Privacy Policy
Effective date: May 16, 2026
This policy explains how we collect, use, and disclose personal data when you interact with our website or use our AI-powered Contextual Platform and Digital Worker solutions (together, the "Platform"). Please read it carefully. It also explains the privacy choices and rights that may be available to you under applicable U.S. privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA/CPRA”).
1. What We Collect
We collect and process the following categories of personal data:
- Identifiers — your name, username, email address, telephone number, and contact information. If you use a third-party authentication tool to log in, we may also receive the username and email address associated with that service.
- Customer Records — your name, job title, employer name, and business contact details provided when registering or engaging with us.
- Customer Details, Company Details, tax details, Billing details and Platform Usage summary that will support in billing
- Commercial Information — details of which Platform features, products, or services you use or have enquired about, and records of transactions or agreements with us.
- Geolocation Data — your general location, inferred from your IP address or region settings.
- Internet or Network Activity — your IP address, browser type and version, operating system, device type, and your activity on the Platform such as pages visited, features clicked, session duration, search queries, and interaction logs.
- Workflow and AI Inputs — documents, queries, data sets, and other content you submit to our AI contextual processing and Digital Worker features for analysis or automation.
We do not intentionally collect sensitive personal data. However, the documents, queries, and datasets you submit to our AI and Digital Worker features (“Workflow and AI Inputs”) are controlled by you or your organisation and may contain personal or sensitive data that you choose to include. Where you or your enterprise client provides such content, we process it on your behalf and under your instructions, as described in your agreement with us (and any Data Processing Agreement). We do not use it for our own purposes. If sensitive data is submitted inadvertently, we handle it under the same safeguards and delete it on request where we are able to do so.
Digital Workers may be built and/or operated by you, your organisation, or us, as agreed between us. Where a Digital Worker processes personal data through the Platform, we act as a processor on behalf of the controlling organisation; personal data handled solely within your own environment remains under your control.
Our Platform is not intended for or directed at anyone under 18. We do not knowingly collect personal information directly from children under 13 without verifiable parental consent, and we do not knowingly sell or share personal information of minors under 18. If we discover that we have collected data from someone under 18, we will promptly delete it. If you believe we have done so, please contact us.
We may use deidentified observability metadata to fine-tune our models for the purpose of improving Platform features. We do not access or use the actual content you submit, whether in structured datasets or documents, for this purpose. Any such use is bounded by the Master Services Agreement (MSA) and applicable Statement(s) of Work (SOW) in place with you or your organisation. We may use platform operational data, telemetry and performance metrics about how the Platform itself operates, which contain no content you submit and do not identify you to monitor, secure, and improve the Platform. We do not use platform operational data to train our AI models. Where such telemetry could otherwise include identifying details or content you submit, those details are masked, redacted, or removed at the point we capture it, before it is stored; organisation-level identifiers may be retained for operational purposes.
2. How We Collect It
Directly from you: when you fill out a form, register an account, log in to the Platform, contact us for support, or otherwise provide information to us voluntarily.
From your devices: automatically, as you browse and use the Platform, through cookies and similar technologies such as web beacons and log files. These tools help us keep the Platform functioning, remember your preferences, and understand how it is used. See our Cookie Policy for full details.
From third parties: from your employer or the enterprise client that has deployed the Platform to configure your account; from identity providers and single sign-on services you use to authenticate; from our vendors and business partners who support delivery of the Platform; and from publicly available professional profile sources where relevant to onboarding.
From connected accounts you authorise: where you connect a third-party account (for example, Gmail or Google Drive through our connector features), we access only the data needed to perform the task you have requested, under the permissions you grant, and only for as long as the connection is active. You can revoke this access at any time.
Generated by the Platform: as you use the Platform, we generate derived data about your activity and your inputs, including analyses, scores, assessments, recommendations, and decision and audit records produced by our AI and Digital Worker features. This generated data may itself constitute personal data and is processed and retained as described in this policy.
3. How We Use It
We use the personal data we collect to operate our business and fulfil our legal and contractual obligations, including:
- Carrying out our contract with you or your employer, and providing the Platform features and Digital Worker capabilities you have requested
- Providing you with information, products, and services you request from us
- Delivering customer service and support, including responding to queries, troubleshooting issues, and managing incidents
- Contacting you about your account, changes to the Platform, updates to our policies, or security notices
- Administering and improving our products and services, including troubleshooting, data analysis, testing, research, and statistical and survey purposes
- Personalising your experience on the Platform, including remembering your preferences and tailoring content to your role and usage patterns
- Informing you about other products and services we offer that are similar to those you have already used or enquired about
- Delivering relevant content and communications, including newsletters, industry updates, product announcements, marketing communications, and advertising, where you have opted in or where we have a legitimate basis to do so
- Keeping our Platform and users secure, including detecting, investigating, and preventing misuse, fraud, and unauthorised access
- Complying with our legal and regulatory obligations, including data protection, financial, and applicable sectoral requirements
- Processing the Workflow and AI Inputs you submit in order to deliver the contextual analysis, automation, and Digital Worker outputs you or your organisation have requested
- Generating analyses, scores, assessments, and recommendations through our AI features, and maintaining decision and audit records so that the outputs produced for you remain traceable, explainable, and accountable
- Improving and developing the Platform using deidentified observability metadata, which we may use to fine-tune our AI models for the purpose of improving Platform features; we do not access or use the content you submit, whether in structured datasets or documents, for this purpose. Any such use is bounded by the Master Services Agreement (MSA) and applicable Statement(s) of Work (SOW) in place
4. Legal Basis for Processing
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases to process your personal data:
- Performance of a contract - to provide the Platform and its features, manage your account, and deliver support, under our contract with you or your employer.
- Legitimate interests - to operate, secure, and improve the Platform, to detect and prevent misuse and fraud, and to send business-to-business communications about similar products and services, balanced against your interests and rights.
- Consent - for optional cookies and similar technologies, for certain marketing communications, and where you connect a third-party account. You may withdraw consent at any time without affecting processing carried out before withdrawal.
- Legal obligation - to comply with applicable legal, regulatory, tax, accounting, and sectoral requirements.
Where we process Workflow and AI Inputs on behalf of your organisation, your organisation is responsible for establishing the legal basis for that processing as the controller; we act on its documented instructions as a processor.
5. Automated Processing and Human Oversight
Our Platform uses automated processing, including AI models, to analyse inputs and produce outputs such as scores, assessments, compliance indicators, and recommendations. These outputs are intended to support human judgement, not replace it. Where an output could have a legal or similarly significant effect on an individual, our processes are designed to keep a person meaningfully involved, including human-in-the-loop review and escalation, so that decisions are not made solely by automated means.
Where you or your organisation uses the Platform to make decisions about individuals, the deploying organisation is responsible for ensuring appropriate human oversight, for informing affected individuals, and for honouring their rights to obtain an explanation of, and to contest, those decisions. We support this by maintaining records of how outputs were produced. To understand the logic involved or to contest a decision that affects you, please contact the organisation that operates the Platform on your behalf, or contact us using the details in this policy. See also Your Rights (Section 10).
6. Who We Share It With
We do not sell your personal data for monetary consideration. Where applicable law treats certain analytics, advertising, or similar disclosures as a “sale” or “sharing” of personal information, we provide the choices described in this Privacy Policy. We may share it with:
Where we process Workflow and AI Inputs, we do so as a processor on behalf of you or your organisation, and any onward sharing of that content is governed by your agreement or Data Processing Agreement with us rather than this policy.
- Service providers and vendors who help us operate the Platform — including cloud infrastructure, identity management, analytics, support, and security providers — all of whom are contractually required to safeguard the data and use it only for the purposes we specify
- AI and model-processing providers who perform inference and processing on our behalf. Where required to deliver the features you use, Workflow and AI Inputs may be processed by these providers under contractual confidentiality and security obligations and solely to provide the service. They do not use your content to train their models. A current list of our sub-processors is available on request.
- Connected third-party services you authorise (such as Google, where you use the Gmail or Drive connectors), strictly to perform the actions you have requested and under the permissions you have granted
- Marketing, analytics, and search-engine partners who help us understand interactions with the Platform and deliver relevant advertising to you. We provide these partners with limited personal data such as internet or network activity. California law may consider this sharing. You can opt out via our cookie settings or the mechanism described in Section 14 (California)
- Your employer or the enterprise client that has deployed the Platform, for account administration, operational reporting, and contractual purposes
- Legal and regulatory authorities, courts, or law enforcement where required by applicable law, legal process, or to protect the rights, property, or safety of us, our users, or others
- Professional advisers such as lawyers and auditors, under duties of confidentiality, where necessary
- Successors in the event of a merger, acquisition, or sale of all or part of our business, subject to equivalent protections
7. How Long We Keep It
We keep personal data only as long as needed to provide the service, comply with legal obligations, or resolve disputes. When no longer required, data is securely deleted or anonymised. Different categories are kept for different periods:
- Workflow and AI Inputs are retained only as long as needed to perform the requested processing and in line with your or your organisation’s instructions and contractual terms, after which they are deleted or returned
- Decision and audit records generated by the Platform (for example, accountability and audit-trail records) are retained for a longer, defined period so that the outputs produced for you remain traceable and verifiable, and to meet governance, regulatory, and contractual requirements
- Account, billing, and contractual records are retained for the period required by applicable tax, accounting, and legal obligations
- Platform operational data is retained in non-identifying form for as long as it remains useful to operate, secure, and improve the Platform
Enterprise clients may have specific retention terms in their contracts, which take precedence where they apply.
8. Cookies
We use cookies for Platform functionality, performance analytics, and (with your consent) marketing. You can manage preferences through our cookie banner or browser settings. Some browsers or extensions also allow you to send opt-out preference signals, such as Global Privacy Control, which we will honor where required by applicable law. See our Cookie Policy for full details.
9. Security
We use encryption, access controls, multi-factor authentication, and continuous monitoring to protect your data. In the event of a breach, we will notify you and relevant authorities promptly and within the timeframes required by applicable law. We also reduce what we store by masking, redacting, or removing identifying details and submitted content from platform operational telemetry at the point of capture.
10. Your Rights
Depending on where you are, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data
- Object to or restrict certain processing
- Receive your data in a portable format
- Opt out of the sale or sharing of your data for targeted advertising
- Withdraw consent at any time, where processing is consent-based
- Where applicable, not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and request meaningful human review (see Automated Processing and Human Oversight, Section 5)
To exercise any of these rights, submit a request via https://trust.neosapients.ai/your-data or email privacy@neosapients.ai. Include “Privacy Request” in your message and describe the nature of your request. We will verify your identity before processing your request, and we will respond within the time required by applicable law. You may designate an authorized agent to submit a request on your behalf where permitted by law.
Where we process your data on behalf of your organisation as a processor (including most Workflow and AI Inputs), please direct your request to that organisation; we will support them in responding.
11. Third-Party Links on the Platform
Our Platform may contain links to third-party websites and integrations. Once you leave our Platform, this policy no longer applies. Third-party services operate under their own privacy policies, which we encourage you to review. We are not responsible for their data practices.
This section concerns passive links that take you off the Platform. It does not apply to integrations or connectors you authorise within the Platform (for example, the Gmail or Drive connectors), which are described in Sections 2 and Section 6; we remain responsible for our own processing of data accessed through those authorised connections.
12. Additional Information - HIPAA (Healthcare & Business Associates)
This section applies where our Platform is used to create, receive, maintain, or transmit Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"), including the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, as amended by the Health Information Technology for Economic and Clinical Health Act ("HITECH").
This section is relevant to you if you are a:
- Covered Entity — a healthcare provider, health plan, or healthcare clearinghouse that transmits health information electronically
- Business Associate engaging us to process, store, transmit, or analyse PHI on your behalf
- Subcontractor or downstream entity in a healthcare data supply chain where PHI may flow through our Platform
If none of the above apply to your use of the Platform, this section does not apply to you.
12.1 Business Associate Relationship
Where our Platform is used to process PHI on behalf of a Covered Entity, Neosapients, Inc. acts as a Business Associate under HIPAA. We will only process PHI under the terms of a signed Business Associate Agreement ("BAA") with the relevant Covered Entity or upstream Business Associate. We do not accept PHI through our Platform unless a BAA is in place. If you are a Covered Entity or Business Associate and require a BAA, please contact us at privacy@neosapients.ai before submitting any PHI to the Platform.
12.2 How We Use and Disclose PHI
Where we act as a Business Associate, we will:
- Use and disclose PHI only as permitted or required by the applicable BAA and not in any manner that would violate HIPAA if done by the Covered Entity itself
- Not use or disclose PHI for any purpose other than providing the contracted services, unless required by law
- Not sell PHI or use PHI for marketing purposes without explicit authorisation
- Not use PHI for our own purposes, including to train AI models, improve our services, or derive insights for internal use, without explicit written consent
12.3 Safeguards for PHI
We implement administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic PHI ("ePHI") in accordance with the HIPAA Security Rule. These include:
- Encryption of ePHI in transit and at rest
- Role-based access controls and minimum necessary access principles
- Audit logging of access to and disclosure of ePHI
- Regular risk assessments and security reviews
- Workforce training on HIPAA obligations
- Physical security controls for systems that store or process ePHI
12.4 Breach Notification
In the event of a Breach of Unsecured PHI as defined under HIPAA, we will notify the relevant Covered Entity without unreasonable delay and in no case later than 60 calendar days after discovery of the Breach, in accordance with our obligations under the HIPAA Breach Notification Rule and the terms of the applicable BAA. Notification will include the information required by HIPAA to the extent known at the time of notification.
12.5 Subcontractors
Where we engage subcontractors or sub-processors who will have access to PHI in the course of providing services to you, we will enter into a BAA with each such subcontractor requiring them to comply with the applicable requirements of HIPAA and HITECH to the same extent that we are obligated.
12.6 Individual Rights Regarding PHI
HIPAA grants individuals certain rights in respect of their PHI held by Covered Entities. As a Business Associate, we will support you in fulfilling those rights upon your written request, including:
- Right of access — providing individuals with access to their PHI held in a Designated Record Set
- Right to amendment — amending PHI held in a Designated Record Set at the Covered Entity's direction
- Right to an accounting of disclosures — providing records of disclosures of PHI as required by HIPAA
- Right to restriction — honouring restrictions on use or disclosure of PHI as directed by the Covered Entity
12.7 Return or Destruction of PHI
Upon termination of the applicable BAA or services agreement, we will, at your election, return or securely destroy all PHI received from or created on behalf of the Covered Entity, and retain no copies, except where retention is required by law.
12.8 Compliance & Audit
We will make our internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services (HHS) for purposes of determining compliance with HIPAA, as required by law and the applicable BAA.
13. Additional Information - UK, EEA & Switzerland
We process your personal data under the following lawful bases under UK/EU GDPR: contractual necessity, legal obligation, legitimate interests, or consent. Where we rely on legitimate interests, we have conducted a balancing assessment to ensure your rights are not overridden.
For transfers of personal data outside the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or UK International Data Transfer Agreements (IDTAs). Contact us at privacy@neosapients.ai for further information. Where you or your organisation submit Workflow and AI Inputs, these may be transferred to and processed by model and inference providers located outside the UK or EEA; such transfers are made under the safeguards described above.
We have appointed a Data Protection Officer. You have the right to lodge a complaint with your local supervisory authority. Please give us the opportunity to address your concerns first:
- UK: Information Commissioner's Office (ico.org.uk)
- EU: The supervisory authority in your member state of residence
- Switzerland: Federal Data Protection and Information Commissioner (edoeb.admin.ch)
14. Additional Information - California (CCPA/CPRA)
This section applies to California residents and is intended to serve as a Notice at Collection and privacy disclosure under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, to the extent those laws apply. We provide these disclosures to promote transparency, even if we do not meet all thresholds that would make the laws mandatory for our business.
In the preceding 12 months, we may have collected the categories of personal information described in Section 1, including identifiers, contact information, customer records, commercial information, internet or other electronic network activity information, geolocation data, and inferences drawn from Platform activity. We collect these categories from you, your device, your employer or enterprise client, our service providers, and third-party platforms or partners as described in this Privacy Policy. We use these categories of personal information for the purposes described in Section 3, disclose them to the categories of recipients described in Section 6, and retain them as described in Section 7.
We do not knowingly collect sensitive personal information for the purpose of inferring characteristics, and we do not knowingly sell or share personal information of consumers under 16.
We may share (as defined by California law) internet or network activity and identifiers with advertising partners for targeted advertising purposes. You can opt out of this sharing by: (a) updating your preferences in our cookie manager; (b) enabling a browser-based opt-out preference signal, such as the Global Privacy Control; or (c) emailing us at privacy@neosapients.ai. California residents have the following rights under the CCPA/CPRA:
- Right to Know/Access — You may request information about the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for which it is used, and the categories of third parties to whom it is disclosed.
- Right to Delete — You may request that we delete personal information we collected from you, subject to legal exceptions.
- Right to Correct — You may request that we correct inaccurate personal information we maintain about you.
- Right to Opt Out — You may opt out of any sale or sharing of personal information, including disclosures for cross-context behavioral advertising, where applicable.
- Right to Limit — You may request that we limit the use and disclosure of sensitive personal information where applicable.
- Right to Non-Discrimination — We will not discriminate against you for exercising your privacy rights.
Automated decision-making technology (ADMT). Where automated decision-making technology is used to make decisions that produce legal or similarly significant effects concerning you, California law gives you the right to receive notice of that use and to access information about, and opt out of, that processing, subject to the exceptions permitted by law. Because the Platform’s outputs are intended to support human decision-making rather than replace it (see Automated Processing and Human Oversight, Section 5), whether these requirements apply depends on how the deploying organisation uses the Platform. Where they apply, we will provide the required notice and support the deploying organisation in honouring access and opt-out requests.
To submit a CCPA/CPRA request, email privacy@neosapients.ai or use our https://trust.neosapients.ai/your-data. Include “Privacy Request” in your message. We may need to verify your identity before fulfilling a request, and you may designate an authorized agent to submit a request on your behalf where permitted by law. We will respond to verifiable requests within the time required by applicable law. For personal information collected by third-party platforms, please contact those platforms directly.
15. Additional Information - Nevada and Other U.S. State Privacy Rights
Nevada residents may submit a request directing us not to sell certain covered information as defined under Nevada law. We do not currently sell covered information as that term is commonly understood under Nevada law, but Nevada residents may contact us using the contact information below to submit such a request.
Residents of other U.S. states may have rights to access, correct, delete, or obtain a copy of personal information, or to opt out of certain targeted advertising, sales, profiling, or other processing, depending on applicable law. To submit a request, please contact us through the contact information provided below and include “Privacy Request” in your message. We will respond as required by applicable law and may provide instructions for appealing a decision where an appeal right applies.
16. Changes to This Policy
We may update this policy periodically. Changes will be posted on this page with an updated effective date. Where changes are material, we will notify you via the Platform or by email, and we may provide additional notice where required by law. We encourage you to review this policy periodically to stay informed about how we handle personal information. Continued use after an update constitutes acceptance of the revised policy.
17. Contact Us
Email: privacy@neosapients.ai
Data Protection Officer
If you have questions about this Privacy Policy, wish to exercise privacy rights, or need to update your marketing preferences, please include “Privacy Request” in your message and describe the nature of your request. We may request information to verify your identity and locate the relevant records before responding.
