QA flow - PRIVACY POLICY

Last updated February 2026

Company Information

QA flow is owned and operated by Soci Finance Inc., a corporation incorporated under the laws of Delaware. Throughout this Privacy Policy, references to "QA flow," "we," "us," or "our" refer to Soci Finance Inc. and its QA flow platform and services.

Privacy Policy Overview

This Privacy Policy ("Privacy Policy") explains Soci Finance Inc.'s ("QA flow," "we," "us," "our") privacy practices for the activities described herein. Please read this Privacy Policy carefully to learn how we collect, use, share and process personal information, and to learn about your rights and choices regarding information we collect from or about you.

General Terms

By using our website, our applications that run on mobile devices or tablets, or any online or mobile site or application that we own or control (collectively, our "Sites"), and/or by agreeing to this Privacy Policy, e.g. in the context of purchasing or utilizing any of our products or services, you understand and acknowledge that we will collect, process, use and share personal information as described in this Privacy Policy and consent to the practices described in this Privacy Policy.

1. Personal Information We Collect

In conducting every aspect of our business, we may collect personal information to help obtain your health data. The information we collect will vary depending on your interaction with us. You are not required to provide any information you are not comfortable sharing. Such information may include, without limitation: your name, addresses, email addresses, telephone numbers, date of birth, age, insurance information, gender, protected health information, and other types of personal information that you choose to provide to us or that we may obtain about you. We collect personal information, as well as other information, in multiple ways. You are provided options to fill out information that you are comfortable sharing with our team when using our platform.

We will not share your information to any outside third parties that you are not aware of. You will have control of who sees your data. You may delete your profile at any time and we will not keep copies of your data on our servers.

Information You Provide to Us

We collect information you provide to us. This may include, for example, when you request information or materials from us, visit or use our Sites, purchase our products or services, create an account in our application, register for an account on the customer portal, communicate with our customer service or sales teams, respond to a survey, or respond to our advertisements.

Information We Collect from Other Sources

We may collect information about you from a variety of third parties. For example, we may obtain information about you from: covered entities such as health plans, health insurance companies, health care providers and healthcare clearinghouses; organizations, universities and private clinics conducting research studies or clinical trials; companies that search for, provide, and/or aggregate information from public records, such as LexisNexis Risk Solutions and Accurint; state and federal government agencies, such as the IRS and Medicare/Medicaid; credit bureaus and credit reporting agencies, such as Equifax; your existing health, medical, provider, or insurance accounts when you grant permission to access your accounts or information; social media networks; and publicly-available sources and data suppliers from which we obtain data to validate or supplement the information we hold.

Information We Collect Automatically

When you use or visit our Sites, we collect some information automatically. For example, when you visit our website, we may collect device, usage and log information such as your computer's operating system, Internet Protocol (IP) address, access times, browser type and language, the search engine you used to locate the website, and the website you visited before or after our site. In addition, we gather certain navigational information about where you go on our website to help us determine which areas of the website are most frequently visited and helps us to tailor the sites to the needs and interests of our online visitors. If you use our mobile applications or use our Services on a mobile device or tablet, we may also collect your device type, mobile phone number, operating system type, wireless carrier, and device IDs, on our mobile applications.

Like most companies, we use technologies such as web beacons, pixels, tags, and JavaScript, alone or in conjunction with cookies, to gather this information. When you visit our website, we, or an authorized third party, place or recognize a unique cookie on your browser (including through use of pixel tags) that collects information, including personal information, about your online activities over time and across different sites. We also use web beacons and pixels in our emails to collect information about how you interact with our emails. For example, we may place a pixel in marketing emails that notify us when you click on a link in the email. If you want to remove or cookies and other collection technology, you may be able to update your browser settings (consult your browser's "help" menu to learn how to remove or block cookies and similar technology). You can find instructions on how to manage collection technology on different types of web browsers at www.allaboutcookies.org.

2. How We Use Personal Information

We use your personal information to help us assist you.

We may use your personal information to:

Complete contracts as well as any disclosures or other documents required by law;

Provide, develop, maintain, and improve our products and Services (e.g. evaluate the performance of our staff, assess the quality of our products and Services, and help us improve our website and processes);

Process any applications, forms, requests, inquiries, or other information submitted to us;

Send marketing communications, promotional offers, and periodic customer satisfaction, market research or quality assurance surveys;

Communicate with you;

Administer and process payments to you or from you;

Create and update your customer account, including aggregating your health and medical records and treatment information;

Allow creation, maintenance, customization, enrollment, registration, and securing of accounts on your behalf;

Administer and support participation in sweepstakes, special offers, special pricing, discounts, and promotions;

Personalize our products, websites, and Services, including content, ads and offerings;

Perform research and analytical activities (e.g. identifying trends and the effectiveness of marketing campaigns);

Solicit your participation in a clinical trial or research study;

Conduct audits, security and fraud monitoring and prevention;

Protect our legitimate business interests and legal rights; and

Assist us with legal claims, compliance, regulatory and investigative purposes as necessary (including in connection with law enforcement investigations, legal process, or litigation).

We may also use personal information we have collected and aggregated or anonymized personal information for any purpose permitted by law. For example, we may use this information to understand more about our users, such as by analyzing aggregated information to calculate the percentage of our users who have a particular telephone area code. This includes demographic data, inferred commercial interests, and other information we may collect from you or from third parties.

3. How We Share Personal Information

We may share personal information with third parties in the following circumstances:

Service Providers

We may share your personal information with third-party vendors, consultants, and other service providers who perform services on our behalf. These companies may assist us with payment processing, data analysis, email delivery, hosting services, customer service, marketing efforts, and other functions necessary to operate our business. These service providers are authorized to use your personal information only as necessary to provide services to us.

Business Transfers

We may share or transfer your personal information in connection with, or during negotiations of, any merger, sale of company assets, financing, acquisition, dissolution, corporate reorganization, or similar transaction involving all or a portion of our business.

Legal Requirements

We may disclose your personal information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). We may also disclose your information to protect and defend our rights or property, prevent fraud, or protect the safety of our users or the public.

With Your Consent

We may share your personal information with third parties when we have your consent to do so.

Affiliates

We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Policy.

4. Data Security

We implement reasonable administrative, technical, and physical safeguards designed to protect the personal information we collect and process. However, no security system is impenetrable and we cannot guarantee the security of our systems 100%. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately.

5. Data Retention

We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When we no longer have a legitimate business need to process your personal information, we will delete or anonymize it.

6. Your Rights and Choices

Depending on your jurisdiction, you may have certain rights regarding your personal information. These may include the right to access, correct, update, delete, or restrict the processing of your personal information. You may also have the right to object to certain processing activities or to request data portability.

To exercise any of these rights, please contact us using the contact information provided below. We may need to verify your identity before processing your request.

7. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18 without verification of parental consent, we will take steps to delete that information.

8. Third-Party Links

Our Sites may contain links to third-party websites or services that are not owned or controlled by QA flow. We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party websites you visit.

9. International Data Transfers

Your information, including personal information, may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. By using our Services, you consent to such transfers.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Effective Date” at the top of this page. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Soci Finance Inc. (QA flow)

Email: team@qaflow.com

Website: www.qaflow.com