Data Protection Policy
Last updated May 9th 2025
Neurameet Limited – Data Protection Policy
Related documents: Privacy Policy • Terms of Service • Security • Trust Centre
This Data Protection Policy outlines how Neurameet Limited complies with UK data protection laws and protects the personal data of schools and their staff. It is designed to inform our customers, staff, and data subjects about our commitment to data protection and our compliance obligations under the UK GDPR and the Data Protection Act 2018.
1. Purpose
This policy sets out how Neurameet Limited ("we", "our", "us") complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It explains the principles we follow, the responsibilities of our staff, and the measures we take to protect personal data.
2. Scope
This policy applies to all personal data processed by Neurameet in the course of providing our services, including:
- Customer account data
- Meeting recordings, transcripts, and minutes
- AI-generated outputs (summaries, reports)
- Support and billing information
It applies to all employees, contractors, and sub-processors acting on our behalf.
3. Confidentiality
Neurameet personnel who have access to customer information or data in the course of providing Services have agreed to maintain strict confidentiality in accordance with this policy and applicable data protection laws.
All Neurameet team members sign and comply with a Confidentiality and Data Protection Agreement, which requires them to:
- Maintain confidentiality of customer information.
- Not disclose data to unauthorised third parties.
- Comply with UK GDPR and the Data Protection Act 2018.
- Report suspected data breaches immediately.
- Protect information from unauthorised access, alteration, or destruction.
Schools can contact security@neurameet.co.uk to request evidence that Neurameet personnel are bound by these confidentiality obligations.
4. Data Protection Principles
We comply with the UK GDPR principles:
- Lawfulness, fairness and transparency – we process data lawfully and explain clearly how it is used.
- Purpose limitation – we only use personal data for the purposes agreed with the school.
- Data minimisation – we only collect the minimum data necessary to provide the service.
- Accuracy – we take reasonable steps to ensure data is accurate and up to date.
- Storage limitation – we only keep data for as long as necessary (see retention schedule).
- Integrity and confidentiality – we protect data using appropriate technical and organisational measures.
- Accountability – we can demonstrate compliance with these principles.
5. Roles and Responsibilities
- Schools (Customers) – act as the Data Controller, deciding what data is processed and why.
- Neurameet – acts as a Data Processor, processing data on behalf of schools.
- Data Protection Lead – responsibility within Neurameet for compliance, breach response, and staff training.
6. Lawful Basis for Processing
We process data on behalf of schools under the lawful bases determined by them (usually public task or legitimate interests). For our own business purposes (e.g. billing, marketing to staff users), we rely on consent or contract.
7. Children's Data
Neurameet is not used directly by children, but meetings may include information about pupils. Where this occurs, the school remains the controller. Neurameet processes this data only as required to provide the service and does not use it for any other purpose.
8. Data Security
We implement technical and organisational measures including:
- Encrypted transmission and storage of meeting data.
- Access controls and authentication.
- Regular security testing and monitoring.
- Staff confidentiality agreements and training.
9. Sub-processors
We use the following sub-processors:
- Akamai Technologies, Inc. (US): cloud computing and content delivery (data processed in UK data centres).
- OpenAI, L.L.C. (US): AI summarisation and report generation.
- Speechmatics Ltd (UK): speech-to-text transcription.
All sub-processors are bound by data processing agreements. Where data is transferred outside the UK, appropriate safeguards (e.g. SCCs with UK Addendum) are in place.
Sub-processor Change Notification
Where Neurameet intends to engage a new sub-processor or replace an existing sub-processor:
- Advance notice: At least ten (10) days before enabling a new sub-processor, we will notify schools and provide the sub-processor's name, location, and activities.
- Transfer details: The notice will include details of any international data transfers and appropriate safeguards (e.g. Standard Contractual Clauses).
- Right to object: Schools may object to a new sub-processor on reasonable grounds relating to data protection by notifying us in writing within ten (10) days of receiving notice.
- Essential sub-processors: Some sub-processors are essential to providing the Services. Objecting to an essential sub-processor may prevent Neurameet from offering that Service to the school.
- Resolution: If a school objects, we will attempt to provide a commercially reasonable alternative. If no alternative is available within a reasonable timeframe, the school may terminate the affected Service without penalty.
Schools can contact us at security@neurameet.co.uk to raise objections or request further details about any sub-processor change.
10. Data Retention
- Meeting recordings: deleted after 7 days.
- Transcripts and minutes: retained up to 2 years (or earlier on school request).
- AI-generated outputs: retained in line with transcripts/minutes.
- Account data: retained while account is active; deleted within 30 days of closure.
- Billing data: retained for 6 years.
- Support tickets: retained up to 2 years.
11. Data Subject Rights
Schools (as data controllers) have obligations to assist individuals exercising their rights under UK GDPR, including:
- Right of access (data export)
- Right to rectification (correction)
- Right to erasure (deletion)
- Right to restrict processing
- Right to object to processing
- Right to data portability
Submitting Data Subject Rights Requests
If an individual wishes to exercise any of their data protection rights, they should submit their request to their school (the data controller). Neurameet will support the school in fulfilling their obligations by:
- Exporting personal data in machine-readable format upon request.
- Deleting or restricting data processing as directed by the controller.
- Providing information needed to respond to the individual's request.
Schools can contact us at security@neurameet.co.uk to assist with data subject rights requests. We aim to respond to such requests within 5 working days.
Data Deletion Evidence
For audit and compliance purposes, schools can request a certificate of deletion confirming that their data has been permanently destroyed from our systems. We will provide this documentation within 5 working days of the deletion being completed. Please contact security@neurameet.co.uk to request deletion evidence.
Audits and Inspections
Under UK GDPR Article 28, schools have the right to audit Neurameet's data security procedures. Schools may request an audit or inspection of systems relevant to their data, subject to:
- Frequency: No more than one audit per calendar year.
- Notice: At least two weeks' prior written notice required.
- Timing: During UK business hours only.
- Scope: Restricted to systems and controls relevant to the school's data.
- Confidentiality: Conducted under a non-disclosure agreement.
- Cost: Schools bear all audit costs, including Neurameet staff time.
Alternatively, schools can request copies of Neurameet's security certifications and documentation via our Trust Centre at no cost. Contact security@neurameet.co.uk to arrange an audit.
12. Breach Management
In the event of a suspected or confirmed personal data breach, Neurameet will:
- Notify the school within 24 hours of discovery of any breach affecting their data.
- Provide initial details including nature of breach, data affected, and likely impact.
- Conduct a thorough investigation and provide a detailed incident report.
- Implement measures to prevent recurrence.
To report a security incident or suspected breach, contact: security@neurameet.co.uk
We maintain internal incident response procedures to investigate and remediate any breaches promptly.
13. Training and Awareness
All Neurameet staff receive training on data protection principles and their responsibilities under this policy.
14. Business Continuity and Data Protection
In the event of acquisition, merger, or dissolution of Neurameet Limited:
- Schools will be notified immediately of any such event.
- Schools will be given the opportunity to export and retrieve their data.
- If data is to be transferred to a successor organisation, schools will be informed in advance and have the right to request deletion instead.
- Any successor organisation must commit to equivalent data protection obligations under this policy.
- If Neurameet ceases operations and no successor assumes the data, all data will be securely deleted within 90 days.
15. Review
This policy is reviewed annually, or sooner if regulations or our practices change.
16. Data Processing Agreement (DPA)
Under UK GDPR Article 28, a Data Processing Agreement is required between Neurameet (as data processor) and your school (as data controller).
Our standard Data Processing Agreement is available as Schedule 1 of our Terms of Service. When you create an account or complete a paid subscription, you agree to our Terms of Service which incorporates this Data Processing Agreement. This agreement covers all processor obligations including data security, sub-processors, international transfers, and data subject rights support.
If your organisation requires a separate, formally executed DPA document for procurement or compliance purposes, please contact us at security@neurameet.co.uk and we will provide a signed standalone version.
Conflict and Precedence
In the event of any conflict between these documents, the following order of precedence applies:
- Standard Contractual Clauses (where applicable to international transfers)
- This Data Protection Policy
- The Terms of Service
Schedule 1 – Data Protection Impact Assessment (DPIA) Guidance
What is a DPIA?
A Data Protection Impact Assessment (DPIA) is a systematic process designed to identify and mitigate data protection risks associated with any new project or processing activity. As the data controller, schools are typically responsible for completing this assessment to ensure compliance with data protection regulations.
Neurameet has developed this guidance to support our educational partners in fulfilling their DPIA requirements under the UK General Data Protection Regulation (UK GDPR). This document provides detailed insights into how personal data is processed within our platform, alongside practical guidance for conducting your assessment.
This template can serve as either a complete foundation for your DPIA or as supplementary material to enhance your existing assessment framework. Schools may adapt this document to align with their specific circumstances and institutional requirements.
Using This DPIA Guidance
This guidance has been structured to align with ICO best practices and includes all essential elements required for a DPIA. Review each section carefully and adapt the content to reflect your school's specific context and data processing activities. Consult with your Data Protection Officer (if appointed) and relevant stakeholders when completing your assessment.
Download our complete DPIA template as a ready-to-use PDF document that you can customise for your requirements.
Download DPIA Template (PDF)Important Legal Notice
Neurameet cannot provide legal advice, and nothing in this document should be considered as such. This information does not replace the need to review guidance from the Information Commissioner's Office or to seek independent legal counsel where appropriate.