Privacy Policy

Signos, Inc. ("Signos," "we," "us," or "our") respects the privacy of others. This PRIVACY POLICY (this "Privacy Policy") is intended to explain Signos's privacy practices with respect to the signos.com website (together with its pages, features, and functions, and any mobile versions of the foregoing, the "Site") and the Signos mobile application that links to this Privacy Policy (together with its sections, features, and functions, the "App"). This Privacy Policy also describes how Signos handles protected health information ("PHI") when it acts as a business associate to covered entities under the Health Insurance Portability and Accountability Act of 1996, as amended, and the applicable regulations ("HIPAA"). This Privacy Policy is also intended to provide you (together with any person helping you visit, access, register with or use the Site and/or the App, "you" or "your") with an overview of the following:

  • The type of information about you Signos collects through the Site and the App;
  • How Signos collects that information;
  • How Signos uses that information;
  • Who will have access to that information; and
  • Signos's security measures for protecting that information;
  • Your rights with respect to your personal information and protected health information; and
  • How Signos complies with applicable federal and state privacy laws, including HIPAA, when handling protected health information.

This Privacy Policy applies to information collected through the Site and/or the App. Please carefully read this Privacy Policy in its entirety.

By creating, registering with, or logging into an account on or through the Site and/or the App, you acknowledge that you have read and understand this Privacy Policy. Your continuing visit, access, registration with, or use of the Site, the App, or any products or services provided by Signos constitutes your acknowledgment of this Privacy Policy as updated from time to time. To the extent required by applicable law, Signos will obtain your affirmative consent before collecting, using, or disclosing your personal information or protected health information.

As used herein, the term "personal information" means information (including personally identifiable information) that would allow someone to specifically identify, contact, or locate you, directly or indirectly, including any information that constitutes "personal information," "personal data," or "personally identifiable information" as defined under applicable state or federal privacy laws; the term "protected health information" or "PHI" means individually identifiable health information, as defined under HIPAA, that Signos creates, receives, maintains, or transmits on behalf of a covered entity. The term "sensitive personal information" means personal information that reveals racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data processed for identification purposes, precise geolocation data, or a person's Social Security number, driver's license number, state identification card number, passport number, financial account information, or credentials allowing access to a financial account. The term "non-personal information" means any information other than personal information that Signos may collect from you, such as anonymized or de-identified data that cannot reasonably be used to identify any individual.

Categories of Information Collected.

Signos may collect personal and non-personal information about you through the Site, the App, and/or any electronic medical record platforms lawfully accessed and used by Signos. The categories of such information might include, for example:

  • Your name (first, last and/or middle);
  • Your unique identifiers (e.g., username, pseudonym);
  • Your login information for the Site and/or the App (e.g., username, password, security questions and answers);
  • Your company name and/or title;
  • Your home and/or business contact information (e.g., mailing address, email address, telephone number, facsimile number);
  • Your profession;
  • Your gender;
  • Your electronic signature;
  • Photographic or video image to the extent provided by you to Signos;
  • Medical history and personal health information, including protected health information (PHI) as defined under HIPAA, the results of any questionnaires, surveys, information requests, interviews, or other documentary, text, video, or audio interactions related to the provision of services by Signos or any other devices tracking health or diagnostic data that is linked to any software, devices, or other services provided and accessed by Signos;
  • Billing, payment or shipping information (e.g., payor or payee name, checking account number, credit card number, expiration date, verification code, accountholder name, cardholder name, billing address, mailing address, tax ID number, billing history);
  • Your transactional information (e.g., offers, orders, pricing, payments, purchases, purchaser, seller, item information, shipping terms, comments, ratings, feedback, and communications made on, through, or with respect to the Site or the App);
  • Your business contact information (e.g., company, title, mailing address, email address, telephone number, facsimile number, tax identification number);
  • Your computer, mobile device and/or browser information (e.g., IP address, mobile device ID information, operating system, connection speed, bandwidth, browser type, referring/exit web pages, web page requests, cookie information, hardware attributes, software attributes);
  • Information about, and/or information found on, your pages and accounts with third-party websites, networks, platforms, servers and applications (e.g., Instagram, Facebook, Tik Tok, YouTube, Pinterest, , LinkedIn, X, etc.);
  • Usage activity concerning your interactions with the Site, the App, and/or third-party websites, networks, platforms, servers or applications accessed on or through the Site and/or the App (e.g., how you accessed the Site or the App, where you go when you leave the Site or the App, number of clicks on a page or feature, amount of time spent on the Site or the App or a page or feature, and identity of third-party websites, networks, platforms, servers and applications accessed through the Site or the App);
  • Usage activity concerning videos, articles, and other content provided to or accessed by you on or through the Site or the App (e.g., viewing habits, viewing preferences, viewing history, title selections, favorites, streams, downloads, demographics and closed captioning selections);
  • Information concerning the type of content that you access or might prefer to access on the Site and/or the App;
  • Usage activity concerning communications with other users (including, without limitation, sharing information regarding weight loss with other users);
  • Information about third parties that you refer to Signos (e.g., name, contact information, relationship);
  • Information set forth in the Site's and/or the App's online account registration, subscriber profile, and/or subscriber directory forms completed by you;
  • Information set forth in your user account and profile with the Site and/or the App;
  • Statements or content (e.g., comments, videos, photographs, images), and information about such statements or content, which you submit or publish on or through the Site and/or the App, or which are accessed via your public or linked social media pages (e.g., Facebook, Google Plus, LinkedIn);
  • Your answers to questionnaires submitted on, through, or in relation to the Site and/or the App;
  • Information concerning your medical or other health information, including in connection with clinical research or clinical research trials;
  • Information relating to your medical prescription medication history;
  • Your geolocation;
  • The name associated with your mobile device;
  • The telephone number associated with your mobile device;
  • Your mobile device ID information;
  • With your express consent, your contacts and/or contact information (e.g., names, telephone numbers, physical addresses, email addresses, photos) stored on your mobile devices; and
  • With your express consent, information about third-party software applications on your mobile device (including, without limitation, general software apps, downloadable software apps, and social media apps)

How Information Is Collected.

Signos might collect personal and non-personal information from you when you visit, access, register with, or use the Site and/or the App or any of its products or services; when you request, register for, order or purchase any products or services on, through or in relation to the Site; when you "sign in," "log in" or the like to the Site and/or the App, even if through third-party online social media sites or accounts (e.g., Instagram, Facebook, Tik Tok, YouTube, Pinterest, LinkedIn, X, etc.); when you allow the Site or the App to access, upload, download, import or export content found on or through, or to otherwise interact with, your computer or mobile device (or any other device you may use to visit, access, register with or use the Site or the App) or online accounts with third-party websites, networks, platforms, servers or applications (e.g., your online social media accounts, your cloud drives and servers, your mobile device service provider); or whenever Signos asks you for such information, such as, for example, when you process a payment through the Site and/or the App, or when you answer an online survey or questionnaire.

In addition, if you or a third party sends Signos a comment, message or other communication (such as, by way of example only, email, instant message, letter, fax, phone call, or voice message) about or referencing you or your activities in relation to the Site or the App, then Signos may collect any personal or non-personal information provided therein or therewith.

Signos might also use various tracking, data aggregation and/or data analysis technologies, including, for example, the following:

  • Cookies, which are small data files (e.g., text files) stored on the browser or device you use to view a website or message. They may help store user preferences and activity, and may allow a website to recognize a particular browser or device. There are several types of cookies, including, for example, browser cookies, session cookies, and persistent cookies. Cookies may record information you access on one page of a website to simplify subsequent interaction with that website, or to help streamline your transactions on related pages of that website. Most major browsers are set up so that they will initially accept cookies, but you might be able to adjust your browser's or device's preferences to issue you an alert when a cookie is downloaded, or to block, reject, disable, delete or manage the use of some or all cookies on your browser or device.
  • Flash cookies, which are cookies written using Adobe Flash, and which may be permanently stored on your device. Like regular cookies, Flash cookies may help store user preferences and activity, and may allow a website to recognize a particular browser or device. Flash cookies are not managed by the same browser settings that are used for regular cookies.
  • Web beacons, which are pieces of code embedded in a website or email to monitor your activity on the website or your opening of the email, and which can pass along information such as the IP address of the computer or device you use to view the website or open the email, the URL page on which the web beacon is located, the type of browser that was used to access the website, and previously set cookie values. Web beacons are sometimes used to collect advertising data, such as counting page views, promotion views or advertising responses. Disabling your computer's, device's or browser's cookies may prevent some web beacons from tracking or recording certain information about your activities.
  • Scripts, which are pieces of code embedded in a website to define how the website behaves in response to certain key or click requests sent by the user. Scripts are sometimes used to collect information about the user's interactions with the website, such as the links the user clicks on. Scripts are often times temporarily downloaded to the user's computer or device from the website server, active only while the user is connected to the Site and/or the App, and deactivated or deleted when the user disconnects from the Site and/or the App.
  • Analytic tools and services, which are sometimes offered by third parties, and which track, measure and/or generate information about a website's or program's traffic, sales, audience and similar information, and which may be used for various reasons, such as, for example, statistical research, marketing research, and content ratings research, and conversion tracking. Google Analytics and Alexa are common examples of these types of technologies. Signos may also use other third-party analytic tools and services.
  • Other third-party data tracking or analytic technologies (e.g., deep linking, eTags, device fingerprinting or cross-device tracking).

Please be advised that if you choose to block, reject, disable, delete or change the management settings for any or all of the aforementioned technologies and/or other tracking, data aggregation and data analysis technologies, then certain areas of the Site and/or the App might not function properly.

By visiting, accessing, registering with or using the Site and/or the App, you acknowledge and agree in each instance that you are giving Signos permission to monitor or otherwise track your activities on the Site and/or the App, and that Signos may use the aforementioned technologies and/or other tracking, data aggregation and data analysis technologies, including for targeted ads and other personalized content. If you would like to opt out of this use of your personal information, please see the section entitled "Privacy Requests" below.

Sensitive Personal Information and Protected Health Information.

Signos collects and processes sensitive personal information and protected health information as necessary to provide its products and services, including health and wellness monitoring, clinical research support, and related services. Signos collects sensitive personal information, including health and biometric data, only with your consent or as otherwise permitted by applicable law. When Signos acts as a business associate to a covered entity under HIPAA, Signos will use and disclose PHI only as permitted by its business associate agreement with the applicable covered entity and in compliance with HIPAA. To the extent not addressed above, we ask that you not send us, and you not disclose, any sensitive personal information (e.g., information related to race or ethnic origin, political opinions, religion or other beliefs, criminal background, or union affiliation) on or through the Site or otherwise to us, unless such information is specifically requested by Signos in connection with the provision of services.

Use of Information Collected.

Signos may use the personal and/or non-personal information it collects from you through the Site or the App in a variety of ways. Examples of those uses might include, for example, to:

  • Place, fulfill, process and/or track your requests;
  • Facilitate and maintain your access of, registration with and use of the Site, the App and/or their products and services;
  • Facilitate and maintain your movement throughout the Site and/or the App;
  • Facilitate and maintain your accounts and profiles with the Site and/or the App;
  • Provide customer service;
  • Operate the Site, the App, and their products and services;
  • Provide administrative services relating to the Site and the App;
  • Send you communications like, for example, administrative emails, answers to your questions and updates about the Site and/or the App;
  • Sending you "push notifications" via the App to your mobile device;
  • Allow you to communicate with others through the Site or the App like, for example, through online messages, online forums, chat rooms, and bulletin boards;
  • Provide you with information about Signos, its parents, its subsidiaries, its affiliates and/or their respective businesses, products and services by letter, email, text message, telephone, or other forms of communications;
  • Provide you with information about third-party businesses, products and/or services by letter, email, text message, telephone, or other forms of communication;
  • Provide you with customized content, services, and user experiences, including advertising and promotional information (e.g., targeted ads, retargeted ads), recommendations for content you might like, and cross-app or cross-site functionality across multiple third-party websites and mobile apps;
  • Improve the Site, the App and/or their content, products, and services;
  • Improve the products, services, marketing and/or promotional efforts of Signos, its parents, its subsidiaries and/or its affiliates;
  • Create new products, services, marketing and/or promotions for Signos, its parents, its subsidiaries and/or its affiliates;
  • Market the businesses, products and/or services of Signos, its parents, its subsidiaries and/or its affiliates;
  • Help personalize user experiences with the Site and/or its products and services;
  • Analyze traffic to and through the Site and/or the App;
  • Analyze user behavior and activity on or through the Site and/or the App;
  • Conduct research and measurement activities for purposes of product and service research and development, publications, advertising claim substantiation, market research and other activities related to Signos, its parents, its subsidiaries, its affiliates, the Site, the App and/or their features, products and services;
  • Monitor the activities of you and others on or through the Site and/or the App;
  • Create device fingerprints and profiles about the possible relationships among different browsers and devices;
  • Create consumer profiles, which may combine your personal or non-personal information from the Site and/or the App with your personal or non-personal information from another source or service;
  • Protect or enforce Signos's rights and properties;
  • Protect or enforce the rights and properties of others (which may include you), assuming that Signos believes it has an obligation to do so; and/or
  • For various other purposes with your consent.

Signos will not use or disclose PHI received in its capacity as a business associate for any purpose other than as permitted or required by its business associate agreement with the applicable covered entity, as required by law, or as otherwise permitted by HIPAA. With respect to other personal information, Signos reserves the right to use your personal and non-personal information when:

  • Required or permitted by applicable law, court order or other governmental authority (including, without limitation and by way of example only, in response to a subpoena or other legal process); and/or
  • Signos believes in good faith that such use is otherwise necessary or advisable (including, without limitation and by way of example only, to investigate, prevent, or take legal action against someone who may be causing injury to, interfering with, or threatening the rights, obligations or properties of Signos, a user of the Site and/or the App (which may include you) or anyone else who may be harmed by such activities or to further Signos's legitimate business interests).

Signos reserves the right to share your personal and/or non-personal information (excluding PHI, which is subject to the HIPAA restrictions described herein), including your SMS opt-in or consent status, with third parties that help Signos provide its messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist Signos in the delivery of text messages. We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. Your mobile information will not be sold or shared with third parties for promotional or marketing purposes.

Use of Artificial Intelligence Technologies.

Signos, and it vendors, may use artificial intelligence ("AI"), machine learning, automated decisioning, large language models, and similar AI-enabled technologies in connection with the Site, the App, and its products and services. This section describes how Signos collects, uses, and processes personal information in connection with its AI-powered features. This section supplements the other provisions of this Privacy Policy and should be read together with them. To the extent personal information constitutes PHI governed by HIPAA, the BAA and HIPAA regulations control.

Signos may use these technologies to support, operate, personalize, secure, improve, and administer the App, including to assist with customer support, respond to or route user inquiries, summarize or format information, personalize content or recommendations, improve the efficiency and accuracy of our services, analyze patterns and trends, detect fraud or security risks, and facilitate communications or information sharing with third-party companies whose services you request or authorize. While AI assists in many processes, critical decisions regarding your health care always involve human oversight from qualified healthcare professionals.

Unless we tell you otherwise in a separate notice or obtain any consent required by applicable law, we do not use AI to provide medical advice, diagnose conditions, prescribe medications, determine treatment, or replace the judgment of a licensed healthcare professional.

Information processed through AI-enabled or automated systems remains subject to this Privacy Policy and our applicable privacy and security safeguards. Signos may use information to develop, test, improve, support, or evaluate AI-enabled features or automated tools, subject to applicable law and the choices, consents, and limitations described in this Privacy Policy. We may use third-party technology providers, including third-party AI service providers, to support some AI-enabled or automated features.

HIPAA Compliance and Protected Health Information.

Signos is not a "covered entity" as defined under HIPAA. However, Signos may act as a "business associate" (as defined under HIPAA) when it provides services to or on behalf of covered entities that involve the creation, receipt, maintenance, or transmission of protected health information. When Signos acts as a business associate, it is contractually and legally obligated to comply with the applicable requirements of HIPAA, including the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. In such circumstances, Signos will:

  • Use and disclose PHI only as permitted or required by its business associate agreement with the applicable covered entity and as permitted by HIPAA;
  • Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, as required by the HIPAA Security Rule (as further explained below);
  • Report to the applicable covered entity any use or disclosure of PHI not provided for by its business associate agreement, including any breach of unsecured PHI;
  • Ensure that any subcontractors or agents to whom Signos provides PHI agree to the same restrictions and conditions that apply to Signos under its business associate agreements;
  • Make PHI available to individuals as required to satisfy a covered entity's obligations to provide access to, or amend, records containing PHI;
  • When sharing personal information or PHI, apply the minimum necessary standard, limiting disclosures to the minimum amount of information reasonably necessary to accomplish the intended purpose of the use, disclosure, or request; and
  • Make its internal practices, books, and records relating to the use and disclosure of PHI available to the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.

With respect to personal information collected directly from you through the Site or the App (as opposed to information received from a covered entity), such information may not be subject to HIPAA protections unless it constitutes PHI received or maintained by Signos on behalf of a covered entity. However, Signos applies appropriate privacy and security protections to personal information and health-related information it collects, regardless of whether HIPAA applies, consistent with applicable state and federal law.

Third Party Providers.

Signos partners with third parties that may provide care, healthcare-related, medication, pharmacy, laboratory, care-support, or other patient-facing services through or in connection with the App, the Site, and the Services. Those third-party services are provided by the applicable third parties, and not by Signos. Signos provides access to the App and may facilitate access to those third-party services, but Signos does not provide medical services, medical advice, diagnosis, treatment, prescriptions, pharmacy services, or other professional healthcare services.

When you use the application in connection with a third party company's services, we may collect, use, disclose, transmit, or otherwise make available your personal information, health related information, account information, scan information, communications, and other information you provide through the application to that third party company and its personnel, providers, vendors, contractors, or service partners so that they can provide, administer, support, or improve the services you request or authorize. Those third party companies and service providers are responsible for the healthcare, wellness, prescribing, body scanning, laboratory, pharmacy, coaching, counseling, consultation, treatment, or other services that they provide to you. If you chose to receive services from or authorize information sharing with a third party company, that third party's own privacy policy, notice of privacy practices, terms, or other legal terms may apply to its collection, use, disclosure, and retention of your information.

Signos independently contracts with OpenLoop Health, Inc. to provide GLP‑1 and other medications or pharmaceuticals through OpenLoop's Pharmaceutical Subscription Services. OpenLoop, and not Signos, is responsible for the medication, pharmacy, and related clinical services it provides to you. When Signos facilitates these services, PHI may be shared with OpenLoop as a covered entity. For information regarding how Protected Health Information about you may be used and disclosed by OpenLoop, and how you can access this information, please see OpenLoop's Notice of Privacy Practices: https://openloophealth.com/notice-of-privacy-practices.

Signos also independently contracts with Prism Labs Inc. to provide 3D body scan and body composition services. When you do a body scan through the App or the Site, Signos send images of you and other data about you (including height and weight, but not name or contact info) to Prism to make 3D scans of you from head to toe and calculate insights like body composition. Prism creates a 3D scan and body insights, which may be used to display body metrics. Prism's collection, use, disclosure, and storage of the 3D scans and other data is subject to Prism's Privacy Policies, not this Privacy Policy, including Prisms Data Protection & Privacy Policy: https://www.prismlabs.tech/privacy-policy and Prisms Consumer Health Data Privacy Policy: https://www.prismlabs.tech/consumer-health-data-privacy-policy.

Sharing of Information Collected.

Signos reserves the right, but not the obligation, to share your personal information with the following:

  • Signos's employees, agents, and administrators;
  • Signos's accountants, financial advisors, and legal advisors;
  • Signos's parents, subsidiaries, and affiliates;
  • In connection with any clinical research or clinical research trial in which Signos is participating or otherwise facilitating, any sponsor or principal investigator of such clinical research or clinical research trial;
  • Service providers and other third parties who help Signos provide, manage, administer, maintain, monitor, distribute, operate, or facilitate the Site and/or the App, who help Signos develop, market or provide its products and services, or who help further Signos's business efforts, e.g., web hosting companies, website administrators, mobile app distribution platforms, support services companies, data analytics and analysis companies, advertising partners, and payment processing vendors (including, for example, through the Apple App Store), as needed in order for them to perform such services. To the extent any such service provider accesses PHI on Signos's behalf, Signos will enter into a business associate agreement or subcontractor agreement with such service provider as required by HIPAA;
  • Law enforcement or other governmental entities in response to what Signos believes to be an allegation or suspicion of illegal activity, a request relating to a civil or criminal investigation, an allegation or suspicion of illegal activity, a subpoena, a court order, or any other activity that may expose Signos to liability if it does not act or comply;
  • Any third parties who Signos believes are necessary to help or allow Signos to protect and enforce its rights and properties, including, without limitation, to enforce its rights under Signos's Terms and Conditions or any other agreements it has with you, and to protect and enforce its intellectual property rights; and/or
  • Any third parties who Signos believes are necessary to help or allow Signos to protect the rights and properties of others (which may include you), assuming that Signos believes it has an obligation to do so.

Signos also reserves the right to share your personal information (excluding PHI received in its capacity as a business associate, except as permitted by applicable law and the relevant business associate agreement) with third parties in connection with or as a result of any potential or actual merger, acquisition, or other event involving a change in ownership or control of Signos or Signos's business (whether by sale of assets, merger, stock purchase, or otherwise). In such transactions, Signos will require the receiving party to protect personal information consistent with this Privacy Policy and applicable law.

Signos also reserves the right to use data collected on, through, or in relation to the Site and/or the App (including your personal information or non-personal information) for use in conducting medical research, studies, and publications (and any other research, studies, and publications) and to share the same with third parties; provided, however, that any such use will be on a de-identified or aggregated basis in compliance with applicable law (including HIPAA de-identification requirements, where applicable), or will be conducted pursuant to an appropriate authorization or institutional review board approval as required by law.

De-identified information is not subject to HIPAA or this Privacy Policy. Signos reserves the right to use or share such de-identified information with its parent, subsidiary, and affiliated companies, its vendors, its suppliers, its representatives, and its customers, as well as with other individuals, businesses, and government entities, for any lawful purpose.

You may choose to share certain information and/or follow other users on the Site and/or the App. You may choose to share your contact information with other users or provide it publicly.

Data Processing and Legal Basis.

Signos processes personal information and PHI on the following legal bases, as applicable: (a) your consent; (b) performance of a contract between you and Signos (including the Terms and Conditions); (c) compliance with a legal obligation to which Signos is subject (including HIPAA requirements when acting as a business associate); (d) to protect the vital interests of you or another person; and (e) for Signos's legitimate interests, provided that such interests are not overridden by your rights and interests. Where Signos processes sensitive personal information or PHI, it does so only with your explicit consent or as otherwise specifically permitted by applicable law.

Data Retention.

Signos retains personal information and non-personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, including to provide you with products and services, comply with legal obligations, resolve disputes, enforce agreements, and as required by applicable law. With respect to protected health information received in Signos's capacity as a business associate, Signos will retain such information for the period required by its business associate agreement and applicable law, including but not limited to the six (6) year retention period for HIPAA-required documentation. Signos may dispose of or delete personal information or non-personal information when retention is no longer required, except as set forth in any other agreement or document executed by Signos or as required by law. Signos will not retain personal information for any period longer than is permitted by applicable law, including any applicable state data retention limitations (such as those under the New York SHIELD Act or other applicable federal or state law).

Transactions.

In connection with any transaction that you conduct through the Site and/or the App (e.g., the payment of any subscription fees, the purchase or sale of any products on or through the Site and/or the App), you may be asked to supply certain information relevant to the transaction, including, without limitation, your credit card number and expiration date, your billing address, your shipping address, your phone number and/or your email address. By submitting such information, you grant Signos the right to provide such information to third parties (e.g., payment processing companies) solely for the purpose of facilitating the transaction. Such information will be handled in accordance with applicable data security standards, including the Payment Card Industry Data Security Standard (PCI DSS) where applicable.

All credit card, debit card and other monetary transactions conducted on or through the Site and/or the App, if any and as applicable, shall occur through an online payment processing application accessible through the Site and/or the App. This online payment processing application is provided by Signos's third-party online payment processing vendor, Stripe ("Stripe"). Additional information about Stripe, its privacy policy, and its information security measures (collectively, the "Stripe Policies") should be available on the Stripe website located at https://stripe.com/privacyor by contacting Stripe directly. Reference is made to the Stripe Policies for informational purposes only and they are in no way incorporated into or made a part of this Privacy Policy. Signos's relationship with Stripe is merely contractual in nature, and Stripe is in no way subject to Signos's direction or control; thus, their relationship is not, and should not be construed as, one of fiduciaries, franchisors-franchisees, agents-principals, employers-employees, partners, joint venturers or the like.

Third Party Applications and Networks.

The Site, the App and/or any communications sent through or as a function of the Site and/or the App might contain links to third-party websites, networks, platforms, servers and/or applications, including, without limitation, DexCom, Inc. ("DexCom"). Third-party websites, networks, platforms, servers and/or applications (including any of the foregoing in relation to DexCom) might also contain links to the Site and/or the App.

In addition, you might have the opportunity to access the Site and/or the App using your online user accounts with certain third-party websites, networks, platforms, servers or applications, which might be subject to separate privacy policies pertaining to those third-party websites, networks, platforms, servers or applications (including, without limitation, any of the foregoing in relation to DexCom). Signos might also collect information from those third-party websites, networks, platforms, servers or applications (such as, for example, your name, gender, date of birth and personal interests, when you "like" or click links provided by or through those third-party websites, networks, platforms, servers, or applications and other information available through your online account or page with those third-party websites, networks, platforms, servers or applications).

Moreover, Signos might permit third parties to use their own tracking, data aggregation and/or data analysis technologies like the ones described above (e.g., third-party cookies). The use of information received from Health Connect will adhere to the Health Connect Permissions Policy, including the Limited Use requirements. To the fullest extent permitted by law, Signos is not responsible for, and you hereby release Signos from any and all liability which may arise from, such third-party websites, networks, platforms, servers and applications (including, without limitation, the privacy policies and practices of such third-party websites, networks, platforms, servers and applications, including any of the foregoing in relation to DexCom). It is your responsibility, and your responsibility alone, to carefully read, accept and comply with any and all relevant terms of use, waivers, and privacy policies associated with those third-party websites, networks, platforms, servers and applications (including, without limitation, any of the foregoing in relation to DexCom).

Security.

Signos implements administrative, physical, and technical safeguards designed to protect personal information and protected health information from unauthorized access, use, disclosure, alteration, or destruction. These safeguards are designed to comply with HIPAA Security Rule requirements (when applicable) and applicable state data security laws, including but not limited to the following:

  • Administrative safeguards, including workforce training on privacy and security policies, designation of a privacy and security officer, access controls and authorization procedures, and regular risk assessments;
  • Physical safeguards, including facility access controls, workstation security, and device and media controls;
  • Technical safeguards, including encryption of PHI and personal information in transit and at rest, unique user identification, automatic logoff, audit controls, and integrity controls;
  • Regular testing and monitoring of the effectiveness of security controls and procedures; and
  • Incident response and contingency planning, including data backup and disaster recovery procedures.

While Signos strives to protect your personal information and PHI, no method of transmission over the Internet or method of electronic storage is completely secure. Signos cannot guarantee absolute security but is committed to implementing and maintaining reasonable safeguards appropriate to the nature and sensitivity of the information it processes.

To help maintain the security of your personal information, Signos asks that you please notify it immediately of any unauthorized visit, access or use of the Site and/or the App, or the loss or unauthorized use of your user access information for the Site and/or the App (e.g., username or password).

Breach Notification.

In the event of a breach of unsecured protected health information (as defined under HIPAA), Signos will notify the applicable covered entity without unreasonable delay and in no case later than sixty (60) calendar days after discovery of the breach. In the event of a breach of personal information (including but not limited to unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information), Signos will notify, or cooperate with the appropriate party to notify, affected individuals and applicable regulatory authorities as required by state breach notification laws. Signos will comply with the notification timing and content requirements of each applicable jurisdiction.

Breach notifications may include, to the extent known and as required by applicable law, a description of the breach, the types of information involved, steps individuals can take to protect themselves, what Signos is doing to investigate and mitigate the breach, and contact information for further inquiries.

Privacy Requests.

You can exercise your privacy rights in accordance with applicable law through our webform and/or through Global Privacy Control, which we have enabled (see the "Do Not Track Signals" section below for more information about Global Privacy Control and Do Not Track signals). You may also contact us at legal@signos.comor by writing to Signos, Inc., Attn: Privacy Officer, at the address set forth in the "Contact Us" section below. You may have multiple privacy rights, subject to applicable law, with respect to the personal information and protected health information we process about you, including:

  • Confirm whether we are processing your personal information.
  • Opt-out of our use or sharing of your personal information and sensitive personal information. You may withdraw permission for us to process personal information about you for certain purposes, including for targeted ads, sale of personal information and email marketing.
  • Delete personal information. You can ask us to erase or delete all or some of the information about you.
  • Change or correct personal information. You can edit some of the information about you. You can also ask us to change, update or fix information about you in certain cases, particularly if it is inaccurate.
  • Object to, limit or restrict use of personal information. You can ask us to stop using all or some of the information about you (for example, if we have no legal right to keep using it) or to limit our use of it (for example, if the information about you is inaccurate).
  • Right to access and/or have your information provided to you. You can also ask us for a copy of information about you and can ask for a copy of information about you provided in machine readable form if you reside in California or another jurisdiction that provides you with this right as a matter of law.
  • Right to an accounting of disclosures. To the extent Signos maintains PHI on behalf of a covered entity, you may have the right under HIPAA to receive an accounting of certain disclosures of your PHI made by Signos during the six (6) years prior to your request. Such requests may be directed to the applicable covered entity, which will coordinate with Signos as necessary.
  • Right to request restrictions. You may have the right to request restrictions on certain uses and disclosures of your PHI, though Signos (or the applicable covered entity) is not required to agree to all such requests except as required by HIPAA.
  • Right to receive confidential communications. You may request that communications regarding your PHI be made by alternative means or sent to an alternative location.

Notwithstanding the above, please note that we may still need to retain personal information necessary to provide you with products or services you have purchased, comply with our legal obligations (including HIPAA retention requirements), or as otherwise permitted by applicable law.

If we decline to act on your request to exercise your privacy rights, you may appeal that decision by sending an email explaining the basis for your disagreement with that decision to legal@signos.com. We will respond to your appeal within the timeframe required by applicable law.

Your State Privacy Rights.

If you are a California resident, California law (including the California Consumer Privacy Act, as amended by the California Privacy Rights Act) may provide you with additional rights regarding our use of your personal information, including the right to know, delete, correct, opt-out of sale/sharing, and limit use of sensitive personal information. To learn more about your California privacy rights, visit the California Supplemental Privacy Policy.

If you are a resident of Arkansas, California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, or another state with a comprehensive consumer privacy law, you may have similar rights under your state's applicable law, including the right to access, delete, correct, and opt-out of the processing of your personal information for targeted advertising, sale, or profiling. To exercise these rights, please contact us as set forth in the "Privacy Requests" section above.

Signos will not discriminate against you for exercising any of your privacy rights under applicable state law. We will not deny you goods or services, charge you different prices, or provide a different level or quality of service because you exercised your privacy rights, unless permitted by applicable law.

Signos does not sell personal information (as "sale" is defined under applicable state privacy laws, including the CCPA) or share personal information for cross-context behavioral advertising, except as disclosed in this Privacy Policy and as permitted by applicable law. Signos does not authorize third parties to collect your personal information when you use the Site and/or the App, except as expressly stated in this Privacy Policy. To the fullest extent permitted by law, Signos is not responsible for, and you hereby release Signos from any and all liability which may arise from, such third parties' unauthorized collection of your personal information.

Important Notice to Non-US Residents.

Signos, the Site, and the App are operated in the United States. Please be aware that your personal information may be transferred to, processed, maintained, and used on computers, services, and systems located outside of your state, province, country, or other governmental jurisdiction where the privacy laws may not be as protective as those in your country of origin. If you are located outside of the United States and choose to use the Site and/or the App, then you do so at your own risk.

A Special Note About Minors.

The Site and the App are intended for use by adults. Neither the Site nor the App are designed or intended to attract, and are not directed to, children under eighteen (18) years of age, let alone children under thirteen (13) years of age. Signos does not knowingly collect personal information through the Site or the App from any person under thirteen (13) years of age and intends to comply with the Children's Online Privacy Protection Act (COPPA), as applicable. If Signos obtains actual knowledge that it has collected personal information through the Site or the App from a person under thirteen (13) years of age without verifiable parental consent, then it will delete such personal information as soon as reasonably practicable. If you believe that a child under 13 has provided personal information to Signos, please contact us at legal@signos.com.

Furthermore, if you are under eighteen (18) years of age, then you (or your parent or legal guardian) may at any time request that Signos remove content or information about you that is posted on the Site and/or the App. Please submit any such request ("Request for Removal of Minor Information") to legal@signos.com, with a subject line of "Removal of Minor Information."

Modifications of this Privacy Policy.

Signos may supplement, amend, or otherwise modify this Privacy Policy from time to time. If Signos makes material changes to this Privacy Policy, it will notify you by posting the updated Privacy Policy on the Site and/or the App with a revised effective date, and where required by applicable law, by providing you with direct notice (such as via email or in-app notification) prior to the changes taking effect. Such supplements, amendments, and other modifications shall be deemed effective as of their stated effective or modification date. It is your responsibility to carefully review this Privacy Policy each time you visit, access, register with or use the Site and/or the App.

By continuing to visit, access, register with, or use the Site or the App after changes to this Privacy Policy become effective, you acknowledge and accept the most-recent version of this Privacy Policy. If you do not agree with any changes, you should discontinue use of the Site and the App.

Mergers, Acquisitions, and Other Business Transactions.

Signos may decide to sell, buy, merge, or otherwise reorganize its business. If that occurs, you will be notified via email or a prominent notice on our website of any ownership change and any changes in the use of your personal information. These types of transactions may involve the disclosure of personal information to prospective or actual purchasers, or receiving it from sellers. Signos will seek appropriate protection for personal information in these types of transactions. See also the "Sharing of Information Collected" section above for additional information about how personal information may be shared in connection with such transactions.

Severability.

If any term or condition of this Privacy Policy is deemed invalid or unenforceable by a court of law with binding authority, then the remaining terms and conditions shall not be affected, and the court shall reform the invalidated or unenforceable term or condition to the maximum extent permitted under the law and consistent with the intent of this Privacy Policy.

Do Not Track Signals.

Signos honors Global Privacy Control (GPC) signals as a valid opt-out of the sale or sharing of personal information, as required by applicable state law, including the California Consumer Privacy Act and the Texas Data Privacy and Security Act. Some browsers may also transmit "Do Not Track" (DNT) signals. Signos will honor DNT signals as an opt-out of targeted advertising to the extent required by applicable law.

Contact Us.

Please direct any questions you may have about this Privacy Policy to legal@signos.com, with a subject line of "Privacy Policy." The foregoing contact information may change from time-to-time by supplementation, amendment, or modification of this Privacy Policy.

Modification Date.

This Privacy Policy was last modified on, and is dated effective as of, August 4, 2026.

MKT-0002_0