Privacy PolicyEffective Date: July 31, 2025
Neuroiam Inc.1. Who We Are & ScopeNeuroiam Inc. (“we,” “our,” or “us”) provides services that analyze user inputs (including text and voice) to identify strengths and deliver individual and team recommendations. This Privacy Policy describes how we collect, use, disclose, and protect personal data for individual users and organization customers (B2B), including their employees and contractors who participate in assessments (“Authorized Users”).
Age Restriction: Our services are intended for users 18+ only.
2. Categories of Personal Data We ProcessDepending on how you interact with the Service (individual or B2B), we process:
- Identifiers & Contact Data: name, email, phone, role/title, team, organization, contract owner contact details.
- Interview & Communication Data: messages with our AI companion, interview transcripts, audio and video recordings, and annotations.
- Calendar & Task Integrations (optional): events, attendees, task names/metadata necessary to provide recommendations.
- Usage & Device Data: IP address, device/browser type, OS, app version, log data, telemetry and interaction events.
- Payment/Subscription Data: limited billing metadata processed via payment processors (e.g., Stripe); we do not store full payment-card numbers.
- Inferences & Profiles: strengths assessment outputs, team readiness indicators, and other insights derived from your inputs and usage.
- Organizational Inputs (B2B): team roster, goals for using the Service, mission/objectives of the team/business unit, and role information provided by the Customer.
Do not submit special-category or highly sensitive data. We do not seek to collect special categories under GDPR (e.g., health, biometric, religious, sexual orientation), government IDs, payment card numbers, precise geolocation, internal disciplinary/sanctions records, or confidential business secrets.
3. Sources of Personal Data- Directly from you (registration, interviews, messages, uploads, settings)
- From your organization (B2B) — contract owner, HR/people ops, or team lead
- From integrations you authorize (e.g., calendars/task tools)
- From service providers (e.g., analytics, payment processors, hosting)
3A. B2B Customer Responsibilities: No Confidential or Unnecessary DisclosuresOrganization Customers must ensure participants do
not disclose:
- Special category personal data
- Government IDs, payment data, or precise location
- Third party personal data without lawful basis
- Confidential business information
- Internal disciplinary/sanctions records
Prohibited data will be treated confidentially but cannot be removed once submitted. Customers are responsible for proper instructions and anonymization.
4. How We Use Personal Data (Purposes)We process personal data to:
- Provide the Service (assessments, reports)
- Deliver team reports (within 10 business days)
- Operate integrations
- Improve quality and safety (including Human Review)
- Product analytics and research
- Security, fraud prevention, and incident response
- Business operations (billing, compliance)
- Communications and marketing (see §12)
5. Legal Bases (GDPR/UK GDPR)Depending on the context:
- Contract necessity
- Legitimate interests (balanced against your rights)
- Consent (where required)
- Legal obligation
For B2B, we act as
processor or
independent controller as permitted by law.
6. Human Review & Model-Assisted ProcessingWe may use trained specialists (under confidentiality obligations) to:
- Verify outputs
- Contextualize recommendations
- Address appeals and perform quality checks
Human Review is
not medical/psychological advice and does
not replace HR/legal processes.
7. Audio/Video Recording (Mandatory for Assessments)Recording is required for assessments and interviews.
- Notice & Consent: Participating affirms consent to recording and processing.
- Two-Party Consent (US): Express consent is mandatory where required.
- Use of Recordings: To generate insights, refine outputs, ensure quality and security.
8. Sharing & DisclosuresWe share data with:
- Service providers / subprocessors (e.g., hosting, Stripe, AI providers)
- Organization Customers (B2B)
- Legal & safety authorities when required
We do not sell personal data. We also do not “share” it for cross-context behavioral advertising as defined by CPRA.
9. International Data TransfersWe use safeguards like:
- Standard Contractual Clauses (EU/EEA)
- UK Addendum / IDTA
- Swiss equivalents
- Transfer risk assessments
10. Data RetentionData is retained:
- Until requested for deletion
- In line with legal requirements
- Some data (e.g., logs, audio) may have shorter retention by default
- Deletion or anonymization occurs within 30 days of request
11. SecurityMeasures include:
- 2FA
- Access controls
- Environment hardening
- Monitoring
- Encryption (planned)
No system is perfect; we strive for continuous improvement.
12. Your Privacy Choices- Access/Correction/Deletion: See §13
- Marketing: Opt out via unsubscribe links or email
- Cookies/Tracking: Consent obtained where required
- Recordings: Required for assessments. No consent = no participation
13. Your Rights (EU/EEA, UK, Switzerland)You may have the right to:
- Access
- Rectify
- Erase
- Restrict processing
- Object (including to profiling)
- Data portability
- Withdraw consent
We respond within
1 month (extendable).
You may lodge complaints with your
data protection authority.
Automated Decisions & Profiling You may request human review and explanations as required by law.
14. California Privacy (CCPA/CPRA)California residents have rights to:
- Know
- Delete
- Correct
- Non-discrimination
We do
not sell or “share” personal data for behavioral advertising.
Contact:
info@neuroiam.com15. Roles (B2B)For B2B:
- Customer = Controller
- Neuroiam = Processor (assessment-related processing)
- Neuroiam = Independent Controller (security, analytics, billing, etc.)
We comply with applicable laws and this Policy.
EU/UK Representatives: Contact info@neuroiam.com for current inquiries.
16. Changes to This PolicyWe may update the Policy.
Material changes will be notified via the Service or email.
Continued use = acceptance of changes.
17. Contact UsNeuroiam Inc.Email:
info@neuroiam.comFor privacy requests, email with subject line
“Privacy Request” and include sufficient information for verification.