Privacy Policy
This Privacy Policy explains how NeuroNet (“we”, “us”, “our”) processes personal data when you visit our website, contact us or engage with our activities. We are committed to handling your data in a lawful, transparent and secure way, in line with applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
Important notice: at this stage NeuroNet operates only as a technical and research infrastructure. We do not provide diagnostic, clinical or therapeutic services via this website and we do not ask patients to upload medical data through public forms.
1. Data Controller
The Data Controller responsible for the processing of your personal data in connection with this website is:
NeuroNet – Davide Brugognone
Registered office: [Full registered address]
Email: privacy@neuronet.ai
(referred to as “NeuroNet”, “we”, “us”.)
If you have any questions about this Privacy Policy or our data processing activities, you can contact us at the email address above.
2. What data we process
Depending on how you interact with our website and services, we may process the categories of personal data listed below.
2.1 Data you provide directly
- Contact data – such as your name, surname, email address, organisation, role, and any other information you choose to include when you contact us via email, contact forms, demo requests or PoC requests.
- Project and collaboration information – information relating to potential research collaborations, PoCs, pilot projects or partnership discussions (e.g. area of interest, type of organisation, timelines).
- Newsletter / updates data – if you subscribe to receive updates, we process your email address and preferences.
- Recruitment data – if you send us a CV or apply to join the team, we process the information contained in your CV and accompanying messages (education, work experience, skills, etc.).
2.2 Data collected automatically
- Technical and usage data – such as IP address (with possible anonymisation / truncation where applicable), browser type, device identifiers, operating system, pages visited, time and date of visits, referrer URLs and interactions with the website.
- Cookies and similar technologies – as described in our Cookie Policy, we may use essential, functional and (where applicable) analytics cookies to operate and improve our website.
2.3 Special categories of data
We do not ask visitors to our public website to provide health data or other special categories of personal data. Any EEG or biosignal datasets processed in research or PoC contexts are handled under dedicated agreements and, whenever possible, in anonymised or properly pseudonymised form.
3. Purposes and legal bases of processing
We process your personal data only when we have a valid legal basis. Depending on the context, the legal basis will be one or more of the following: performance of a contract or pre-contractual measures, legitimate interest, consent, or compliance with legal obligations.
| Purpose | Data categories | Legal basis |
|---|---|---|
| Responding to contact requests, demo / PoC enquiries | Identification and contact data; project and collaboration information | Performance of pre-contractual measures at your request (Art. 6(1)(b) GDPR); our legitimate interest in properly managing enquiries (Art. 6(1)(f) GDPR) |
| Managing collaborations, PoCs and pilot projects | Contact and project data, contractual information, communication history | Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR); compliance with legal obligations (Art. 6(1)(c) GDPR) |
| Sending newsletters or updates (where available) | Email address, subscription preferences | Your consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time by using the unsubscribe link or by contacting us. |
| Recruitment and evaluation of candidates | CV data, professional experience, contact data, communications | Pre-contractual measures at the request of the data subject (Art. 6(1)(b) GDPR); legitimate interest in recruiting qualified personnel (Art. 6(1)(f) GDPR) |
| Operating, monitoring and improving our website (security, logs, analytics) | Technical and usage data; cookies / identifiers (subject to cookie choices where required) | Our legitimate interest in ensuring the security, integrity and improvement of the website (Art. 6(1)(f) GDPR); consent for non-essential analytics cookies where applicable (Art. 6(1)(a) GDPR) |
| Compliance with legal obligations and defence of rights | Data necessary to comply with legal requirements or to establish, exercise or defend legal claims | Compliance with legal obligations (Art. 6(1)(c) GDPR); legitimate interest in defending our rights (Art. 6(1)(f) GDPR) |
4. How long we keep your data
We retain personal data only for as long as necessary to achieve the purposes for which it was collected, unless a longer retention period is required or permitted by law. In particular:
- Contact and enquiry data are normally kept for up to 24 months from the last meaningful interaction, unless a contractual relationship or collaboration is established.
- Contractual and project data are kept for the duration of the contract and for the applicable statutory limitation periods (e.g. 5–10 years, depending on the jurisdiction).
- Newsletter data are processed until you unsubscribe or withdraw your consent.
- Recruitment data are normally retained for up to 12 months after the end of the selection process, unless local law allows or requires a different period or you authorise longer retention.
- Technical logs are kept for the time necessary to ensure security and proper functioning of the website, typically from a few days up to 12 months, unless longer retention is necessary in case of security incidents.
5. Who we share your data with
We do not sell your personal data. We may share it only with the following categories of recipients, strictly on a need-to-know basis:
- Service providers and processors – such as hosting providers, email and collaboration tools, analytics providers, security and IT service providers, who act on our instructions and provide sufficient guarantees of data protection (“data processors”).
- Professional advisors – such as legal, accounting, or compliance advisors, where necessary to protect our rights or comply with legal requirements.
- Business and research partners – in the context of PoCs, pilot projects or collaborations, always under appropriate contractual safeguards and only to the extent necessary for the specific initiative.
- Authorities – where required by law or to protect our rights or those of third parties.
When we share personal data with processors, we put in place data processing agreements in accordance with Article 28 GDPR.
6. International data transfers
Some of our service providers or partners may be located outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards are in place, such as:
- An adequacy decision by the European Commission for the destination country; or
- Standard Contractual Clauses approved by the European Commission, supplemented where necessary by additional technical and organisational measures.
You can obtain more information about the international transfers relating to your data, and a copy of the applicable safeguards, by contacting us at privacy@neuronet.ai.
7. Security of your data
We adopt appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction or damage. These include, for example:
- Secure hosting environments and access controls.
- Role-based access limitations and need-to-know principles.
- Encryption in transit (e.g. HTTPS) and, where appropriate, at rest.
- Logging and monitoring of critical systems.
- Internal policies on data protection, confidentiality and retention.
While we strive to protect your personal data, no transmission or storage system can be guaranteed 100% secure.
8. Your rights under GDPR
Under the GDPR, you have a number of rights in relation to your personal data, subject to the conditions and limits set out in the law:
- Right of access – to obtain confirmation as to whether we process your personal data, and access to such data.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of your data when certain conditions are met (e.g. data no longer necessary, consent withdrawn, unlawful processing).
- Right to restriction of processing – to request that we limit processing under certain circumstances.
- Right to data portability – to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format, and to transmit those data to another controller where technically feasible.
- Right to object – to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests. We will stop such processing unless we demonstrate compelling legitimate grounds or for the establishment, exercise or defence of legal claims.
- Right to withdraw consent – where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
To exercise your rights, you can contact us at privacy@neuronet.ai. We may need to verify your identity before responding to your request.
You also have the right to lodge a complaint with your local supervisory authority for data protection. For EU residents, you can find contact details of supervisory authorities on the website of the European Data Protection Board.
9. Cookies and similar technologies
Our website may use cookies and similar technologies to ensure its proper functioning, remember your preferences and, where applicable, perform aggregated analytics.
For detailed information about the types of cookies we use, their purposes and how you can manage your preferences, please refer to our dedicated Cookie Policy.
10. Minors
Our website and services are intended for professionals, organisations, and adult users. We do not knowingly collect personal data from persons under 18 years of age via our public website. If you believe that a minor has provided us with personal data, please contact us so that we can take appropriate steps.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example in case of changes to our processing activities or applicable law.
When we publish a new version, we will update the “Last updated” date below. We encourage you to review this page periodically.
Last updated: [DD Month YYYY]
12. How to contact us
For any questions, requests or concerns regarding this Privacy Policy or the way we process personal data, you can contact us at:
Email: privacy@neuronet.ai
Postal address: Piazza Nicolò Bruno 1, 16014 Campomorone, GE (Italy)