Privacy Policy

How Neurohain collects, uses, and protects your personal data

1. Who We Are

Controller: Amparo Iglesias Gordillo, operating as Neurohain — AI Consulting & Implementation, Düsseldorf, Germany.

Contact: info@neurohain.com | neurohain.com

We are committed to protecting your personal data and processing it in accordance with applicable data protection law, including the EU General Data Protection Regulation (GDPR).

2. Data We Collect

Contact form

When you submit the contact form, we collect: name, email address, company name (optional), industry, country, and your message. We use this data solely to respond to your enquiry.

Calendly booking

If you book a call via Calendly, data is processed by Calendly LLC under their own privacy policy. We receive your name, email, and meeting notes.

Newsletter / waitlist forms

When you sign up for updates or a waitlist, we collect your email address to send you the relevant communications. You can unsubscribe at any time.

Language preference

We store your selected language (EN/DE/ES) in your browser's localStorage. This is not a cookie and does not leave your device.

Server logs

Our web hosting provider automatically collects standard server log data (IP address, browser type, pages visited, timestamps). This data is not linked to you personally and is retained for a maximum of 7 days.

3. Legal Basis

We process your data on the following legal bases (Art. 6 GDPR):

  • Contract / pre-contractual measures (Art. 6(1)(b)): Processing necessary to answer your enquiry or provide a requested service.
  • Legitimate interests (Art. 6(1)(f)): Server log analysis for security and performance.
  • Consent (Art. 6(1)(a)): Newsletter and marketing emails — you can withdraw consent at any time.

4. Data Sharing

We do not sell your personal data. We may share data with:

  • Hosting providers (e.g., the WordPress host) acting as data processors under a data processing agreement.
  • Calendly LLC — for scheduling. Their privacy policy applies.
  • Email service providers used to send transactional or marketing emails.
  • Legal authorities where required by law.

Where third parties are located outside the EU/EEA, appropriate safeguards (Standard Contractual Clauses) are in place.

5. Retention

Contact enquiries are retained for up to 3 years after last contact, or as required by applicable commercial and tax law. You may request earlier deletion.

6. Your Rights

Under GDPR, you have the following rights. To exercise any of them, contact us at info@neurohain.com.

Access (Art. 15) Request a copy of the data we hold about you.
Rectification (Art. 16) Correct inaccurate or incomplete data.
Erasure (Art. 17) Request deletion of your personal data.
Restriction (Art. 18) Limit how we process your data.
Portability (Art. 20) Receive your data in a structured, machine-readable format.
Objection (Art. 21) Object to processing based on legitimate interests.
Complaint Lodge a complaint with the supervisory authority in your EU member state.

7. Changes to This Policy

We may update this privacy policy from time to time. The latest version is always available on this page. Material changes will be communicated via email where we hold your contact details.

8. Access to Client Systems (Implementation Clients)

This section does not concern visitors to this website. It applies to organisations that have contracted a Neurohain system (VetFlow AI™, LeadFlow AI™, CoreFlow AI™ or a bespoke implementation).

Neurohain systems are installed in the client's own infrastructure: the client's server, the client's accounts, the client's API keys. End-customer data is not copied to, stored on, or processed on Neurohain's own systems.

To operate, monitor and update the system, Neurohain retains limited technical access to that infrastructure for as long as the service agreement is in force. Specifically:

  • Scope: the automation layer (n8n / workflows), monitoring and logs, and the technical configuration of the integrations. Access is limited to the minimum needed to keep the system running.
  • Named accounts: access is granted through individual, named accounts, never shared credentials.
  • Client control: the access is granted by the client and can be revoked by the client at any time, from its own administration, without depending on Neurohain.
  • Role: where this access involves personal data of the client's own customers, Neurohain acts as a processor under Art. 28 GDPR, on the client's documented instructions, under a data processing agreement (DPA / AVV) signed before go-live.
  • Termination: when the service agreement ends, Neurohain's access is revoked and the client's administrators remain the sole holders of the credentials.

The exact scope of access, the sub-processors involved and the retention periods are set out in the data processing agreement for each client.

Last updated: August 2026