{"id":2302,"date":"2026-03-11T10:58:10","date_gmt":"2026-03-11T10:58:10","guid":{"rendered":"https:\/\/leopoly.com\/leoshape\/?page_id=2302"},"modified":"2026-03-11T11:12:55","modified_gmt":"2026-03-11T11:12:55","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/leopoly.com\/leoshape\/legal\/privacy-policy\/","title":{"rendered":"Privacy Policy for LeoShape Software Services"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"2302\" class=\"elementor elementor-2302\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7a41a33b e-flex e-con-boxed e-con e-parent\" data-id=\"7a41a33b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d8639a0 elementor-widget elementor-widget-heading\" data-id=\"d8639a0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Privacy Policy<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ed81269 elementor-widget elementor-widget-heading\" data-id=\"ed81269\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">For LeoShape Software Services<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0e9ed01 elementor-widget elementor-widget-text-editor\" data-id=\"0e9ed01\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Effective Date: March 11, 2026<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-55f67f7 elementor-widget elementor-widget-heading\" data-id=\"55f67f7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">1. Introduction and Our Roles<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1c37773b elementor-widget elementor-widget-text-editor\" data-id=\"1c37773b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This Privacy Policy explains how Leopoly Ltd. (Registered office: 6000 Kecskem\u00e9t, Homokszem u. 3., Hungary) and Leopoly Next Inc. (3 E 3RD AVE San Mateo Clocktower, CA 94401, USA) \u2014 collectively referred to as <strong>&#8220;Leopoly&#8221;<\/strong>, <strong>&#8220;Service Provider&#8221;<\/strong>, <strong>&#8220;we&#8221;<\/strong>, <strong>&#8220;us&#8221;<\/strong>, or <strong>&#8220;our&#8221;<\/strong> \u2014 collect, use, store, and protect personal and health-related data when you use the LeoShape editors, the Order Management System (OMS), and the LeoCapture mobile application (collectively: the <strong>&#8220;Services&#8221;<\/strong>).<\/p><p>To align out practices with key data protection laws, including the European General Data Protection Regulation (GDPR) and we applicable the U.S. Health Insurance Portability and Accountability Act (HIPAA), Leopoly acts in two distinct legal capacities depending on the type of data:<\/p><ul><li><strong>As a Data Controller:<\/strong> When we collect and process the personal data of the professionals, clinics, doctors, or technicians (hereinafter: <strong>&#8220;Subscribers&#8221;<\/strong> or <strong>&#8220;Users&#8221;<\/strong>) who register to use our Services (e.g., account credentials, billing information).<\/li><li><strong>As a Data Processor \/ Business Associate:<\/strong> When we store and process the personal and health-related data of the patients uploaded or captured by our Subscribers using our Services (e.g., 3D scans, diagnoses, order details). In this scenario, the <strong>Clinic \/ Professional is the Data Controller \/ Covered Entity<\/strong>, responsible for obtaining patient consent. Leopoly processes this data solely on behalf of the Subscriber, strictly following their instructions and the applicable Data Processing Agreement (DPA) or Business Associate Agreement (BAA).<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5a00c28 elementor-widget elementor-widget-heading\" data-id=\"5a00c28\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">2. Information We Collect<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-79c1371 elementor-widget elementor-widget-text-editor\" data-id=\"79c1371\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>A) Information Collected from Subscribers (Professionals):<\/strong><\/p><ul><li><strong>Identification Data:<\/strong> Email address, name (optional), passwords (encrypted).<\/li><li><strong>Contractual and Billing Data:<\/strong> Company details, workplace, job title, and payment information.<\/li><li><strong>Technical and Usage Data:<\/strong> IP addresses, login timestamps, browser and device types, and analytics regarding the usage of the Services (e.g., number of downloads, edits performed).<\/li><\/ul><p>\u00a0<\/p><p><strong>B) Information Managed about Patients (Processed on behalf of Subscribers):<\/strong><\/p><p>While using the Services, Subscribers may highly customize the patient data they record. We treat all such data as sensitive health data and, where applicable for U.S. healthcare customers, as Protected Health Information (PHI). This may include:<\/p><ul><li>Patient name or identification number.<\/li><li>Patient address (for shipping purposes).<\/li><li>3D scans and captures of limbs or other body parts.<\/li><li>Scan dates, order IDs, and order status history.<\/li><li>Final orthosis\/prosthesis geometry and CAD design parameters.<\/li><li>Free text notes (which may contain medical history, clinical relationship, or manufacturing instructions).<\/li><li>Patient-clinician-doctor relationship details<\/li><li>Project files for the orthosis editor<\/li><li>Photos of human body parts and order forms &#8211; produced by the clinician<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fbb71b9 elementor-widget elementor-widget-heading\" data-id=\"fbb71b9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">3. Purpose and Legal Basis for Processing<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c6a89d elementor-widget elementor-widget-text-editor\" data-id=\"7c6a89d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>For Subscriber (Professional) Data:<\/strong><\/p><ul><li><strong>Purpose:<\/strong> To provide access to the software, manage user permissions within the OMS, provide customer support, process billing, maintain system security, and enforce our Terms of Service (ToS).<\/li><li><strong>Legal Basis (under GDPR):<\/strong> Processing is necessary for the performance of a contract (Art. 6(1)(b)) and our legitimate interests in improving and securing our software (Art. 6(1)(f)).<\/li><\/ul><p>\u00a0<\/p><p><strong>For Patient Data:<\/strong><\/p><ul><li><strong>Purpose:<\/strong> To provide the core functionalities of the software (3D scanning, CAD editing, order management, and tracking) for Clinics and Labs to prepare for the manufacturing process (3D printing \/ CNC). <strong>We never use patient data for our own marketing purposes, nor do we sell this data to third parties.<\/strong><\/li><li><strong>Legal Basis (under GDPR):<\/strong> The legal basis for uploading patient data is established by the Data Controller (the Clinic\/Doctor), for example on the basis of healthcare provision or other applicable legal grounds under the GDPR and\/or HIPAA. Leopoly acts solely upon the instructions of the Clinic based on the executed DPA\/BAA.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5fcc542 elementor-widget elementor-widget-heading\" data-id=\"5fcc542\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">4. Data Security (HIPAA &amp; GDPR Compliance)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dcf666a elementor-widget elementor-widget-text-editor\" data-id=\"dcf666a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Safeguarding the Protected Health Information (PHI) and personal data uploaded to our Services is our top priority.<\/p><ul><li><strong>Encryption:<\/strong> Data is encrypted both in transit and at rest on our servers.<\/li><li><strong>Access Controls:<\/strong> Within the OMS, our Subscribers can configure strict, role-based access levels. Leopoly personnel only access specific patient data when explicitly authorized by the Subscriber for technical support or troubleshooting.<\/li><li><strong>Hosting Infrastructure:<\/strong> Data is securely hosted with industry-leading cloud service providers (e.g., Amazon Web Services &#8211; AWS). We strive to respect data residency requirements for region-sensitive clients (e.g., hosting production environment for U.S. clients in the US and for EU clients in the EU), subject to our infrastructure design and the terms of the applicable DPA\/BAA.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9b4c7dc elementor-widget elementor-widget-heading\" data-id=\"9b4c7dc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">5. Data Sharing and Sub-processors<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0489fa2 elementor-widget elementor-widget-text-editor\" data-id=\"0489fa2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>We only share personal and health data with trusted sub-processors strictly necessary for operating our Services:<\/p><ul><li><strong>Cloud Hosting Providers<\/strong> (e.g., AWS).<\/li><li><strong>Payment Processors<\/strong> (e.g., Stripe &#8211; exclusively for Subscriber billing data; they do not have access to patient data).<\/li><li><strong>Manufacturing Integrations:<\/strong> If a Subscriber chooses to forward data directly to a third-party laboratory or 3D printing service via the OMS or Editor, this transfer is executed strictly at the Subscriber\u2019s command and responsibility.<\/li><\/ul><p>\u00a0<\/p><p>Leopoly executes appropriate Data Processing Agreements and Business Associate Agreements with all sub-processors to ensure GDPR and HIPAA compliance.<\/p><p>Where we engage sub\u2011processors located outside the EEA, any transfer of personal data is carried out on the basis of the Data Controller\u2019s documented instructions and appropriate safeguards, such as the EU Standard Contractual Clauses and, where applicable, the EU\u2011U.S. Data Privacy Framework, supplemented by additional technical and organizational measures where required.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3015437 elementor-widget elementor-widget-heading\" data-id=\"3015437\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">6. Data Retention Policy<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-615bd79 elementor-widget elementor-widget-text-editor\" data-id=\"615bd79\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li><strong>Subscriber Data:<\/strong> We retain your account data for as long as your contract (ToS) is active, or as required by applicable accounting and tax laws.<\/li><li><strong>Patient Data:<\/strong> 3D models, order IDs, and notes are stored as long as the Clinic uses our Services and in accordance with the data retention instructions and legal obligations of the Clinic as Data Controller. If a Subscriber terminates their contract, all associated patient data will be deleted from our servers or returned upon request, in accordance with the terms of the DPA\/BAA. Subscribers can also independently delete their patients&#8217; data from the OMS at any time.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5bd8ff4 elementor-widget elementor-widget-heading\" data-id=\"5bd8ff4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">7. Data Subject Rights (Access, Correction, Deletion)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dbd9d01 elementor-widget elementor-widget-text-editor\" data-id=\"dbd9d01\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>If you are a User of the Software (Professional \/ Doctor):<\/strong> You have the right to request access to, correction, or deletion of your personal data, or object to its processing under the GDPR. You can exercise these rights by contacting us at privacy@leopoly.com. Please indicate \u201cData protection\u201d or \u201cData breach notification\u201d in the subject line so that we can ensure your request is handled without undue delay.<\/p><p><strong>If you are a Patient (whose data was recorded in our system by your doctor):<\/strong> Because Leopoly acts as a Data Processor\/Business Associate, you must exercise your data privacy rights (such asas access, correction, or deletion under the GDPR, or your HIPAA rights) <strong>directly with your healthcare provider or Clinic (the Data Controller\/Covered Entity)<\/strong>. Leopoly is contractually obligated to assist Clinics technologically in fulfilling these requests promptly.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6994b26 elementor-widget elementor-widget-heading\" data-id=\"6994b26\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">8. International Data Transfers<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-af5625c elementor-widget elementor-widget-text-editor\" data-id=\"af5625c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Because Leopoly Ltd. is based in the European Union and Leopoly Next Inc. is based in the United States, cross-border data transfers may occur.<\/p><p>Any such cross\u2011border transfers of personal data relating to individuals in the EEA\/UK will be carried out only on the basis of the Data Controller\u2019s documented instructions and subject to appropriate safeguards as required by applicable data protection laws.<\/p><ul><li>For <strong>United States clients<\/strong> (HIPAA), data is stored on servers located within the USA.<\/li><li>For <strong>European Union clients<\/strong> (GDPR), data is stored within the EU (e.g., AWS Frankfurt\/Ireland). If international data transfer is required, we rely on legally approved mechanisms such as Standard Contractual Clauses (SCCs) or the EU-U.S. Data Privacy Framework.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b4639a8 elementor-widget elementor-widget-heading\" data-id=\"b4639a8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">9. Changes to this Privacy Policy<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-25b45e4 elementor-widget elementor-widget-text-editor\" data-id=\"25b45e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>We reserve the right to update this Privacy Policy periodically to reflect changes in our Services or legal requirements. We will notify our Subscribers of any material changes via the OMS platform or by email prior to the changes taking effect.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dd21d69 elementor-widget elementor-widget-heading\" data-id=\"dd21d69\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">10. Contact Us<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e624e24 elementor-widget elementor-widget-text-editor\" data-id=\"e624e24\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>If you have any questions about our privacy practices, data processing, or DPA\/BAA agreements, please contact us at:<\/p><ul><li><strong>Email:<\/strong> <a href=\"mailto:privacy@leopoly.com\">privacy@leopoly.com<\/a><\/li><li><strong>Mailing Address (EU):<\/strong> Leopoly Kft., 6000 Kecskem\u00e9t, Homokszem u. 3., Hungary<\/li><li><strong>Mailing Address (USA):<\/strong> Leopoly Next Inc., 3 E 3RD AVE San Mateo Clocktower, CA 94401 USA<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>This Privacy Policy explains how Leopoly Ltd. and Leopoly Next Inc. \u2014 collectively referred to as &#8220;Leopoly&#8221;, &#8220;Service Provider&#8221;, &#8220;we&#8221;, &#8220;us&#8221;, or &#8220;our&#8221; \u2014 collect, use, store, and protect personal and health-related data when you use the LeoShape editors, the Order Management System (OMS), and the LeoCapture mobile application (collectively: the &#8220;Services&#8221;).<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":2328,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-2302","page","type-page","status-publish","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/pages\/2302","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/comments?post=2302"}],"version-history":[{"count":13,"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/pages\/2302\/revisions"}],"predecessor-version":[{"id":2332,"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/pages\/2302\/revisions\/2332"}],"up":[{"embeddable":true,"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/pages\/2328"}],"wp:attachment":[{"href":"https:\/\/leopoly.com\/leoshape\/wp-json\/wp\/v2\/media?parent=2302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}