Privacy Policies

ELEPHAS PRIVACY POLICY AND NOTICE AT COLLECTION

Effective Date: July 2025

Elephas Biosciences Corporation ("Elephas," "us," "we," or "our") is committed to protecting your privacy. This Privacy Policy and Notice at Collection ("Privacy Notice") describes how we may collect and use information about you ("you," "user").

This Privacy Notice applies to: the Elephas website at elephas.com and other digital or online services that link to or reference this Privacy Notice; and your interactions with us in the ordinary course of business, such as communications by phone, email, or in person (collectively, the "Services").

Note: If you are a healthcare provider accessing our clinical laboratory services through Elephas Laboratories, please refer to the Elephas Laboratories Privacy Policy and HIPAA Notice of Privacy Practices, which govern our handling of protected health information.

NOTICE AT COLLECTION

What Types of Personal Information Do We Collect?

We collect and generate different types of Personal Information depending on how you use or interact with our Services. For purposes of this Privacy Notice, "Personal Information" means information that identifies, describes, or is reasonably capable of being associated with you that we collect or generate when you use or interact with our Services. The following describe various categories and sources of Personal Information we have collected, may collect, or generate, including in the past 12 months.

Demographic and Contact Information. Information you provide to us such as your name, mailing address, email address, and telephone number.

Professional Information. Information about your professional background, including your job title, employer or organization, professional credentials, and business contact information.

Webforms and Requests. Information you submit to us through online or interactive forms available within our Services, including "contact us" forms, feedback forms, newsletter sign-ups, requests for information about our products and services, and partnership or investor inquiries.

Website Information. Information such as unique identifiers, preference information, browser type, Internet service provider (ISP), referring/exit pages, the files viewed on our site, operating system, date/time stamp, and clickstream data.

Device Information. Device-specific information including Internet Protocol ("IP") address, hardware model, operating system, unique device identifiers, browser type, and mobile network information. We may also associate the information we collect from your different devices, which helps us provide consistent Services across your devices.

Log Information. Usage details of our Services, including the address (or URL) where you came from before visiting us, which pages or features you visit or utilize, search terms you enter, and items you click on. We may also create usage statistics and monitor the traffic from your use or interaction with our Services.

Internet Protocol (IP) Addresses. IP addresses are unique identifiers automatically assigned to each computer when logging onto the Internet. We generally collect IP address information from visitors using or interacting with the Services and we log them for system administration purposes. In some cases, we may also use IP addresses to serve you advertisements on third party websites regarding our Services that may be of interest to you.

Location Information. Your general location information may be collected in a variety of ways depending on how you use or interact with our Services, including from your IP address, country or location selection, or other location-based components of our Services.

Business Interactions. Information derived from your business-related requests, communications, and dealings we have with you, or the company/organization you work(ed) for or are associated with. This may include information about products or services you expressed an interest in, partnership opportunities, investor relations, and career inquiries.

Social Media. Our Services may link to our pages or accounts on third party social media networks. If you choose to interact with us on social media, we may collect the information you publish or submit. Note that this information is also governed by the privacy policies of the respective companies offering the social media service.

Tracking Technologies. Our Services may incorporate tracking technologies to provide you with certain functionalities. These tracking technologies may collect or generate Personal Information about you when you interact with us. You may adjust your preferences at any time through your Cookie Settings or individual browser settings. Please review our Cookie Notice for more information. Our Services may incorporate the following tracking technologies:

  • Cookies: Small files that are transferred to your device's hard drive for a period of time to store user preferences and other types of information.
  • Web Beacons: Electronic images placed in the code of a webpage, application, or email that allow us to monitor things such as user activity and site traffic.
  • Tags: Pieces of code which gather information about users to better understand online usage patterns and trends. We may also use tags in our emails or newsletters to count how many of those messages are read.
  • Google Analytics: Google Analytics uses cookies to collect data such as time of visit, website pages visited, time spent on each page, IP address, URL, and type of operating system. To learn more about how Google Analytics collects and processes Personal Information, please visit www.google.com/policies/privacy/partners.

HOW DO WE USE PERSONAL INFORMATION?

Depending on what Services you use and how you interact with us, we may use Personal Information about you in the following ways. We will generally rely on the following business purposes to collect and use Personal Information: performance of a contract, compliance with our legal obligations, pursuing our legitimate interests, consent, or protection of vital interests.

To respond to your inquiries and provide information about the Services. If you send us questions, make an inquiry or request, or ask for certain information, we may use Personal Information about you to respond to you.

To send you marketing information. We may use Personal Information about you to provide you with information about our Services, to send you marketing communications, newsletters, updates, or to enable you to participate in surveys or questionnaires.

To serve advertisements you may be interested in. We may use Personal Information about you to tailor and deliver relevant advertisements to you when you are using our Services, or when you are accessing a third-party service. For example, you may receive online advertisements, emails, texts, or social media notifications from us for promotional purposes.

To manage business transactions. During certain business interactions, we may use Personal Information about you to manage business transactions, partnership discussions, investor relations, and career opportunities.

To improve the Services and user experience. We may use Personal Information about you to gather and create statistics regarding your usage of our Services, to better understand our users, personalize users' experiences and interactions with us, and improve the content and performance of our Services.

To comply with applicable laws and our legal obligations. We may use Personal Information about you to comply with applicable laws, regulations, industry codes of conduct, and Elephas's internal policies and procedures, including:

  • For compliance with applicable retention obligations;
  • To respond to lawful requests by public authorities (e.g., to investigate fraud or respond to a government request);
  • To investigate potential breaches; and
  • To protect our rights, property, safety, and those of our users.

Merger or Sale. If we are involved in a merger, acquisition, or sale of our assets (or a portion thereof), we may share Personal Information about you with a corporate purchaser, successor in interest, or prospect to the extent permitted by law.

Other uses. Where permitted by law, we may also enhance or combine information about you, including Personal Information about you, with information about you that we obtain from third parties for the same purposes described in this Privacy Notice.

Use of Non-Personally Identifiable Information. We may use non-personally identifiable information, such as anonymized and/or aggregated Services usage data, in any manner that does not identify individual users for the purpose of improving the operation and management of the Services, including to develop new features, functionality, and services, to conduct internal research, to better understand usage patterns, to resolve disputes, to troubleshoot problems, or for security and compliance purposes.

DO WE SHARE PERSONAL INFORMATION WITH THIRD PARTIES?

Links to Third-Party Websites. As a resource to our users, we may provide links to other unaffiliated websites or services within our Services. If you choose to visit such third-party websites or services, please note that any information you submit to them is not subject to this Privacy Notice.

Elephas Affiliates and Subsidiaries. Elephas shares Personal Information with its affiliates and subsidiaries, including Elephas Laboratories, LLC, for the purposes described in this Privacy Notice.

Service Providers. We may share Personal Information about you with third party service providers that we hire to help us administer and provide the Services to you. These third parties are required to treat Personal Information about you in accordance with appropriate contractual and legal privacy and security requirements.

Advertising and Analytics. We may engage third party service providers who utilize tracking technologies to serve you advertisements that you may be interested in. Some of these advertisements may be personalized to you based on what we, or the third-party service providers, know about you. Depending on where you live, we may be required to obtain your consent before we serve you with these types of advertisements.

DO WE SELL OR SHARE PERSONAL INFORMATION?

We may disclose Personal Information about you to a third party for a business purpose. When we disclose Personal Information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that Personal Information confidential and not use it for any purpose except performing the contract.

We may "sell" or "share" (as those terms are defined under applicable state privacy laws) certain categories of Personal Information to third parties for purposes of targeted advertising or cross-contextual behavioral advertising. To opt-out of such sales or sharing, please visit our "Do Not Sell or Share My Personal Information" page or adjust your Cookie Settings.

In the preceding twelve (12) months, we have disclosed the following categories of Personal Information to the categories of third parties indicated in the chart below:

CATEGORIES OF THIRD PARTIES

Personal Information Category

Commercial or Business Purpose

Category of Third Party

Identifiers

Marketing, customer relationship management, web hosting, data storage

HubSpot, Google Analytics

Communications

Customer relationship management, data storage

HubSpot, Google Analytics

Internet or Network Activity

Marketing, web hosting, analytics

HubSpot, Google Analytics

Geolocation Information

Marketing, web hosting

HubSpot, Google Analytics

We may also share Personal Information about you to:

  • Comply with any court order, law, or legal process, including responding to any government or regulatory request;
  • A buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Elephas's assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding;
  • If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of Elephas, our customers, or others, including exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction; and
  • Enforce or apply our Terms of Service and other agreements.

HOW DO WE SECURE AND RETAIN PERSONAL INFORMATION?

We have reasonable security measures in place to protect against the loss, misuse, and alteration of any Personal Information we receive about you. We maintain reasonable security standards to protect the Personal Information that we maintain. For more information about Elephas's information security program, please visit our Trust Center at trustcenter.elephas.com. If you have any questions about the security of Personal Information about you, please contact us.

We will only store Personal Information as long as necessary to fulfill the purposes for which the information is collected and processed or, where the applicable law provides for longer storage and retention period, for the storage and retention period required by law. After that, Personal Information will be deleted, blocked, or anonymized, as provided by applicable law. In particular:

  • If you request that we delete your Personal Information, we will do so except to the degree legal requirements or other prevailing legitimate purposes dictate a longer storage.
  • Certain transactional data may be retained under statutory commercial and tax law requirements.
  • If you withdraw your consent on which processing of your Personal Information is based, we will delete your Personal Information without undue delay to the extent that the collection and processing was based on the withdrawn consent.

DOES ELEPHAS TRANSFER PERSONAL INFORMATION TO OTHER COUNTRIES?

To provide our Services, we may need to transfer and process Personal Information internationally (including to destinations outside the country in which you are located). As a result, your information may be transferred to and/or processed in countries which may not guarantee the same level of protection for Personal Information as the country in which you reside. However, we have taken appropriate safeguards to ensure that Personal Information about you will remain protected in accordance with this Notice. Further information can be provided on request: please contact us using the details found in the section "How can you Contact Elephas?"

HOW OLD DO I HAVE TO BE TO USE THE ELEPHAS SERVICES?

Online components of our Services are not directed to children under the age of 13 (or 14, depending on where you reside), and we do not knowingly collect Personal Information via online Services from children under those ages. If you think that we have collected Personal Information via an online Service from a child under those ages, please contact us as described below.

California Minors: If you are a California resident who is under age 18 and you are unable to remove publicly available content that you have submitted to us, you may request removal by contacting us at: security@elephas.com. When requesting removal, you must be specific about the information you want removed and provide us with specific information, such as the URL for each page where the information was entered, so that we can find it. We are not required to remove any content or information that: (1) federal or state law requires us or a third party to maintain; (2) was not posted by you; (3) is anonymized so that you cannot be identified; (4) you don't follow our instructions for removing or requesting removal; or (5) you received compensation or other consideration for providing the content or information.

WHAT ARE MY DATA PROTECTION CHOICES AND RIGHTS?

State consumer privacy laws may provide their residents with additional rights regarding our use of Personal Information. The following Section applies to individuals who reside in jurisdictions that provide additional privacy rights.

Your Rights and Choices

Right to Access Specific Information and Data Portability. You have the right to request that we disclose certain information to you about our collection and use of Personal Information over the past twelve (12) months, including: the categories of Personal Information we collected about you; the categories of sources for the Personal Information; our business or commercial purpose for collecting or selling that Personal Information; the categories of third parties with whom we share that Personal Information; the specific pieces of Personal Information we collected about you; and if we disclosed Personal Information for a business purpose, the business purpose for which it was disclosed.

Right to Correct Information. You have the right to request we update Personal Information about you that is incorrect in our systems.

Right to Delete. You have the right to request that we delete any Personal Information about you that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) the Personal Information from our records, unless an exception applies.

Right to Opt-out of the Sale or Sharing of Personal Information. You have the right to opt-out of the sale or sharing of your Personal Information for cross-contextual behavioral advertising. To exercise this right, visit our "Do Not Sell or Share My Personal Information" page.

Right to Limit Sensitive Personal Information Use. You have the right to limit the use of sensitive Personal Information regarding you.

Non-Discrimination. We will not discriminate against you for exercising any of your rights.

How to Exercise These Rights. To submit a request to exercise these rights, you may use one of these methods:

  • Email: security@elephas.com
  • Phone: (608) 622-7954
  • Mail: Elephas Biosciences Corporation, Attn: Privacy Inquiries, 1 Erdman Place, Suite 100, Madison, WI 53717

For all requests, please clearly state that the request is related to "Your Privacy Rights," indicate which type of request you are making, and provide your name, street address, city, state, zip code, and an email address or phone number where we may contact you.

Appeals. To appeal a decision regarding a consumer rights request, please submit your appeal using one of the methods above. Your appeal should include an explanation of the reason you disagree with our decision. Within 60 days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.

Only you, or a person registered with the applicable Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to Personal Information about you. You may only make such a request for access or data portability twice within a 12-month period.

We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded.

Opt-out Preference Signals. Our website honors Global Privacy Control ("GPC") opt-out preference signals when such signals are configured through your browser. You can get further help in configuring your browser by visiting: https://globalprivacycontrol.org/

California Shine the Light Law. California Civil Code Section 1798.83 permits users who are California residents to obtain from us once a year, free of charge, a list of third parties to whom we have disclosed Personal Information (if any) for direct marketing purposes in the preceding calendar year. If you are a California resident and you wish to make such a request, please send an email with "California Privacy Rights" in the subject line to security@elephas.com or write us at: Elephas Biosciences Corporation, Attn: Privacy Inquiries, 1 Erdman Place, Suite 100, Madison, WI 53717.

DOES THIS PRIVACY NOTICE CHANGE?

We may periodically update this Privacy Notice to describe new Services and how such Services may affect our collection and use of Personal Information. If we make material changes to this Privacy Notice, we will post a notice of the material changes on our website. If we use Personal Information about you for other purposes not specified in this Privacy Notice, we will notify you and obtain your consent, to the extent required by applicable law. We encourage you to periodically review this Privacy Notice for the latest information on our privacy practices.

HOW CAN YOU CONTACT ELEPHAS?

If you have questions or concerns about this Privacy Notice, our information practices, or any other aspect of the privacy and security of Personal Information about you, please contact us using the information below.

Elephas Biosciences Corporation

Attn: Privacy Inquiries

1 Erdman Place, Suite 100

Madison, WI 53717

United States

Email: security@elephas.com

Phone: (608) 622-7954

Information Security Policy

Last updated: 9/6/2024

1. Introduction

The goal of the Elephas Information Security Program is to protect the Confidentiality, Integrity, and Availability of the data employed within the organization while providing value to the way we conduct business. Protection of the Confidentiality, Integrity, and Availability are basic principles of information security, and can be defined as:

  • Confidentiality – Ensuring that information is accessible only to those entities that are authorized to have access, many times enforced by the classic “need to know” principle.
  • Integrity – Protecting the accuracy and completeness of information and the methods that are used to process and manage it.
  • Availability – Ensuring that information assets (information, systems, facilities, networks, and computers) are accessible and usable when needed by an authorized entity.

Elephas has recognized that our business information is a critical asset and as such our ability to manage, control, and protect this asset will have a direct and significant impact on our future success.

This document establishes the framework from which other information security policies may be developed to ensure that the enterprise can efficiently and effectively manage, control and protect its business information assets and those information assets entrusted to Elephas by its stakeholders, partners, customers and other third parties.

The Elephas Information Security Program is built around the information contained within this policy and its supporting policies. For additional information regarding our Information Security
program, please visit https://trustcenter.elephas.com

2. Purpose

The purpose of the Elephas Information Security Policy is to describe the actions and behaviors required to ensure that due care is taken to avoid inappropriate risks to Elephas, its business partners, and its stakeholders.

3. Audience

The Elephas Information Security Policy applies equally to any individual, entity, or process that interacts with any Elephas Information Resource.

4. Responsibilities

Executive Management

  • Ensure that an appropriate risk-based Information Security Program is implemented to protect the confidentiality, integrity, and availability of all Information Resources collected or maintained by or on behalf of Elephas.
  • Ensure that information security processes are integrated with strategic and operational planning processes to secure the organization’s mission.
  • Ensure adequate information security financial and personnel resources are included in the budgeting and/or financial planning process.

Information Security Team

  • Manage compliance with all relevant statutory, regulatory, and contractual requirements.
  • Participate in security related forums, associations and special interest groups.
  • Assess risks to the confidentiality, integrity, and availability of all Information Resources collected or maintained by or on behalf of Elephas.
  • Facilitate development and adoption of supporting policies, procedures, standards, and guidelines for providing adequate information security and continuity of operations.
  • Ensure that Elephas has trained all personnel to support compliance with information security policies, processes, standards, and guidelines. Train and oversee personnel with significant responsibilities for information security with respect to such responsibilities.
  • Ensure that appropriate information security awareness training is provided to company personnel, including contractors.
  • Implement and maintain a process for planning, implementing, evaluating, and documenting remedial action to address any deficiencies in the information security policies, procedures, and practices of Elephas.
  • Develop and implement procedures for testing and evaluating the effectiveness of the Elephas Information Security Program in accordance with stated objectives.
  • Develop and implement a process for evaluating risks related to vendors and managing vendor relationships.
  • Report annually, in coordination with the Information Security Team, to Executive Management on the effectiveness of the Elephas Information Security Program, including progress of remedial actions.
  • Ensure compliance with applicable information security requirements.
  • Formulate, review and recommend information security policies.
  • Approve supporting procedures, standards, and guidelines related to information security.
  • Assess the adequacy and effectiveness of the information security policies and coordinate the implementation of information security controls.
  • Review and manage the information security policy waiver request process.
  • Identify and recommend how to handle non-compliance.
  • Provide clear direction and visible management support for information security initiatives.
  • Promote information security education, training, and awareness throughout Elephas, and initiate plans and programs to maintain information security awareness.
  • Educate the team and staff on ongoing legal, regulatory and compliance changes as well as industry news and trends.
  • Identify significant threat changes and vulnerabilities.
  • Evaluate information received from monitoring processes.
  • Review information security incident information and recommend follow-up actions.

All Employees, Contractors, and Other Third-Party Personnel

  • Understand their responsibilities for complying with the Elephas Information Security Program.
  • Formally sign off and agree to abide by all applicable policies, standards, and guidelines that have been established.
  • Use Elephas Information Resources in compliance with all Elephas Information Security Policies.
  • Seek guidance from the Information Security Team for questions or issues related to information security.

Policy

Elephas maintains and communicates an Information Security Program consisting of topic-specific policies, standards, procedures and guidelines that:

  • Serve to protect the Confidentiality, Integrity, and Availability of the Information Resources maintained within the organization using administrative, physical and technical controls.
  • Provide value to the way we conduct business and support institutional objectives.
  • Comply with all regulatory and legal requirements, including:
    • All applicable federal, state, and local laws or requirements.

The information security program is reviewed no less than annually or upon significant changes to the information security environment.

5. Enforcement

Personnel found to have violated this policy may be subject to disciplinary action, up to and including termination of employment, and related civil or criminal penalties.

Any vendor, consultant, or contractor found to have violated this policy may be subject to sanctions up to and including removal of access rights, termination of contract(s), and related civil or criminal penalties.

Opt-out Policy

Last updated: June 11th, 2025

1. Introduction

This Opt-Out Policy outlines the procedures and mechanisms for individuals to opt out of certain activities or communications conducted by Elephas. We respect the privacy and preferences of our customers, users, and other individuals with whom we interact and provide clear and accessible options for them to exercise their right to opt out of specific interactions.

2. Purpose

The purpose of this Opt-Out Policy is to ensure transparency, fairness, and compliance with applicable privacy laws and regulations. It serves as a commitment to respecting the choices and preferences of individuals regarding marketing communications, data collection, and other activities that may impact their privacy.

3. Scope

This policy applies to all individuals who interact with Elephas, including customers, users, website visitors, and any other parties whose personal information may be collected, processed, or used for various purposes.

4. Opt-Out Mechanisms

4.1. Marketing Communications

4.1.1. Email Communications

Individuals have the right to opt out of receiving marketing emails and newsletters from Elephas. Every marketing email will include a clear and prominent "unsubscribe" link that allows recipients to opt out of future email communications.

4.1.2. SMS and Text Messages

For SMS or text message communications, individuals will be provided with clear instructions on how to opt out by replying with a designated keyword (e.g., "STOP"). Opting out through this method should cease further SMS communications.

4.1.3. Postal Mail

Individuals who wish to opt out of receiving postal mailings can contact Elephas by phone, email, or postal mail to request removal from the mailing list. Elephas will promptly update its records accordingly.

4.2. Data Collection and Cookies

4.2.1. Cookies and Tracking Technologies

Elephas will provide information on its website about the use of cookies and other tracking technologies. Individuals can adjust their browser settings to manage or block cookies or may choose to opt out of certain third-party tracking services if available.

4.2.2. Data Collection and Analytics

Individuals may have the option to opt out of data collection for analytics purposes through the use of browser plugins or settings provided by Elephas. Additionally, Elephas will clearly explain data collection practices in its privacy policy and provide opt-out instructions if applicable.

4.3. Telemarketing Calls

Individuals who receive telemarketing calls from Elephas have the right to opt out of future calls. Individuals can request their phone number to be added to the organization's "do not call" list.

5. Timing of Opt-Out Requests

Opt-out requests will be processed promptly and in accordance with applicable laws. Elephas will make reasonable efforts to ensure that individuals' preferences are respected, and they are not contacted for the specific activities they have opted out of.

6. Compliance

Elephas is committed to complying with all relevant data protection laws and regulations, including but not limited to the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), with respect to opt-out requests and data privacy rights.

7. Contact Information

Individuals who wish to exercise their right to opt out or have questions about this policy can contact Elephas using the following contact information:

  • Email: security@elephas.com
  • Phone: (608) 622-7954
  • Postal Address: 1 Erdman Place Suite 100, Madison, WI 53717

8. Review and Revision

This Opt-Out Policy will be reviewed and updated as necessary to ensure compliance with evolving privacy regulations and best practices. Any changes will be communicated to affected individuals as appropriate.

By implementing this Opt-Out Policy, Elephas aims to provide individuals with meaningful choices regarding their interactions with the organization while respecting their privacy preferences and rights.

icon-data

Our data

Read the latest data behind our platform.

icon-join-us

Join Us

We're always on the lookout for talented individuals to join our team.