Who we are, and in which role
neolumi, Inc. (“neolumi”, “we”, “us”) builds AI tools for GxP compliance. We act in two different roles, and which one applies decides almost everything else on this page.
On this website (neolumi.io) we are the controller. We decide what is collected and why, and you exercise your rights directly against us.
In the neolumi platform we are a processor. Your employer is the controller: they decide who is trained, on what, and for how long the records are kept, and we act on their documented instructions under a data processing agreement. If you are a trainee or an administrator and you want to exercise a right, the fastest route is your own organisation — but write to us and we will act, and tell them.
For anything on this page, write to privacy@neolumi.io.
- GDPR
- Art. 4(7), 4(8)
What we collect
From this website. The demo request form collects your first and last name, work email address, organisation name, role, and approximate company size, plus anything you choose to write in the message field. We use it to answer your enquiry, and — only where you asked for them — to send product updates.
In the platform, on your organisation's instructions:
- Email addresses of training participants, used to assign training and record completion
- Learning-group membership, which is how role-based training requirements are applied
- Progress through the material, assessment answers, and completion status
- Electronic signature records where 21 CFR Part 11 signing is used: the signer, the timestamp and the meaning of the signature
- The content of documents your organisation uploads, which is what training is generated from
- Authentication events, including sign-in timestamps and session metadata
- Audit records — who did what, when, and from which IP address — which regulated customers are required to keep
- GDPR
- Art. 13, 14
Why we are allowed to
Where we are the controller, the basis below is ours. Where we process on a customer's behalf, the basis is theirs and is set out in the data processing agreement we sign with them; the table names the one that applies in practice.
| Processing activity | Legal basis |
|---|---|
| Demo request on this website | Legitimate interest — answering a business enquiry, Art. 6(1)(f) |
| Product updates by email | Consent, where you asked for them, Art. 6(1)(a). Withdrawable at any time |
| Training assignment and completion tracking | Contract — service delivery to your organisation, Art. 6(1)(b) |
| Generating training from an uploaded document | Contract — service delivery to your organisation, Art. 6(1)(b) |
| Authentication and session management | Contract — secure access to the platform, Art. 6(1)(b) |
| Audit logging | Legitimate interest in a tamper-evident record, Art. 6(1)(f), serving your organisation's own record-keeping obligations under 21 CFR Part 11 and EU GMP Annex 11 |
- GDPR
- Art. 6
Who else touches it
Three sub-processors, each bound by a data processing agreement that imposes obligations equivalent to our own.
| Sub-processor | What it processes | Where |
|---|---|---|
| Microsoft Azure | Application hosting, PostgreSQL database, file storage, and email delivery | United States (Central US) |
| Auth0 (Okta) | Authentication, identity, and the organisation directory | United States / EU |
| OpenAI, or Azure OpenAI | Generating training and assessments from uploaded documents. Document content is passed for generation only; it is not retained by the model provider and is not used to train models | United States, or the EU where Azure OpenAI is the configured processor |
One AI processor is active at a time and is configured at the platform level. Customers with data-residency requirements should confirm which one is active before uploading documents.
We give customers 30 days' notice before adding or replacing a sub-processor. A customer may object within 14 days, and may end their subscription without penalty if the objection cannot be resolved.
We do not sell personal data, and we do not share it with third parties for their own marketing.
- GDPR
- Art. 28
How long we keep it
| Data category | Retention period |
|---|---|
| Training and completion records | 10 years |
| Audit records | 7 years |
| Source-file version history | 2 years |
| Uploaded files, after deletion | 90 days |
| Demo requests from this website | Until you ask us to delete them |
| Authentication session | The session itself. Thirty minutes without activity ends it |
The first four are platform defaults and are configurable per customer, because the controller of that data is the customer and the period is theirs to set. The ten-year default is set against the record-keeping minimums in EU GMP Annex 11 and GLP, which is the reason a training record outlives the person's employment.
Deletion is enforced rather than intended: a scheduled job purges soft-deleted data once it passes the window, and writes what it removed into the audit trail.
- GDPR
- Art. 5(1)(e)
How it is protected
Personal data is encrypted at rest column by column, under AES-256-GCM with a per-record nonce, and searched through a keyed blind index rather than by decrypting it. Traffic is TLS throughout, the database accepts connections from one address, secrets live in a managed vault, and the audit log is written by a role that holds INSERT and nothing else. The full control set, with what backs each part of it, is on the security page.
- GDPR
- Art. 32
Automated processing
neolumi uses AI in two places: generating a training and its assessment from a document your organisation uploaded, and evaluating free-text answers against that material.
Neither is a decision about you that produces legal effects or similarly significantly affects you. A person is assigned training by an administrator at your organisation, not by a model; the result is a record of what was completed rather than a judgement about you; and that administrator can reopen, extend or waive any of it. If you disagree with an assessment result, raise it with them — they can act on it directly, and we will help them if asked.
- GDPR
- Art. 22
Your rights
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with comparable law, you have the following rights. Write to privacy@neolumi.io and we will answer within one month.
- Access — a copy of the personal data we hold about you
- Rectification — correction of anything inaccurate
- Erasure — deletion of your personal data
- Restriction — a pause on how we use it
- Portability — your data in a machine-readable format
- Objection — to processing based on legitimate interests
- Withdrawal of consent — for product updates, at any time, without affecting anything sent before
Erasure in the platform runs end to end: addresses and identifiers are pseudonymised in every tenant, learning-group memberships are removed, and the corresponding account at the identity provider is deleted, so nothing is left behind with them either. Completion records survive without anything that identifies you, because they are your employer's compliance evidence and the obligation to keep them is theirs.
neolumi, Inc. is incorporated in the United States. If you are a resident of a US state with a comprehensive privacy law, the rights to know, delete, correct and appeal are honoured through the same address. We do not sell personal information or share it for cross-context behavioural advertising.
- GDPR
- Art. 15–21
International transfers
Our infrastructure is in the United States, and two sub-processors may process there. Where personal data leaves the EEA we rely on the Standard Contractual Clauses adopted by the European Commission, incorporated into each sub-processor agreement. Where a processor also certifies under the EU–US Data Privacy Framework, the Clauses are retained as the fallback rather than replaced by it.
- GDPR
- Art. 46
Children
The platform is workplace software, licensed to organisations for their staff. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe we have, write to privacy@neolumi.io and we will delete it.
- GDPR
- Art. 8
Complaints
Tell us first if you can — it is usually faster, and we would rather fix it. You also have the right to complain to the data protection supervisory authority where you live or work, at any time and without asking us first. In the EEA, the list is published by the European Data Protection Board. In the United Kingdom it is the Information Commissioner's Office.
- GDPR
- Art. 77
Changes to this policy
We update this policy when what we do changes. Material changes are notified to account holders by email, and the revision at the head of this page moves with every change, material or not — so a reviewer who recorded a revision number can tell whether they are reading the same document.
- REVISION
- 2026.08