PRIVACY POLICY

Last updated February 2, 2024

This privacy notice for Xaia, Inc. (“Xaia,” “we,” “us,” or “our”), describes how and why we might collect, store, use, and/or share (“process”) your information when you use our services (“Services”), such as when you:

IF YOU DO NOT WISH TO AGREE TO THESE TERMS THEN YOU MUST NOT USE XAIA, SYNERGI, AND/OR ANY OTHER XAIA SERVICES.

Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you still have any questions or concerns, please contact us at dpo@xaia.health.

Any capitalized term not defined in this Privacy Policy shall have the meaning ascribed to it in the User Agreement between you and us.

SUMMARY OF KEY POINTS

This summary provides key points from our privacy notice, but you can find out more details about any of these topics by reviewing our Privacy Policy in full.

What personal information do we process? When you visit, use, or navigate our Services (including but not limited to our website), we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more in Section 1.

Do we process any sensitive personal information? We may process sensitive personal information when necessary with your consent or as otherwise permitted by applicable law. Learn more in Section 1.

Do we receive any information from third parties? We do not receive any information from third parties.

How do we process your information? We process your information to provide, improve, and administer our Services; communicate with you; prevent fraud and secure data; and comply with law. We may also process your information for other purposes with your consent. Learn more in Section 2.

In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties. Learn more in Section 4.

How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no system is 100% secure. Learn more in Section 7.

What are your rights? Depending on where you are located, the applicable privacy law may give you certain rights regarding your personal information. Learn more in Section 8.

How do you exercise your rights? The easiest way is by submitting a data subject access request or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Personal Information Provided by You. The personal information we collect may include the following:

Sensitive Information. When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:

Payment Data. We may collect data necessary to process your payment if you make purchases, such as your payment instrument number and the security code. All payment data is stored by Apple. You may find their privacy notice here: https://www.apple.com/legal/privacy/en-ww/.

Social Media Login Data. We may provide you with the option to register with us using your existing social media account details. If you choose this option, we will collect the information described in Section 5.

All personal information that you provide must be true, complete, and accurate, and you must notify us of any changes.

Information automatically collected

In Short: Some information — such as your IP address and/or browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, and location. This information is primarily needed to maintain the security and operation of our Services, as well as for internal analytics and reporting.

The information we collect includes:

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services; communicate with you; prevent fraud; secure data; and comply with law.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law.

If you are located in the EU or UK, this section applies to you.

The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on. These may include: Consent, Performance of a Contract, Legitimate Interests, Legal Obligations, and Vital Interests.

If you are located in Canada, this section applies to you.

We may process your information with your consent (express or implied) or where otherwise permitted by law. You can withdraw your consent at any time by contacting us.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We may share information in specific situations described in this section and/or with the following third parties.

We may need to share your personal information in the following situations:

5. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.

Our Services offer you the ability to register and log in using third-party social media account details. We will use the information we receive only for the purposes described in this privacy notice. We do not control and are not responsible for other uses of your personal information by the social media provider.

6. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information unless you ask us to delete it.

We will keep your personal information unless you ask us to delete it. If you request deletion, we will do so unless a longer retention period is required or permitted by law.

7. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organizational and technical security measures.

We have implemented reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, no method of electronic transmission or storage is 100% secure.

8. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: In some regions, such as the EEA, UK, Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information.

Depending on your location, these rights may include the right to request access, rectify, erase, restrict, or object to processing, and data portability. You can make such a request by contacting us at the details below.

Withdrawing your consent: If we rely on your consent to process your personal information, you may withdraw it at any time by contacting us.

Opting out of marketing and promotional communications: You can unsubscribe from marketing emails at any time by clicking the unsubscribe link or contacting us.

Account Information: If you would like to review or change the information in your account or terminate your account, you can log into your account settings. Upon your request to terminate your account, we will deactivate or delete it from our active databases.

9. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems and applications include a Do-Not-Track (“DNT”) feature or setting. No uniform technology standard for recognizing and implementing DNT signals is finalized, so we do not currently respond to DNT browser signals.

10. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: If you are a resident of California, Colorado, Connecticut, Utah, or Virginia, you are granted specific rights regarding access to your personal information.

What categories of personal information do we collect?

We may collect your first name and email address and any other data you choose to provide in connection with your use of the Services.

How do we use and share your personal information?

See "HOW DO WE PROCESS YOUR INFORMATION?" above.

Will your information be shared with anyone else?

We may disclose your personal information with our service providers under contract. We have not disclosed, sold, or shared any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months.

California Residents

California Civil Code Section 1798.83 (the "Shine The Light" law) allows California residents to request information about categories of personal information we disclosed to third parties for direct marketing in the prior calendar year.

We do not permit individuals under 18 to use Xaia Services. Notwithstanding that restriction, if you are under 18, reside in California, and have a registered account with our Services, you can request removal of unwanted data you publicly post.

CCPA Privacy Notice

This section applies only to California residents under the California Consumer Privacy Act (CCPA). California residents have various rights including the right to request deletion, the right to know, and the right to non-discrimination.

Colorado Residents

Under the Colorado Privacy Act (CPA), you have certain rights including access, correction, and deletion of personal data. You may email dpo@xaia.health or submit a data subject access request.

Connecticut Residents

Under the Connecticut Data Privacy Act (CTDPA), you have certain rights including access, correction, and deletion. You may email dpo@xaia.health.

Utah Residents

Under the Utah Consumer Privacy Act (UCPA), you have rights including access and deletion. You may email dpo@xaia.health.

Virginia Residents

Under the Virginia Consumer Data Protection Act (VCDPA), you have various rights including access, correction, and deletion. You may email dpo@xaia.health.

11. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and will be effective as soon as it is accessible. If we make material changes, we may notify you by posting a notice or sending you a direct notification.

12. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments, you may contact our Data Protection Officer (DPO) at dpo@xaia.health, or by mail at:

Xaia, Inc.
16192 Coastal Highway
Lewes, DE 19958
United States

13. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the laws of your country, you may have the right to request access to the personal information we collect from you, change it, or delete it. To request review, update, or deletion, please email dpo@xaia.health.