HOLISTIC AI TRACKER PRIVACY POLICY

Last Update: [12.11.2023]

1. INTRODUCTION

Welcome to “Holistic AI Tracker,” operated by Holistic AI Limited, located at 18 Soho Square, London, W1D 3QL, United Kingdom. This privacy policy outlines how we use, collect, protect and share your personal information. By accessing or using our website, you agree to the practices described here in Holistic AI Limited's Privacy and Data Protection Policy (“Privacy Policy”).

At Holistic AI Limited. (“we”, “us”, or “our”) we are committed to protecting and respecting your privacy and processing your personal data in compliance with the United Kingdom General Data Protection Regulation (“UK-GDPR”), the Data Protection Act 2018, and all other applicable data protection laws.

This Privacy Policy explains how we collect, process, and keep your data safe. The Privacy Policy will tell you about your privacy rights, how the law protects you, and inform our employees and staff members of all their obligations and protocols when processing personal data.

This Privacy Policy applies to all Personal Data processed at any time by us. Terms ‘personal data’, ‘processing’, ‘controller’, ‘processor’, and ‘consent’ must be understood as in their respective meanings provided under Article 4 of the UK-GDPR. 1.1 Who is your data controller?

Holistic AI Limited is your data controller (“Controller”) and is responsible for your Personal Data.

You have the right to make a complaint at any time to the Information Commissioner’s Office (“ICO”), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance. 1.2 Processing data on behalf of the Controller and processors’ responsibility to you

In discharging our responsibilities as the Controller we have employees who will deal with your data on our behalf (“Processors”). Therefore, the responsibilities described below may be assigned to an individual or may be taken to apply to the organisation as a whole as the Processors. The Controller and the Processors have the following responsibilities:

• Ensure that all processing of personal data is governed by one of the legal bases laid out under Article 6 of the UK-GDPR (see below for more information on those bases);

• Ensure that the Processors authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

• Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk associated with the processing of personal data;

• Obtain the prior specific or general authorisation of the Controller before engaging with another Processor;

• Assist the Controller in the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights;

• Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in the UK-GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller;

• Maintain a record of all categories of processing activities carried out on behalf of the Controller;

• Cooperate, on request, with ICO and other competent authorities in the performance of its tasks;

• Ensure that any person acting under the authority of the Processor who has access to personal data does not process personal data except on instructions from the Controller; and

• Notify the Controller without undue delay after becoming aware of a personal data breach.

2. INFORMATION WE COLLECT

2.1 What categories of personal data we collect?

We may collect, use, store and transfer different categories of personal data about you which we have grouped together below. Not all of the following types of data will necessarily be collected from you but this is the full scope of data that we collect and when we collect it from you:

• Identity information: Your name, surname, age, date of birth, birthplace,

• Contact information: Email address, phone number, address,

• Professional information: Your job title and the name of the company you work for,

• Payment information: Information needed to process the payment required for your subscription,

• Device information: IP addresses, device information, browser type, operation system information

• Usage information: Information on content you viewed, liked, or saved and time spent on the Holistic AI Tracker, referral URL

• Cookies,

We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

2.2 How do we collect your personal information?

We collect data through online forms and cookies. All information collected with the exception of necessary cookies is provided voluntarily by consenting to cookies or providing the information on sign-up. We use cookies to save login information and user preferences. Users can opt out of cookies or delete their account to stop data collection.

3. HOW WE USE YOUR INFORMATION

We may use your personal data for the following purposes:

• To create your user account, manage it and keep your user account functioning and secure,

• To verify your information and identity for security purposes,

• To provide you service according to the User Agreement,

• To process your payments (if applicable)

• To process your event registration (if applicable)

• To communicate with you about potential and planned changes to our services as well as the Holistic AI Tracker,

• To personalize your user experience based on your preferences,

• To gather feedback on the Holistic AI Tracker and improve our services,

• To create metrics to evaluate and measure the performance of the Holistic AI Tracker and our other services,

• To comply with our legal and regulatory obligations.

4. LEGAL BASIS FOR PROCESSING

We rely on the following legal bases for processing your personal data:

Performance of a contract: We need to process your personal data to fulfil our contractual obligations to you when you sign up for our events.

Legitimate interests: We may process your personal data for our legitimate interests in organizing and promoting events, as long as your fundamental rights and freedoms do not override these interests.

Consent: We will obtain your consent before sending you sales and marketing emails and sharing your personal data with our sponsors and partners for marketing and promotional purposes related to the event. You have the right to withdraw your consent at any time.

Legal Compliance: We’re required by law to collect and process certain types of data, such as fraudulent activity or other illegal actions.

5. SALES AND MARKETING EMAILS

If you have created an account and chosen to receive sales and marketing emails from us, we may send emails you information about our other events, products, and services. From time to time, we may make suggestions and recommendations to you about goods or services that may be of interest to you.

You can unsubscribe from these emails at any time by clicking on the unsubscribe link at the bottom of the email.

6. CHANGE OF PURPOSE

We will only use your personal data for the purposes for which we collected it unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

7. YOUR RIGHTS AND HOW YOU ARE PROTECTED BY US

Your account information will be protected by a password for your privacy and security. You need to prevent unauthorized access to your account and personal information by selecting and protecting your password appropriately and limiting access to your computer or device and signing off after you have finished accessing your account.

You will need to contact us if you would like to delete your account.

California Privacy Rights:

Under California Civil Code sections 1798.83-1798.84, California residents are entitled to ask us for a notice identifying the categories of personal customer information which we share with our affiliates and/or third parties for marketing purposes and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to we@holisticai.com.

7.1 User Rights

Under the UK-GDPR, you have the following rights regarding your personal data:

Right to access: You have the right to request access to your personal data and to receive a copy of your personal data that we hold.

Right to rectification: You have the right to request that we correct any inaccurate or incomplete personal data that we hold about you.

Right to erasure: You have the right to request that we delete your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.

Right to restriction of processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of your personal data.

Right to data portability: You have the right to receive a copy or request a transfer of your data in a portable format.

Right to object: You have the right to object to the processing of your personal data. on grounds relating to his or her particular situation, at any time to processing of personal data concerning you which is based on public or legitimate interest.

You can exercise these rights and request further information about our personal data processing practices by submitting your request via an e-mail to we@holisticai.com or send in a letter to 18 Soho Square, London, W1D 3QL, United Kingdom.

We strongly recommend you include information by which we could verify your identity. Otherwise, we may need to request specific information from you to help us confirm your identity and ensure you have the right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We handle such requests in accordance with the rules provided under the UK-GDPR. You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, if your request is manifestly excessive or unfounded, we could refuse to comply with your request.

7.2 Opting Out of Marketing Promotions

You can ask us to stop sending you marketing messages at any time by clicking a link at the bottom of the e-mail to unsubscribe from our marketing communications.

Where you opt out of receiving these marketing messages, we will continue to retain other personal data provided to us as a result of interactions with us not related to your marketing preferences.

8. DATA SECURITY

User data is stored securely in a database to prevent unauthorized access to breaches. We are concerned with keeping your data secure and protecting it from inappropriate disclosure. We implement a variety of security measures to ensure the security of your personal data on our site. Any personal data collected by us are only accessible by a limited number of employees who have special access rights to such systems and are bound by obligations of confidentiality. If we use subcontractors to store your data, we will not relinquish control of your personal data or expose it to security risks that would not have arisen had the data remained in our possession. However, unfortunately, no transmission of data over the internet is guaranteed to be completely secure. It may be possible for third parties not under the control of Holistic AI Limited to intercept or access transmissions or private communications unlawfully. While we strive to protect your personal data, we cannot ensure or warrant the security of any personal data you transmit to us. Any such transmission is done at your own risk. If you believe that your interaction with us is no longer secure, please contact us.

9. DATA RETENTION

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it. We may retain your personal data for a longer period than usual in the event of a complaint or if we reasonably believe there is a prospect of litigation with respect to our relationship with you. Users will be notified of data retention changes via the email address they have provided.

10. YOUR DATA AND THIRD PARTIES

We may also share personal data with interested parties in the event that Holistic AI Limited anticipates a change in control or the acquisition of all or part of our business or assets or with interested parties in connection with the licensing of our technology.

We may share your personal data at any time if required for legal reasons or in order to enforce our terms or this Privacy Policy.

11. GOOGLE ANALYTICS

We use the web analytics service Google Analytics from Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; 'Google') on our website.

The data processing serves the purpose of analysing this website and its visitors as well as for marketing and advertising purposes. For this purpose, Google will use the information obtained on our behalf as the operator of this website to evaluate your use of the website, to compile reports on website activity and to provide us with other services related to website activity and internet usage.

11.1 Data Collection

The following information, among others, can be collected: IP address, date and time of the page view, click path, information about the browser you are using and the device you are using (device), pages visited, referrer URL (website from which you accessed our website) and location data. The IP address of your browser transmitted by Google Analytics is not linked to any other Google data.

Google Analytics uses technologies such as cookies, web storage in the browser and tracking pixels, which enable an analysis of your use of the website.

11.2 Data Processing and IP Anonymization

IP anonymization is automatically activated on this website. However, when you activate IP anonymization on our website, Google shortens your IP address within the Member States of the European Union or in other countries that are parties to the European Marketing Area Treaty. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there.

Cookies or comparable technologies are used with your consent as per Article 6(1) of the UK-GDPR. Your personal data will be processed with your consent on the basis of Article 6 (1) (a) of the UK-GDPR. You can revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent up to the revocation. You can find more information on terms of use and data protection for Google services at:

  • https://marketingplatform.google.com/about/analytics/terms/us/
  • https://policies.google.com/?hl=en&gl=US
  • https://policies.google.com/technologies/cookies?hl=en.

Our website also uses Google Analytics reports for performance, based on demographic characteristics and interests as well as reports to impressions in the Google Display Network. You may deactivate Google Analytics for display advertising and set the displays in the Google Display Network by accessing the personalized display settings under this link:

https://adssettings.google.us/anonymous?hl=us.

11.3 Tag Manager

This website uses Google Tag Manager. Google is a group of companies and consists of the companies Google Ireland Ltd. (provider of the service), Gordon House, Barrow Street, Dublin 4, Ireland and Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA and other affiliated companies of Google LLC.

This service allows you to administer so-called website tags centrally via an interface. Google Tag Manager implements only tags. No cookies are used and no personal data is collected.

Google has a privacy policy for such data collection by third-party providers:https://marketingplatform.google.com/intl/de/about/analytics/tag-manager/use-policy/. However, Google Tag Manager does not access this data. If certain domains/websites or cookies were deactivated, it remains in place for all tracking tags provided that they are implemented using Google Tag Manager.

12. CHILDREN’S PRIVACY

Holistic AI Tracker is not aimed at persons under 16. If you are a parent or guardian and you become aware that your child has provided us with personal data without your consent, please contact us.

13. INTERNATIONAL TRANSFER OF DATA

Your information may be stored and processed in the UK or other countries or jurisdictions outside the UK where Holistic AI Limited has facilities. By using Holistic AI Limited, you are permitting and consenting to the transfer of information, including Personal Data, outside of the UK.

Some of our third-party service providers may be located in countries outside of the European Union that do not provide the same level of protection for personal data as the GDPR. In these cases, we will ensure that appropriate safeguards are in place to protect your personal data.

14. UPDATES TO THE POLICY

We keep our Privacy Policy under review and will place any updates on this webpage. We will also notify users of policy changes via the email address they provided. This version is dated 12 November 2023.