Privacy Policy

Exhibit E

Last Updated: July 20, 2026

Welcome to Prahsys—an all-in-one issuing, acquiring, processing, and settlement platform built just for you. This Privacy Notice explains how Prahsys, Inc. (“Prahsys”) collects, uses, discloses, and otherwise processes personal data in connection with our website, services, and any related applications (collectively, the “Services”).

This Privacy Notice does not address our privacy practices relating to Prahsys job applicants, employees, and other employment-related individuals. This Privacy Notice also does not address data that is exempt from applicable data protection laws (such as deidentified or publicly available information). This Privacy Notice is not a contract and does not create any legal rights or obligations not otherwise provided by law.


Our Collection and Use of Personal Data

Categories of Personal Data Collected

The categories of personal data we collect depend on how you interact with us and our Services. This includes:

  • Account Information: First and last name, email address, phone number, and account credentials.
  • Feedback and Support Information: Information provided through customer support forms, emails, chat, or recorded calls.
  • Device and Network Information: Device type, manufacturer, IP address, browser type, operating system, and network details.
  • Usage Data: Interaction details such as pages visited, browsing behavior, and engagement with our content.
  • Phone Number Consent: When you pay through the Prahsys payments and give your phone number for payment receipts and payment invoicing,
    we will send that information via payments

Medical Data Collection and Usage

  • Medical Data Governance: Prahsys follows strict data governance protocols when collecting and processing medical data. All medical data used for analysis, research, and artificial intelligence (AI) training is anonymized before processing to comply with applicable laws and ethical guidelines.
  • Use of Medical Data in AI Training: Anonymized patient data may be used to improve the performance of PrognosiX and other AI-driven tools. No personally identifiable medical records or raw HIPAA-protected data are used for AI training.
  • Practitioner Agreements on Data Use: All practitioners associated with Prahsys must enter into a legal agreement ensuring that any patient data provided for AI training is fully anonymized. Prahsys will not accept or process raw patient data that could violate HIPAA or other privacy regulations.

Sharing Scans and Diagnostic Imaging with Patients

PrognosiX allows a dental practice to share a patient’s own scan and related diagnostic imaging directly with that patient. When a practice uses this feature, the following applies:

  • The practice controls the sharing. Your dental practice, not Prahsys, decides whether to share a scan, which scan to share, and with whom. The practice is the healthcare provider responsible for your care and for confirming the accuracy of the contact information used to share your imaging. Prahsys acts only as the practice’s service provider (a “business associate” under HIPAA), processing and delivering the imaging on the practice’s instruction and under the business associate agreement in effect between Prahsys and the practice.
  • Secure, limited access. Imaging is shared through a secure, access-controlled link tied to the contact information the practice provides. Access is encrypted in transit and at rest, may expire after a period of time, and can be revoked by the practice, or by Prahsys to protect the security of your imaging or on the practice’s instruction. We keep access logs so that the practice can see when a shared scan was viewed. Disabling a shared link never affects your ability to obtain your imaging from your dental practice.
  • Purpose limitation. A scan routed through PrognosiX for sharing with a patient is used only to make that scan available to the intended patient. It is not sold, used for advertising, or used to train or evaluate our artificial intelligence models. This is consistent with our commitment, described above, that no personally identifiable medical records or raw HIPAA-protected data are used for AI training.
  • Informational purpose only; not a diagnosis. Shared imaging, including any AI-generated visualization such as a highlighted pulp-tissue overlay, is provided for your general information and to support the conversation with your treating provider. Any such AI-generated visualization is produced by investigational software that is still in development, has not been cleared or approved by the U.S. Food and Drug Administration, and is not a diagnosis. It must not be relied upon for any medical decision. Always consult your treating dental provider, who remains responsible for interpreting your imaging and for your care.
  • Your rights over your imaging. Your scan is part of the medical record that your dental practice maintains as the covered entity under HIPAA. To access, correct, obtain a copy of, or restrict the use of your imaging, or to ask that a shared link be disabled, please contact your dental practice directly. Nothing in this notice limits any right you have under HIPAA or other applicable law, including your right of access to your own records.
  • Keep your link private. A shared link is personal to you and your authorized representatives. Please do not forward it or post it publicly, and do not attempt to access imaging that was not shared with you. If you received a link that was not intended for you, or you believe someone else has gained access to your imaging, please contact Prahsys at [email protected] (or, if you are the patient, your dental practice) so that access can be disabled.

SMS Messaging Services

Phone Number Collection and Consent: We collect phone numbers from merchants during account setup and from merchant customers who opt-in to Pay by Text services. Consent is obtained through:

  • Checkbox opt-in during merchant onboarding
  • Double opt-in confirmation for Pay by Text services
  • Clear disclosure of message frequency and data rates

SMS Data Usage: We use phone numbers and consent data to:

  • Send account notifications and alerts to merchants
  • Request additional information during the merchant onboarding process
  • Facilitate Pay by Text transactions when customers request to pay later via SMS
  • Provide transaction confirmations and payment reminders

Message Frequency: Merchants may receive 2-4 SMS messages per month. Pay by Text customers receive messages only for requested payment transactions.

SMS Data Sharing: SMS phone numbers and consent data are never shared with third parties for marketing purposes. We only share this information with our SMS service providers solely to deliver requested messages.


Data Governance and Security

  • Data Handling Standards: All data collected, including medical information and AI training data, is governed by strict access controls to prevent misuse or unauthorized access.
  • Token Handling in MSAs: Our Master Service Agreements (MSAs) include provisions for token management, ensuring secure storage and deletion protocols. Customers must adhere to these token management guidelines to prevent unauthorized access.
  • Unauthorized Access Prevention: Prahsys enforces strict token usage policies, including encryption, access controls, and expiration mechanisms to protect sensitive data.

Sharing Your Information

We do not sell personal data. However, we may share information in the following circumstances:

  • Service Providers: We work with third-party service providers to facilitate payment processing, analytics, and customer support.
  • Legal Obligations: We may disclose information in response to legal requests, law enforcement inquiries, or regulatory requirements.
  • Business Transactions: In the event of a merger, acquisition, or business restructuring, data may be transferred as part of the transaction.
  • With Your Consent: We will share data with third parties only if you provide explicit consent.

No Sharing Clause

No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.


Data Retention

We retain personal data only for as long as necessary to fulfill its original purpose, comply with legal requirements, resolve disputes, and enforce agreements. Once data is no longer required, it is securely deleted or anonymized.


Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal data, including:

  • Access: You may request access to the data we hold about you.
  • Correction: You may request corrections to inaccurate or incomplete information.
  • Deletion: You may request the deletion of personal data, subject to legal exceptions.
  • Opt-Out: You may opt out of promotional communications.

To exercise your privacy rights, contact us at [email protected].


International Data Transfers

If you access our Services outside the United States, your data may be transferred to and processed in the U.S. or other jurisdictions where our service providers are located. We take appropriate measures to ensure that your data is handled securely and in compliance with applicable regulations.


Children’s Privacy

Our Services are not intended for children under the age of 13. We do not knowingly collect or process data from children under 13. If we learn that such data has been collected, it will be deleted promptly.


Updates to This Privacy Notice

We may update this Privacy Notice periodically. Any changes will be communicated via email, website notifications, or other appropriate channels. Continued use of our Services after an update constitutes acceptance of the revised terms.


Contact Us

If you have any questions regarding this Privacy Notice, please contact us at:

Prahsys Inc.
Email: [email protected]