Materia Labs

PATIENT PERSONAL DATA PROCESSING NOTICE — instapharm (Patient Privacy Notice — Article 13 GDPR)

Version: 1.1.0 (Beta) Effective date: 1 July 2026

This Notice is provided by «MATERIA TECHNICA P.C.» ("Materia Technica", "we") to you, as a patient and user of the «instapharm» app, in accordance with Article 13 of the General Data Protection Regulation (Regulation (EU) 2016/679, hereinafter "GDPR"), Law 4624/2019, Law 3471/2006 and the other applicable Greek personal-data legislation.

The purpose of this Notice is to inform you clearly about who processes your data, for which purposes, on which legal basis, for how long, with which third parties it may be shared, and which rights you have. Please read it carefully before using the app.


I. WHO WE ARE

The private capital company under the name «MATERIA TECHNICA P.C.» (trading as

«MATERIA TECHNICA»):

- Seat: 8A Saki Karagiorga Street, 15121, Pefki, Attica - VAT No.: 802200695, Tax Office of Amarousio - G.E.MI. No.: 171973201000 - Contact for personal-data matters (Privacy Lead): Theodoros Katsaros email: privacy@materiatechnica.com / privacy@materia-labs.ai tel.: +30 698 854 3617

The «instapharm» app allows patients to connect with one or more pharmacies, to track their electronic prescriptions through the National Electronic Prescription System (operated by IDIKA — "Η.Δ.Υ.Κ.Α."), to authorise a third person to collect medicines on their behalf, and to receive notifications relating to the dispensing of their prescriptions.

II. WHO IS THE DATA CONTROLLER — ROLES AND LIMITS

The processing of your personal data in the context of the «instapharm» app is shared between Materia Technica and the pharmacy / pharmacies to which you are connected. It is important to understand the difference:

(a) For your «instapharm» account as such — that is, for the creation and management of your account, the display and support of the app, the functional (push) notifications, the management of authorisations to a third person to collect medicines, the enabling/disabling of commercial communications, and the keeping of the platform's operational security logs — Materia Technica acts as an independent Controller within the meaning of Article 4(7) GDPR. This Notice covers that flow.

(b) For the dispensing of your prescription at a specific pharmacy — that is, for searching for and identifying you at the pharmacy, retrieving and dispensing your electronic prescription through IDIKA, the automated regular retrieval of prescription status (Polling) on behalf of the pharmacy, the collection of medicines by an authorised third person, and the keeping of audit records of access to patient data — the Controller is the pharmacy you have selected, on the basis of its operating licence and Greek pharmaceutical law (Law 1963/1991, Law 4512/2018, Article 64 of Law 4509/2017, Presidential Decree 340/1993). In these flows Materia Technica acts as a Processor under a contract pursuant to Article 28

GDPR.

For those flows, the separate Data Protection Notice provided to you by the pharmacy itself applies. We encourage you to ask your pharmacy for its own Notice.

III. WHAT DATA WE PROCESS

In the context of the flows for which Materia Technica is an independent Controller (Section II(a)), we process the following categories of your data:

1. Identification details: first name, surname, AMKA (social-security number, where provided), and — optionally — date of birth. The date of birth is not requested as a general age threshold upon registration; it is collected only where required for a specific feature (e.g. confirmation of the 15-year threshold at the point of activation of an optional consent-based feature — Article 21 of Law 4624/2019; see Section XII). 2. Contact details: mobile telephone number, email address (optional), postal address (optional). 3. Device and technical data: device token for push notifications, device characteristics (operating system, model), IP address during use, session identifiers. 4. Account data: user identifier, registration timestamp, record of acceptance of the Terms of Use and of this Notice (version, text shown, IP, timestamp). 5. Prescription Data: structured metadata and structured content of your electronic prescription as retrieved from IDIKA, for as long as dispensing is pending. *Note*: the primary role over the Prescription Data belongs to your pharmacy — see Section II(b). 6. Execution Data: date of dispensing, dispensing pharmacy, prescription status. The Execution Data is monitored by Materia Technica as supporting processing for your pharmacy — see Section II(b). 7. Third-party authorisation (Delegation) data: details of the third person you authorise, the scope of the authorisation, your digital signature on the relevant form, the date/time and the text signed. 8. Commercial-communication data: the indication of consent or refusal to receive commercial communications, as well as the date and text of the consent or of its withdrawal. 9. Audit Logs: operational logging records of the app (technical events, errors, timestamps), the register of regular retrieval/dispensing of IDIKA prescriptions, and consent/registration evidence (version, text, timestamp). During the Beta an immutable (append-only), per-user record of every access to patient data is not kept; per-access logging is a planned future addition. These records are used exclusively for security, audit and compliance-evidence purposes. 10. Usage-analytics data and error diagnostics: (a) usage metadata of the platform (behavioural analytics) collected client-side and server-side through the subprocessor PostHog; and (b) error and crash metadata (error & crash monitoring) collected through the subprocessor Sentry on the platform (server + browser) and in the mobile app, to ensure proper operation, error correction and security.

Client-side analytics collection (PostHog) operates on a cookieless basis, in memory only: no information is stored on, nor accessed from, the terminal equipment; session replay is disabled and details that might identify a patient (on-screen text, parts of URLs) are masked.

The error diagnostics (Sentry) are sanitised before being sent (sendDefaultPii=false; no session replay/profiling/recordings): they do not include AMKA, telephone number, signature or prescription content, but only the error type/message (sanitised) and a pseudonymous installation identifier. The mobile app embeds an error/crash-monitoring tool (Sentry), but not a behavioural analytics-tracking tool.

As, for client-side analytics, no storage of, or access to, information on the terminal equipment takes place (and the local temporary storage of crash data in the mobile app is strictly necessary for its operation), no consent banner is required under Article 4(5) of Law 3471/2006. The legal basis is legitimate interest (Article 6(1)(f) GDPR) in the improvement and secure operation of the service, with the possibility to object (opt-out). The data is hosted within the EU (PostHog EU Cloud; Sentry EU — de.sentry.io, Frankfurt). 11. Location data: the approximate or precise location of your device, only if you grant the relevant permission, and exclusively to find and suggest nearby pharmacies. Location is used at the moment of the search and is not kept for other purposes, nor used for tracking. You may revoke the location permission at any time from your device settings (see Section XIV). 12. Dosage-schedule and medication-reminder data: if you activate the relevant feature, your medication-taking schedule (medicines, dosage, times/frequency) and your reminder settings. This data may constitute health data (Article 9 GDPR) and is processed as set out in Section

IV(H).

13. Device-calendar data (local): if you so choose, medication reminders can be entered as events in your device's calendar. These events are stored locally on your device, under your control, and you can delete them through the app or through your calendar settings.

Some of the above constitute special categories of data within the meaning of Article 9 GDPR (health data — in particular the Prescription and Execution Data, as well as the dosage-schedule / medication-reminder data). Their processing is permitted only in the cases of Article 9(2), as set out in more detail in the next Section.

IV. FOR WHICH PURPOSES AND ON WHICH LEGAL BASIS

For each processing purpose within the flows of Section II(a), we state the legal basis separately:

(A) Creation and management of your account in the app. Legal basis: Article 6(1)(b) GDPR (performance of the Terms-of-Use contract). The app may be used for yourself or, through representation, for a dependant whom you lawfully represent; no general age threshold of 15 years applies to these core functions (see Section XII).

(B) Identifying you at the pharmacy and facilitating the dispensing of an electronic prescription (primary Controller: your pharmacy). Legal bases in the context of our supporting processing: - Article 9(2)(h) GDPR (provision of health services by a lawfully licensed health professional — your pharmacy), - Article 6(1)(b) + (c) GDPR (performance of a contract + compliance with a legal obligation — Presidential Decree 340/1993, IDIKA manual on the dispensing of paperless prescriptions, Dec. 2023).

(C) Regular Polling of Prescription Status from IDIKA, on behalf of your pharmacy. This is an expressly disclosed processing purpose: the app and the platform carry out automated, regular retrieval of prescription status through the IDIKA interface, so that your pharmacy is automatically informed when a prescription is pending dispensing.

Legal bases: Article 9(2)(h) GDPR + Article 6(1)(b) GDPR (performance of the service contract between your pharmacy and Materia Technica).

Execution model (data minimisation under Article 5(1)(c) GDPR): retrieval is carried out first in a status-list form. Full prescription retrieval is carried out exclusively for prescriptions whose status has changed. Each retrieval is recorded in the retrieval/dispensing register (timestamp, scope); the retrieval is performed by an automated service without per-user identification.

The technical standards and the Polling rate are observed in line with IDIKA's communication (up to 500 requests per second per IP).

(D) Management of a third-party authorisation to collect medicines (Delegation) — as regards the right to authorise and the infrastructure to evidence it. Legal basis: Article 6(1)(a) + Article 9(2)(a) GDPR (your explicit consent). You may withdraw your consent at any time — withdrawal does not affect the lawfulness of prior processing.

*Note*: when the authorised person appears at the pharmacy to collect a medicine, the legal bases of Section (B) above additionally apply — that part of the flow belongs to your pharmacy.

(E) Functional notifications (push notifications). Purpose: to inform you of new prescriptions pending dispensing, active authorisations, changes of app status.

Legal basis: Article 6(1)(b) GDPR (performance of the Terms-of-Use contract).

Opacity design rule (push opacity). The content of push notifications is kept generic and opaque (e.g. "New update — open the app"). It does not contain the medicine name, the health status, your AMKA, raw technical error messages from IDIKA, or any other element that reveals health-related or sensitive information. Details are displayed only within the app, after your authentication. See Section VIII for more.

(F) Commercial communication (marketing). Purpose: to inform you of new app features, commercial promotions (including promotions of pharmacies to which you are connected).

Legal basis: Article 6(1)(a) + Article 9(2)(a) GDPR (explicit consent), in conjunction with Law 3471/2006 on electronic communication.

You may withdraw your consent for commercial communication at any time through the app's settings, without this affecting your use of the other features.

*Beta note*: during the Beta, Materia Technica does not send commercial campaigns. The legal basis and the consent mechanism are maintained so that you can exercise an informed choice when such communications begin.

(G) Security, fraud prevention, operational logging. Purpose: to prevent malicious access, to prevent unauthorised use of patient data, to keep operational logging records in accordance with Article 32 GDPR.

Legal basis: Article 6(1)(f) GDPR (the legitimate interest of Materia Technica and of patients in the security of the Platform).

A balancing of interests has been carried out: we process minimal metadata (operational events, timestamp, scope of action). During the Beta a per-user record of every access to patient data is not kept (see Section III.9). We do not use these records for any other purpose (e.g. commercial profiling, targeting, differentiated pricing).

(H) Medication reminders and dosage-schedule management. Purpose: to help you monitor and adhere to your medication through optional reminders.

Legal basis: Article 6(1)(a) + Article 9(2)(a) GDPR (your explicit consent to the activation of the feature); where the dosage schedule derives from your prescriptions, the processing is additionally connected to the coordination of your pharmaceutical care (Article 9(2)(h) GDPR). You may disable the reminders and withdraw your consent at any time, without this affecting the other features.

(I) Finding nearby pharmacies (geolocation). Purpose: to suggest pharmacies near your location.

Legal basis: Article 6(1)(a) GDPR (consent, through your device's location permission). Location is used only at the moment of the search; for the conversion of addresses into coordinates the subprocessor Mapbox may be used (see Section VI), which does not receive health data. You may revoke the location permission at any time from your device settings.

(J) Other features that require device permissions (camera for scanning a barcode/photographing a prescription, microphone for voice entry *(upcoming feature)*, calendar for reminders). Legal basis: Article 6(1)(a) GDPR (consent through the corresponding device permission). For details of each permission, see Section XIV.

V. RECIPIENTS — WITH WHOM WE SHARE YOUR DATA

1. The pharmacy / pharmacies to which you are connected. As stated in Section II, these pharmacies are independent Controllers for the prescription-dispensing flows. They have their own channels for informing patients about their own flows.

2. IDIKA Single-Member S.A. (Η.Δ.Υ.Κ.Α. Μ.Α.Ε.) — a public health- infrastructure body, as the operator of the National Electronic Prescription System. IDIKA is a separate Controller on the basis of its own legal regime.

3. Subprocessors of Materia Technica. Detailed in Section VI.

4. Judicial, supervisory and tax authorities, where there is a legal obligation to disclose or where there is voluntary cooperation following a lawful order.

VI. SUBPROCESSORS

Materia Technica uses selected third-party service providers (Subprocessors), bound by contractual data-protection obligations under Article 28 GDPR:

ProviderRole / purposeProcessingLocation
Clerk Inc.User authenticationMobile number, name, profile pictureUSA (SCCs)
Google LLC / Firebase Cloud MessagingSending push notificationsDevice token, prescription identifier, status. Not medicine name / health status / AMKA.USA (SCCs)
Vercel Inc.App hosting (hosting / serverless functions)Request metadata, IPEU (Western Europe region) with US parent (SCCs)
Supabase Inc.Database (PostgreSQL) and file storage (object storage)Storage of all app data, including prescription data (IDIKA XML), digital signatures and health dataEU — Frankfurt (eu-central-1); US parent (SCCs)
Novu Co.Notification orchestrationRecipient identifier, flow metadataEU (primary), US parent (SCCs)
PostHog Inc.Usage analytics (behavioural), client- and server-sideUsage metadata (error monitoring has moved to Sentry). Client-side collection operates without cookies (cookieless, in-memory only — no storage of, or access to, information on the terminal equipment), session replay is disabled and details that might identify a patient are masked; legal basis is legitimate interest (Article 6(1)(f) GDPR), with no consent banner (Article 4(5) of Law 3471/2006 is not triggered), with the possibility to object (opt-out).EU (PostHog EU Cloud) with US parent (SCCs)
Functional Software, Inc. (Sentry)Error & crash monitoring — platform (server + browser) and mobile appSanitised error metadata (type/message, stack trace, version, pharmacy tag); no AMKA, telephone, signature or prescription content, no session replay, sendDefaultPii=false; only a pseudonymous installation identifier. Legal basis is legitimate interest (Article 6(1)(f) GDPR). The Sentry DPA expressly prohibits special categories (Article 9).EU — de.sentry.io (Frankfurt); US parent (DPF + SCCs)
Expo (650 Industries Inc.)Delivery of push notifications to mobile devices (Expo Push → APNs/FCM)Device token; the notification content is transient and is not storedUSA (Google Cloud) — SCCs + DPF
Resend (Plus Five Five Inc.)Sending transactional emailFull name and partially masked telephone number (pharmacy interest-expression email)USA — SCCs + DPF
SMS.to (Intergo Telecom Ltd)Sending SMS (one-time login code + welcome SMS)Mobile telephone number, authentication codeCyprus (EEA); servers in EU/USA (SCCs where required)
Mapbox Inc.Address autocomplete and geocoding (pharmacy addresses only — not patient/health data)Address to be searched, requester's IP addressUSA — SCCs + DPF

(Note: the subprocessor DocuSign is used exclusively for the signing of contracts between Materia Technica and your pharmacy — it does not process your personal data as a patient.)

(Note: the delivery of web push notifications to browsers / Apple is carried out through infrastructure operated by Materia Technica itself (VAPID protocol) and not through a third-party provider; only the technical details of the push subscription are stored (endpoint, p256dh/auth keys).)

The above table is the current list of subprocessors for the Beta version. When a subprocessor is added or replaced, this Section is updated and, where required, the corresponding notification is sent to the cooperating pharmacists.

VII. TRANSFERS OUTSIDE THE EEA

Where subprocessors are established or carry out processing outside the European Economic Area (EEA), the following apply:

1. Standard Contractual Clauses (SCCs) of the European Commission (Implementing Decision (EU) 2021/914), as an appropriate safeguard under Article 46(2)(c) GDPR. 2. Transfer Impact Assessments (TIA) per subprocessor outside the EEA. 3. Additional technical mitigation measures where applicable — in particular (a) the push-content opacity design rule (Sections IV-E and VIII), which reduces the scope of data transferred to Firebase / FCM, and (b) the sanitisation (scrub) of error diagnostics before they are sent to the subprocessor Sentry (sendDefaultPii=false, no session replay, masking of AMKA / telephone / prescription content), so that no health data is transferred.

Some subprocessors with a US parent company store the data in an EU region (in particular Supabase — Frankfurt, PostHog EU Cloud, and Sentry — de.sentry.io / Frankfurt); for those transfers the EU–US Data Privacy Framework (DPF) (Functional Software, Inc. / Sentry is an active DPF member, participation #5869) and the SCCs (Implementing Decision (EU) 2021/914) apply, as applicable.

A copy of the SCCs and the relevant documentation may be requested at privacy@materiatechnica.com / privacy@materia-labs.ai.

VIII. PUSH NOTIFICATIONS — DESIGN RULE

All push notifications of the «instapharm» app observe the content opacity design rule:

- The visible text of the notification does not contain a medicine name, a health status or any other element that reveals health-related content. - The mention of the pharmacy's name is permitted (e.g. "Your prescription is ready at pharmacy X"), which does not reveal a medicine or a health status. - The full content of the update (medicines, health status) is displayed only within the app, after your authentication. - Specifically for notifications of a failure or a problem in dispensing a prescription, the visible text does not contain your AMKA or raw technical error messages from IDIKA; the relevant details are displayed only within the app, after your authentication.

This rule is applied as an additional security measure and as a transfer-impact mitigation measure (Section VII), given that Firebase / FCM is a subprocessor established in the USA.

IX. RETENTION PERIOD

We keep your data only for as long as is necessary for the purposes for which it was collected, or for as long as is required by applicable law.

We keep each category of data for the following period:

- User account and identification / contact details: for as long as you maintain an active account. An accounting-retention obligation of five (5) years (Article 7 of Law 4308/2014) arises only if an accounting document is issued; for a free account without any payment, no such obligation arises. - Authentication/session, device data and push records: for as long as the operational need lasts and, for the related security records, for a maximum of ninety (90) days, under Articles 5(1)(c) and (e) and 32 GDPR. - Evidence of acceptance of terms (B1/B2) and signed authorisations (third-party authorisation): for as long as the relationship lasts and for a short evidentiary period thereafter (in principle twelve (12) months from the closing of the account), with extension only where a specific dispute, complaint or claim exists (retention for the establishment, exercise or defence of legal claims, Article 17(3)(e) GDPR). We do not apply a fixed ten-year limit. - Audit logs: the twenty-four (24)-month limit is of future application — it presupposes the future implementation of a per-access logging record (AuditLog), which does not exist during the Beta; operational records are kept for the investigation of a security incident or for legal retention (Articles 5 and 32 GDPR). - Commercial-communication consent: for as long as it remains active and for a further five (5) years as evidence after withdrawal or last use (Article 7(1) GDPR; Law 3471/2006); we additionally keep a minimal suppression record, so as not to contact you again, for as long as required. - Usage-analytics data (PostHog) *(behavioural; error monitoring has moved to Sentry)*: up to twelve (12) months; this is platform usage metadata (see Sections III and VI), on the basis of legitimate interest (Article 6(1)(f) GDPR) under the "Path A" approach, which is pending final confirmation. - Error diagnostics (Sentry): errors/crashes are retained for up to ninety (90) days; trace samples (traces) for up to thirty (30) days; no session replay is kept. The data is hosted by the subprocessor in an EU region (de.sentry.io / Frankfurt) and is deleted at the end of the contract, on the basis of legitimate interest (Article 6(1)(f) GDPR).

The above positions are documented on the basis of primary legal research; their final validation by legal counsel is pending before the full release and, should they change, this Section is updated with a new version of the Notice.

X. DATA SECURITY

Materia Technica applies appropriate technical and organisational measures to protect your data, in accordance with Article 32 GDPR:

- Encryption in transit (TLS 1.2 or later) and at rest (encryption at rest) in the database. - Multi-factor authentication (MFA) for all employees with access to production infrastructure. - Least-privilege principle in the database. - Operational logging records of the app and centralised monitoring with alerting, as well as a register of regular retrieval/dispensing of IDIKA prescriptions. During the Beta an immutable (append-only), per-user record of every access to patient data is not kept (a planned future addition). - Secrets management outside the code and the repository. - Regular vulnerability management and updating of dependencies. - A tested backup and recovery plan.

XI. YOUR RIGHTS

You have the following rights as a data subject (Articles 15-22 GDPR):

1. Access (Article 15): to learn which of your data we hold and how we process it, and to receive a copy of it. 2. Rectification (Article 16): to request the correction of inaccurate or incomplete data. 3. Erasure / Right to be Forgotten (Article 17): to request the deletion of your data, under the conditions of the GDPR. 4. Restriction of processing (Article 18): to request a temporary restriction of the processing. 5. Portability (Article 20): to receive your data in a structured form or to request its transmission to another Controller. 6. Objection (Article 21): to object to processing based on legitimate interest (Section IV-G), setting out the particular reasons relating to your situation. 7. Withdrawal of consent (Article 7(3)): where processing is based on consent (commercial communication, third-party authorisation), you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of the prior processing. 8. Right not to be subject to an automated decision (Article 22): we do not make automated decisions under Article 22 — see Section XIII.

How to exercise your rights:

- Where an in-app function is available (e.g. withdrawal of commercial-communication consent, management of authorisations), through the app. - By sending a request to privacy@materiatechnica.com / privacy@materia-labs.ai. - We respond within thirty (30) days (Article 12(3) GDPR), possibly extended by sixty (60) days for complex requests, with relevant information to you within the initial deadline.

XII. MINORS — DEPENDANTS

The processing of health data for the core care-coordination and prescription-dispensing functions is based on the necessity of providing and coordinating healthcare (Article 9(2)(h) GDPR in conjunction with Article 22(1)(b) of Law 4624/2019). This processing is not subject to the age threshold of fifteen (15) years — that threshold concerns exclusively processing based on consent (Article 21 of Law 4624/2019, Article 8 GDPR). Consequently, we do not apply a general age exclusion, nor a mandatory recording of the date of birth upon account creation.

Minors through representation. The app may be used for a child or other dependant by the person exercising parental care or their legal representative (Articles 1510 and 1516 of the Civil Code), on the basis of the child's own AMKA — following the model of IDIKA's paperless prescribing for a protected / dependent member. As a rule, no notarial act or upload of custody documents is required; additional supporting evidence is requested only where this is reasonably necessary (e.g. non-parent representatives, known custody restrictions, conflicting claims).

Dependant profile of a minor. When you create a dependant profile for a minor child, you sign a solemn declaration of guardianship and gain access to the child's health data (prescriptions, orders, reminders, medication), receiving the relevant notifications yourself, on behalf of the child. Access concerns only that specific child and terminates automatically when they reach the age of 18 (calculated from the AMKA at the time of each access). The legal basis remains Article 9(2)(h) GDPR (provision of care) — not consent; the declaration of guardianship evidences the power of representation (Articles 1510 and 1516 of the Civil Code, Law 1599/1986). The child remains the data subject, with rights under Articles 15-22 GDPR, exercised until adulthood through their representative, taking account of their maturity (Article 1511 of the Civil Code).

Minors aged 15-17. A minor aged 15-17 may use the app for their own already-prescribed prescriptions; informing the person exercising parental care is desirable and not mandatory.

Optional features with consent. Where any optional feature based on consent is offered (e.g. commercial communication) and the user is under 15, consent is given or approved by their legal representative, at the point of activation of the feature.

XIII. AUTOMATED DECISIONS

We do not make automated decisions producing legal effects or significantly affecting you within the meaning of Article 22 GDPR (e.g. automatic medical diagnosis, automatic prescribing, automatic determination of a treatment plan).

The automatic dosage-suggestion feature through AI has been postponed from this Beta and is not implemented. If it is reintroduced, this Notice will be amended to describe the logic, the significance, and the consequences of the automated processing — and your explicit consent will be requested where required.

XIV. DEVICE PERMISSIONS

The «instapharm» app requests certain permissions to access functions of your device. Each permission is optional, is requested with your explicit consent at the moment you use the relevant feature (Article 6(1)(a) GDPR), and may be revoked at any time from your device settings:

- Notifications (push): to receive functional notifications (see Sections IV(E) and VIII). - Camera: to scan the barcode/QR of the prescription and to photograph a prescription document, where supported. We do not gain access to your photos beyond the capture you carry out within the app. - Microphone / voice entry *(upcoming feature — not active during the Beta)*: foreseen for the optional voice entry of prescription details (speech-to-text). When activated, the microphone permission will be requested, the recording will not be kept beyond what is required for the conversion, and — where the conversion is carried out through a third-party provider — that provider will be added to Section VI with a corresponding update of this Notice. - Location: to find nearby pharmacies (see Section IV(I)). Used only at the moment of the search. - Calendar: for the optional entry of medication reminders as events in your device's calendar, which are stored locally (see Section III.13). - Photo library: not used during the Beta; should it be activated in the future, separate consent will be requested and this Notice will be updated.

The non-provision or revocation of a permission limits only the specific feature and not the overall use of the app.

XV. ACCOUNT DELETION

You may request the deletion of your account at any time:

- Within the app, through the delete-account option in the settings; and/or - by sending a request to privacy@materiatechnica.com / privacy@materia-labs.ai.

Upon deletion of your account, we delete or anonymise the personal data we hold as an independent Controller (Section II(a)), and we delete/deactivate the device token for push notifications.

Exceptions: we may retain certain data to the extent and for the period imposed by law or for the establishment, exercise or defence of legal claims, in accordance with Section IX (Retention Period). Data relating to the dispensing of prescriptions at your pharmacy is kept by the pharmacy itself as Controller, in accordance with its own policy and pharmaceutical law (Section II(b)); for its deletion, address yourself to your pharmacy.

Deletion of the account does not affect the lawfulness of the processing carried out before it.

XVI. RIGHT TO LODGE A COMPLAINT WITH THE HDPA

You retain the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):

- Postal address: 1-3 Kifisias Avenue, 115 23, Athens - email: complaints@dpa.gr - telephone: +30 210 6475600 - website: www.dpa.gr

XVII. CHANGES TO THIS NOTICE

We reserve the right to amend this Notice. In the event of material amendments (e.g. the addition of a new purpose or of a new subprocessor outside the EEA, a change of the legal basis of a purpose), we will inform you within the app and you may be asked for renewed acceptance. In the event of non-material amendments (e.g. correction of typographical errors, renewal of contact details), the version number and effective date will be updated and the version history will be available at privacy@materiatechnica.com / privacy@materia-labs.ai.

XVIII. VERSIONS

VersionDateSummary
1.1.01 July 2026Addition of the subprocessor Sentry (Functional Software, Inc.) for error & crash monitoring on the platform and in the mobile app (EU region — de.sentry.io); update of §III.10, §VI, §VII and §IX (90-day retention). PostHog was limited to behavioural analytics (error monitoring moved to Sentry as of 27/06/2026). Corrected the statement that "the mobile app does not embed analytics-tracking tools" (it embeds Sentry for error diagnostics, not behavioural analytics). Legal basis for error monitoring: Article 6(1)(f) GDPR.
1.0.018 June 2026First version — start of Beta. Section XII (minors): core-care processing on the basis of Article 9(2)(h) GDPR / Article 22(1)(b) of Law 4624/2019, with no general age threshold; dependants through representation; 15-year threshold only for consent-based features. Includes sections on device permissions (XIV) and account deletion (XV), as well as data/purposes for location and medication reminders (III.11-13, IV(H)/(I)/(J)).

XIX. CONTACT

For any question or request relating to your data:

MATERIA TECHNICA P.C.

Privacy Lead: Theodoros Katsaros 8A Saki Karagiorga Street, 15121, Pefki, Attica email: privacy@materiatechnica.com / privacy@materia-labs.ai tel.: +30 698 854 3617

XX. LEGAL REFERENCES

- Regulation (EU) 2016/679 (GDPR). - Law 4624/2019 — national GDPR implementation measures; Article 21 age threshold. - Law 3471/2006 — protection of data in electronic communications. - Presidential Decree 340/1993 — Code of Pharmaceutical Ethics. - Law 1963/1991, Law 4512/2018, Article 64 of Law 4509/2017 — establishment, operation and licensing of pharmacies. - Law 4308/2014 — accounting standards. - Civil Code — Article 249 (general limitation period). - Implementing Decision (EU) 2021/914 — Standard Contractual Clauses. - IDIKA manual on the dispensing of paperless prescriptions, Dec. 2023. - HDPA model guidance for Article 13 notices.

© 2026 Materia Technica P.C. All rights reserved.