Privacy Policy
Who we are
This Privacy Policy describes how Neumetria collects, uses, and protects personal data in connection with the website www.neumetria.com (the "Site"), the Neumetria customer portal (the "Portal"), and our business communications with prospects, customers, and partners.
The data controller for personal data covered by this policy is:
- Neumetria, Inc. (Delaware, USA) — for visitors and contacts outside the European Economic Area and the United Kingdom; and
- Neumetria OÜ (Estonia, reg. no. 17327225) — for visitors and contacts in the European Economic Area and the United Kingdom.
Contact details for both entities are in Section 15.
What this policy does not cover
Platform data. Neumetria provides a behavioral understanding platform to businesses such as banks, fintechs, and lenders. When our business customers submit data to the platform (including their end users' bank transaction data), Neumetria processes that data as a processor on the customer's behalf, under the agreement and data processing agreement (DPA) with that customer — not under this policy. The categories of data processed, the subprocessors involved, and the safeguards applied are described in our DPA and subprocessor list. If you are an end user of a financial product that uses Neumetria, the provider of that product is the controller of your data — please direct privacy inquiries to them; we support our customers in responding to such requests.
Claroo. The Claroo consumer application is operated separately by Claroo SIA (Latvia) and has its own terms and privacy policy, available within the Claroo application and on its website. Claroo uses the Neumetria platform as a customer, under the same processor arrangement described above. This policy does not apply to Claroo.
Personal data we collect
- Contact and business information — name, email address, job title, company, and the content of your messages when you contact us (for example at hello@neumetria.com or sales@neumetria.com), request information, or engage with us commercially.
- Portal account data — if your organization uses the Neumetria Portal: your name, email address, avatar, authentication data (passwords are stored only in hashed form; single sign-on tokens are encrypted), session information (IP address, browser/device), API key metadata, and your organization's billing contact details.
- Website usage and technical data — IP address, device and browser information, pages viewed, and interaction events collected through the analytics and monitoring tools described in Section 5.
We collect only what is necessary for the purposes described below. We do not sell or rent personal data, and we do not use personal data covered by this policy — the data of site visitors and portal users described above — to train artificial-intelligence models. What happens to platform data, which this policy does not cover, is described in Section 13.
'How we use personal data and legal bases
We use personal data to:
- operate, secure, and improve the Site and the Portal — legal basis: legitimate interests (running and protecting our services), or performance of the contract with your organization;
- respond to inquiries and manage commercial relationships — legal basis: legitimate interests, or steps taken at your request prior to entering into a contract;
- understand how the Site is used (analytics) — legal basis: consent, where required by law, otherwise legitimate interests;
- send communications about our products and events — legal basis: legitimate interests or consent, where required; you can opt out at any time;
- comply with legal obligations — legal basis: legal obligation; and
- establish, exercise, or defend legal claims — legal basis: legitimate interests.
Cookies, analytics, and monitoring
The Site and Portal use:
- PostHog — product and website analytics (hosted in the United States); and
- Sentry — error and performance monitoring.
Where required by applicable law (including for visitors in the EEA and the UK), non-essential cookies and analytics run only with your consent, which you can withdraw at any time via the cookie settings on the Site. Strictly necessary cookies (such as session and security cookies for the Portal) do not require consent.
Sharing and disclosure
We share personal data only with: service providers who help us operate the Site, the Portal, and our business — including hosting and infrastructure (Google Cloud), analytics and monitoring (PostHog, Sentry), email delivery (Resend), merchant enrichment and categorisation (Anthropic, OpenAI, OpenRouter, Google Maps Platform, TriqAI), sign-in (Google, GitHub), and content management and media delivery (Sanity) — under confidentiality and data protection obligations; our group companies (Neumetria, Inc. and Neumetria OÜ) for the purposes described in this policy; professional advisers, regulators, or authorities where required by law or to protect our rights; and a successor entity in connection with a merger, acquisition, corporate reorganization, or sale of assets, subject to the same privacy commitments.
To categorise a transaction we send the merchant descriptor — the text your bank recorded — to the enrichment providers named above. A descriptor can contain a person’s name, for example on a transfer between individuals. We remove account numbers, email addresses and long digit sequences before sending; we do not remove names, because a merchant name is what the lookup is for. You can switch this off per person: with third-party sharing disabled, no descriptor leaves our systems.
Most of those providers receive data from our servers. One does not: images published with our articles are served to your browser directly from Sanity’s media CDN, so Sanity receives your IP address and request headers when such an image loads on a page you visit. No other third party is contacted by your browser before you make a cookie choice — our webfonts and scripts are served from our own domain for that reason.
A current list of the subprocessors used to provide the Neumetria platform is available on request and is maintained for customers under our DPA.
International transfers
Personal data may be processed in the United States (by Neumetria, Inc. and by US-based service providers including PostHog, Sentry, Resend, Anthropic, OpenAI, OpenRouter and Google) and in the European Union (by Neumetria OÜ; our primary platform infrastructure is hosted in the EU).
Where personal data is transferred out of the EEA or the UK, such a transfer requires an appropriate safeguard recognised by applicable law — typically the European Commission’s Standard Contractual Clauses, or certification under the EU–US Data Privacy Framework. We are completing this exercise and it is not finished. We maintain a register of every recipient, what it receives and the transfer mechanism relied on for it, and that register presently records the mechanism as not yet established for several recipients. We would rather say so here than assert a safeguard we have not yet put in place. The current position for any recipient is available on request, and for our business customers it is maintained under our data processing agreement.
Security
Neumetria maintains an information security programme with administrative, technical, and physical safeguards aligned with the SOC 2 Trust Services Criteria and the ISO/IEC 27001 control framework, and processes personal data in accordance with GDPR. Measures include tenant-level data isolation, role-based access controls, hashed credentials and API keys, encryption of tokens at rest, TLS-encrypted transport, and rate limiting. We will provide applicable certifications or third-party assurance reports when available. No system is completely secure; where required by law, we will notify you and the relevant authorities of a personal data breach.
Retention
We retain personal data only as long as necessary for the purposes described in this policy, to comply with legal obligations, or to resolve disputes. Portal account data is deleted when your organization's account is closed, subject to legal retention requirements. When personal data is no longer needed, we delete it.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to certain processing, and to withdraw consent at any time where processing is based on consent. If you are in the EEA or the UK, you also have the right to lodge a complaint with a supervisory authority — for Neumetria OÜ, the lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). To exercise any of these rights, contact privacy@neumetria.com. We will respond within the timelines required by applicable law. Where Neumetria acts as processor for one of our customers, we will refer your request to that customer and assist them in responding.
Children
The Site and Portal are directed at business audiences and not at children. We do not knowingly collect personal data from anyone under 18.
Automated decision-making
Neumetria does not make automated decisions producing legal or similarly significant effects about individuals covered by this policy — site visitors and portal users. Nothing about you is scored, profiled or decided here.
Separately, our platform processes credit applicants’ data on behalf of business customers, under those customers’ agreements rather than this policy. In that context a customer may publish its own credit policy to us and have us execute it, and the customer chooses whether a person reviews each result: every one held for a named reviewer, a sampled proportion held, or resolved automatically. That choice is theirs and so is the responsibility for it — a customer resolving automatically is making a solely automated decision and must have a lawful basis for it. Our software will not publish such a policy until that basis is recorded, and where a review lapses no outcome is recorded at all.
In every mode the customer remains the controller and is responsible for the decision and for their obligations to you, including explanation, human intervention and the right to contest. Those facilities are always available in our platform and cannot be switched off by a customer’s configuration; we supply the reasons and evidence behind every assessment. If a decision was made about you by a business using Neumetria, direct your request to that business — they are the controller, and we assist them in answering it.
Model training on platform data
This section describes something this policy does not otherwise cover, and we have put it here rather than only in a contract because a reader looking for it should be able to find it.
Platform data can be used to improve our models, and it is pooled. When a business customer sends us their end users’ transaction data, we may use it to train and improve the models we serve — and the resulting model is served to all of our customers, not only the one whose data contributed. This is a deliberate design choice: a model trained on one lender’s applicants alone is a worse model, and the alternative is not a more private product but a less accurate one. We do not sell data, we do not share one customer’s data with another, and no customer can retrieve another’s data through the platform — what is shared is the model, not the records.
It can be refused, per person. Each individual carries a model_training setting. Where it is refused, that person’s data is excluded from the training corpus, and the number of records withheld is recorded on every model we fit — so the refusal is visible in our own artifacts rather than asserted here. Refusal does not degrade the assessment that person receives.
Who has to tell you this. For platform data we act as a processor and the business you deal with is the controller, so it is that business, not us, that owes you notice under Article 13 and that decides whether to permit training at all. We publish this so a customer can describe our processing accurately in their own notice, and so you can read what we do without needing a copy of our contract. If you want your data excluded, ask the provider of the financial product you use; they can set it, and we will honour it.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above indicates the latest revision. Where required by law, we will notify you of material changes.
Contact
Neumetria, Inc., 1111B South Governors Avenue, STE 39948, Dover, DE 19904, USA
Neumetria OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia