DRAFT — for counsel review. Not legal advice, and not yet in effect.
Version 0.1 (draft) · Effective [Effective Date] · [Neivan Legal Entity, Inc.]
This Privacy Policy explains how [Neivan Legal Entity, Inc.] ('Neivan', 'we', 'us') collects, uses, discloses, and protects personal data in connection with the Synapse platform and the neivan.example website (together, the 'Service'). It is written to meet GDPR / UK-GDPR-grade expectations and to address California (CCPA/CPRA) and similar global privacy requirements.
NOTE TO COUNSEL: Bracketed items are organizational blanks to confirm before publication. Cross-references to the Data Processing Agreement (DPA), Cookie Policy, and Subprocessor List assume those documents are published alongside this Policy.
Neivan provides Synapse, a business-to-business (B2B) software-as-a-service platform on which organizations build and run AI agents, skills, and workflows that act on their connected systems, including an assistant ('Jarvis'), build-and-optimize-with-AI tooling, teach-by-demonstration, and an automation pipeline.
Our role under data-protection law depends on whose data is involved:
If you are an Authorized User and have questions about how your employer uses your data in Synapse, please contact your employer (the Customer) first, as it is the controller of that data.
We collect the following categories. Not all apply to every person; what we collect depends on whether you are a site visitor, an account contact, or an Authorized User in a Customer workspace.
Name, business email, organization, role, and the credentials and settings needed to create and secure an account.
For Authorized Users in a Customer workspace, the Customer may configure Synapse to process:
Content and metadata Synapse accesses from systems a Customer connects — email, calendar, drive, CRM, and custom APIs — via OAuth or API keys, strictly to perform the tasks the Customer has configured.
For paid plans, payment is processed by Stripe. Card data is tokenized by Stripe (PCI SAQ-A) and is never stored by Neivan. Neivan retains only non-sensitive payment metadata such as card brand, last four digits, and Stripe reference identifiers.
Logs, device and connection information, feature usage, error and diagnostic data, and the contents of support communications.
Cookies, similar technologies, and browser local storage used to operate, secure, and (where enabled) measure the Service. See Section 11 and our Cookie Policy.
We collect personal data: (a) directly from you when you register, configure, or use the Service or contact us; (b) from the Customer that administers your workspace and configures observation, connections, and Authorized-User records; (c) automatically through your use of the Service (usage, telemetry, cookies, local storage); (d) from connected systems the Customer authorizes; and (e) from service providers such as our payment processor.
Where GDPR / UK-GDPR applies, we rely on the lawful bases below. Where we act as processor, the Customer is responsible for establishing the lawful basis for the underlying processing it directs.
| Purpose | Personal data | Lawful basis |
|---|---|---|
| Provide, operate, and secure the Service | Account, Authorized-User, connected-system, usage data | Performance of a contract; legitimate interests (security, service integrity) |
| Authenticate users and enforce access controls | Account data, credentials, audit logs | Performance of a contract; legal obligation (security) |
| Process payments and manage billing | Payment metadata | Performance of a contract |
| Run AI agents, skills, workflows, and the Jarvis assistant | Prompts, connected-system content, configuration | Performance of a contract |
| Observation and desktop capture features | Activity metadata, screen frames, accessibility metadata | Consent and/or Customer-established basis (see Section 5) |
| Improve, troubleshoot, and develop the Service | Usage, telemetry, diagnostics | Legitimate interests |
| Communicate about the account and respond to support | Account and support data | Performance of a contract; legitimate interests |
| Comply with law and enforce terms | As needed | Legal obligation; legitimate interests |
| Non-essential cookies and analytics (where enabled) | Cookie and device data | Consent |
Where we rely on legitimate interests, we balance those interests against your rights and you may object (see Section 9).
Synapse offers two observation capabilities, both designed to be transparent and consent-gated:
Observation is configured by the Customer as controller. Neivan processes observation data on the Customer's behalf under the DPA. Authorized Users are shown transparency surfaces describing what is being observed.
Synapse delivers AI features by sending prompts and related content to a third-party large language model (LLM) provider via its API. Depending on the Customer's configuration, the provider may be Anthropic, OpenAI, Google, Perplexity, Mistral, DeepSeek, or xAI.
We do not sell personal data. We share personal data only as follows:
We do not 'sell' personal data, and we do not 'share' it for cross-context behavioral advertising, as those terms are defined under California law (see Section 9).
We and our subprocessors may process personal data in countries other than your own. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, principally the European Commission Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where applicable), together with supplementary measures as needed. You may request information about these safeguards using the contact details in Section 13.
Subject to applicable law and verification, you may have the rights below. Where Neivan is a processor, we will forward your request to the relevant Customer (controller) and assist it in responding.
Access; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interests; the right to withdraw consent at any time (without affecting prior processing); and the right to lodge a complaint with your supervisory authority. We do not make decisions producing legal or similarly significant effects based solely on automated processing without a lawful basis and appropriate safeguards.
The rights to know, access, correct, and delete personal information; to data portability; to opt out of the 'sale' or 'sharing' of personal information; and to limit the use of sensitive personal information. Neivan does not sell personal information and does not share it for cross-context behavioral advertising, so there is no 'Do Not Sell or Share My Personal Information' transaction to opt out of; we honor opt-out preference signals where required. We will not discriminate against you for exercising your rights.
Submit a request to [[email protected]] or via [Rights Request Mechanism]. We will verify your identity before responding and will respond within the timeframes required by applicable law. You may use an authorized agent where the law permits.
We retain personal data only as long as necessary for the purposes in this Policy, including providing the Service, meeting legal, accounting, and security obligations, and resolving disputes. For workspace data we process as processor, retention follows the Customer's configuration and the DPA, including retention controls for observation events and redacted screen frames. When data is no longer needed, we delete or de-identify it. Specific retention periods are set out in [Retention Schedule].
The Service uses cookies, similar technologies, and browser local storage to operate, secure, and (where enabled) measure the Service. Strictly necessary technologies are used without consent; analytics and other non-essential technologies are used only with consent where required. For details and choices, see our Cookie Policy and Section 9.
The Service is a B2B product intended for business use by adults and is not directed to children or minors. We do not knowingly collect personal data from minors. If you believe a minor has provided us personal data, contact us at [[email protected]] and we will take appropriate steps.
We maintain administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit and at rest, role-based access control (RBAC), audit logging, tenant isolation, server-side secret vaulting, and a breach-notification process. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected parties and regulators of qualifying incidents as required by law.
We may update this Policy from time to time. We will post the updated version with a new effective date and, where required, provide additional notice. Material changes will be communicated through the Service or by other appropriate means.
[Neivan Legal Entity, Inc.], [Registered Address]. Privacy contact: [[email protected]]. Our Data Protection Officer and/or EU/UK Representative (where appointed) can be reached at [DPO / EU Representative]. Governing law and venue for disputes are set out in [Governing-Law Jurisdiction] and the applicable customer agreement.
DRAFT for counsel review — substantive first pass only; not legal advice and not yet in effect. Counsel must validate jurisdictional coverage, lawful bases, retention periods, and all bracketed placeholders before publication. Questions: [[email protected]].