PRIVACY POLICY

1. Introduction

Lucerum, Inc. is committed to protecting personal data processed through our websites, applications, and cloud-based platforms, including LucerumCarto, LucerumKey, and any related products, services, and support channels (collectively, the “Platform”). This Privacy Policy explains how Lucerum collects, uses, discloses, transfers, retains, and protects personal data in connection with the Platform and related business operations.

2. Scope

This Privacy Policy applies to:

• website visitors;

• customer administrators, account owners, billing contacts, and procurement contacts;

• authorized users of the Platform;

• support, training, onboarding, and communications with Lucerum; and

• personal data processed by Lucerum on behalf of enterprise customers through the Platform.

This Privacy Policy does not replace any privacy notice, consent form, patient notice, research notice, or other disclosure that a customer is required to provide to its own patients, participants, users, employees, or other individuals.

3. Roles and responsibilities

Lucerum may act in different privacy roles depending on the context.

A. Lucerum as controller

Lucerum acts as a controller, or the equivalent role under applicable law, for personal data that Lucerum collects and uses for its own business purposes, such as:

• website operation;

• account administration;

• contract management;

• billing and payment administration;

• security, fraud prevention, and abuse detection;

• customer support and service communications;

• legal compliance; and

• internal business operations.

B. Lucerum as processor / service Provider

Where Lucerum processes personal data through the Platform on behalf of an enterprise customer, Lucerum acts as a processor, service provider, or equivalent role under applicable law, and the customer remains responsible for determining the purposes of processing, the categories of data uploaded, the legal basis for processing, and the lawfulness of disclosures to Lucerum.

C. Customer-controlled data

Customer-controlled data may include EEG, qEEG, ECG, EMG, biosignal, behavioral, sleep, cognitive, neuroimaging, metadata, log, research, clinical, or similar data that an enterprise customer uploads, imports, stores, or analyzes through the Platform. For such data, the relevant enterprise customer is responsible for providing notices, obtaining consents or other permissions where required, responding to individual requests where required by law, and ensuring that the customer has the right to disclose the data to Lucerum for processing.

4. Categories of personal data

Lucerum may collect and process the following categories of personal data:

A. Account and business information

• name;

• title or role;

• employer or organization;

• business email address;

• business phone number;

• billing details;

• contract and account records;

• authentication and access credentials.

B. Customer-controlled platform data

• EEG, qEEG, ECG, EMG, and other physiological or multimodal signals;

• behavioral, sleep, cognitive, performance, and related data;

• neuroimaging outputs;

• metadata;

• logs, traces, and test artifacts;

• clinical or research-related information;

• Personal health information only where the customer is permitted to provide such data.

C. Technical, device, and usage data

• IP address;

• browser and device metadata;

• operating system;

• application logs;

• session and authentication data;

• audit logs and security event records;

• performance, diagnostic, and telemetry data.

D. Support and communications data

• support tickets;

• onboarding records;

• customer correspondence;

• feedback;

• training participation records;

• communication preferences.

5. How Lucerum uses personal data

Lucerum uses personal data only for legitimate business and service-related purposes, including to:

• provide, host, operate, maintain, secure, and support the Platform;

• authenticate users and administer customer accounts;

• perform analytics, processing, visualization, storage, and related customer-requested functions;

• provide onboarding, implementation, and customer support;

• monitor performance, availability, integrity, and security of the Platform;

• investigate misuse, fraud, unauthorized access, and security incidents;

• comply with legal, regulatory, contractual, and compliance obligations; and

• improve the reliability, functionality, and security of the Platform.

Lucerum may also use data that has been aggregated and/or de-identified so that it no longer identifies an individual, to improve products, algorithms, workflows, system performance, accuracy, security, and service quality, to the extent permitted by applicable law and the parties’ agreements.

6. Legal bases where applicable

Where applicable law requires a legal basis for processing, Lucerum relies on one or more of the following:

• performance of a contract;

• compliance with legal obligations;

• legitimate interests, including security, fraud prevention, platform administration, service improvement, and internal operations;

• consent, where required by law; and

• instructions from the enterprise customer, where Lucerum processes customer-controlled data on the customer’s behalf.

7. Disclosure of personal data

Lucerum may disclose personal data only as reasonably necessary for the purposes described in this Privacy Policy. Recipients may include:

• affiliates and service providers supporting hosting, infrastructure, security, communications, analytics, support, and administration;

• subprocessors or equivalent service providers engaged to help provide the Platform;

• professional advisers, auditors, insurers, and financing or transaction counterparties;

• regulators, courts, law enforcement, or public authorities, where required by law or legal process; and

• an acquirer, investor, successor, or transaction counterparty in connection with a merger, acquisition, financing, reorganization, or sale of assets.

Where Lucerum engages service providers or subprocessors that process personal data, Lucerum requires them to maintain appropriate confidentiality, security, and data protection obligations appropriate to the services they provide.

8. International transfers

Lucerum may process personal data in the United States and in other countries where Lucerum or its service providers operate. Those countries may have different data protection rules than the country in which the data originated. By using the Platform, the customer acknowledges that such transfers may occur and confirms that it has obtained any permissions or approvals required under its own local law before uploading the data.

9. Data retention

Lucerum retains personal data for as long as reasonably necessary and legally applicable for the purposes described in this Privacy Policy, including to provide services, maintain security, comply with legal obligations, resolve disputes, and enforce agreements.

In general:

• account and business records are retained for the duration of the customer relationship and a reasonable period thereafter;

• customer-controlled data is retained for the period specified by the customer, the applicable contract, product configuration, or applicable law;

• logs, security records, and audit trails may be retained for security, integrity, forensic, compliance, and service-improvement purposes;

• support records and communications may be retained for continuity, training, quality assurance, and legal purposes.

10. Security

Lucerum maintains reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, and destruction. These safeguards may include:

• encryption in transit and at rest where appropriate;

• role-based and least-privilege access controls;

• authentication and access management measures;

• logging, monitoring, and audit trails;

• vulnerability management and secure development practices;

• incident response procedures; and

• workforce confidentiality and security training;

• SOC2-aligned security policies

No security measure is absolute, and Lucerum cannot guarantee complete security. Customers are also responsible for maintaining the security of their own credentials, endpoints, networks, users, permissions, and internal workflows.

11. Individual rights and requests

Where Lucerum processes personal data on behalf of an enterprise customer, requests relating to customer-controlled data should be directed to the relevant enterprise customer, which is the party responsible for determining how that data is processed and for responding to such requests. Lucerum may assist enterprise customers in handling such requests where required by law or contract.

Privacy requests relating to data controlled directly by Lucerum may be sent to: Contact us.

12. Sensitive data and health data

Lucerum recognizes that some customer-controlled data may include sensitive, clinical, or health-related information. Where such data is uploaded, the customer is solely responsible for ensuring that its collection, use, and disclosure are lawful in the relevant jurisdiction.

Unless expressly agreed otherwise in writing:

• customers remain responsible for determining whether health, clinical, patient, research, or other sensitive data may lawfully be uploaded to the Platform; and

• customers are responsible for obtaining any necessary notices, consents, authorizations, ethics approvals, or other legal permissions for their collection and use of such data.

13. Children

The Platform is not intended for children under 18.

14. Changes to this Privacy Policy

Lucerum may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, security practices, or product functionality. Where required by law, Lucerum will provide notice of material changes through the Platform, by email, or by other appropriate means.

Questions, claims, and support requests relating to Lucerum products and website should be directed to:

Lucerum, Inc;

Contact us.