.

BACKGROUND

This Privacy Policy for Conformix ("we," "us," or "our") located at Baarerstrasse 25, 6300 Zug, Switzerland (“registered address”), describes how and why we might access, collect, store, use, and/or share (" the process") the website or the application visitor (“User”, “User”) provides personal information when User use our services ("Services"), including when User:

  • Visit our website at conformics.com, or any website of oursthat links to this Privacy Policy available at privacy policy.
  • Please be informed that our Website is a SaaS-based application which allows easy user data integration and user experience.
  • The Users are advised to go through this Privacy Policy with utmost patience and understand the privacy rights and choices in their entirety. We are only responsible for making decisions about how User personal information is processed after it has been voluntarily shared with us.
  • It is strictly informed that in case the Users do not agree with our policies and practices, they may please avoid using our Services.
  • It is emphasized and highlighted that Conformix is a General Data Protection Regulation (GDPR) compliant entity along with the Swedish Data Protection Act, any applicable local laws based on the location of the data server and its strict compliance for storing and utilization of any stored data.
  • The User is expected to exhibit general awareness about data sensitivity and adopting high-security measures when sharing personal data in the public domain.

SUMMARY OF KEY POINTS

When the User visit, use, or navigate our Services, we may process personal information depending on the User’s interaction with Website and Mobile Application and the Services, including the products related services, products catalogue and features utilized by the Visitor or the User. Learn more about personal information User disclose to us.

We specifically declare and state that certain user driven data stored or collected maybe utilized and specified as "special" or "sensitive" in certain jurisdictions including Switzerland under the treaties applicable under EU laws including the Swedish Data Protection Act, Data Regulations under General Data Protection Regulation and other International Conventions, due to the fundamental concerns, lawful requirements and under order of the lawful authorities.

It is declared that the User or Users impart their voluntary consent to process their supplied data to be collected, based on categories of certain selected preferences such as gender, nationality and religious beliefs or any other preference as permitted under the applicable law.

We specifically declare and state that any data maybe shared or collected from the User maybe be shared with third parties strictly on the grounds of fraud prevention, compliance under law and orders from legal authorities.

We may also collect information including User data from public databases, marketing partners, social media platforms, and other outside sources for various processes including data dissemination for the limited purpose of fraud prevention, compliance under local jurisdiction law and legal authorities.

We specifically declare and state that we reserve our rights to share User based information in specific situations and with specific third parties in strict conformance with the applicable laws. However, we declare and inform that no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure and therefore despite our best practices and safeguards, we cannot always promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify User information.

The Website and the Application ensure strict compliance under the applicable privacy laws including EU laws including the Swedish Data Protection Act, Data Regulations under General Data Protection Regulation and other International Conventions and the applicable local regulations.

SERVICES

The solutions provided by Confomrix include but are not limited to Intrims, Chemsortia and Regulatory Intelligence & Alerts. These solutions are designed to support users with comprehensive data management, regulatory compliance, and communication capabilities.

PERSONAL INFORMATION

We state and declare that we collect personal information voluntarily provided by the User to us when registering on the Services, expresses an interest in obtaining information about us or Our advertised products and Services,

when User participate in activities on the Services, or otherwise when User contact us. Personal Information Provided by User. The personal information that we collect depends on the context of User interactions with us and the Services, the choices User make, and the products and features User use.

The personal information we collect may include the following: names, phone numbers, email addresses, mailing addresses, job titles, usernames, passwords, billing addresses, contact or authentication data, contact preferences, debit/credit card numbers.

SENSITIVE INFORMATION

When necessary, with User consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:

  • financial data
  • biometric dat
  • health data
  • payment data

We may collect data necessary to process User payment if User choose to make purchases, such as User payment instrument number, and the security code associated with User payment instrument.

All payment data is handled and stored by our trusted payment service provider, in compliance with strict security measures and relevant data protection laws, including the EU Conventions, General Data Protection Regulation, and Swedish Data Protection Act.

MOBILE DEVICE OR SMARTPHONE DEVICE ACCESS.

The Website and Application may request access or permission from User to access certain features from their mobile device, including the mobile device's camera, calendar, bluetooth, contacts, sms messages, social media accounts, reminders, and other features. If the User wishes to change our access or permissions, he may do so in User device's settings by allowing such access to the Website and the application.

MOBILE DEVICE DATA

The Website and Application may automatically collect device information (such as User mobile device ID, model, and manufacturer), operating system, version information and system configuration information, device and application identification numbers, browser type and version, hardware model, Internet service provider and/or mobile carrier, and Internet Protocol (IP) address (or proxy server).

If User are using our application(s), we may also collect information about the phone network associated with User mobile device, User mobile device’s operating system or platform, the type of mobile device User use, User mobile device’s unique device ID, and information about the features of our application(s) User accessed.

Push Notifications: We may request to send User push notifications regarding User account or certain features of the application(s). If User wish to opt out from receiving these types of communications, User may turn them off in User device's settings. This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and for our internal analytics and reporting purposes.

All personal information that the User may provide to us is assumed to be true, complete, and accurate.

Some information such as User Internet Protocol (IP) address and/or browser and device characteristics is collected automatically when User visit our Services.

We automatically collect certain information when User visit, use, or navigate the Services such as User IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when User use our Services, and other technical information to ensure the security and operation of our Services.

We also collect information through cookies and similar technologies. The information we collect includes:

  • Log and Usage Data: Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when User access or use our Services and which we record in log files including the User’s IP address, device information, browser type, and settings and information about User activity in the Services (such as the date/time stamps associated with User usage, pages and files viewed, searches, and other actions User take such as which features User use), device event information (such as system activity, error reports (sometimes called "crash dumps"), and hardware settings).
  • Device Data: We collect device data such as information about User computer, phone, tablet, or other device User use to access the Services. Depending on the device used, this device data may include information such as User IP address (or proxy server), device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information
  • Location Data: We collect location data such as information about User device's location, which can be either precise or imprecise. How much information we collect depends on the type and settings of the device User use to access the Services. For example, we may use GPS and other technologies to collect geolocation data that tells us User current location (based on User IP address). The User can opt out of allowing us to collect this information either by refusing access to the information or by disabling User Location setting on User device. However, if User choose to opt out, User may not be able to use certain aspects of the Services. Google API Our use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

We may collect certain data from public databases, marketing partners, social media platforms, and other outside sources. In order to enhance our ability to provide relevant marketing, offers, and services to User and update our records, we may obtain information about User from other sources, such as public databases, joint marketing partners, affiliate programs, data providers, social media platforms, and from other third parties. This information includes mailing addresses, job titles, email addresses, phone numbers, intent data (or user behavior data), Internet Protocol (IP) addresses, social media profiles, social media URLs, and custom profiles, for purposes of targeted advertising and event promotion. If User interact with us on a social media platform using User social media account (e.g., Facebook Handle or X Login), we receive personal information about User from such platforms such as User name, email address, and gender. User may have the right to withdraw User consent to processing User personal information. Any personal information that we collect from User social media account solely depends on User social media account's privacy settings.

We process User information to provide, improve, and administer our Services, communicate with User, for security and fraud prevention, and to comply with law. We may also process User information for other purposes only with User authorized consent. We process User personal information for a variety of reasons, depending on how User interact with our Services, including:

  • To facilitate account creation and authentication and otherwise manage user accounts. We may process User information so User can create and log in to User account, as well as keep User account in working order.
  • To deliver and facilitate delivery of services to the user. We may process User information to provide User with the requested service.
  • To respond to user inquiries/offer support to users. We may process User information to respond to User inquiries and solve any potential issues User might have with the requested service.
  • To send administrative information to User. We may process User information to send User details about our products and services, changes to our terms and policies, and other similar information.
  • To fulfill and manage User orders. We may process User information to fulfill and manage User orders, payments, returns, and exchanges made through the Services.
  • To enable user-to-user communications. We may process User information if User choose to use any of our offerings that allow for communication with another user.
  • To request feedback. We may process User information when necessary to request feedback and to contact User about User use of our Services.
  • To send User marketing and promotional communications. We may process the personal information User send to us for our marketing purposes, if this is in accordance with User selected marketing preferences.
  • To deliver targeted advertising to User. We may process User information to develop and display personalized content and advertising tailored to User interests, location, and more.
  • To identify usage trends. We may process information about how User use our Services to better understand how they are being used so we can improve them.
  • To determine the effectiveness of our marketing and promotional campaigns. We may process User information to better understand how to provide marketing and promotional campaigns that are most relevant to User.
  • To save or protect an individual's vital interest. We may process User information when necessary to save or protect an individual’s vital interest, such as to prevent harm.

LEGAL BACKGROUND

We only process User personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with User consent, to comply with laws, to provide User with services to enter into or fulfill our contractual obligations, to protect User rights, or to fulfill our legitimate business interests.

Any data store or collected over the servers is treated as confidential data and cannot be shared unless under the applicable norms of EU conventions, General Data Protection Regulation and Swedish Data Protection Act.

If User are located in the Switzerland, United Kingdom, European Union, this section applies to User. The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process User personal information. Therefore, we rely on the following legal bases to process User personal information and any shared personal confidential data:

  • Consent: We may process User information if User have given us permission (i.e., consent) to use User personal information for a specific purpose. User can withdraw User consent at any time.
  • Performance of a Contract: We may process User personal information when we believe it is necessary to fulfill our contractual obligations to User, including providing our Services or at User request prior to entering into a contract with User.
  • Legitimate Interests: We may process User information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh User interests and fundamental rights and freedoms. For example, we may process User personal information for some of the purposes described in order to:
    • Send users information about special offers and discounts on our products and services
    • biometric dat
    • Develop and display personalized and relevant advertising content for our users
    • Analyze how our Services are used so we can improve them to engage and retain users
    • Support our marketing activities
    • Understand how our users use our products and services so we can improve user experience
  • Legal Obligations: We may process User information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose User information as evidence in litigation in which we are involved.
  • Vital Interests: We may process User information where we believe it is necessary to protect User vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.

SHARING OF USER PERSONAL INFORMATION?

We may share information in specific situations described in this section and/or with the following third parties. Vendors, Consultants, and Other Third-Party Service Providers. We may share User data with third-party vendors, service providers, contractors, or agents ("THIRD PARTIES") who perform services for us or on our behalf and require access to such privileged personal information to execute their work. However, please note such transfer or delivery of such confidential data will always be governed and protected under GDPR regulations and EU conventions. .

We legally enforceable contracts in place with our third parties, which are designed to help safeguard User personal information ensuring that any personal information is not shared with any organization.

We commit to protect the collected and stored data and to retain it for a specific period. It is stated that the third parties we may share personal information with are as follows :

  • Allow Users to Connect to Their Third-Party Accounts: Amazon account, Facebook account, PayPal account, and Youtube account.
  • Cloud Computing Services: Google Cloud Platform and Amazon Web Services (AWS).
  • Data Backup and Security: Google Drive Backup.
  • Functionality and Infrastructure Optimization: Amazon Web Services.
  • Invoice and Billing: Amazon Payments.
  • User Account Registration and Authentication: Windows Live Connect.
  • Web and Mobile Analytics: Alexa.
  • Website Hosting: Blogger.
  • Website Performance Monitoring: Datadog.
  • We may share or transfer User information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • When we use Google Maps Platform APIs, we may share User information with certain Google Maps Platform APIs (e.g., Google Maps API, Places API).

COOKIE NOTICE

We may use cookies and other tracking technologies to collect and store User information as permitted under the applicable EU conventions and applicable local laws and international regulations. We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when User interact with our Services. Some online tracking technologies help us maintain the security of our Services and User account, prevent crashes, fix bugs, save User preferences, and assist with basic site functions. We also permit third parties and service providers to use online tracking technologies on our Services for analytics and advertising, including to help manage and display advertisements, to tailor advertisements to User interests, or to send abandoned shopping cart reminders (depending on User communication preferences). The third parties and service providers use their technology to provide advertising about products and services tailored to User interests which may appear either on our Services or on other websites.

AFFILIATES

We may share User information with our affiliates under legal authority or under the applicable EU Conventions and Regulations, in which case we will require those affiliates to honor this Privacy Notice and such includes any Affiliates including our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.

BUSINESS PARTNERS

We may share certain User information with our business partners to offer User specific certain products, services, or promotions under the applicable norms. Our application(s) may display a third-party hosted "offer wall".

Such an offer wall allows third-party advertisers to offer virtual currency, gifts, or other items to users in return for the acceptance and completion of an advertisement offer. Such an offer wall may appear in our application(s) and be displayed to User based on certain data, such as User geographic area or demographic information.

When User click on an offer wall, User will be brought to an external website belonging to other persons and will leave our application(s). A unique identifier, such as User ID, will be shared with the offer wall provider in order to prevent fraud and properly credit User account with the relevant reward.

1

DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

To the extent these online tracking technologies are deemed to be a "sale"/"sharing" (which includes targeted advertising, as defined under the applicable laws) as under applicable US state laws, EU conventions, and any applicable local laws based on the location of the data server. User can opt out of these online tracking technologies by submitting a request to the authorities under the contact information.

2

SOCIAL LOGINS?

If User choose to register or log in to our Services using a social media account, we may have access to certain information about User. Our Services offer User the ability to register and log in using User third-party social media account details (like User Facebook or X logins). Where User choose to do this, we will receive certain profile information about User from User social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include User name, email address, friends list, and profile picture, as well as other information User choose to make public on such a social media platform.

We will use the information we receive only for the purposes that are described in this Privacy Notice or that are otherwise made clear to User on the relevant Services. Please note that we do not control, and are not responsible for, other uses of User personal information by User third-party social media provider. We recommend that User review their privacy notice to understand how they collect, use, and share User personal information, and how User can set User privacy preferences on their sites and application.

3

CAN USER INFORMATION BE TRANSFERRED INTERNATIONALLY?

We may transfer, store, and process User information in countries other than User own. Our servers are located in. If User are accessing our Services from outside, please be aware that User information may be transferred to, stored by, and processed by us in our facilities and in the facilities of the third parties with whom we may share User personal information in and other countries. If User are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in User country and may require specific area wise implementation. However, we will take all necessary steps to protect User personal information in accordance with this Privacy Notice and jurisdiction specific applicable law.

4

HOW LONG DO WE RETAIN USER INFORMATION?

We keep User information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law. We will only keep User personal information for as long as it is necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).

No purpose in this notice will require us keeping User personal information for longer than nine (9) months past the start of the idle period of the user's account.

When we have no ongoing legitimate business need to process User personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because User personal information has been stored in backup archives), then we will securely store User personal information and isolate it from any further processing until deletion is possible.

5

HOW DO WE KEEP USER INFORMATION SAFE?

We aim to protect User personal information through a system of organizational and technical security measures. We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure User information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify User information. Although we will do our best to protect User personal information, transmission of personal information to and from our Services is at User own risk. It is strictly advised that User should only access the Services within a secure environment.

6

DO WE COLLECT INFORMATION FROM MINORS?

We do not knowingly collect data from or market to children under 18 years of age. We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information.

By using the Services, User represent that User are at least 18 or that User are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records.

If User become aware of any data we may have collected from children under age 18, please contact us at [email protected].

7

WHAT ARE USER PRIVACY RIGHTS?

Depending on User’s state of residence in the US or in some regions, such as Switzerland, User may have rights that allow User greater access to and control over User personal information. User may review, change, or terminate User account at any time, depending on User country, province, or state of residence. In some regions (like Switzerland or under EU Convention), User have certain rights under applicable data protection laws. These may include the right

  • Allow Users to Connect to Their Third-Party Accounts: Amazon account, Facebook account, PayPal account, and Youtube account.
  • to request access and obtain a copy of User’s personal information,
  • to request rectification or erasure;
  • to restrict the processing of User personal information;
  • if applicable, to data portability; and
  • not to be subject to automated decision-making. In certain circumstances, User may also have the right to object to the processing of User personal information. User can make such a request by contacting us by using the contact details provided in the section

8

HOW CAN USER CONTACT US ABOUT THIS NOTICE?

We will consider and act upon any request in accordance with applicable data protection laws. In case a User is located in the EEA or UK and believes that we are unlawfully processing his personal information, he has the right to complain to User Member State data protection authority or UK data protection authority. If User are located in Switzerland, User may contact the Federal Data Protection and Information Commissioner.

Withdrawing User consent: If we are relying on User consent to process User personal information, which may be express and/or implied consent depending on the applicable law, User have the right to withdraw User consent at any time. User can withdraw their consent at any time by contacting us by using the contact details provided in the section

9

CONTACT US ABOUT THIS NOTICE?

Opting out of marketing and promotional communications: User can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, replying "STOP" or "UNSUBSCRIBE" to the SMS messages that we send, or by contacting us using the contact details.

User will then be removed from the marketing lists after receiving such request. However, we may still communicate with User to send User service-related messages that are necessary for the administration and use of User account, to respond to service requests, or for other non-marketing purposes. Account Information If User would at any time like to review or change the information in User account or terminate User account, User can:

  • Log in to User account settings and update User account. Upon User request to terminate User account, we will deactivate or delete User account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements. Cookies and similar technologies: Most Web browsers are set to accept cookies by default. If User prefer, User can usually choose to set User browser to remove cookies and to reject cookies. If User choose to remove cookies or reject cookies, this could affect certain features or services of our Services.

10

WHEN AND WITH WHOM DO WE MAY SHARE USER PERSONAL INFORMATION?

We may sell or share the following categories of personal information to third parties in the preceding () months: The categories of third parties to whom we sold personal information are: The categories of third parties to whom we shared personal information with are:

  • Advertising, Direct Marketing, and Lead Generation 
  • Social Media Sharing and Advertising
  • Web and Mobile Analytics Alexa User Rights User have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline User request as permitted by law.

These rights include:

  • Right to know whether or not we are processing User personal data
  • Right to access User personal data
  • Right to correct inaccuracies in User personal data
  • Right to request the deletion of User personal data
  • Right to obtain a copy of the personal data User previously shared with us
  • Right to non-discrimination for exercising User rights
  • Right to opt out of the processing of User personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling") How to Exercise User Rights To exercise these rights, User can contact us by submitting a data subject access request, by emailing us at [email protected],
  • Under certain US state data protection laws, User can designate an authorized agent to make a request on User behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on User’s behalf in accordance with applicable laws. Request Verification Upon receiving User request, we will need to verify User’s identity to determine if the User is the same person about whom we have the information in our system. We will only use personal information provided in User request to verify User identity or authority to make the request. However, if we cannot verify User identity from the information already maintained by us, we may request that User provide additional information for verification

11

DO WE MAKE UPDATES TO THIS NOTICE?

Yes, we will update this notice as necessary to stay compliant with relevant laws and applicable International Conventions and Guidelines. We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Revised" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we will notify User in communication through email and by prominently posting a notice of such changes or by directly sending User a notification.

We encourage User to review this Privacy Notice frequently to be informed of how we are protecting User information.

12

HOW CAN USER CONTACT US ABOUT THIS POLICY?

If User have questions or comments about this notice, User may contact us by email at [email protected]

Based on the applicable local laws of User country or state of residence in the US, User may have the right to request access to the personal information we collect from User, details about how we have processed it, correct inaccuracies, or delete User’s personal information. User may also have the right to withdraw User consent to our processing of User supplied personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete User personal information, please fill out and submit a request seeking data subject access request.

DISCLAIMER

This Privacy Policy for Conformix ("we," "us," or "our") located at Baarerstrasse 25, 6300 Zug, Switzerland (“registered address”), describes how and why we might access, collect, store, use, and/or share (" the process") the website or the application visitor (“User”, “User”) provides personal information when User use our services ("Services"), including when User: The abovementioned information provided by Conformixs ("we," "us," or "our") on conformics.com (the "site") and our mobile application is for general informational purposes only and User awareness.

All information on the site and our mobile application on data maintenance and security is provided in good faith and for increasing the awareness of the User of Website and application.

It is made clear that under no circumstance, shall the parent entity or its affiliates entity will bear or have any liability to User for any loss or theft of any kind of personal data shared, incurred as a result of the use of the site or our mobile application or reliance on any information voluntarily provided on the site and our mobile application including the usage of the site and our mobile application.