LEGALREV 2026.08

Privacy policy

What we collect, why we are allowed to, who else touches it, how long it stays, and what you can make us do about it.

ENTITYneolumi, Inc.
EFFECTIVEMARCH 2026
LAST UPDATEDAUGUST 2026
·01

Who we are, and in which role

neolumi, Inc. (“neolumi”, “we”, “us”) builds AI tools for GxP compliance. We act in two different roles, and which one applies decides almost everything else on this page.

On this website (neolumi.io) we are the controller. We decide what is collected and why, and you exercise your rights directly against us.

In the neolumi platform we are a processor. Your employer is the controller: they decide who is trained, on what, and for how long the records are kept, and we act on their documented instructions under a data processing agreement. If you are a trainee or an administrator and you want to exercise a right, the fastest route is your own organisation — but write to us and we will act, and tell them.

For anything on this page, write to privacy@neolumi.io.

GDPR
Art. 4(7), 4(8)
·02

What we collect

From this website. The demo request form collects your first and last name, work email address, organisation name, role, and approximate company size, plus anything you choose to write in the message field. We use it to answer your enquiry, and — only where you asked for them — to send product updates.

In the platform, on your organisation's instructions:

  • Email addresses of training participants, used to assign training and record completion
  • Learning-group membership, which is how role-based training requirements are applied
  • Progress through the material, assessment answers, and completion status
  • Electronic signature records where 21 CFR Part 11 signing is used: the signer, the timestamp and the meaning of the signature
  • The content of documents your organisation uploads, which is what training is generated from
  • Authentication events, including sign-in timestamps and session metadata
  • Audit records — who did what, when, and from which IP address — which regulated customers are required to keep
GDPR
Art. 13, 14
·03

Why we are allowed to

Where we are the controller, the basis below is ours. Where we process on a customer's behalf, the basis is theirs and is set out in the data processing agreement we sign with them; the table names the one that applies in practice.

Processing activities and the legal basis for each
Processing activityLegal basis
Demo request on this websiteLegitimate interest — answering a business enquiry, Art. 6(1)(f)
Product updates by emailConsent, where you asked for them, Art. 6(1)(a). Withdrawable at any time
Training assignment and completion trackingContract — service delivery to your organisation, Art. 6(1)(b)
Generating training from an uploaded documentContract — service delivery to your organisation, Art. 6(1)(b)
Authentication and session managementContract — secure access to the platform, Art. 6(1)(b)
Audit loggingLegitimate interest in a tamper-evident record, Art. 6(1)(f), serving your organisation's own record-keeping obligations under 21 CFR Part 11 and EU GMP Annex 11
GDPR
Art. 6
·04

Who else touches it

Three sub-processors, each bound by a data processing agreement that imposes obligations equivalent to our own.

Approved sub-processors, what each processes, and where
Sub-processorWhat it processesWhere
Microsoft AzureApplication hosting, PostgreSQL database, file storage, and email deliveryUnited States (Central US)
Auth0 (Okta)Authentication, identity, and the organisation directoryUnited States / EU
OpenAI, or Azure OpenAIGenerating training and assessments from uploaded documents. Document content is passed for generation only; it is not retained by the model provider and is not used to train modelsUnited States, or the EU where Azure OpenAI is the configured processor

One AI processor is active at a time and is configured at the platform level. Customers with data-residency requirements should confirm which one is active before uploading documents.

We give customers 30 days' notice before adding or replacing a sub-processor. A customer may object within 14 days, and may end their subscription without penalty if the objection cannot be resolved.

We do not sell personal data, and we do not share it with third parties for their own marketing.

GDPR
Art. 28
·05

How long we keep it

Data categories and how long each is retained
Data categoryRetention period
Training and completion records10 years
Audit records7 years
Source-file version history2 years
Uploaded files, after deletion90 days
Demo requests from this websiteUntil you ask us to delete them
Authentication sessionThe session itself. Thirty minutes without activity ends it

The first four are platform defaults and are configurable per customer, because the controller of that data is the customer and the period is theirs to set. The ten-year default is set against the record-keeping minimums in EU GMP Annex 11 and GLP, which is the reason a training record outlives the person's employment.

Deletion is enforced rather than intended: a scheduled job purges soft-deleted data once it passes the window, and writes what it removed into the audit trail.

GDPR
Art. 5(1)(e)
·06

How it is protected

Personal data is encrypted at rest column by column, under AES-256-GCM with a per-record nonce, and searched through a keyed blind index rather than by decrypting it. Traffic is TLS throughout, the database accepts connections from one address, secrets live in a managed vault, and the audit log is written by a role that holds INSERT and nothing else. The full control set, with what backs each part of it, is on the security page.

GDPR
Art. 32
·07

Automated processing

neolumi uses AI in two places: generating a training and its assessment from a document your organisation uploaded, and evaluating free-text answers against that material.

Neither is a decision about you that produces legal effects or similarly significantly affects you. A person is assigned training by an administrator at your organisation, not by a model; the result is a record of what was completed rather than a judgement about you; and that administrator can reopen, extend or waive any of it. If you disagree with an assessment result, raise it with them — they can act on it directly, and we will help them if asked.

GDPR
Art. 22
·08

Your rights

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with comparable law, you have the following rights. Write to privacy@neolumi.io and we will answer within one month.

  • Access — a copy of the personal data we hold about you
  • Rectification — correction of anything inaccurate
  • Erasure — deletion of your personal data
  • Restriction — a pause on how we use it
  • Portability — your data in a machine-readable format
  • Objection — to processing based on legitimate interests
  • Withdrawal of consent — for product updates, at any time, without affecting anything sent before

Erasure in the platform runs end to end: addresses and identifiers are pseudonymised in every tenant, learning-group memberships are removed, and the corresponding account at the identity provider is deleted, so nothing is left behind with them either. Completion records survive without anything that identifies you, because they are your employer's compliance evidence and the obligation to keep them is theirs.

neolumi, Inc. is incorporated in the United States. If you are a resident of a US state with a comprehensive privacy law, the rights to know, delete, correct and appeal are honoured through the same address. We do not sell personal information or share it for cross-context behavioural advertising.

GDPR
Art. 15–21
·09

International transfers

Our infrastructure is in the United States, and two sub-processors may process there. Where personal data leaves the EEA we rely on the Standard Contractual Clauses adopted by the European Commission, incorporated into each sub-processor agreement. Where a processor also certifies under the EU–US Data Privacy Framework, the Clauses are retained as the fallback rather than replaced by it.

GDPR
Art. 46
·10

Cookies and browser storage

This website sets no cookies. There is no analytics, no advertising and no tracking on neolumi.io. That is why you were not asked to consent to any: there is nothing to consent to.

The platform is different, because staying signed in requires state. Your browser holds an authentication token in local storage so that reloading a page does not sign you out, and the identity provider sets its own session cookie on auth.neolumi.io. Both are strictly necessary to provide a service you asked for, and neither is read for analytics or advertising.

ePRIVACY
Art. 5(3)
·11

Children

The platform is workplace software, licensed to organisations for their staff. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe we have, write to privacy@neolumi.io and we will delete it.

GDPR
Art. 8
·12

Complaints

Tell us first if you can — it is usually faster, and we would rather fix it. You also have the right to complain to the data protection supervisory authority where you live or work, at any time and without asking us first. In the EEA, the list is published by the European Data Protection Board. In the United Kingdom it is the Information Commissioner's Office.

GDPR
Art. 77
·13

Changes to this policy

We update this policy when what we do changes. Material changes are notified to account holders by email, and the revision at the head of this page moves with every change, material or not — so a reviewer who recorded a revision number can tell whether they are reading the same document.

REVISION
2026.08

Questions about your data

Ask, and a person will answer. If your question is about how the platform is built and secured rather than about what we collect, the security page answers that side, and the compliance pack behind it goes to reviewers on request.