PRIVACY POLICY

Last updated: February 19, 2026

This Privacy Notice for Solais Wellness Limited (doing business as Solais Wellness) (“we”, “us”, or “our”) describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our services (“Services”), including when you:

• Visit our website at https://www.solaiswellness.com/ (or any website of ours that links to this Privacy Notice)

• Engage with us in other related ways, including any marketing or events

Questions or concerns?

Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at hello@solaiswellness.com.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.

What personal information do we process?

When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.

Do we process any sensitive personal information?

Some of the information may be considered “special” or “sensitive” in certain jurisdictions. We may process sensitive personal information when necessary with your consent or as otherwise permitted by applicable law.

Do we collect any information from third parties?

We do not collect any information from third parties.

How do we process your information?

We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so.

In what situations and with which types of parties do we share personal information?

We may share information in specific situations and with specific categories of third parties.

How do we keep your information safe?

We have adequate organisational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure.

What are your rights?

Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.

How do you exercise your rights?

The easiest way to exercise your rights is by contacting us at hello@solaiswellness.com. We will consider and act upon any request in accordance with applicable data protection laws.

Want to learn more about what we do with any information we collect?

Review the Privacy Notice in full (see below).

TABLE OF CONTENTS

1. WHAT INFORMATION DO WE COLLECT?

2. HOW DO WE PROCESS YOUR INFORMATION?

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

7. HOW LONG DO WE KEEP YOUR INFORMATION?

8. HOW DO WE KEEP YOUR INFORMATION SAFE?

9. DO WE COLLECT INFORMATION FROM MINORS?

10. WHAT ARE YOUR PRIVACY RIGHTS?

11. CONTROLS FOR DO-NOT-TRACK FEATURES

12. DO WE MAKE UPDATES TO THIS NOTICE?

13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Personal Information Provided by You.

The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include:

• names

• phone numbers

• email addresses

• mailing addresses

• emergency contact details

• payment details (processed securely by our payment provider; we do not store full card numbers)

Sensitive Information.

When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:

• health data

Payment Data.

We may collect data necessary to process your payment if you choose to make purchases. All payment data is handled and stored by Stripe. You may find their privacy notice here: https://stripe.com/gb/privacy

All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

Information automatically collected

In Short: Some information — such as your IP address and/or browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.

Like many businesses, we also collect information through cookies and similar technologies. You can find out more about this in our Cookie Notice: [link not provided in pasted text].

The information we collect includes:

• Log and Usage Data (including IP address, device information, browser type, settings, date/time of use, pages viewed, actions taken, and device event information such as error reports)

Device Data (such as IP address or proxy server, device/application IDs, location, browser type, hardware model, ISP/mobile carrier, operating system, and system configuration)

• Location Data (either precise or imprecise, depending on device settings; you can opt out by refusing permissions or disabling location settings, but some parts of the Services may not work)

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

• To deliver and facilitate delivery of services to the user.

• To respond to user inquiries/offer support to users.

• To send administrative information to you.

• To fulfil and manage your orders (including payments, returns, and exchanges).

• To request feedback.

• To protect our Services (including fraud monitoring and prevention).

• To identify usage trends (to improve the Services).

• To save or protect an individual’s vital interest (such as to prevent harm).

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law (a “legal basis”), such as consent, compliance with laws, performance of a contract, protection of rights, or legitimate interests.

The GDPR and UK GDPR require us to explain the valid legal bases we rely on. We may rely on:

• Consent (you can withdraw at any time).

• Performance of a Contract.

• Legitimate Interests (for example, to analyse how our Services are used, diagnose problems/prevent fraud, and improve user experience).

• Legal Obligations.

• Vital Interests.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We may share information in specific situations described in this section and/or with categories of third parties.

Vendors, Consultants, and Other Third-Party Service Providers.

We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf. We have contracts in place designed to safeguard your personal information.

Categories of third parties we may share personal information with include:

• Payment Processors

• Website Hosting Service Providers

• Communication & Collaboration Tools

• Data Analytics Services

• Performance Monitoring Tools

• Finance & Accounting Tools

We may also need to share your personal information in the following situations:

• Business Transfers (e.g. merger, sale, financing, acquisition).

• Affiliates (who must honour this Privacy Notice).

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: We may use cookies and other tracking technologies to collect and store your information.

We may use cookies and similar technologies (like web beacons and pixels) to gather information when you interact with our Services. Some technologies help us keep the Services secure, prevent crashes, fix bugs, save preferences, and support basic site functions.

We also permit third parties and service providers to use online tracking technologies on our Services for analytics and advertising, including to help manage and display adverts, tailor adverts to your interests, or send abandoned shopping cart reminders (depending on your communication preferences).

Specific information about how we use these technologies and how you can refuse certain cookies is set out in our Cookie Notice: [link not provided in pasted text].

6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

In Short: We may transfer, store, and process your information in countries other than your own.

Our servers are located in the United States and India. Your information may be transferred to, stored by, and processed by us in our facilities and in the facilities of third parties with whom we may share your personal information, including facilities in the United States, Ireland, and other countries.

If you are a resident in the EEA, UK, or Switzerland, these countries may not have data protection laws as comprehensive as those in your country. We will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law.

European Commission’s Standard Contractual Clauses

We have implemented measures to protect your personal information, including by using the European Commission’s Standard Contractual Clauses for transfers of personal information between our group companies and between us and our third-party providers.

Our Data Processing Agreements that include Standard Contractual Clauses are available here:

• https://www.squarespace.com/dpa

• https://stripe.com/en-gb-pt/legal/dta

7. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice unless otherwise required by law.

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than 2 years.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it. If deletion is not possible (for example, stored in backups), we will securely store it and isolate it from any further processing until deletion is possible.

8. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organisational and technical security measures.

We have implemented appropriate and reasonable technical and organisational security measures designed to protect the security of any personal information we process. However, no method of transmission over the internet or storage technology can be guaranteed to be 100% secure. Transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

9. DO WE COLLECT INFORMATION FROM MINORS?

In Short: We do not knowingly collect data from or market to children under 18 years of age.

We do not knowingly collect, solicit data from, or market to children under 18, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 (or are the parent/guardian consenting to a minor’s use). If we learn we have collected personal information from someone under 18, we will deactivate the account and take reasonable measures to delete such data. If you become aware of any such data, contact us at hello@solaiswellness.com.

10. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: In some regions (such as the EEA, UK, and Switzerland), you have rights that allow you greater access to and control over your personal information.

These may include the right to request access and obtain a copy, request rectification or erasure, restrict processing, data portability (if applicable), and not to be subject to automated decision-making. In some circumstances, you may also have the right to object to processing.

We will consider and act upon requests in accordance with applicable data protection laws.

If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority or the UK Information Commissioner’s Office (ICO). If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Withdrawing your consent

If we rely on consent, you can withdraw it at any time by contacting us using the contact details in the “HOW CAN YOU CONTACT US ABOUT THIS NOTICE?” section.

Opting out of marketing and promotional communications

You can unsubscribe at any time by clicking the unsubscribe link in emails we send, or by contacting us. You will be removed from marketing lists, but we may still send service-related messages.

Cookies and similar technologies

Browsers usually accept cookies by default. You can set your browser to remove or reject cookies, but this may affect features of our Services. For more information, see our Cookie Notice:

If you have questions or comments about your privacy rights, you may email us at hello@solaiswellness.com.

11. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems/apps include a Do-Not-Track (“DNT”) feature. No uniform standard for recognising and implementing DNT signals has been finalised. We do not currently respond to DNT browser signals. If a standard is adopted in the future, we will inform you in a revised version of this Privacy Notice.

12. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated ‘Revised’ date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.

13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, you may email us at hello@solaiswellness.com or contact us by post at:

Solais Wellness Limited
Unit 7, RFL House,
Anderson St,
Dunblane FK15 9AJ
Scotland

14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.

To request to review, update, or delete your personal information, please contact us at hello@solaiswellness.com.