Privacy Policy

Our privacy policy and how we use your data

Version dated August 24, 2026

1. Controller

NEURAWARE, a French SAS with a share capital of €100, Paris Trade Register no. 932 207 616, 66 avenue des Champs-Élysées, 75008 Paris, France (contact: contact form), is the controller for the processing described below, except for prospect data (section 4).

2. Data processed

  • Account data: identity, business email, language, phone number (optional, provided at sign-up or in the settings), billing data.
  • Usage data: technical logs, usage statistics, preferences.
  • Connected-account data: elements required to run campaigns (conversations, contacts), processed on the Client's behalf.
  • Prospect data: public professional data targeted by the Client (identity, role, company, public profile URL).

3. Purposes and legal bases

  • Provision of the Service and account management — performance of the contract.
  • Billing, accounting, fraud prevention — legal obligations and legitimate interest.
  • Service improvement, audience measurement — legitimate interest (statistics) or consent where required.
  • Account lifecycle emails (sign-up, trial end, billing) — performance of the contract.
  • Sales contact and onboarding assistance by phone, where you have provided your number (optional) — legitimate interest, based on your voluntary submission; removable at any time from the account settings.

The Client's content and conversations are never used to train third-party models.

4. Prospect data — GDPR roles

For outreach campaigns, the Client is the controller (choice of targets, messages and purposes) and Neuraware acts as processor, on instructions, in accordance with Article 28 GDPR. The Client warrants having a legal basis for their outreach and honoring individuals' rights (information, objection). This processing is governed by our data processing agreement (DPA), which forms an integral part of the terms of service.

5. Recipients and processors

Data is processed by authorized Neuraware staff and by technical sub-processors acting on instructions, by category:

  • website and application hosting;
  • database hosting (European Union);
  • secure payment provider;
  • infrastructure providers for connecting to professional platforms and enriching professional data;
  • artificial-intelligence model providers;
  • audience-measurement tool (EU hosting).

The named list of sub-processors is available upon request through the contact form. No data is ever sold.

6. Transfers outside the European Union

Application data is hosted within the European Union. Where a sub-processor processes data outside the EU, the transfer is governed by appropriate safeguards (European Commission standard contractual clauses, supplementary measures).

7. Retention periods

  • Account data: duration of the contract, then deletion upon closure (subject to legal obligations — invoicing: 10 years).
  • Campaign and prospect data: duration of the contract; deletion upon account closure or on the Client's instruction.
  • Technical logs: 12 months at most.

8. Your rights

Under the GDPR and French data-protection law, you have rights of access, rectification, erasure, restriction, portability and objection. Exercise them through the contact form; we reply within one (1) month. You may lodge a complaint with the CNIL (cnil.fr) at any time. Individuals prospected by a Client exercise their rights with that Client, as controller; Neuraware forwards without delay any request it receives directly.

9. Export and deletion

The Client may export their data and request deletion of their account at any time from the Service or through the contact form.

10. Security

Neuraware implements appropriate technical and organizational measures: encryption in transit, per-workspace data segregation, strict access control, logging. In the event of a data breach presenting a risk, the CNIL and the individuals concerned are notified in accordance with Articles 33 and 34 GDPR.

11. Cookies

See the cookie policy.