This Privacy Policy explains how Neobuilt AB (Neobuilt, we, us or our) collects, uses, shares and protects personal data when you visit our websites, create or use a Neobuilt account, buy or use our software, including Paramora Prism™, or contact us. It also explains the rights you have and how to exercise them.
We are established in Sweden, and we are the controller of the personal data described in this policy unless a section says otherwise. Our contact details are in section 16.
Privacy at a glance
Desktop model viewing and conversion take place on your computer. Account, licensing, payment and support services process the data described below. You choose whether to send support material. We do not sell personal data or use advertising trackers. First-party website analytics runs only with your consent and does not link visits to your account.
1. Who we are and how to reach us
The controller is Neobuilt AB, a limited company incorporated in Sweden. For privacy questions and to exercise your rights, write to privacy@neo-built.com. This mailbox is our data-protection contact. Company identification and contact details are in section 16.
2. What this policy covers
This policy applies to:
- the websites at www.neo-built.com and its subdomains, including the account portal at www.neo-built.com, the authorization service at auth.neo-built.com and the product API at api.neo-built.com (together, the Website);
- your Neobuilt account and the account portal (the Account);
- our desktop software, including Paramora Prism™, and their account, licensing and delivery services (the Software);
- support, sales and other communications with us.
Third-party websites, payment providers and identity providers publish their own notices for processing they control. This policy still covers information we send to or receive from them and processing they carry out on our behalf. Section 12 explains processing on an organisation's instructions. A future product or materially different use of data requires an appropriate notice before that processing starts.
3. Personal data we collect
3.1 Information you give us
- Account details. Your email address, display name, optional profile information, such as your name, company and country, an optional avatar, and your sign-in methods. Our authentication service processes password credentials, passkey public keys and authentication records, and any second-factor enrolment you enable. A passkey's private key stays with your authenticator; we do not receive a fingerprint or face scan used to unlock it.
- Organisation details. If you administer an organisation, its name, members' names and roles, existing seat assignments, and billing-contact details supplied through our assisted sales or administration process.
- Premium evaluation history. If you explicitly start an individual premium evaluation, we store the selected tier, activation and expiry times, a consumed-evaluation record, and any support-authorized extension history. We use this to provide access and enforce one evaluation per account. It does not include model content or file paths. The account-linked record follows account deletion; separately required staff audit records follow the existing audit retention and erasure rules.
- Billing details. Your billing name and address, country, VAT or tax identification number, and the last four digits and card type of the payment method that Stripe holds. For annual orders, we record your stated consumer or business capacity, renewal consent, agreed amount and currency, and renewal reminder and cancellation evidence. These financial and order records follow the billing retention schedule; account deletion removes the account link where retention is required. Full card numbers go directly to Stripe and never reach our systems.
- Communications. Messages to support, sales, security or privacy, including the product, subject, description and other details you provide. Website request forms store your submission, relevant diagnostic or sales details, replies and case status. Staff can record internal review notes. We send transactional confirmations, replies and status notifications through our email provider. Guest requests use a private access link that expires after 30 days; this expiry does not delete the request. To prevent abuse, we use a keyed hash of the connection IP address in short-lived rate counters. Attachments and Diagnostics are received only through a channel agreed with support.
- Choices. Cookie choices, notification preferences, interface and workflow settings, and saved preferences about product usage analytics, crash reports, personalisation and synchronisation. Availability of these settings in each app depends on the features it supports. Saving an optional choice does not itself send telemetry or a crash report.
3.2 Information collected automatically on the Website
- Connection and country data. Cloudflare processes IP addresses, requested pages, timestamps, browser and device information and security signals to deliver and protect the Website. For cookie controls we reduce its country signal to an in-scope or rest-of-world category. Separately, pricing and checkout use country information to select a regional price and check purchase eligibility. Billing, payment-country and pricing-zone information may be retained with transaction records; the reduction used for cookie controls does not apply to all country data.
- Sign-in events. When you sign in or change security settings, our authentication provider records the time, the method used, the IP address and the browser, so that you can review your sessions and we can detect misuse.
- Cookies and similar storage. Section 5 describes sign-in, preference, security and payment storage. With your prior analytics consent, we record public page views and selected link clicks, pseudonymous visitor and session IDs, referring domains and campaign tags, device/browser/operating-system categories, approximate country/region and IP address. We do not collect query strings, form contents or activity on private account, payment or applicant-access pages. We do not use advertising pixels, session replay or account linking. Checkout embeds Stripe's payment interface, and its processing is described separately below.
3.3 Information from the Software
Paramora Prism™
- Sign-in. Prism signs you in through your system browser and our authorization service; the plugin never sees your password. It receives short-lived tokens that identify your Account.
- Entitlement checks. Account and licence identifiers, activation and lease records, product version and channel, device identifiers or machine hashes, request times and connection information are used to validate access and deliver licensed components. A hash or pseudonymous identifier can still be personal data when linked to an Account; it is not automatically anonymous.
- Automation keys. For headless use, we store only a hash of the key and a four-character hint.
- Local logs. The plugin writes logs and validation reports on your own machine. They are not sent to us.
- Diagnostics. The plugin can keep local logs and technical details on your machine. This site does not currently provide a Diagnostics upload. If support asks for a file through a separately agreed secure channel, you choose what to provide and should review it first; access tokens must never be included.
- Model content. Opening or converting a model locally does not upload its contents, exports or validation reports to us. If you separately provide any of that material to support, we process the material you send for that request.
Update and component requests disclose connection information to the delivery service. Some catalogue information may be public; entitled delivery can also use Account and licence information. We do not treat all update requests as anonymous. Material changes to this processing will be explained before they are introduced.
3.4 Information from other sources
- Identity providers. If you choose an enabled third-party sign-in method, the provider sends identity information such as a provider identifier, email address and profile name or image, according to the permissions and configuration of that sign-in method.
- Your organisation. If our assisted administration process links your Account to an organisation, we receive the membership and role information needed to do so. Your Account email remains part of your own identity record and is not exposed in the organisation member directory.
- Stripe. Payment and subscription events provide customer, order, invoice and subscription identifiers, amounts, currencies, taxes, billing or payment-country information, payment-method details such as card brand and last four digits where available, and payment, refund, dispute or fraud-review status. We retain transaction records and some provider event data for provisioning, reconciliation and support. Full payment-card numbers are entered directly into Stripe's payment interface.
- Public and commercial sources. For business customers we may check company registration and sanctions lists to meet legal obligations.
3.5 What we do not collect
We do not intentionally collect special categories of personal data (such as health, biometric, genetic, religious or political data), government identification numbers, precise geolocation, or personal data from children (section 13). Please do not include such data in support requests.
4. Why we use personal data and on what legal basis
The table explains our purposes and the relevant GDPR legal bases when we act as controller. Contract applies where processing is necessary for our contract with you personally; for an organisation's contact person, our legitimate interest is administering that customer relationship. Processing solely on an organisation's instructions follows section 12. Where we rely on legitimate interests, we must balance those interests against your rights; you may object as described in section 10.
| Purpose | Data | Legal basis |
|---|---|---|
| Deliver the Website and keep it secure | Connection data, security signals, region class | Legitimate interests (Article 6(1)(f)): running a secure, available website |
| Create and manage your Account, sign you in, keep your sessions and security settings | Account details, avatar, preferences and sign-in events | Contract (Article 6(1)(b)) |
| Sell, activate, validate and enforce licences, seats, pools and keys | Account details, entitlement checks, machine identifiers, organisation details | Contract (Article 6(1)(b)) for personal licences; legitimate interests (Article 6(1)(f)) for licence enforcement and administering business customer access |
| Take payment, issue invoices, handle refunds, collect and report tax, keep accounts | Billing details, order history | Contract (Article 6(1)(b)); legal obligation (Article 6(1)(c)): bookkeeping and tax law |
| Provide support and respond to your requests | Communications, Diagnostics you send, Account details | Contract (Article 6(1)(b)) where needed for your service or requested pre-contract steps; legitimate interests (Article 6(1)(f)) in answering enquiries and resolving problems; instructions under Annex B for processor data |
| Detect, investigate and prevent fraud, abuse and security incidents | Connection data, sign-in events, entitlement checks, Stripe fraud signals | Legitimate interests (Article 6(1)(f)): protecting the service and its users; legal obligation: security of processing |
| Record service events and present notices in the Account; support provider-hosted receipts or separately arranged notices where configured | Account details, billing details | Contract (Article 6(1)(b)); legal obligation (Article 6(1)(c)) |
| Save communication and optional product preferences | Account identifier and your saved choices | Contract (Article 6(1)(b)) for requested settings; consent (Article 6(1)(a)) for optional processing only when separately explained and enabled |
| Investigate service problems and plan capacity | Operational, support and licensing information; aggregated statistics | Legitimate interests (Article 6(1)(f)) in maintaining and improving service reliability; no separate use of processor support samples beyond instructions |
| Comply with the law, including sanctions screening and lawful requests from authorities | Account and billing details, order history | Legal obligation (Article 6(1)(c)) |
| Respond to data-protection requests and demonstrate compliance | Request details, proportionate identity checks, export or erasure records and correspondence | Legal obligation (Article 6(1)(c)): data-subject rights and accountability requirements |
| Establish, exercise or defend legal claims | Any of the above, as relevant | Legitimate interests (Article 6(1)(f)) |
| Select regional prices and check purchase eligibility | Country signals, billing and payment-country information, pricing zone | Legitimate interests (Article 6(1)(f)) in administering regional offers and preventing misuse; legal obligation (Article 6(1)(c)) where tax or applicable sanctions law requires it |
We need required identity and contact information to create an Account, licence and device information to validate licensed access, and relevant billing information to process a purchase. Necessary connection and security data are processed when you use the service. Optional profile details, an avatar and support samples are voluntary; without enough information we may be unable to investigate a request. Licence checks and regional price or eligibility checks use automated rules. They can affect the price shown or whether access is granted. If you believe a result is wrong, contact support for human review and to contest it. We will assess any additional safeguards required where an automated decision has legal or similarly significant effects.
7. International data transfers
We operate from Sweden. The configured primary Supabase database region for Account, licence and billing data is Stockholm, Sweden (eu-north-1), but a primary database region does not establish where every backup, log or support access occurs. Other providers' hosting, delivery, support or payment operations can involve countries outside the EEA. The provider register identifies the location information and confirmation still needed for this revised notice. Restricted transfers require a valid basis for the particular recipient and processing, such as a relevant adequacy decision or executed Standard Contractual Clauses with the required assessment and supplementary safeguards. UK or Swiss transfer rules apply separately where relevant. We do not treat a provider's public certification or published contract template as proof of the mechanism governing our engagement. Contact the privacy mailbox for the applicable transfer information and a copy of safeguards, with necessary confidential information redacted.
8. How long we keep personal data
Retention depends on the purpose, whether your Account or a case remains active, the need to investigate security events, and applicable recordkeeping or claims requirements. The proposed time limits below are not yet an implemented automatic deletion schedule. Time-based deletion and redaction remain disabled until an approved legal-hold model and privileged-audit archive checkpoint can be enforced, so merely passing a proposed age window does not cause deletion or redaction. Records may remain beyond those proposed limits while retention controls are completed, but that does not create a right to retain unnecessary personal data indefinitely. Requests for erasure are assessed separately and remain subject to legal response deadlines. The unresolved schedule and provider backup periods require confirmation before this revised notice is final.
| Data | How long | What happens then |
|---|---|---|
| Account profile, preferences, sign-in methods and organisation membership | For the life of the Account | Deleted when an approved Account erasure completes; requester details are cleared from the completed request record |
| Security and activity logs (sign-ins, seat changes, key events) | 24 months | Proposed deletion limit. Account erasure removes or redacts identifying links where possible; remaining event records are not necessarily anonymous. |
| Prism activations and machine identifiers | 18 months after deactivation | Deleted with the activation; deleted with the Account |
| Historical application device records | 12 months after last sign-in | Deleted; deleted with the Account |
| Prism floating leases | 90 days after release or expiry | Deleted; deleted with the Account |
| Revoked automation keys and activation-attempt evidence | 24 months after revocation or attempt | Deleted |
| Accounting information in orders, invoices and related records | Through the seventh year after the calendar year in which the financial year ends, where Swedish bookkeeping law requires it | Keep information actually required for accounting and tax; the statutory period does not automatically apply to every licence or device record. Remove other personal details and direct Stripe links when no longer needed. One-way provider suppression hashes prevent accidental relinking after the direct link is removed. |
| Support correspondence and Diagnostics | Diagnostics until the matter is closed; correspondence up to 24 months after closure | Deleted |
| Consented website analytics | IP addresses seven days; events 90 days; hashed withdrawal receipts 90 days | Expired IPs and events are excluded from reports immediately and removed in bounded scheduled maintenance every 15 minutes. Withdrawal requests deletion of the browser’s events. Protected backups follow the processor’s separate retention and must be purged before restored data serves traffic. |
| Data-subject request workflow records | 24 months after completion or rejection | The requester email, Account link and working notes are cleared as soon as the request closes; the pseudonymous workflow record is then deleted after 24 months |
| Closed support impersonation and external-operation records | 24 months after closure | Deleted |
| Verified Stripe webhook and mirror payloads | Webhook payloads 30 days after the later of completed processing and completed provisioning; terminal object payloads 90 days after sync | Proposed redaction of detailed payment events, retaining the identifiers and results still needed for reconciliation. Retained identifiers may remain personal data. |
| Privileged-access audit chain | Retention limit remains to be confirmed | Access and security evidence currently remains in the audit record until an approved archive-checkpoint and deletion schedule is adopted. Technical audit integrity alone is not a statutory retention requirement or a legal hold. |
| Consumed or expired staff step-up token digests | 24 hours after use or expiry | Deleted under the proposed schedule |
| Communication choices and opt-outs | For as long as needed to honour your choice | Kept as a suppression record so you are not contacted again |
| Website connection logs at our hosting provider | Provider-specific periods remain to be confirmed | Deletion depends on the configured service; no fixed provider deletion period is promised here |
| Cookie choice and region class | 12 months and 24 hours respectively, in your browser | Expire automatically |
| Data relevant to a legal claim | Until the claim and any limitation period end | Deleted |
The Account portal submits a deletion request; it does not erase the Account immediately or cancel a subscription. We verify the request, arrange any subscription cancellation and organisation ownership changes, and coordinate deletion of profile images and external account records. An approved erasure removes account data and releases organisation Seats; records still needed for a lawful purpose are restricted or de-linked where possible. De-linked, hashed or pseudonymous records may still be personal data. We explain any data we must keep and why. Provider records and backups need their own deletion arrangements; a database deletion does not establish that every copy has been erased. Stripe may retain information for purposes it controls under its own notice.
9. How we protect personal data
We apply technical and organisational measures appropriate to the risk, including:
- encryption in transit for every connection, and host-only, secure session cookies on the account domain;
- email verification and the passkey or second-factor options enabled for your Account;
- database access policies and role checks that restrict access to your own records and any organisation records you are authorised to manage;
- hashed password and automation-key verification where applicable, protected server credentials, and restricted access to administrative functions;
- separate controls for software delivery, described on the security page; an unsigned preview is identified as such rather than represented as a signed production release;
- logging of security-sensitive account and administrative actions;
- a coordinated vulnerability-disclosure process, described on the security page.
No system is perfectly secure. Where we are controller, we notify the competent supervisory authority of a personal-data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless it is unlikely to result in a risk to individuals' rights and freedoms. We explain any delay and inform affected individuals without undue delay where the breach is likely to create a high risk, subject to the statutory exceptions. Where we act as processor, we notify the relevant controller under Annex B of the Terms. Report an account compromise or vulnerability to security@neo-built.com.
10. Your rights and how to exercise them
10.1 Your rights
Subject to the conditions and exceptions in applicable law, your rights include:
- access the personal data we hold about you and receive a copy;
- rectification of inaccurate or incomplete data;
- erasure of your data where there is no longer a reason for us to keep it;
- restriction of processing in the circumstances the law describes;
- portability: where processing is automated and based on consent or a contract, receive personal data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, on grounds relating to your particular situation, and to direct marketing at any time;
- withdraw consent at any time where we rely on it, without affecting processing before the withdrawal;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to the exceptions in the law;
- lodge a complaint with a supervisory authority.
10.2 How to exercise them
Use the Account portal to update your profile, request an export, manage sessions and devices, or request deletion. The export request enters our privacy queue for a response; it also unlocks a protected ZIP download containing account data and any saved avatar. Contact privacy@neo-built.com for other personal data or help with any right, including if you cannot sign in. We request additional identity information only where reasonably necessary. Under the GDPR we respond without undue delay and within one month of receipt. If complexity or the number of requests justifies an extension of up to two further months, we tell you within the first month and explain why. Requests are normally free; if a request is manifestly unfounded or excessive, we may charge a reasonable permitted fee or refuse, explaining the reason and your complaint and judicial-remedy options. We do not penalise you for exercising your rights.
10.3 Complaints and supervisory authorities
You can raise a concern with us, but do not have to do so before complaining to an authority. In Sweden you can contact Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, Box 8114, 104 20 Stockholm, Sweden, imy@imy.se, www.imy.se. Under the GDPR you may also complain to an authority where you habitually live, work or believe an infringement occurred. UK and Swiss residents may contact the Information Commissioner's Office or the Federal Data Protection and Information Commissioner respectively, where the relevant law applies.
11. Marketing communications
Neobuilt uses Resend for support conversations and, for enabled annual subscription programs, necessary renewal reminders with your plan, renewal date, amount and billing link. Supabase Auth may send the configured confirmation, recovery and secure email-change messages needed for your Account, and Stripe may send a payment receipt or other provider notice when that feature is configured there. This site does not currently operate a general product, security or marketing email sender. Those necessary account and provider messages are separate and do not subscribe you to marketing. Saved notification choices do not mean a marketing message is sent today. We will not enable self-service annual automatic renewal until the required renewal-notice content and delivery have been verified. Before introducing marketing, we will explain the purpose and obtain consent where required. Any existing-customer exception will be used only if all applicable conditions are met, including relevant similar products and a clear, free opt-out both when the address is collected and in each message. You can object to direct marketing at any time at privacy@neo-built.com. We do not disclose your details for another organisation's own marketing.
12. Organisation Accounts
When an organisation licenses our Software for its members, membership creation, invitation, removal and leaving are currently handled through assisted sales or administration. In the Account portal, authorised managers can assign, release and reassign existing seats and see members' names, roles, seat and activation state, and the status of the organisation's licences. They cannot see member email addresses, passwords, passkeys, personal licences or sessions.
For directory, role and Seat administration on the organisation's documented instructions, and agreed support samples processed on its behalf, we act as processor under Annex B of the Terms of Service. The organisation is responsible for its purposes and notices. For our own account authentication, security, licence enforcement, invoicing and legal compliance we remain a controller, including where you use an organisation's licence. You can contact either the organisation or us about your rights; we direct processor-data requests to the organisation and handle our controller-data requests ourselves. Removing membership ends organisation access; a personal Account may continue separately.
13. Children
Accounts and purchases are intended for adults aged at least 18, or the higher age of majority where applicable. We do not direct these services to children or knowingly invite them to create Accounts. If you believe we hold a child's personal data, contact privacy@neo-built.com. We will investigate and take appropriate steps, including deletion where there is no lawful reason to retain it. The contractual age requirement is separate from any national rule on children's consent to data processing.
14. Information for particular jurisdictions
14.1 European Economic Area, United Kingdom and Switzerland
The GDPR applies to processing in the context of our Swedish establishment, including where an individual is outside the EEA. UK and Swiss laws apply according to their own scope and requirements; they are not identical to the GDPR. Any required local representative and additional disclosures must be identified for the relevant service before that processing begins.
14.2 United States
US state privacy laws have different scope, definitions and rights. Where one applies to our processing, we honour its applicable access, correction, deletion, portability, opt-out, appeal and non-discrimination requirements. We do not sell personal data or share it for cross-context behavioural advertising, and do not use it for targeted advertising. Account credentials may count as sensitive personal information under some laws; we use them for account access and security. Contact the privacy mailbox to make a request or challenge our response. An authorised agent may act where permitted, subject to proportionate verification. A state-specific supplement is required if applicable law requires disclosures beyond this policy.
14.3 Other countries
You may also have rights under other applicable local privacy laws. Contact the privacy mailbox for help exercising them. This policy does not replace a required local notice, representative or complaint route; those must be provided for a service where applicable.
15. Changes to this policy
We update this policy when our processing, our providers or the law change. The effective date and the date of the last change are shown at the top of the page, and we keep earlier versions available on request. For material changes we give the legally required notice through the Website and Account. Where the applicable law or contract requires delivery by email, we will not make that change effective until a verified delivery channel exists. We will not apply a materially different use of personal data already collected without a lawful basis for it, which may mean asking for your consent.
16. Contact us
Questions, requests and complaints about this policy go to privacy@neo-built.com. Product support is at support@neo-built.com, billing at billing@neo-built.com, and security reports at security@neo-built.com.
| Item | Details |
|---|---|
| Legal name | Neobuilt AB |
| Country of incorporation | Sweden |
| Organisation number | 559519-2781 |
| VAT identification number | SE559519278101 |
| Website | www.neo-built.com |
| General enquiries and support | support@neo-built.com |
| Billing and orders | billing@neo-built.com |
| Privacy and data subject requests | privacy@neo-built.com |
| Security reports | security@neo-built.com |