Privacy Policy

Our company is Neuronostics Limited.

Our company number is 11123728 and we are registered with the ICO as a data controller, number ZA506302. 

This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data. 

We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, accessible from https://www.neuronostics.com 

Definitions 

  • Service 
    Service is the https://www.neuronostics.com website operated by Neuronostics Ltd and the Neuronostics Platform (BioEP) 
  • Personal Data 
    Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession). 
  • Usage Data 
    Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit). 
  • Cookies 
    Cookies are small pieces of data stored on your device (computer or mobile device). 
  • Data Controller 
    Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your Personal Data. 
  • Data Processors (or Service Providers) 
    Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively. 
  • Data Subject (or User) 
    Data Subject is any living individual who is using our Service and is the subject of Personal Data. 

 

Your Privacy 

At Neuronostics, your privacy is important to us. This privacy policy explains what Personal Information Neuronostics (“Neuronostics”, “we”, “us”, “our”, “Platform”, “Services”) collects from you through our products and how we use that information.‌ 

Neuronostics serves a number of groups of users in different ways. References to products in this policy include Neuronostics services, which are offered through our websites and Platform. 

Please read product-specific details in this privacy policy, which provide additional information about some Neuronostics products.‌ 

This policy applies to all users of Neuronostics products or services or its affiliates anywhere in the world, and to anyone else who contacts or otherwise submits information to Neuronostics, unless noted below. 

Data Protection Principles 

We are committed to complying with all applicable data protection law and principles, which means that your Personal Information will be: 

  1. Processed lawfully, fairly and in a transparent way; 
  2. Collected for specific, explicit and legitimate purposes stated in this policy and not used in any way that is incompatible with those purposes; 
  3. Adequate, relevant and limited to what is necessary for those purposes; 
  4. Accurate and, where necessary, kept up to date; 
  5. Kept for no longer than is necessary for those purposes; and 
  6. Processed securely. 

 

Accountability is an important data protection principle. Neuronostics must put in place appropriate technical and organisational measures to meet these requirements and review and update where necessary the measures that have been put into place. Being accountable is key to maintain trust with other parties and may help mitigate any enforcement action if the situation arises. 

 

Collection of Personal Information  

Neuronostics acts as the data controller for the information you provide or that is collected by Neuronostics or its affiliates. Neuronostics collects Personal Information to operate effectively as a business and to provide you, the user, with tailored services and products. 

You have choices about the Personal Information we collect. When you are asked to provide Personal Information, you may decline. But if you choose not to provide Personal Information that is necessary in order for us to provide services to you, you may not be able to use that product. 

We provide further information below on the types of Personal Information we obtain and how we use them, throughout your use of our products and services. 
 

Collection of Personal Information ‌ 

Information you give to us:‌ 

We will collect and process the Personal Information from you that you give to us by filling in forms on our website or software or by corresponding with us by phone, email or otherwise. It includes information you provide when you register to use the site or our software products, subscribe to our service, search for a product, participate in discussion boards or other social media functions on or via the site or software products, enter a competition, promotion or survey, submit a query, and when you report a problem with the site or our software. All Personal Information is kept private and will not be shared without obtaining your prior consent. ‌ 

If you are asked to provide this express consent, we will clearly and unambiguously explain to you what Personal Information we will be sharing, with whom and for what purpose. Consent in regards to use of our Platform is requested via agreement of our Terms and Conditions. 

The (“Personal Information”) you give us may include the types described below (the purpose of data collection is written next to each):‌ 

  • Your name; to create a Neuronostics account 
  • Email address; to create a Neuronostics account 
  • Phone number; to create a Neuronostics account 
  • Date of birth 
  • Medical History 
  • Demographic information 
  • Password; to create a Neuronostics account. We are not able to access user passwords. 
  • General identifiers; your NHS number may be collected to ensure you are correctly identified by your Healthcare Provider 

 

‌Other: 

  • Gender 
  • Ethnicity 

 

‌Any information about your health and ethnicity is classed as sensitive Personal Information and we ensure that additional safeguarding measures are in place to protect this information. Our lawful basis for processing this sensitive Personal Information is your consent. You can withdraw your consent at any time – for more information please email dpo@neuronostics.com 

 

 Engagement data, Cookies and other data collection technologies 

For all users, when you begin to use our software or services, we monitor engagement and feature usage on our platform by recording every interaction you have with products you are registered on. This includes, but is not limited to, page visits, content viewed and logs made on our platform.‌ 

We also infer your location based on your IP address during registration and for opt-ins. In addition to IP address, our platform automatically collects data about your device, including the model, platform, locale code and UUID (universally unique identifier) every time you visit the Neuronostics website or use our software. This information may also be collected in combination with an identifier associated with your device to enable us to recognise your mobile browser or device when you return to the site or our software.‌ 

Neuronostics uses cookies and similar technologies to allow us to store your personal preferences and settings; optimise login processes; maintain a high level of security and to monitor and analyse performance of our online services. On our website, we may use traffic log cookies to track pages you view. The purpose of this is to analyse web page traffic in order to further optimise the journey users must undertake to access content that is relevant to them. You may adjust the settings on your browser to refuse cookies, however, this may lead to limited access to our online services. 

In addition to cookies, we may log information about your device, including the existence of cookies, your IP address and information about your browser. The purpose of this information collection is to diagnose service issues and to administer and track your usage of our platforms.‌ 

Information about your visit may include the full Uniform Resource Locators (URL), clickstream to, through and from the site, and any phone number used to call our customer service number or social media handle used to connect with our customer service team.‌ 

 

Legal Basis for Processing Personal Data Under General Data Protection Regulation (GDPR) 

If you are from the European Economic Area (EEA), Neuronostics Ltd legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it. 

Neuronostics Ltd may process your Personal Data because: 

  • We need to perform a contract with you 
  • You have given us permission to do so – e.g. marketing communication where we’ve asked for consent, such as for people who sign up for our newsletter via our website. Consent can be withdrawn, but this may then affect what we can do for you. 
  • The processing is in our legitimate interests and it’s not overridden by your rights 
  • To comply with the law 
  • To carry out user/product research 

 

How Neuronostics uses your Personal Information 

To operate effectively as a business and to perform essential business operations, including developing and providing products optimised for patients and clinicians. 

Neuronostics may contact you directly by email to find out how the product you are using is working for you. We do this so that we can improve our products and make them more beneficial to our users. If you choose to provide us with information about your experiences using Neuronostics products (e.g. via a questionnaire we send out), we may contact you for clarification with regards to specific information that you provide. Any information you provide will be held by Neuronostics (and not shared externally) for 15 years. 

Neuronostics uses your Personal Information to identify you and notify you about changes to our service. We infer your location from your device IP address in order to geo-restrict certain content on our platform.‌ 

Product issues, identified by users and communicated through customer support, are effectively diagnosed and resolved using data collected from interactions on the platform. Decisions on product development and evaluations of product performance are based on aggregate analysis and business intelligence. 

Neuronostics may use your email address, phone number and/or details to present you with occasional marketing messages where you have opted in to receive these, based on our legitimate interest in marketing our services to you and subject to your right to opt out at any time. We also use third parties (such as LinkedIn, Google, Facebook, YouTube) to serve advertisements that may be of interest to you on other websites. ‌‌ 

In addition to the specific disclosures of Personal Information set out in this section, we may disclose your Personal Information where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. We may also disclose your Personal Information where such disclosure is necessary for the establishment, exercise or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.‌ 

To deliver communications of personal interest including product and content releases, motivational prompts and in response to product queries or support requests.‌ 

Direct communications 

Communications sent by Neuronostics come in the form of emails to the email address provided by you during the registration process and through notifications delivered to your device. Neuronostics may send you communications relating to new and existing product and content releases and updates. We send such communications so that you are aware of changes we are making to the content or features of our products, or new releases, which could affect the usefulness of our core services to you. 

Third party communications 

We may ask you during registration whether you want to receive third party communications such as promotional material related to other services outside of our platform. You, of course, have the right to opt out of such email communication at any time by using the unsubscribe link, found at the bottom of every email, or by updating your account setting in the Platform. Neuronostics will not send you communications unrelated to its core services, unless you specifically tell us you are interested in receiving them. 

Transparency and Choices 

In this section, we have summarised the rights that all users of Neuronostics software products and services have under data protection law. We recommend that you read the relevant laws and guidance from the regulatory authorities for a full explanation of these rights. 

Your principal rights under data protection law are: 

  1. the right to be informed; 
  2. the right of access; 
  3. the right to rectification; 
  4. the right to erasure; 
  5. the right to restrict processing; 
  6. the right to data portability 
  7. the right to object; and 
  8. rights in relation to automated decision making and profiling.

 

You have the right to ask us to confirm whether or not we hold or process your Personal Information and, where we do, access to the Personal Information, together with certain additional information. That additional information includes details of the purposes of the processing, the categories of Personal Information concerned and the recipients of the Personal Information. Providing the rights and freedoms of others are not affected, we will supply to you a copy of your Personal Information, or do one of the following: 

 

  1. We may ask you to verify your identity, or ask for more information about your request; or 
  2. Where we are legally permitted to do so, we may decline your request, but we will explain why if we do so.

 

You have the right to have any inaccurate Personal Information about you rectified and, taking into account the purposes of the processing, to have any incomplete Personal Information about you completed. 

In some circumstances, you have the right to the erasure of your Personal Information without undue delay. Those circumstances include: the Personal Information is no longer necessary in relation to the purposes for which it was collected or otherwise processed; you withdraw consent to consent-based processing; you object to the processing under certain rules of applicable data protection law; the processing is for direct marketing purposes; and the Personal Information being unlawfully processed. However, there are exclusions of the right to erasure. The general exclusions include where processing is necessary, for example: for exercising the right of freedom of expression and information; for compliance with a legal obligation; or for the establishment, exercise or defence of legal claims. 

You have the right to request that your Personal Information is no longer processed for example, due to the inaccuracy of the Personal Information or the reason for the Personal Information being processed. 

If you have given additional consent for your Personal Information to be shared to a third party, including academic institutions, medical device companies and pharmaceutical companies, you have the right to withdraw this consent at any time. You have the right to request that your Personal Information be transferred to another party. 

If you consider that our processing of your Personal Information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement.‌‌ 

To the extent that the legal basis for our processing of your Personal Information is consent, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal. If you opted in to third party marketing communications when you registered, you may opt-out at any time within the Platform, or by emailing dpo@neuronostics.com 

Lastly, you will not be subject to decisions that will have a significant impact on you based solely on automated decision-making. 

You may exercise any of your rights in relation to your Personal Information by written notice to us or via any of the methods specified in section 7. We will respond to requests to exercise your rights  in relation to your Personal Information within 1 month. 

To contact us in relation to any of these requests, please use the email address dpo@neuronostics.com 

 

Retention of Data 

Neuronostics Ltd will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with Platformlicable laws), resolve disputes, and enforce our legal agreements and policies. 

Neuronostics Ltd will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods. 

 

Transfer Of Data 

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. 

If you are located outside United Kingdom and choose to provide information to us, please note that we transfer the data, including Personal Data, to United Kingdom and process it there. 

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer. 

Neuronostics Ltd will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organisation or a country unless there are adequate controls in place including the security of your data and other personal information.  

Neuronostics is committed to protecting the security of Personal Information by endeavouring to ensure appropriate technologies and processes are maintained to avoid unauthorised access or disclosure. We utilise, for all data storage and processing purposes, Amazon Web Services (“AWS”), Google’s G Suite and Google Cloud. Specifically, all our AWS storage containers and databases are located in London (UK) . All Personal Information collected by Neuronostics software products is encrypted to the highest possible degree both when it is stored in our databases and when it is being transmitted. 

 

Service Providers 

We may employ third party companies and individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, to perform Service-related services or to assist us in analysing how our Service is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. 

 

Links To Other Sites 

Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. 

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services. 

 

Children’s Privacy 

Our current product does not address anyone under the age of 18 (“Children”). However, for the purposes of research relating to future product development, we may collect personally identifiable information from “Children” under the age of 18.  

 

Changes To This Privacy Policy 

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the “effective date” at the top of this Privacy Policy. 

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. 

 

Contact Us 

If you have any questions about this Privacy Policy, please contact us: 
By visiting this page on our website: https://www.neuronostics.com/contact/ 

In the UK, general information on protection of Personal Information, including your rights and freedoms under the General Data Protection Regulation, is available via the Information Commissioner’s Office (“ICO”). Their website address is www.ico.org.uk.