NEO& / Legal / Data Protection
Data Protection
01About this statement
This statement summarizes the organizational and technical approach we use to protect personal data. It should be read together with our Privacy Policy, which explains how and why we process personal data.
02Our approach
We aim to collect only the personal data reasonably needed for a defined purpose, keep material records accurate, limit access according to business need, retain information only for as long as justified, and consider privacy and security when systems or processing activities materially change.
03Security measures
We use risk-based security measures appropriate to the systems and information involved. These may include encrypted transmission, access controls, multi-factor authentication, secure configuration, backups, logging, anti-abuse controls, software updates and security features provided by our technology suppliers.
Payment-card details are intended to be handled directly by the relevant payment provider rather than stored in NEO&'s ordinary website or program systems.
04People and suppliers
Access to personal data is limited to people who reasonably need it for their role. Employees, contractors and facilitators who handle confidential or personal information are subject to appropriate confidentiality obligations.
We also assess service providers proportionately to the service and information involved and use appropriate contractual and data-protection arrangements where they process personal data for us.
05Data incidents
If we become aware of a suspected personal-data breach, we assess the circumstances, take appropriate steps to contain and address the issue, keep relevant records and make any notification required by applicable law.
06Service providers and transfers
We use third parties for services such as hosting, email, live-session delivery, productivity tools, security and payment. The exact providers may change. Where a provider processes personal data for us, we seek contractual and security protections appropriate to its role. Cross-border processing is handled as described in the Privacy Policy.
07Access, deletion and disposal
Access to working records is restricted according to business need. When data reaches the end of its approved retention period, it is deleted, anonymized or otherwise disposed of using a method proportionate to the system and sensitivity, subject to backup cycles and legal holds.
08Contact us
Privacy questions, rights requests and reports of suspected personal-data incidents may be sent to business@neoand.com. We may need to verify your identity before providing personal data or acting on certain requests.
Questions? Email business@neoand.com.