Legal Document

Privacy Policy

This Privacy Policy describes how Biosspine collects, uses, stores, and protects your personal information when you visit our website or use our services.

1. Data Controller Information

The data controller responsible for your personal information is:

  • Company Name: Biosspine
  • Address: 75 9th Ave, New York, NY 10011, USA
  • Phone: +1 212-652-2110
  • Email: assist@biosspine.world
  • Website: biosspine.world

For any questions regarding this Privacy Policy or the processing of your personal data, you may contact us using the details above.

2. Scope and Applicability

This Privacy Policy applies to all personal data collected through our website at biosspine.world, including data submitted via contact forms, cookie interactions, and any correspondence you initiate with us. It also applies to data collected during nutrition consulting sessions, educational program enrollment, and purchase of educational products.

By using our website or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please discontinue use of our website and services.

This policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) where applicable, and other relevant data protection legislation in jurisdictions where our services are accessed.

3. Categories of Personal Data We Collect

3.1 Information You Provide Directly

When you interact with our website or services, you may voluntarily provide the following categories of personal data:

  • Identity Data: Your full name and any preferred name you share during consultations.
  • Contact Data: Email address, phone number, and mailing address when provided.
  • Communication Data: Content of messages submitted through our contact form, email correspondence, and consultation notes.
  • Preference Data: Dietary preferences, food restrictions, scheduling preferences, and service interests you share during consultations.
  • Consent Records: Records of GDPR consent checkboxes, cookie preferences, and marketing opt-in or opt-out selections.

3.2 Information Collected Automatically

When you visit our website, certain data may be collected automatically through cookies and similar technologies, subject to your consent preferences:

  • Technical Data: IP address, browser type and version, operating system, device type, and screen resolution.
  • Usage Data: Pages visited, time spent on pages, navigation paths, referral sources, and click patterns.
  • Cookie Data: Information stored in cookies as described in our Cookie Policy.

3.3 Information from Third Parties

We do not routinely purchase or receive personal data from third-party data brokers. If you are referred to us by a partner organization with your explicit consent, we may receive your name and contact details solely for the purpose of initiating communication about our services.

4. Purposes of Data Processing

We process your personal data for the following specific purposes, each supported by an appropriate legal basis under GDPR:

  1. Responding to Inquiries: To read, process, and respond to messages submitted through our contact form or sent via email. Legal basis: legitimate interest in operating our business and responding to customer requests; consent where required.
  2. Providing Consulting Services: To schedule, conduct, and follow up on nutrition consulting sessions and deliver personalized meal planning guidance. Legal basis: performance of a contract or pre-contractual steps at your request.
  3. Delivering Educational Products: To process enrollments, deliver educational materials, and manage program participation. Legal basis: performance of a contract.
  4. Website Operation and Security: To maintain website functionality, prevent fraud, detect security incidents, and protect against unauthorized access. Legal basis: legitimate interest in securing our systems.
  5. Analytics and Improvement: To analyze website usage patterns and improve content, navigation, and user experience. Legal basis: consent for non-essential analytics cookies.
  6. Marketing Communications: To send informational newsletters or service updates where you have opted in. Legal basis: consent, which may be withdrawn at any time.
  7. Legal Compliance: To comply with applicable laws, regulations, court orders, or governmental requests. Legal basis: legal obligation.

5. Legal Bases for Processing Under GDPR

For individuals located in the European Economic Area (EEA), United Kingdom, or other jurisdictions where GDPR applies, we rely on the following legal bases:

  • Consent (Article 6(1)(a)): Where you have given clear consent for specific processing activities, such as analytics cookies or marketing emails.
  • Contract Performance (Article 6(1)(b)): Where processing is necessary to fulfill a contract with you or to take steps at your request before entering a contract.
  • Legitimate Interests (Article 6(1)(f)): Where processing is necessary for our legitimate business interests, such as responding to inquiries or maintaining website security, provided your rights do not override those interests.
  • Legal Obligation (Article 6(1)(c)): Where processing is required to comply with a legal obligation to which we are subject.

6. Data Retention Periods

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law:

  • Contact Form Submissions: Retained for 24 months from the date of submission, unless an ongoing business relationship develops.
  • Consultation Records: Retained for 5 years from the date of the last session to support continuity of service and reference.
  • Contract and Payment Records: Retained for 7 years to comply with tax and accounting obligations.
  • Cookie Consent Records: Retained for 12 months from the date consent was given or updated.
  • Marketing Consent Records: Retained until you withdraw consent, plus 3 years for compliance documentation.
  • Server Log Files: Retained for 90 days for security monitoring purposes.

Upon expiration of the applicable retention period, personal data is securely deleted or anonymized so that it can no longer be associated with you.

7. Data Sharing and Third-Party Processors

We do not sell your personal data to third parties. We may share your data with the following categories of recipients under strict data processing agreements:

  • Hosting Providers: Cloud infrastructure providers that store our website and email systems.
  • Email Service Providers: Platforms used to send and receive business correspondence.
  • Analytics Providers: Services that help us understand website usage, activated only with your consent.
  • Payment Processors: Secure payment gateways used to process transactions for consulting services and educational products.
  • Professional Advisors: Legal, accounting, or compliance professionals bound by confidentiality obligations.

All third-party processors are required to implement appropriate technical and organizational measures to protect your data and process it only according to our documented instructions.

8. International Data Transfers

Our primary operations are based in the United States. If you access our website from the EEA, UK, or other regions with data transfer restrictions, your personal data may be transferred to and processed in the United States.

Where required, we implement appropriate safeguards for international transfers, including Standard Contractual Clauses approved by the European Commission, and we assess the adequacy of data protection in recipient countries.

9. Security Measures

We implement technical and organizational security measures designed to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • HTTPS encryption for all data transmitted between your browser and our servers.
  • Access controls limiting personal data access to authorized personnel on a need-to-know basis.
  • Regular review and updating of security practices and infrastructure.
  • Secure storage of consultation records with encryption at rest where technically feasible.
  • Employee training on data protection principles and confidentiality obligations.
  • Incident response procedures for detecting, reporting, and addressing data breaches.

While we work to protect your personal data, no method of transmission over the Internet or electronic storage is completely secure. We commit to notifying affected individuals and relevant authorities of breaches as required by applicable law.

10. Your Rights Under GDPR and Applicable Law

Depending on your location, you may have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data where there is no compelling reason for continued processing.
  • Right to Restrict Processing: Request limitation of processing in certain circumstances.
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: File a complaint with a supervisory authority in your country of residence.

To exercise any of these rights, contact us at assist@biosspine.world or by mail at our address listed above. We will respond within 30 days of receiving a verifiable request.

11. Children's Privacy

Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without verified parental consent, we will take steps to delete that information promptly.

12. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on individuals. Any personalization of meal planning guidance is performed by human consultants based on information you provide.

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. The date at the top of this page indicates when the policy was last revised. Material changes will be communicated through a notice on our website. Continued use of our website after changes constitutes acceptance of the updated policy.

14. Contact Information for Data Protection Inquiries

For questions, concerns, or requests related to this Privacy Policy or your personal data, please contact:

  • Biosspine
  • 75 9th Ave, New York, NY 10011, USA
  • Phone: +1 212-652-2110
  • Email: assist@biosspine.world