This Data Processing Agreement (“DPA“) forms part of the agreement between Human Design Technologies LTD, company number 13963882, registered at 45 Osidge Lane, London, N14 5JL, United Kingdom (“Bodygraph“, “we“, “us” or “our“), and the person or legal entity subscribing to or using the Bodygraph Services (“Bodygraph Subscriber“, “you” or “your“).
This DPA explains how Personal Data is processed when you use Bodygraph and, in particular, clearly distinguishes between:
- Personal Data relating to you as a Bodygraph Subscriber;
- Personal Data relating to your clients or users processed through Bodygraph’s native embeds, chart calculators and report functionality; and
- data processed through the Bodygraph API.
This DPA should be read together with Bodygraph’s Terms and Conditions and Privacy Policy.
1. Applicable Law and Key Terms
This DPA applies in accordance with applicable privacy and data protection law, including, where relevant, the UK GDPR, the Data Protection Act 2018, PECR, applicable EEA data protection legislation and other applicable privacy laws.
For the purposes of this DPA:
Personal Data means information relating to an identified or identifiable individual.
Controller means the person or organisation that determines why and how Personal Data is processed.
Processor means the person or organisation processing Personal Data on behalf of a Controller.
Bodygraph Subscriber means the individual or legal entity subscribing to, purchasing, accessing or using Bodygraph Services.
Subscriber Client means an individual whose information is processed by a Bodygraph Subscriber through Bodygraph, including a customer, client, chart calculator user, report recipient, prospect or website visitor.
Subscriber Client Data means Personal Data relating to a Subscriber Client that Bodygraph processes on behalf of a Bodygraph Subscriber.
Bodygraph Services include Bodygraph websites, software, applications, APIs, chart calculators, embeds, hosted functionality, chart generation, report generation and related services.
2. Bodygraph Subscriber Data – Bodygraph as Controller
Personal Data relating directly to the Bodygraph Subscriber is separate from Subscriber Client Data.
When you create, trial or maintain a Bodygraph subscription, Bodygraph may collect and process information including:
- full name;
- email address;
- billing address;
- tax or VAT identification number where supplied;
- subscription and billing information;
- payment method and transaction information; and
- account, support and service-related information (including live chat, email and other communication records).
Bodygraph processes this information as an independent Controller for the purposes listed below:
- creating and administering your Bodygraph account;
- providing and managing your subscription;
- processing payments and invoices;
- providing customer support;
- communicating with you about your account or Services;
- maintaining security and preventing fraud;
- complying with accounting, tax, regulatory and legal obligations; and
- operating and protecting the Bodygraph Services.
Bodygraph Subscriber Data is collected when you create or begin using a Bodygraph account or trial and is retained while your account or subscription remains active.
Where a subscription is cancelled without deletion of the account, account information may remain associated with the Bodygraph account so that the Subscriber may reactivate the account in the future.
A Bodygraph Subscriber may, subject to technical availability and applicable legal retention requirements:
- remove or update billing information through the Bodygraph account dashboard;
- delete their Bodygraph account through the account dashboard; or
- request account or Personal Data deletion by contacting support@bodygraph.com.
Deletion may not apply immediately to information Bodygraph is legally required or reasonably entitled to retain, including records required for accounting, taxation, fraud prevention, dispute resolution, security or the establishment, exercise or defence of legal claims.
3. Third-Party Service Providers Used by Bodygraph
Bodygraph uses selected third-party service providers where reasonably necessary to operate, support and administer the Bodygraph Services.
These providers may process different categories of Personal Data depending on the service they provide.
Stripe
Bodygraph uses Stripe for subscription billing, payment collection, invoicing and related payment services.
Stripe may process information including:
- name;
- billing address;
- payment method information;
- transaction information;
- applicable tax information; and
- other information necessary to process payments, refunds or invoices.
Stripe is used in connection with Bodygraph Subscriber Data and is not used by Bodygraph for the calculation of Human Design or astrology charts or for storage of Subscriber Client birth data.
HubSpot
Bodygraph uses HubSpot to manage customer service communications and related account support activity.
Where a Bodygraph Subscriber contacts Bodygraph through customer support, live chat, email or another supported communication channel, relevant information may be stored within HubSpot, including:
- name;
- email address;
- communication history;
- support enquiries;
- replies and correspondence;
- account-related information supplied during the support interaction; and
- technical or service information reasonably necessary to investigate and respond to the enquiry.
Bodygraph processes this information as part of administering and supporting its relationship with the Bodygraph Subscriber.
Support and communication records may be retained after the immediate enquiry has been resolved where reasonably necessary for:
- maintaining an accurate customer service history;
- investigating previous enquiries or technical issues;
- protecting Bodygraph against fraudulent or abusive activity;
- handling complaints and disputes;
- demonstrating communications or agreements between Bodygraph and the Subscriber;
- establishing, exercising or defending legal claims;
- complying with legal, regulatory, tax or accounting obligations; and
- protecting Bodygraph’s legitimate business interests.
A Bodygraph Subscriber may not necessarily be able to delete these records directly through the account dashboard.
Requests concerning such records may be submitted to support@bodygraph.com. Bodygraph will consider such requests in accordance with applicable Data Protection Law, taking into account any lawful reason requiring or permitting continued retention.
Bodygraph will not retain identifiable support communications for longer than reasonably necessary for the purposes for which they are retained.
Fathom
Bodygraph may use Fathom to record, transcribe, summarise or otherwise document video meetings between Bodygraph and Bodygraph Subscribers.
Depending on the meeting and the functionality used, Fathom may process:
- the Subscriber’s name;
- email address;
- voice;
- video image where video is enabled;
- meeting recording;
- meeting transcript;
- meeting summary;
- information discussed during the meeting; and
- meeting metadata.
Meeting recordings and transcripts may be used for purposes including:
- Providing recording and transcript access to Bodygraph Subscriber who booked a meeting;
- documenting consultations, onboarding sessions or support meetings;
- maintaining an accurate record of matters discussed or agreed;
- staff training and service quality;
- resolving misunderstandings or disputes;
- establishing, exercising or defending legal claims; and
- maintaining appropriate business records.
Where required by applicable law, Bodygraph will provide appropriate notice that a meeting is being recorded and will obtain consent where consent is required.
Meeting recordings, transcripts and associated records may be retained for a reasonable period according to Bodygraph’s applicable retention practices and may be retained for longer where reasonably necessary in connection with an existing or anticipated complaint, dispute, investigation or legal claim.
Subscribers may contact support@bodygraph.com concerning Personal Data contained within recorded meetings. Any deletion request will be considered in accordance with applicable Data Protection Law and may be refused or restricted where Bodygraph has a lawful basis or legal obligation to retain the relevant information.
4. Subscriber Client Data – Bodygraph Subscriber as Controller
Where a Bodygraph Subscriber collects information from its own clients, customers, website visitors or other individuals through Bodygraph’s native chart calculators, embed codes or related functionality:
- the Bodygraph Subscriber is the Controller;
- Bodygraph is the Processor; and
- the Subscriber Client is the Data Subject.
The Bodygraph Subscriber determines why the Subscriber Client Data is collected and is responsible for ensuring that the collection and use of that information is lawful.
Bodygraph does not acquire ownership of Subscriber Client Data.
5. Data Processed Through Native Bodygraph Embeds and Chart Calculators
Where a Bodygraph Subscriber uses Bodygraph’s native embed codes, chart calculators or related native functionality, Bodygraph may collect and process the following Subscriber Client Data:
- name;
- date of birth;
- time of birth;
- place of birth; and
- email address only where the Bodygraph Subscriber has enabled an email field or otherwise configured the applicable Bodygraph form to collect it.
Birth location information is processed where necessary to identify the appropriate time zone and/or geographical latitude and longitude required for Human Design or astrology calculations.
Bodygraph processes this information solely as necessary to:
- calculate Human Design information;
- calculate astrology information;
- generate charts;
- render charts;
- generate or render PDF reports;
- display the requested results; and
- provide the native Bodygraph functionality selected by the Bodygraph Subscriber.
Bodygraph does not use Subscriber Client Data collected through native chart functionality for Bodygraph’s own marketing, profiling, advertising or unrelated commercial purposes.
Bodygraph does not sell Subscriber Client Data.
Bodygraph does not independently disclose Subscriber Client Data to third parties for their own purposes.
If the Bodygraph Subscriber independently connects, enables or configures a third-party integration that causes information to be transferred outside Bodygraph, that transfer is treated in accordance with Section 9 of this DPA.
6. 90-Day Retention of Native Subscriber Client Data
Subscriber Client Data collected through Bodygraph’s native embed codes or chart calculator functionality is made available to the Bodygraph Subscriber through the Statistics section of the Bodygraph dashboard.
Each individual entry is retained for 90 days.
At the end of the applicable 90-day period, the entry is automatically removed from Bodygraph’s active system and cannot be restored through the Bodygraph account.
The Bodygraph Subscriber is responsible for reviewing, managing or exporting any information it requires before the 90-day retention period expires.
The 90-day retention period does not transfer responsibility for Subscriber Client Data to Bodygraph. The Bodygraph Subscriber remains the Controller throughout the period in which Bodygraph processes the data.
7. Bodygraph Subscriber Responsibilities for Client Data
Because the Bodygraph Subscriber is the Controller of Subscriber Client Data, the Bodygraph Subscriber is responsible for:
- determining the lawful basis for collecting and processing the data;
- obtaining consent where consent is legally required;
- providing appropriate privacy notices to Subscriber Clients;
- determining which Personal Data should be collected;
- ensuring that unnecessary or unlawful Personal Data is not submitted;
- ensuring that information supplied to Bodygraph is accurate and appropriate;
- protecting access to its Bodygraph account;
- protecting passwords, API credentials and access credentials;
- controlling access by its employees, contractors and authorised users;
- monitoring Subscriber Client Data available through its account;
- responding to Subscriber Client requests concerning their Personal Data;
- deleting Subscriber Client Data where required and technically available;
- complying with applicable retention requirements;
- ensuring that its websites, forms and systems comply with applicable law; and
- ensuring that its use of Bodygraph is lawful.
Subscriber Client rights may include rights of access, correction, deletion, restriction, objection, portability and withdrawal of consent where applicable.
Where a Subscriber Client contacts Bodygraph directly concerning data controlled by a Bodygraph Subscriber, Bodygraph may refer that individual to the relevant Bodygraph Subscriber.
Bodygraph will provide reasonable assistance to the Bodygraph Subscriber where required by applicable law and technically possible.
8. API-Only Processing
Different rules apply where a Bodygraph Subscriber uses the Bodygraph API without using Bodygraph’s native embed codes or hosted data collection functionality.
For an API request, Bodygraph receives only the birth and location information necessary to perform the requested calculation, such as:
- date of birth;
- time of birth; and
- birth location information required to determine the applicable time zone and/or geographical latitude and longitude.
Bodygraph processes that information solely for the technical purpose of:
- receiving the API request;
- performing the requested Human Design or astrology calculation;
- generating the requested response; and
- returning that response to the Bodygraph Subscriber.
API Personal Data is processed only for the duration necessary to complete and return the API request.
Bodygraph does not use the API as a storage service for Subscriber Client Data.
Once the requested API response has been generated and returned, Bodygraph does not retain the Personal Data submitted for that API request as Subscriber Client records.
The Bodygraph Subscriber using the API is solely responsible for the subsequent:
- collection;
- storage;
- security;
- hosting;
- retention;
- deletion;
- disclosure;
- transmission;
- integration;
- use; and
- further processing
of Subscriber Client Data and API results within the Subscriber’s own websites, applications, databases, platforms and systems.
The Bodygraph Subscriber is responsible for ensuring that its own API implementation complies with Applicable Data Protection Law.
9. Third-Party Integrations Selected by the Subscriber
Bodygraph may provide functionality allowing a Bodygraph Subscriber to connect Bodygraph with third-party applications, systems or services.
A third-party platform selected, connected, activated or configured by the Bodygraph Subscriber is not automatically a Bodygraph Processor or Subprocessor merely because Bodygraph makes the integration technically possible.
Where the Bodygraph Subscriber chooses to send Subscriber Client Data to a third-party service, the Bodygraph Subscriber is responsible for:
- choosing the third-party provider;
- deciding what data is transferred;
- establishing a lawful basis for the transfer;
- reviewing that provider’s privacy and security terms;
- entering into any required agreements with that provider;
- obtaining any required Subscriber Client consent;
- configuring the integration correctly;
- determining retention and deletion requirements; and
- ensuring that the third party’s processing complies with applicable law.
This applies to customer-configured integrations and third-party services, including Bodygraph GoHighLevel extension (subaccount/add-on) made available for connection through the Bodygraph ecosystem (App Integrations).
Bodygraph is not responsible for processing independently undertaken by such third parties.
To the maximum extent permitted by law, Bodygraph will not be liable for unauthorised access, loss, disclosure, alteration, corruption, deletion, misuse or other compromise of Subscriber Client Data occurring within a third-party service selected or configured by the Bodygraph Subscriber via App Integrations and Bodygraph GoHighLevel subaccount.
Nothing in this section excludes liability that cannot lawfully be excluded.
10. Processing Instructions
The Bodygraph Subscriber instructs Bodygraph to process Subscriber Client Data only as reasonably necessary to provide the Bodygraph Services selected and used by the Subscriber.
Those instructions include processing necessary for:
- Human Design calculations;
- astrology calculations;
- chart generation;
- report generation;
- native chart embeds;
- API requests;
- technical operation of the Services;
- security;
- fraud and abuse prevention;
- troubleshooting;
- customer support where applicable; and
- compliance with applicable law.
Bodygraph will not knowingly process Subscriber Client Data for purposes unrelated to providing the requested Bodygraph Services.
Bodygraph is not required to follow an instruction that would cause Bodygraph to violate applicable law.
Where Bodygraph reasonably believes that an account, instruction, data submission or use of the Services is fraudulent, unlawful, abusive, materially misleading or contrary to Bodygraph’s Terms, Bodygraph may refuse processing, restrict access, suspend or terminate relevant Services, remove affected information and take other action reasonably necessary to protect Bodygraph, its Services, users or affected individuals.
11. Confidentiality and Access
Bodygraph will take reasonable measures to ensure that persons authorised to access Personal Data are subject to appropriate confidentiality obligations.
Access to Personal Data will be restricted to authorised persons who reasonably require access for purposes connected with providing, maintaining, securing or supporting the Bodygraph Services.
12. Security
Bodygraph will implement appropriate technical and organisational measures designed to protect Personal Data processed through its Services against accidental or unlawful:
- destruction;
- loss;
- alteration;
- disclosure;
- access; or
- other unauthorised processing.
Measures may include, where appropriate:
- access controls;
- authentication;
- secure transmission;
- encryption;
- system monitoring;
- logging;
- vulnerability management;
- backup procedures;
- incident response procedures; and
- restrictions on personnel access.
No internet-based service, electronic transmission method or security system can be guaranteed to be completely secure.
The Bodygraph Subscriber remains responsible for the security of its own systems, devices, accounts, passwords, API credentials, websites, applications and third-party integrations.
13. Personal Data Breaches
Where Bodygraph becomes aware of a Personal Data breach affecting Bodygraph Subscriber and.or Subscriber Client Data processed by Bodygraph on behalf of a Bodygraph Subscriber, Bodygraph will notify the Bodygraph Subscriber without undue delay where required by Applicable Data Protection Law.
Where reasonably available, Bodygraph may provide information concerning:
- the nature of the incident;
- affected categories of Personal Data;
- likely consequences; and
- measures taken or proposed to address the incident.
The Bodygraph Subscriber remains responsible for Subscriber Client Data, as Controller, for determining whether any notification must be made to Subscriber Clients, the Information Commissioner’s Office or another supervisory authority.
Notification of an incident does not constitute an admission of liability or wrongdoing by Bodygraph.
14. Data Subject Requests and Compliance Assistance
Taking into account the nature of the processing and information reasonably available to Bodygraph, Bodygraph will provide reasonable assistance where required by applicable law in relation to:
- Data Subject requests;
- security obligations;
- Personal Data breaches;
- Data Protection Impact Assessments; and
- consultation with supervisory authorities.
The Bodygraph Subscriber remains responsible for deciding how to respond to Subscriber Clients and whether any Data Protection Impact Assessment, regulatory notification or consultation is required.
Where legally permitted, Bodygraph may charge reasonable fees for substantial assistance falling outside the normal operation of the Bodygraph Services.
15. Return and Deletion
Native Subscriber Client Data is subject to the 90-day automatic retention and deletion period described in this DPA.
API-only Personal Data is processed transiently and is not retained as Subscriber Client records after the API response has been completed and returned.
Where technically available, a Bodygraph Subscriber may remove applicable Subscriber Client Data before automatic deletion through the Bodygraph dashboard or request appropriate assistance from Bodygraph.
Once information has been permanently deleted from the relevant operational system, Bodygraph may be unable to restore it.
Limited information may remain temporarily within secure system backups until overwritten or deleted through Bodygraph’s normal backup lifecycle.
Bodygraph may retain information where retention is required or permitted by law, including where reasonably necessary for security, fraud prevention, regulatory compliance or legal claims.
16. International Data Transfers
Where Bodygraph transfers Personal Data to a country requiring an international data transfer safeguard under Applicable Data Protection Law, Bodygraph will use an appropriate lawful mechanism where required.
Such mechanisms may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- EU Standard Contractual Clauses where applicable; or
- another legally recognised transfer mechanism.
Where a Bodygraph Subscriber independently transfers information to a third-party service or integration, responsibility for establishing the appropriate transfer mechanism rests with the Bodygraph Subscriber.
17. Government and Legal Requests
Bodygraph may disclose Personal Data where required by applicable law, a valid court order, regulatory requirement or other binding legal process.
Where legally permitted, Bodygraph will take reasonable steps to notify the Bodygraph Subscriber of a legally binding request concerning Bdygraph Subscriber and.or Subscriber Client Data before disclosure.
Bodygraph may withhold or delay such notification where disclosure of the request is prohibited by law or could interfere with a lawful investigation or security matter.
18. Compliance Information and Audits
Bodygraph will make available information reasonably necessary to demonstrate compliance with its Processor obligations under Applicable Data Protection Law.
Where an audit is legally required and equivalent information cannot reasonably satisfy the requirement, Bodygraph will reasonably cooperate with an appropriate audit relating specifically to Bodygraph’s processing of Subscriber Client Data.
Audits must:
- be conducted on reasonable prior written notice;
- occur during normal business hours;
- avoid unreasonable disruption to Bodygraph’s operations;
- protect confidential, commercially sensitive and third-party information;
- comply with reasonable Bodygraph security requirements; and
- be limited to information relevant to the Bodygraph Subscriber’s processing relationship.
Where permitted by law, the Bodygraph Subscriber may be responsible for reasonable costs associated with audits or assistance exceeding Bodygraph’s normal compliance obligations.
19. Custom Fields, Special Category Data and Subscriber Responsibility
Bodygraph may allow a Bodygraph Subscriber to add custom field/s to a Subscriber Client submission form. The Bodygraph Subscriber may choose the name, label and purpose of that custom field and determine what information it asks Subscriber Clients to provide.
Because the custom field is created and configured by the Bodygraph Subscriber, Bodygraph does not determine what Personal Data is requested or submitted through that field.
The Bodygraph Subscriber is therefore solely responsible for:
- deciding whether the custom field is necessary and appropriate;
- determining what information is requested through the field;
- ensuring that there is a lawful basis for collecting and processing that information;
- providing any required privacy notice or disclosure to the Subscriber Client;
- obtaining consent where legally required;
- ensuring that unnecessary, excessive or unlawful Personal Data is not requested; and
- complying with any additional legal requirements applicable to sensitive or Special Category Personal Data.
Information submitted through the custom field is stored together with the relevant Subscriber Client entry within the Statistics section of the Bodygraph Subscriber’s dashboard and is subject to the same 90-day retention period applicable to native Bodygraph form submissions. After that period, the entry and associated custom-field data are automatically removed and cannot be restored through the Bodygraph account.
Bodygraph Services do not require a Bodygraph Subscriber to collect Special Category Personal Data through the custom field, and Bodygraph does not determine or recommend that such information should be collected.
If a Bodygraph Subscriber chooses to use the custom field to request or process information concerning health, racial or ethnic origin, religious or philosophical beliefs, biometric information, sexual orientation or any other Special Category or otherwise legally protected Personal Data, the Bodygraph Subscriber remains fully responsible as Controller for ensuring that the collection and processing of that information is lawful.
Bodygraph acts only as Processor in relation to Personal Data submitted through the custom field as part of Bodygraph’s native form functionality and processes that data solely to provide the functionality selected and configured by the Bodygraph Subscriber.
To the maximum extent permitted by applicable law, Bodygraph accepts no responsibility or liability for the nature, content, lawfulness, accuracy or appropriateness of Personal Data that a Bodygraph Subscriber chooses to request, collect or process through a custom field, and the Bodygraph Subscriber remains solely responsible for that data and its use.
20. No Compliance Guarantee
Bodygraph provides software and technology services.
Bodygraph does not provide legal, regulatory, tax or data protection advice.
The Bodygraph Subscriber remains responsible for determining whether its business, website, forms, privacy notices, integrations, data collection and use of Bodygraph comply with the laws applicable to that Subscriber.
Use of Bodygraph does not, by itself, make a Bodygraph Subscriber compliant with UK GDPR, EU GDPR or any other privacy or data protection law.
Bodygraph Subscribers should obtain independent professional advice where appropriate.
21. Relationship With Other Bodygraph Terms
This DPA forms part of the agreement governing the Bodygraph Subscriber’s use of Bodygraph.
It should be read together with Bodygraph’s Terms and Conditions and Privacy Policy.
If there is a direct conflict between this DPA and Bodygraph’s general Terms concerning Bodygraph’s processing of Subscriber Client Data as Processor, this DPA will prevail to the extent necessary to resolve that conflict.
Bodygraph’s Terms and Conditions continue to govern all matters not specifically addressed in this DPA, including applicable limitations of liability.
Nothing in this DPA transfers ownership of Subscriber Client Data to Bodygraph.
22. Changes to this DPA
Bodygraph may update this DPA where reasonably necessary to reflect:
- changes in law;
- regulatory requirements;
- changes to Bodygraph Services;
- changes to processing practices;
- changes to security measures;
- changes to service providers; or
- other legitimate operational or legal requirements.
Where required by applicable law or Bodygraph’s Terms and Conditions, Bodygraph will provide notice of material changes.
The updated DPA will apply from the effective date stated in the revised version.
23. Term and Termination
This DPA remains effective for as long as Bodygraph processes Subscriber Client Data on behalf of the Bodygraph Subscriber.
Following termination or expiry of the relevant Bodygraph Services, Bodygraph will cease processing Subscriber Client Data except:
- during an applicable retention or deletion period;
- within normal backup lifecycles;
- where processing is necessary for security or fraud prevention; or
- where retention or processing is permitted or required by law.
Provisions which by their nature should continue after termination, including confidentiality, security, deletion, legal compliance and liability provisions, will survive termination.
24. Governing Law and Jurisdiction
This DPA is governed by the laws of England and Wales.
The courts of England and Wales will have jurisdiction over disputes arising from or relating to this DPA, subject to any mandatory rights or jurisdiction that cannot lawfully be excluded.
Signed on behalf of the Data controller for Bodygraph subscriber data and Processor for Bodygraph Subscriber Client data:
Human Design Technologies LTD
Company No. 13963882
45 Osidge Lane
London, N14 5JL
United Kingdom
Email: support@bodygraph.com