifically outlines how we comply with local laws and regulations.
List of Contents
- Collection of Personal Data
- Creation of Personal Data
- Categories of Personal Data We Collect and Process
- Purpose of Processing
- Legal Basis for Processing
- Disclosure of Personal Data
- Your Privacy Choice
- Children's Policy
- International Transfer of Personal Data
- Data Retention
- Direct Marketing
- Links to Other Websites
- Cookies, Analytics, and Tailor Advertising
- Keep Your Personal Data Safe and Secure
- Contact Us
- Details of Controllers
- Definitions
- Annex Ⅰ – Details of Processing
- Annex Ⅱ - SDKs List
- Annex Ⅲ - Supplement Terms – Jurisdiction - Specific
1. Collection of Personal Data
Depending on how you use our Sites, Applications, Products, or Services, we may collect or obtain Personal Data about you from the following sources:
- Data you provide to us: We obtain Personal Data when you provide those data to us (e.g., when you register an account with us; when you contact us via email, telephone, or by any other means; or when you purchase a Product or Subscription with your credit card).
- Account creation details: We collect or obtain Personal Data when you register or create an account to use any of our Sites or Applications.
- Sites and Application data: We collect or obtain Personal Data when you visit or use any of our Sites or Applications, or use any features or resources available on or through our Sites or Applications.
- Content and advertising information: If you interact with any third-party content or advertising on our Sites and/or Applications (including third-party plugins and cookies), we allow the relevant third-party providers to collect your Personal Data relating to your interaction with that content or advertising, and we receive some or all of this Personal Data from the relevant third-party provider relating to your interaction with that content or advertising.
- Data you make public: We may collect the Personal Data content you publish, or otherwise manifestly make public, including comments you make about us, through our Applications and other platforms, your social media, or any other publicly available platforms.
- Third-party information: We collect or obtain Personal Data from third parties who provide it to us (e.g., single sign-on providers and other authentication services you use to connect to our services, third-party providers of integrated services, third-party providers of social media services, other BodyPark customers, business partners, Processors, and law enforcement authorities).
- Data automatically collected: We and our third-party partners automatically collect information you provide to us and information about how you access and use our Sites, Applications, Products, or other services when you visit our Services, read our emails, or otherwise engage with us. We typically collect this information through a variety of tracking technologies, including (i) cookies or small data files that are stored on an individual's computer and (ii) other related technologies, such as web beacons, pixels, mobile SDKs, location-identifying technologies, and logging technologies (collectively, "tracking technologies") and we may use third-party partners or technologies to collect this information. Information we collect automatically about you may be combined with other personal information we collect directly from you or receive from other sources.
For more information on which data we collect, please also refer to the table in Annex Ⅰ – Details of Processing.
2. Creation of Personal Data
We also create Personal Data records about you in certain circumstances, such as records of your usage, records of your interactions with us. We may also link Personal Data collected from any of our Sites, Applications, Products, or services, including where those data are collected from different devices.
3. Categories of Personal Data We Collect and Process
When you first register for a BodyPark account, we may collect the following categories of Personal Data about you: username and password, email addresses, and/or phone numbers. After successfully creating your BodyPark account, you can use it to log in across BodyPark's Application.
When using our Sites, Applications, Products, or other services, we may also collect and/or process the following categories of Personal Data about you:
- Contact information: Including your email address, mailing address, phone number, and communication preferences, all of which you have voluntarily provided.
- Profile information: Including your user name, email address, date of birth/age, gender, height and weight, image or avatar, language, and country/region, all of which you have voluntarily provided, along with the records of your usage (including without limitation workout videos you have authorised to be recorded, the total number of exercises you have taken, and the dates you took those exercises).
- Transaction information: including records of purchases and prices, consignee first and last name, shipping address and contact information, shipment tracking details, details of returns, and warranty details, when you place orders on our Sites.
- Payment details: such as invoice/payment records, payment amount, payment date, billing address, and payment method, when you place orders on our Sites. Please note that we use third-party payment providers, including Stripe and PayPal, to process payments made to us. We do not receive or retain any personally identifiable financial information such as payment card numbers; rather, all such information is provided directly by you to our third-party payment providers. The payment provider's use of your personal data is governed by their privacy policy.
- Information collected from third-party authentication services or other third-party accounts you link to our services: Our Sites, Applications, Products, or services may allow you to log in through a third-party social network or authentication service, such as Apple and Google. When you use these single sign-on services to access our Sites, Applications, Products, or services, we do not receive your login credentials for the relevant third-party service. Instead, we receive tokens from the single sign-on service to help identify you in our system (such as by your username) and confirm that you successfully authenticated with the single sign-on service. In addition to authenticating your identity, these services will, in most cases, provide you with the option to share certain Personal Data with us, which could include your name, email address, or other information in your public profile (e.g., profile picture, age range, gender, language, country). The data we receive is dependent on that third party's policies and your privacy settings on that third-party site.
- Product-specific information: Our Services depend on our fitness device (BodyPark ATOM, a fitness companion, the "Product"), and only when the Product is bound to our Application can you fully use our services. Therefore, during Product binding and use, we will also collect the following product-specific information:
- Location information: We may request access to your location permission to activate your Product and establish your Bluetooth connection.
- Fitness and movement data: When you use the Services, we may collect your heart rate, calories burned, and exercise taken gathered by any digital device (such as a heart rate monitor, a smart bracelet) that you have connected to the Product, exercise taken, fitness performance history (including workout history, such as hours spent on workouts, days spent on workouts, and times of workouts), movement data (including movement distance, range of motion, strength output, and training intensity, and speed with every rep), and details and additional fitness information that you choose to link to or share with us through the Services.
- Visual image; skeleton motion and posture information: The Product may contain a camera feature. When you participate in workouts, we may capture your visual image, according to which we would be able to calculate and analyze your skeleton motion and posture information and provide various kinds of exercise feedback (such as exercise scores, video playback for review after each set) based on our use of artificial intelligence technologies. Please do not that we will not store the relevant visual image after the aforementioned skeleton motion and posture calculation and analysis.
- Video data: When you authorize access to the camera and microphone features of your ATOM, you are deemed to agree that ATOM will record your workout video during training. The workout video you have authorized to be recorded remains entirely under your control and is stored in your cloud storage space. You retain the right to decide whether to retain or delete such videos. We will not store your workout videos.
This skeleton motion, posture information, and video data mentioned above, may constitutes biometric data under applicable law (including the GDPR). We will only process this data based on your explicit consent, which you will be asked to provide via a prominent pop-up when you first enable the camera or/and microphone features. You may withdraw your consent at any time via your Product permission settings or by contacting us at cs@bodypark.fit. Withdrawal of consent does not affect the lawfulness or processing based on consent before withdrawal.
Please be advised that the camera feature is integral to the core data processing required for the Product's analytical features. Without access, these advanced features will be unavailable, limiting your training insights.
- Information you provide: When you use the generative artificial intelligence service, we provide you with dialogue and interaction services based on generative artificial intelligence model technology. You can send us text, pictures, voice, and other content through the dialog box or click the operation bar button to directly send an operation command request and have conversations or interactions with the artificial intelligence model. We will automatically receive the above information to provide you with intelligent dialogue in text and voice form. Please note that in order to provide AI services, these instruction requests will be uploaded to the cloud server.
- Information from third parties: If you connect your Apple Health account through the "Apple Health" feature, we may receive additional health data, such as real-time heart rate, energy expenditure, and calorie data, related to you.
- Log data: Such as device status, event logs, error and fault logs, maintenance logs, and security logs.
4. Purpose of Processing
We use your Personal Data for the following purposes and as otherwise described in this Privacy Policy or at the time of collection.
Service Delivery.
We may use your Personal Data to:
- provide, deliver, and customize your use of the Services (i.e., to provide real-time feedback, to deliver an in-depth report after each session);
- provide you with the Services and any products that you purchase from us;
- generally manage individual information and accounts;
- to communicate with you about the Services, including regarding the status of any orders for the Services and to respond to your inquiries, including for customer support;
- understand your needs and interests, and personalize your exercise and activity plans for you based on your settings and your historical exercise or activity data;
- provide support and maintenance for the Services.
Research and Development.
We may use Personal Data for research and development purposes, including analyzing and improving our existing products and the Services or developing new products and the Services. As part of these activities, we may create aggregated, de-identified, or other anonymous data by removing information that makes the data personally identifiable to you. We may use this anonymous data and share it with third parties for our lawful business purposes, including to analyze and improve the Services and promote our business.
Marketing and Advertising.
We may use Personal Data to provide you with materials about offers, products, and the Services that may be of interest, including new content or services. We may provide you with these materials by phone, postal mail, text, or email, as permitted by applicable law. Such uses include:
- to tailor content, advertisements, and offers;
- to notify you about offers, products, and services that may be of interest to you or about which you have previously expressed an interest;
- for other purposes as otherwise disclosed at the time of collection.
You may contact us at any time to opt-out of the use of your Personal Data for marketing purposes, as further described in Section 7 below.
Compliance and Protection.
We may use your Personal Data to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities;
- protect our, your, or others' rights, privacy, safety, or property (including by making and defending legal claims);
- enforce the terms and conditions that govern the Services; and
- prevent, identify, investigate, and deter fraudulent, harmful, unauthorized, unethical, or illegal activity, including cyberattacks and identity theft.
Automated Decision-making/Profiling.
We may perform automated analysis and profiling based on your fitness data, exercise history, preferences, and performance to generate personalized training plans, exercise scores, and feedback for you. This constitutes automated decision-making/profiling. The logic of this processing is based on your historical exercise performance, goal settings, and movement data. You have the right to object to such processing at any time by contacting us at cs@bodypark.fit. If you exercise this right, you may not be able to receive personalized training recommendations or feedback.
Fulfill any other purpose for which you provide your personal data, or for which you have otherwise consented.
You can find more information about how we Process your Personal Data in the table in Annex I.
5. Legal bases for Processing
The legal bases on which we rely for the processing of Personal Data are as follows:
Perform our contractual services or prior to entering into a contract with you:
If you order products or services from us or if you contact us to request our products or services, we use your Personal Data to provide you with these products or services, including for account and contract management, to facilitate user benefits and services, including customer support and process payment for our products and services or with information that may be relevant for you to decide on whether you want to order our products and services.
Justified by our legitimate interests:
The usage of your Personal Data may also be necessary for our own business interests. For example, we may use some of your Personal Data to update and monitor the services, or diagnose or fix technology problems; help maintain the safety, security, and integrity of our property and services, technology assets, and business; enforce our terms, resolve disputes, carry out our obligations, and enforce our rights, and protect our business interests and the interests and rights of third parties; and prevent, investigate, or provide notice of fraud or unlawful or criminal activity.
Consent:
In some cases, we may ask you to grant us separate consent to use your Personal Data. In this case, you can revoke your consent at any time with effect for the future.
Compliance with legal obligations:
We are obligated to collect or retain certain Personal Data because of legal requirements, for example, tax or commercial laws, or we may be required by law enforcement to provide Personal Data on request.
You can find more information on the legal basis in the table in Annex I.
6. Disclosure of Personal Data
We may also share, transmit, disclose, grant access to, make available, and provide Personal Data with and to third parties, as described below.
- you and, where appropriate, your appointed representatives.
- BodyPark affiliates: We share Personal Data amongst the legal entities that make up the Group Company, for legitimate business purposes and the operation of our Sites, Applications, Products, and services for you, in accordance with applicable law. These legal entities may use your Personal Data in the manner described in this Privacy Policy.
-
As required by law: We may disclose Personal Data to third parties, such as legal advisers and law enforcement agencies, regulations, other authorities, and other third parties for legal reasons if we reasonably believe in good faith that such action is necessary:
- in connection with the establishment, exercise, or defense of legal claims;
- to comply with laws or to respond to lawful requests and legal process;
- to protect our rights and property and the rights, personal safety, and property of others, including to enforce our agreements and policies;
- to detect, suppress, or prevent fraud or other criminal activity; or
- as otherwise required by applicable law.
- Third-party Processors: We share Personal Data with third-party contractors and service providers subject to reasonable confidentiality terms, such as email service providers; marketing/advertising service providers; call service providers; payment service providers; shipping companies; and postal carriers, subject to the requirements noted below in this Section 6. These Processors support us in processing the types of Personal Data described above in Sections 1–3, and for the purposes described in Section 4. They are only authorized to process that information as necessary and as directed by us;
- Third-party AI Providers: To enable AI voice conversations, some data (such as voice recordings and transcribed text messages) may be securely processed by trusted third-party AI providers. To be specific, your voice recordings will be sent to the Google Speech-to-Text Cloud Service to convert speech into text; the transcribed text message will be sent to Google Gemini to generate AI responses.
- Advertising networks and partners: To efficiently market our products and services to you, including to deliver advertising and personalize content on our Sites, Applications, products, and services, on other websites and services, and across other devices, we may share Personal Data with advertising networks and partners. These parties may collect information automatically from your browser or device when you visit our websites and other services through the use of cookies and similar technologies. This information is used to provide and inform targeted advertising, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research. For more information about how these technologies work and the choices you may have in relation to these technologies, please refer to Section 13 below;
- Business and marketing partners: We may also disclose Personal Data with other business and marketing partners with whom we jointly offer products or services or who are part of our partner program. We may obtain your consent where required by applicable law;
- Independent advisors: We may disclose Personal Data to our independent advisors, such as accountants, auditors, consultants, lawyers, and other outside professional advisors to BodyPark, subject to binding contractual or statutory obligations or statutory confidentiality obligations.
- Corporate transactions: if BodyPark is involved in a corporate business transaction, such as a merger, acquisition, or sale of all or a portion of our company assets, we may disclose Personal Data to a third party during negotiation of, in connection with, or as an asset in such a corporate business transaction. If BodyPark completes such a corporate business transaction, you will be notified via email and/or a prominent notice on our website of any change in ownership, uses of your Personal Data, and choices you may have regarding your Personal Data. Personal Data may also be disclosed in the event of insolvency, bankruptcy, or receivership; and
- Third-party services integrated in our services: We use third-party software development kits ("SDKs") as part of the functionality of our Services. Your interactions with SDKs are governed by the privacy policy of the respective service providers. For more information on the SDKs in the table in Annex Ⅱ - SDKs List.
- Other Disclosures We may also disclose your Personal Data to any other third party or publicly with your prior consent or direction.
If we engage a third-party Processor to Process your Personal Data, the Processor will be subject to binding contractual obligations to: (i) only Process the Personal Data in accordance with our prior written instructions; and (ii) use measures to protect the confidentiality and security of the Personal Data; together with any additional requirements under applicable law. Please note that third parties and business partners may process your Personal Data in accordance with their own privacy policies and terms of service.
7. Your Privacy Choice
Subject to applicable laws, you may have the following rights regarding the Processing of your Personal Data:
- the right not to provide your Personal Data to us (however, please note that we may be unable to provide you with the full benefit of our services if you do not provide us with your Personal Data – e.g., we might not be able to process your requests without the necessary details);
- the right to request access to, or copies of, your Relevant Personal Data, together with additional information, such as information regarding the nature, Processing and disclosure of those Relevant Personal Data;
- the right to request rectification of any inaccuracies or incompleteness in your Relevant Personal Data;
- the right to request, on legitimate grounds, restriction of Processing of your Relevant Personal Data (limiting the purposes for which we Process your Personal Data);
- the right to have certain Relevant Personal Data transferred to another location, in a structured, commonly used, and machine-readable format, to the extent applicable;
- the right to request the deletion or removal of your Relevant Personal Data where there is no other legal basis for us to keep using it. Please note that we may not be able to immediately remove the information from the backup system due to applicable laws and regulations or technological limitations. If this is the case, we will isolate your Relevant Personal Data from any further processing until the backup can be deleted or be anonymized / deidentified;
- where we Process your Relevant Personal Data on the basis of your consent, the right to withdraw that consent at any time (noting that such withdrawal does not affect the lawfulness of any Processing performed prior to the date on which we receive notice of such withdrawal).
To exercise one or more of these rights, or to ask a question about these rights or any other provision of this Privacy Policy, or about our Processing of your Personal Data, please use the contact details provided in Section 15 below. Please note that:
- in some cases, it will be necessary to provide evidence of your identity before we can give effect to these rights; and
- where your request requires the establishment of additional facts (e.g., a determination of whether any Processing is non-compliant with applicable law) we will investigate your request reasonably promptly, before deciding what action to take.
Please do note that if we perform some of the requests above, for example, withdrawal of consent, right of erasure, objection to processing, etc, we may no longer be able to provide you with certain services, which may include any requests for technical support, warranty, or otherwise. Our legal rights are hereby expressly reserved.
Please give us at least thirty (30) days to process each request.
8. Children's Policy
Our Services are not directed to children under the age of 13. In addition, you are not permitted to use our Services if you do not meet the minimum age requirement applicable to our Services in your jurisdiction. We do not knowingly collect personal information from children under the age of 13. If you learn that your child has provided us with personal information without your consent, you may alert us at cs@bodypark.fit. If we learn that we have collected personal information of a child under the age of 13 (or under the age of 16 in certain jurisdictions), we will take steps to delete such information from our files as soon as possible and terminate the child's account unless we receive verifiable parental consent.
9. International Transfer of Personal Data
Because of the international nature of our business, we transfer Personal Data within the BodyPark group, and to third parties as noted in Section 6 above, in connection with the purposes set out in this Privacy Policy. For this reason, we transfer Personal Data to other countries that may have different laws and data protection compliance requirements than those that apply in the country in which you are located, including China and the US.
In the event of a transfer by BodyPark, we ensure that international transfers of your Personal Data are made pursuant to appropriate safeguards to ensure that the Personal Data is only transferred to countries recognized as Adequate Jurisdictions.
If you wish to enquire further about these safeguards, including the specific contracts entered into or used, please contact us using the details set out under Section 15 of this Privacy Policy.
10. Data Retention
We have implemented processes designed to ensure that your Personal Data are only processed for the minimum period necessary for the purpose set out in this Privacy Policy. The criteria for determining the duration for which we will retain your Personal Data are as follows:
We will retain Personal Data in a form that permits identification only for as long as:
- we maintain an ongoing relationship with you (e.g., where you are a user of our services, or you are lawfully included in our mailing list and have not unsubscribed); or
- your Personal Data are necessary in connection with the lawful purposes set out in this Privacy Policy, for which we have a valid legal basis (e.g., where your Personal Data are included in a contact between you and us, and we have a legitimate interest in Processing those Personal Data for the purposes of operating our business and fulfilling our obligations under that contract; or where we have a legal obligation to retain your Personal Data).
the duration of:
- any applicable limitation period under applicable law (i.e., either any statutory retention periods as required by the law of the applicable region (e.g., the European Union or a member state of the EEA), or any period during which any person could bring a legal claim against us in connection with your Personal Data, or to which your Personal Data are relevant); and
- an additional two (2) month period following the end of such applicable limitation period (so that, if a person brings a claim at the end of the limitation period, we are still afforded a reasonable amount of time in which to identify any Personal Data that are relevant to that claim).
In addition, if any relevant legal claims are brought, we continue to Process Personal Data for such additional periods as are necessary in connection with that claim.
During the periods noted in 10.1.2 above, we will restrict our Processing of your Personal Data to storage of, and maintaining the security of, those data, except to the extent that those data need to be reviewed in connection with any legal claim, or any obligation under applicable law.
Once the periods in 10.1 above, each to the extent applicable, have concluded, we will either:
- permanently delete or destroy the Relevant Personal Data; or
- anonymize or deidentify the Relevant Personal Data.
11. Direct Marketing
We Process Personal Data to contact you via email, telephone, SMS, EMS, direct mail, or other communication formats to provide you with information regarding Sites, Applications, Products, and services that may be of interest to you. If we provide Sites, Applications, Products, or services to you, we may send or display information to you regarding our Sites, Applications, Products, or services, upcoming promotions, and other information that may be of interest to you, including by using the contact details that you have provided to us, or any other appropriate means, subject always to obtaining your prior opt-in consent to the extent required under applicable law. Please note that we may track your opening and clicking behavior.
You may unsubscribe from specific promotional email campaigns at any time by simply clicking on the unsubscribe link included in every promotional electronic communication we send. After you unsubscribe, we will not send you further promotional emails in connection with the email campaigns you have unsubscribed from, but in some circumstances we will continue to contact you to the extent necessary for the purposes of providing any Sites, Applications, Products, or services you have requested or in connection with any email campaigns to which you remain subscribed.
You may unsubscribe from specific promotional text campaigns at any time by replying STOP or R via text message to any of the promotional text communications we send in relation to the specific campaign you would like to opt out from. After you unsubscribe, we will not send you further promotional text messages in connection with the text campaigns you have unsubscribed from, but in some circumstances, we will continue to contact you to the extent necessary for the purposes of providing any Sites, Applications, Products, or services you have requested or in connection with any text campaigns to which you remain subscribed.
12. Links to Other Websites
This Privacy Policy applies only to BodyPark practices, technologies, and services. Our online properties may include links to websites and online services that are operated by other companies not under the control or direction of BodyPark. If you provide or submit Personal Data to those websites or online services, the privacy policies on those websites or online services apply to your Personal Data. We encourage you to carefully read the privacy policies of any website you visit.
13. Cookies, Analytics and Tailor Advertising
BodyPark and its third-party partners and providers use cookies and similar technologies to automatically collect certain Personal Data when you visit or interact with our Sites, Applications and services to enhance navigation, analyze trends, administer the Sites, track users' movements around the Sites, gather demographic information about our user base as a whole, and assist with our marketing efforts and customer service. You can control the use of cookies at the individual browser level, but if you choose to disable cookies, it may limit your use of certain features or functions on our Sites and services.
You may stop or restrict the placement of cookies on your computer or remove them from your browser by adjusting your web browser preferences. Please note that cookie-based opt-outs are not effective on mobile applications. However, on many mobile devices, application users may opt-out of certain mobile advertisements via their device settings. These cookie preference manager tools are website, device, and browser specific, so you will need to change your preferences on each device and browser you use when interacting with the specific Site you are visiting. You can also stop all collection of information via our web services by not using our Sites and services.
You may also be able to utilize third-party tools and features to further restrict our use of cookies and similar technologies. For example, cookies may generally be disabled or removed by tools available as part of most commercial browsers, and in some instances blocked in the future by selecting certain settings. Browsers offer different functionalities and options, so you may need to set them separately. In addition, you may be able to exercise specific privacy choices, such as enabling or disabling certain location-based services, by adjusting the permissions in your mobile device or internet browser.
The online advertising industry also provides websites from which you may opt-out of receiving targeted ads from our data partners and our other advertising partners that participate in self-regulatory programs.
For a detailed list of the specific cookies, web beacons, and similar tracking technologies we use, including the name, provider, type, and purpose of each, please refer to our separate Cookie Notice, which is incorporated into this Privacy Policy by reference.
14. Keep Your Personal Data Safe and Secure
All BodyPark Products are built with strong security features that continuously protect your information. The insights we gain from maintaining our services help us detect and automatically block security threats from ever reaching you. And if we do detect something risky that we think you should know about, we'll notify you and help guide you through steps to stay better protected.
We work hard to protect you and BodyPark from unauthorized access, alteration, disclosure, or destruction of information we hold, including:
- We use encryption to keep your data private while in transit.
- We offer a range of security features, like Safe Browsing, Security Checkup, and 2 Step Verification to help you protect your account.
- We review our information collection, storage, and processing practices, including physical security measures, to prevent unauthorized access to our systems.
- We restrict access to personal information to BodyPark employees, contractors, and agents who need that information in order to process it. Anyone with this access is subject to strict contractual confidentiality obligations.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant data protection authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with applicable law (including Article 34 of the GDPR).
15. Contact Us
We value your opinions. If you have any questions or comments about our Privacy Policy or questions or concerns about the use of your personal information, please contact us by email at cs@bodypark.fit or postal mail at the below address:
ATOMIC AI TECHNOLOGY (HONG KONG) LIMITED
Attn: Legal Department
Room 6706, Central Plaza, 18 Harbour Road, Wanchai, Hong Kong, China
Email: legal@fiture.com
16. Details of Controllers
Your Personal Data is controlled by the BodyPark Group company located in your region. The following entities are responsible for processing your data:
| Controller entity | Contact details |
|---|---|
| Fiture Holding LLC | 1013 Centre Road, Suite 403S Wilmington, Delaware 19805 United States |
| ATOMIC AI TECHNOLOGY (HONG KONG) LIMITED | Room 6706, Central Plaza, 18 Harbour Road, Wanchai, Hong Kong, China |
| Chengdu Fiture Technology Co., Ltd. | Room 6, 9th Floor, Block E3, Building 1, No. 1268, Middle Section of Tianfu Avenue, Chengdu High-tech Zone, China (Sichuan) Pilot Free Trade Zone |
With respect to the processing of Personal Data through our Site, Applications, and Products, these entities may both access your Personal Data and determine the means and purposes of the processing. Therefore, they are jointly responsible for such processing. If there is no BodyPark entity established in your region, your Personal Data will be controlled by ATOMIC AI TECHNOLOGY (HONG KONG) LIMITED, which processes your data on behalf of the BodyPark Group.
If you are a user outside China or the United States, your Personal Data will be uniformly processed by ATOMIC AI TECHNOLOGY (HONG KONG) LIMITED and stored on Google Cloud (operated by Google LLC, located in the United States). We have ensured that we have entered into agreements with Google LLC in compliance with the applicable laws.
To provide our products and services, the Data Controllers listed above may engage other BodyPark Group entities to process your Personal Data strictly on their behalf and under their documented instructions. These intra-group service providers, acting as Data Processors, include our entities headquartered in Hong Kong, China that provide global services such as product research, data operations, and customer support. This relationship is governed by a robust intra-group Data Processing Agreement designed to ensure that your Personal Data is protected in accordance with applicable laws and to the highest standards.
17. Definitions
- "Personal Data" means information that is about any individual, or from which any individual is directly or indirectly identifiable, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that individual.
- "Relevant Personal Data" means Personal Data in respect of which we are the Controller.
- "Biometric Data" means personal data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person, which allows or confirms the unique identification of that natural person, such as facial images or dactyloscopic data.
- "Site" means any website operated, or maintained, by us or on our behalf. In particular, our product sales websites: https://bodyparkatom-6c6986085f02816acfb3.o2.myshopify.dev/
- "Application" means the "Atom Fitness" and any applications operated, or maintained, by us or on our behalf.
- "Product" means any product operated, or maintained, by us or on our behalf. In particular, the BodyPark Atom, a fitness companion.
- "Cookie" means a small file that is placed on your device when you visit a website (including our Sites). In this Privacy Policy, a reference to a "Cookie" includes analogous technologies such as web beacons.
- "Process", "Processing" or "Processed" means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction.
- "Processors" means any person or entity that Processes Personal Data on behalf of the Controller (other than employees of the Controller).
- "Controller" means the entity that decides how and why Personal Data are Processed. In many jurisdictions, the Controller has primary responsibility for complying with applicable data protection laws.
- "Adequate Jurisdiction" means a jurisdiction that has been formally designated by the European Commission as providing an adequate level of protection of Personal Data.
- "Data Protection Authority" means an independent public authority that is legally tasked with overseeing compliance with applicable data protection laws.
- "EEA" means the European Economic Area (Member States of the European Union together with Iceland, Norway, and Liechtenstein).
- "GDPR" means the General Data Protection Regulation (EU) 2016/679.
- "Standard Contractual Clauses" means template transfer clauses adopted by the European Commission or adopted by a Data Protection Authority and approved by the European Commission.
Annex Ⅰ - Details of Processing
| Processing activity and Processed Personal Data | Purposes | Legal basis for Processing |
|---|---|---|
|
Provision of Sites or Applications: IP address Website from which access occurred Unique identifiers (UUID), Open ID Mobile model Browser used (incl. type, ID and configuration) and your browser settings |
To ensure we can provide a smooth connection to our Sites or Applications. To ensure users can comfortably use our Sites or Applications. To assess system security and stability. |
The Processing is necessary to enter into or perform a contract with you; and/or Our legitimate interest is to provide secure, needs-based Sites or Applications. |
|
Creating user accounts and managing user profiles: Email address, or Phone numbers Passwords Other user profiles: such as user name, date of birth / age, gender, height, weight, avatar, language preference, country/region |
Provision of a user account, with address management, and order overview. Organization of the email-preferences. Security of the account. Evaluation of user profiles and engagement levels. |
The Processing is necessary to enter into or perform a contract with you, or Where separately indicated, the Processing is based on your consent. |
|
Logging in via a Google / Apple Account: Information collected from a Google Account or an Apple Account is linked to your services. The data we receive is dependent on that third party's privacy settings. |
To provide account login services. | The Processing is necessary to enter into or perform a contract with you. |
|
Transaction and Payment: Transaction information: records of purchases and prices, consignee first and last name, shipping address and contact information, shipment tracking details, details of returns, and warranty details. Payment information: payment amount, payment date, billing address, and payment method. |
Receiving remuneration that we are owed. Fulfilling the orders / contracts concluded with you. Enabling you to utilize our products and services. Responding to returns and/or warranty claims. Processing financing applications. Contacting you in relation to your orders and returns. Documentation and compliance with accounting obligations. |
The Processing is necessary for to enter into or perform a contract with you. |
|
Activating products, binding products to Applications: Information about your device and network: such as mobile brand, mobile model, operating system, IP address, browser type, device type, device name, device ID. |
To ensure users can use our Applications to connect, control, and operate the Product you have purchased. Providing you with product-related services. |
The Processing is necessary to enter into or perform a contract with you, or Where separately indicated, the Processing is based on your consent. |
|
Engaging in events, promotions, and surveys: Information you provide when you sign up for an event, enter a promotion activity, complete a survey, or submit a testimonial. |
To enhance the user experience. Improving products and services. Tailoring marketing strategies, and Establishing effective communication with participants. |
The Processing is based on your consent. |
|
Contacting us: user name / user ID phone number email address mailing address, and communication preferences |
Processing of your request. Performance of the communication. Analyzing errors and improving our services. |
Depending on the reason you are contacting us: The Processing is necessary to enter into or perform a contract with you, or Our legitimate interests in responding to customer inquiries. |
|
Support and Warranty Application: E-mail address Order number, or a screenshot of the order or receipt (if any) The contents of custom messages sent through the forms, email addresses, or channels |
Verification of the warranty claim. Implementation of the warranty claim. Documentation of the defect. |
The Processing is necessary to enter into or perform a contract with you |
|
Live Chat with Support: User name E-mail address Contents of the chat |
Provision of the live chat. Security of the live chat. Feedback on and improvement of our products. |
The Processing is necessary to enter into or perform a contract with you, or Our legitimate interest in providing a live chat. |
|
Comments and opinions, if they are expressed directly to us or if you publicly post about us: Communications data, depending on the method of contact. Your comments and opinions. |
Responding to and addressing your queries, issues, and concerns, Improving our products and services Informing our marketing strategies |
Our legitimate interests, namely communicating with current or prospective customers and others about our products and services. |
|
Notification of changes, product security communications, and product recalls: Name E-mail address Address (including region) Phone number Information about the communication we made to you and any following communications. |
Informing you about changes or security communications. Notification of the need for a product recall and the manner in which such a recall will be conducted. |
Depending on the reason you are contacting us: The Processing is necessary to fulfil a legal obligation, or The Processing is necessary to perform a contract with you. |
|
Analyzing trends, usage, and activities: Country Information about your application, device, and network: this includes the mobile name, mobile brand, mobile model, operating system, IP address. |
Analyzing trends, usage, and activities to address errors and optimize performance for a better user experience. | The Processing is based on your consent. To manage it, adjust the "Share App Analytics" and "Share Device Analytics" settings (if available). |
|
Maintaining IT security (including audits): IP address of the requesting computer or phones, Date and time of access, Name and URL of the accessed file, Website from which access occurred (referrer URL), Browser used (incl. type and configuration) and your browser settings. |
To ensure users can comfortably use our Sites, products, and services. To assess system security and stability. Finding and eliminating security vulnerabilities. Adapting the Sites, products, and services to the needs of our users. |
The Processing is necessary to enter into or perform a contract with you, and/or Our legitimate interests in ensuring the safety of our Sites, products, and services. |
|
Legal: All of the above. |
Complying with regulatory obligations, Litigation, Exercise, enforcement, and defense of claims |
The Processing is necessary for our legitimate interest in compliance with regulatory obligations and the exercise, enforcement, and defense of claims |
Annex Ⅱ - SDKs List
We use third-party software development kits ("SDKs"), as part of the functionality of our Services; the SDKs we use include:
- Volcano Engine Streaming Speech Recognition SDK, which was developed by Beijing Volcano Engine Technology, whose privacy policy is available at: https://www.volcengine.com/docs/6561/108794?lang=en;
- Tencent Real-Time Communication (TRTC), which was developed by Tencent RTC, whose privacy policy is available at: https://trtc.io/document/48827.
Annex Ⅲ - Supplement Terms – Jurisdiction - Specific
UNITED STATES
The following disclosures supplement the information contained in the main body of our Privacy Policy by providing additional information about our Personal Data processing practices relating to individual residents of certain states in the United States, including the states of California, Nevada, Colorado, Connecticut, Montana, Oregon, Texas, Utah, and Virginia in the United States. For a detailed description of how we collect, use, disclose, and otherwise process Personal Data, please read the main body of our Privacy Policy.
Collection and Use of Personal Data
Personal Data
As described in more detail in Section 3 above, we collect, and have collected in the preceding 12 months, the following categories of Personal Data:
- Identifiers, such as a phone number, email address, mailing address, user ID, and online identifiers.
- Customer records, such as account information.
- Protected classification characteristics, such as date of birth/age, gender, height and weight.
- Commercial information, such as records of purchases and prices, shipping addresses and contact information, and details of returns, and consumer histories and tendencies.
- Internet / network information, such as the device type, model, operating system, IP address, browser type, Internet service provider, and unique identifiers associated with you, your device, or your network.
- Audio, visual, or similar information, including voice prompts and services avatars, and workout videos.
- Sensitive Personal Data, such as account credentials, biometric information, and health data (as further described below).
- Other Personal Data, such as your communication preferences, language preferences, and any other Personal Data you choose to share in custom messages sent through the forms, email address, or other contact information we make available to customers.
As described in Section 1 above, we collect Personal Data directly from you, automatically when you interact with our Sites, Applications, Products, or other services, from third parties, and from public third-party platforms such as social media websites.
We collect Personal Data from and about you for a variety purposes. For example, we use Personal Data to communicate with you; to facilitate, process, and fulfill orders you place with us or the services you request; to conduct surveys, sweepstakes, or promotions; to analyze and improve the use of our Sites, Applications, and Products; to deliver marketing communications and personalized and non-personalized advertising; and to facilitate our customer service. For more information about our use of Personal Data, please refer to Section 4 above.
Sensitive Personal Data
The following Personal Data elements we collect or are otherwise processed in connection with our Sites, Applications, Products, or services may be classified as "sensitive" under certain privacy laws ("Sensitive Personal Data").
- Account credentials.
- Payment card information (collected and processed solely by our third-party payment providers, including Stripe and PayPal; BodyPark does not have access to this data).
- Biometric information, such as the visual image and your workout video, are processed and maintained solely on the user's ATOM and entirely under the user's control. BodyPark does not have access to this data.
- Health metrics, including height, weight, heart rate, movements, and training history.
- Precise geolocation data.
We only use or disclose Sensitive Personal Data where reasonably necessary and proportionate, and where permitted by law, for the purposes of performing services you have requested, verifying and improving the services we provide, detecting security incidents, fraud, and other illegal actions, ensuring the physical safety of natural persons, performing services on behalf of the business, or short-term transient use. We only collect and process Sensitive Personal Data without the purpose of inferring characteristics about the relevant individual, and we do not sell Sensitive Personal Data or process or otherwise share Sensitive Personal Data for the purpose of targeted advertising (as further described below).
However, depending on your state of residency and subject to certain legal limitations and exceptions, you may be able to limit, or withdraw your consent for, our processing of Sensitive Personal Data (as described in the Your Additional U.S. Privacy Choices section below).
Deidentified information
We may at times receive or process Personal Data to create deidentified information that can no longer reasonably be used to infer information about, or otherwise be linked to, a particular individual or household. Where we maintain deidentified information, we will maintain and use the information in deidentified form and not attempt to reidentify the information except as required or permitted by law.
Personal Data Disclosures, Sales, and Targeted Advertising
We may disclose the categories of Personal Data above to the following categories of third parties: the entities that make up the BodyPark Group, Processors, ad networks and advertising partners, business and marketing partners, third-party providers with services integrating with our services, individuals you choose to share Personal Data with, and certain third parties where you have provided consent or where otherwise required or permitted by law. Please see Section 6 for more detail.
Please be aware that we will not transfer your Sensitive Personal Data to any third parties, including advertising platforms, data brokers, or information resellers, for purposes other than providing or improving the use case or features of our Sites, Applications, Products, or services, without your consent.
Based on our understanding of the term "sell" under the CCPA (California Consumer Privacy Act of 2018), we do not "sell" your Personal Information and have not sold it to third parties for a business or commercial purpose in the 12 months preceding the effective date of this Privacy Policy. However, like many companies online, we may disclose your identifiers, customer records, commercial information, internet/network information, and inferences to ad networks and advertising partners, such as Google and Facebook, to help deliver interest-based ads to you (otherwise known as "targeted advertising").
Depending on your state of residency and subject to certain legal limitations and exceptions, you may be able to limit or opt-out of the processing of Personal Data for purposes of targeted advertising (as described in the Your Additional U.S. Privacy Choices section below).
Your Additional U.S. Privacy Choices
Depending on your state of residency and subject to certain legal limitations and exceptions, you may be able to exercise some or all of the following rights:
-
Right to Know: the right to confirm whether we are processing Personal Data about you and, under California and Oregon law only, to obtain certain personalized details about the Personal Data we have collected about you for the preceding 12 months, including:
- The categories of Personal Data collected;
- The categories of sources of the Personal Data;
- The purposes for which the Personal Data were collected;
- The categories of Personal Data disclosed to third parties (if any), and the categories of recipients to whom this Personal Data were disclosed (or, for Oregon residents only, a list of the specific third parties to whom personal data have been disclosed);
- The categories of Personal Data shared for targeted advertising purposes (if any), and the categories of recipients to whom the Personal Data were disclosed for these purposes; and
- The categories of Personal Data sold (if any) and the categories of third parties to whom the Personal Data were sold.
- Right to Access & Portability: the right to obtain access to the Personal Data we have collected about you and, where required by law, the right to obtain a copy of the Personal Data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance.
- Right to Correction: the right to correct inaccuracies in your Personal Data, taking into account the nature of the Personal Data and the purposes of the processing of the Personal Data.
- Right to Control Over Sensitive Personal Data: the right to exercise control over our collection and processing of certain Sensitive Personal Data.
- Right to Opt-Out of Targeted Advertising: the right to direct us not to use or share Personal Data for certain targeted advertising purposes.
- Right to Opt-Out of Sales: the right to direct us not to sell Personal Data to third parties.
- Right to Deletion: the right to have us delete Personal Data we maintain about you (subject to certain exceptions).
Depending on your state of residency, you may also have the right not to receive retaliatory or discriminatory treatment in connection with a request to exercise the above rights. However, the exercise of the rights described above may result in a different price, rate, or quality level of product or service where that difference is reasonably related to the impact the right has on our relationship or is otherwise permitted by law.
Submitting Privacy Rights Requests
Please submit a request specifying the right you wish to exercise by sending us an email at the following address: cs@bodypark.fit. We will acknowledge receipt of your request within 10 business days and begin processing it within 45 days.
Before processing your request to exercise certain rights (including the Right to Know, Access & Portability, Correction, Control and Deletion), we will need to verify your identity and confirm you are a resident of a state that offers the requested right(s). In order to verify your identity, we will generally either require the successful authentication of your account, or the matching of sufficient information you provide us to the information we maintain about you in our systems. As a result, we require requests submitted through our email address to include the requester's name and email address, their relationship with BodyPark, the products relevant to the request, and the data subject's email address, state/country/zip, and any comments relating to the request.
In certain circumstances, we may decline or limit your request, particularly where we are unable to verify your identity or locate your information in our systems, or where you are not a resident of one of the eligible states.
Submitting Authorized Agent Requests
In certain circumstances, you are permitted to use an authorized agent to submit requests on your behalf through the designated methods set forth above, where we can verify the authorized agent's authority to act on your behalf. In order to verify the authorized agent's authority, we generally require evidence of either (i) a valid power of attorney or (ii) a signed letter containing your name and contact information, the name and contact information of the authorized agent, and a statement of authorization for the request. Depending on the evidence provided and your state of residency, we may still need to separately reach out to you to confirm the authorized agent has permission to act on your behalf and to verify your identity in connection with the request.
Appealing Privacy Rights Decisions
Depending on your state of residency, you may be able to appeal a decision we have made in connection with your privacy rights request. All appeal requests should be submitted by replying to the communication resolving your original request.
European Economic Area and the United Kingdom
In compliance with the European Union General Data Protection Regulation or the Data Protection Act 2018, as applicable ("GDPR"). The following disclosures supplement the information contained in the main body of our Privacy Policy by providing additional information about our Personal Data processing practices relating to individual residents within the European Economic Area (EEA) and the United Kingdom. For a detailed description of how we collect, use, disclose, and otherwise process Personal Data, please read the main body of our Privacy Policy.
The Personal Data We Collect
For more details, please refer to Sections 3, 4, and 5 above. Please do not that the voice recording, video recording, and skeleton motion analysis features involve the processing of Sensitive Personal Data. We will obtain your separate, explicit consent via a prominent pop-up when you first enable these features.
How We Disclose Your Personal Data
We may disclose certain or all of the Personal Data (described above) that we collect, as stated above and in accordance with the terms and the purposes as set forth in this Policy. We do not reveal personally identifiable information about you to third-parties for their independent use, save as follows: (1) unless you request or authorize us; (2) in connection with our Sites, Applications, and Products as described above; (3) the information is required to be provided in compliance with applicable laws, regulations, search warrants, subpoenas or court orders, to enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (4) the information is provided to our agents, vendors or service providers who perform functions on our behalf, where such information may be processed on servers located outside the country where you live (please see clause 2.3 below); or (5) the information is to address emergencies or acts of God or to address disputes or claims, or to persons holding a legal or beneficial interest. By entering into and using this our Sites, Applications and Products, you consent to the processing of data about you by our third-party vendors and marketing agents for the purposes set out hereinabove.
If you wish to opt-out, please contact us by sending us an email at the following address: cs@bodypark.fit. We shall, under no circumstances, be liable or responsible to you in any way for the data protection policies, privacy policies, security, or other policies of these third-party vendors/social media/marketing agents or otherwise. Subject to the provisions and exceptions as provided in the GDPR, we may disclose or share your information with our subsidiaries or affiliated companies within the Creative Group, or our service providers as necessary.
Protection of Your Personal Data
To prevent unauthorized access to our database systems, and to ensure the appropriate use of Personal Data, we have used commercially reasonable efforts to put in place electronic and managerial processes and procedures to help safeguard your Personal Data. Such safeguards include, but are not limited to, ensuring that online transfers of personal data are carried out via secure (encrypted) means.
Your personal data might be stored in the United States, with third-party vendors known as "data processors" under the GDPR. We have identified Google Cloud (operated by Google LLC, located in the United States) as our data processors and have ensured that Google LLC has entered the Data Privacy Framework List in compliance with the GDPR.
Your Additional Privacy Choices
Under the GDPR, you may also have the following additional rights regarding the Processing of your Relevant Personal Data:
- Right of withdrawal of consent - if you gave express consent previously, for example by ticking a checkbox, you can contact us to request that your consent for such matters be withdrawn.
- Right of erasure - the right to have your data erased.
- Right of data portability - the right to have your personal data transferred to another location.
- Right of objection to processing - the right to object to having your personal data processed for specific reasons.
- Right to rectify errors - requesting us to correct any errors in your personal data.
For other rights that you may have, please refer to https://gdpr-info.eu/, as applicable.
You may contact us (details are as provided in Section 15 above) for the above requests. Please give us at least thirty (30) days to process each request.
Please be aware that you have the right to lodge a complaint with an applicable Data Protection Authority, in particular, the UK Information Commissioner's Office, or the Data Protection Authority of the EU Member State in which you live, or in which you work, or in which the alleged infringement occurred. If you live in Germany, the relevant Data Protection Authority is the "Bayerisches Landesamt für Datenschutzaufsicht", Promenade 18, 91522 Ansbach). However, we encourage you to first contact us so that we can together solve any concerns you may have.
SINGAPORE
In compliance with the Personal Data Protection Act (2012) of the Republic of Singapore. The following disclosures supplement the information contained in the main body of our Privacy Policy by providing additional information about our Personal Data processing practices relating to individual residents within the Republic of Singapore. For a detailed description of how we collect, use, disclose, and otherwise process Personal Data, please read the main body of our Privacy Policy.
How We Protect Your Personal Data
To prevent unauthorized access to our database systems, and to ensure the appropriate use of information, we have used commercially reasonable efforts to put in place electronic and managerial processes and procedures to help safeguard your personal information. If your information is transferred out of Singapore as required for any of the purposes set forth in this Policy, we use commercially reasonable efforts to ensure that your information will be protected according to standards comparable to the PDPA.
Your Personal Data might be stored in the United States, with the third-party vendor Google Cloud (operated by Google LLC, located in the United States). We have ensured that we have entered into a Data Processing Agreement (DPA) with Google LLC to ensure that Google LLC provides a standard of protection for your personal data that is at least comparable to the PDPA. Such agreement is based on (1) the PDPA Model Clauses or ASEAN Model Contractual Clauses (MCCs); and (2) Binding Corporate Rules, to comply with the transfer limitation obligations under Section 26 of the PDPA.
Access and Correction of Your Personal Data
You may contact us at cs@bodypark.fit for access to your Personal Data or to correct errors in the Personal Data you previously submitted to us. We reserve the right to charge a nominal administration fee per access request. Please give us at least thirty (30) days to process the request.
You may withdraw your consent to our processing of your personal data at any time by contacting us at cs@bodypark.fit. Please note that: (1) withdrawal of consent does not affect the lawfulness of any processing based on your consent prior to such withdrawal; (2) after withdrawal, we may be unable to continue providing you with all or part of our services, including personalized training features; and (3) we will inform you of the likely consequences of your withdrawal before processing your request.
Please note that we are inter alia, prohibited from providing you with access if the provision of the Personal Data or other information could reasonably be expected to:
- threaten the safety or physical or mental health of an individual other than the individual who made the request;
- cause immediate or grave harm to the safety or to the physical or mental health of the individual who made the request;
- reveal Personal Data about another individual;
- reveal the identity of an individual who has provided Personal Data about another individual and the individual providing the Personal Data does not consent to the disclosure of his identity; or
- be contrary to the national interest.
Please also note the exceptions to the correction obligation found in the Sixth Schedule of the PDPA. (For more information, please refer to https://www.pdpc.gov.sg/).
AUSTRALIA
The following disclosures supplement the information applicable to residents of Australia. We strictly comply with relevant Australian laws and regulations to ensure transparency in the collection, use, and sharing of your information. These laws include the Privacy Act 1988, the Spam Act 2003, and other applicable privacy and data protection legislation.
How We Protect Your Personal Data
All Personal Data we hold will be processed and stored in compliance with obligations under the Privacy Act 1988. We take reasonable steps to:
- Implement practices, procedures, and systems to ensure legal compliance and address compliance inquiries/complaints.
- Maintain the accuracy, completeness, and currency of collected personal information.
- Secure information against misuse, interference, loss, or unauthorized access through physical and technological safeguards.
- Destroy or permanently de-identify information when no longer needed for legal/business purposes.
If you identify any security vulnerabilities, please notify us immediately. We adhere to all mandatory data breach notification requirements outlined in the Privacy Act.
We use Google Cloud (operated by Google LLC, located in the United States) to store and process certain Personal Data we collect from you. This means that your Personal Data may be transferred to, and stored on, servers located in the United States.
We have taken reasonable steps to ensure that Google Cloud provides a level of protection for your Personal Data that is consistent with the APPs. These steps include:
- Entering into a Data Processing Agreement (DPA) with Google LLC, which contractually requires them to handle your Personal Data in accordance with applicable data protection laws and our instructions.
- Ensuring that Google Cloud maintains robust technical and organizational security measures, including encryption of data in transit (TLS/HTTPS) and at rest (AES-256), access controls, and regular security audits.
If you consent to the transfer of your personal data to the United States (including via Google Cloud), please be aware that under Australian Privacy Principle (APP) 8.2(b), once your personal information is disclosed to the overseas recipient (Google LLC), we will no longer be accountable under the Privacy Act 1988 for any breach of the Australian Privacy Principles by that overseas recipient. You may not be able to seek redress in Australia for such breaches. The overseas recipient may also be subject to foreign laws (such as U.S. national security or law enforcement laws) that could compel the disclosure of your personal information to foreign authorities.
Right to Deal Anonymously or Pseudonymously
You have the option to deal with us anonymously or by using a pseudonym. If you choose this option, we may be unable to provide you with certain services that require the collection of your personal information (e.g., account creation, personalized training recommendations). Please contact us at cs@bodypark.fit if you wish to interact with us anonymously or by pseudonym.
Complaints
To lodge a complaint about our handling of personal information, please submit written details via post or email using the contact information in this policy. We will respond to formal complaints within 30 days.
If you are unsatisfied with our resolution, you may escalate the matter to the Office of the Australian Information Commissioner (OAIC). For additional details about the OAIC, you may:
- (A) Visit the Office of the Australian Information Commissioner (OAIC) website: www.oaic.gov.au
- (B) Call: 1300 363 992 (local call charges may apply)