Data Processing Addendum
IntelaMetrix Holdings, Inc.
Data Processing Addendum | v3.0 · Effective Date: July 21, 2026 · Forms part of the IntelaMetrix Master EULA
IntelaMetrix Holdings, Inc. ("IntelaMetrix," "BodyMetrix," or "the Company," collectively referred to as "we," "us," or "our") and the Customer identified in the applicable order or activation record enter into this Data Processing Addendum ("DPA"). This DPA forms part of, and is subject to, the IntelaMetrix Master End User License Agreement (EULA). This page mirrors Schedule C of the Master EULA for transparency. In the event of any conflict between this page and the Master EULA, including Schedules C and D, the Master EULA controls.
This DPA applies where IntelaMetrix processes personal data in connection with the Platform and the Customer is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), or Quebec Law 25. IntelaMetrix's obligations under this DPA are best-effort obligations reflecting IntelaMetrix's commitment to good-faith compliance. They do not constitute a warranty or guarantee of full technical compliance with any specific regulatory requirement, per Master EULA Section 10.4 and Schedule C1.
1. Roles of the Parties
| Data Category | Customer Role | IntelaMetrix Role |
|---|---|---|
| Customer Data (BodyMetrix App) — body composition measurements, End User records, assessment results submitted through the Platform | Controller | Processor, processing on Customer's behalf per the Master EULA |
| Aggregated, De-Identified, and Derived Data; AI/ML Training Data | None — Customer assigns all rights per EULA Section 4.3 | Controller and exclusive owner |
| License Validation Data (legacy BodyView) — IP address, device identifier, license key, software version, OS version, validation timestamp | None | Independent Controller |
| Locally stored BodyView measurement data (legacy) | Sole Controller | None — never received, accessed, or processed by IntelaMetrix |
2. Scope of Processing
2.1 BodyMetrix App (Cloud Platform)
Where Customer uses the BodyMetrix App, IntelaMetrix processes the following categories of personal data on Customer's behalf, for the purposes set forth in the Master EULA:
| Data Category | Purpose | Retention |
|---|---|---|
| Customer Data — body composition measurements, End User records, assessment results | Operating, supporting, maintaining, and improving the Platform; generating aggregated, de-identified, and derived data; AI/ML model development per EULA Sections 4 and 5 | Duration of active subscription plus 30 days post-termination (EULA Section 4.8) |
| Device telemetry — subscription status, device activity, error logs, performance data | License enforcement, abuse detection, security investigation, Platform operation (EULA Section 7.2) | Per EULA Section 4.8; telemetry collection is continuous and cannot be disabled |
| Account, billing, and support data | Account management, billing, support delivery | Duration of relationship plus applicable legal retention periods |
| Log, security, and audit data | Security monitoring, incident investigation, compliance | Per IntelaMetrix security retention schedules |
Aggregated Data, De-Identified Data, and Derived Data generated from the foregoing are owned exclusively by IntelaMetrix, are retained indefinitely, and are not subject to Customer-requested deletion, per EULA Sections 4.3 and 4.8.
2.2 Legacy BodyView (On-Premise)
For legacy BodyView installations, IntelaMetrix processes only License Validation Data transmitted through periodic license checks:
| Data Element | Purpose | Legal Basis | Retention |
|---|---|---|---|
| IP address | License validation, fraud prevention | Legitimate interest (contract performance) | 2 years from last validation |
| Device / machine identifier | License enforcement, anti-piracy | Contract performance | 2 years from last validation |
| License key | License status confirmation | Contract performance | Duration of subscription + 2 years |
| Software version | Update eligibility, support triage | Legitimate interest | 2 years from last validation |
| OS version | Compatibility validation | Legitimate interest | 2 years from last validation |
| Validation timestamp | Audit trail, fraud detection | Legitimate interest | 2 years from last validation |
IntelaMetrix does not receive, access, or process body composition measurements, client records, session notes, or any data stored in the local BodyView database of legacy installations.
3. Processing Obligations
IntelaMetrix shall, on a best-effort basis, per Master EULA Schedule C3:
- process Customer Data only for the purposes set forth in the Master EULA
- implement commercially reasonable technical and organizational safeguards appropriate to the risk
- assist Customer with valid data subject requests to the extent technically feasible
- notify Customer of a confirmed personal data breach within a commercially reasonable timeframe consistent with applicable law
- upon termination, handle Customer Data in accordance with EULA Section 4.6, including the thirty (30)-day data export window
4. Data Security
IntelaMetrix maintains a security program appropriate to the risk of the data it processes, including:
- Encryption of data in transit using TLS 1.2 or higher
- Role-based access controls limiting data access to personnel with a defined operational need
- Regular security assessments of Platform infrastructure
- Audit logging of access to personal data
5. Breach Notification
IntelaMetrix will use commercially reasonable efforts to notify Customer of a confirmed security breach affecting Customer Data within a timeframe consistent with applicable law, per Master EULA Section 7.4. Notification obligations for HIPAA-covered PHI are governed by EULA Schedule D, which requires notification without unreasonable delay and no later than thirty (30) calendar days after discovery of a Breach of Unsecured PHI. Notification obligations for GDPR and UK GDPR personal data are governed by EULA Schedule C.
6. Subprocessors
Customer authorizes IntelaMetrix's use of subprocessors to deliver the Platform, per Master EULA Schedule C4. IntelaMetrix remains responsible for subprocessors' compliance to the extent within IntelaMetrix's reasonable control. Current subprocessor categories:
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloud computing platform | Platform hosting and license validation infrastructure | United States |
| eCommerce Platform | Account and subscription management | United States / Canada |
| CRM | Account holder contact data only | United States |
| Payment Platform | Payment processing | United States |
A current list of subprocessors may be provided upon written request to privacy@BodyMetrix.com.
7. International Transfers
Customer Data may be transferred to and processed in the United States and other jurisdictions outside Customer's country of residence. Where required by applicable law, IntelaMetrix will implement appropriate safeguards for international transfers, including Standard Contractual Clauses (SCCs) for EU, UK, and Swiss transfers, per Master EULA Schedule C5. For Customers in the European Economic Area, the United Kingdom, and Switzerland, IntelaMetrix does not transfer End User personal data or body composition measurement records to United States infrastructure until the applicable SCC instrument (or equivalent safeguard) has been executed for the Customer’s account. This restriction is enforced technically by the BodyMetrix App, which holds such data on the Customer’s local device until the safeguard is in place.
8. Canada: PIPEDA and Quebec Law 25
For Canadian customers, IntelaMetrix endeavors to process personal data in a manner consistent with PIPEDA's accountability, consent, and accuracy principles and with Quebec Law 25's transparency and privacy impact assessment requirements. IntelaMetrix's Canadian compliance obligations are best-effort and will be updated as IntelaMetrix's compliance program matures and as Canadian privacy law enforcement guidance develops, per Master EULA Schedule C6.
9. Data Subject Rights
Where required by applicable law, individuals may exercise data subject rights including access, correction, deletion, portability, and objection to processing. Requests may be submitted through our Privacy Rights Request Form or by emailing privacy@BodyMetrix.com. For End User data submitted by a professional or organizational Customer through the Platform, the Customer is the Controller; we will assist Customers in responding to valid requests to the extent technically feasible.
The exercise of data subject rights does not affect IntelaMetrix's rights with respect to Aggregated Data, De-Identified Data, Derived Data, and AI/ML Training Data, per Master EULA Sections 4.3 and 5 and Schedule C7. Where applicable law grants a right to erasure, IntelaMetrix will de-identify and suppress the underlying identifiable source data; erasure of individual data points from trained model weights or aggregated datasets may not be technically feasible, as set forth in EULA Section 5.4.
10. Retention and Deletion
- Customer Data (BodyMetrix App): retained for the duration of the active subscription plus thirty (30) days following termination, during which Customer may export data. After that period, IntelaMetrix has no obligation to retain Customer Data in identifiable form, per EULA Section 4.8.
- License Validation Data (legacy BodyView): retained for 2 years from the last validation event.
- Aggregated, De-Identified, and Derived Data: retained indefinitely as IntelaMetrix-owned assets, not subject to Customer-requested deletion.
- HIPAA Business Associate documentation: retained for a minimum of six (6) years where Schedule D applies, per 45 C.F.R. § 164.530(j).
11. HIPAA: Business Associate Addendum
Where Customer is a Covered Entity or Business Associate under HIPAA and self-identifies as such at Platform activation (or otherwise during the subscription term), the HIPAA Business Associate Addendum set forth in Schedule D of the Master EULA activates automatically. Under Schedule D, IntelaMetrix acts as Business Associate with respect to Protected Health Information (PHI) it creates, receives, maintains, or transmits on behalf of the Covered Entity through the Platform, and undertakes obligations including Security Rule safeguards, breach notification within thirty (30) days, subcontractor flow-down, and support for individual rights under 45 C.F.R. §§ 164.524 through 164.528. Read the full BAA in the Master EULA, Schedule D.
PHI that has been de-identified in accordance with 45 C.F.R. § 164.514(b) is no longer PHI and is subject to IntelaMetrix's data and AI/ML rights under the Master EULA, per Schedule D9.2.
For legacy BodyView installations, IntelaMetrix does not receive, access, or maintain PHI, because measurement data never leaves the Customer's local PC. If a Customer's specific configuration would result in IntelaMetrix receiving PHI outside a Schedule D engagement, that Customer must notify IntelaMetrix at legal@BodyMetrix.com before any such data transmission occurs.
12. Limitation
This DPA does not expand IntelaMetrix's obligations under Master EULA Sections 4.3 and 5 with respect to Aggregated Data, De-Identified Data, Derived Data, or AI/ML Training Data, which IntelaMetrix owns and controls exclusively, per Schedule C7. Nothing in this DPA expands IntelaMetrix's aggregate liability beyond the cap set forth in EULA Section 12.2, except to the extent applicable law prohibits such limitation.
13. Order of Precedence
This DPA is governed by the laws of the State of Delaware. This page summarizes and mirrors Schedules C and D of the Master EULA. In the event of a conflict between this page and the Master EULA, the Master EULA controls. In the event of a conflict between Schedule D and any other provision of the Master EULA with respect to PHI, Schedule D controls, per EULA Schedule D9.1.
14. Contact
IntelaMetrix Holdings, Inc. — Privacy & Legal
2010 Elkins Way, Suite 2, Brentwood, CA 94513
privacy@BodyMetrix.com
916-840-0096
