1. Preamble and Commitment
At Neodustria.com, we uphold a stringent commitment to the privacy, confidentiality, and security of data pertaining to our clients and users. This comprehensive Privacy Policy sets forth the methods by which we procure, process, and safeguard personal and industrial information, ensuring full adherence to the General Data Protection Regulation (GDPR) (EU 2016/679), the EU AI Act, and all relevant global data protection statutes and jurisdictions.
2. Data Procurement and Lawful Basis for Processing
Neodustria collects and processes specific categories of data strictly limited to the necessity of delivering, maintaining, and improving the proprietary platform services.
- Account & Identity Data
Specific Data Elements:Name, email address, corporate affiliation, professional role, geographical region.
Lawful Basis / Purpose of Processing:Contractual Necessity for service provision, communication, and support. - Usage & Activity Data
Specific Data Elements:Logs of platform activity, simulation queries, module utilization statistics.
Lawful Basis / Purpose of Processing:Legitimate Interest for platform optimization, performance diagnostics, and continuous service improvement. - Financial & Billing Data
Specific Data Elements:Subscription tier, detailed invoices, and status of payments.
Lawful Basis / Purpose of Processing:Compliance with Legal Obligations for financial record-keeping and contract execution. - Technical & Diagnostic Data
Specific Data Elements:Browser information, IP address, device type, network diagnostics.
Lawful Basis / Purpose of Processing:Legitimate Interest for system maintenance, security audit, and mitigating service disruption.
Data Disclosure Prohibition:We affirm that user data shall not be sold, rented, or leased to third parties. All processing activities are solely dedicated to platform functionality, billing integrity, regulatory compliance, and client support.
3. Data Integrity and Security Measures
All client data is subject to rigorous security protocols:
- Data Location & Certification:Data is secured within ISO 27001-certified data centers situated exclusively within the European Union.
- Encryption Standards:We enforce AES-256 encryption for data at rest and TLS 1.3 encryption protocols for data transmitted over networks.
- Access Control:Access to sensitive customer data is governed by role-based access control (RBAC), mandatory Multi-Factor Authentication (MFA), and comprehensive audit logging.
- Security Validation:System integrity is validated through regularly scheduled penetration testing and independent security audits.
4. Cookies and Analytical Technologies
Neodustria.com utilizes cookies and analogous technologies for enhancing user experience and conducting operational analysis:
- Essential Cookies:Deployed strictly to ensure secure login functionality and persistent session integrity.
- Analytics Cookies:Utilized to facilitate performance improvement and optimize the User Experience (UX).
Users retain the right to manage and customize their cookie preferences via the conspicuous cookie consent banner presented upon accessing the domain.
5. Data Sharing, Processors, and Legal Compliance
Data sharing with external entities is restricted to instances necessary for service fulfillment or required by law:
- Cloud Processors:We engage third-party cloud processors (e.g., for data hosting, billing infrastructure) exclusively under fully executed Data Processing Addendums (DPAs).
- Internal Data Use:Usage data may be shared internally for the refinement of proprietary AI models, provided the data is fully anonymized prior to processing.
- Lawful Disclosure:We shall respond to substantiated, lawful data access requests from governmental or regulatory authorities, strictly in compliance with all relevant provisions of the GDPR.
6. Data Subject Rights
Pursuant to the GDPR and obligations established by the EU AI Act, data subjects possess the following rights, exercisable via written request:
- Right of Access:The entitlement to obtain confirmation and a legible copy of all personal data undergoing processing.
- Right to Rectification:The right to obtain the correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"):The right to request the deletion of personal data under specific statutory conditions.
- Right to Object:The right to opt out of processing for direct marketing purposes or specific forms of analytics.
- Right to Data Portability:The right to receive personal data in a structured, commonly used, and machine-readable format.
To formally exercise any of these rights, please submit your request to the contact details provided in Section 10.
7. AI Systems and Automated Decision-Making
Neodustria’s Artificial Intelligence (AI) modules are explicitly designed to augment and support human professional judgment and shall not be deployed to replace final human oversight.
- Prohibition:We do not engage in personal profiling or automated decision-making that yields legal effects or similarly significant consequences for the data subject.
- EU AI Act Obligations:We adhere to the transparency, documentation, and human oversight requirements applicable to high-risk AI systems.
8. Data Retention Protocol
Data retention periods are governed by the principle of data minimization:
- Client Data:Client data is retained for the duration of the active service subscription, followed by a six (6) month grace period for account recovery purposes.
- Logs and Analytics:System logs and aggregated performance analytics are retained for twelve (12) months, after which they are subject to full aggregation.
- Account Deletion:Formal deletion requests trigger the immediate erasure of data in full compliance with the statutory principles of data minimization.
9. Regulatory Compliance and Certifications
This policy and our operational architecture adhere to the following key standards:
- GDPR (EU 2016/679):Full adherence to all requirements concerning the processing of personal data and data subject rights.
- EU AI Act:Ongoing implementation of obligations pertaining to responsible development and deployment of industrial AI systems.
- ISO 27001:Application of certified information security management practices across the platform and infrastructure.
10. Official Contact Information
For all inquiries pertaining to this Privacy Policy, data subject rights, or compliance matters, please contact our designated Data Protection Officer:
- Email:info@neodustria.com