Skip to content

Legal

Privacy Policy

Last updated 13 September 2026

This Privacy Policy explains how Neobuilt AB (Neobuilt, we, us or our) collects, uses, shares and protects personal data when you visit our websites, create or use a Neobuilt account, buy or use our software, including Paramora Prism™, or contact us. It also explains the rights you have and how to exercise them.

We are established in Sweden, and we are the controller of the personal data described in this policy unless a section says otherwise. Our contact details are in section 16.

Privacy at a glance

Desktop model viewing and conversion take place on your computer. Account, licensing, payment and support services process the data described below. You choose whether to send support material. We do not sell personal data or use advertising trackers. First-party website analytics runs only with your consent and does not link visits to your account.

1. Who we are and how to reach us

The controller is Neobuilt AB, a limited company incorporated in Sweden. For privacy questions and to exercise your rights, write to privacy@neo-built.com. This mailbox is our data-protection contact. Company identification and contact details are in section 16.

Back to contents

2. What this policy covers

This policy applies to:

  • the websites at www.neo-built.com and its subdomains, including the account portal at www.neo-built.com, the authorization service at auth.neo-built.com and the product API at api.neo-built.com (together, the Website);
  • your Neobuilt account and the account portal (the Account);
  • our desktop software, including Paramora Prism™, and their account, licensing and delivery services (the Software);
  • support, sales and other communications with us.

Third-party websites, payment providers and identity providers publish their own notices for processing they control. This policy still covers information we send to or receive from them and processing they carry out on our behalf. Section 12 explains processing on an organisation's instructions. A future product or materially different use of data requires an appropriate notice before that processing starts.

Back to contents

3. Personal data we collect

3.1 Information you give us

  • Account details. Your email address, display name, optional profile information, such as your name, company and country, an optional avatar, and your sign-in methods. Our authentication service processes password credentials, passkey public keys and authentication records, and any second-factor enrolment you enable. A passkey's private key stays with your authenticator; we do not receive a fingerprint or face scan used to unlock it.
  • Organisation details. If you administer an organisation, its name, members' names and roles, existing seat assignments, and billing-contact details supplied through our assisted sales or administration process.
  • Premium evaluation history. If you explicitly start an individual premium evaluation, we store the selected tier, activation and expiry times, a consumed-evaluation record, and any support-authorized extension history. We use this to provide access and enforce one evaluation per account. It does not include model content or file paths. The account-linked record follows account deletion; separately required staff audit records follow the existing audit retention and erasure rules.
  • Billing details. Your billing name and address, country, VAT or tax identification number, and the last four digits and card type of the payment method that Stripe holds. For annual orders, we record your stated consumer or business capacity, renewal consent, agreed amount and currency, and renewal reminder and cancellation evidence. These financial and order records follow the billing retention schedule; account deletion removes the account link where retention is required. Full card numbers go directly to Stripe and never reach our systems.
  • Communications. Messages to support, sales, security or privacy, including the product, subject, description and other details you provide. Website request forms store your submission, relevant diagnostic or sales details, replies and case status. Staff can record internal review notes. We send transactional confirmations, replies and status notifications through our email provider. Guest requests use a private access link that expires after 30 days; this expiry does not delete the request. To prevent abuse, we use a keyed hash of the connection IP address in short-lived rate counters. Attachments and Diagnostics are received only through a channel agreed with support.
  • Choices. Cookie choices, notification preferences, interface and workflow settings, and saved preferences about product usage analytics, crash reports, personalisation and synchronisation. Availability of these settings in each app depends on the features it supports. Saving an optional choice does not itself send telemetry or a crash report.

3.2 Information collected automatically on the Website

  • Connection and country data. Cloudflare processes IP addresses, requested pages, timestamps, browser and device information and security signals to deliver and protect the Website. For cookie controls we reduce its country signal to an in-scope or rest-of-world category. Separately, pricing and checkout use country information to select a regional price and check purchase eligibility. Billing, payment-country and pricing-zone information may be retained with transaction records; the reduction used for cookie controls does not apply to all country data.
  • Sign-in events. When you sign in or change security settings, our authentication provider records the time, the method used, the IP address and the browser, so that you can review your sessions and we can detect misuse.
  • Cookies and similar storage. Section 5 describes sign-in, preference, security and payment storage. With your prior analytics consent, we record public page views and selected link clicks, pseudonymous visitor and session IDs, referring domains and campaign tags, device/browser/operating-system categories, approximate country/region and IP address. We do not collect query strings, form contents or activity on private account, payment or applicant-access pages. We do not use advertising pixels, session replay or account linking. Checkout embeds Stripe's payment interface, and its processing is described separately below.

3.3 Information from the Software

Paramora Prism™

  • Sign-in. Prism signs you in through your system browser and our authorization service; the plugin never sees your password. It receives short-lived tokens that identify your Account.
  • Entitlement checks. Account and licence identifiers, activation and lease records, product version and channel, device identifiers or machine hashes, request times and connection information are used to validate access and deliver licensed components. A hash or pseudonymous identifier can still be personal data when linked to an Account; it is not automatically anonymous.
  • Automation keys. For headless use, we store only a hash of the key and a four-character hint.
  • Local logs. The plugin writes logs and validation reports on your own machine. They are not sent to us.
  • Diagnostics. The plugin can keep local logs and technical details on your machine. This site does not currently provide a Diagnostics upload. If support asks for a file through a separately agreed secure channel, you choose what to provide and should review it first; access tokens must never be included.
  • Model content. Opening or converting a model locally does not upload its contents, exports or validation reports to us. If you separately provide any of that material to support, we process the material you send for that request.

Update and component requests disclose connection information to the delivery service. Some catalogue information may be public; entitled delivery can also use Account and licence information. We do not treat all update requests as anonymous. Material changes to this processing will be explained before they are introduced.

3.4 Information from other sources

  • Identity providers. If you choose an enabled third-party sign-in method, the provider sends identity information such as a provider identifier, email address and profile name or image, according to the permissions and configuration of that sign-in method.
  • Your organisation. If our assisted administration process links your Account to an organisation, we receive the membership and role information needed to do so. Your Account email remains part of your own identity record and is not exposed in the organisation member directory.
  • Stripe. Payment and subscription events provide customer, order, invoice and subscription identifiers, amounts, currencies, taxes, billing or payment-country information, payment-method details such as card brand and last four digits where available, and payment, refund, dispute or fraud-review status. We retain transaction records and some provider event data for provisioning, reconciliation and support. Full payment-card numbers are entered directly into Stripe's payment interface.
  • Public and commercial sources. For business customers we may check company registration and sanctions lists to meet legal obligations.

3.5 What we do not collect

We do not intentionally collect special categories of personal data (such as health, biometric, genetic, religious or political data), government identification numbers, precise geolocation, or personal data from children (section 13). Please do not include such data in support requests.

Back to contents

4. Why we use personal data and on what legal basis

The table explains our purposes and the relevant GDPR legal bases when we act as controller. Contract applies where processing is necessary for our contract with you personally; for an organisation's contact person, our legitimate interest is administering that customer relationship. Processing solely on an organisation's instructions follows section 12. Where we rely on legitimate interests, we must balance those interests against your rights; you may object as described in section 10.

Purposes, data and legal bases
PurposeDataLegal basis
Deliver the Website and keep it secureConnection data, security signals, region classLegitimate interests (Article 6(1)(f)): running a secure, available website
Create and manage your Account, sign you in, keep your sessions and security settingsAccount details, avatar, preferences and sign-in eventsContract (Article 6(1)(b))
Sell, activate, validate and enforce licences, seats, pools and keysAccount details, entitlement checks, machine identifiers, organisation detailsContract (Article 6(1)(b)) for personal licences; legitimate interests (Article 6(1)(f)) for licence enforcement and administering business customer access
Take payment, issue invoices, handle refunds, collect and report tax, keep accountsBilling details, order historyContract (Article 6(1)(b)); legal obligation (Article 6(1)(c)): bookkeeping and tax law
Provide support and respond to your requestsCommunications, Diagnostics you send, Account detailsContract (Article 6(1)(b)) where needed for your service or requested pre-contract steps; legitimate interests (Article 6(1)(f)) in answering enquiries and resolving problems; instructions under Annex B for processor data
Detect, investigate and prevent fraud, abuse and security incidentsConnection data, sign-in events, entitlement checks, Stripe fraud signalsLegitimate interests (Article 6(1)(f)): protecting the service and its users; legal obligation: security of processing
Record service events and present notices in the Account; support provider-hosted receipts or separately arranged notices where configuredAccount details, billing detailsContract (Article 6(1)(b)); legal obligation (Article 6(1)(c))
Save communication and optional product preferencesAccount identifier and your saved choicesContract (Article 6(1)(b)) for requested settings; consent (Article 6(1)(a)) for optional processing only when separately explained and enabled
Investigate service problems and plan capacityOperational, support and licensing information; aggregated statisticsLegitimate interests (Article 6(1)(f)) in maintaining and improving service reliability; no separate use of processor support samples beyond instructions
Comply with the law, including sanctions screening and lawful requests from authoritiesAccount and billing details, order historyLegal obligation (Article 6(1)(c))
Respond to data-protection requests and demonstrate complianceRequest details, proportionate identity checks, export or erasure records and correspondenceLegal obligation (Article 6(1)(c)): data-subject rights and accountability requirements
Establish, exercise or defend legal claimsAny of the above, as relevantLegitimate interests (Article 6(1)(f))
Select regional prices and check purchase eligibilityCountry signals, billing and payment-country information, pricing zoneLegitimate interests (Article 6(1)(f)) in administering regional offers and preventing misuse; legal obligation (Article 6(1)(c)) where tax or applicable sanctions law requires it

We need required identity and contact information to create an Account, licence and device information to validate licensed access, and relevant billing information to process a purchase. Necessary connection and security data are processed when you use the service. Optional profile details, an avatar and support samples are voluntary; without enough information we may be unable to investigate a request. Licence checks and regional price or eligibility checks use automated rules. They can affect the price shown or whether access is granted. If you believe a result is wrong, contact support for human review and to contest it. We will assess any additional safeguards required where an automated decision has legal or similarly significant effects.

Back to contents

5. Cookies and similar technologies

The Website uses cookies and similar storage for sign-in, security, requested appearance settings, desktop authorisation and your cookie choices. Storage strictly necessary for a service you request does not require cookie consent; optional storage does. This rule also applies to local storage even when information stays in your browser. We save your theme when you choose it and do not use it to track you. Rejecting optional categories does not disable sign-in or other necessary functions.

Cookies and browser storage used by the Website
NameKindSet byLifetimePurpose
Cloudflare TurnstileThird-party anti-abuse script and challenge token on support and careers formsCloudflare, when a protected form is openedChallenge token: five minutes and single useNecessary automated-abuse prevention; processes network and browser signals. No advertising or analytics purpose. Any clearance cookie is disclosed separately below
nb-analyticsHost-only optional cookieNeobuilt, after analytics consent30 daysPseudonymous public-site visitor ID; no account linking
nb-analytics-sessionOptional session storageNeobuilt, after analytics consentTab session; new session after 30 minutes of inactivityGroups consented page views and key link clicks
nb-analytics-deleteNecessary host-only cookie for a requested deletionNeobuilt, on withdrawalUntil deletion succeeds, at most seven daysRetries your privacy request; never used to track visits
sb-<project-ref>-auth-token (and .0, .1, … chunks)Host-only cookie on www.neo-built.comSupabase SSR authentication400 days, or the browser session when Remember me is offMaintains the signed-in session
nb-session-onlyCookieSign-in formBrowser sessionRecords that Remember me was left off
__Host-neo-built-auth-nextCookiePasswordless sign-in action10 minutesPreserves a validated desktop authorization return path
__Host-neo-built-email-tokenCookieEmail confirmation flow10 minutesPrevents link scanners from consuming an emailed token
__Host-neo-built-recovery-tokenCookiePassword recovery flow10 minutesPrevents link scanners from consuming a recovery token
themeLocal storageFooter theme controlUntil clearedKeeps the light or dark theme in this browser
nb-desktop-approval:<request-id>Session storageDesktop authorization screenTab sessionPrevents submitting one authorization request twice
__cf_bmCookie, only when Cloudflare bot controls require itCloudflare30 minutes of inactivityProtects the site from automated abuse
cf_clearanceCookie, only when a Cloudflare challenge is usedCloudflareConfigured challenge-passage period; may be extended during a challengeRecords that the browser passed a security challenge
__stripe_mid / __stripe_sid and payment-provider storageCookies or similar storage in the payment flow, where setStripeProvider-dependent; commonly one year and 30 minutes respectivelyPayment processing and fraud prevention; see Stripe's cookie information
nb-regionHost-only cookieNeobuilt middleware24 hoursStores only eu or row to decide whether to show consent controls
nb-consentHost-only cookieCookie settings12 monthsStores the policy version, decision time, and optional-category choices

Cookie controls are available through Cookie settings. All visitors on applicable public pages receive equally prominent Accept all and Reject all choices. Choices last 12 months unless withdrawn, cleared or replaced by a new consent version. First-party website analytics uses your consent as its legal basis. Full IP addresses become inaccessible after seven days and are removed by scheduled maintenance; visit events are retained for up to 90 days. Only authorised owners can access visitor-level reports. Withdrawal stops future collection, clears tracking identifiers and requests deletion of this browser's events. A necessary deletion-retry cookie lasts up to seven days if that request fails; contact our privacy mailbox if you need confirmation of erasure. A hashed revocation receipt remains for 90 days to prevent delayed events from recreating deleted history. A materially new purpose requires fresh consent. We do not sell or share data for targeted advertising.

Payment pages use Stripe's embedded interface and may use its fraud-prevention storage. Its exact storage depends on the payment method and enabled features. See Stripe's cookie information. The strictly necessary exception applies only to the extent a technology meets that legal test; a provider's label alone does not establish an exemption.

Back to contents

6. Who we share personal data with

6.1 Service providers and their roles

Providers perform different roles. A processor handles data on our instructions; a sub-processor does so where we in turn act for an organisation. An independent controller determines its own purposes under its own notice. The register below distinguishes those roles. Annex B of the Terms governs direct notice and authorisation for changes to sub-processors handling an organisation's data. Contracting entities, locations and safeguards marked for confirmation must be verified before this revised notice is published as final.

Provider register
ProviderPurposeRoleLocationSafeguard or notice
Resend (Plus Five Five, Inc. (Resend); applicable account agreement to be confirmed)Transactional support conversations and annual renewal reminders: recipient details, message content, plan, renewal date, amount, billing link and delivery eventsProcessor; sub-processor for agreed organisation processingSending region: EU (Ireland, eu-west-1); international processing and support access, including the United StatesResend DPA; applicable account agreement, transfer safeguards and organisation authorisation to be confirmed
Supabase (contracting entity to be confirmed)Authentication, database, and private object storageProcessor; sub-processor for agreed organisation processingPrimary database region: EU (Stockholm, eu-north-1); backups and support-access locations to be confirmedApplicable DPA and transfer safeguards to be confirmed against our service agreement
Cloudflare (contracting entity to be confirmed)Website and account delivery, Workers, CDN, DNS and securityProcessor for hosted service data; other roles depend on the service termsGlobal edgeApplicable DPA, access locations and transfer safeguards to be confirmed against our service agreement
Stripe (contracting entity to be confirmed)Payments, subscriptions, and invoicingProcessor for specified services; independent controller for its own payment, fraud and legal purposesInternational processing; applicable locations to be confirmedStripe Privacy Policy; our applicable DPA and transfer arrangements remain to be confirmed

6.2 Other recipients

  • Your organisation. If your Account is part of an organisation, its managers can see your name, role, seat and activation state, and the status of the organisation's licences (section 12). The current member directory does not expose your email address.
  • Identity providers. When you sign in through a third-party provider, that provider learns that you signed in to Neobuilt.
  • Professional advisers. Auditors, accountants, lawyers and insurers, under confidentiality, where needed to run the company or handle a claim.
  • Authorities. Courts, regulators, law-enforcement and tax authorities where the law requires it or where a request is lawful and proportionate. We review every request, disclose only what is required, and tell you when the law allows.
  • Business transfers. If we merge, are acquired or sell assets, personal data may be transferred to the successor, which must honour this policy. We will notify you before your data becomes subject to a different policy.
  • With your consent or at your direction, for example when you ask us to share something with a colleague.

We do not sell personal data, we do not share it with advertising networks or data brokers, and we do not share it for targeted advertising.

Back to contents

7. International data transfers

We operate from Sweden. The configured primary Supabase database region for Account, licence and billing data is Stockholm, Sweden (eu-north-1), but a primary database region does not establish where every backup, log or support access occurs. Other providers' hosting, delivery, support or payment operations can involve countries outside the EEA. The provider register identifies the location information and confirmation still needed for this revised notice. Restricted transfers require a valid basis for the particular recipient and processing, such as a relevant adequacy decision or executed Standard Contractual Clauses with the required assessment and supplementary safeguards. UK or Swiss transfer rules apply separately where relevant. We do not treat a provider's public certification or published contract template as proof of the mechanism governing our engagement. Contact the privacy mailbox for the applicable transfer information and a copy of safeguards, with necessary confidential information redacted.

Back to contents

8. How long we keep personal data

Retention depends on the purpose, whether your Account or a case remains active, the need to investigate security events, and applicable recordkeeping or claims requirements. The proposed time limits below are not yet an implemented automatic deletion schedule. Time-based deletion and redaction remain disabled until an approved legal-hold model and privileged-audit archive checkpoint can be enforced, so merely passing a proposed age window does not cause deletion or redaction. Records may remain beyond those proposed limits while retention controls are completed, but that does not create a right to retain unnecessary personal data indefinitely. Requests for erasure are assessed separately and remain subject to legal response deadlines. The unresolved schedule and provider backup periods require confirmation before this revised notice is final.

Current retention criteria and proposed time limits
DataHow longWhat happens then
Account profile, preferences, sign-in methods and organisation membershipFor the life of the AccountDeleted when an approved Account erasure completes; requester details are cleared from the completed request record
Security and activity logs (sign-ins, seat changes, key events)24 monthsProposed deletion limit. Account erasure removes or redacts identifying links where possible; remaining event records are not necessarily anonymous.
Prism activations and machine identifiers18 months after deactivationDeleted with the activation; deleted with the Account
Historical application device records12 months after last sign-inDeleted; deleted with the Account
Prism floating leases90 days after release or expiryDeleted; deleted with the Account
Revoked automation keys and activation-attempt evidence24 months after revocation or attemptDeleted
Accounting information in orders, invoices and related recordsThrough the seventh year after the calendar year in which the financial year ends, where Swedish bookkeeping law requires itKeep information actually required for accounting and tax; the statutory period does not automatically apply to every licence or device record. Remove other personal details and direct Stripe links when no longer needed. One-way provider suppression hashes prevent accidental relinking after the direct link is removed.
Support correspondence and DiagnosticsDiagnostics until the matter is closed; correspondence up to 24 months after closureDeleted
Consented website analyticsIP addresses seven days; events 90 days; hashed withdrawal receipts 90 daysExpired IPs and events are excluded from reports immediately and removed in bounded scheduled maintenance every 15 minutes. Withdrawal requests deletion of the browser’s events. Protected backups follow the processor’s separate retention and must be purged before restored data serves traffic.
Data-subject request workflow records24 months after completion or rejectionThe requester email, Account link and working notes are cleared as soon as the request closes; the pseudonymous workflow record is then deleted after 24 months
Closed support impersonation and external-operation records24 months after closureDeleted
Verified Stripe webhook and mirror payloadsWebhook payloads 30 days after the later of completed processing and completed provisioning; terminal object payloads 90 days after syncProposed redaction of detailed payment events, retaining the identifiers and results still needed for reconciliation. Retained identifiers may remain personal data.
Privileged-access audit chainRetention limit remains to be confirmedAccess and security evidence currently remains in the audit record until an approved archive-checkpoint and deletion schedule is adopted. Technical audit integrity alone is not a statutory retention requirement or a legal hold.
Consumed or expired staff step-up token digests24 hours after use or expiryDeleted under the proposed schedule
Communication choices and opt-outsFor as long as needed to honour your choiceKept as a suppression record so you are not contacted again
Website connection logs at our hosting providerProvider-specific periods remain to be confirmedDeletion depends on the configured service; no fixed provider deletion period is promised here
Cookie choice and region class12 months and 24 hours respectively, in your browserExpire automatically
Data relevant to a legal claimUntil the claim and any limitation period endDeleted

The Account portal submits a deletion request; it does not erase the Account immediately or cancel a subscription. We verify the request, arrange any subscription cancellation and organisation ownership changes, and coordinate deletion of profile images and external account records. An approved erasure removes account data and releases organisation Seats; records still needed for a lawful purpose are restricted or de-linked where possible. De-linked, hashed or pseudonymous records may still be personal data. We explain any data we must keep and why. Provider records and backups need their own deletion arrangements; a database deletion does not establish that every copy has been erased. Stripe may retain information for purposes it controls under its own notice.

Back to contents

9. How we protect personal data

We apply technical and organisational measures appropriate to the risk, including:

  • encryption in transit for every connection, and host-only, secure session cookies on the account domain;
  • email verification and the passkey or second-factor options enabled for your Account;
  • database access policies and role checks that restrict access to your own records and any organisation records you are authorised to manage;
  • hashed password and automation-key verification where applicable, protected server credentials, and restricted access to administrative functions;
  • separate controls for software delivery, described on the security page; an unsigned preview is identified as such rather than represented as a signed production release;
  • logging of security-sensitive account and administrative actions;
  • a coordinated vulnerability-disclosure process, described on the security page.

No system is perfectly secure. Where we are controller, we notify the competent supervisory authority of a personal-data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless it is unlikely to result in a risk to individuals' rights and freedoms. We explain any delay and inform affected individuals without undue delay where the breach is likely to create a high risk, subject to the statutory exceptions. Where we act as processor, we notify the relevant controller under Annex B of the Terms. Report an account compromise or vulnerability to security@neo-built.com.

Back to contents

10. Your rights and how to exercise them

10.1 Your rights

Subject to the conditions and exceptions in applicable law, your rights include:

  • access the personal data we hold about you and receive a copy;
  • rectification of inaccurate or incomplete data;
  • erasure of your data where there is no longer a reason for us to keep it;
  • restriction of processing in the circumstances the law describes;
  • portability: where processing is automated and based on consent or a contract, receive personal data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible;
  • object to processing based on legitimate interests, on grounds relating to your particular situation, and to direct marketing at any time;
  • withdraw consent at any time where we rely on it, without affecting processing before the withdrawal;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to the exceptions in the law;
  • lodge a complaint with a supervisory authority.

10.2 How to exercise them

Use the Account portal to update your profile, request an export, manage sessions and devices, or request deletion. The export request enters our privacy queue for a response; it also unlocks a protected ZIP download containing account data and any saved avatar. Contact privacy@neo-built.com for other personal data or help with any right, including if you cannot sign in. We request additional identity information only where reasonably necessary. Under the GDPR we respond without undue delay and within one month of receipt. If complexity or the number of requests justifies an extension of up to two further months, we tell you within the first month and explain why. Requests are normally free; if a request is manifestly unfounded or excessive, we may charge a reasonable permitted fee or refuse, explaining the reason and your complaint and judicial-remedy options. We do not penalise you for exercising your rights.

10.3 Complaints and supervisory authorities

You can raise a concern with us, but do not have to do so before complaining to an authority. In Sweden you can contact Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, Box 8114, 104 20 Stockholm, Sweden, imy@imy.se, www.imy.se. Under the GDPR you may also complain to an authority where you habitually live, work or believe an infringement occurred. UK and Swiss residents may contact the Information Commissioner's Office or the Federal Data Protection and Information Commissioner respectively, where the relevant law applies.

Back to contents

11. Marketing communications

Neobuilt uses Resend for support conversations and, for enabled annual subscription programs, necessary renewal reminders with your plan, renewal date, amount and billing link. Supabase Auth may send the configured confirmation, recovery and secure email-change messages needed for your Account, and Stripe may send a payment receipt or other provider notice when that feature is configured there. This site does not currently operate a general product, security or marketing email sender. Those necessary account and provider messages are separate and do not subscribe you to marketing. Saved notification choices do not mean a marketing message is sent today. We will not enable self-service annual automatic renewal until the required renewal-notice content and delivery have been verified. Before introducing marketing, we will explain the purpose and obtain consent where required. Any existing-customer exception will be used only if all applicable conditions are met, including relevant similar products and a clear, free opt-out both when the address is collected and in each message. You can object to direct marketing at any time at privacy@neo-built.com. We do not disclose your details for another organisation's own marketing.

Back to contents

12. Organisation Accounts

When an organisation licenses our Software for its members, membership creation, invitation, removal and leaving are currently handled through assisted sales or administration. In the Account portal, authorised managers can assign, release and reassign existing seats and see members' names, roles, seat and activation state, and the status of the organisation's licences. They cannot see member email addresses, passwords, passkeys, personal licences or sessions.

For directory, role and Seat administration on the organisation's documented instructions, and agreed support samples processed on its behalf, we act as processor under Annex B of the Terms of Service. The organisation is responsible for its purposes and notices. For our own account authentication, security, licence enforcement, invoicing and legal compliance we remain a controller, including where you use an organisation's licence. You can contact either the organisation or us about your rights; we direct processor-data requests to the organisation and handle our controller-data requests ourselves. Removing membership ends organisation access; a personal Account may continue separately.

Back to contents

13. Children

Accounts and purchases are intended for adults aged at least 18, or the higher age of majority where applicable. We do not direct these services to children or knowingly invite them to create Accounts. If you believe we hold a child's personal data, contact privacy@neo-built.com. We will investigate and take appropriate steps, including deletion where there is no lawful reason to retain it. The contractual age requirement is separate from any national rule on children's consent to data processing.

Back to contents

14. Information for particular jurisdictions

14.1 European Economic Area, United Kingdom and Switzerland

The GDPR applies to processing in the context of our Swedish establishment, including where an individual is outside the EEA. UK and Swiss laws apply according to their own scope and requirements; they are not identical to the GDPR. Any required local representative and additional disclosures must be identified for the relevant service before that processing begins.

14.2 United States

US state privacy laws have different scope, definitions and rights. Where one applies to our processing, we honour its applicable access, correction, deletion, portability, opt-out, appeal and non-discrimination requirements. We do not sell personal data or share it for cross-context behavioural advertising, and do not use it for targeted advertising. Account credentials may count as sensitive personal information under some laws; we use them for account access and security. Contact the privacy mailbox to make a request or challenge our response. An authorised agent may act where permitted, subject to proportionate verification. A state-specific supplement is required if applicable law requires disclosures beyond this policy.

14.3 Other countries

You may also have rights under other applicable local privacy laws. Contact the privacy mailbox for help exercising them. This policy does not replace a required local notice, representative or complaint route; those must be provided for a service where applicable.

Back to contents

15. Changes to this policy

We update this policy when our processing, our providers or the law change. The effective date and the date of the last change are shown at the top of the page, and we keep earlier versions available on request. For material changes we give the legally required notice through the Website and Account. Where the applicable law or contract requires delivery by email, we will not make that change effective until a verified delivery channel exists. We will not apply a materially different use of personal data already collected without a lawful basis for it, which may mean asking for your consent.

Back to contents

16. Contact us

Questions, requests and complaints about this policy go to privacy@neo-built.com. Product support is at support@neo-built.com, billing at billing@neo-built.com, and security reports at security@neo-built.com.

Company identification and contact points
ItemDetails
Legal nameNeobuilt AB
Country of incorporationSweden
Organisation number559519-2781
VAT identification numberSE559519278101
Websitewww.neo-built.com
General enquiries and supportsupport@neo-built.com
Billing and ordersbilling@neo-built.com
Privacy and data subject requestsprivacy@neo-built.com
Security reportssecurity@neo-built.com

Back to contents