AXIONOVA™ operates a precision health technology platform designed for physician-governed biological systems, verified compound documentation, governed delivery infrastructure, practitioner review, and controlled access workflows. AXIONOVA™’s public materials describe a formulary of compounded formulation systems, AXIS governed delivery infrastructure, AXIONOVA™ Ring and Bracelet physiology streams, AXIONOVA™ bio record management, ALETHRA™ governance, and ALETHA™AI-assisted support. This Privacy Policy explains how AXIONOVA™ collects, uses, discloses, protects, and retains personal information in connection with those services.
This Policy applies to visitors, access-gate applicants, practitioners, clinics, longevity centers, authorized resellers, research entities, reservation holders, business contacts, and individuals whose information is submitted through AXIONOVA™ systems. It also applies to personal information processed through integrated service providers, including Attio for relationship management, Datasite for secure document handling, and DocuSign for electronic signatures.
AXIONOVA™’s privacy model is built around one principle: measured source data, derived wellness features, clinical protocol context, AI-generated observations, practitioner annotations, and compliance records must remain distinguishable, traceable, and governed.
AXIONOVA™ compounds and compound-related documentation describe compounded medications prepared by licensed pharmacies pursuant to valid prescriptions issued by licensed healthcare providers for individually identified patients. Compounded medications are not FDA-approved and are not offered as over-the-counter products or substitutes for licensed clinical judgment. All clinical decisions are made by the prescribing physician; AXIONOVA™ is a technology platform and does not practice medicine.
AXIONOVA™ may process wellness, physiology, laboratory, protocol, and practitioner-review information. Some of this information may be considered sensitive personal information, health-related information, or, in limited workflows, protected health information (PHI). HIPAA applies to health plans, health care clearinghouses, and certain health care providers that electronically transmit health information in covered transactions, and may also apply to business associates acting on behalf of covered entities. AXIONOVA™ will treat HIPAA-regulated information under applicable Business Associate Agreements and HIPAA policies where AXIONOVA™ is acting as a business associate or otherwise subject to HIPAA.
AXIONOVA™ collects information needed to operate a controlled, practitioner-oriented, prescription-governed platform. The categories below are illustrative and should be finalized against AXIONOVA™’s actual data inventory before publication.
Under California privacy law, personal information may include information that identifies, relates to, or could reasonably be linked with a person or household, and sensitive personal information may include health, genetic, biometric, precise geolocation, account credentials, and certain other protected categories. Under Mexico’s LFPDPPP, personal data is information concerning an identified or identifiable individual, and sensitive personal data may include information affecting the most intimate sphere of the individual or whose misuse may give rise to discrimination or serious risk.
AXIONOVA™ AGIS-related data may include paired AXIONOVA™ Ring and Bracelet device status, signal quality, baseline-aware monitoring context, consent status, contact permissions, practitioner-review status, and approved response workflow records where available. AXIONOVA™ AGIS data should not be described as emergency-service data unless a specific Safety Escalation Workflow workflow is approved, configured, jurisdictionally available, and legally supported.
AXIONOVA™ may collect personal information directly from you, from your clinic, organization, practitioner, authorized reseller, research entity, or employer, from AXIONOVA™ devices or applications, from laboratories or connected data sources you authorize, from electronic-signature and secure-document workflows, from public professional-license or credential sources, and from service providers that support AXIONOVA™ operations.
Where AXIONOVA™ receives data from a practitioner, clinic, reseller, or research entity, that party is responsible for ensuring it has the legal authority, consent, authorization, or other lawful basis necessary to submit the information to AXIONOVA™.
AXIONOVA™ may process applicant, user, practitioner, device, biometric, protocol, and support information to operate governed prescription-based workflows; route applicants through Path 1 credential review or Path 2 telehealth oversight; support ALETHA™ first-contact assistance; maintain ALETHRA™ governance records; manage AXIONOVA™ Ring and Bracelet, AXIS, CDM, AXIONOVA™ bio, and AXIONOVA™ AGIS workflows; preserve auditability; comply with applicable privacy, security, professional, and jurisdictional requirements; and support human review where clinical, safety-sensitive, specialist, or regulated questions arise.
AXIONOVA™ does not use ALETHA™ AI outputs as a substitute for licensed professional judgment, medical diagnosis, treatment, or emergency care. Protocol-dependent decisions must route through the appropriate authorized practitioner, clinic, research entity, or access pathway.
AXIONOVA™ uses AXIONOVA™ AGIS-related information to configure approved safety workflows, verify consent, manage emergency-contact routing, support practitioner review, preserve incident records, maintain provenance, audit configuration changes, evaluate device readiness, and administer approved access pathways. AXIONOVA™ AGIS-related information is not used to create an unmanaged consumer emergency-service guarantee.
ALETHA™ may process user inputs, device data, laboratory data, protocol context, and adherence records to generate explanations, summaries, educational context, progress views, preparatory questions, or practitioner-review flags. ALETHRA™ preserves source identity, timestamp, device provenance, signal quality, user consent, access authorization, and boundary labels before ALETHA™ interprets the record.
AXIONOVA™ does not intend ALETHA™ to make legally or clinically determinative decisions without appropriate human oversight. Where an output could affect restricted access, practitioner review, compliance status, or protocol-dependent decisions, AXIONOVA™ may require human review by AXIONOVA™ personnel, an authorized partner, or a licensed practitioner. Users should not rely on AI outputs as medical advice, diagnosis, treatment, or evidence of compound effect.
AXIONOVA™ may disclose personal information to the following categories of recipients when reasonably necessary for the purposes described in this Policy.
AXIONOVA™ does not intend to sell sensitive health-related information. If AXIONOVA™ engages in activities that constitute a “sale” or “sharing” of personal information under applicable U.S. state privacy law, AXIONOVA™ will provide required notices and opt-out mechanisms.
Where a AXIONOVA™ AGIS workflow includes approved response vendors, notification services, practitioner-review teams, clinics, research programs, or emergency-contact routing, AXIONOVA™ may share the minimum information necessary to support the configured workflow, subject to consent, access controls, contractual restrictions, jurisdictional availability, and applicable legal requirements. AXIONOVA™ does not authorize unrestricted disclosure of AXIONOVA™ AGIS incident records or emergency-contact information.
AXIONOVA™ may use cookies, pixels, tags, device identifiers, log files, and similar technologies to operate the website, authenticate users, protect restricted access, remember preferences, measure engagement, detect abuse, and improve communications. AXIONOVA™ should maintain a cookie inventory and, where required, provide cookie notices, preference tools, and opt-out mechanisms for analytics, advertising, or cross-context behavioral advertising.
AXIONOVA™ may send professional, educational, product-update, reservation, and availability communications. Commercial email communications will be structured to comply with the U.S. CAN-SPAM Act, including accurate header information, non-deceptive subject lines, clear advertising identification where required, a valid physical postal address, an unsubscribe mechanism, honoring opt-out requests within 10 business days, and oversight of vendors sending messages on AXIONOVA™’s behalf.
Transactional and relationship communications, including security notices, access-gate updates, DocuSign notices, compliance alerts, service notices, and practitioner-review communications, may continue even if you opt out of marketing communications.
AXIONOVA™ may use DocuSign or similar services for consents, acknowledgements, access authorizations, partner agreements, reseller documents, data-room acknowledgements, and compliance attestations. Under the U.S. ESIGN Act, electronic signatures, contracts, and records may not be denied legal effect solely because they are electronic, subject to applicable consent and consumer-disclosure requirements.
Where consumer electronic-record consent is legally required, AXIONOVA™ will provide clear disclosures regarding electronic delivery, paper-copy rights, withdrawal procedures, categories of electronic records, and hardware/software requirements, and will obtain affirmative electronic consent in a manner that reasonably demonstrates access to the electronic record format.
AXIONOVA™ may process and transfer personal information between the United States, Mexico, and other jurisdictions where AXIONOVA™ personnel, affiliates, service providers, practitioners, or partners operate. Mexico’s LFPDPPP requires privacy-notice transparency and imposes obligations regarding national and international transfers of personal data, subject to statutory exceptions and consent requirements.
AXIONOVA™ will use reasonable contractual, administrative, technical, and organizational safeguards for cross-border transfers, including confidentiality clauses, service-provider agreements, business-associate agreements where applicable, data-processing terms, access controls, and secure document-room permissions.
Individuals in Mexico may have rights under the LFPDPPP to Access, Rectify, Cancel, and Oppose processing of their personal data, commonly known as ARCO rights, as well as rights to limit use or disclosure and to revoke consent where legally available.
To exercise these rights, contact AXIONOVA™ at privacy@axionova.com with your name, contact information, the right you wish to exercise, information sufficient to identify the relevant record, and proof of identity or authority where required. AXIONOVA™ will respond within the timelines required by Mexican law after receiving a complete request.
Depending on your state of residence and whether AXIONOVA™ meets statutory applicability thresholds, you may have rights to know or access personal information, receive a portable copy, delete personal information, correct inaccurate information, opt out of certain sale, sharing, targeted advertising, or profiling activities, limit use of sensitive personal information, and appeal a denied request.
For California residents, the CCPA/CPRA provides rights to know, delete, opt out of sale or sharing, correct inaccurate information, limit use and disclosure of sensitive personal information, receive notice at or before collection, and exercise rights without discrimination. These rights apply only when AXIONOVA™ is subject to the CCPA’s applicability thresholds or otherwise chooses to extend similar rights voluntarily.
AXIONOVA™ may receive health-related information from users, practitioners, clinics, laboratories, or connected devices. Not all health-related data is HIPAA-regulated PHI. Where AXIONOVA™ acts as a business associate for a HIPAA covered entity, AXIONOVA™ will handle PHI according to the applicable Business Associate Agreement, HIPAA Privacy Rule, HIPAA Security Rule, and breach-notification requirements.
Where HIPAA does not apply, AXIONOVA™ will still treat health-adjacent, physiology, biometric, laboratory, and protocol information as sensitive and will apply appropriate privacy, security, access-control, and retention safeguards.
AXIONOVA™ will maintain administrative, technical, and physical safeguards reasonably designed to protect personal information against unauthorized access, loss, misuse, alteration, destruction, or disclosure. These safeguards may include role-based access controls, multi-factor authentication, encryption in transit and at rest where appropriate, secure document-room permissions, audit logging, vendor diligence, least-privilege access, incident-response procedures, and periodic security reviews.
Mexico’s LFPDPPP requires controllers to establish and maintain administrative, technical, and physical security measures to protect personal data, and to notify data subjects immediately when security breaches significantly affect patrimonial or moral rights. AXIONOVA™ will evaluate security incidents under applicable U.S. state breach-notification laws, HIPAA where applicable, and Mexican law.
AXIONOVA™ retains personal information only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law, contract, audit requirements, clinical documentation needs, chain-of-custody controls, electronic-signature record retention, dispute resolution, tax, accounting, regulatory, or safety obligations.
Because AXIONOVA™ operates controlled access, prescription-governed, chain-of-custody, device-event, and practitioner-review workflows, certain compliance, authorization, lot, cartridge, DocuSign, Datasite, and ALETHRA™ audit records may be retained longer than ordinary contact or marketing records.
AXIONOVA™ AGIS configuration records, consent records, notification records, incident records, practitioner-review notes, device-readiness records, and audit logs may be retained for safety, governance, legal, operational, and review purposes according to AXIONOVA™’s approved retention schedule. Revocation, deletion, or export requests must be handled according to applicable law, approved access requirements, safety-record obligations, and technical feasibility.
AXIONOVA™’s restricted platform, professional access workflows, and prescription-restricted materials are not directed to children. The governed access gate should require users to confirm that they are at least 21 years old or otherwise legally authorized to act on behalf of an approved organization. AXIONOVA™ does not knowingly collect personal information from children for consumer use of prescription-restricted materials.
You may update certain account information, request marketing opt-outs, unsubscribe from commercial email, request deletion where legally available, limit certain disclosures, revoke consent where applicable, or contact AXIONOVA™ to restrict optional data integrations. Some choices may limit access to AXIONOVA™ services because identity verification, chain-of-custody records, practitioner review, DocuSign records, and restricted-access controls are necessary to operate the platform.
Approved AXIONOVA™ AGIS users must be provided controls to review consent status, update emergency contacts, change notification preferences, revoke eligible AXIONOVA™ AGIS permissions, request export of eligible records, and request deletion where permitted by applicable law and operational requirements. Revocation of AXIONOVA™ AGIS permissions may disable configured escalation workflows.
AXIONOVA™ may update this Privacy Policy as its platform, product classifications, service providers, jurisdictions, and legal requirements evolve. AXIONOVA™ will post the updated version and revise the effective date. Where required by law, AXIONOVA™ will provide additional notice or obtain consent for material changes.
Questions, privacy requests, ARCO requests, state privacy requests, HIPAA-related inquiries, and data-protection concerns may be submitted to: