Data Processing Agreement

Terms under which NeuroGen processes personal data on behalf of business customers, in accordance with GDPR Article 28 and comparable data-protection laws.

Draft — pending legal review. This DPA is provided for review. A countersigned version is available to business customers on request and is the operative agreement. Do not rely on this page as an executed contract.

1. Roles & scope

For personal data you (the "Customer", acting as controller) submit to the NeuroGen service, NeuroGen ("we", acting as processor) processes that data only on your documented instructions, which include your use of the service and this Agreement. Where you act as a processor for your own customers, we act as your sub-processor on the same terms.

2. Subject matter, duration, nature & purpose

We process personal data for the duration of your subscription to provide the marketing, communications, AI, funnel, and analytics functionality of the service. The nature and purpose of processing is the operation of those features on your behalf.

3. Categories of data & data subjects

Data subjects include your contacts, leads, and end users. Categories may include identifiers (name, email, phone), marketing engagement data, content you submit to AI features, and any personal data contained in files or messages you process through the service.

4. Our obligations as processor

  • Process personal data only on your documented instructions, including for international transfers, unless required by law (in which case we notify you unless legally prohibited).
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Section 6).
  • Respect the conditions for engaging sub-processors (Section 5).
  • Assist you, taking into account the nature of processing, in responding to data-subject requests and in meeting your security, breach-notification, and data-protection-impact-assessment obligations.
  • At your choice, delete or return personal data at the end of the provision of services (Section 8).
  • Make available information necessary to demonstrate compliance and allow for and contribute to audits.

5. Sub-processors

You provide general authorization for us to engage the sub-processors listed at /subprocessors. We impose data-protection obligations on each sub-processor no less protective than those in this Agreement and remain liable for their performance. We will update the sub-processor list before adding or replacing a sub-processor; you may object on reasonable data-protection grounds as described there.

6. Security

We maintain measures including encryption in transit (TLS 1.3) and an encrypted secrets vault (AES-256-GCM), least-privilege access controls, field-level encryption of sensitive data, audit logging, and tenant isolation. Details are described on our Security page.

7. International transfers

Where processing involves transfer of personal data outside the EEA/UK — including to sub-processors in the United States and, for certain AI routing, to Zhipu AI in China — we rely on Standard Contractual Clauses and a transfer risk assessment. See /subprocessors for the cross-border disclosure.

8. Deletion & return

On termination, and on your request, we delete or return personal data processed on your behalf and delete existing copies unless retention is required by law. Account-level erasure is available through our in-product data-deletion flow, subject to a short grace period.

9. Personal-data breach

We notify you without undue delay after becoming aware of a personal-data breach affecting your data, and provide information reasonably necessary for you to meet your notification obligations.

Need a signed DPA for your organization?

Request one and we'll send a countersigned copy.

Request a DPA
Connecting