About this Policy
Controller: Neuroclusive, Inc., a Delaware corporation
Applies to: the Neuroclusive website, the Enterprise Neuroinclusivity System (ENS), NeuriPrint™, and related products and services (together, the "Service").
Version: 1.0
1. Scope and who we are
Neuroclusive, Inc. ("Neuroclusive", "we", "us", or "our") operates the Service. This Policy explains what personal data we process, why we process it, who may receive it, how long we retain it, and the choices and rights available to you.
Neuroclusive is the controller for the assessment responses, derived indices, and individual profile data created in the Service. We determine the purposes and means of this processing and accept responsibility for its lawful basis, special-category condition, security, and data-subject rights.
2. The roles in an individual-controlled sharing flow
2.1 Neuroclusive as controller
We are controller for an Individual's profile and for the product processing needed to create, protect, and present it. We do not transfer that responsibility to the Individual or their Organization.
2.2 The Individual controls sharing
The Individual chooses which bounded result to share, the named recipient or Organization, the purpose, and the duration. Raw assessment responses are not disclosed to an Organization as a reusable copy. A diagnosis disclosure is excluded unless the Individual separately and explicitly selects it.
2.3 The Organization as a separate controller
Once an Organization receives an authorised result, it is a separate controller for what it does with that result, such as considering or administering a workplace accommodation. It must provide its own notice where required and is responsible for lawful, fair, non-discriminatory, and purpose-limited use, retention, and deletion.
2.4 Neuroclusive as processor
For a feature where an Organization determines the purposes and means of processing, such as Organization account administration or configured aggregate reporting, Neuroclusive processes that data on the Organization's instructions under a data processing agreement. The Organization is controller for that processing.
3. Personal data we process
3.1 Account and contact data
- name, email address, account identifiers, and credentials;
- profile details and communication preferences;
- Organization and team membership; and
- support requests and communications with us.
3.2 NeuriPrint™ and profile data
- assessment answers, task responses, and interaction timing;
- calculated scores, trait indices, and profile dimensions;
- cognitive, psychological, accessibility, and working preferences;
- neurodivergence or diagnosis information that you choose to provide; and
- sharing choices, consent receipts, grants, revocations, and disclosure records.
This information can reveal health, disability, cognitive, psychological, or neurodivergence-related characteristics. We treat the entire NeuriPrint™ profile as special-category data where applicable law classifies it that way.
3.3 Service, device, and security data
- features used, learning progress, and product interactions;
- device, browser, IP address, and approximate location;
- authentication, access, audit, and security events; and
- content submitted to an AI-assisted feature where you choose to use that feature.
4. Why we process data and our legal bases
Where UK GDPR or EU GDPR applies, we use the following Article 6 legal bases:
- Contract: to create your account and provide Service features you request.
- Consent: where you make an optional processing choice.
- Legitimate interests: to secure, maintain, and improve the Service, prevent misuse, and support users, where those interests are not overridden by your rights.
- Legal obligation: to meet legal, regulatory, accounting, or data-protection duties.
4.1 Special-category data
We rely on explicit consent under Article 9(2)(a) for assessment administration, score calculation and storage, profile generation, and Individual-directed sharing. Consent must be specific, informed, freely given, and recorded. An Organization must not make assessment completion or disclosure compulsory through the Service.
Before Neuroclusive produces protected statistical reporting as controller, we document the applicable Article 6 lawful basis and Article 9 condition for that activity. Article 9(2)(j) is used only where the processing is necessary, in the public interest, based in applicable law, and subject to Article 89(1) safeguards. It is not assumed merely because an output is aggregated. Where an Organization is controller for configured aggregate reporting, that Organization must establish its own lawful basis and special-category condition, and we process on its instructions under the data processing agreement. In either case, ordinary aggregate results are released only when the shared minimum cohort threshold described in Section 7 is met.
5. How we use personal data
- provide, maintain, secure, and improve the Service;
- administer assessments and generate your private profile;
- honour, display, and withdraw your sharing choices;
- provide learning, productivity, and support features;
- respond to support and data-rights requests;
- detect misuse, investigate incidents, and enforce our Terms;
- meet legal and regulatory obligations; and
- produce protected aggregate reporting where the required threshold and purpose controls are satisfied.
The Service does not provide a clinical diagnosis, determine fitness for work, or make a hiring-eligibility decision. An Organization must not use a result for those purposes.
6. Sharing, recipients, and withdrawal
6.1 We do not sell personal data
We do not sell, rent, or trade personal data, assessment responses, or NeuriPrint™ profiles.
6.2 Individual-authorised Organization sharing
An Organization receives only the bounded result the Individual authorised for the stated recipient, purpose, scope, and period. It does not receive raw assessment responses as a reusable copy.
When the Individual withdraws sharing, the authority used to re-derive or re-access that result through Neuroclusive is retired. Withdrawal does not recall information that a recipient already saw or separately stored. The Organization is responsible for that copy under its own legal obligations and retention policy.
6.3 Service providers and sub-processors
We use service providers for functions such as hosting, authentication, communications, support, analytics, and AI-assisted features. They may process personal data only for the contracted purpose, subject to appropriate data-protection terms. Our current AI provider purposes, regions, and retention positions are listed on the sub-processors page.
6.4 Legal disclosures and corporate events
We may disclose data where required by law or a binding legal process, or where necessary to protect rights, safety, and Service security. If our business is reorganised, acquired, or sold, data may transfer subject to this Policy and applicable law.
7. Aggregate and team reporting
Ordinary aggregate reporting uses a shared minimum cohort of five. When fewer than five eligible people contribute, the Service returns an insufficient-data result instead of releasing the aggregate. Aggregate reports do not disclose raw responses, individual profiles, names, or completion status.
The threshold is a minimum safeguard, not a guarantee that every aggregate is anonymous in every context. We also apply purpose-limitation, access, lineage, and disclosure controls and may withhold an output where re-identification risk remains.
8. Security and AI-assisted processing
We use technical and organizational measures appropriate to the sensitivity of the data, including encryption, access controls, authentication, audit logging, vulnerability management, incident response, and revocable purpose-scoped access on protected paths. No system is immune from every security threat, so we do not claim absolute security.
8.1 Pseudonymisation for AI requests
Where an AI-assisted feature does not need a real name, our NameCurtain control replaces the name with an opaque token before the request leaves Neuroclusive. The mapping is kept only for the bounded period needed to keep the interaction coherent and is not provided to the AI provider.
AI providers do not receive raw NeuriPrint™ assessment responses or a full profile merely because an AI-assisted feature is used. Any additional disclosure must follow the applicable purpose, minimisation, and access rules.
9. Retention, profile closure, and erasure
We retain data only for as long as needed for the purpose described in this Policy, to provide the Service, or to meet a legal obligation. Retention varies by data class and is shown in the Service's retention map where available.
- account data is retained while the account is active and then handled under the applicable closure schedule;
- profile and assessment data is retained while the relevant consent and profile remain active;
- withdrawing consent or closing a profile starts the applicable retirement and erasure process for affected profile data; and
- minimised audit, legal-hold, fraud-prevention, or compliance records may remain where law permits or requires them.
An Organization that separately stored a received result controls its own retention and deletion of that copy. You may exercise your rights directly with that Organization as well as with Neuroclusive.
10. Your data-protection rights
Depending on where you live and the processing involved, you may have rights to:
- access your personal data and receive a copy;
- correct inaccurate or incomplete data;
- request erasure;
- restrict or object to processing;
- receive portable data in a structured format;
- withdraw consent at any time;
- ask for safeguards around solely automated significant decisions; and
- complain to the data-protection authority where you live.
To exercise a right, use the privacy controls in the Service or contact privacy@neuroclusive.com. We may need to verify your identity. We will respond within the period required by applicable law.
11. Cookies and similar technologies
We use essential cookies and similar storage to authenticate users, protect the Service, remember requested settings, and keep core features working. We may use analytics or preference technologies to understand and improve the Service, subject to the choices and consent requirements that apply where you live.
Browser controls can block or remove cookies, but disabling essential storage may prevent parts of the Service from working.
12. International transfers
Data may be processed outside the country where it was collected. Where a restricted international transfer occurs, we use an applicable safeguard such as an adequacy decision, approved contractual clauses, or another lawful transfer mechanism, and assess supplementary measures where required.
13. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child under 13 has provided personal data, contact us so that we can investigate and take appropriate action.
14. Changes to this Policy
We may update this Policy as the Service or law changes. We will give reasonable notice of a material change by email, an in-Service notice, or another appropriate channel. The current version and effective date will always appear on this page.
15. NeuroLayer extension resources
If you use the NeuroLayer browser extension, these pages provide installation guidance, troubleshooting, and support:
16. Contact us
Privacy questions and data-rights requests may be sent to privacy@neuroclusive.com.
Neuroclusive, Inc.
Entity No. 10616925
74 E Glenwood Ave Unit #5761
Smyrna, DE 19977