Privacy Policy
Who we are
This Privacy Policy describes how Neumetria collects, uses, and protects personal data in connection with the website www.neumetria.com (the "Site"), the Neumetria customer portal (the "Portal"), and our business communications with prospects, customers, and partners.
The data controller for personal data covered by this policy is:
- Neumetria, Inc. (Delaware, USA) — for visitors and contacts outside the European Economic Area and the United Kingdom; and
- Neumetria OÜ (Estonia, reg. no. 17327225) — for visitors and contacts in the European Economic Area and the United Kingdom.
Contact details for both entities are in Section 14.
What this policy does not cover
Platform data. Neumetria provides a behavioral intelligence platform to businesses such as banks, fintechs, and lenders. When our business customers submit data to the platform (including their end users' bank transaction data), Neumetria processes that data as a processor on the customer's behalf, under the agreement and data processing agreement (DPA) with that customer — not under this policy. The categories of data processed, the subprocessors involved, and the safeguards applied are described in our DPA and subprocessor list. If you are an end user of a financial product that uses Neumetria, the provider of that product is the controller of your data — please direct privacy inquiries to them; we support our customers in responding to such requests.
Claroo. The Claroo consumer application is operated separately by Claroo SIA (Latvia) and has its own terms and privacy policy, available within the Claroo application and on its website. Claroo uses the Neumetria platform as a customer, under the same processor arrangement described above. This policy does not apply to Claroo.
Personal data we collect
- Contact and business information — name, email address, job title, company, and the content of your messages when you contact us (for example at hello@neumetria.com or sales@neumetria.com), request information, or engage with us commercially.
- Portal account data — if your organization uses the Neumetria Portal: your name, email address, avatar, authentication data (passwords are stored only in hashed form; single sign-on tokens are encrypted), session information (IP address, browser/device), API key metadata, and your organization's billing contact details.
- Website usage and technical data — IP address, device and browser information, pages viewed, and interaction events collected through the analytics and monitoring tools described in Section 5.
We collect only what is necessary for the purposes described below. We do not sell or rent personal data, and we do not use personal data covered by this policy to train artificial-intelligence models.
How we use personal data and legal bases
We use personal data to:
- operate, secure, and improve the Site and the Portal — legal basis: legitimate interests (running and protecting our services), or performance of the contract with your organization;
- respond to inquiries and manage commercial relationships — legal basis: legitimate interests, or steps taken at your request prior to entering into a contract;
- understand how the Site is used (analytics) — legal basis: consent, where required by law, otherwise legitimate interests;
- send communications about our products and events — legal basis: legitimate interests or consent, where required; you can opt out at any time;
- comply with legal obligations — legal basis: legal obligation; and
- establish, exercise, or defend legal claims — legal basis: legitimate interests.
Cookies, analytics, and monitoring
The Site and Portal use:
- PostHog — product and website analytics (hosted in the United States);
- Vercel Insights — website performance analytics; and
- Sentry — error and performance monitoring (EU data ingestion).
Where required by applicable law (including for visitors in the EEA and the UK), non-essential cookies and analytics run only with your consent, which you can withdraw at any time via the cookie settings on the Site. Strictly necessary cookies (such as session and security cookies for the Portal) do not require consent.
Sharing and disclosure
We share personal data only with: service providers who help us operate the Site, the Portal, and our business — including hosting and infrastructure (Vercel, Google Cloud, Supabase), analytics and monitoring (PostHog, Sentry), and email delivery (Resend) — under confidentiality and data protection obligations; our group companies (Neumetria, Inc. and Neumetria OÜ) for the purposes described in this policy; professional advisers, regulators, or authorities where required by law or to protect our rights; and a successor entity in connection with a merger, acquisition, corporate reorganization, or sale of assets, subject to the same privacy commitments.
A current list of the subprocessors used to provide the Neumetria platform is available on request and is maintained for customers under our DPA.
International transfers
Personal data may be processed in the United States (by Neumetria, Inc. and by US-based service providers such as PostHog) and in the European Union (by Neumetria OÜ; our primary platform infrastructure is hosted in the EU). Where personal data is transferred out of the EEA or the UK, we rely on appropriate safeguards recognized by applicable law, such as the European Commission's Standard Contractual Clauses.
Security
Neumetria maintains an information security programme with administrative, technical, and physical safeguards aligned with the SOC 2 Trust Services Criteria and the ISO/IEC 27001 control framework, and processes personal data in accordance with GDPR. Measures include tenant-level data isolation, role-based access controls, hashed credentials and API keys, encryption of tokens at rest, TLS-encrypted transport, and rate limiting. We will provide applicable certifications or third-party assurance reports when available. No system is completely secure; where required by law, we will notify you and the relevant authorities of a personal data breach.
Retention
We retain personal data only as long as necessary for the purposes described in this policy, to comply with legal obligations, or to resolve disputes. Portal account data is deleted when your organization's account is closed, subject to legal retention requirements. When personal data is no longer needed, we delete it.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to certain processing, and to withdraw consent at any time where processing is based on consent. If you are in the EEA or the UK, you also have the right to lodge a complaint with a supervisory authority — for Neumetria OÜ, the lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). To exercise any of these rights, contact privacy@neumetria.com. We will respond within the timelines required by applicable law. Where Neumetria acts as processor for one of our customers, we will refer your request to that customer and assist them in responding.
Children
The Site and Portal are directed at business audiences and not at children. We do not knowingly collect personal data from anyone under 18.
Automated decision-making
Neumetria does not make automated decisions producing legal or similarly significant effects about individuals covered by this policy. Our platform provides decision-support signals to business customers; those customers remain responsible for their own decisions and for any related obligations to their end users.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above indicates the latest revision. Where required by law, we will notify you of material changes.
Contact
Neumetria, Inc., 1111B South Governors Avenue, STE 39948, Dover, DE 19904, USA
Neumetria OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia