Privacy Policy

Draft version: 2026-09-13

Production data-protection review required. Complete all controller, lawful-basis, processor, retention, transfer, DPO/contact and DPIA fields before launch.

BodyTrace is designed to separate the public website from the private health-assessment application and to minimize unnecessary collection of health information on the public site.

Controller

__CONTROLLER_LEGAL_NAME__, __CONTROLLER_ADDRESS__. Privacy contact: __PRIVACY_CONTACT__.

Health data in the private application

The private BodyTrace application may process symptoms, body locations, laboratory values, medications, allergies, medical history, pregnancy-related context where voluntarily provided, assessment answers and generated reports. Health information can be special-category personal data under GDPR Article 9. The final production lawful basis and Article 9 condition must be documented and legally reviewed.

Public website live counters

The public website includes aggregate “visitors today” and “reports created today” counters. For the visitor counter, the browser creates a random first-party identifier and stores it locally so the same browser is not counted repeatedly on every page refresh. The server stores only a daily cryptographic hash of that random identifier for the aggregate count; it is not designed to contain health data, a name, email address or report content. The report counter receives only a protected server-to-server event after successful report creation and does not require report medical content.

Consent review: before EU production deployment, confirm with privacy counsel whether the chosen local-storage visitor counting method requires consent under the applicable ePrivacy/cookie rules. If required, gate the counter identifier behind the site's consent mechanism.

Purpose and legal bases

Purposes may include providing the requested assessment, generating requested reports/exports, maintaining authenticated sessions, protecting the service from abuse, operating the public website and producing minimal aggregate service metrics. Article 6 basis: __ARTICLE_6_BASIS__. Article 9 condition: __ARTICLE_9_CONDITION__.

Retention

BodyTrace should retain personal data only for documented purposes and periods. Current application-specific retention targets must be verified against the deployed system, hosting, backups, logs, email provider and any security services before this policy becomes effective. The public daily counter files are configured to be automatically removed after 31 days; production counsel should confirm that this period is appropriate for the final purpose and legal basis.

Processors and transfers

Hosting: __HOSTING_PROVIDER__. Transactional email: __EMAIL_PROVIDER__. Bot protection: __BOT_PROTECTION_PROVIDER__. Other processors: __OTHER_PROCESSORS__. International transfer details: __TRANSFER_MECHANISM_AND_COUNTRIES__.

Your rights

The final policy must describe applicable access, rectification, erasure, restriction, portability, objection and complaint rights; identity-verification procedures; and the competent supervisory authority for the final controller jurisdiction.

Security

Technical and organizational safeguards should include access control, secret management, transport encryption, least-privilege administration, secure logging practices, vulnerability management, backups appropriate to the service and incident-response procedures. No website can guarantee absolute security.

DPIA

Where required, a Data Protection Impact Assessment should remain a production release gate for the health-data workflow, especially where systematic automated assessment or special-category data processing creates a likely high risk to individuals.