Legal

Privacy Policy

Effective Date: August 14, 2026 · Last Reviewed: August 14, 2026

This Policy describes how Xelecta Inc.("Xelecta") collects, uses, shares, and protects your personal and health data. Xelecta operates exclusively within the United States. We handle highly sensitive health and genomic data and take our obligations seriously. Please read this Policy carefully.

1. Overview

Xelecta Inc.("Xelecta," "we," "us," or "our") operates the Xelecta precision precision medicine platform at xelecta.com and related services. This Privacy Policy explains our practices regarding the collection, use, storage, sharing, and protection of personal information, including highly sensitive health, wellness, and genomic data.

Xelecta is a US-based company and our services are available exclusively to residents of the United States. This Policy applies to all US-based users of our Platform and incorporates our obligations under: HIPAA (45 CFR Parts 160 and 164), the California Consumer Privacy Act (CCPA / CPRA), the Genetic Information Nondiscrimination Act (GINA), and the Children's Online Privacy Protection Act (COPPA).

Core Commitment: We do not sell, rent, or license your personal health or genomic data to third parties. Your data exists to provide you with a better wellness experience. Nothing else.

2. Data We Collect

A. Data You Provide Directly

  • Account registration data: name, email address, password (hashed), date of birth
  • Billing and payment data: credit/debit card details (tokenized and processed by Stripe; we do not store raw card numbers)
  • Shipping address for physical product orders (US addresses only)
  • Health intake data: health goals, existing conditions you choose to disclose, hardware preferences
  • Application data for the Healthspan Program: health focus, wearable hardware, biomarker availability, and contact details
  • Genomic data: if you choose to upload a DNA file from a third-party genotyping service (e.g., 23andMe, AncestryDNA) or our at-home kit
  • Communications: emails, messages, and feedback you send us

B. Health & Biometric Data Generated Through the Platform

  • Continuous glucose monitoring (CGM) data: glucose readings, meal events, exercise events
  • Body composition data: weight, body fat percentage, visceral fat index, skeletal muscle mass
  • Heart-rate variability (HRV): RMSSD, SDNN, autonomic tone metrics
  • Sleep architecture: sleep stages (N1, N2, N3/deep, REM), total sleep time, sleep efficiency
  • Wearable device data imported via API integrations (e.g., Apple Health, Google Fit, Oura, Garmin)
  • Protocol adherence data: supplement logs, activity records you enter

C. Automatically Collected Technical Data

  • IP address and approximate geolocation (city/region level only)
  • Browser type and version, operating system, device type
  • Pages visited, features used, session duration, clickstream data
  • Cookies and similar tracking technologies (see Section 7)
  • Error logs and crash reports

3. Sensitive Health and Genomic Data

Special Category Data

Health, biometric, and genomic data are treated as sensitive personal information under US federal law (HIPAA, GINA) and the California Consumer Privacy Act (CCPA). We apply heightened protections to these categories at all times.

Genomic Data Handling:Raw genomic files (e.g., VCF, 23andMe raw data format) are encrypted on your device before transmission. Processing occurs exclusively within hardware-based Trusted Execution Environments (TEEs). Xelecta's servers and employees never have access to your raw DNA sequence data. Only computed variant classifications are stored in our systems, encrypted under your user key.

CGM and Biometric Data: All sensor data is transmitted over TLS 1.3 and stored with AES-256 encryption at rest. Access is restricted to your account and (for Healthspan Program members) your assigned health specialist and, for Concierge-tier consultations, the treating Licensed Partner Network Physician.

Legal Basis for Processing: We process sensitive health data based on your explicit consent, provided through the intake and account creation process. You may withdraw consent at any time by contacting us at privacy@xelecta.com, though this may limit your ability to use certain features.

4. How We Use Your Data

We use your data to:

  • Provide, operate, and improve the Platform and its features
  • Generate personalized wellness protocols, supplement recommendations, and insights
  • Process purchases, fulfill orders, and manage billing
  • Authenticate your account and protect against unauthorized access
  • Enable your assigned health specialist, and for Concierge-tier consultations the treating Licensed Partner Network Physician, to support your Healthspan Program membership
  • Send transactional communications: order confirmations, receipts, security alerts
  • Send marketing communications, only with your explicit opt-in consent, and you may unsubscribe at any time
  • Comply with legal and regulatory obligations
  • Investigate and prevent fraud, abuse, and security incidents
  • Analyze de-identified, aggregated usage patterns to improve algorithms and platform features (data cannot be used to re-identify you)

We do not use your health or genomic data for advertising, advertising targeting, or to infer characteristics for non-wellness commercial purposes.

5. How We Share Your Data

We share your data only in the following limited circumstances:

Service Providers (Sub-Processors)

We share data with vetted third-party service providers who process data on our behalf under written data processing agreements (and HIPAA Business Associate Agreements where applicable). These include:

  • Stripe Inc.: Payment processing. They handle card data directly; we receive only a payment token.
  • Amazon Web Services (AWS): Cloud infrastructure and encrypted data storage.
  • Terra API / Tryvital: Wearable device data aggregation.
  • SendGrid: Transactional email delivery.
  • Analytics providers: Privacy-preserving, server-side analytics (no PII shared).

All sub-processors are contractually prohibited from using your data for their own purposes and are bound by HIPAA BAAs where applicable.

Legal Requirements

We may disclose your data to comply with applicable US law, regulation, legal process, or governmental request; to enforce our Terms; to protect the rights, property, or safety of Xelecta, its users, or the public; or to respond to an emergency involving physical danger. We will notify you of such disclosures to the extent permitted by law.

Business Transfers

In the event of a merger, acquisition, sale of assets, or bankruptcy, your data may be transferred as part of that transaction. We will provide 30 days' notice and offer you the ability to delete your account before the transfer becomes effective. The acquiring entity must agree to honor this Privacy Policy or provide equivalent protections.

With Your Consent

We may share your data in ways not described above with your prior explicit written consent.

6. We Do Not Sell Your Data

Unconditional Commitment

Xelecta does not sell, rent, trade, license, or commercialize your personal information, including health data, genomic data, biometric data, behavioral data, or program application data, to any third party for commercial purposes. This includes data brokers, insurers, pharmaceutical companies, advertisers, and research institutions. This is an unconditional commitment, not a conditional CCPA opt-out right.

7. Cookies and Tracking Technologies

We use the following types of cookies and similar technologies on our Platform:

  • Strictly Necessary Cookies: Required for the Platform to function (authentication, security). Cannot be disabled.
  • Functional Cookies: Remember your preferences and login state.
  • Analytics Cookies: Server-side, privacy-preserving analytics to understand how the Platform is used in aggregate. No personal data is shared with analytics providers.

We do not use advertising cookies, third-party advertising pixels, social media tracking pixels, or any cross-site behavioral tracking on our Platform.

You can control cookies through your browser settings. Disabling functional cookies may affect Platform functionality.

8. Data Security

We implement comprehensive technical, administrative, and physical safeguards to protect your data, including:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for all data at rest
  • Hardware Security Module (HSM) based key management
  • Role-based access controls with principle of least privilege
  • Multi-factor authentication required for all employee access to production systems
  • Continuous vulnerability scanning and annual third-party penetration testing
  • 24/7 security monitoring and incident response
  • Regular employee security and HIPAA training
  • Physical security controls at data center facilities

Despite these measures, no security system is impenetrable. In the event of a data breach affecting your personal information, we will notify you as required by applicable law, including the HIPAA Breach Notification Rule (within 60 days of discovery) and applicable US state breach notification laws.

9. Data Retention

We retain your data for as long as your account is active and as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements.

  • Account data: Retained while account is active + 3 years after closure (for legal/audit purposes)
  • Health and biometric sensor data: Retained for duration of service + 2 years, then deleted
  • Healthspan Program application data: Retained for duration of engagement + 2 years
  • Genomic data (computed variants only): Deleted within 30 days of account closure upon request
  • Raw genomic files: Never stored on Xelecta servers (processed in TEE and discarded)
  • Transaction records: Retained 7 years for tax and audit compliance
  • Audit and security logs: Retained 7 years per HIPAA requirements
  • Marketing communications data: Deleted within 30 days of unsubscribe request

You may request earlier deletion of your data (see your rights below), subject to our legal retention obligations.

10. Your HIPAA Rights

To the extent Xelecta handles Protected Health Information (PHI) under HIPAA, you have the following rights:

  • Right to Access: Request a copy of your health information that we maintain. We will respond within 30 days.
  • Right to Amend: Request corrections to inaccurate or incomplete health information.
  • Right to Restriction: Request restrictions on certain uses and disclosures of your PHI, subject to limitations.
  • Right to Accounting of Disclosures: Request a list of certain disclosures we have made of your PHI.
  • Right to Confidential Communications: Request we communicate with you through alternative means or at alternative locations.
  • Right to Receive a Notice of Privacy Practices: See our full HIPAA Notice.
  • Right to File a Complaint: You may file a complaint with our Privacy Officer at privacy@xelecta.com or with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/privacy. We will not retaliate against you for filing a complaint.

11. Your CCPA/CPRA Rights (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell (we do not sell).
  • Right to Delete: Request deletion of your personal information, subject to legal exceptions.
  • Right to Correct: Request correction of inaccurate personal information we maintain about you.
  • Right to Opt Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: We only use your sensitive personal information (which includes health and genomic data) for purposes necessary to provide services.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

How to Submit a CCPA Request: Email privacy@xelecta.comwith the subject "CCPA Request" and include your full name, email address on file, and the specific right(s) you wish to exercise. We will verify your identity before processing the request and respond within 45 days.

Categories of Personal Information Collected in the Last 12 Months:Identifiers, commercial information, internet activity, geolocation data (city-level), health information, biometric information, and inferences drawn from health data.

12. Genetic Information and GINA

The Genetic Information Nondiscrimination Act (GINA) prohibits discrimination based on genetic information in health insurance and employment. Xelecta honors the spirit and protections of GINA:

  • We will never share your genetic information with any insurance company, employer, or entity that could use it to discriminate against you.
  • We process genetic data exclusively for health optimization purposes.
  • We will never use genetic information to make employment decisions.
  • Your genetic data is processed in isolated, encrypted environments as described in Section 3.

13. Children's Privacy (COPPA)

The Xelecta Platform is not directed to, and we do not knowingly collect personal information from, children under 13 years of age. We do not knowingly collect personal information from individuals under 18 years of age without verified parental consent.

If we learn that we have inadvertently collected personal information from a child under 13, we will promptly delete that information. If you believe a child has provided us with personal information, please contact us at privacy@xelecta.com.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other business reasons. When we make material changes, we will notify you by email and by posting a prominent notice on the Platform at least 30 days before the changes take effect.

Your continued use of the Platform after the updated Policy takes effect constitutes acceptance. If you do not agree to the updated Policy, you must stop using the Platform and may request deletion of your data.

15. Contact and Privacy Rights Requests

For privacy questions, requests, or complaints, contact our Privacy Officer:

Privacy Officer: Xelecta Inc.

1200 Brickell Ave, Suite 800, Miami, FL 33131

privacy@xelecta.com

Response time: within 30 days for most requests; 45 days for CCPA requests

For HIPAA-related requests and complaints, contact our HIPAA Privacy Officer at privacy@xelecta.com. You may also file a complaint with the HHS Office for Civil Rights: U.S. Department of Health and Human Services, 200 Independence Avenue S.W., Washington, D.C. 20201, hhs.gov/ocr/privacy.

California residents may also contact the California Attorney General's office or the California Privacy Protection Agency (CPPA) at cppa.ca.gov.

This Privacy Policy was last reviewed and updated on August 14, 2026. Xelecta is a US-based company serving US residents exclusively. This Policy has been prepared with reference to HIPAA (45 CFR Parts 160 and 164), CCPA (Cal. Civ. Code § 1798.100 et seq.) as amended by CPRA, GINA (Pub. L. 110-233), and COPPA (15 U.S.C. § 6501 et seq.). This document is not legal advice.