Narbis legal / Consumer Health Data Privacy Policy

Document 02 of 12

Consumer Health Data Privacy Policy

Your consumer health data rights under Washington, Nevada, Connecticut and California law.

Effective 1 September 2026Last updated 1 October 2026Consumer health data, published separately as required

1. Why this is a separate policy#

1.1 This Consumer Health Data Privacy Policy is a standalone document. It is published separately from the Narbis Privacy Policy, it is reached from its own distinct link on the homepage of narbis.com labelled "Consumer Health Data Privacy Policy", and it is not merged into, summarized inside, or replaced by any other Narbis document. Washington and Nevada law require a dedicated consumer health data privacy policy with its own homepage link, and we maintain that separation deliberately.

1.2 The entity responsible for the data described here is Narbis, Corp., a Delaware corporation ("Narbis", "we", "us" or "our").

1.3 This policy tells you, in one place: the categories of consumer health data we collect and where each category comes from; why we collect it and the specific ways we use it; the categories we share; the categories of third parties and the specific affiliates we share it with; the two separate consents we ask for; and how you exercise your rights. If a category of consumer health data is not disclosed in this policy, we do not collect it, we do not use it, and we do not share it. That is a rule we hold ourselves to, and it is also the law in Washington.

1.4 How this fits with our other documents. The Narbis Privacy Policy describes everything we do with personal information generally, including information that is not consumer health data. The Narbis Cookie Notice describes cookies and similar technologies. The Narbis Subscription Terms of Service, Terms of Sale, End User License Agreement and Website Terms of Use govern the commercial and licensing relationship. Where the Privacy Policy and this policy both address the same data, both apply, and where this policy grants a stronger protection or a faster timeline, this policy controls for consumer health data.

1.5 If you train with a Practitioner. If your data reaches Narbis because a clinician, coach or other Practitioner uses the Narbis Platform with you, the document that describes your position is the Privacy Notice for End Users, Practitioner Context. Where the Practitioner is a HIPAA covered entity, the data Narbis handles for them is protected health information governed by HIPAA and by the Business Associate Agreement appended to the Narbis Practitioner Terms, and the Washington, Nevada, Connecticut and California consumer health data statutes exempt it on that basis. Where the Practitioner is not a covered entity, this policy applies to that data as well.


2. Who this policy protects#

2.1 This policy protects you if you are a natural person who is a resident of Washington, Nevada, Connecticut or California, and it protects you if your consumer health data is collected while you are physically in one of those states, whatever your residence.

2.2 Washington has no threshold. The My Health My Data Act, RCW ch. 19.373, applies to any legal entity that conducts business in Washington or produces a product or service targeted at Washington consumers and that determines the purpose and means of collecting consumer health data. There is no revenue floor, no data volume floor, and no small business exemption. Narbis sells the Smart Glasses and Narbis Edge to consumers in Washington and provides the Apps to them, so the Act applies to Narbis in full. We do not claim any threshold exemption and we do not build our practices around one.

2.3 We apply the substantive protections in this policy to every Narbis consumer in the United States, not only to residents of the four states named above. Running one high standard is simpler than running five, and it means a consumer who lives in a state with no consumer health data statute gets the same treatment as a consumer who lives in Washington.

2.4 "Consumer" does not include an individual acting in an employment context. Information we hold about a Narbis employee, contractor or job applicant in that capacity is governed by our employment privacy practices and not by this policy.

2.5 This policy covers our consumer channel. Narbis Edge is certified and sold in the United States and Canada only. The Smart Glasses are sold internationally, but not in the European Economic Area, the United Kingdom or Switzerland, where Narbis has offered no products or services since 1 October 2026. Nothing in this policy should be read to suggest that Edge is available outside the United States and Canada, or that any Narbis product is available in the European Economic Area, the United Kingdom or Switzerland.


3. The definitions we use#

3.1 These four definitions are used identically across the entire Narbis legal package.

"Neural Data" means information generated by measuring the activity of your central or peripheral nervous system, and that is not inferred from nonneural information. For Narbis this means the electroencephalographic (EEG) signal recorded by the Smart Glasses or by a compatible EEG headband, together with the frequency band values computed directly from that signal.

"Cardiac Data" means the photoplethysmographic (PPG) or electrocardiographic signal recorded by the Narbis ear clip or by a compatible heart rate sensor, the interbeat intervals derived from it, and heart rate variability values computed from those intervals.

"Derived Metrics" means the scores, indices, states and summaries that we compute from Neural Data or Cardiac Data, including coherence scores, engagement or focus indices, reward rate, session summaries and longitudinal trends.

"Neurophysiological Data" means Neural Data, Cardiac Data and Derived Metrics together.

3.2 In addition, in this policy:

"Smart Glasses" means the Narbis EEG neurofeedback smart glasses.

"Edge" means the Narbis Edge HRV biofeedback glasses, certified and sold in the United States and Canada only.

"Sensor Device" means any Narbis or third party device that measures Neurophysiological Data for use with the Services, including the Smart Glasses, Edge, the Narbis ear clip, and compatible third party EEG headbands and heart rate sensors.

"Apps" means the Narbis applications for iOS, watchOS, Android and the web.

"Platform" means the Narbis practitioner facing dashboard, its cloud services and its data stores, marketed as Edge Pro for coaches and NeuroPro for clinicians.

"Practitioner" means a clinician, coach or other professional who uses the Platform with their own clients or patients.

"Consumer health data" means personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present or future physical or mental health status, as that phrase is defined by the applicable state statute and described in the next section.

"Sale" means the exchange of consumer health data for monetary or other valuable consideration.


4. Your Narbis data is consumer health data, and we say so plainly#

4.1 Washington law defines consumer health data expansively, and it expressly includes:

a. bodily functions, vital signs, symptoms and measurements of the kind described in the definition of consumer health data;

b. biometric data, meaning data generated from the measurement or technological processing of an individual's physiological, biological or behavioral characteristics;

c. diagnoses, diagnostic testing, treatment and medications;

d. social, psychological, behavioral and medical interventions;

e. precise location information that could reasonably indicate an attempt to acquire or receive health services or supplies; and

f. critically, any information that is derived or extrapolated from information that is not health information, by any means, including by an algorithm or by machine learning.

4.2 We do not hedge about how that applies to us. Neurophysiological Data is consumer health data. Specifically:

a. Neural Data is consumer health data. An EEG recording is a direct measurement of central nervous system function. It is a bodily function and it is biometric data. It falls inside the definition without needing the derived data limb at all.

b. Cardiac Data is consumer health data. A PPG or electrocardiographic signal is a vital sign measurement, interbeat intervals are a bodily function measurement, and heart rate variability is a measure of autonomic, that is peripheral, nervous system activity. It is biometric data as well.

c. Every Derived Metric is consumer health data. A coherence score, an engagement or focus index, a stress index, a reward rate, a session summary and a longitudinal trend line are each computed from Neural Data or Cardiac Data by an algorithm. The derived data limb of the Washington definition was written for exactly this. A score is not less health data than the signal it came from. It is often more revealing, because it is interpretable.

4.3 We treat Cardiac Data with exactly the same protections as Neural Data throughout. It is genuinely unsettled whether heart rate variability is "neural data" under every state statute, and we are not interested in running a two track consent architecture in order to argue the point later. Both streams get the higher standard.

4.4 Neurophysiological Data is always sensitive data. We never describe it, treat it, or process it as ordinary personal information.


5. The categories of consumer health data we collect, and where each comes from#

5.1 We collect the categories set out in the table below and nothing else. Each row states the source.

Category What it is Source
Neural Data The EEG signal recorded during a training session, and the frequency band values computed directly from it. The Smart Glasses or a compatible EEG headband, transmitted through the Apps.
Cardiac Data The PPG or electrocardiographic signal, the interbeat intervals derived from it, and heart rate variability values. Edge, the Narbis ear clip, or a compatible heart rate sensor, transmitted through the Apps.
Derived Metrics Coherence scores, engagement or focus indices, stress indices, reward rate, session summaries and longitudinal trends. Computed by Narbis software from Neural Data and Cardiac Data. Derived, not directly measured.
Session and adherence records Session start and end time, duration, protocol used, number and pattern of sessions completed over time, and whether a session was completed or abandoned. Generated by the Apps and the Sensor Device during use.
Signal quality and artifact data Electrode contact quality, impedance indicators, motion artifact and noise measures. Generated by the Sensor Device and the Apps during a session.
Questionnaire and assessment responses Answers you give to in app questionnaires, symptom or wellbeing scales, and results of continuous performance tests where you take one. Provided directly by you.
Regional survey and band analysis Analysis of signal by scalp region and by frequency band, and the reports built from it. Computed by Narbis software from Neural Data.
Self reported health and goal information Any health information, symptom description, medication note, goal or reason for training that you choose to enter in the Apps or send to our support team. Provided directly by you.
Trainee profile information used with health data Name or nickname, year of birth or age band, and any note the account holder adds about the trainee, to the extent it is linked to the data above. Provided by the account holder.
Account identifiers linked to health data The account and device identifiers that link a session record to a person, including account identifier, email address and device identifier. Provided by you at sign up and generated by the Apps.
Device and technical data linked to health data Sensor Device model, serial number, firmware version, app version, operating system and connection diagnostics, where associated with a session. Generated by the Sensor Device and the Apps.
Support and correspondence records containing health information The content of a support request, warranty claim or safety report where you describe a health matter in it. Provided directly by you.
Purchase records that reveal a health product The fact that you bought a neurofeedback or biofeedback device, and the order records associated with it. Generated at checkout on narbis.com or narbis.shop, or by an authorized reseller who passes the order to us.

5.2 Precise location. We do not collect precise geolocation. We derive an approximate region, at country and state or province level, from your internet protocol address and from your billing address, for tax, shipping, product availability and regional legal compliance. We do not use location information to infer anything about your health, and we do not collect location for that purpose. See the section titled "Our unconditional geofencing commitment".

5.3 What we do not collect. We do not collect genetic data. We do not collect facial images, fingerprints, voiceprints or iris scans. We do not collect data about reproductive or sexual health, gender affirming care, or the use of prescription medication, other than what you volunteer in a free text field, and we ask you not to volunteer it because we do not need it. We do not buy consumer health data from data brokers, and we do not receive consumer health data from advertising networks, social platforms or list vendors.

5.4 Audio, video, camera and typed content. We do not capture audio, video or camera input at any point in the Apps, including during calibration, setup or a training session. We do not operate an in app chat, coaching or large language model feature that retains what you type. Confirmed as at the effective date. If either changes, this section is updated and the category is disclosed here before any collection begins, because under RCW 19.373 we may not collect a category that is not disclosed in this policy.


6. Why we collect consumer health data, and the specific ways we use it#

6.1 We collect and use consumer health data for the purposes below, and for no other purpose. Each entry states what we actually do, not a category label.

a. To deliver a training session. We read the EEG or cardiac signal from the Sensor Device in real time, compute the frequency band values or interbeat intervals from it, compare them against the active protocol, and drive the feedback, which for the Smart Glasses means changing the tint of the lenses and for the Apps means the on screen and audio feedback. Without this the product does not function.

b. To show you your own results. We store session records and Derived Metrics so that you can see your session history, your progress over time, and your adherence.

c. To compute Derived Metrics. We run algorithms over Neural Data and Cardiac Data to produce coherence scores, engagement or focus indices, stress indices, reward rate, session summaries and longitudinal trend lines, and we display those to you.

d. To run regional survey and band analysis and produce reports where you use that feature, so that you and, if you choose, a Practitioner you share with can see analysis by scalp region and frequency band.

e. To adjust the protocol. We use your recent results to set thresholds and to adapt the difficulty of the feedback, so that training stays in a useful range.

f. To assess signal quality and warn you. We use impedance, contact and artifact measures to tell you when a Sensor Device is not seated correctly and when a session is not usable.

g. To score questionnaires and continuous performance tests you complete, and to show you those scores alongside your session data.

h. To provide support and honor the warranty. We look at session and device records to diagnose a fault, answer a support question, and process a warranty claim or a return.

i. To keep the Services secure and to prevent fraud and abuse, including detecting unauthorized access to an account and detecting misuse of a Sensor Device.

j. To maintain and debug the Services, which means engineering personnel may need to inspect a specific record to fix a specific fault. That access is logged and limited as described in the section titled "Data minimization and who inside Narbis can see your data".

k. To meet legal obligations, including product safety obligations, tax and accounting record keeping, responding to lawful legal process, and keeping the authorization and consent records that Washington and Nevada law require us to keep.

l. To carry out safety monitoring, meaning to identify a pattern in session data that suggests a device fault or a safety issue that we are required to investigate.

m. For research and product improvement, only if you opt in, and only on de-identified data. This is off by default. It is a separate opt in from every other consent. If you turn it on, we use data de-identified to the standard in 45 C.F.R. 164.514, by Safe Harbor or by Expert Determination, to evaluate and improve protocols and algorithms and to conduct or support research. We contractually commit not to attempt to re-identify that data and we bind any recipient to the same commitment. If you turn it off, we stop using your data for this purpose going forward.

6.2 Purposes we exclude. We do not use consumer health data for advertising, for marketing to you based on your health data, for profiling that produces legal or similarly significant effects about you, for insurance, credit, employment or housing decisions, or for training a general purpose machine learning model on identifiable data. We do not sell it. See the section titled "We do not sell consumer health data".


7. What we share, who we share it with, and the specific affiliates#

7.1 Categories of consumer health data we share. We share the following categories, and only in the circumstances described in this section:

a. Neural Data and Cardiac Data;

b. Derived Metrics;

c. session and adherence records, and signal quality data;

d. questionnaire, assessment and continuous performance test responses;

e. regional survey and band analysis and the reports built from it;

f. account identifiers and device and technical data where linked to the above; and

g. support and correspondence records containing health information.

7.2 Categories of third parties we share with. Each of these acts on our documented instructions under a written contract that limits them to the purpose we specify, requires confidentiality and appropriate security, prohibits any use of the data for their own purposes, prohibits any sale, and requires deletion or return at the end of the engagement.

Category of third party What they receive Why
Cloud infrastructure and hosting providers All categories, at rest and in transit, encrypted. To operate the servers, storage and databases that hold your data.
Database and data storage providers All categories. Storage, indexing and backup of session and account records.
Error and crash reporting Device and technical data, and session identifiers. Never Neural Data, Cardiac Data or Derived Metrics. To detect crashes and faults. Error reports are generated in the App and sent to a Narbis mailbox. We do not use a third party crash reporting service. If we ever add one, it is named on the subprocessor page before it is switched on.
Customer support platform providers Support and correspondence records, which may contain health information you chose to include, plus account identifiers. To receive, route and answer your support requests.
Security, logging and threat detection providers Access logs, device and technical data, and account identifiers. To detect and investigate unauthorized access and security incidents.
Payment and order processing providers The fact of a purchase and order records. They do not receive Neurophysiological Data. To take payment and fulfil an order.
Practitioners you choose to connect with The categories you select when you connect, which you control and can revoke. So a clinician or coach you have chosen can see your data.
Professional advisers, being lawyers, auditors and insurers, under professional duties of confidentiality Only what is necessary for a specific matter. Legal advice, audit and insurance.
Government authorities, courts and law enforcement Only what a valid legal demand actually requires. To comply with law. We assess every demand, we require lawful process, we object to an overbroad demand, and we notify you unless we are legally prohibited from doing so.
An acquirer in a merger, acquisition, reorganization or sale of assets The categories that are part of the transaction. Corporate transaction. See paragraph 7.6.

7.3 We do not share consumer health data with advertising networks, advertising technology providers, social media platforms, data brokers, list vendors, marketing analytics providers, or any recipient whose business is the monetization of personal information. That exclusion is unconditional.

7.4 Specific affiliates. Washington law requires us to name the specific affiliates with whom we share consumer health data, and not merely to describe them as a category. No other United States privacy statute imposes that requirement, and we meet it directly.

Narbis, Corp. does not currently share consumer health data with any affiliate. Narbis, Corp. is the only entity in the group that collects, holds or processes consumer health data. There is no parent company, subsidiary, sister company or commonly controlled entity that receives it. 7.5 What sharing requires. Except where a disclosure is strictly necessary to provide a product or service you have requested, or is required by law, we share consumer health data only with your separate, specific, opt in consent, obtained before the sharing begins, as described in the section titled "The two separate consents we ask for". Where we can name a recipient specifically, we name it specifically in the consent request rather than describing it as a category.

7.6 Corporate transactions. If Narbis is involved in a merger, acquisition, reorganization or sale of assets, consumer health data may transfer as part of that transaction. We will notify affected consumers before the transfer takes effect, the acquirer will be bound to this policy for data collected before the transfer, and if the acquirer intends to process the data for a purpose that is materially different from the purposes stated here, it must obtain fresh consent before doing so. A change of ownership does not by itself unlock a new use.

7.7 Every one of these recipients is named specifically. The categories above tell you what kind of recipient receives what. The specific entities behind each category, with the purpose, the categories they receive, the processing location and whether a Business Associate Agreement is in place, are published at narbis.com/legal/subprocessors and kept current. Washington law requires the specific names rather than the categories alone, and that page is how we meet it. We update that page before adding a provider that will handle consumer health data, and because sharing with a recipient not previously disclosed requires fresh consent, we obtain that consent before any data moves.


8. We do not sell consumer health data#

8.1 Narbis does not sell consumer health data. We never have and we do not intend to. This is stated without qualification. There is no "except with your permission" hedge, no "we may sell in a future business model" reservation, and no exception for de-identified data sold as a product.

8.2 We also do not use consumer health data for advertising, and we do not share it with advertising networks or data brokers.

8.3 It is worth explaining why the commitment is absolute rather than conditional, because the alternative is not attractive to anyone.

a. Under Washington law, selling consumer health data requires a valid authorization that is separate and distinct from consent to collect and consent to share. The authorization must be signed by the consumer, must identify the specific data being sold, the name and contact information of both the seller and the purchaser, a description of the purpose, a statement that the data may be subject to redisclosure, an expiration date, and a statement of the right to revoke. A copy must be given to the consumer, and both the seller and the purchaser must retain the signed authorization for six years.

b. Under Nevada law, a comparable authorization is required and it expires no later than one year after it is signed, which means a consumer would have to be asked again every year.

c. Selling would also require us to abandon the position that makes this product trustworthy. A neurofeedback company that sells brain data is not a company we want to run.

8.4 We have therefore chosen not to sell, and we have built the systems and contracts to match that choice rather than to preserve the option. If that position ever changed, it would require a change to this policy, prior notice to you, and a signed authorization from you before any data moved. Continuing to use the Services would not be enough, and it would never be enough.

8.5 We do not sell, license or otherwise make available de-identified data derived from consumer health data as a commercial product.


9. The two separate consents we ask for#

9.1 There are two consents, they are asked for separately, and one is never treated as the other.

9.2 Consent to collect. We collect consumer health data on one of two bases, and no others:

a. What is necessary to provide what you asked for. If you start a training session, we must read the signal from the Sensor Device, compute the band values or interbeat intervals, and store the session record, because that is the product. We rely on necessity only for what is genuinely necessary, and we read "necessary" narrowly.

b. Your separate opt in consent for anything beyond that. Collection that is not strictly necessary to deliver the product or service you requested happens only if you say yes first. This includes collecting questionnaire and assessment responses beyond a session, collecting self reported health and goal information, collecting data for research and product improvement, and retaining raw signal beyond what a session requires.

9.3 Consent to share. Separately, and by a distinct affirmative act, we ask for your consent before sharing consumer health data with a third party, except where a disclosure is strictly necessary to provide what you requested or is required by law. Consent to collect is not consent to share. Saying yes to collection never causes sharing to begin.

9.4 What a consent request tells you. Before you decide, each request states, in plain language and in the request itself rather than by a link you have to chase:

a. the specific categories of consumer health data that would be collected or shared;

b. the specific purpose, including the specific ways the data would be used;

c. for a sharing consent, the categories of third parties and, where we can identify them, the specific recipients by name;

d. how long the data would be retained; and

e. how to withdraw the consent, and that withdrawing is as easy as giving.

9.5 Consent is granular by purpose. Each purpose has its own control. Turning on research and product improvement does not turn on anything else. Connecting to one Practitioner does not connect you to another.

9.6 Withdrawal. You can withdraw any consent at any time, in the Apps under Settings and then Privacy, or by writing to info@narbis.com. Withdrawal is as easy as giving consent and takes no more steps. We honor a withdrawal promptly and in any event within 15 days, we stop the relevant collection or sharing going forward, and we notify recipients to stop as described in the section titled "Your rights". Withdrawing consent does not make our earlier processing unlawful, and it does not by itself delete data already collected, so if you want deletion as well, ask for deletion and we will do both.


10.1 Consent means a clear affirmative act that signifies your freely given, specific, informed, opt in, voluntary and unambiguous agreement. We obtain it before collection or sharing begins, not afterwards.

10.2 None of the following is consent, and we will never treat any of it as consent:

a. your acceptance of a general or broad terms of use, terms of service, end user license agreement, purchase agreement, or any other Narbis contract. Consent to collect or share consumer health data is never bundled into acceptance of terms;

b. hovering over, muting, pausing, swiping past, scrolling past, or closing a banner, dialog, notice or any other piece of content;

c. continuing to browse, continuing to use the Apps, or the passage of time;

d. a pre ticked box, a toggle switched on by default, a slider preset to accept, or any other default that treats silence as agreement;

e. an agreement obtained through a deceptive design, meaning an interface designed or manipulated to subvert or impair your autonomy, decision making or choice. That includes making the accept option more prominent than the decline option, hiding the decline option behind extra steps, using confusing double negatives, repeatedly re-asking after you have declined, or implying that the product will not work if you decline something that is not in fact necessary;

f. consent given by someone other than you, or by an adult account holder purporting to consent on behalf of an adult trainee; or

g. consent to collect, treated as consent to share. These are separate and we keep them separate.

10.3 Declining a consent, or withdrawing one, does not degrade the parts of the Services that do not depend on it. We do not withhold a feature that works without the data as a way of pressuring you to say yes, and we do not charge a different price because you declined.

10.4 We keep a record of each consent: what you were shown, what you agreed to, the version of the request, and when. We keep that record so that we can demonstrate your consent if we are asked to, and we keep it for as long as the law requires.


11. Your rights#

11.1 You have the following rights in relation to your consumer health data. They are available to you free of charge, and you can exercise them regardless of which state you live in.

11.2 The right to know and to access. You can ask us to confirm whether we are collecting, sharing or selling your consumer health data, and to give you a copy of it. When you make an access request we will provide:

a. confirmation of whether we collect, share or sell your consumer health data, and we will confirm that we do not sell it;

b. a copy of the consumer health data we hold about you, in a portable and readily usable format;

c. the categories we collect, the sources, the purposes of collection and use, and the categories we share;

d. a list of all third parties and affiliates with whom we have shared your consumer health data, and an active email address or other online contact mechanism for each of them, so that you can contact each recipient yourself. This is a specific Washington requirement and we meet it as stated, naming each recipient rather than describing categories; and

e. the retention period that applies to each category.

11.3 The right to withdraw consent. You can withdraw your consent to the collection of your consumer health data, to the sharing of it, or to both, as described in the section titled "The two separate consents we ask for". You may withdraw one consent and keep another.

11.4 The right to delete. You can ask us to delete your consumer health data. When you do:

a. we delete it from our active production systems, and from our archives, within 30 days of receiving your request;

b. we delete it from backup and disaster recovery systems as those systems cycle, and in any event within 35 days of the deletion from primary systems, consistent with our published retention schedule. Data in a backup awaiting its cycle is not restored to production and is not used for any purpose in the meantime;

c. we notify every third party and affiliate with whom we have shared that data, and instruct each of them to delete it, and we ask each to confirm. We do this within 30 days of your request; and

d. we tell you when it is done, and we tell you if any part of it cannot be done and why.

11.5 Limits on deletion, stated honestly. We may retain a narrow set of records after a deletion request, and we will tell you which ones apply to you:

a. the consent and authorization records that Washington and Nevada law require us to keep, which we keep for six years and use for no purpose other than demonstrating compliance;

b. purchase, warranty and support records needed for tax, accounting and product safety obligations, which we keep for seven years;

c. a minimal suppression record, meaning your identifier and the fact that you asked for deletion, so that we can honor the deletion and not re-collect the same data;

d. records we are required to preserve by a legal hold or lawful legal process; and

e. data already de-identified to the standard in 45 C.F.R. 164.514, which is no longer linked or reasonably linkable to you and which we commit contractually not to attempt to re-identify.

Nothing else is retained after a deletion request.

11.6 The right to appeal. If we decline a request, you can appeal. See the section titled "How to make a request, our timelines, and how to appeal".

11.7 Rights under other laws. Your rights under the Washington My Health My Data Act are in addition to, and not in place of, any right you have under the California Consumer Privacy Act, the Connecticut Data Privacy Act, the Nevada privacy statutes, or any other law. Exercising a right here does not waive a right elsewhere. The Narbis Privacy Policy describes the broader set of rights that apply to your personal information generally.

11.8 We will not discriminate against you for exercising any right in this policy. We will not deny you a product or service, charge you a different price, give you a lower quality of service, or suggest that you will receive any of those, because you exercised a right.


12. How to make a request, our timelines, and how to appeal#

12.1 How to make a request. Use any of these routes:

a. in the Apps, under Settings and then Privacy, where access, download, consent withdrawal and deletion are available as self service controls;

b. by email to info@narbis.com, with "Consumer health data request" in the subject line; or

c. through the request form at narbis.com/contact.

12.2 Authorized agents. You may use an authorized agent. We will ask the agent for written proof of authority signed by you, and we may ask you to confirm directly that you authorized the request.

12.3 Verification. Before we act on a request for access or deletion, we verify that the request comes from you. We match the request against information already in your account. Where the request involves Neurophysiological Data, we may ask for an additional confirmation step, because the data is sensitive and a wrongful disclosure cannot be undone. We ask only for what is needed to verify, we do not use verification information for any other purpose, and we delete it when verification is complete. If we cannot verify you, we will tell you why and what would let us verify.

12.4 Our timelines.

a. We acknowledge a request within 10 days.

b. We respond substantively within 45 days of receiving the request.

c. Where the request is complex or we have received a number of requests from you, we may take one extension of a further 45 days. We will tell you within the first 45 days that we are extending, and why.

d. We honor a withdrawal of consent within 15 days, and stop the relevant collection or sharing going forward.

e. We complete a deletion within 30 days, including notifying downstream recipients, and we purge backups within 35 days of the primary deletion.

f. Some states allow longer than 45 days for some requests. We apply the 45 day standard to everyone, because running one clock is simpler and it meets or beats each state's requirement.

12.5 Cost. Responses are free. If a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee or decline, and if we do we will explain why and tell you how to appeal. We do not expect to use this and we will not use it to discourage a genuine request.

12.6 Appeals.

a. If we refuse a request in whole or in part, our response will explain the reason and will tell you how to appeal, including a direct email route.

b. To appeal, write to info@narbis.com with "Appeal" in the subject line, within 60 days of our response. Tell us what you asked for and why you think our answer was wrong.

c. An appeal is reviewed by someone who was not involved in the original decision.

d. We respond to an appeal in writing within 45 days of receiving it, explaining the reasons for our decision.

e. If we deny the appeal, we will give you a method to contact the Attorney General of your state to submit a complaint, and we will provide the relevant online complaint route in our decision.


13. Data minimization and who inside Narbis can see your data#

13.1 We collect the minimum. We collect only what is necessary to provide the product or service you have asked for, or what you have separately consented to. We do not collect a category because it might be useful later. When a purpose ends, the collection for that purpose stops.

13.2 Access inside Narbis is restricted to personnel for whom access is necessary. Nobody at Narbis has standing access to consumer health data by virtue of working here. Specifically:

a. access is granted on a role basis, and only to personnel whose job actually requires it, which in practice means a small number of support, engineering, security and clinical quality staff;

b. access is granted for a defined purpose and, where possible, for a defined period, and it is removed when the role changes or the person leaves;

c. every access to identifiable consumer health data is logged, and the logs are reviewed;

d. all personnel with access are bound by written confidentiality obligations and are trained on the handling of sensitive health data before access is granted;

e. we use de-identified or aggregated data for any internal task that does not require identifiable data, which includes most analysis and most engineering work; and

f. access rights are reviewed on a regular schedule and any access that is no longer necessary is removed.

13.3 The same restrictions are imposed contractually on every third party that processes consumer health data on our behalf.

13.4 The practitioner estate is separate. Data held in the Platform for a Practitioner is kept logically and contractually separate from the direct to consumer estate. Protected health information we hold as a business associate does not commingle with consumer data, and consumer data does not flow into the business associate environment.


14. How long we keep consumer health data#

14.1 We state retention in numbers, not in adjectives. The schedule below applies.

Data Retention Then
Raw Neural Data and Cardiac Data 24 months from collection Deleted, or de-identified where you have opted into research
Derived Metrics Life of the account plus 12 months Deleted
Account and profile data Life of the account plus 24 months of inactivity Deleted
Purchase, warranty and support records 7 years Deleted. Driven by tax and warranty obligations
Data of a trainee under 13 Raw signal 12 months, all data deleted within 90 days of account closure Deleted
Washington and Nevada authorization and consent records 6 years, statutory Retained then deleted
Backups Purged within 35 days of primary deletion Deleted
Protected health information held as a business associate Per the covered entity's instruction, default return or destroy within 30 days of termination Returned or destroyed

14.2 We do not retain consumer health data indefinitely. Indefinite retention is prohibited outright for children's data and is indefensible for everything else.

14.3 You can ask for deletion sooner at any time, and we will act on it as described in the section titled "Your rights".

14.4 When a retention period ends, deletion happens on a scheduled job rather than on request, so that the schedule is enforced whether or not anyone is watching.


15. Our unconditional geofencing commitment#

15.1 Narbis does not use, and will never use, a geofence around or near any health care facility. This commitment is unconditional. It is not subject to your consent, because we do not want the option, and consent would not make it acceptable.

15.2 Specifically, and everywhere we operate, we do not and will not:

a. establish a virtual boundary, by any means, around any health care facility, health care provider location, hospital, clinic, mental health facility, substance use treatment facility, reproductive or sexual health facility, pharmacy, or any other location where health services or supplies are provided or obtained;

b. use any such boundary to identify or track a consumer seeking health care services;

c. use any such boundary to collect consumer health data;

d. use any such boundary to send a notification, message or advertisement relating to consumer health data or health care services; or

e. instruct, permit or pay any third party to do any of the above on our behalf.

15.3 We state this as one global commitment rather than as a recitation of each state's radius, because the radii differ and the principle does not. Washington prohibits the practice outright with no consent exception. Connecticut prohibits it within a stated distance of mental health and reproductive health facilities. California prohibits it and attaches a private right of action with treble damages. Vermont will prohibit it within a stated distance. We do not track which line we are inside. We do not do it anywhere.

15.4 We do not collect precise geolocation from the Apps for any purpose. See paragraph 5.2. Removing the capability is a stronger commitment than promising not to misuse it, so that is the approach we take.


16. Washington: the My Health My Data Act#

16.1 This section is provided for Washington consumers, and for anyone whose consumer health data is collected while they are in Washington.

16.2 The Act applies to Narbis in full. RCW ch. 19.373 has no revenue threshold and no data volume threshold. It applies to any legal entity that conducts business in Washington or produces a product or service targeted at Washington consumers and determines the purpose and means of collecting consumer health data. Narbis does both. We do not claim an exemption.

16.3 We meet the specific disclosure requirements of the Act. This policy states, as the Act requires: the categories of consumer health data we collect and the sources of that data, in the section titled "The categories of consumer health data we collect, and where each comes from"; the purposes of collection and the specific ways the data is used, in the section titled "Why we collect consumer health data, and the specific ways we use it"; the categories of consumer health data that are shared, the categories of third parties, and the specific affiliates with whom the data is shared, in the section titled "What we share, who we share it with, and the specific affiliates"; and how a consumer exercises rights, in the sections titled "Your rights" and "How to make a request, our timelines, and how to appeal".

16.4 We do not collect, use or share a category that is not disclosed here. The Act prohibits it, and this policy is written to be complete rather than to leave room. Where a category is not yet settled we have said so in a marked drafting note rather than covering it with a vague catch all. Before this policy publishes, every such note is resolved and removed.

16.5 Consent. We obtain consent to collect that is separate and distinct from consent to share, as described in the sections titled "The two separate consents we ask for" and "What we never treat as consent". Neither consent is obtained through acceptance of general terms, through hovering, muting, pausing or closing content, or through any deceptive design.

16.6 No sale, and no authorization sought. We do not sell consumer health data, so we do not seek and do not hold a valid authorization under RCW 19.373.030. If we ever did, the authorization would have to be separate from both consents, contain every element the statute requires, be signed by you, be copied to you, and be retained by both Narbis and the purchaser for six years. We have chosen not to sell instead.

16.7 Geofencing. RCW 19.373.040 prohibits implementing a geofence around a facility providing in person health care services where the geofence is used to identify or track consumers seeking health care, collect consumer health data, or send health related messages or advertising. There is no consent exception. Our commitment goes further and is set out in the section titled "Our unconditional geofencing commitment".

16.8 Enforcement, stated plainly. A violation of the My Health My Data Act is a per se violation of the Washington Consumer Protection Act, RCW ch. 19.86. That means it can be enforced by the Washington Attorney General, and it also carries a private right of action, under which a consumer may recover actual damages, which a court may treble subject to the statutory cap, together with costs and reasonable attorneys' fees. We are aware that this is the highest exposure in our legal package, and we have written this policy, and built the practices behind it, to be accurate rather than aspirational. If a statement in this policy is not true of the running system, it does not publish.

16.9 Washington contact. Questions about this section go to info@narbis.com. If you are not satisfied after an appeal, you may complain to the Washington State Office of the Attorney General through its consumer complaint process.


17. Nevada: consumer health data under SB 370#

17.1 Nevada's consumer health data law, enacted by Senate Bill 370 and codified in NRS Chapter 603A, applies to Narbis as a regulated entity collecting consumer health data about Nevada consumers.

17.2 The Nevada framework closely tracks Washington's. In particular:

a. we do not collect consumer health data about a Nevada consumer except with affirmative, voluntary consent, or to the extent necessary to provide a product or service the consumer has requested;

b. we do not share consumer health data except with a separate consent or where necessary to provide what was requested;

c. we honor the rights of confirmation, access, a list of the third parties with whom data has been shared, deletion, and withdrawal of consent, on the terms set out in the section titled "Your rights"; and

d. we do not implement a geofence around a health care facility, as set out in the section titled "Our unconditional geofencing commitment".

17.3 Sale. We do not sell consumer health data. Under Nevada law a sale would require a signed authorization containing prescribed elements, and that authorization expires no later than one year after it is signed, which means a Nevada consumer would have to be asked again annually. We have chosen not to sell rather than to run an annual re-authorization cycle.

17.4 Timelines. Nevada permits a response within 60 days with a further 30 day extension. We apply our standard 45 day response with one 45 day extension to Nevada consumers as well, which is faster than the statute requires in the ordinary case.

17.5 The Nevada law is enforced by the Nevada Attorney General, and a violation is a deceptive trade practice. Questions go to info@narbis.com.


18. Connecticut: consumer health data under SB 3#

18.1 Connecticut protects consumer health data through the Connecticut Data Privacy Act as amended by Senate Bill 3. Consumer health data is treated as sensitive data.

18.2 For Connecticut consumers:

a. we process consumer health data only with your consent, obtained by a clear affirmative act and never through a dark pattern. Under Connecticut law an agreement obtained through a dark pattern is not consent, and we treat it that way;

b. we do not sell consumer health data. Connecticut prohibits the sale of consumer health data without consent, and our position is that we do not sell it at all;

c. you have the rights to confirm and access, to correct, to delete, to obtain a portable copy, and to opt out of targeted advertising, sale and certain profiling. We do not conduct targeted advertising using consumer health data, we do not sell it, and we do not conduct profiling that produces legal or similarly significant effects using it, so those opt outs have nothing to switch off in our case;

d. we honor a universal opt out preference signal, including Global Privacy Control, where your browser or device sends one. How we handle it is described in the Narbis Cookie Notice and the Narbis Privacy Policy;

e. we respond within 45 days with one 45 day extension, and we operate the appeal process described in the section titled "How to make a request, our timelines, and how to appeal"; and

f. we do not establish a geofence around any mental health facility or reproductive or sexual health facility. Connecticut sets that boundary at 1,750 feet. Our commitment carries no distance because it carries no exception.

18.3 The Connecticut Data Privacy Act is enforced by the Connecticut Attorney General. There is no private right of action under that Act. Questions go to info@narbis.com.


19. California: AB 45 and health data#

19.1 California Assembly Bill 45 adds protections for health data on top of the California Consumer Privacy Act. It matters to us for two reasons.

19.2 Geofencing. AB 45 prohibits establishing a geofence around a family planning or other covered health care facility in order to identify or track individuals, collect their data, or deliver advertising or messages to them. Unlike the Connecticut and Washington provisions, the California prohibition carries a private right of action with treble damages, so a single violation is directly actionable by the individual affected. Narbis does not geofence anywhere, for any reason, as set out in the section titled "Our unconditional geofencing commitment", and we do not collect precise geolocation at all.

19.3 Health data handling. AB 45 restricts the sale and sharing of health data and constrains the use of health data for advertising. Narbis does not sell consumer health data, does not share it for cross context behavioral advertising, and does not use it for advertising of any kind.

19.4 CCPA rights. Neurophysiological Data is sensitive personal information under the California Consumer Privacy Act, and neural data is expressly named as sensitive personal information in California law. As a California consumer you have the rights to know, access, correct, delete, obtain a portable copy, limit the use and disclosure of sensitive personal information, and opt out of sale and sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we use sensitive personal information only for the purposes permitted without a limitation right, so the limitation right has nothing to switch off in our case. You may still exercise it and we will confirm that position to you in writing. The full description of your California rights, including how we handle authorized agents and how we treat opt out preference signals, is in the Narbis Privacy Policy.

19.5 We do not discriminate against a California consumer for exercising any right, and we do not offer a financial incentive in exchange for consumer health data.

19.6 Questions go to info@narbis.com. You may also complain to the California Privacy Protection Agency or the California Attorney General.


20. Security#

20.1 We protect consumer health data with administrative, technical and physical safeguards appropriate to how sensitive it is, and we treat Neurophysiological Data as our highest sensitivity tier.

20.2 Those safeguards include encryption in transit and at rest, role based access control with least privilege, multi factor authentication for administrative access, logging and monitoring of access to identifiable data, network segmentation between the practitioner estate and the direct to consumer estate, secure software development practices, vulnerability management and patching, background checks and confidentiality obligations for personnel with access, written security requirements imposed on every processor, and a documented incident response plan that is tested.

20.3 No system is perfectly secure, and we do not claim otherwise. If a breach of consumer health data occurs, we will notify affected consumers and the relevant regulators as required by law. Because Narbis is not a HIPAA covered entity in the consumer channel, notification in that channel is governed by state breach notification law and by the Federal Trade Commission's Health Breach Notification Rule, which applies to a vendor of personal health records and which we treat as applicable to us.

20.4 To report a suspected vulnerability or incident, write to info@narbis.com.


21. Children and trainees#

21.1 Only an adult aged 18 or over may create a Narbis account and agree to our terms. An account holder may add a trainee aged 6 or over to their account.

21.2 Compatible third party sensors are subject to their own manufacturer's minimum age requirement, which may be higher than the Narbis minimum. Where a manufacturer sets a higher minimum age, that higher age applies to any use of that device with a Narbis product, and we do not permit a trainee below that age to pair it. The Narbis Privacy Policy sets this out in the section titled "Children and trainees".

21.3 Where the trainee is under 13, we obtain verifiable parental consent from the account holder before any Neurophysiological Data is collected from the trainee. That consent is separate from consent to any third party disclosure, and the two are never bundled.

21.4 The under 13 experience is designed to run with no third party software development kits, so that no third party receives a child's data at all.

21.5 Consumer health data of a trainee under 13 is retained on the shorter schedule in the section titled "How long we keep consumer health data": raw signal for 12 months, and all data deleted within 90 days of account closure.

21.6 A parent or guardian may exercise every right in this policy on behalf of a trainee under 18 on the account. A trainee aged 13 to 17 may also contact us directly at info@narbis.com and we will work with them and with the account holder.


22. Changes to this policy#

22.1 If we change this policy we will update the Last Updated date and post the revised policy at its canonical location, reached from the distinct homepage link on narbis.com.

22.2 A material change does not apply retroactively to data we already hold. If we want to collect a new category, use consumer health data for a new purpose, or share it with a recipient we have not disclosed, we will tell you before the change takes effect and we will obtain fresh consent for the new collection, use or sharing. Continuing to use the Services is not consent to a new purpose, and it never will be.

22.3 We keep prior versions of this policy available so that you can see what applied when.


23. How to reach us#

How to reach us
Email: info@narbis.com
Web: narbis.com/contact

One mailbox handles everything. To help us route your message quickly, please begin your subject line with one of these words where it applies: Privacy, Legal, Practitioner, Security or Appeal. We read everything either way.

23.1 For anything in this policy, including a request to access, withdraw consent, delete, or appeal, write to info@narbis.com with "Consumer health data request" in the subject line, or use the form at narbis.com/contact. We acknowledge within 10 days and respond within 45 days, as described in the section titled "How to make a request, our timelines, and how to appeal".