Legal

Privacy Notice

Effective 26 July 2026 · Controller: Bodymaker LLC

1 Introduction and scope

This Privacy Notice explains how Bodymaker LLC processes your personal data when you use the Bodymaker spirometry reference-interpretation service. It is written to meet the transparency requirements of Article 13 of the EU General Data Protection Regulation (the “GDPR”) and the UK GDPR, and to provide the disclosures required for users located in the United States under applicable state privacy laws (including the California Consumer Privacy Act and the Washington My Health My Data Act).

Bodymaker’s explicit-consent notice, shown separately at the point you submit your first spirometry measurement, is the operative consent for the health-data processing described here. This Privacy Notice is informational and does not replace that consent.

This notice covers only the Bodymaker spirometry service. Other Bodymaker services, if any, are governed by their own notices.

2 Who we are (Data Controller)

Controller: BODYMAKER LLC — Single-Member Limited Liability Company, State of Delaware, USA

  • Federal EIN: 32-0845313
  • Registered address: 8 The Green, STE R, Dover, DE 19901, USA
  • Contact for privacy matters: Serhii Pylkevych, Managing Member — office@bodymaker.us
  • EU Representative under GDPR Art. 27: Not currently designated — see §10 below for the position on Article 27 designation during the early-stage launch phase.

3 What personal data we process

For this service, we process the following categories of personal data:

Data concerning your health (special category under GDPR Art. 9):

  • Forced Expiratory Volume in the first second (FEV₁).
  • Forced Vital Capacity (FVC).
  • The FEV₁/FVC ratio.
  • Bronchodilator state (pre- or post-bronchodilator).

Ordinary personal data used only in the reference calculation:

  • Age.
  • Height.
  • Sex, as required by the reference equations.
  • A random session identifier that links your test to its result without using your name after pseudonymisation.

We do not process:

  • Any free-text fields containing names, medical record numbers, or dates of birth.
  • Any biometric identifier for the purpose of uniquely identifying you.
  • Any location data more precise than your country of residence.
  • Any data of persons under the age of 18. The service is not offered to minors.

4 Purposes of processing and legal basis

The only purpose for which we process the data listed in §3 is to compute a reference interpretation of your FEV₁/FVC using the peer-reviewed Global Lung Function Initiative (GLI Global 2022) reference equations, endorsed by the American Thoracic Society and the European Respiratory Society. The output is an interpretation, not a medical diagnosis, and is not intended to drive clinical decisions.

Legal basis:

  • For users in the European Union, European Economic Area, or the United Kingdom: your consent under Article 6(1)(a) GDPR for ordinary personal data and your explicit consent under Article 9(2)(a) GDPR for the health-data element. Your consent is captured through the separate Consent Notice at the point of first submission.
  • For users in the United States: your voluntary consent under applicable federal and state law. Where you reside in Washington State, we obtain the affirmative opt-in consent required by the Washington My Health My Data Act for the collection, processing, and sharing of consumer health data. Where you reside in California, we obtain your consent for the collection and processing of sensitive personal information as defined in the California Consumer Privacy Act as amended by the California Privacy Rights Act.

We do not use this data for any secondary purpose. In particular:

  • We do not use it for marketing.
  • We do not sell or share it (in the meaning of California law) with any third party.
  • We do not use it to train unrelated products or artificial-intelligence models.
  • We do not use it to profile you for automated decision-making producing legal or similarly significant effects on you.

5 Who receives your personal data

Only two entities receive your personal data:

  • Bodymaker LLC — the Controller, as identified in §2.
  • Hetzner Online GmbH — our hosting infrastructure provider, established at Industriestraße 25, 91710 Gunzenhausen, Germany. Hetzner acts strictly as a data processor under GDPR Article 28. A signed Data Processing Agreement between Bodymaker and Hetzner dated 26 July 2026 governs this relationship.

A current list of processors and Hetzner’s own downstream sub-processors is published at bodymaker.us/subprocessors and is kept up to date. We will notify you and give you an opportunity to object before we engage a further third-party processor.

We do not disclose your personal data to any other third party except where required by a binding legal obligation (for example, a court order or a lawful request from a supervisory authority). If such a disclosure is legally required, we will inform you unless the law itself prohibits us from doing so.

6 Where your data is stored and international transfers

All personal data — whether you are located in the European Union, the United Kingdom, or the United States — is processed and stored on servers operated by Hetzner Online GmbH in Germany, within the European Union.

For users located in the European Union or the European Economic Area:

Your data does not leave the EEA at this phase. No cross-border transfer instrument under GDPR Chapter V is required for Bodymaker’s current use of Hetzner.

For users located in the United Kingdom:

Your data is transferred from the UK to Germany, which is covered by the UK adequacy regulations recognising the EU’s data-protection regime as ensuring an adequate level of protection.

For users located in the United States:

Your data is transferred to and stored in Germany. This transfer is made on the basis of your explicit consent to the Consent Notice. Germany applies the EU General Data Protection Regulation, which the U.S. Department of Commerce has recognised as providing meaningful data-protection safeguards.

When Bodymaker expands to United States hosting infrastructure at a later phase, this notice will be updated to reflect the new architecture and any applicable transfer mechanism.

7 How long we keep your data

At the end of the retention period, data is destroyed by cryptographic destruction of the encrypted records and destruction of the pseudonymisation key. A signed certificate of destruction is written to our immutable audit log.

We keep your personal data while your account is active. After you close your account or ask us to erase your data, we delete it within 30 days, after which destruction proceeds as described above.

8 Your rights

Subject to applicable law, you have the following rights in relation to your personal data. To exercise any of them, write to office@bodymaker.us. We respond within one month; where a request is complex or we receive a high volume of requests, we may extend the response period by up to two further months and will tell you why.

  • Right of access — to obtain confirmation of whether we process your personal data and a copy of that data (GDPR Art. 15).
  • Right to rectification — to have inaccurate or incomplete personal data corrected (GDPR Art. 16).
  • Right to erasure (“right to be forgotten”) — to have your personal data deleted in the cases listed in GDPR Art. 17.
  • Right to restriction of processing — to have processing limited in the cases listed in GDPR Art. 18.
  • Right to data portability — to receive your data in a structured, commonly used, machine-readable format, and to transmit it to another controller (GDPR Art. 20).
  • Right to object to processing on the grounds set out in GDPR Art. 21.
  • Right to withdraw consent — you may withdraw the consent given through the Consent Notice at any time, without giving a reason, at app.bodymaker.us/account/privacy. Withdrawal is as easy as giving consent and does not affect the lawfulness of any processing carried out before withdrawal (GDPR Art. 7(3)).
  • Right to lodge a complaint with the supervisory authority of your country of residence, place of work, or the place where an alleged violation occurred (GDPR Art. 77).

For users in the United States — additional statutory rights:

  • Washington State residents (Washington My Health My Data Act, RCW 19.373): right to confirm processing, right to access, right to deletion, right to withdraw consent, and enforcement through the Washington Attorney General or a private right of action.
  • California residents (California Consumer Privacy Act as amended by the California Privacy Rights Act, Cal. Civ. Code §1798.100 et seq.): right to know, right to delete, right to correct, right to limit the use and disclosure of sensitive personal information, and the right to opt out of any “sale” or “share.” Bodymaker does not sell or share your personal data and honours any “Limit the Use of My Sensitive Personal Information” request.
  • Residents of other U.S. states with applicable comprehensive privacy legislation (including Colorado, Connecticut, Utah, Virginia, Texas, Oregon, Delaware, and others as those statutes become effective): rights of access, deletion, correction, and portability, exercised through the same mailbox at office@bodymaker.us.

9 How we protect your data

We apply technical and organisational measures under GDPR Article 32, including:

  • Pseudonymisation of your data at the boundary of our ingestion service, with the re-identification key stored separately in a segregated secrets vault under strict four-eye access.
  • Encryption at rest using AES-256 and in transit using TLS 1.3.
  • Role-based and attribute-based access controls, least-privilege principles, no standing production access, and just-in-time access elevation with ticket linkage.
  • Immutable, append-only audit logs with monthly review by our Data Protection Contact.
  • Confidentiality undertakings for personnel with production access, plus annual data-protection training.
  • A documented incident-response plan covering the 72-hour supervisory notification clock under GDPR Article 33 and the notification of affected data subjects under Article 34 where required.

10 Governance positions

Data Protection Officer:

Bodymaker has assessed the criteria of GDPR Article 37(1) and determined that formal designation of a Data Protection Officer is not currently required. A named Data Protection Contact — Serhii Pylkevych, Managing Member — handles data-subject rights requests, breach coordination, and communication with supervisory authorities. Contact: office@bodymaker.us. This position will be reassessed if the nature or scale of processing changes materially.

EU Representative (Article 27 GDPR):

Bodymaker LLC is established in the United States and does not currently have an establishment in the European Union. In the early-stage launch phase of the service, in which no confirmed EU data subject has yet registered and the service is not actively marketed to the Union, Bodymaker has not designated a written representative under GDPR Article 27. Bodymaker will designate such a representative on the earlier of (a) the first registration of a data subject located in the Union or (b) ninety (90) days from the effective date of this notice, and this section will be updated with the name, address, and contact details of that representative at that time. Until such designation, data subjects located in the Union may address any communication concerning our processing directly to Bodymaker at office@bodymaker.us.

11 Children

The service is offered exclusively to adults aged 18 and above. We do not knowingly process personal data of persons under the age of 18. If we become aware that we hold personal data of a minor, we will delete it without undue delay.

12 Automated decisions and profiling

The service applies a peer-reviewed reference calculation to your measurements. It does not produce any decision that has legal effects concerning you or similarly significantly affects you, and does not fall within the definition of automated individual decision-making under GDPR Article 22. The output is intended as reference information only, not as a medical diagnosis or a basis for clinical decisions.

13 Changes to this notice

We keep this Privacy Notice under review and update it when required. The current version is always shown at the top of this page with its effective date. When a change is material, we will notify you before it takes effect and, where the change affects the basis of your consent, we will ask you for renewed consent through the Consent Notice flow.

Version history:

  • Version 1.0 — 26 July 2026 — initial publication.

14 Contact

For any question about this notice, about how we process your personal data, or to exercise any of your rights, contact:

  • Data Protection Contact: Serhii Pylkevych, Managing Member, Bodymaker LLC.
  • Email (primary): office@bodymaker.us
  • Postal: Bodymaker LLC, 8 The Green, STE R, Dover, DE 19901, USA.
  • EU Representative under Art. 27 GDPR: not currently designated — see §10 above for the position.

15 Legal anchors (for reference)