Privacy Policy
Valid from 10.10.2024.
This section describes the processing of your personal data and sets out the grounds on which we process the personal data we collect from you or that you provide to us.
1. Data controller and contact information
Bodymaja Oy
In the marketing of the service and later on this page, the company will be called Bodymaja
Customer service
Email: [email protected]
Phone: 010 517 3991 (Mon-Fri 9-15)
Postal address: P.O. Box 2, 99131 Sirkka
Bodymaja Oy is registered as a health service provider in the Valvira register.
2. What information do we collect?
Bodymaja collects information that is necessary for the customer relationship between you and Bodymaja and for the purposes for which the information is used. Bodymaja collects the following categories of personal data.
- Basic and contact information
- Permission information – for example, marketing permissions
- Communication
- Order and contract information – for example, order or contract type, payment method
- Health and well-being information – for example, body composition measurement results, blood pressure and compression force measurement results or information you enter yourself regarding measurements, health and well-being, which are sensitive personal data.
- Other information provided by the customer: wishes and choices related to services, satisfaction information and other similar information
- Payment transaction information – for example, information necessary for billing and payment
- Online behavior information – for example, login information, other information obtained from the use of our services, customer profiling, including offline online behavior, information collected using website cookies.
- Email marketing data – we track the effectiveness of email marketing by analyzing message opens and link clicks. This data is used to target communications and marketing and to develop services.
- Location usage data (Appointment data and lock data)
- Measurement device usage data (Actual usages)
- Cleaning service visit data
- Customer service call and chat recordings
- Information about the use of our services – for example, services ordered
- Communication – for example, in response to surveys and other feedback and messages you send to us
- Data regarding the data processing device – for example, IP address, cookie data
3. From what sources is personal data obtained?
The personal data processed includes information received from you during the subscription, during the service subscription or during the customer relationship.
The results of measurements obtained through Bodymaja and produced by measuring devices and locations.
All information created about you within the platform, using, for example, artificial intelligence or other analysis tools.
We also receive tracking information about how you use our website and services. Bodymaja may also process derived information that has been derived or inferred based on the information received. Our service is also connected to parties that provide identification, verification, credit information, payment processing or other similar services and receives information related to these.
In addition, the user’s online behavior is monitored and analyzed using Google Analytics, Active Campaign, LiveChat, Youtube, Google Optimize, Google Ads, Google Tag Manager and Meta, Freshdesk, MailGun, Vello services.
The above services are used for website development, customer service and marketing targeting. Data is collected from, for example, email campaigns.
4. We process personal data for the following purposes:
- The processing of personal data is based on, among other things, obligations set by legislation, such as the processing and storage of information related to health services, in accordance with Valvira’s guidelines.
- Customer relationship management – for example, sending notifications related to orders, product or service-related notifications or updates, customer instructions
- Providing and maintaining the service, managing and delivering orders
Identifying data subjects - Storing transaction data
- Organizing, implementing and monitoring measurements
- Subcontractor communication with our contractual partners
- Managing the user’s own health and other information
- Invoices, collection, refunding payments to customers
- Archiving agreements and invoices
- Communication and marketing related to Bodymaja’s or our partners’ products and services
- Targeting communication, marketing and services to the customer.
- Monitoring the effectiveness of email marketing (for example, message openings and link clicks) so that we can develop communications and offer better targeted content to our customers.
- Informing and reminding customers, for example, about test renewals or Bodymaja services
- Collecting and monitoring, analyzing, and developing customer service related to customer interests, choices, and wishes regarding services and locations
- Taking into account customer wishes and developing customer service and targeting offerings
- Targeted direct marketing (for current and potential future customers)
- Developing Bodymaja’s services and business and developing related customer service.
- Bodymaja’s own operations planning, development, statistics, reporting, audits and other tasks required to implement the rights and obligations of the controller
- Feedback and surveys and customer satisfaction measurements
- Statistical processing, for example to compare results with a specific target group
- Processing customer feedback, managing complaints and disputes
- Processing official requests for clarification based on EU or Finnish legislation, e.g. the Data Protection Regulation
- Transfers of personal data (for example, business transfers, transfers or business transactions)
- Partner reporting
- Substantiation, presentation or defense of legal claims
5. What is the legal basis for processing personal data?
The legal bases for processing personal data include, among others, the following:
- We need to establish a contractual relationship between you and Bodymaja and fulfill our contractual obligations.
- Your consent. If our processing of personal data is based on your consent, you can withdraw your consent at any time.
- We need to comply with legal obligations (for example, the law requires us to retain certain information for a certain period of time) and to justify, assert or defend Bodymaja’s legal claims.
- The legal basis for processing personal data may also be a statutory obligation, such as the retention of information related to the provision of healthcare services and reporting to Valvira.
We need to defend our legitimate interests, including:
- Internal reporting
- Partner reporting
- Product and service development, including feedback and surveys
- Transfers of personal data (including transfers and disclosures)
- Compensation requests
- Direct marketing to current and potential future customers
- Debt collection
6. Who processes my personal data and where is it disclosed?
Bodymaja processes personal data for the above-mentioned purposes. Bodymaja may outsource the processing of personal data to external service providers who process personal data on behalf of Bodymaja.
Bodymaja staff only process personal data as part of their work duties and within the protection of a confidentiality agreement. For example, customer service may check your data without notice when you inquire about something related to your results or personal data stored in the service. Customer service may also check the matter without notice to clarify other matters.
Bodymaja acquires the equipment used in the measurement services from Inbody Co Ltd, which is responsible for the data as an independent data controller in Europe. The results of body composition measurements ordered by Bodymaja customers are also delivered to Bodymaja’s online service for the customer to view.
At Bodymaja, your data and the measurement results you ordered are visible in Bodymaja’s online service so that you can view them and follow your progress.
Bodymaja is a Finnish company and operates independently.
With the Bodymaja results report, you can, if you wish, purchase additional services from third parties and receive, for example, advice regarding your health.
Customer data is generally not transferred outside the European Union or the European Economic Area.
7. Automated decision-making and profiling
Our operations use automated decision-making and profiling to develop and target services. For example, we use artificial intelligence-based systems that analyze user data, such as behavioral patterns and purchase history, so that we can offer more personalized services and offers.
Automated decision-making can also be used, for example, to speed up customer service and streamline service processes.
Profiling means the automatic processing of data to evaluate certain characteristics of a person, such as preferences or behavior. This may include, for example, personalization of services and targeting of marketing.
Customers have the right to request that decisions based on automated decision-making be reviewed by a human. These services are generally subject to an additional fee.
8. Your rights
Right to access personal data: You have the opportunity to view your own data via your order receipt and/or Bodymaja’s OmaBody service. The service covers the personal data you have provided, as well as the measurement results and information you have provided related to your health. You can also make a written request for inspection of your personal data to Bodymaja.
Right to rectification of data: You can make a written request for rectification to Bodymaja’s customer service.
Right to delete data: Your data can be deleted from Bodymaja based on your request, unless there is a special reason for refusing the deletion request.
Withdrawal of consent: When the processing is based on your consent, you can withdraw your consent at any time. You can withdraw your consent from our customer service.
Right to transfer data from one system to another: You can save your test results for yourself and copy the information you have provided yourself via the Oma Body service. If the service has an export function, you can export the data to another system to a limited extent.
Right to lodge a complaint with a supervisory authority: If you believe that the processing of your personal data has violated the Data Protection Regulation, you have the right to lodge a complaint with a supervisory authority.
9. How is personal data protected?
Data protection and security are of paramount importance to us. All data processing is carried out using Bodymaja’s information systems. Personal data is stored in a high-security server room in Finland and Europe.
Health data is only processed by those persons responsible for the measurement services who are necessary for providing the service and who have given a written confidentiality commitment. Personal data is processed in accordance with the personal user ID and the authorizations required by the job duties.
Sensitive health and well-being data is only processed by healthcare professionals who are bound by confidentiality and is stored in protected information systems that meet the requirements for healthcare data protection.
Bodymaja uses a certified patient information system that is connected to the Kanta service. The customer is identified with strong identification before an appointment or a sensitive information request.
The CEO is the data protection officer at Bodymaja.
Get an accurate picture of your body composition
effortlessly and whenever you want!
We want to offer you a new way to get an accurate picture of your body composition. With our InBody 770 measurement, you can explore the inner world of your body and better understand what it needs to function at its best.
Update your knowledge today, measure regularly and give your body the attention it deserves. Solve problems, achieve your goals and take the first step towards a healthier and more balanced life.