RESSA HEALTH
Privacy Policy
Website, Marketing, and Platform Privacy Practices - GLOBAL
Effective Date: September 1, 2026 Version 1.3
PLEASE READ THIS POLICY TOGETHER WITH THE RESSA HEALTH TERMS OF SERVICE. THIS POLICY DESCRIBES HOW RESSA HANDLES PERSONAL INFORMATION ACROSS OUR WEBSITE, OUR MARKETING, AND THE SERVICE. SECTION 6 EXPLAINS HOW WE HANDLE HEALTH INFORMATION. IF YOU LIVE IN WASHINGTON, NEVADA, ILLINOIS OR ANOTHER U.S. STATE WITH A CONSUMER HEALTH DATA STATUTE, OUR SEPARATE CONSUMER HEALTH DATA PRIVACY POLICY ALSO APPLIES TO YOU. ANNEX A CONTAINS U.S. STATE-SPECIFIC DISCLOSURES, ANNEX C CONTAINS ADDITIONAL DISCLOSURES FOR CANADIAN RESIDENTS, INCLUDING A SEPARATE QUEBEC SECTION, AND ANNEX D CONTAINS ADDITIONAL DISCLOSURES FOR INDIVIDUALS IN THE EUROPEAN ECONOMIC AREA AND UNITED KINGDOM. SECTION 15 EXPLAINS YOUR RIGHTS AND HOW TO EXERCISE THEM.
1. About This Policy
1.1 Who We Are. This Privacy Policy (“Policy”) describes how Metabolic Terrain Omics, Inc., a Delaware corporation doing business as Ressa Health (“Ressa,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information. Our address is 2 East Congress Street, Suite 900, Tucson, AZ 85701. You can reach us at privacy@ressahealth.com.
1.2 What This Policy Covers. This Policy applies to the Ressa Health public website and any subdomain or marketing page we operate; our email, text message, and other marketing and communications activity; our applications and the Ressa Health platform (together with the website, the “Service”); and information we collect from prospective users, website visitors, practitioners, and business contacts. Capitalized terms not defined here have the meanings given to them in the agreement under which you use the Service: for individuals, the Ressa Health Terms of Service (the “Terms of Service”); for practitioners, the Ressa Health Provider Master Services Agreement (the “Provider MSA”). The Terms of Service and the Provider MSA are together the “User Agreements.” Except where this Policy names a specific section of the Terms of Service, references to the User Agreements mean whichever of them applies to you.
1.3 What This Policy Does Not Cover. This Policy does not cover: (a) information a practitioner, laboratory, health plan, or other third party holds in its own records, including information you shared with them through the Service, which is governed by that party’s own policies and by the law that applies to it; (b) information we handle as a “business associate” under the federal Health Insurance Portability and Accountability Act and its implementing regulations (“HIPAA”) on behalf of a practitioner you have connected, which is governed by HIPAA and by our business associate agreement with that practitioner; or (c) any third-party website, application, device, or service that we link to or that you choose to connect.
1.4 Relationship to the User Agreements. This Policy is incorporated by reference into each of the User Agreements. Where this Policy and the User Agreement that applies to you address the same subject and conflict as to the handling of health information, the document that gives the greater protection to the individual controls. For individuals, this is provided in Section 23.2 of the Terms of Service; the Provider MSA contains a corresponding provision.
1.5 Our U.S. Consumer Health Data Privacy Policy. Washington, Nevada, Illinois and certain other U.S. states require a company that handles consumer health data to publish a separate, dedicated consumer health data privacy policy with its own link. We therefore maintain this Policy and the Ressa Health Consumer Health Data Privacy Policy, which is available at <u>https://ressahealth.com/legal/consumer-health-data-privacy-policy</u> and linked separately from our homepage. Neither replaces the other. If you live in a U.S. state with a consumer health data statute, read both.
1.6 Our Privacy Policies and Your Data Choices. This Privacy Policy describes Ressa’s information practices. Our separate Consumer Health Data Privacy Policy provides additional disclosures for information covered by the state laws described there and is available through its own homepage link. The Research, Data and Marketing Authorization explains the terms of the core-service and optional choices you submit. It includes the core genetic and laboratory data consent. Visiting or acknowledging a privacy policy does not grant optional permission. Oregon and Nevada residents complete the separate state consent for the activities it covers. A separate Practitioner Health Information Marketing Authorization governs optional marketing using information held on a practice’s behalf.
1.7 Where the Service Is Offered. The Service may be offered to individuals located in the United States, Canada, the European Economic Area (the “EEA”), and the United Kingdom where Ressa expressly makes it available. Annex A contains additional U.S. state disclosures. Annex C contains additional Canadian disclosures. Annex D contains the disclosures required for EEA and UK individuals and explains the additional rules that apply under the EU General Data Protection Regulation (“EU GDPR”), the UK GDPR, the UK Data Protection Act 2018 as amended, and applicable electronic-communications privacy laws. We do not offer the Service in another jurisdiction unless we expressly make it available there and address applicable legal requirements. Annex A contains additional U.S. state disclosures. Annex C contains additional Canadian disclosures. Annex D contains the disclosures required for EEA and UK individuals. These annexes supplement, and do not replace, the Terms of Service. Where an annex refers to a right or obligation set out in the Terms of Service — including the genetic-information commitments in Section 7, the practitioner-connection provisions in Section 8, and the minor/parental-consent provisions in Section 2.1 — that section of the Terms of Service governs the specific mechanics, and this Policy governs the privacy disclosures around it.
1.8 Privacy Person. Our Privacy Person may be reached at <u>privacy@ressahealth.com</u> or by postal mail at the address above, marked “Attention: Privacy Person.” The Privacy Person is responsible for receiving privacy questions, requests, and complaints and for coordinating Ressa’s privacy compliance. For Quebec, the Privacy Person serves as Ressa’s person in charge of the protection of personal information. Additional EEA and UK representative and Data Protection Officer information, where required, is provided in Annex D. Unless Annex D expressly identifies the Privacy Person as Ressa’s statutory Data Protection Officer, their role as Privacy Person does not by itself constitute such an appointment.
2. The Short Version
This summary is provided for convenience. It is not a substitute for the rest of this Policy, and where it is less specific than the sections that follow, those sections control.
-
Your Health Vault is private by default. Nothing in it is visible to a practitioner or anyone else unless you approve them.
-
We do not sell your identifiable information, and we do not sell or share your health information for advertising.
-
We will not use or disclose your protected health information for marketing purposes without your prior authorization, except as otherwise permitted by applicable law.
-
We do not run third-party advertising or analytics trackers on any signed-in page, on any page that displays or collects health information, or in our applications, without your prior authorization.
-
We do not use your individually identifiable health information to train artificial-intelligence models, and we do not permit any provider we use to train its own general-purpose models on it.
-
We do not collect precise geolocation, and we do not operate or permit any geofencing around a healthcare facility.
-
If you are outside of the United States your information may be processed in the United States. We use contractual, technical, and organizational safeguards appropriate to the applicable law. Canadian cross-border requirements are described in Annex C; EEA and UK international-transfer requirements are described in Annex D.
-
If you are in the EEA or United Kingdom, health and genetic information is special-category personal data. We identify a lawful basis for processing and an additional special-category condition; for the direct-to-consumer Health Vault, we generally obtain explicit consent for special-category processing unless another lawful condition applies.
-
You can see, correct, export, and delete your information, and withdraw a consent you gave us, at any time. Section 15 explains how.
3. Information We Collect
3.1 Information You Give Us. We collect the information described in the table below when you provide it to us, by creating an account, using the Service, filling out a form, subscribing to a mailing list, contacting support, applying for a job, or otherwise communicating with us.
| Category | Examples | Purpose |
|---|---|---|
| Identifiers and contact information | Name, email address, mobile telephone number, postal address, account username, date of birth, and the identifiers we assign to your account. | Creating and administering your account; authenticating you; communicating with you about the Service; responding to your requests. |
| Account security information | Password (stored only in hashed form), multi-factor authentication telephone number, authentication codes, security questions, and login and access logs. | Authenticating you; protecting your account and our systems; investigating suspected fraud or unauthorized access. |
| Health Information | Laboratory results, medical records, imaging reports, genetic information, symptom assessments, intake questionnaires, health history, notes, and information from devices and applications you connect. See Section 6. | Providing the Health Vault and Insights; sharing with practitioners you approve; the purposes described in Section 9 of the Terms of Service. |
| Commercial and payment information | Subscription tier, plan history, transaction records, and the last four digits and expiration date of a payment card. We do not collect or store full payment card numbers. | Processing payments through our payment processor; billing; refunds; tax and accounting records. |
| Communications | Support tickets, emails, chat messages, call notes, survey responses, product feedback, and any files you attach. | Providing support; improving the Service; keeping records of what we told you. |
| Practitioner and business contact information | For practitioners and business contacts: name, practice or company name, professional role, business email address, business telephone number, and license or credential information you provide. | Evaluating and administering practitioner and business relationships; business communications. |
| Inferences | Preferences and characteristics we derive from the information above, including health-related patterns and trends the Service surfaces from your Health Vault. | Generating Insights for you; organizing your information; improving the Service. |
3.2 Information We Collect Automatically. When you visit our website or use the Service, we and, on our unauthenticated marketing pages only, the limited set of service providers identified in Section 7, automatically collect the information described below.
| Category | Examples | Purpose |
|---|---|---|
| Device and connection information | IP address, browser type and version, operating system, device type, screen dimensions, language and time-zone settings, and referring and exit pages. | Delivering and securing the website and the Service; diagnosing errors; detecting and preventing fraud, abuse, and automated attacks. |
| Usage information | Pages and screens viewed, features used, links and buttons selected, dates and times of access, session duration, and error and crash data. | Understanding how the Service is used so we can maintain and improve it; measuring the performance of our marketing. |
| Cookies and similar technologies | Strictly necessary cookies that keep you signed in, remember your consent choices, and protect against attacks; and, only where you have consented on our marketing pages, analytics cookies. See Section 7. | Operating the Service; remembering your preferences and consent choices; security; measuring marketing performance where you have consented. |
| Approximate location | The general region (typically state, province, or metropolitan area) inferred from your IP address. | Security and fraud prevention; determining which jurisdiction-specific rights and disclosures apply to you; general analytics. |
| Email and message engagement | Whether you opened one of our emails and which links you selected, and delivery status for text messages. | Measuring whether our communications reached you and are useful; managing subscription lists; suppressing messages to inactive addresses. |
We do not collect precise geolocation. We do not collect GPS coordinates or other precise location data from your device, we do not ask any third party to provide precise location data about you, and we do not operate or permit any geofence around a hospital, clinic, laboratory, pharmacy, family planning facility, or any other place where healthcare services are provided.
3.3 Information We Receive from Third Parties. We receive information about you from: practitioners you have approved, who may upload laboratory results, records, and other information about you; laboratory partners, which return results for testing you requested; devices and applications you choose to connect; our payment processor, which tells us whether a transaction succeeded and provides limited card metadata; our infrastructure, security, and communications vendors, in the course of providing their services to us; and, for practitioners and business contacts, publicly available professional and licensure sources. We do not buy personal information from data brokers, and we do not acquire marketing lists of individuals.
3.4 Sensitive Information. Much of what the Service holds is sensitive under U.S. and Canadian privacy law and is “special category” personal data under the EU GDPR and UK GDPR, including health and medical information and genetic information. We collect sensitive information only where it is necessary to provide a feature you have asked for or where another lawful purpose is identified. Where applicable law requires consent, we obtain a form of consent appropriate to the sensitivity and purpose. Where legally permitted, coupled with an authorization, we may use such information to build de-identified commercial data sets or for personalized marketing purposes under the <u>Research, Data and Marketing Authorization</u>. For Canadian health and genetic information, this generally means express, affirmative consent unless a lawful exception applies. For EEA and UK special-category information, we identify both an Article 6 lawful basis and an Article 9 special-category condition; for direct-to-consumer Health Vault processing, we generally rely on explicit consent under Article 9(2)(a) unless another condition is specifically identified and legally available. We do not use or disclose sensitive or special-category information to infer characteristics about you for advertising or commercial profiling.
4. Where Our Information Comes From
We collect personal information from the following categories of sources:
-
Directly from you, including through account registration, forms, uploads, assessments, support requests, surveys, and communications.
-
Automatically from your device and browser when you use the website or the Service.
-
From practitioners you have approved to connect to your account.
-
From laboratory partners that perform testing you requested through the Service.
-
From devices and applications you choose to connect.
-
From our service providers, including our cloud hosting provider, our software development vendor, our payment processor, our email and text messaging providers, and our security assessors.
-
From publicly available sources, for practitioner credential and licensure information only.
5. Why We Use Information
We use personal information only for the purposes listed below. We do not use personal information for a materially different or incompatible purpose without first telling you and, where applicable law requires it, obtaining valid consent or identifying another lawful authority. For Canadian residents, we limit collection, use, and disclosure to purposes that a reasonable person would consider appropriate in the circumstances. For EEA and UK individuals, Annex D identifies the principal Article 6 lawful bases and Article 9 conditions on which we rely and explains purpose-compatibility requirements.
-
Providing the Service. Creating and maintaining your account, storing and organizing your Health Vault, generating Insights, transmitting testing requests, delivering results, and enabling the practitioner connections you approve.
-
Security and integrity. Authenticating you, protecting accounts and data, monitoring for and investigating unauthorized access, preventing fraud and abuse, and maintaining audit logs.
-
Support and communications. Responding to your questions, sending transactional and service messages, and giving you notice of changes.
-
Payment and business records. Processing subscriptions and payments and keeping the financial, tax, and accounting records the law requires.
-
Maintaining and improving the Service. Diagnosing errors, testing changes, measuring performance, and improving features, including the quality of Insights. Where we use information to train or refine models, we do so only on a de-identified or aggregated basis, as described in Section 11.
-
Optional commercial datasets. With your effective dataset permission and the other applicable legal and contractual authority, we may use health and genetic information to create qualifying deidentified datasets and license or sell only those datasets for health research and commercial health, wellness, pharmaceutical and life-sciences uses. Section 11 describes the restrictions. Core-service consent alone does not enroll you.
-
Marketing. Sending you information about Ressa where you have asked to receive it or where the law otherwise permits it, and measuring whether our marketing works. We do not use your Health Information for this purpose without your separate written authorization. If we have your authorization, we may be paid for sponsored messages where sponsors do not receive your identifiable health or genetic information. See Section 8.
-
Legal compliance and defense. Complying with law, responding to lawful requests, enforcing our terms, and establishing, exercising, or defending legal claims.
-
Corporate transactions. Evaluating and carrying out a merger, acquisition, reorganization, financing, or sale of assets, subject to Section 9.5.
6. Health Information
6.1 Section 9 of the Terms of Service and This Policy Govern. How we treat the Health Information in your Health Vault - including what we will and will not do with it, the safeguards we apply, the rights you have in it, and applicable U.S. health-privacy commitments - is set out in Section 9 of the Terms of Service, the Research, Data and Marketing Authorization. That section is part of your agreement with us and we do not restate it here. Nothing in this Policy reduces a commitment we made in it.
6.2 Our Core Commitments. We protect Health Information with access controls, encryption and contractual restrictions; use it for the requested service and other lawful purposes described in the governing documents; and apply the particular consent or authorization required for an optional use. We do not sell identified or identifiable health or genetic records or disclose them to sponsors or advertising platforms under the optional permissions. We do not use individually identifiable Health Information for a vendor’s independent general-purpose AI model training.
6.3 Annexes. For Canadian residents, Annex C supplements our commitments. For EEA and UK individuals, Annex D supplements them with GDPR/UK GDPR lawful-basis, special-category, controller/processor, transfer, and individual-rights requirements. Nothing in this Policy reduces a commitment we made in the Terms of Service.
6.4 When HIPAA Applies in the United States, and When It Does Not. Ressa is not a healthcare provider, a health plan, or a healthcare clearinghouse, and for most of what we do we are not a HIPAA "covered entity." When you use the Service on your own in the United States, the information in your Health Vault is your own personal health record and is generally not "protected health information" under HIPAA. When you connect a U.S. practitioner and that practitioner accesses or requests your information in their capacity as a healthcare provider, we may handle that information on the practitioner's behalf, your information may become protected health information, and we may become that practitioner's "business associate." We enter into a business associate agreement with every U.S. practitioner before any access that requires one occurs. See Section 8.2 of the Terms of Service.
6.5 Canadian, EEA, and UK Health Information and Practitioner Relationships. HIPAA is a U.S. law and does not replace Canadian, EEA, or UK privacy or health-information law. When Ressa provides the Service directly to a Canadian individual, applicable federal or provincial private-sector privacy law governs our handling of that individual’s personal information. When Ressa provides the Service directly to an EEA or UK individual, Ressa generally acts as controller for the purposes and means of the direct-to-consumer Service. When Ressa processes personal or health information on behalf of a Canadian, EEA, or UK practitioner or other regulated healthcare organization that determines the purposes and means of processing, that organization may be the responsible custodian/controller and Ressa may act as its service provider or processor. We use the contracts and subprocessor controls required by the applicable law, including Article 28 processor terms where the EU GDPR or UK GDPR requires them. Annex C and Annex D provide additional details.
6.6 What That Means Practically. More than one privacy regime can apply to information about you depending on where you are located, how you use the Service, and whether a practitioner is acting as a regulated healthcare provider, health-information custodian, or controller. In the United States, HIPAA and U.S. state laws may apply in different circumstances. In Canada, federal or provincial private-sector privacy laws and provincial health-information laws may apply. In the EEA and United Kingdom, the EU GDPR or UK GDPR and national health, genetic, electronic-communications, and professional-confidentiality laws may apply. Our approach is to preserve the safeguards, use limits, and marketing and sale prohibitions described in Section 9.1 of the Terms of Service across the Service and to apply any additional protection required by the law that governs the particular information and relationship.
6.7 Genetic Information. Section 7 of the Terms of Service governs genetic information. We will not disclose your genetic information, or the fact that you have undergone genetic testing, to any health, life, disability, or long-term-care insurer, to any employer, or to any educational institution except where you expressly direct or authorize a disclosure or applicable law requires it. U.S. states, Canadian jurisdictions, EU Member States, and the United Kingdom may impose additional consent, confidentiality, or processing conditions for genetic and health information; where applicable law gives you greater rights or imposes stricter conditions, that law controls. See Annex A, Annex C, and Annex D.
7. Cookies, Analytics, and Website Tracking Technologies
7.1 Our Rule. We divide the Service into two zones for tracking purposes, and the dividing line is health information:
- **Our public, unauthenticated marketing pages**. On these pages we use first-party strictly necessary technologies, and we also also use third-party analytics, marketing-measurement, and advertising or retargeting technologies, including pixels and referral, campaign, and link-tracking parameters, but only with your affirmative consent as described in Section 7.3. If you reach our website by following a link from a social-media platform or an advertisement, standard referral and campaign information may be collected so we can tell which campaigns are working.
- **Everywhere health information lives**. We do not permit any third-party advertising, analytics, session-recording, heat-mapping, chat, or social-media tracking technology to operate on any authenticated page of the Service, on any page or screen that displays, collects, or discusses health information, or on any upload or results flow. On those pages and screens we use only first-party, strictly necessary technologies. We do not transmit health information, or any identifier that would allow a third party to infer health information about you, to any advertising platform. This is a deliberate design decision and it is the most important commitment in this section.
7.2 Strictly Necessary Technologies. Throughout the Service we use first-party cookies and similar technologies that are necessary to make the Service work: keeping you signed in, maintaining your session, remembering your language and display preferences, recording the consent and opt-out choices you have made, balancing load across our servers, and protecting against automated attacks and fraud. These are not used for advertising and cannot be switched off while you use the Service, because without them the Service cannot function or cannot be kept secure.
7.3 Optional and Advertising Technologies on Our Marketing Pages. On our public, unauthenticated marketing pages, we use the optional technologies identified below, which may include analytics, advertising, and retargeting technologies, only if you affirmatively consent through our cookie banner where prior consent is required. For EEA visitors, we apply the applicable national rules implementing the ePrivacy framework together with the EU GDPR; for UK visitors, we apply the Privacy and Electronic Communications Regulations 2003 (“PECR”), as amended. We do not load optional analytics or advertising technologies before consent for EEA or UK visitors even where a narrower statutory exemption might be available, unless we update this Policy and our consent interface accordingly. Closing or dismissing the banner is not consent. You can withdraw or change your choice through Cookie Preferences.
<table style="width:100%;"> <colgroup> <col style="width: 16%" /> <col style="width: 23%" /> <col style="width: 43%" /> <col style="width: 16%" /> </colgroup> <thead> <tr> <th><strong>Technology</strong></th> <th><strong>Provider</strong></th> <th><strong>What it does</strong></th> <th><strong>Retention</strong></th> </tr> <tr> <th>Website analytics</th> <th>Google Analytics</th> <th>Measures page views, referral sources, and general navigation patterns on our marketing pages, so we can tell which pages are useful. Configured with IP truncation and without cross-site identifiers.</th> <th>As configured and no longer than reasonably necessary for the stated purpose; shorter where required by law or after withdrawal of consent where applicable.</th> </tr> <tr> <th>Marketing measurement</th> <th><p>Google Ads</p> <p>LinkedIn Campaign Manager</p></th> <th>Measures whether a marketing campaign led to a visit or a sign-up.</th> <th>As configured and no longer than reasonably necessary for the stated purpose; shorter where required by law or after withdrawal of consent where applicable.</th> </tr> </thead> <tbody> </tbody> </table>7.4 Managing Your Choices. You can change your cookie choices at any time through our website footer, cookie preferences. You can also block or delete cookies through your browser settings, though doing so may prevent parts of the Service from working. Withdrawing consent is as easy as giving it, and takes no more steps.
7.5 Opt-Out Preference Signals and Global Privacy Control. We recognize and honor opt-out preference signals sent by your browser or a browser extension, including the Global Privacy Control (GPC). When we detect a valid signal we treat it as a request to opt out of any sale or sharing of personal information for cross-context behavioral advertising and, where the law provides, of targeted advertising, and we display a confirmation that we have processed it. Because we do not sell or share personal information for advertising in the first place, the practical effect of the signal for a Ressa visitor is limited to suppressing the optional technologies described in Section 7.3.
7.6 Do Not Track. Separate from the opt-out preference signals described above, some browsers transmit a legacy “Do Not Track” header. There is no common industry standard for interpreting it, and we do not respond to it. We do respond to the Global Privacy Control.
8. Advertising, Marketing, and Communications
8.1 We Do Not Advertise Using Your Health Information. We do not use, disclose, or make available your health information, or any inference we draw from it, for advertising or marketing of any kind without your separate written authorization. We do not disclose identified health information to any advertising platform, advertising network, data broker, or social media platform.
8.2 Service Messages. We send messages that are necessary to operate the Service and to keep your account secure, including one-time authentication codes, security alerts, billing notices, changes to our terms, and responses to your requests. These are not marketing messages. As explained in Section 3.3 of the Terms of Service, you cannot opt out of authentication and security messages while you hold an account that requires them.
8.3 Email Marketing. If you have asked to hear from us, or where the law otherwise permits it, we may send you email about Ressa’s own and its partner’s offerings including product news, educational content, and offers. Every marketing email includes a working unsubscribe link and our postal address, and we honor unsubscribe requests promptly. For recipients in Canada, we send commercial electronic messages only where permitted by Canada’s Anti-Spam Legislation (CASL). For EEA recipients, we comply with the applicable Member State rules implementing the ePrivacy framework and the EU GDPR. For UK recipients, we comply with PECR and the UK GDPR, including consent requirements where they apply. Unsubscribing from marketing email does not stop service messages.
8.4 Text Message Marketing. We send promotional text messages only to a mobile number for which we hold the consent required by applicable law, obtained separately from the authentication consent described in Section 3.3 of the Terms of Service, and never as a condition of using the Service. For recipients in Canada, promotional text messages are sent only where permitted by CASL. For EEA and UK recipients, we apply the applicable electronic-marketing consent rules under the ePrivacy framework or PECR together with the EU GDPR or UK GDPR. You may stop promotional text messages at any time by replying STOP or through your account settings. Message and data rates may apply. Message frequency varies.
8.5 Marketing Based on Health Information Requires Your Authorization. If we ever want to send you a communication that is selected, targeted, or personalized based on your health information (for example, a message about a test or program because of something in your results), we will first obtain the separate authorization or explicit consent required by applicable law. For EEA or UK special-category data, this means we will identify a valid Article 6 basis, an Article 9 condition - ordinarily explicit consent for this purpose - and any separate electronic-marketing consent required by ePrivacy law or PECR. We will not condition access to the Service, or any feature, price, or level of service, on your giving consent to health-based marketing.
8.6 Testimonials, Reviews, and Case Studies. We publish a testimonial, review, quotation, photograph, or case study about an identifiable individual only with that individual’s written permission. We do not offer compensation in exchange for a positive review, we do not suppress negative reviews, and we do not write or publish reviews in the voice of a person who did not write them. Where a testimonial reflects an individual experience, we say so and we do not present it as a typical result.
8.7 Claims About Privacy and Security in Our Marketing. Statements we make in our marketing about privacy, security, and confidentiality are representations we intend to be held to. If you believe something we have published is inconsistent with this Policy or with how the Service actually behaves, tell us at privacy@ressahealth.com and we will correct it.
8.8 Referrals. If a feature lets you invite another person to the Service, we use the contact information you give us for that purpose only, we tell the recipient who invited them, and we do not add them to a marketing list unless they ask us to.
9. How We Share Information
9.1 We Do Not Sell Identified Personal Information. We do not sell identified personal information, and we do not share identified personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined under state privacy law. We have not done so in the twelve months preceding the effective date of this Policy. We do not sell or share the personal information of any individual we know to be under eighteen.
9.2 Service Providers. We disclose personal information to vendors that perform services for us, under written contracts that limit them to processing the information for the purposes we specify, prohibit them from using it for their own purposes or disclosing it onward except as permitted by the contract and law, require appropriate security safeguards, and require deletion or return at the end of the engagement where appropriate. For any vendor that handles health information, we use a business associate agreement where HIPAA requires one or an equivalent written data protection agreement where another law applies. Where Ressa acts as a processor under the EU GDPR or UK GDPR, our controller-processor agreements include the terms required by Article 28 and we impose applicable subprocessor authorization and flow-down requirements. We remain accountable for personal information transferred to service providers to the extent required by applicable law. Our current categories of service providers, and the principal vendors in each, are:
<table> <colgroup> <col style="width: 24%" /> <col style="width: 26%" /> <col style="width: 48%" /> </colgroup> <thead> <tr> <th><strong>Category</strong></th> <th><strong>Vendor</strong></th> <th><strong>What they receive</strong></th> </tr> <tr> <th>Cloud hosting and infrastructure</th> <th>Amazon Web Services</th> <th>All information stored in the Service, encrypted at rest and in transit.</th> </tr> <tr> <th>Software development and technical operations</th> <th>NebulaWorks</th> <th>Access to production systems as necessary for development, maintenance, and support, under written confidentiality and data protection obligations.</th> </tr> <tr> <th>Payment processing</th> <th>Stripe, Inc.</th> <th>Name, email address, billing information, and transaction data. Stripe does not receive health information.</th> </tr> <tr> <th>Artificial-intelligence processing</th> <th>AI provider: Amazon Bedrock (Anthropic Claude), hosted inside our own AWS account (us-west-2), under the AWS BAA. We send no data to any public LLM API (no OpenAI, Google, or public Anthropic), and no other third-party AI, OCR, analytics, or embedding service receives clinical data. Because Bedrock runs within our AWS boundary, it falls under our AWS BAA, and per AWS terms prompts are not retained or used to train the models.</th> <th>Health Information processed within our own cloud environment under a business associate agreement, as described in Section 5.10 of the Terms of Service. The provider does not retain prompts or use them to train its models.</th> </tr> <tr> <th>Laboratory partners</th> <th><p>Evexia</p> <p>Quest</p></th> <th>The information necessary to transmit a testing request you made and to return the result.</th> </tr> <tr> <th>Email and text messaging</th> <th>Google Workspace & Amazon Web Services</th> <th>Name, email address, mobile telephone number, and message content and delivery status.</th> </tr> <tr> <th>Security assessment and penetration testing</th> <th>Secure Web Solutions</th> <th>Time-limited, logged, least-privilege access under written confidentiality and data protection obligations.</th> </tr> <tr> <th>Customer Relationship Managers</th> <th><p>B2C: Klaviyo</p> <p>B2B: GoHighLevel</p></th> <th>Information pertaining to customer/prospect name, address, email, phone, contact dates</th> </tr> </thead> <tbody> </tbody> </table>9.3 Processing Outside Your Province or Country. Ressa is a U.S. company and personal information of Canadian, EEA, and UK users may be stored, accessed, or processed in the United States, including through the service providers identified above. Information processed in another jurisdiction may be subject to lawful access by courts, law-enforcement agencies, national-security authorities, or other governmental authorities in that jurisdiction. We use contractual, technical, and organizational measures designed to provide protection appropriate to the information. Canadian cross-border requirements, including the additional requirements that apply before information is communicated or entrusted outside Quebec, are described in Annex C. EEA and UK restricted-transfer mechanisms and safeguards are described in Annex D.
9.4 At Your Direction. We share your information with a practitioner when you approve that practitioner, and with any other person or service when you tell us to. Section 8 of the Terms of Service explains what a practitioner you approve can see, what happens when you remove them, and why information that has already been shared cannot be recalled.
9.5 Affiliates. Common ownership does not authorize an affiliate or related consumer brand to use your identifiable health or genetic information independently. An affiliate performing a contracted service is subject to the same applicable confidentiality, purpose and security restrictions as other service providers. The Consumer Health Data Privacy Policy identifies the specific affiliates with which consumer health data is shared. Ressa may promote an affiliate’s offerings through messages it sends under your effective personalized-marketing authorization, without providing your identifiable health or genetic information to the affiliate for its own use.
9.6 Corporate Transactions. If we are involved in a merger, acquisition, reorganization, financing, bankruptcy, or sale of assets, personal information may be disclosed or transferred as part of that transaction. Any acquirer or successor must assume the commitments in Section 9 of the Terms of Service with respect to your health information, and we will notify you of the transfer, as Section 23.5 of the Terms of Service requires.
9.7 Legal Requirements and Safety. We may disclose personal information where we are required to do so by law or where we reasonably believe disclosure is necessary to comply with valid legal process, to protect our legal rights, to enforce our terms, or to prevent imminent physical harm. We evaluate each request, we disclose no more than the request requires, and where we are legally permitted to tell you about a request for your information we will. We will not disclose genetic information to law enforcement except pursuant to a valid court order or as otherwise compelled by law.
9.8 Insurers, Employers, and Schools. We do not disclose your health information, or the fact that you use the Service, to any insurer, employer, or educational institution.
9.9 Aggregate and De-Identified Information. We may disclose de-identified and aggregated information as described in Section 11.
10. What We Do Not Do
The commitments in this section are made to you directly and we intend to be held to them.
-
We do not sell identified personal information for money or other valuable consideration.
-
We do not share identified personal information for cross-context behavioral advertising or targeted advertising.
-
We do not disclose individually identifiable health information to any advertising platform, advertising network, data broker, or social media platform.
-
We do not use individual identifiable health information for marketing without your separate written authorization.
-
We do not use your individually identifiable health information to train or refine artificial-intelligence models, and we do not permit any artificial-intelligence provider we use to train its own general-purpose models on it.
-
We do not use or sell personal information to develop or train large language models or other general-purpose artificial-intelligence systems for any third party.
-
We do not collect precise geolocation, and we do not operate, commission, or permit any geofence around a healthcare facility.
-
We do not run third-party advertising, analytics, session-recording, or chat technologies on authenticated pages, on pages that display or collect health information, or in our applications.
-
We do not buy personal information from data brokers or acquire marketing lists of individuals.
-
We do not disclose health information to insurers, employers, or educational institutions.
-
We do not condition access to the Service, or any feature, price, or level of service, on your agreeing to any use or disclosure of information that is not necessary to provide the Service.
11. De-Identified and Aggregated Information
11.1 What We May Do. We may use and disclose information that has been de-identified, anonymized, or aggregated for lawful business purposes, including operating, securing, and improving the Service. Whether such information remains “personal information” or “personal data” depends on the law that applies. For Canadian information, we continue to treat de-identified information as personal information whenever Canadian law still regards it as capable of identifying an individual. Under the EU GDPR and UK GDPR, pseudonymized information remains personal data; we treat information as anonymous and outside those regimes only when the individual is no longer identifiable under the applicable legal standard.
11.2 Our De-Identification and Anonymization Commitments. We use a method recognized under applicable law, including the de-identification standards in 45 C.F.R. Part 164 where they apply and, for Quebec information, the applicable statutory and regulatory requirements for anonymization where we intend information to cease being personal information. We do not attempt to re-identify information that we have represented as de-identified or anonymized, do not permit a recipient to do so, and use contractual and technical measures appropriate to the risk.
11.3 Future Licensing, and the Notice You Will Get First. Ressa reserves the right in the future to provide or license lawfully de-identified, anonymized, or aggregated information to third parties, including academic institutions, research organizations, and commercial or pharmaceutical partners, and to do so for a fee. As of the effective date of this Policy we do not do this. Before beginning any such arrangement, we will update the Terms of Service and this Policy and obtain consent where applicable law requires it. For Canadian information, we will not treat information as outside privacy-law requirements merely because identifiers have been removed if the information remains personal information under applicable Canadian law.
11.4 What Deletion Cannot Reach. A deletion request generally does not require us to remove information from a dataset or analysis after the information has been lawfully anonymized or aggregated so that it is no longer personal information under the law that applies and cannot reasonably be linked back to you. If de-identified information remains personal information under applicable Canadian law, we continue to apply that law to it. See Section 15.3 of the Terms of Service.
12. How Long We Keep Information
We keep personal information only for as long as reasonably necessary to fulfill the purposes described in this Policy, to provide the Service, to satisfy legal, regulatory, accounting, security, and contractual requirements, to maintain required consent or incident records, and to establish or defend legal claims. The table below describes our retention approach. Where applicable U.S., Canadian, EEA, or UK law requires a shorter period, the shorter period controls. For EEA and UK personal data, we apply the storage-limitation principle and periodically review whether identifiable information remains necessary for the stated purpose. At the end of the applicable period we securely delete the information or, where lawful, anonymize or de-identify it so that it is no longer personal information or personal data under the applicable standard. Information in encrypted backups is removed on our ordinary backup rotation. You may contact our Privacy Person for the current retention period or criteria applicable to a specific category.
| Category | Retention period | Why |
|---|---|---|
| Health Information in your Health Vault | For as long as your account is open. After closure, up to seven (7) years where permitted and reasonably necessary. If you ask us to delete, we ordinarily delete within thirty days after verification unless applicable law, a practitioner/custodian obligation, a legal hold, or another permitted retention ground requires us to keep some information longer. | Supporting your Health Vault, applicable medical/health-record obligations, account recovery where permitted, legal compliance, and verified deletion rights. |
| Account, identifier, and contact information | While your account is active and thereafter only for the period reasonably necessary for account administration, security, fraud prevention, legal compliance, or a documented legal need. | Administering the account; responding to post-closure questions; preventing account takeover; legal compliance. |
| Authentication and access logs | For the period reasonably necessary for security monitoring and incident investigation, and longer only where tied to a documented incident, legal hold, or legal obligation. | Security monitoring, incident investigation, and audit logging. |
| Payment and transaction records | For the period required by applicable tax, accounting, financial-recordkeeping, chargeback, and other legal obligations. | Tax, accounting, financial recordkeeping, billing disputes, and other legal obligations. Our payment processor follows its own lawful schedule. |
| Support communications | While needed to provide support and continuity and thereafter only for the period reasonably necessary to document the interaction, comply with law, or resolve a dispute. | Providing continuity of support and keeping an appropriate record of what we told you. |
| Marketing and subscription preferences, and suppression lists | For as long as needed to honor your preference. A minimal suppression record may be retained for as long as necessary to ensure that an opt-out remains effective. | Honoring unsubscribe, consent, and opt-out choices. |
| Consent and authorization records | For as long as reasonably necessary to demonstrate the consent or authorization and satisfy applicable law, regulatory obligations, or a related legal claim. | Documenting what you agreed to, when, and any later withdrawal or change. |
| Website and marketing analytics | For the period configured in the applicable analytics tool and no longer than reasonably necessary for the stated analytics purpose; future collection stops when consent is withdrawn where consent is required. | Measuring and improving our marketing while applying applicable consent and retention requirements. |
| Records needed for a legal claim or investigation | For the duration of the applicable legal hold, claim, investigation, audit, limitation period, or other legal obligation, plus a reasonable period to close the matter. | Establishing, exercising, or defending legal claims and complying with legal or regulatory obligations. |
13. Security
13.1 Our Safeguards. We maintain administrative, physical, and technical safeguards designed to protect personal information, including encryption in transit and at rest, role-based access controls, multi-factor authentication, audit logging, least-privilege and minimum-necessary access, written confidentiality obligations for every workforce member and contractor with access, vendor security review, and periodic independent security assessment. These commitments are made in Section 9.1 of the Terms of Service.
13.2 Your Part. Keep your credentials and authentication codes confidential, do not share them, and tell us promptly at privacy@ressahealth.com if you believe your account has been accessed without your authorization. Think carefully before you approve a practitioner: as Section 8 of the Terms of Service explains, approving a practitioner may expose your whole record to them, and information that has already been shared cannot be recalled.
13.3 No System Is Perfect. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do commit to telling you when something goes wrong, as described in Section 14.
14. If There Is a Data Breach
14.1 Notice to You. If we discover a breach of security, confidentiality incident, or other reportable incident affecting your personal information, we investigate promptly, take reasonable steps to contain and mitigate the incident, assess the risk of harm, and notify you within the time and in the manner required by the law that applies. U.S. HIPAA, the FTC Health Breach Notification Rule, and U.S. state laws retain their own notification standards and deadlines. For Canadian information, where PIPEDA applies we provide required notice as soon as feasible after determining that a breach creates a real risk of significant harm; where Quebec law applies, we act with diligence when a confidentiality incident presents a risk of serious injury. For EEA personal data, where the EU GDPR requires notice to affected individuals because a breach is likely to result in a high risk to their rights and freedoms, we notify them without undue delay. We apply the corresponding UK GDPR standard to UK individuals. Our notice includes the information required by the applicable law and practical steps you can take to protect yourself.
14.2 Notice to Regulators and Others. Where the law requires it, we notify the appropriate regulator or other body. In the United States, this may include the U.S. Department of Health and Human Services, the Federal Trade Commission, state attorneys general, affected practitioners for whom we act as a business associate, and media where applicable. In Canada, this may include the Office of the Privacy Commissioner of Canada, a provincial privacy commissioner, the Commission d’accès à l’information du Québec, affected Canadian practitioners or health-information custodians, and other organizations able to reduce the risk of harm. Under the EU GDPR and UK GDPR, a controller must notify a notifiable personal-data breach to the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it. Where Ressa acts as a processor, we notify the responsible controller without undue delay so that the controller can meet its obligations.
14.3 Why the Federal Trade Commission. For the part of our business that is not governed by HIPAA, the Health Vault is a personal health record and Ressa is a vendor of personal health records subject to the Federal Trade Commission’s Health Breach Notification Rule, 16 C.F.R. Part 318. Under that rule, an unauthorized disclosure of health information (including a disclosure we make voluntarily and without your authorization, such as a disclosure to an advertising platform) is a reportable breach. We have designed the Service, and in particular the tracking-technology rule in Section 7.1, so that no such disclosure occurs.
14.4 Our Vendors’ Obligations and Incident Records. Our written agreements require vendors that handle personal information to notify us promptly of suspected or actual incidents so that we can meet applicable deadlines. We maintain breach and confidentiality-incident records for the periods required by applicable law, including Canadian recordkeeping requirements and the EU GDPR/UK GDPR obligation to document personal-data breaches whether or not notification is required.
15. Your Privacy Rights
15.1 We Offer These Rights Broadly. Privacy laws give different rights to residents of different U.S. states and Canadian jurisdictions and to individuals in the EEA and United Kingdom. Rather than limit our baseline process by location, we offer the rights listed below broadly, subject to lawful exceptions, verification, and the legal basis for processing. Annex A describes additional U.S. state-specific disclosures and mechanics. Annex C describes additional Canadian disclosures, statutory timelines, and complaint rights. Annex D describes EEA and UK rights, lawful-basis consequences, objection and restriction rights, supervisory-authority complaints, and the different UK complaints process now required by the Data Protection Act 2018 as amended.
15.2 Your Rights. You may:
-
Know and access. Confirm whether we process personal information about you and obtain a copy of it, including the categories we collected, the sources, the purposes, the categories of third parties to whom we disclosed it, and the inferences we hold. You may download the contents of your Health Vault from the Service at any time, free of charge.
-
Correct. Ask us to correct inaccurate personal information about you. You can edit much of it yourself in the Service.
-
Delete. Ask us to delete personal information about you, subject to lawful exceptions. For EEA and UK individuals this includes the right to erasure where the conditions in the applicable GDPR are met; it is not an absolute right and may not apply where processing remains necessary for legal obligations, legal claims, or another lawful ground. Section 15 of the Terms of Service describes what deletion reaches and what it cannot reach.
-
Take it with you. Obtain eligible information in a portable, readable, machine-usable format. Quebec residents have the additional portability right described in Annex C. EEA and UK individuals have the GDPR/UK GDPR right to receive qualifying personal data they provided to us in a structured, commonly used, machine-readable format and, where technically feasible and legally required, to have it transmitted to another controller when the statutory conditions are met.
-
Withdraw a consent. Withdraw a consent you gave us, including explicit consent for health or genetic processing, subject to legal restrictions and reasonable notice. Withdrawal does not invalidate processing that was lawful before withdrawal. If the information is objectively necessary to provide a feature you requested and no other lawful basis or special-category condition applies, withdrawal may mean we can no longer provide that feature or may need to close the relevant Health Vault functionality.
-
Opt out / object. Opt out of any sale of personal information, any sharing for cross-context behavioral advertising or targeted advertising, and any profiling in furtherance of a decision that produces a legal or similarly significant effect where U.S. law provides such rights. EEA and UK individuals may object to processing based on legitimate interests or public-task grounds as provided by applicable law and have an absolute right to object to processing for direct marketing. As Section 9.1 explains, we do not sell or share personal information for targeted advertising.
-
Restrict or limit processing. Direct us to limit our use and disclosure of sensitive personal information where applicable U.S. law provides that right. EEA and UK individuals may request restriction of processing where the statutory conditions are met, including while accuracy is contested or an objection is being evaluated. Because our baseline use of health information is already limited to providing and securing the Service and other disclosed lawful purposes, some U.S. limitation requests may not require a further operational change; Annex D describes the separate EEA/UK restriction right.
-
Get a list of recipients. Obtain a list of the specific third parties to which we have disclosed your personal information, with a means of contacting each of them.
-
Be free from retaliation. Exercise any of these rights without being denied service, charged a different price, or given a different level or quality of service.
-
Appeal or complain. Appeal a decision we make on a request where applicable U.S. law provides an appeal right, or make a privacy/data-protection complaint to Ressa and the competent regulator as described in Annex A, Annex C, or Annex D.
15.3 How to Make a Request. Submit a request through your account settings, by emailing our Privacy Person (the fastest way) at privacy@ressahealth.com, or by calling us at +1-520-724-1376 or by writing to us at the address in Section 1.1. Tell us what you want us to do and give us enough information to locate your records. Canadian access and correction requests that must be in writing are satisfied by an email or written request to our Privacy Person.
15.4 How We Verify You. Because the information we hold is sensitive, we verify who you are before we act. For an account holder, we verify through your authenticated account and the second authentication factor on it. Where you are not signed in, we may ask you to confirm information we already hold, and for a request to access or delete health information we may ask for additional confirmation. We use information you give us for verification only for that purpose. If we cannot verify you, we will tell you why and, where the law permits, treat the request as an opt-out instead of denying it.
15.5 Authorized Agents. Someone may submit a request for you if you give them written permission and we can verify both your identity and their authority, or if they hold a valid power of attorney. Note that, under Section 2.2 of the Terms of Service, no one may hold or operate an account on behalf of another adult.
15.6 Parents and Guardians. A parent or legal guardian may exercise these rights for a minor whose account they manage under Section 2.1 of the Terms of Service.
15.7 Our Timeline. We acknowledge requests promptly and respond within the period required by applicable law. For U.S. requests governed by the baseline process in this Policy, we ordinarily respond within forty-five days and use an extension only where permitted. For Canadian access requests governed by PIPEDA, we respond within thirty calendar days, subject to the limited extensions PIPEDA permits; for Quebec access or correction requests, within thirty days; for Alberta PIPA requests, generally forty-five calendar days; and for British Columbia PIPA requests, generally thirty business days, in each case subject to lawful extensions. For EEA and UK rights requests, we respond without undue delay and ordinarily within one month, with any extension only as permitted by the applicable GDPR or UK law. We charge no fee except where applicable law permits one and we give any required advance notice.
15.8 Appeals and Complaints. If we decline your request in whole or in part, we tell you why to the extent permitted by law and explain available review or complaint rights. You may ask us to reconsider or make a privacy complaint by emailing privacy@ressahealth.com with “Appeal” or “Privacy Complaint” in the subject line or by using the web form in Section 20. For U.S. residents, Annex A identifies certain regulators. Canadian residents may complain to the applicable federal or provincial privacy regulator as described in Annex C. EEA individuals may complain to a competent EEA supervisory authority as described in Annex D. UK individuals may complain to the UK Information Commissioner; under current UK law, Ressa also provides a direct data-protection complaint process, acknowledges a UK data-protection complaint within 30 days, investigates it appropriately, keeps the complainant informed as appropriate, and communicates the outcome without undue delay.
15.9 Requests That Belong to Your Practitioner, Health-Information Custodian, or Controller. Where we hold information on behalf of a practitioner or other organization acting as controller/custodian for its own records, that organization may be legally responsible for deciding the request. In the United States, we route requests as required by HIPAA and the applicable business associate agreement. In Canada, where a practitioner or other regulated health-information custodian or trustee has custody or control under provincial law, we route or support the request as required by that law and our agreement. In the EEA or UK, where Ressa acts as processor for a practitioner or healthcare organization that is the controller, we assist that controller with data-subject requests as required by Article 28 and our data processing agreement. See Sections 8.6 and 9.2 of the Terms of Service, Annex C, and Annex D.
16. Children and Minors
16.1 The Service Is Not for Children. The Service is not directed to children under thirteen and we do not knowingly permit a child under thirteen to establish and operate their own account. If we learn that a child has supplied personal information contrary to our account rules, we investigate and take appropriate action. Different parental-consent and age-assurance rules may apply in Canada, the EEA, and United Kingdom; Annex C and Annex D describe the additional requirements that apply where we offer the Service to minors.
16.2 Minors Generally. Under Section 2.1 of the Terms of Service, an account for a minor is held and operated by the minor’s parent or legal guardian, who provides the authorization required for the minor’s use of the Service. In the EEA, the age at which a child may provide their own consent for an information-society service varies by Member State from 13 to 16. In the United Kingdom, the corresponding digital-consent age is 13. Because Ressa handles health and genetic information, we may apply a more protective parent/guardian-managed account rule even where a child could provide consent to some online processing under local law, and we make reasonable efforts to verify parental authority where required.
16.3 We Do Not Advertise to Minors. We do not sell the personal information of any individual we know to be under eighteen, we do not use it for targeted advertising or profiling, and we do not disclose it to any advertising platform.
17. Automated Processing and Insights
17.1 What the Service Does Automatically. The Service applies algorithmic and artificial-intelligence tools to the information in your Health Vault to organize it, identify patterns and trends, compare values over time, flag values that fall outside a configured range, and present educational material. Section 5 of the Terms of Service governs this processing, explains its limits, and explains why an Insight is not medical advice, not a diagnosis, and not a clinical determination. Read it.
17.2 No Decisions Are Made About You. We do not use automated processing to make, or to substantially replace human judgment in making, any decision about your eligibility for or access to healthcare, credit, insurance, housing, education, employment, or any other significant benefit or service. No clinician at Ressa reviews your results, and the Service does not triage you, prioritize you, or decide what care you should receive.
17.3 Your Rights If That Changes. If we ever introduce a feature that uses automated processing to make or substantially replace human decision-making about a significant decision concerning you, we will provide the notice, lawful basis, and safeguards required by the law that applies. Under the EU GDPR, individuals generally have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to statutory exceptions and safeguards; use of special-category data for such a decision is more restricted. Under the UK GDPR as amended by the Data (Use and Access) Act 2025, significant solely automated decisions may be permitted in a broader range of circumstances, but appropriate safeguards remain mandatory and special-category data remains subject to stricter restrictions. Where Quebec law applies to a decision based exclusively on automated processing, we provide the notice and review opportunity described in Annex C. Ressa does not currently use the Service to make the significant eligibility or access decisions described in Section 17.2.
18. Third-Party Websites, Services, and Connections
18.1 Links. Our website and the Service may link to websites and services we do not control. This Policy does not apply to them, and we are not responsible for their content, security, or privacy practices. Read their policies before you use them.
18.2 Connected Devices and Applications. If you connect a third-party device, application, or account, you authorize us to receive data from it and, where the connection is two-way and you have so elected, to send data to it. Your use of that third party remains governed by its own terms and privacy policy. Disconnecting stops future data flow but does not delete data already received. See Section 13.5 of the Terms of Service.
18.3 Laboratory Partners. Where you request testing through the Service, your testing relationship is with the independent laboratory partner and that partner’s own terms, privacy policy, and consent forms govern the testing. See Section 6 of the Terms of Service.
18.4 Payment Processing. Payments are processed by Stripe, Inc. Stripe’s handling of your payment information is governed by Stripe’s own privacy policy, available at https://stripe.com/privacy. As Section 15.3 of the Terms of Service explains, closing your Ressa account does not delete the records Stripe maintains; contact Stripe directly about those.
19. Changes to This Policy
19.1 How We Change It. We may update this Policy. When we do, we will change the effective date at the top and post the updated Policy on our website. We review this Policy at least once a year whether or not it needs changing.
19.2 Material Changes. If we make a material change - in particular, if we begin to collect a new category of information, use information for a new purpose, disclose it to a new category of recipient, or materially change a practice on which you previously relied - we give notice before the change takes effect and obtain new consent where applicable law requires it. For Canadian residents, we will not rely on an earlier consent for a materially new collection, use, or disclosure where fresh consent is required. For EEA and UK individuals, we evaluate whether a new purpose is compatible with the original purpose, update the applicable lawful-basis and Article 9 analysis, and obtain new consent where the existing basis does not cover the new processing.
19.3 Prior Versions. We keep prior versions of this Policy and will provide one on request.
20. How to Contact Us
Questions, requests, and complaints about privacy should be directed to our Privacy Person:
-
Privacy Person: <u>privacy@ressahealth.com</u> (the best and fastest way)
-
Mail: Metabolic Terrain Omics, Inc. (d/b/a Ressa Health), Attention: Privacy Person, 2 East Congress Street, Suite 900, Tucson, AZ 85701
-
Phone: +1-520-724-1376
If you are not satisfied with our response, you may contact the regulator that has jurisdiction over your complaint. Annex A identifies certain U.S. regulators. Annex C identifies Canadian federal and provincial privacy regulators and explains the Quebec complaint process. Annex D explains EEA supervisory-authority and UK Information Commissioner.
Annex A - U.S. State-Specific Disclosures
This Annex supplements the Policy above for residents of the United States. It applies only to residents of the states named, and only to the extent the law of that state applies to Ressa. Where this Annex and the Policy conflict, this Annex controls for residents of the state in question. Canadian disclosures are in Annex C.
A-1. Washington, Nevada, Illinois and Other Consumer Health Data States
Washington, Nevada, Illinois and certain other states regulate “consumer health data” separately and require a dedicated privacy policy for it. Those disclosures, and the rights and mechanics that go with them, are set out in the Ressa Health Consumer Health Data Privacy Policy, available at <u>https://ressahealth.com/legal/consumer-health-data-privacy-policy</u>
and linked separately from our homepage. That document, not this one, is the policy required by RCW 19.373.020 and NRS 603A.495. Washington residents should note that a violation of the Washington My Health My Data Act is an unfair or deceptive act under the Washington Consumer Protection Act, chapter 19.86 RCW, and that the Act may be enforced privately as well as by the Washington Attorney General.
A-2. California
Scope. The California Consumer Privacy Act, as amended, applies to businesses that meet statutory thresholds relating to revenue, the number of consumers whose personal information they buy, sell, or share, or the share of revenue they derive from selling or sharing personal information. We nonetheless provide the disclosures and offer the rights below to California residents, and we will do so whether or not we are a covered business.
Categories and practices. The categories of personal information we collect, the sources, the purposes, and the categories of recipients are described in Sections 3, 4, 5, and 9 of the Policy. Our retention periods are in Section 12. We collect the following categories of personal information as those categories are defined in the CCPA: identifiers; personal information listed in the California Customer Records statute; commercial information; internet and other electronic network activity information; approximate geolocation data; audio and visual information, where you send it to us; professional information, for practitioners and business contacts; and inferences. We do not collect biometric information for identification purposes.
Sensitive personal information. We collect sensitive personal information, including personal information collected and analyzed concerning your health, genetic data, and account log-in credentials. We use and disclose it only to perform the services you requested, to prevent and investigate security incidents and fraud, to ensure the physical safety of individuals, for short-term transient use that does not involve disclosure or profiling, and to verify or maintain the quality and safety of the Service; that is, only for the purposes permitted by 11 C.C.R. § 7027(m). Because we do not use or disclose sensitive personal information for any other purpose, we are not required to offer, and we do not display, a “Limit the Use of My Sensitive Personal Information” link. You may still direct us to limit our use of it under Section 15.2 of the Policy and we will honor the request.
Selling and sharing. We have not sold personal information and have not shared personal information for cross-context behavioral advertising in the twelve months preceding the effective date of this Policy. We therefore do not display a “Do Not Sell or Share My Personal Information” link. We honor the Global Privacy Control as described in Section 7.5.
Disclosures for a business purpose. In the twelve months preceding the effective date of this Policy we disclosed each category of personal information identified above to the categories of service providers and contractors listed in Section 9.2, and to professional advisors, for the business purposes described in Section 5.
Your California rights. You have the rights to know, access, correct, delete, and port your personal information; to opt out of the sale or sharing of personal information; to limit the use and disclosure of sensitive personal information; and to be free from retaliation for exercising any of them. Requests to know reach back to January 1, 2022 where we retain information for longer than twelve months. Section 15 of the Policy explains how to make a request, how we verify you, and how to use an authorized agent.
Notice at collection. Annex B is our notice at collection. It is also delivered at or before the point at which we collect personal information.
Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We make no such disclosures. Requests may be sent to privacy@ressahealth.com.
Complaints. California residents may contact the California Privacy Protection Agency or the California Attorney General. The notice required by California Civil Code § 1789.3 appears in Section 22.1 of the Terms of Service.
A-3. Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Texas, Virginia, and Other Comprehensive-Law States
Whether these laws apply to Ressa depends on thresholds that vary by state. We offer the rights below to residents of each of these states without regard to whether a threshold is met.
-
The rights of access, correction, deletion, and portability; the right to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects; the right to withdraw consent to the processing of sensitive data; and the right to appeal. Sections 15.2 through 15.9 of the Policy describe the mechanics, including our forty-five-day response period, the single forty-five-day extension, and the appeal process.
-
We process sensitive data, including health data, only with your consent and only where it is necessary to provide a feature you asked for. We do not sell sensitive data. We do not process sensitive data for targeted advertising or profiling.
-
Large language models and artificial intelligence. Connecticut requires us to tell you whether we use or sell personal data to train large language models. We do not. We use only de-identified or aggregated information to train or refine models, and we do not permit any artificial-intelligence provider we use to train its own general-purpose models on your individually identifiable information.
-
List of specific third parties. Connecticut and certain other states give you the right to obtain a list of the specific third parties to which we have disclosed your personal data. Section 15.2 of the Policy offers this right to everyone.
-
Maryland. Maryland prohibits the sale of sensitive data outright and permits its collection and processing only where strictly necessary to provide or maintain a specific product or service the consumer requested. Our purposes for health information in Section 5 are written to that standard, and we do not sell sensitive data to anyone, anywhere.
-
Texas and Nebraska. Texas and Nebraska prohibit even a small business from selling sensitive personal data without consent. We do not sell sensitive personal data.
-
Nevada. Separately from the consumer health data statute described in Annex A-1, Nevada law gives residents the right to direct a website operator not to sell covered information. We do not sell covered information. A verified request may be sent to privacy@ressahealth.com.
-
Profiling and assessments. We do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. See Section 17.2 of the Policy.
A-4. Illinois
Illinois restricts the disclosure of genetic testing information and, effective January 1, 2027, extends those restrictions to biomarker testing information, which may include the analysis of blood, tissue, and fluid samples. We do not disclose genetic or biomarker testing information, or the fact that you have undergone such testing, to any employer, insurer, or educational institution, and we obtain your written consent before releasing it to anyone other than a practitioner you have approved. Illinois law provides statutory damages for violations.
A-5. Other Genetic Privacy Statutes
A number of states impose additional requirements on direct-to-consumer genetic testing, including separate consent for collection, use, retention, transfer, and destruction, and some provide statutory damages. Section 7 of the Terms of Service governs genetic information, and where a state gives you greater rights than that section or this Policy provides, that state’s law controls.
Annex B - U.S. Notice at Collection
This short U.S. notice is provided at or before the point at which we collect personal information where applicable U.S. law requires it. It summarizes the Policy; the Policy controls. Canadian collection disclosures are addressed in Annex C and in the collection interface where Canadian law requires additional notice.
| What we collect | Why | Do we sell or share it? | How long we keep it |
|---|---|---|---|
| Identifiers and contact information | To create and run your account and communicate with you | No | While the account is active and thereafter only as described in Section 12. |
| Account security information | To authenticate you and protect your account | No | For the security and legal-compliance period described in Section 12. |
| Health Information, including genetic information (sensitive) | To provide the Health Vault and Insights and to share with practitioners you approve | No | While the account is open and thereafter as described in Section 12; verified deletion requests are ordinarily completed within 30 days unless a lawful retention ground applies. |
| Commercial and payment information | To process payments and keep financial records | No | For the applicable tax, accounting, financial, and legal recordkeeping period described in Section 12. |
| Internet and device activity | To deliver and secure the Service and measure our marketing | No | For the period reasonably necessary for security, service operation, or analytics, as described in Section 12. |
| Approximate location | Security, fraud prevention, and applying jurisdiction-specific rights | No | For the period reasonably necessary for security, fraud prevention, and jurisdictional compliance. |
| Communications | To support you and keep a record of what we told you | No | For the support, compliance, or dispute-resolution period described in Section 12. |
| Inferences | To generate Insights and organize your information | No | While your account is open and thereafter only as reasonably necessary for the stated purpose, subject to Section 12. |
Annex C - Canadian Privacy Disclosures
This Annex supplements the Policy for individuals in Canada. It is intended to address the Personal Information Protection and Electronic Documents Act (PIPEDA), where applicable; substantially similar provincial private-sector privacy laws, including Alberta's Personal Information Protection Act and British Columbia's Personal Information Protection Act; Quebec's Act respecting the protection of personal information in the private sector; and applicable provincial health-information laws when Ressa handles information in connection with a regulated Canadian practitioner or health-information custodian. The law that applies depends on the province, the nature of the transaction, and the role Ressa is performing. Where this Annex gives a Canadian individual greater protection than another provision of this Policy, this Annex controls for that individual. Nothing in this Annex reduces any HIPAA or U.S. privacy obligation that applies to information Ressa handles in the United States.
C-1. Accountability and Our Privacy Person
Ressa is responsible for personal information under its control to the extent required by applicable Canadian law, including information transferred to a service provider for processing. Our Privacy Person may be reached at privacy@ressahealth.com. The Privacy Person receives privacy questions, access and correction requests, consent-withdrawal requests, and complaints; coordinates our privacy management program; and oversees our response to Canadian privacy incidents. For Quebec, the Privacy Person serves as Ressa's person in charge of the protection of personal information. You may also write to: Metabolic Terrain Omics, Inc. (d/b/a Ressa Health), Attention: Privacy Person - 2 East Congress Street, Suite 900, Tucson, AZ 85701.
C-2. Meaningful Consent and Sensitive Health Information
Canadian privacy law generally requires meaningful consent for the collection, use, and disclosure of personal information unless a statutory exception applies. We identify the information involved, the purposes for which it is collected, used, or disclosed, and the parties or categories of parties to whom it will be disclosed in a manner designed to be understandable at the time consent is sought. We do not require consent to a collection, use, or disclosure that is not reasonably necessary for the Service as a condition of providing the Service. Because health, medical, laboratory, genetic, and similar information is sensitive, we use express or affirmative consent where applicable Canadian law requires or expects that form of consent. We keep appropriate records of consent and allow consent to be withdrawn subject to legal or contractual restrictions and reasonable notice. If withdrawal prevents us from providing a requested feature, we will explain that consequence.
C-3. Collection, Use, Disclosure, and Data Minimization
Sections 3 through 5 describe the categories of personal information we collect, our sources, and our purposes. Sections 7 through 10 describe cookies, marketing, disclosures, and practices we prohibit. For Canadian residents, we limit collection to information reasonably necessary for identified purposes; use and disclose it only for those purposes, compatible purposes permitted by law, or another purpose for which we obtain any consent the law requires; and use safeguards appropriate to the sensitivity of the information. We do not sell identifiable health information, use it for targeted advertising, or use it to train third-party general-purpose artificial-intelligence models.
C-4. Processing and Storage Outside Canada
Ressa is located in the United States, and Canadian personal information may be transferred to, stored in, accessed from, or otherwise processed in the United States by Ressa and the service providers identified in Section 9.2.
How we ensure comparable protection. Before we transfer personal information to a service provider outside Canada, we (a) enter into a written agreement with that service provider containing data-protection obligations substantially equivalent to those required of a Canadian organization, including limits on the purposes for which the information may be used, restrictions on onward disclosure, data security and breach-notification requirements, audit and deletion-on-termination obligations, and confidentiality commitments binding the provider's personnel; and (b) assess the recipient jurisdiction's legal framework, including the likelihood of government access to the information, before relying on that agreement. These are the same contractual protections and diligence process we apply to satisfy Article 28 of the EU GDPR and the UK GDPR for our EEA and UK transfers, extended to cover Canadian personal information as well.
Ressa remains accountable for personal information transferred to a service provider to the extent required by Canadian law. Personal information processed in the United States is subject to U.S. law and may be accessible to U.S. courts, law-enforcement agencies, national-security authorities, or other governmental authorities where lawful process permits.
On request, our Privacy Person will confirm which of our service-provider agreements govern a specific category of your personal information and will provide additional information about the safeguards that apply, subject to lawful redactions for confidential or security-sensitive terms.
C-5. Canadian Access, Correction, and Complaint Rights
Subject to lawful exceptions, Canadian residents may ask whether we hold personal information about them; obtain access to that information and an account of its use and disclosure; ask us to correct information that is inaccurate or incomplete; withdraw a consent; and challenge our compliance with applicable Canadian privacy law. We may need to verify identity before granting access. We respond within the statutory period that applies to the request: generally 30 calendar days under PIPEDA and Quebec private-sector law, 45 calendar days under Alberta PIPA, and 30 business days under British Columbia PIPA, subject to extensions permitted by the applicable statute. If we refuse access or correction, we will explain the refusal to the extent the law permits and identify available recourse.
C-6. Canadian Practitioner and Health-Information Relationships
When a Canadian practitioner uses Ressa in a capacity regulated by a provincial health-information statute, the practitioner or other regulated organization may be the health-information custodian, trustee, or organization responsible for custody or control of the clinical record. In those circumstances, Ressa may act as an electronic service provider, information manager, agent, service provider, or similar processor under the applicable provincial law and our agreement with that provider. Requests concerning a provider-controlled clinical record may therefore need to be decided by the provider. We will route the request or assist the provider as required by applicable law and contract. HIPAA terminology and business associate agreements apply only where U.S. HIPAA applies; they do not displace Canadian law.
C-7. Quebec Residents - Additional Requirements
If Quebec's Act respecting the protection of personal information in the private sector applies, the additional requirements in this section apply to you. Ressa's Privacy Person is in charge of the protection of personal information for purposes of this Policy. When we collect personal information from you, we provide the information required by Quebec law in clear and simple language, including the purposes and means of collection, your access and correction rights, your right to withdraw consent where applicable, the relevant recipient information required by law, and the possibility that information may be communicated outside Quebec. On request, we will also provide the categories of persons within Ressa who have access and the applicable retention period or criteria.
Sensitive information and consent. Medical, health, genetic, and similar information is sensitive. Where Quebec law requires consent for sensitive personal information, we obtain express consent. A written request for consent is presented separately from other information where required, and consent is requested for each specific purpose where the law requires separate consent. We do not condition the Service on consent to a use or disclosure that is not necessary for the requested Service unless the law permits us to do so.
Privacy by default and technology. Where a Quebec requirement applies to a technological product or service offered to the public, privacy settings that allow a choice are configured to provide the highest level of confidentiality by default, except for settings expressly excluded by law. Your Health Vault is private by default. Where technology includes a function that allows identification, location, or profiling and Quebec law requires notice or activation, we provide the required information and means to activate the function before using it. The Service does not collect precise geolocation.
Privacy impact assessments. We conduct privacy impact assessments where Quebec law requires them, including for qualifying projects involving the acquisition, development, or redesign of information systems or electronic service-delivery systems that involve personal information. Before communicating personal information outside Quebec or entrusting a person or body outside Quebec with collecting, using, communicating, or keeping it on our behalf, we conduct the privacy impact assessment required by Quebec law. The assessment considers the sensitivity of the information, the purpose, the protection measures including contractual measures, and the legal framework in the destination jurisdiction. We make the communication only if the assessment supports adequate protection and we use a written agreement that takes the assessment and risk-mitigation measures into account.
Access, correction, and portability. We respond to Quebec access and correction requests within 30 days of receipt, subject to lawful exceptions. For qualifying computerized personal information that we collected from you, you may request a copy in a structured, commonly used technological format and, where the law requires, ask us to transmit it in that format to a person or organization authorized to collect it. The portability right does not require us to provide information that was created or inferred by us where the statute excludes that information. Where Quebec law provides a right to request that dissemination cease or that a hyperlink be de-indexed or re-indexed, we will evaluate a qualifying request under the statutory conditions.
Exclusively automated decisions. Ressa does not currently use automated processing to make decisions about your eligibility for healthcare, insurance, employment, credit, housing, education, or another significant benefit. If we make a decision based exclusively on automated processing and Quebec law applies, we will give the notice and information described in Section 17.3, including an opportunity to submit observations to a person who can review the decision.
Retention, destruction, and anonymization. We retain Quebec personal information only for the period reasonably necessary for the purposes for which it was collected and for applicable legal or regulatory obligations. When those purposes are fulfilled and no legal retention ground remains, we securely destroy the information or anonymize it where Quebec law permits and the statutory and regulatory anonymization requirements are satisfied. Merely removing direct identifiers does not cause us to treat information as anonymous if it remains personal information under Quebec law.
Confidentiality incidents. We maintain a register of confidentiality incidents involving Quebec personal information for the period required by Quebec law. When an incident presents a risk of serious injury, we notify the Commission d'accès à l'information du Québec and affected individuals with the diligence and information required by law and take reasonable measures to reduce the risk of injury and prevent recurrence.
French-language version. A French-language version of this Policy and the Quebec-facing consent materials are available for Quebec users in French, as required by Quebec law. The French Privacy Policy will be available at <u>https://ressahealth.com/legal/privacy-policy</u>
C-8. Canadian Privacy Regulators
You may raise a privacy concern with our Privacy Person first, but doing so does not limit any right to complain to a regulator. Depending on the law that applies, the relevant regulator may include: the Office of the Privacy Commissioner of Canada (priv.gc.ca); the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca); the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca); or, for Quebec, the Commission d'accès à l'information du Québec (cai.gouv.qc.ca). A provincial health-information commissioner or privacy regulator may also have jurisdiction where a regulated Canadian healthcare provider is responsible for the record.
C-9. Relationship Between Canadian Law and U.S. HIPAA Obligations
This Canadian Annex is supplemental. It does not amend, waive, or reduce any obligation Ressa has under HIPAA, the HIPAA Privacy, Security, or Breach Notification Rules, a U.S. business associate agreement, the FTC Health Breach Notification Rule, or applicable U.S. state law. When U.S. HIPAA governs a particular disclosure or record, Ressa will continue to comply with HIPAA and the applicable business associate agreement. When Canadian law also applies to Ressa or to a separate Canadian record or relationship, Ressa will apply the Canadian requirement in addition to the U.S. commitments to the extent the laws can be complied with together. If a legal conflict cannot be reconciled, Ressa will evaluate the specific information, role, and jurisdiction and follow the legally controlling requirement while preserving the greatest privacy protection that can lawfully be provided.
Annex D - European Economic Area and United Kingdom Privacy Disclosures
This Annex supplements the Policy for individuals in the European Economic Area (European Union Member States plus Iceland, Liechtenstein, and Norway) and the United Kingdom. It applies when the EU GDPR or UK GDPR applies to Ressa’s processing. The UK GDPR operates together with the Data Protection Act 2018 and has been amended by the Data (Use and Access) Act 2025. National laws may impose additional rules, particularly for health, genetic, electronic-communications, medical-confidentiality, and children’s data. Where this Annex conflicts with another part of the Policy for EEA or UK personal data, this Annex controls to the extent required by applicable law.
D-1. Ressa’s Role, Territorial Scope, and Privacy Contacts
Direct-to-consumer users. When an EEA or UK individual creates and uses a Ressa consumer account, Ressa generally determines the purposes and means of the processing described in this Policy and acts as the controller for that direct-to-consumer processing.
Practitioner relationships. When an EEA or UK practitioner, clinic, laboratory, or other healthcare organization determines the purposes and means for processing a clinical record and uses Ressa to process that record on its behalf, that organization may be the controller and Ressa may act as processor. In that role, Ressa processes personal data on documented instructions, uses the processor terms required by Article 28, applies confidentiality and security safeguards, assists with rights and breach obligations, and uses subprocessors only as permitted by the applicable agreement and law.
Privacy Person. Ressa’s Privacy Person may be contacted at <u>privacy@ressahealth.com</u> (the best and fastest way) Phone: +1-520-724-1376. The Privacy Person coordinates privacy requests and compliance but is not designated by this Policy as a statutory EU or UK Data Protection Officer or as the EU or UK representative.
EU representative - EU Representative (GDPR Article 27) Ressa Health has appointed Engage Data Consulting B.V., trading as Engage Compliance, as its EU Representative under GDPR Article 27. Status: Active, verified 4 September 2026 Contact the representative: <u>https://www.engagecompliance.co/representatives/ressahealth</u> By email: <u>ressahealth@engagecompliance.co</u> By post: Engage Data Consulting B.V., KvK 82538638, Amsterdam, Noord-Holland, Netherlands Verify this appointment: <u>https://www.engagecompliance.co/representatives/verify?id=GOg9ZvDtI1VXn75nFyBNp5GZ</u> Representative service: <u>https://www.engagecompliance.co/eu-representative-service</u>
UK representative - UK Representative (UK GDPR Article 27) Ressa Health has appointed Engage Compliance UK Ltd, trading as Engage Compliance, as its UK Representative under UK GDPR Article 27. Status: Active, verified 4 September 2026 Contact the representative: <u>https://www.engagecompliance.co/representatives/ressahealth</u> By email: <u>ressahealth@engagecompliance.co</u> By post: Engage Compliance UK Ltd, <u>124 City Road, London, EC1V 2NX, United Kingdom</u> Verify this appointment: <u>https://www.engagecompliance.co/representatives/verify?id=1nQ5I2Eg70t69VHuPmDAoEVZ</u> Representative service: <u>https://www.engagecompliance.co/uk-representative-service</u>
D-2. Lawful Bases and Special-Category Health and Genetic Data
The EU GDPR and UK GDPR require a lawful basis under Article 6 for processing personal data. Health information, genetic information, and certain related information are special-category personal data and require an additional condition under Article 9. The table below identifies the principal bases Ressa expects to rely on. The precise basis may differ for a particular feature, jurisdiction, or practitioner relationship, and Ressa will update the notice or obtain consent before using a materially different basis where required.
| Processing purpose | Principal Article 6 basis | Article 9 condition for special-category data | Notes |
|---|---|---|---|
| Create and administer a consumer account; provide the non-health portions of the Service | Article 6(1)(b) - necessary to perform the user contract; Article 6(1)(c) where a legal obligation applies | Not applicable unless special-category data is involved | Account identifiers and billing information are ordinarily processed to provide the requested Service. |
| Operate the Health Vault; store, organize, display, and analyze health and genetic information; generate requested Insights | Article 6(1)(b) - necessary to perform the requested Service | Article 9(2)(a) - explicit consent, unless Ressa identifies another legally available condition for a specific processing activity | Ressa obtains a clear affirmative, explicit consent for direct-to-consumer special-category processing. Withdrawal may prevent continued provision of a health feature if no other condition applies. |
| Practitioner-controlled clinical processing where Ressa acts as processor | The practitioner/controller identifies its Article 6 basis; Ressa processes on documented instructions under Article 28 | The practitioner/controller identifies its Article 9 condition, such as an applicable health-care condition where its legal prerequisites are met | Ressa does not assume that Article 9(2)(h) applies to Ressa’s independent controller activities merely because the information is health-related. |
| Security, fraud prevention, service integrity, and incident investigation | Article 6(1)(f) - Ressa’s legitimate interests in protecting users, accounts, systems, and the Service; Article 6(1)(c) where law requires processing | For special-category information necessarily involved in securing the Health Vault, the condition supporting that health processing continues to apply; another Article 9 condition is used where specifically available | Our legitimate interests are balanced against individual rights and do not override special-category requirements. |
| Service communications, customer support, billing, tax, and accounting | Article 6(1)(b) - contract; Article 6(1)(c) - legal obligation; Article 6(1)(f) for limited support/administrative interests where appropriate | Only where special-category data is included in a support interaction, using the applicable Article 9 condition for that information | Do not include health information in support communications unless necessary. |
| Marketing, optional analytics, advertising measurement, and promotional messages | Article 6(1)(a) - consent where ePrivacy/PECR or GDPR requires it; Article 6(1)(f) only where applicable law permits and the balancing test is satisfied | Health-based marketing requires an additional Article 9 condition, ordinarily explicit consent; Ressa does not otherwise use health data for marketing | Optional tracking is off until consent for EEA/UK visitors under Ressa’s current design. |
| Comply with law, respond to regulators or legal process, and establish, exercise, or defend legal claims | Article 6(1)(c) - legal obligation; Article 6(1)(f) where legitimate interests lawfully apply | Article 9(2)(f) for legal claims where applicable, or another condition specifically authorized by EU, Member State, or UK law | Ressa discloses no more information than legally necessary. |
Consent standards. Where Ressa relies on consent under the EU GDPR or UK GDPR, the consent must be freely given, specific, informed, unambiguous, and demonstrated by a clear affirmative action. Where Article 9 requires explicit consent, we ask for an express statement that identifies the nature of the special-category data and specified purposes. We keep records of consent and provide a method to withdraw it as easily as it was given. We do not bundle optional marketing, advertising, research, or similar uses into consent that is necessary for the core Health Vault.
National health and genetic rules. EU Member States may impose additional conditions or limitations on genetic, biometric, and health data. Ressa will assess applicable national requirements before actively launching in a Member State and will use the stricter national requirement where it applies.
D-3. Information Required by the EU GDPR and UK GDPR
The categories of personal data, sources, purposes, recipients, security measures, retention criteria, and contact information are described in Sections 3 through 13 of this Policy. For EEA and UK individuals, the following additional points apply:
• Ressa is Metabolic Terrain Omics, Inc., d/b/a Ressa Health, 2 East Congress Street, Suite 900, Tucson, AZ 85701, United States, and is the controller for the direct-to-consumer processing described above.
• The lawful bases and special-category conditions are identified in Section D-2.
• Where we rely on legitimate interests, those interests include protecting accounts and systems, preventing fraud and abuse, maintaining and improving the reliability of the Service using non-health operational information, administering business relationships, and establishing or defending legal rights, balanced against your rights and interests.
• Where we obtain personal data from a practitioner, laboratory, connected device, or application rather than directly from you, the sources are described in Sections 3.3 and 4. We provide required Article 14 information within the applicable timeframe unless a lawful exception applies.
• Whether you must provide information depends on the feature. Account identifiers and information objectively necessary to provide a requested feature are contractual requirements; if you do not provide them, we cannot provide that feature. Optional marketing, advertising, testimonial, and similar consents are not required to use the core Service.
• Ressa does not currently use automated processing to make the significant eligibility, access, credit, employment, insurance, housing, education, or healthcare decisions described in Section 17.2.
D-4. International Transfers and Processing in the United States
Ressa is established in the United States, and the Service is hosted and supported through U.S.-based infrastructure as described in Section 9.2. EEA and UK personal data may therefore be processed in the United States. The fact that Ressa is directly subject to the EU GDPR or UK GDPR does not eliminate the separate international-transfer rules where a disclosure or transfer is a restricted transfer under applicable law.
EEA transfer mechanisms. Where Chapter V of the EU GDPR applies to a transfer, Ressa uses an available lawful mechanism. Depending on the recipient and circumstances, this may include a European Commission adequacy decision; the EU-U.S. Data Privacy Framework only where the relevant U.S. recipient is an active participant for the data at issue; European Commission Standard Contractual Clauses; or another mechanism permitted by the EU GDPR. Where Standard Contractual Clauses are used, we assess the transfer and use supplementary contractual, technical, or organizational safeguards where appropriate.
UK transfer mechanisms. For restricted transfers under the UK GDPR, Ressa uses a lawful UK mechanism, which may include UK adequacy regulations, including the UK Extension to the EU-U.S. Data Privacy Framework only where the relevant U.S. recipient is eligible and participating; the UK International Data Transfer Agreement; the UK Addendum to the EU Standard Contractual Clauses; or another mechanism permitted by UK law. We conduct the transfer-risk assessment required by UK law where applicable.
Government access. Information processed in the United States may be subject to lawful demands from U.S. courts, law-enforcement agencies, or national-security authorities. Ressa evaluates requests, challenges or narrows them where appropriate and legally available, discloses no more than legally required, and uses the safeguards described in this Policy.
Copies of safeguards. Where required, you may contact privacy@ressahealth.com to request information about the applicable transfer safeguard or a copy of the relevant contractual protection, subject to lawful redactions for confidential or security-sensitive information.
D-5. Your EEA and UK Data Protection Rights
Subject to the conditions and exceptions in the applicable law, EEA and UK individuals have the following rights:
• Access: obtain confirmation whether we process your personal data and receive a copy together with the information required by law.
• Rectification: correct inaccurate personal data and complete incomplete information.
• Erasure: request deletion where the statutory conditions are met.
• Restriction: request that we limit processing in circumstances specified by law.
• Portability: receive qualifying personal data you provided to us in a structured, commonly used, machine-readable format and, where technically feasible and legally required, transmit it to another controller.
• Object: object, on grounds relating to your situation, to qualifying processing based on legitimate interests or public-task grounds; object at any time to processing for direct marketing.
• Withdraw consent: withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
• Automated decisions: exercise the rights and safeguards applicable to solely automated significant decisions, as described in D-8.
• Complaint: complain to the competent supervisory authority, as described in D-9.
Timing and fees. We respond without undue delay and ordinarily within one month after receipt of a valid request. Where the applicable GDPR permits an extension because of complexity or number of requests, we notify you within the original one-month period and explain the extension. Requests are ordinarily free of charge; we may charge or refuse only where the applicable law permits, such as for manifestly unfounded or excessive requests.
Identity and authorized representatives. We may request information reasonably necessary to confirm identity. An authorized representative may act for you where legally permitted and their authority can be verified. Where Ressa acts only as a processor for a practitioner/controller, the controller is responsible for deciding the request and Ressa assists as required by contract and law.
D-6. Cookies, Similar Technologies, and Direct Marketing
EEA cookies and tracking. For EEA visitors, Ressa applies the EU GDPR together with the law of the relevant Member State implementing the ePrivacy framework. Under our current design, optional analytics, advertising, retargeting, and marketing-measurement technologies on public marketing pages remain off until the visitor affirmatively consents. Strictly necessary technologies used to provide a requested service or secure the Service remain available as permitted by law. Cookie consent can be changed or withdrawn through Cookie Preferences.
UK cookies and tracking. For UK visitors, Ressa applies PECR as amended together with the UK GDPR. Although UK law now permits certain cookies in additional circumstances without consent, Ressa’s current design continues to obtain consent before loading the optional analytics and advertising technologies listed in Section 7.3. If Ressa later relies on a statutory exception, we will update the cookie notice and controls before doing so.
Marketing messages. We send marketing email or text messages to EEA and UK individuals only where the applicable electronic-marketing rules and data-protection law permit. We provide an easy method to unsubscribe or object. We do not use health or genetic information to select marketing without a separate explicit special-category consent and any separate ePrivacy/PECR consent required for the communication channel.
D-7. Security, Data Protection Impact Assessments, and Data Protection by Design
Ressa applies the safeguards described in Section 13 and implements data protection by design and by default for EEA and UK processing. We conduct a Data Protection Impact Assessment before processing that is likely to result in a high risk to individuals, including where required for large-scale special-category processing, qualifying systematic evaluation, new technologies, or other high-risk processing. We review DPIAs when risks or processing materially change. If a DPIA indicates residual high risk that cannot be mitigated, we will consult the competent supervisory authority before beginning the processing where applicable law requires prior consultation.
We maintain records of processing activities to the extent required, document our lawful bases and special-category conditions, conduct processor/subprocessor diligence, restrict access according to role and need, and use appropriate measures to test and evaluate security. These EU/UK accountability obligations supplement rather than replace Ressa’s HIPAA, U.S. state, and Canadian safeguards.
D-8. Automated Processing and Insights
Current Ressa Insights. As Section 17 explains, Ressa uses algorithmic and artificial-intelligence tools to organize Health Vault information, identify patterns and trends, compare values, flag configured ranges, and present educational material. These functions do not currently make decisions about eligibility for or access to healthcare, insurance, employment, credit, housing, education, or another significant benefit and do not substantially replace human judgment in such decisions.
EU GDPR. If Ressa introduces a decision based solely on automated processing that produces legal effects or similarly significant effects for an EEA individual, we will comply with Article 22 and applicable national law. Where a statutory exception allows the decision, we will provide applicable safeguards, including the ability to obtain human intervention, express a point of view, and contest the decision. Solely automated significant decisions using special-category data are subject to the additional restrictions in Article 22(4), including the requirement for explicit consent or an applicable substantial-public-interest basis with safeguards.
UK GDPR after the Data (Use and Access) Act 2025. UK law permits significant solely automated decisions in a broader range of circumstances for non-special-category data, provided an appropriate lawful basis and statutory safeguards are in place. Those safeguards include providing information about the decision and enabling the individual to make representations, obtain human intervention, and contest the decision. The stricter restriction for special-category data remains: Ressa will not use health, genetic, or other special-category data for a significant solely automated decision unless the processing satisfies the special UK statutory conditions and safeguards. Ressa does not currently conduct such significant decisions.
D-9. Complaints and Supervisory Authorities
EEA complaints. You may complain to the data protection supervisory authority in the EEA country connected to your complaint, including the country of your habitual residence, place of work, or the alleged infringement, as provided by the EU GDPR. A list of EEA supervisory authorities is available through the European Data Protection Board. You may contact Ressa first, but doing so does not waive your right to complain to an authority.
EU Representative (GDPR Article 27) Ressa Health has appointed Engage Data Consulting B.V., trading as Engage Compliance, as its EU Representative under GDPR Article 27. Status: Active, verified 4 September 2026 Contact the representative: <u>https://www.engagecompliance.co/representatives/ressahealth</u> By email: <u>ressahealth@engagecompliance.co</u> By post: Engage Data Consulting B.V., KvK 82538638, Amsterdam, Noord-Holland, Netherlands Verify this appointment: <u>https://www.engagecompliance.co/representatives/verify?id=GOg9ZvDtI1VXn75nFyBNp5GZ</u> Representative service: <u>https://www.engagecompliance.co/eu-representative-service</u>
UK complaints. UK individuals may complain to Ressa at privacy@ressahealth.com and may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk. For complaints received on or after 19 June 2026, UK law requires controllers to facilitate a data-protection complaint process. Ressa acknowledges a UK data-protection complaint within 30 days after receipt, takes appropriate steps to investigate and respond without undue delay, keeps the complainant informed of progress as appropriate, and informs the complainant of the outcome without undue delay.
UK Representative (UK GDPR Article 27) Ressa Health has appointed Engage Compliance UK Ltd, trading as Engage Compliance, as its UK Representative under UK GDPR Article 27. Status: Active, verified 4 September 2026 Contact the representative: <u>https://www.engagecompliance.co/representatives/ressahealth</u> By email: <u>ressahealth@engagecompliance.co</u> By post: Engage Compliance UK Ltd, <u>124 City Road, London, EC1V 2NX, United Kingdom</u> Verify this appointment: <u>https://www.engagecompliance.co/representatives/verify?id=1nQ5I2Eg70t69VHuPmDAoEVZ</u> Representative service: <u>https://www.engagecompliance.co/uk-representative-service</u>
D-10. Children and Minors
Ressa’s baseline account rule is that a minor account is held and operated by a parent or legal guardian. If Ressa offers an information-society service directly to a child and relies on the child’s consent as the Article 6 basis, the EU GDPR requires parental authorization below the digital-consent age set by the applicable Member State, which may range from 13 to 16, and reasonable efforts to verify that authorization. In the United Kingdom, the digital-consent age for such an online service is 13. Because the Service processes health and genetic information, Article 9 and national health/privacy requirements may require additional parental authorization or may make another lawful basis more appropriate. Ressa will assess the applicable country and feature before enabling a minor to provide their own consent.
For a UK online service likely to be accessed by children, Ressa will also evaluate and apply the UK Age Appropriate Design Code to the extent it applies, including a child-focused DPIA, high-privacy defaults, data minimization, and age-appropriate transparency.
D-11. Relationship to HIPAA, Canadian Law, and National European Requirements
This Annex is supplemental. It does not amend, waive, or reduce any obligation Ressa has under HIPAA, the HIPAA Privacy, Security, or Breach Notification Rules, a U.S. business associate agreement, the FTC Health Breach Notification Rule, applicable U.S. state law, PIPEDA, Canadian provincial law, or Quebec Law 25 requirements. When Ressa handles U.S. protected health information as a HIPAA business associate, it continues to comply with HIPAA and the applicable business associate agreement. When the EU GDPR or UK GDPR also applies because an EEA or UK individual is offered the Service or monitored within the territorial scope of those laws, Ressa applies the relevant EU/UK requirement in addition to its U.S. and Canadian commitments to the extent the requirements can be satisfied together. EU Member State laws may impose additional requirements for health and genetic data; those national requirements control where applicable.
