This Privacy Policy describes how Atlasiops Technologies Private Limited, a company incorporated in India with its registered office at 512, Zion Prime, 5th Floor, Near Four Pole Structure, Thaltej, Ahmedabad, Gujarat – 380059 (“Atlasiops”, “we”, “us”), collects, uses, shares, and protects personal data when you visit our websites (including atlasiops.com and nuroen.ai), register for content or events, or use the Nuroen AI platform and related services (together, the “Services”). It also describes your rights and how to exercise them.
Personal Data We Collect
Information you provide
Name, work email, phone number, company, and role when you create an account, request a demo or trial, register for a webinar or event, subscribe to communications, apply for a job, or contact us; billing and transaction details when you purchase (payment card details are processed by our payment processors, not stored by us); and content you submit to the Services, such as prompts, files, knowledge-base content, and agent configurations (“Customer Content”).
Information collected automatically
Usage and device data when you use the websites or Services — IP address, browser and device type, pages viewed, features used, timestamps, and approximate (city-level) location derived from IP — collected through logs and cookies and similar technologies (see Section 9).
Information from other sources
Data from single sign-on providers you choose to use, from resellers and partners through whom you purchase, from your organisation when it provisions your account, and from publicly available business sources used to keep our records accurate.
How We Use Personal Data
We use personal data to: provide, operate, secure, and support the Services; create and administer accounts; process payments and maintain records; respond to enquiries and provide customer support; send service communications (such as security, billing, and change notices); send marketing communications you can opt out of at any time; understand how the Services are used, through aggregated and anonymised statistics, in order to improve them; detect, prevent, and investigate fraud, abuse, and security incidents; and comply with legal obligations. We do not use Customer Content to train or improve machine-learning models without express consent or opt-in, and we do not sell personal data.
Legal Bases
Where laws such as the EU/UK GDPR apply, we process personal data on these bases: performance of a contract (providing the Services you or your organisation signed up for); legitimate interests (securing and improving the Services, business-to-business marketing, and managing our business), balanced against your rights; consent (where required — for example, certain cookies and marketing — which you may withdraw at any time); and compliance with legal obligations. Under India’s Digital Personal Data Protection Act, 2023, we process personal data on the basis of your consent or for legitimate uses recognised by that Act.
International Transfers
We are based in India and use cloud infrastructure that may store or process data in other countries, including the United States and Europe. Where personal data protected by the GDPR or similar laws is transferred internationally, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and equivalent mechanisms, together with technical and organisational protections. Enterprise customers may have region-specific hosting or self-hosted deployment options under their agreements.
Retention
We retain personal data for as long as needed for the purposes described in this Policy: for the life of your account plus a reasonable period thereafter; for Customer Content, as described in the applicable service agreement (with export and deletion on termination); and longer only where required for legal, tax, accounting, or dispute-resolution purposes. When retention is no longer justified, we delete or anonymise the data, or, where that is not immediately practicable (for example, in backups), we isolate it from further processing until deletion is possible.
Security
We maintain administrative, technical, and organisational measures designed to protect personal data — including encryption in transit, access controls, logging, and monitoring — aligned with recognised industry frameworks, and we test and review these measures periodically. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; we will notify affected customers and authorities of personal-data breaches as required by applicable law.
Your Rights
Subject to applicable law, you may: access the personal data we hold about you and request a copy; correct inaccurate or incomplete data; request deletion; object to or request restriction of processing; receive your data in a portable format; withdraw consent at any time (without affecting prior processing); nominate, under Indian law, another individual to exercise your rights in the event of death or incapacity; and complain to a supervisory authority — including, in India, the Data Protection Board of India, or in the EU/UK, your national data protection authority. To exercise rights, contact us as described in Section 12; we will respond within the time required by applicable law (and in any case within 30 days where feasible). We may need to verify your identity before acting on a request. Opting out of marketing is available in every marketing email or by writing to us; you will still receive service communications.
Children
The Services are intended for business and professional use and are not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.
Notice to End Users of Our Customers
If you use the Nuroen platform through your employer or another organisation, or interact with an AI agent operated by one of our customers, that organisation controls the personal data processed through the platform and its privacy notices apply. Please direct privacy requests to that organisation; we will refer requests we receive to it and support its response as its processor.
Contact and Grievance Officer
Questions, requests, and complaints: privacy@nuroen.ai, or by post to Atlasiops Technologies Private Limited (512, Zion Prime, 5th Floor, Near Four Pole Structure, Thaltej, Ahmedabad, Gujarat – 380059). In accordance with Indian law, our Grievance Officer is reachable at privacy@nuroen.ai; we will acknowledge grievances promptly and resolve them within the timelines required by applicable law.
Region-Specific Notices
California (CCPA/CPRA)
In the preceding 12 months we have collected the categories of personal information described in Section 1 (identifiers, commercial information, internet activity, approximate geolocation, professional information, and inferences drawn for service improvement), for the purposes in Section 2, sharing them as described in Section 4. We do not sell personal information or share it for cross-context behavioural advertising. California residents may exercise the rights to know, access, correct, delete, and non-discrimination by contacting privacy@nuroen.ai; authorised agents may submit requests with proof of authorisation.
EU / UK
The controller for data covered by this Policy is Atlasiops Technologies Private Limited. You may lodge a complaint with your local supervisory authority, though we would welcome the chance to address concerns first.
Changes to This Policy
We may update this Policy from time to time. The “Last updated” date shows the current version; material changes will be notified on the websites or by email before they take effect. Your continued use of the Services after changes take effect constitutes acknowledgement of the updated Policy.