Last Updated: October 22, 2025
1. Introduction
Welcome to Pinguis Vir. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not use our services.
This Privacy Policy applies to our subscription-based AI-driven transcranial photobiomodulation (tPBM) protocol services, including our web platform, client management tools, and related services.
2. Information We Collect
2.1 Personal Information
We collect personal information that you voluntarily provide to us when you register for an account, subscribe to our services, or communicate with us. This may include:
- Name and contact information (email address, phone number)
- Account credentials (username, password)
- Professional information (credentials, practice details for healthcare providers)
- Payment information (processed securely through third-party payment processors)
- Profile information and preferences
2.2 Client and Patient Data
If you are a healthcare professional using our services with clients or patients, you may provide:
- Client/patient names and contact information
- QEEG (Quantitative Electroencephalogram) data and brain mapping information
- Health-related information relevant to protocol customization
- Treatment notes and protocol usage records
You are responsible for obtaining appropriate consent from your clients/patients before uploading their data to our platform.
2.3 Usage Data
We automatically collect certain information about your device and how you interact with our services, including:
- IP address, browser type, and operating system
- Device identifiers and characteristics
- Pages viewed, features used, and actions taken
- Date and time stamps of your activities
- Referring URLs and clickstream data
2.4 Cookies and Tracking Technologies
We use cookies, web beacons, and similar tracking technologies to collect information about your browsing activities. See Section 5 for more details about our use of cookies.
3. How We Use Your Information
We use the information we collect for various purposes, including:
3.1 Service Delivery
- Providing access to our AI-driven tPBM protocol services
- Creating and managing your account
- Processing subscriptions and payments
- Generating personalized protocols based on QEEG data
- Enabling client management and protocol delivery features
3.2 Service Improvement and Development
- Analyzing usage patterns to improve our services
- Developing new features and functionality
- Training and improving our AI algorithms
- Conducting research and data analysis
3.3 Communication
- Sending service-related notifications and updates
- Responding to your inquiries and support requests
- Providing important account and subscription information
- Sending promotional materials (with your consent, where required)
3.4 Security and Legal Compliance
- Detecting and preventing fraud, abuse, and security incidents
- Enforcing our Terms and Conditions
- Complying with legal obligations and responding to legal requests
- Protecting the rights, property, and safety of Pinguis Vir and our users
4. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Third-Party Service Providers
We use trusted third-party service providers to help us operate our business and deliver our services:
- Xano - Backend database and API services for data storage and processing
- Memberstack - User authentication and membership management
- Analytics providers - Web analytics and usage tracking (such as Plausible Analytics or Google Analytics)
- Payment processors - Secure payment processing for subscriptions
- Cloud hosting services - Infrastructure and hosting providers
- Email service providers - Transactional and marketing email delivery
These service providers are contractually obligated to use your information only for the purposes of providing services to us and are required to maintain appropriate security measures.
4.2 Business Transfers
If Pinguis Vir is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
4.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities, including to meet national security or law enforcement requirements.
4.4 Protection of Rights
We may disclose information when we believe it is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
4.5 Hardware Manufacturers
We do not share your data with hardware manufacturers. Photobiomodulation helmets and hardware devices are not sold by Pinguis Vir, and any data collected by such devices is subject to the manufacturer's privacy policies.
5. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience and collect information about how you use our services.
5.1 Types of Cookies We Use
- Essential Cookies - Required for the operation of our services, including authentication and security
- Functional Cookies - Enable enhanced functionality and personalization
- Analytics Cookies - Help us understand how users interact with our services
- Marketing Cookies - Used to track visitors across websites for advertising purposes (with consent)
5.2 Managing Cookies
Most web browsers allow you to control cookies through their settings. You can typically set your browser to refuse cookies or alert you when cookies are being sent. However, if you disable cookies, some features of our services may not function properly.
For more information about cookies and how to manage them, visit www.allaboutcookies.org.
6. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using SSL/TLS protocols
- Encryption of sensitive data at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Employee training on data security and privacy
- Secure backup and disaster recovery procedures
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.
You are responsible for maintaining the confidentiality of your account credentials and for any activities that occur under your account. Please notify us immediately of any unauthorized access or use of your account.
7. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Specifically, we retain:
- Account information - For the duration of your active subscription and for a reasonable period after cancellation
- Client/patient data - As long as your account is active or as required by applicable healthcare regulations
- Transaction records - For accounting and legal compliance purposes, typically 7 years
- Usage data - Aggregated and anonymized usage data may be retained indefinitely for analytics purposes
When we no longer need your information, we will securely delete or anonymize it in accordance with our data retention policies.
8. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information:
8.1 Access and Portability
You have the right to request access to the personal information we hold about you and to receive a copy of your data in a portable format.
8.2 Correction
You have the right to request correction of inaccurate or incomplete personal information. You can update most of your account information directly through your account settings.
8.3 Deletion
You have the right to request deletion of your personal information, subject to certain legal exceptions (such as records we must retain for compliance purposes).
8.4 Restriction and Objection
You may have the right to restrict or object to certain processing of your personal information, including for marketing purposes.
8.5 Exercising Your Rights
To exercise any of these rights, please contact us at dreagle@braincoresystems.com. We will respond to your request within a reasonable timeframe and in accordance with applicable law.
9. Third-Party Services and Links
Our services may contain links to third-party websites, services, or applications that are not owned or controlled by Pinguis Vir. This Privacy Policy does not apply to third-party services.
We encourage you to review the privacy policies of any third-party services you access through our platform:
- Xano privacy policy: www.xano.com/privacy
- Memberstack privacy policy: www.memberstack.com/privacy
- Hardware manufacturer (Neuronic): www.neuronic.online
We are not responsible for the privacy practices of third parties and encourage you to read their privacy policies before providing any personal information to them.
10. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.
If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 18 without verification of parental consent, we will take steps to delete that information.
Healthcare providers using our services to manage pediatric clients/patients are responsible for obtaining appropriate consent from parents or guardians before uploading any information about minors.
11. International Users and Data Transfers
Pinguis Vir operates primarily in the United States. If you are accessing our services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
Data protection laws in the United States and other countries may be different from those in your country. By using our services, you consent to the transfer of your information to the United States and other countries.
11.1 European Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with a supervisory authority.
We process your personal information based on the following legal bases:
- Contract performance - To provide our services as outlined in our Terms and Conditions
- Legitimate interests - To improve our services, prevent fraud, and ensure security
- Legal compliance - To comply with applicable laws and regulations
- Consent - Where you have provided consent for specific processing activities
11.2 California Users (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information we collect, use, and disclose
- The right to request deletion of your personal information
- The right to opt-out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by:
- Posting the updated Privacy Policy on our website with a new "Last Updated" date
- Sending an email notification to the address associated with your account
- Displaying a prominent notice on our platform
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Your continued use of our services after any changes to this Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should discontinue use of our services.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Pinguis Vir
Email: dreagle@braincoresystems.com
For our complete Terms and Conditions, please visit our Terms and Conditions page.
By using Pinguis Vir services, you acknowledge that you have read, understood, and agree to this Privacy Policy.