Last updated: July 20, 2026
This Privacy Policy explains how Neurasafe FZC LLC (“NeuraSafe”, “we”, “us”, or “our”) collects, uses, discloses, and protects your personal data when you visit neurasafe.io or use the NeuraSafe AI-assisted HSE (Health, Safety & Environment) Compliance Management Platform and related services (the “Services”).
We are committed to processing personal data lawfully, fairly, and transparently in line with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and, where applicable, the EU/UK General Data Protection Regulation (GDPR).
1. Who we are
Neurasafe FZC LLC is the controller responsible for your personal data. For privacy questions or to exercise your rights, contact us at support@neurasafe.io.
2. Scope
This policy applies to personal data we process about website visitors, prospective customers, account holders and their authorised users, and people who contact us through our website forms, email, WhatsApp, or social media channels. It does not cover third-party websites we link to but do not control.
3. Personal data we collect
- Account & identity data — name, work email, company name, job role, and login credentials.
- HSE content you provide — the documents, records, and inputs you upload or generate through the Platform. This may include information about your personnel where you choose to include it.
- Communications — messages you send us via contact forms, email, WhatsApp, or social media, including content and metadata.
- Billing data — subscription plan and transaction records (card details are handled by our payment processor, not stored by us).
- Usage & device data — pages visited, features used, IP address, browser type, and similar technical information.
- Cookies & similar technologies — see Section 9.
4. How we use your data
- To provide, operate, and maintain the Services and your account.
- To generate, draft, and manage HSE documentation at your request.
- To respond to enquiries and provide customer support.
- To process subscriptions and payments.
- To improve and secure the Services, prevent fraud, and maintain audit and access logs.
- To send service-related communications and, where permitted, updates you can opt out of.
- To comply with legal, regulatory, and audit obligations.
5. Automated and AI processing
The Platform uses artificial-intelligence models to help draft and analyse content. Inputs you provide may be processed by these models to produce outputs for you. We do not use your confidential HSE content to train third-party foundation models, and AI-assisted outputs support—not replace—your professional judgement. You remain responsible for reviewing and approving generated documentation before relying on it.
6. Legal bases for processing (GDPR)
Where GDPR applies, we rely on: performance of a contract; legitimate interests (to secure, improve, and support the Services); consent (for optional marketing and certain cookies, withdrawable at any time); and legal obligation.
7. How we share your data
We do not sell your personal data. We share it only with:
- Service providers (sub-processors) who process data on our behalf under contract — including cloud hosting, AI model providers, email delivery, and messaging platforms. A current sub-processor list is available on request.
- Professional advisers and authorities where required by law or valid legal process.
- Business transfers — in connection with a merger, acquisition, or reorganisation, subject to this policy.
8. International data transfers
Your data may be processed outside your country, including outside the UAE or EEA. Where we transfer data internationally, we use appropriate safeguards such as adequacy decisions or Standard Contractual Clauses as required by law.
9. Cookies
We use strictly necessary cookies to run the site and, with your consent where required, analytics cookies to understand usage. You can control cookies through your browser settings and any cookie banner we provide.
10. Data retention
We keep personal data only as long as necessary for the purposes above and to meet legal, tax, and audit obligations, then delete or anonymise it. Audit logs are retained in a tamper-evident form for the period required by our compliance controls.
11. Security
We apply audit-grade technical and organisational measures, including encryption in transit, least-privilege access controls, human approval of sensitive actions, and tamper-evident audit logging. No system is perfectly secure, but we work to protect your data and to notify you and the authorities of any breach as required by law.
12. Your rights
Subject to applicable law, you may have the right to access, correct, delete, or restrict processing of your personal data; to object; to data portability; and to withdraw consent. Under the UAE PDPL and GDPR you may also lodge a complaint with the competent authority. To exercise any right, contact support@neurasafe.io.
13. Children
The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from children.
14. Changes to this policy
We may update this policy from time to time. We will post the updated version here and revise the “Last updated” date. Material changes will be communicated where appropriate.
15. Contact us
Neurasafe FZC LLC
Email: support@neurasafe.io



