Effective Date: 5 June 2026
Download Data Privacy Policy v1.1 (PDF)
Neural Defend Private Limited (Neural Defend), accessible at www.neuraldefend.com, protects the privacy of individuals who interact with our websites, applications, Atlas APIs, and related services. This Privacy Policy explains how personal data is collected, used, stored, and safeguarded, and what rights data subjects have.
This policy is aligned with the Digital Personal Data Protection Act 2023 (India), EU GDPR, UAE PDPL 2021, and ISO/IEC 27701:2019, and corresponds to our official Data Privacy Policy v1.1.
1. Scope
This policy applies to all personal data collected through Neural Defend's websites, applications, services, Atlas APIs, and other interactions with individuals.
2. Definitions
- Personal Data — information relating to an identified or identifiable individual.
- Processing — any operation on personal data (collection, storage, use, disclosure, deletion).
- Data Controller — entity determining purposes and means of processing.
- Data Processor — entity processing data on behalf of a controller.
- DPO — Data Protection Officer (held by the CDO/CISO).
- Biometric Data — facial images and embeddings processed by Atlas; treated as sensitive personal data.
3. Data We Collect
- Identification: name, email, phone, address, date of birth.
- Account: username, hashed password, preferences.
- Financial: payment metadata, billing address (payment processing handled by a PCI-DSS compliant gateway).
- Technical: IP address, device identifiers, operating system, cookies, usage analytics.
- Biometric (Atlas): face images submitted by clients for deepfake detection. Processed in-memory only; not persisted (data-minimisation by design).
- Sensitive Personal Data: only with explicit consent or legal basis.
4. Atlas Client Content — Zero Retention
Neural Defend's Atlas service processes client-submitted content (images, video, audio, and any other media) strictly in-memory and on-the-fly for the sole purpose of generating a detection prediction. The submitted content is never written to persistent storage (no disk, no database, no object store, no backup, no log, no archive) and is discarded from memory immediately after the prediction is returned to the client.
We retain only the following non-content metadata for billing, audit, and service-improvement purposes:
- Request ID and timestamp.
- Authenticated client / tenant ID.
- Inference outcome (confidence score / classification label).
- Resource consumption metrics (request size in bytes, duration, HTTP status code).
- Source IP and User-Agent (security telemetry).
No content reconstruction is possible from the metadata. No client-submitted face images or media are transmitted to any external AI service or third-party generative AI provider.
5. How We Collect Data
- Directly from individuals (forms, accounts, support).
- Automatically via cookies, analytics, and logs.
- From clients (B2B integrations) where individuals are end-users of client services.
For details on cookies, see our Cookie Policy.
6. Legal Bases for Processing
- Consent — explicit consent for marketing or biometric processing where applicable.
- Contractual Necessity — fulfilling a contract with the data subject or our client.
- Legal Obligation — compliance with laws and regulators.
- Legitimate Interests — fraud prevention, security, and service improvement.
7. How We Use Personal Data
- Provide and improve Atlas and related services.
- Process transactions and manage accounts.
- Communicate updates, offers, and support.
- Conduct analytics and research (using de-identified data where possible).
- Ensure security, detect fraud, and comply with legal obligations.
8. Data Sharing & Disclosure
- Service providers and sub-processors under contractual privacy and security terms.
- Legal compliance — to respond to lawful requests, subpoenas, or court orders.
- Business transfers — in case of merger or acquisition (with continuity of protections).
- With consent — when the individual explicitly agrees.
9. Data Retention
Personal data is retained only as long as necessary for the purposes collected, unless a longer retention period is required by law.
10. Data Security
- Encryption at rest (Azure Storage / SQL TDE) and in transit (TLS 1.2+).
- Identity and access controls via Microsoft Entra ID; MFA mandatory.
- Regular vulnerability scanning, audits, and security assessments.
- Logging and monitoring via Azure Monitor and Microsoft Sentinel.
- Data residency — production data resides in Azure Central India; DR in Azure South India.
11. Your Data-Subject Rights
Depending on jurisdiction, you may exercise the following rights by contacting our DPO at sumit@neuraldefend.com:
- Access — request access to data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten").
- Data Portability — receive your data in a portable format.
- Restriction — limit processing.
- Objection — object to certain processing (e.g., direct marketing).
- Withdraw Consent — where processing is consent-based.
12. Cookies & Tracking
Cookies and similar technologies enhance your experience on our Site. Preferences are manageable via the cookie banner or browser settings. See our Cookie Policy for full details.
13. Children's Privacy
Neural Defend does not knowingly collect personal data from children under 18. If such data is identified, it is deleted promptly.
14. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for their privacy practices.
15. International Transfers
Where personal data is transferred outside the country of collection, appropriate safeguards are applied (Standard Contractual Clauses, adequacy decisions, or explicit consent). On-premise / sovereign deployment is offered for clients with strict data-residency obligations (e.g., UAE PDPL).
16. Policy Updates
This policy is reviewed annually or when laws, regulations, or business practices materially change. Material changes are notified to data subjects.
17. Contact Us
Neural Defend Private Limited
CIN: U63999DL2024PTC429114
Registered Office: 00/5 G/F Jai Bihar Block-F-2, Baprola, South West Delhi, Delhi 110043, India
Data Protection Officer: sumit@neuraldefend.com
General Support: support@neuraldefend.com