Privacy Policy

Spartan Kismet LLC d/b/a DexaFit Central Jersey

Effective: August 17, 2026

THIS POLICY EXPLAINS WHAT INFORMATION WE COLLECT, HOW WE USE IT, WHO WE SHARE IT WITH, AND THE CHOICES YOU HAVE. IT COVERS BOTH OUR WEBSITE AND THE HEALTH AND FITNESS INFORMATION WE COLLECT WHEN YOU COME IN FOR TESTING. IT IS INCORPORATED INTO OUR TERMS & CONDITIONS.

1. Who We Are and What This Policy Covers

Spartan Kismet LLC, a New Jersey limited liability company doing business as DexaFit Central Jersey ("DexaFit Central Jersey," "we," "us," or "our"), operates a health and wellness assessment facility at 665 Martinsville Rd, Unit 22b, Basking Ridge, NJ 07920. We provide DXA body composition and bone density scans, VO₂ max testing, resting metabolic rate (RMR) and metabolic testing, and related services.

This Privacy Policy applies to information we collect through our website, our booking and scheduling system, our intake forms, our email and text messaging, and your visits to our facility. It is incorporated by reference into our Terms & Conditions, and capitalized terms used here have the meanings given there.

This Policy does not govern the DexaFit software platform, mobile applications, or digital reports operated by DexaFit, Inc. ("DexaFit Corporate"), which are governed by DexaFit Corporate's own privacy policy at dexafit.com/privacy. It also does not govern the separate privacy practices of any physician, laboratory, or other provider you engage directly.

2. Our Status Under HIPAA — Please Read This Carefully

People often assume that any business handling health information is governed by HIPAA. That is not how the law works, and we want to be straightforward with you about where we sit.

Under HIPAA, a health care provider becomes a "covered entity" only if it transmits health information electronically in connection with certain standard transactions — principally insurance claims, eligibility checks, and related billing transactions. DexaFit Central Jersey does not bill any private insurer, Medicare, Medicaid, TRICARE, or any other government healthcare program, and does not conduct those standard transactions. On that basis, we do not believe we are a HIPAA covered entity, and this Policy — not a HIPAA Notice of Privacy Practices — is the document that governs how we handle your information.

What we commit to anyway. We hold health information, and we think you are entitled to the same level of protection whether or not a federal statute compels it. As a matter of our own binding policy, we apply safeguards equivalent to those HIPAA requires: we limit internal access to those who need it, we do not use or disclose your health information for marketing, we do not sell it, we obtain your written authorization before disclosing it for research or to anyone you have not designated, and we give you the access, copy, and correction rights described in Section 11. These commitments are enforceable against us as terms of this Policy.

Two related points. First, the physician who orders and interprets your DXA scan may be a HIPAA covered entity in his own practice, and his own privacy practices apply to the records he maintains. Second, if our operations change — for example, if we begin billing insurance — we will reassess our status, update this Policy, and issue a Notice of Privacy Practices if one is required.

3. Information We Collect

A. Information you give us directly.

•       Identity and contact information: name, date of birth, postal address, email address, telephone number, and emergency contact.

•       Health and eligibility information: your health history questionnaire, current and past medical conditions, symptoms, medications, implants or prostheses, injuries, surgical history, pregnancy status, activity level, height and weight, and any medical clearance or physician's order you provide. This is the information our Medical Director reviews before deciding whether to order a DXA scan.

•       Appointment and transaction information: services booked, appointment history, packages and gift cards purchased, promotional codes used, and cancellation history.

•       Payment information: billing name and address, and the payment method you use. Full payment card numbers are collected and stored by our third-party payment processor, not by us; we retain only a token and the last four digits.

•       Communications: emails, text messages, voicemails, and notes of conversations with our staff.

•       Optional information: any goals, preferences, feedback, reviews, or survey responses you choose to give us.

B. Information created when we test you.

•       DXA scan data and imagery, including body composition values, bone density measurements, region-of-interest data, and the scan images themselves.

•       VO₂ max, RMR, and metabolic testing data, including gas-exchange measurements, heart rate, and exercise protocol data.

•       3D body scan renders and measurements, where you receive that service.

•       The order issued by the ordering practitioner, and the report and interpretation produced by the interpreting practitioner.

•       Technologist notes regarding positioning, protocol, and quality assurance.

C. Information collected automatically when you use our website.

•       We use Google Analytics to understand how visitors find and use our site. Google Analytics sets cookies and collects your IP address, approximate location derived from it, device and browser type, pages viewed, time on page, and referring website.

•       Our booking system and web host may set cookies that are strictly necessary to operate the site, keep you signed in, and secure your session.

•       We do not run advertising, retargeting, or social media tracking pixels on our website. We do not use session-replay tools that record your screen or keystrokes.

D. Information we receive from others.

•       From a physician or other provider you designate: an order, referral, records, or medical clearance.

•       From DexaFit Corporate: report and analytics output generated by the DexaFit platform from your assessment data.

•       From our service providers: confirmations, delivery receipts, and fraud-prevention signals relating to payments and messages.

4. How We Use Your Information

•       To schedule, prepare for, and deliver the Services you book.

•       To allow the ordering practitioner to determine whether a DXA scan is clinically appropriate for you and to issue an individualized order, and to allow the interpreting practitioner to review your study and produce a report.

•       To generate, deliver, and explain the mechanics of your results and reports.

•       To notify you of results, including abnormal findings, and to arrange follow-up contact where a finding requires it.

•       To take payment, apply packages and promotional codes, and administer cancellation and no-show terms.

•       To communicate with you about appointments, preparation instructions, results, and service changes.

•       To send you marketing communications, where you have consented and until you opt out.

•       To maintain our records, meet our quality assurance obligations, train our staff, and improve our service.

•       To comply with law, respond to regulators and lawful requests, and establish or defend legal claims.

•       To create de-identified and aggregated data as described in Section 9.

5. How We Share Your Information

We share your information only in the circumstances listed below.

•       With the ordering and interpreting practitioner. Your intake, health history, and scan data are provided to our Medical Director or another licensed practitioner so that a scan can be ordered and interpreted, as required by New Jersey law and as described in Sections 3 and 4 of our Terms & Conditions.

•       With providers you designate. We will send your results and reports to any physician or other provider you identify to us, and to anyone else you authorize in writing.

•       With DexaFit Corporate. Your assessment data is transmitted to the DexaFit platform to generate your results and reports. DexaFit Corporate's handling of that data is governed by its own privacy policy at dexafit.com/privacy.

•       With service providers who work on our behalf, under contract and only for the purposes we specify: our booking and scheduling software, payment processor, email and SMS delivery vendors, secure file storage and IT support, and our accountants and professional advisers.

•       With regulators and in legal proceedings. New Jersey regulators may inspect certain records — for example, the Department of Environmental Protection's Bureau of X-Ray Compliance may inspect radiation and quality assurance records under N.J.A.C. 7:28-2.11. We may also disclose information where required by subpoena, court order, or law, or to establish or defend a legal claim.

•       In an emergency, to summon or assist emergency medical services.

•       In a business transfer. If we are acquired, merged, or reorganized, your information may transfer as part of that transaction, subject to this Policy or a successor policy that is no less protective, and we will notify you of any material change.

What we do not do. We do not sell your personal information. We do not share your health information with advertisers, data brokers, or social media platforms. We do not use your health information to target advertising to you. We do not disclose your identifiable records for research without your separate written authorization. We do not share your mobile opt-in or text-messaging consent with third parties for their own marketing.

6. Cookies, Analytics, and Your Website Choices

We use Google Analytics and strictly necessary operational cookies, as described in Section 3.C. We have configured our site so that health information is never passed to Google Analytics: your health history, intake responses, results, and any page content that would reveal what you were tested for are not transmitted to analytics, and are not included in page titles, URLs, or event names that analytics can read.

Your choices:

•       You can block or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent booking from working.

•       You can opt out of Google Analytics entirely by installing Google's browser add-on at tools.google.com/dlpage/gaoptout.

•       We honor the Global Privacy Control (GPC) signal where your browser sends one.

Our website is not designed to respond to browser "Do Not Track" signals, which have no agreed standard meaning.

7. Email and Text Message Communications

Section 24 of our Terms & Conditions sets out the consents you give when you provide your mobile number and email address. In summary:

•       Transactional messages — appointment confirmations, reminders, preparation instructions, results notifications, and service changes — are sent because you are a client, and continue even if you opt out of marketing.

•       Marketing messages — promotions, events, referral and loyalty programs, newsletters — are sent only with your consent, are never a condition of purchasing anything, and stop when you opt out.

•       To opt out of marketing texts, reply STOP to any message. To opt out of marketing emails, use the unsubscribe link. You can also email centraljersey@dexafit.com and we will remove you from all marketing lists.

We do not include health information, results, or the name of a specific test in a marketing message, and we do not segment our marketing lists on the basis of your health information or test results.

8. How We Protect Your Information

We maintain administrative, physical, and technical safeguards appropriate to the sensitivity of the information we hold. These include access controls that limit staff access to what each role requires, individual user accounts rather than shared logins, encryption of data in transit to and from our website and booking system, encryption at rest with our storage and software vendors, locked physical storage for paper records, contractual confidentiality obligations for staff and vendors, and periodic review of who has access to what.

No system is perfectly secure. We cannot guarantee that information transmitted over the internet or stored electronically will never be accessed without authorization, and you send information to us at your own risk. If you ask us to send results to you by ordinary unencrypted email, you accept the risk that email can be intercepted or misdirected; we will use a secure delivery method instead if you ask.

9. Research and De-Identified Data

De-identified and aggregated data. We create and use de-identified and aggregated data — information from which your name, contact details, and other identifiers have been removed so that it does not identify you and cannot reasonably be used to identify you — for quality assurance, benchmarking, service improvement, and statistical and scientific purposes. You acquire no ownership, royalty, or compensation rights in anything developed using de-identified or aggregated data.

Identifiable research requires your separate written authorization. We will not review, use, or disclose your identifiable records to assess your eligibility for a clinical study, contact you about a study, or provide your records to any researcher or third party for research purposes unless you sign a separate written research authorization. That authorization is entirely voluntary, is never a condition of receiving any Service, describes specifically what would be shared and with whom, and may be revoked in writing at any time. Accepting our Terms & Conditions or this Policy does not authorize research use of your identifiable information.

10. How Long We Keep Your Information

•       Client health and testing records, including intake forms, orders, scan data, imagery, and reports: seven years from the date of the most recent entry, consistent with N.J.A.C. 13:35-6.5(b). Records of a client who was a minor are retained at least until the client reaches age 25, to account for the tolling of a minor's claims under N.J.S.A. 2A:14-21.

•       Quality assurance and quality control records for our DXA equipment: at least one year, as required by N.J.A.C. 7:28-22.11(d), and radiation survey and personnel monitoring records for the longer periods required by N.J.A.C. 7:28-8.

•       Transaction and payment records: seven years, for tax and accounting purposes.

•       Marketing contact information: until you opt out, after which we retain only what is needed to honor your opt-out.

•       Website analytics data: retained by Google Analytics for the retention period we have configured, which does not exceed 14 months.

When a retention period ends, we securely delete or destroy the information, or de-identify it.

11. Your Choices and Rights

•       Access and copies. You may request a copy of your records. We will provide it within 30 days. Consistent with N.J.A.C. 13:35-6.5(c), we charge no more than $1.00 per page or $100 for the entire record, whichever is less (and no more than $10 for a record of 10 pages or fewer); for imaging and other material that cannot be photocopied, the actual cost of duplication plus an administrative fee of the lesser of $10 or 10% of the cost of reproduction. We will not withhold your records because you have an unpaid balance where another provider needs them for your care.

•       Correction. If you believe information we hold about you is inaccurate or incomplete, tell us and we will correct it or, where the entry is part of a clinical record that cannot simply be overwritten, add your statement to the record.

•       Deletion. You may ask us to delete your information. We will do so unless we are required to retain it under Section 10, in which case we will tell you what we must keep and why, and delete the rest.

•       Restrictions. You may ask us to restrict how we use or disclose your information. We are not required to agree, but if we do agree, we will be bound by that agreement except in an emergency.

•       Withdrawing consent. You may revoke any authorization you have given us — including the authorization to release information to a designated party, and any research authorization — in writing at any time, except to the extent we have already acted in reliance on it.

•       Marketing opt-out. As described in Section 7.

•       Paper copies. You may request a paper copy of this Policy at no charge.

To exercise any of these, contact us using the details in Section 16. We may need to verify your identity before acting on a request. We will not discriminate against you for exercising any of these rights.

12. New Jersey Residents

The New Jersey Data Privacy Act, N.J.S.A. 56:8-166.4 et seq., which took effect on January 15, 2025, applies to businesses that control or process the personal data of at least 100,000 New Jersey consumers in a year, or the personal data of at least 25,000 consumers where the business derives revenue from the sale of personal data. We are a single-location facility, we do not sell personal data, and we do not meet either threshold, so the Act does not currently apply to us.

We nonetheless extend the substantive rights the Act provides — access, correction, deletion, portability, and the right not to have sensitive data processed without consent — to all our clients, as set out in Section 11. Health information is "sensitive data" under the Act, and we process it only with your consent and only for the purposes described in Section 4. If our operations grow past the statutory thresholds, we will update this Policy and comply with the Act in full.

New Jersey residents may also contact the New Jersey Division of Consumer Affairs, Office of Consumer Protection, with a privacy concern.

13. Children and Minors

Our website is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from a child under 13 through our website. If you believe a child under 13 has provided information to us through the site, contact us and we will delete it.

We do provide Services to clients under 18, but only where a parent or legal guardian is present and has signed our Terms & Conditions, as described in Section 16 of those Terms. Where a client is a minor, we collect the minor's health and testing information from the parent or guardian, share results with the parent or guardian, and handle that information under this Policy. A parent or guardian may exercise the rights in Section 11 on the minor's behalf.

14. If There Is a Data Breach

If personal information about you is accessed by an unauthorized person, we will notify you in the most expedient time possible and without unreasonable delay, and in any event consistent with the New Jersey breach notification statute, N.J.S.A. 56:8-163. As that statute requires, we will report the breach to the Division of State Police in the New Jersey Department of Law and Public Safety before notifying you.

Separately, the Federal Trade Commission's Health Breach Notification Rule, 16 C.F.R. Part 318, applies to certain businesses that handle identifiable health information and are not covered by HIPAA. Where that Rule applies to a breach affecting your health information, we will notify you, the FTC, and where required the media, within the time the Rule allows.

15. Third-Party Websites and the DexaFit Platform

Our website may link to other websites, including the DexaFit platform where you access your reports. We are not responsible for the content or privacy practices of any site we do not operate. When you use the DexaFit platform, your information is handled under DexaFit Corporate's privacy policy at dexafit.com/privacy, and we encourage you to read it — particularly regarding how long your reports are retained and what account controls are available to you.

16. Contact Us, and How to Raise a Concern

Questions, requests, or complaints about this Policy or how we handle your information:

Spartan Kismet LLC d/b/a DexaFit Central Jersey · Attn: Privacy · 665 Martinsville Rd, Unit 22b, Basking Ridge, NJ 07920 · (908) 291-3533 · centraljersey@dexafit.com

We take privacy complaints seriously and will respond within 30 days. You will never be penalized, refused service, or treated differently for raising a concern or filing a complaint.

If you are not satisfied with our response, you may contact the New Jersey Division of Consumer Affairs. If your concern involves a provider who is a HIPAA covered entity, you may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights.

17. Changes to This Policy

We may update this Policy from time to time. When we do, we will change the effective date at the top and post the updated version on our website. If a change materially affects how we use or share information we already hold about you, we will notify you by email or at your next appointment before the change takes effect, and where the change requires your consent, we will ask for it.

Spartan Kismet LLC d/b/a DexaFit Central Jersey · 665 Martinsville Rd, Unit 22b, Basking Ridge, NJ 07920 · (908) 291-3533 · centraljersey@dexafit.com