Tholos Privacy Policy

Last revised: April 4, 2023

INTRODUCTION

At Tholos Inc. we are committed to protecting your privacy. This Privacy Policy covers how Tholos collects, receives, uses, retains, and discloses Personal Information on Tholos's website and/or platform.

Tholos Inc. (" Tholos", " us", " we", or " our") operates the Tholos mobile applications (the " App"), the website https://www.tholos.app (the " Site"), any other website, web application or mobile application that we own or control and which posts or links to this Privacy Policy now existing or implemented in the future (the " Services"). This Privacy Policy covers all Personal Information collected by Tholos through the Services.

Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, do not download the App, register with, or use any part of the Site or the Services. By submitting information through the App, the Site or in connection with the Services, you agree to the terms of this Privacy Policy and you expressly consent to the processing of your Personal Information in accordance with this Privacy Policy.   We will review this policy regularly, and we may update it from time to time. This Privacy Policy is incorporated into and subject to our Terms of Use.

This Privacy Policy also explains how we process 'personal data' about people in the European Economic Area (" EEA"), United Kingdom (" UK") or Switzerland, as required under the General Data Protection Regulation (" GDPR"). For people in California, we have also prepared a Supplemental Privacy Statement for California Consumers under CCPA (" California Statement") in compliance with the California Consumer Privacy Act of 2018 (" CCPA"). Please review our California Statement attached below for more information.

1. When We Collect Personal Information. When you download the App or visit the Site, you are free to view the Site and the App without providing any Personal Information. In order to register to use the App or the Site, you will be required to provide certain Personal Information about yourself. Each time you visit the App and login, we request that you provide Personal information about yourself, and we may collect Navigational Information on our Site and App.

2. Definitions.

2.1 Data or Personal Information - Personal Information means Individually Identifiable Information about a Data Subject.

2.2 Usage Data - Usage Data is data collected automatically either generated by the use of the App or the Site or from the App's or the Site's infrastructure itself (for example, the duration of a page visit).

2.3 Cookies - Cookies are small pieces of data stored on your device (computer or mobile device).

2.4 Data Controller - Data Controller means the person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information are, or are to be, processed.

For the purpose of this Privacy Policy, we are the Data Controller of your Personal Information. You can contact us at Tholos Inc., 2248 Broadway #1617 New York, NY 10024 or via email at legal@tholos.app.

2.5** Data Processors** (or Service Providers) - Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller.

We may use the services of various Service Providers in order to process your Data and/or Personal Information more effectively.

2.6 Data Subject - Data Subject is any identified or identifiable individual who is using the App or the Site and is the provider of Personal Information.

3. Information Collection and Use. We collect several different types of information for various purposes to provide and improve our service to you.

4. Types of Data Collected.

4.1 Personal Information. The specific types of Personal Information we collect will depend upon the Services you use, how you use them, and the information you choose to provide. The types of Data we collect directly from you includes, without limitation:

  • Username and email address
  • Log-in credentials, if you create an account
  • Information about your session interactions with us
  • Feedback or correspondence you send to us
  • Any other information you choose to directly provide to us in connection with your use of the Services.

We may invite comments, questions, or feedback on certain public areas of the Site. If you provide information in those public areas of the Site, and such information may read, collected, and used by us and other users of the Site. If you provide information directly to us in other ways, such as by sending us an email, we may retain that information and add it with the other information we have collected from you.

We may use your Personal Information to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send.

4.2 Usage Data

We may also collect information how the App and the Site are accessed and used. This Usage Data may include information such as your computer's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of the App or the Site that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

4.3 Tracking Cookies Data. We use cookies and similar tracking technologies to track the activity on the App and the Site and hold certain information.

Cookies are files with small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a Site and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze the App and the Site.

We may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer until you delete them). You can set your browser to not accept cookies, but that may prevent us from providing you with the full range of Services we offer. Also, please be aware that if you visit other sites you may be required to accept cookies. The use of cookies by third parties is not covered by our Privacy Policy.

4.4 Web Beacons. Web beacons are electronic images that may be used on our Site or in our emails. We use web beacons to deliver cookies, count visits, understand usage and campaign effectiveness and to tell if an email has been opened and acted upon.

4.5 Clear Gifs. We may also use clear gifs or other data files or identifiers to collect information for statistical purposes and to improve and develop the Services. Clear gifs are tiny graphics with a unique identifier, similar in function to cookies. In contrast to cookies, which are placed on a hard drive, clear gifs are embedded invisibly on web pages.

4.6** Mobile Application Software Development Kits (SDKs)**. We may use third-party software development kits ("SDKs") in our mobile applications. An SDK is third-party computer code that may be used for a variety of purposes, including to provide us with analytics regarding the use of the App, to integrate with social media, add features or functionality to our Sites or Apps, or to facilitate online advertising. SDKs may enable third parties to collect information directly via the App or the Site.

4.7 Google Analytics. Google Analytics is a web analytics service offered by Google that tracks and reports application and website traffic. Google uses the data collected to track and monitor the use of the App and the Site. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.

You can opt-out of having made your activity on the Services available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sharing information with Google Analytics about visits activity.

For more information on the privacy practices of Google, please visit the Google Privacy Terms web page here.

4.9 Do Not Track. We also may use these technologies to collect information about your online activities over time and across third-party sites or other online services (behavioral tracking). We do not respond to browser-based "do not track" signals. Some third-party sites who push content to our Site may keep track of your browsing activities over time and across different sites when they serve you content, which enables them to tailor what they present to you.

5. Use of Personal Information. Tholos uses or may use your collected Data for various purposes:

  • To operate, provide and improve our Services;
  • To send information or content to you which we think may be of interest to you by post, email, or other means and send you marketing communications relating to our business;
  • To promote use of our services to you and share promotional and information content with you in accordance with your communication preferences;
  • To send information to you regarding changes to our Terms of Use found at [TERMS OF USE LINK], this Privacy Policy or other legal agreements;
  • To respond to support requests as well as send you information regarding service upgrades, improvements or issues regarding the use of the App or the Site;
  • To gather analysis or valuable information so that we can improve the App or the Site;
  • To monitor the usage of the App or the Site;
  • To ensure network and information security
  • To inform you of upgrades or changes to the App or the Site; and
  • To detect, prevent and address technical issues.

6.   Disclosure of Personal Information.

6.1 Disclosures . Regardless of any choices you make regarding your information (as described below), the Company may disclose information if it believes in good faith that such disclosure is necessary to (a) comply with relevant laws or to respond to subpoenas or warrants served on the Company; or (b) protect or defend the rights or property of the Company, users of the Services, or any other party.

6.2 Affiliates . We may share some or all of your information with any other company or individual that directly or indirectly controls, is controlled by or is under common control with the Company (each an " Affiliate"), if any, in which case we will require our Affiliates to honor this Privacy Policy. We may share your Personal Information in connection with, or during negotiations of, a transaction that alters the structure of our business, such as a reorganization, merger, sale, transfer, change of control, or other disposition of all or a portion of our business, assets or stock, including a bankruptcy or similar proceeding. If another company acquires the Company or our assets, or an Affiliate or its assets, that company will possess the information we have collected and will assume the rights and obligations described in this Privacy Policy.

6.3 Disclosure to Third Parties . We may share your information with third party Service Providers or third party business partnersthat are contractually bound to safeguard your information. We may make such disclosure in order to provide you with the Services; to conduct quality assurance testing; to facilitate creation of accounts; to facilitate your use of the Service; to process any transactions you make through our Site or Services (including without limitation credit card processing); to provide technical support; or to offer you certain products or services or for their promotional or marketing purposes, as permitted by law. We may also share your information with any other party with your express consent.

6.4 Third Party Platforms. We may link to or frame third party websites, decentralized applications and platforms (collectively, " Third Party Platforms"). Our provision of a link to or frame of any Third Party Platform is for your convenience and does not signify our endorsement of such Third Party Platform or its contents. If we display third party websites through a frame, you are on another site. During this process, another entity may collect information from you. We have no control over, do not review, and cannot be responsible for, these outside Third Party Platforms or their content or their privacy practices. Please be aware that the terms of this Privacy Policy do not apply to these Third Party Platforms or content, or to any collection of data after you click on links to such Third Party Platforms.

6.5 We Do Not Sell Personal Information. We do not sell your Personal Information to any third party.

6.6 Use of Navigational Information. We may use Navigational Information to operate and improve the App or the Site.

6.7 Testimonials and Comments. We may post customer testimonials and comments on our Site, which may contain Personal Information. We will obtain each customer's consent via email, Instagram, Facebook, or other social network prior to posting the customer's name and testimonial.

6.8. Security of your Personal Information. The Site, cloud computing services and data storage are hosted by AWS. Please review their privacy policy to understand security protocols for AWS – you can access the AWS Privacy Policy web page here. We are committed to protecting the security of your Personal Information. We use a variety of industry-standard security technologies and procedures to help protect your information from unauthorized access, use, or disclosure. But remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal information, we cannot guarantee its absolute security.

6.9 Service Providers. We may employ third party companies and individuals to facilitate our Site, to manage the Site on our behalf, to perform Support-related services or to assist us in analyzing how our Site are used.

These third parties Service Providers have access to your Personal Information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

7. Your Choices Regarding Your Information.

7.1 Choices . We offer you choices regarding the collection, use, and sharing of your information. When you receive communications from us, you may indicate a preference to stop receiving further communications from us and you will have the opportunity to "opt-out" by following the unsubscribe instructions provided in the e-mail you receive. Should you decide to opt-out of receiving future mailings, we may share your e-mail address with third parties to ensure that you do not receive further communications from these third parties. Despite your indicated e-mail preferences, we may send you emails related to your account or transactions thereunder, or notices of any updates to our Terms of Use or Privacy Policy.

You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies or block the use of other tracking technologies, some parts of the Service may be inaccessible or not function properly. You can choose whether or not to allow the Service to collect and use real-time information about your device's location through the device's privacy settings. If you block the use of location information, some parts of the Service may be inaccessible or not function properly.

7.2 Changes to Information . You may change any information in your account by sending an e-mail to us at legal@tholos.app. You may request deletion of your information by us, but please note that we may be required (by law or otherwise) to keep this information and not delete it (or to keep this information for a certain time, in which case we will comply with your deletion request only after we have fulfilled such requirements). When we delete any information, it will be deleted from the active database, but may remain in our archives.

7.3 To Unsubscribe from Our Communications. You may unsubscribe from our marketing communications by clicking on the "unsubscribe" link located on the bottom of our e-mails or by sending us email us at legal@tholos.app.

Customers cannot opt out of receiving transactional emails.

8. Links to Other Site and Mobile Applications. The App and the Site may contain links to other sites that are not operated by us, including links to our Social Media accounts on Facebook and Instagram. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.

We may maintain pages for Tholos on social media platforms, such as Facebook, LinkedIn, Twitter, Google, YouTube, Instagram, and other third-party platforms. When you visit or interact with our pages on those platforms, the platform provider's privacy policy will apply to your interactions and their collection, use, and processing of your personal information. You or the platforms may provide us with information through the platform, and we will treat such information in accordance with this Privacy Policy.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party site or services.

9. Legal Basis for Processing Personal Information Under General Data Protection Regulation (GDPR)

9.1 If you are from the European Economic Area (" EEA"), the United Kingdom (" UK"), or Switzerland, the Company's legal basis for collecting and using the Personal Information described in this Privacy Policy depends on the Personal Information we collect and the specific context in which we collect it.

The Company may collect and process your Personal Information because:

  • We need to perform a contract with you.
  • You have given us your consent to do so.
  • The processing is in our legitimate interests and it is not overridden by your rights.
  • To comply with the law.
  • To protect the vital interests of an individual.
  • For the performance of a task carried out in the public interest or in the exercise of official authority vested in us.

The Company will retain your Personal Information only for as long as is necessary for the purposes set out in this Privacy Policy. We also may retain and use your Personal Information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

The Company will also retain Usage Data for internal analysis purposes. We do not use your Personal Information for the purposes of automated decision-making or profiling.

9.2 Transfer of Data. Your information, including Personal Information, may be transferred to, and maintained on, computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.

The App and Site are hosted in the United States. If you are located outside of the United States and choose to provide information to us, please note that we may transfer the data, including Personal Information, to the United States or other country and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer to the United States or another country.

The Company will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Information will take place to an organization or a country unless there are adequate controls in place including the security of your data and other Personal Information.

9.3 Disclosure of Data

Legal Requirements

The Company may disclose your Personal Information in the good faith belief that such action is necessary to:

  • To comply with a legal obligation
  • To protect and defend the rights or property of the Company
  • To prevent or investigate possible wrongdoing in connection with the App or Site
  • To protect the personal safety of users of the App, Site or the public
  • To protect against legal liability

9.4 Your Data Protection Rights Under General Data Protection Regulation (GDPR). If you are a resident of the EEA, you with data protection rights to correct, amend, delete, or limit the use of your Personal Information. To exercise any of these rights, please contact us at legal@tholos.app.

Under the GDPR, you have the following data protection rights:

  • The right to be informed what Personal Information we hold about you.
  • The right to access, update or to delete the Personal Information we have about you..
  • The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
  • The right to object. You have the right to object to our processing of your Personal Information.
  • The right of restriction. You have the right to request that we restrict the processing of your Personal Information.
  • The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.
  • The right to withdraw consent. You also have the right to withdraw your consent at any time where the Company relied on your consent to process your Personal Information. (However, withdrawing your consent will not affect the lawfulness of any collection or processing we conducted prior to your withdrawal, nor will it affect collection or processing of your Personal Information conducted in reliance on lawful grounds other than consent.)

We will strive to respond to your request within a month, but this may be extended by an additional two months, if necessary. Please note that we may ask you to verify your identity before responding to your request.

In addition, where we obtain Personal Information about you from a source other than yourself, we may not be not required to provide you with certain information described in this Privacy Policy if:

  • You already have the information
  • Providing you with the information would prove impossible or would involve a disproportionate effort on our part
  • We are under legal obligation to obtain or disclose the information, which provides appropriate measures to protect your legitimate interests
  • We are obliged to keep the information confidential as a result of an obligation of professional secrecy under applicable law

You have the right to complain to a Data Protection Authority about our collection and use of your Personal Information. For more information, please contact your local data protection authority in the EEA, UK or Switzerland. A list of Data Protection Authorities is available at: https://edpb.europa.eu/about-edpb/board/members_en. Unless otherwise indicated in this Privacy Policy, Tholos is a Data Controller for the Personal Information we collect and process.

10.  Residents of Canada

Users of the App and Site from Canada are informed we take appropriate steps to comply with applicable Canadian data privacy requirements, including the Anti-Spam Legislation (CASL) and the Personal Information Protection and Electronic Documents Act (PIPEDA). Note, however, that Personal Information stored or processed outside of Canada, including in the United States or another foreign country, may not be subject to the PIPEDA. In addition, Personal Information stored or processed outside of Canada is subject to the laws of that other country and may be available to the foreign government of the country in which the Personal Information or the entity controlling it is located pursuant to a lawful order in that jurisdiction. This Privacy Policy is intended to provide the required notices regarding our collection and use of Personal Information, including transfer to the United States.

You may request to access, correct, or delete your Personal Information, or withdraw consent to our collection, use or disclosure of your Personal Information, by contacting us at legal@tholos.app.

11. Children's Privacy. The App and the Site are not intended to be accessed or used by anyone under the age of 18 (a "Child").

We do not knowingly collect Personal Information directly from anyone under the age of 13. If you are a parent or guardian and you are aware that your child has provided us with Personal information, please contact us. If we become aware that we have collected Personal information from a child without verification of parental consent we take steps to remove that information from our databases.

12. Changes to This Privacy Policy. We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Site, prior to the change becoming effective and update the "effective date" at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

13. Dispute Resolution.If you have any questions or concerns, please contact Tholos by e-mail at legal@tholos.app. We will do our best to address your concerns. If you feel that your complaint has been addressed incompletely, we invite you to let us know for further investigation. If you and Tholos are unable to reach a resolution to the dispute, you and Tholos will settle the dispute exclusively under the rules of the American Arbitration Association (www.adr.org) as set forth in the Terms of Use found at www.tholos.app/terms-of-use.

14. Supplemental Privacy Statement for California Consumers under CCPA

Introduction

Our business proudly serves or will serve certain natural persons residing in the State of California (each, a "consumer"). This California Statement explains rights that California consumers may have under the CCPA.

When we use the term "personal information" in this supplemental California Statement, we are using that term as CCPA defines it, which CCPA generally defines "personal information" to mean information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. However, personal information does not include publicly available, deidentified, or aggregate consumer information (which are all defined in CCPA). Notably, the definition of "personal information" also does not apply to the collection of personal information from job applicants, employees – whether you are our employee or any employee of the entity arranging access to our Services for you, business owners, directors, officers, or contractors.

14.1 Categories of personal information we collect, the sources of that information, purposes for why we collect it, who we share it with, and whether we sell that personal information. Where we act as a "business" under CCPA (meaning we determine the manner and reasons for why we process your personal information), we may be required to disclose additional information regarding the categories of personal information we collect, the sources where we obtain that information, the purposes for why we collect that information, who we share that information with, as well as whether we sell that personal information – all of which depends on the specific Service.

In particular, we have collected and disclosed the following categories of personal information from users within the last twelve (12) months:

CategoryExamplesCollectedDisclosed for Business Purpose
A. IdentifiersName, postal address, e-mail address, IP address.YesNo
B. Personal information categories listed in the California Customer Records statuteName, telephone number, credit card and debit card information or other financial informationNoNo
C. Protected classification characteristics under California or federal lawAge (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, gender, sexual orientation, veteran or military status, genetic information (including familial genetic information).NoNo
D. Commercial informationRecords of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.NoNo
E. Biometric informationGenetic, physiological, biological or behavioral characteristics.NoNo
F. Internet or other similar network activityBrowsing history, search history, information on a consumer's interaction with a website, application, or advertisement.YesNo
G. Geolocation dataPhysical location or movementsNoNo
H. Sensory dataAudio, electronic, visual, thermal, olfactory, or similar information.NoNo
I. Professional or employment-related informationCurrent or past job history or performance evaluations.NoNo
J. Non-public education information collected by certain federally funded institutionsEducation records directly related to a student maintained by an educational institution or party acting on its behalf.NoNo
K. Inferences drawn from other personal informationProfile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.NoNo

14.2. Your privacy rights. If you are a resident of California and are not a job applicant, employee/contractor, or employee/contractor of another company interacting with us in your job role, you have the right to request what information we collect, use, and disclose. You also have the right to request that we delete your information.

To make a request, you can contact us at legal@tholos.app. Provide us enough information to verify your identity. We will use information you provide to us to verify your identify. If we cannot initially verify your identity, we may request additional information to complete the verification process, such as, for example, a copy of your driver's license and/or a recent utility or credit card bill.

We will confirm receipt of your request within 10 business days. We must provide the requested information or delete your personal information within 45 days of receipt of your request, but we can use up to an additional 45 days if we let you know that additional time is needed.

You can designate an agent to make a request on your behalf by either: (1) having your agent send us a letter, signed by you, certifying that the agent is acting on your behalf and showing proof that they are registered with the California Secretary of State; or (2) by you and the agent executing and sending us a notarized power of attorney stating that the agent is authorized to act on your behalf. Please note that we may still require you to verify your identity before we process a request submitted by your agent.

California residents also have certain rights regarding the sale of personal information. California residents have the right to opt out of the sale of their personal information by contacting us at legal@tholos.app.

We will not discriminate against you because you have exercised any of your privacy rights under the CCPA.

Contact Information. We welcome your comments or questions regarding this Privacy Policy. Please e-mail us at legal@tholos.app.