AEDIT, LLC

Privacy Policy

Effective Date: February 9, 2020



This Privacy Policy explains how AEDIT may collect, use, disclose and otherwise process personal information in connection with our website, mobile applications (including The AEDITOR app), and the services we provide in connection with the apps and websites (collectively, the “Platform”). The Privacy Policy also describes the rights and choices available to you regarding your personal information. The term “AEDIT,” “we,” and “us” includes AEDIT, LLC and our affiliates and subsidiaries.

AEDIT is an expert portal for beauty treatments, brought to you by the doctors and editors that matter. Our website and The AEDITOR app are directed at two types of users:

  • Trusted providers and medical experts who use the Platform to advertise their practices and connect with potential patients (“Providers”); and
  • Consumers who wish to learn about cosmetic procedures and locate and connect with Providers (“Users”). Our AEDITor app also lets Users edit their photo to see what they may look like with a certain cosmetic enhancement. In addition, Users can direct us to share their information with Providers with whom they wish to connect through the Platform.

INFORMATION AEDIT COLLECTS

We collect the following types of personal information in connection with the Platform:

From Users:

  • • Account Information. When you create a User account on the Platform (an “Account”), you will provide us with certain personal information, such as your user name and password. If you log in to your Account through a third-party platform, such as Google, we may collect the information that you allow the third-party platform to provide to us, based on your privacy settings with that third party (such as your email address and calendar information). Our processing of the information we obtain from third-party platforms is governed by the requirements these third-party platforms impose on us in their relevant terms and conditions.
  • • User Contact Information. When you register for an Account or otherwise interact with us, we may collect your name, email address, mailing address, and phone number.
  • • Demographic Information. When you register for an Account or otherwise choose to provide it to us, we may collect your gender, date of birth, general location information (i.e., city and state)
  • • Cosmetic Preferences and Concerns. When you register for an Account or otherwise choose to provide it to us, you may identify your desired areas of improvement and cosmetic concerns.
  • • Camera and Photos (iOS App Only). If you use the app’s photo editing features, we collect the photographs you provide via your camera or camera roll, including any metadata associated with the photographs and any customizations you make to your photographs using the app. The editing features require that you grant us permission to access your camera or camera roll. You can revoke these permissions as described in the “Choice” section below.
  • • Biometric Data (iOS App Only). If you use the app’s photo editing features, we collect biometric data such as facial scans of photographs you upload to or take using the App, and data derived from this information. We do so by making use of Apples built in TruDepth API. The TruDepth Camera that is built into newer Apple Phones allows AEDIT to determine the distance of a pixel from the front facing camera thus allowing us to determine the facial measurements of our end users.

From Providers:

  • • Provider Contact Information. If you become, or consider becoming, a trusted provider on the Platform, we may collect your personal and business contact information, such as your name, email address, mailing address, and phone number.
  • • Professional Credentials. We may collect information about our Providers’ professional credentials, such as your role or specialty, and your educational or work history.

Please note that if you become a Provider on our Platform, our processing of your personal information will be governed by the terms and conditions of your engagement with the Platform.

From All Platform Visitors:

  • • Reviews and Comments. We collect the reviews and comments you submit to the Platform or provide when you visit or interact with our pages on social media platforms, such as when you post a review of a doctor on the Platform, leave a comment on our Facebook page, or interact with our blog. If you choose to submit reviews and comments to any public area of the Platform, such content will be considered “public” and will not be subject to the privacy protections set forth herein.
  • • Feedback. We may also collect personal information from you when you communicate with us. For example, you may send us personal information by providing feedback, requesting assistance, or writing an email to us or subscribing to an Aedit mailing. If you contact us, we may keep a record of that correspondence.
  • • Survey Responses. From time to time, we may contact you to participate in online surveys. If you do decide to participate, you may be asked to provide certain information which may include personal information, and we will collect your responses to such surveys.
  • • Passive Collection. We, our service providers and third party partners use cookies, beacons, pixel tags and other tracking technologies to collect and store:
  • • Device data, such as information about the device you are using to visit our websites or use our apps, including your device operating system type and version number, manufacturer and model, device identifier (such as the Google Advertising ID or Apple ID for Advertising), browser type, screen resolution, Internet protocol (IP) addresses, and Internet service provider (ISP).
  • • Online activity data, such as browsing history, search history, referring/exit pages, the files viewed on our Platform (e.g., HTML pages, graphics, etc.), date/time stamp, clickstream data, and other information about your interactions with our websites and apps, social media pages, and our email communications. [

We use this passively-collected data for internal purposes, including to analyze trends, compile statistics about use of the Platform, track Users’ movements around the Platform, help you navigate between pages efficiently, remember your preferences and generally improve your browsing experience, and measure the success of our marketing campaigns (including whether recipients of our emails open or click links within them), and to gather demographic information about our user base as a whole. Information that we collect using these technologies may be combined with other information we maintain about you.

Information Provided by Third Parties. Aedit may collect information about you from third parties or supplement the information we collect from you with additional records received from third parties.[b]

HOW AEDIT USES YOUR INFORMATION

We use personal information for the following purposes:

Biometric and Non-Biometric Personal Information:

Service-Related Usage. We use personal information to operate the Platform, including to provide the photo editing features of the app, to provide our services, and to provide support and maintenance for the Platform.

Platform Development and Improvement. We may also use personal information to analyze use of and improve the Platform and our services, including to train and improve the technology underlying the photo editing features of the app.

Compliance. We may use your personal information and disclose it to law enforcement, government authorities, and private parties as we believe necessary or appropriate to: (a) comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities; (b) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (c) enforce the terms and conditions that govern the Platform; and (d) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

Additional Uses of Non-Biometric Personal Information Account Maintenance. We use personal information to establish and maintain User and Provider accounts on the Platform. Advertisements. We may also work with third party advertising partners who use cookies and similar technologies to help us deliver targeted advertising that is displayed on unaffiliated websites, to measure the effectiveness of advertising on behalf of our advertising partners, and to identify the audience most likely to respond to an advertisement. These advertisements are delivered by our advertising partners and may be targeted based on your use of the Platform or your activity elsewhere online. We believe that the use of such information is helpful to providing users with better services. However, if you would like to opt-out of these interest-based advertisements, please follow the opt-out process described below under “Choice.”[c] Communications. We also use personal information to communicate with you about the Platform, including by sending you announcements, updates, security alerts, and support and administrative messages; and to respond to your requests, questions and feedback. Marketing. We may use information about you, including personal information, to send you information about the Platform. Anonymized. We create anonymized, aggregated or other pseudonymized data that is not personally identifiable to you, and use it for any of our lawful business purposes.

HOW AEDIT MAY DISCLOSE YOUR INFORMATION

We may share your information with third parties as described below, or as you otherwise authorize: Biometric and Non-Biometric Information: Service Providers. We may share personal information with our service providers who perform services on our behalf, such as: Payment processing Sending, evaluating, and improving marketing communications Fulfilling subscription services Conducting research and analysis Measuring and improving the performance of the Platform Verifying your identity and preventing fraud Developing and improving the Platform Registering and managing your Account Detecting, preventing and remediating fraud or other potentially prohibited or illegal activities These third parties may use your personal information only as directed or authorized by us and in a manner consistent with this Privacy Policy, and are prohibited from using or disclosing your information for any other purpose. As Required by Law and Similar Disclosures. We may access, preserve, and disclose your personal information, other Account information, and content if we believe doing so is required or appropriate to comply with law enforcement requests and legal process, such as a court order, government request, or subpoena. We may also access, preserve, and disclose your personal information, other Account information, and content if we believe in good faith that disclosure is necessary to protect yours’, ours’ or others’ rights, property, or safety, or investigate fraud. Merger, Sale, or Other Asset Transfers. If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, then your information may be sold or transferred as part of such a transaction as permitted by law and/or contract. The use of your personal information following any of the foregoing events should be governed by the provisions of the Privacy Policy in effect at the time such personal information was collected. Additional Sharing of Users’ Non-Biometric Personal Information Providers (at your direction). Our business is, in part, to match individuals seeking cosmetic procedures to our trusted Providers. When you request to be connected to a Provider, we will share the information you have authorized us to share with the relevant Provider(s). Third-Party Platforms and Social Media Networks. If you have enabled features or functionality that connect the Platform to a third-party platform or social media network, we may disclose the personal information that you authorized us to share, which may include photographs. We do not control the third-party’s use of your personal information. Advertising Partners. We may enable third-party advertising partners to collect information directly from our Platform for marketing purposes. [d] Additional Sharing of Providers’ Non-Biometric Personal Information Platform Users and Site Visitors. If you apply to become a trusted Provider, we may list your name, business address, specialty, and other information you choose to provide in connection with your listing on our publicly-available directory. This information is available to any Platform User. Advertising Partners. We may enable third-party advertising partners to collect information directly from our Platform for marketing purposes. [e] ACCESS, CORRECTION, DELETION Upon request, Aedit may provide you with information about whether we hold your personal information. You may also request that we update, correct, or delete any information that you have provided to us through your use of the app or the website. You may submit your request [through your Account or] [f]by email to privacy@aedit.com. We will respond to your request within a reasonable timeframe. We may deny your request where permitted by applicable law. CHOICE Cookies and Similar Technologies, Targeted Advertising. [g]As noted above, you may stop or restrict the placement of cookies on your computer or remove them from your browser by adjusting your web browser preferences. Many browsers accept cookies by default until you change your settings. Please note that if you set your browser to disable cookies, the Platform may not work properly. Please note that cookie-based opt-outs are not effective on mobile applications. However, on many mobile devices, App users may opt out of certain mobile ads via their device settings, which may limit our, or our partners’, ability to engage in ad tracking or targeted advertising using the Google Advertising ID or Apple ID for Advertising associated with your mobile device. To manage our advertising on other sites, we engage third party advertising partners. These third-party partners may use technologies such as cookies to gather information about your activities on the Platform and other sites in order to provide you advertising based upon your browsing activities and interests. Certain of our third-party advertising partners participate in self-regulatory organizations, and those organizations operate websites that give you the ability to opt-out of receiving targeted ads from those partners. You can access these websites, and also learn more about targeted advertising and privacy, at Network Advertising or AboutAds (for members of the Digital Advertising Alliance). You can also choose not to be included in Google Analytics here. App users may opt out of receiving targeted advertising in mobile apps through participating members of the Digital Advertising Alliance by installing the AppChoices mobile app, available here, and selecting the user’s choices. Please note that we also may work with companies that offer their own opt-out mechanisms and may not participate in the opt-out mechanisms that we linked above. To be clear, whether you are opting out by adjusting your browser/device settings or by using a website established by a self-regulatory group, cookie-based opt-outs must be performed on each device and browser that you wish to have opted-out. For example, if you have opted out on your computer browser, that opt-out will not be effective on your mobile device. You must separately opt out on each device. Do Not Track. Please note that we do not respond to or honor “do not track” (a/k/a/ DNT) signals or similar mechanisms transmitted by web browsers. Marketing. If you receive a marketing email from us, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future marketing emails. You can opt out of text messages from us by replying to the message with the word “STOP”, “BLOCK”, “CANCEL”, “STOPALL”, “UNSUBSCRIBE”, “QUIT”, or “END”. In addition, if you submit your mobile phone number through such a form, then you understand and consent to AEDIT and/or the health care provider sending you text messages. You understand that standard text messaging fees and data rates may apply. You can opt back in to text messages from AEDIT by texting “START”, “YES”, “UNSTOP”. We will process your request within a reasonable time after receipt. You may continue to receive service-related and other non-marketing communications. App Permissions. You may revoke any permissions you previously granted to us through the app, such as permission to access your camera or camera roll, or send you push notifications, through the settings on your mobile device. Third-Party Platforms. If you choose to connect a third-party platform to your Account, such as by using Google login, you may have the ability to limit the information that we may obtain from the third party or control your settings through the third party’s platform. If you use the Platform to post content to a third-party platform or social media network, you can manage such content directly through the third-party platform or social media network. THIRD PARTY SITES AND SOCIAL MEDIA PLATFORMS The Platform may contain links to other websites and other websites may reference or link to our Platform. These other domains and websites are not controlled by us. We encourage our users to read the privacy policies of each and every website and application that they interact with. We do not endorse, screen or approve, and are not responsible for the privacy practices or content of such other websites or applications. Visiting these other websites or applications is at your own risk. USER GENERATED CONTENT We may make available on our Platform, or link to, features that allow you to share information online (e.g., on our blog, in comment areas, through reviews, etc.). Please be aware that whenever you voluntarily disclose personal information online, that information becomes public and can be collected and used by others. We have no control over, and take no responsibility for, the use, storage or dissemination of such publicly-disclosed personal information. By posting personal information online in public forums, you may receive unsolicited messages from other parties. SECURITY OF YOUR INFORMATION We take reasonable steps to ensure that your information is treated securely and in accordance with this Privacy Policy. We follow generally accepted standards to protect personal information submitted to us, both during transmission and once it is received. Unfortunately, the measures we take to protect information cannot be guaranteed to be 100% secure, and we cannot ensure or warrant the security of any information you provide to us. We do not accept liability for unintentional disclosure.

HOW AEDIT RETAINS YOUR DATA

We retain photographs, including customizations and the information we derive from the photographs, to analyze use of and improve the Platform and our services, including to train and improve the technology underlying the photo editing features of the app. We will retain this information unless you request that we delete it.[h] We retain this information permanently except where applicable law requires us to delete it. [i] Except as described above, we will retain your information only as long as your Account is active or as needed to provide you services or otherwise fulfill the purpose(s) for which we collected your information, as set forth in this Privacy Policy (including as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements).[j] BIOMETRIC DATA RETENTION FOR ILLINOIS RESIDENT USERS If you are an Illinois resident User, in accordance with Illinois state law we will retain your biometric data only until the occurrence of the first of the following, after which we will permanently destroy the biometric data: The initial purpose for collecting or obtaining such biometric data – as set out in this Privacy Policy – has been satisfied; or Three years following your last interaction with us, where your last interaction is the later of the date on which you closed your Account, or the last date you communicated with us about the Platform. CHILDREN’S PRIVACY We do not knowingly collect, maintain, or use personal information from children under 13 years of age, and no part of the Platform is directed to children under the age of 13. If you learn that your child has provided us with personal information without your consent, you may alert us at privacy@aedit.com. If we learn that we have collected any personal information from children under 13, we will promptly take steps to delete such information and terminate the child’s Account. NON-US USERS We are headquartered in the United States and have service providers in other countries, and by using the Platform, your personal information may be transferred to the United States or other locations outside of your state, province or country where privacy laws may not be as protective as those in your state, province or country. CHANGES TO OUR PRIVACY POLICY AND PRACTICES We may revise this Privacy Policy, so review it periodically. If you continue to visit our Platform and use the services made available to you after such changes have been made, you hereby provide your consent to the changes. Posting of Revised Privacy Policy. We will post any adjustments to the Privacy Policy on this web page, and the revised version will be effective when it is posted. If you are concerned about how your information is used, bookmark this page and read this Privacy Policy periodically. New Uses of Personal Information. From time to time, we may desire to use personal information for uses not previously disclosed in our Privacy Policy. If our practices change regarding previously collected personal information in a way that would be materially less restrictive than stated in the version of this Privacy Policy in effect at the time we collected the information, we will make reasonable efforts to provide notice and obtain consent to any such uses as may be required by law. CONTACT INFORMATION You may contact us with questions about this Privacy Policy or our privacy practices at privacy@aedit.com, or write to us at: Aedit, LLC Attn: Privacy[k] 345 E. 33rd Street Suite 3D New York, New York 10016 NOTICE TO CALIFORNIA RESIDENTS We are required by the California Consumer Privacy Act of 2018 (“CCPA”) to provide to California residents an explanation of how we collect, use and share their personal Information, and of the rights and choices we offer California residents regarding our handling of the personal information. This notice does not apply to information related to our business contacts (including Providers). We do not sell personal information. As we explain in this Privacy Policy, we use cookies and other tracking technologies to analyze website traffic and facilitate advertising. If you would like to opt out of our (and our third party advertising partners’) use of cookies and other tracking technologies, please review the instructions provided in the Online Tracking Opt-out Guide. [l] Our Platform allows Users to direct us to share their information with Providers with whom they wish to connect. In addition to the information in our Privacy Policy, the following chart further describes our privacy practices with respect individuals whose information is governed by the CCPA.

Please note that we may also disclose all personal information to service providers, as required by law or similar purposes, and in connection with a merger, sale, or other asset transfer. For additional information, visit the “How AEDIT May Disclose Your Information” section of our Privacy Policy. California Residents’ Privacy Rights Except as excluded from the scope of this notice above, the CCPA grants California residents the following rights. Information. You can request information about how we have collected, used and shared and used your personal information during the past 12 months. We have made this this information available to California residents without having to request it by including it in this notice, in the above chart. Access. You can request a copy of the personal information that we maintain about you. Deletion. You can ask us to delete the personal information that we collected or maintain about you. Please note that the CCPA limits these rights by, for example, prohibiting us from providing certain sensitive information in response to an access request and limiting the circumstances in which we must comply with a deletion request. If we deny your request, we will communicate our decision to you. You are entitled to exercise the rights described above free from discrimination.

HOW TO SUBMIT A REQUEST FOR ACCESS TO OR DELETE PERSONAL INFORMATION

Visit: aedit.com/contact-us Email: privacy@AEDIT.com Identity verification. The CCPA requires us to verify the identity of the individual submitting a request to access or delete personal information before providing a substantive response to the request. We may attempt to verify your identify by asking you to confirm information that we have on file about you or your interactions with us. Where we ask for additional personal information to verify your identity, we will only use it to verify your identity or your authority to make the request on behalf of another consumer. Authorized agents. California residents can empower an “authorized agent” to submit requests on their behalf. We will require the authorized agent to have written authorization confirming such authority.

Online Tracking Opt-Out Guide Like many companies online, we may use services provided by Google, Facebook and other companies that use tracking technology. These services rely on tracking technologies – such as cookies and web beacons – to collect directly from your device information about your browsing activities, your interactions with websites, and the device you are using to connect to the Internet. There are a number of ways to opt out of having your online activity and device data collected through these services, which we have summarized below: Blocking cookies in your browser. Most browsers let you remove or reject cookies, including cookies used for interest-based advertising. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. For more information about cookies, including how to see what cookies have been set on your device and how to manage and delete them, visit www.allaboutcookies.org. Blocking advertising ID use in your mobile settings. Your mobile device settings may provide functionality to limit use of the advertising ID associated with your mobile device for interest-based advertising purposes. Using privacy plug-ins or browsers. You can block our websites from setting cookies used for interest-based ads by using a browser with privacy features, like Brave, or installing browser plugins like Privacy Badger, Ghostery or uBlock Origin, and configuring them to block third party cookies/trackers. Platform opt-outs. The following advertising partners offer opt-out features that let you opt-out of use of your information for interest-based advertising: Google: https://adssettings.google.com Facebook: https://www.facebook.com/about/ads Hotjar: https://www.hotjar.com/legal/compliance/opt-out FullStory: https://www.fullstory.com/optout/ Advertising industry opt-out tools. You can also use these opt-out options to limit use of your information for interest-based advertising by participating companies: Digital advertising Alliance: http://optout.aboutads.info Network Advertising Initiative: http://optout.networkadvertising.org/?c=1 AppChoices Mobile App: https://youradchoices.com/appchoices Note that because these opt-out mechanisms are specific to the device or browser on which they are exercised, you will need to opt-out on every browser and device that you use.