PRIVACY POLICY

Last updated: March 2024

This Privacy Policy explains the privacy practices of She Matters Incorporated (“She Matters,” “we,” “us,” or “our”) for users of the She Matters website, application (the “App”) and any other online products and platforms (collectively referred to herein as the “Platform”) and the associated data, services, information, tools, functionality, updates and similar materials (all of the foregoing collectively the “Services”). As used herein, “you” or “your” refers to you, the individual accessing the Services as a user (all users collectively referred to herein as “users”).

By using Services you agree to the use (including disclosure) of Personal Information (including personal health-related information) as described in this Privacy Policy. For users of the App, this Privacy Policy incorporates by reference our Application Terms of Service, and for users of the website, this Privacy Policy incorporates by reference our Website Terms of Service located at [TOS link], as each may be amended from time to time and each of which is made a part of this Privacy Policy if recited here in full.

We may change this Privacy Policy from time to time. If we make changes, we will revise the date at the top of the policy and, in some cases, we may provide you with additional notice.

1. Our Commitment to Privacy

She Matters understands that your privacy is important. Your ability to make informed choices about the uses of your information is important to us. She Matters is committed to protecting your privacy and the information that can identify you (“Personal Information”) that we may collect from you or that you may provide to us when you access and use Services. This Privacy Policy explains our policy regarding the collection, use, disclosure and protection of Personal Information. By accessing and using Services, you agree and consent to the collection, use and disclosure of your Personal Information as outlined in this Privacy Policy. We do not provide medical or other healthcare services and are not licensed to practice medicine.

2. What is Personal Information?

Personal Information is any information relating to a natural person who is, or can be, identified either directly or indirectly from such information and includes information such as a user’s name, address, telephone number, email address, internet activity (such as browsing history), or other information directly linked to that person. Personal Information that we collect may also include the personal health-related information which users choose to provide to us to use some of the Services. You are not legally required to provide Personal Information to us and you decide which Information, if any, you would like to share with us, but some functions of the Platform or the Services may not be available to you without providing us the necessary Information.

3. Information that We Collect

We collect Personal Information about you in a variety of ways. Sometimes we collect Personal Information automatically when you interact with the Services, and sometimes we collect Personal Information directly from you. At times, we may also receive Personal Information about you from other sources and third parties.

In order to access and use certain parts of the Platform and Services, including the App, you may be required to provide Personal Information directly to us. The Personal Information you provide may include:

  • Your registration and contact information (such as, your name, address, telephone number, gender, email address, date of birth, and a username and password to access your account);

  • Personal health, medical and well-being information;

  • Records and copies of your correspondence (including email addresses) if you contact us; and

  • Details of transactions you carry out through our Platform.

In addition to collecting Personal Information that you directly provide to us, we may automatically collect certain Personal Information when you use Services, such as an IP address, information about your browser, device or operating system or similar information. IP addresses are ID numbers for the location of your computer or network on the internet. Log files are recordings of the traffic to and from a server. She Matters servers log IP addresses for systems administration and troubleshooting. We track page hits in the aggregate to track the popularity of pages that people visit. With that information we can improve the quality of our Platform. We may also use or allow third parties to use web beacons on our Platform to monitor the effectiveness of survey qualification. Web beacons are small, graphic images on web pages, web-based documents, or in email messages that allow us or third parties to monitor who is visiting our Platform or if an email has been read. Web beacons collect the IP address of the device where the web beacon is sent, the URL of the page where the web beacon originates, and the time it was viewed. Web beacons may be linked to your Personal Information. We may also use third-party devices, services, links, or electronic mail to deliver surveys to you, which may use cookies, web beacons, or other technology to collect information about your visits to the Platform (or other websites) in order to present surveys that may be of interest to you.

From time to time, we may also use or augment the Personal Information we have about you with information obtained from other sources, such as public databases, social media platforms and other third parties.

4. How We Use Personal Information

We use your Personal Information in our normal course of business to provide Services to you. Specifically, She Matters uses this information in connection with:

  • Providing and maintaining the Services;

  • Maintaining reasonable security;

  • Diagnosing problems with our servers;

  • Developing and improving the Platform and Services, including the development of new products and services;

  • Communicating with you about the Services, including sending you emails, texts, and mobile application updates;

  • Responding to your inquiries about Services;

  • Creating anonymous or aggregated data that no longer can be reasonably used to identify you;

  • Protecting the rights and property of She Matters, including enforcing our agreements and policies, and to resolve disputes; and

  • Compliance with law.

Any Personal Information that you provide through your use of the Platform allows She Matters to help provide Services to you, including, but not limited to, conducting research, assessing your needs, and connecting you with relevant goods and services.

Information you provide to She Matters through your use of the Services is treated as confidential. This information is shared with She Matters employees, She Matters partners, and/or service providers in order to provide Services to you. This information may be combined with information gathered from other users and is reported to She Matters partners in aggregate and de-identified format. At times your Personal Information may be tied to other publicly-available information or other data sources, and used for segmentation or analytical model building.

You acknowledge and agree that we may use, track, store, copy, distribute, broadcast, transmit, publicly display and perform, reproduce, digitally perform, modify, create derivative works of, and otherwise use and commercially exploit any feedback or other information that you provide to us via the Platform or relative to your use of the Services in accordance with this Privacy Policy. If you are deemed to have retained, under applicable law, any right, title, or interest in or to any portion of such information or materials, you agree to and hereby do assign solely and exclusively to us all of your right, title and interest in and to such information or materials, without additional consideration, under applicable patent, copyright, trade secret, trademark and other similar laws or rights, in perpetuity. If such assignment is ineffective under applicable law, you hereby grant us the sole and exclusive, irrevocable, sub-licensable, transferable, worldwide, royalty-free license to reproduce, modify, create derivative works from, publish, distribute, sell, transfer, transmit, publicly display, use, and practice such information or materials, and to incorporate the same in other works in any form, media, or technology now known or later developed.

5. How We Share Personal Information

She Matters will not sell, rent, share or otherwise disclose the Personal Information you provide or we collect through your use of the Services to any unaffiliated organization without your permission, with the following exceptions:

(a) We may connect users with relevant services and products based upon information provided by users. These services and products may be offered by other companies and individuals (“Third Party Services”). We may share Personal Information with providers of Third Party Services for certain purposes such as delivering advertising and content targeted to your interests.

(b) We may use companies and contractors to perform services for us or to provide Services, including digital service providers (such as, email, web services and payment vendors) and professional advisors (such as, accountants, auditors and lawyers). We may also use third-party tools to track and optimize your experience, in which case your Personal Information may be governed by applicable third party privacy policies.

(c) Where you have authorized She Matters to disclose Personal Information to your healthcare provider.

(d) In addition, we reserve the right to disclose Personal Information in the following situations to:

  • Comply with the law or respond to legal process or lawful requests;

  • Protect the rights, property, safety or security of She Matters, our employees, other users, Platform visitors or the public;

  • As part of a corporate transaction such as a merger or sale of assets;

  • Respond to an emergency or when She Matters believes in good faith that access or disclosure is necessary to protect the public; or

  • Enforce any terms of use agreement governing use of Services controlled or operated by us.

We may also use Personal Information to create aggregate or de-identified data that is not personally identifiable. We may use such aggregate or de-identified data for any legally permissible purposes without restriction and may disclose such data to third parties for any legally permissible purposes.

6. External Links

In providing information about Third Party Services, we may provide links to third-party websites, services, and applications that are not operated or controlled by us. While we attempt to facilitate access only to those Third Party Services that share our respect for your privacy, we cannot take responsibility for the content, privacy policies, or practices of those Third Party Services. We encourage you to review and understand the privacy practices of any Third Party Services before providing any information to or through them. Your interactions with these features are governed by the privacy policy of the Third Party Service that provides the feature. Where possible, we will warn you when you are leaving our Platform and connecting to a site operated by a third party.

7. Storage of Data

We will only store Personal Information for as long as it is needed to fulfill the purposes for which it was collected, subject to applicable data retention periods imposed upon us by applicable law. This may mean that your Personal Information is stored by us for a number of years, depending on the purpose and need for that data to be processed. Thereafter, we securely destroy Personal Information when it is no longer required to fulfill the Services, our commitments to you, or to enforce our rights or meet our legal obligations.

In addition, the data we collect may be stored in databases owned by the providers of the Third Party Services. Providers of Third Party Services may use such data for promotion and marketing purposes. Procedures for opting out of marketing communications from these third parties are governed by the privacy policies and terms of use policies of the third parties.

8. Aggregate and De-identified Information

We sometimes aggregate or de-identify information we collect, and the types of systems and browsers of users for internal purposes, so that we may better understand the She Matters Platform user population. Personal Information does not include “aggregate” or “de-identified” information. Aggregate or de-identified information is data we collect about a group of users, from which individual identities have been removed. In other words, information about how you use Services, or the results of such use, may be collected and combined with similar information from others, but no Personal Information will be included in the resulting aggregate or de-identified data. We can extract statistical data from your content in order to provide it to other users or partners without connecting it to any personal data such as name or email address. Aggregate or de-identified data helps us understand trends and user needs so that we can better consider new products and services, and tailor existing products and services to customer desires. You understand that we may commercialize aggregate or de-identified information by any and all means, and that you will receive no payment or other consideration with respect of such use. In addition, we may share and disclose aggregate or de-identified information for any purpose.

9. Consent to Communications

10. Cookies

A cookie is a small piece of information that a website can store on a computer and sometimes later use to recognize a user. The purpose of cookies is to enhance your ability to receive the information you want. In the future, She Matters may use cookies to enhance the experience of users. A “session” cookie expires when the user closes the browser in which the website was viewed. A “persistent” cookie may be used to help save your settings and customizations. As with all cookies, you can personalize you web browser settings to reject session cookies. Though some cookies, that are strictly necessary for site operation, cannot be toggled off.

Some of our business partners with whom we contract to carry out Services (e.g., website providers) may use their cookies on our Platform. Although we may not have direct access to or control over such cookies, this Privacy Policy governs the use of cookies by us and such business partners on our Platform. We may also allow social media companies (e.g., Facebook) to put “widgets” on our websites. These third-party tools may also be used to track you across websites. For example, so long as you are logged in to Facebook, every time you land on a webpage that has a Facebook widget, Facebook will know you are on that webpage. We do not control the privacy practices of these third parties.

Some internet browsers allow you to limit or disable the use of tracking technologies that collect unidentified information, such as a “Do Not Track” (“DNT”) setting. Currently, we do not respond to DNT signals.

11. Children’s Privacy

You must be 18 years of age or older in order to establish an account on and use the Services. She Matters is concerned about the safety and privacy of children online. Because of this, we will make all efforts to comply with the Children’s Online Privacy Protection Act of 1998 (“COPPA”). COPPA and its accompanying FTC regulations establish United States federal law that protects the privacy of children using the internet. Further, Services are neither intended for nor designed to attract users under the age of 18. It is possible that by fraud or deception by others we may receive information given to us or pertaining to minors, including children under 13. If we are notified of this, as soon as we verify the information, we will immediately obtain parental consent or else delete the information from our servers. If you want to notify us of our receipt of information by minors, including children under 13, please email hello@shematters.health.

12. Your Rights

Residents of certain states may have additional rights under applicable data protection laws in relation to their Personal Information. Such rights may include the right to opt-out of or limit certain uses of Personal Information (such as the right to opt-out of the sale, targeted advertising or sharing of a user’s Personal Information) and to exercise control over certain uses and disclosures of Personal Information (such as, the right to access, update, correct and/or delete a user’s Personal Information. If these additional rights

apply to you, you can exercise these rights by emailing us at hello@shematters.health. We will respond to your request consistent with applicable law.

Please note that, in all cases, we may need to retain Personal Information for a longer period where we are subject to legal or regulatory requirements to do so.

13. Security

She Matters has put into place commercially reasonable security measures in an effort to protect Personal Information from loss, misuse, or alteration while it is under our control. We use standard technical, contractual, administrative, and physical measures in an effort to protect against unauthorized access. Only select She Matters staff have access to personally identifiable information provided by visitors to non-public areas of our physical offices. Please note, however, that security incidents can occur even if reasonable steps are taken to prevent such incidents; for example, we cannot guarantee that information provided through our sites will not be illegally accessed on our servers or intercepted while being transmitted to us over the internet. Additionally, we have absolutely no control over the security or

other third-party sites you might visit, interact with, or do business with.

14. Breach of Personal Information

If your Personal Information is altered, destroyed, acquired, accessed, used, or disclosed in a manner not outlined by this Privacy Policy that compromises the privacy or security of the Personal Information, you agree to receive any required notifications of this breach from She Matters or its delegate via electronic mail in lieu of first-class mail. The notification may be provided in one or more electronic mailings as information becomes available. If you do not agree to receive breach information via electronic mail, you

must contact She Matters at hello@shematters.health and withdraw your consent. You also permit She Matters, to the extent your phone number is available and current, to call you and notify or update you about the breach of your Personal Information prior to and after sending electronic mail notification. To the extent required by applicable law, She Matters may report the breach of information to governmental authorities or other third parties.

15. Service and Privacy Policy Updates

We plan to regularly update and add new features to our Platform and Services. Because of this, She Matters reserves the right to revise its Privacy Policy at any time. Such amendments will be posted in the Privacy Policy section of the Platform. You can determine whether the Privacy Policy has been modified since you last visited the Platform or used Services by checking the “Last updated” legend at the top of the Privacy Policy. As stated above, the spirit of this Privacy Policy will be maintained, and our policy to never sell, exchange, rent, trade, or give your Personal Information to unauthorized third parties will not be altered.

16. Contact Us

If you have any questions about this Privacy Policy, or our collection and use of information, or you think we may have incorrect Personal Information, or would like a copy of the Personal Information we hold on you, or concerns about how we have handled your Personal Information, please write to hello@shematters.health.