This document is a courtesy translation. In the event of any discrepancy, inconsistency, or conflict between this translated version and the original Spanish version, the Spanish version shall prevail and be legally binding.
Who is the Data Controller of your personal data?
NeuronUP, S.L., with Spanish VAT Number (NIF) B-26479725 and registered office at Piqueras Street, No. 31, 5th floor, Logroño (La Rioja, Spain), is the Data Controller for the personal data collected through this website and the NeuronUP platform.
DPO contact details: [email protected].
For what purposes do we process your personal data?
At NeuronUP, we process the information provided by the data subject for the following purposes:
- To address and respond to requests exercising the rights set forth in the GDPR.
- To record and manage incidents related to data protection and information security.
- To manage the contractual relationship established with partners, administrators, clients, suppliers, students, teachers, collaborators, and employees.
- To identify and contact potential clients and/or students to offer products or services based on a public professional profile, using both human agents and virtual assistants.
- To record incoming and outgoing telephone calls for quality control, incident management and resolution, and security purposes.
- To manage and process registration forms for contests, sweepstakes, fairs, and events, as well as to send commercial mailings and newsletters.
- To send communications regarding significant changes and modifications that may affect our products or services.
- To manage and monitor training activities organized for professionals, as well as webinars.
- To conduct surveys to measure user satisfaction levels.
- To evaluate job applications in the event we receive a CV/resume.
- To recognize user sessions and the acceptance of policies regarding first-party cookies.
- To measure web traffic and count visits regarding third-party cookies.
- To ensure security and access control to our facilities through video surveillance and photo detectors.
- To manage the data of individuals who report serious or very serious criminal or administrative offenses through the whistleblowing channel.
- To conduct clinical studies on the performance of the tool with real patients.
- To verify the proper functioning of the platform through usability testing.
- To manage the data of users participating in usability tests conducted by the entity to improve the user experience.
- To extract and duplicate data from the original source in order to guarantee and preserve the integrity, availability, and continuity of our information systems.
How do we obtain your personal data?
The data processed by NeuronUP is, generally, provided by the data subject themselves or their legal representative. In some cases, we may legitimately obtain it from publicly accessible sources.
Lawful basis for processing
- Compliance with a legal obligation (GDPR and applicable national data protection laws) regarding the response to requests exercising the rights set forth in the GDPR, as well as the recording and management of incidents related to data protection and information security.
- Performance of a contract in the case of partners, administrators, suppliers, collaborators, employees, students, teachers, winners of contests and promotions, call recordings, execution of backups, and for compliance with BAAs required under HIPAA regulations by US clients.
- Legitimate interest in identifying and contacting potential students and/or clients, in accordance with the GDPR and applicable national data protection laws.
- Legitimate interest for call recording in order to guarantee the quality of the service and for security reasons.
- Consent of the data subject for managing and processing registration forms for contests and sweepstakes, fairs and events, sending commercial mailings and newsletters, as well as contact via WhatsApp through human agents and/or virtual assistants, attendance at NeuronUP Academy and webinars, installation of analytical and/or advertising cookies, and conducting satisfaction surveys and usability tests.
- Legitimate interest for sending communications regarding significant changes and modifications that may affect our products or services, for the installation of technical and/or necessary cookies, and to prevent unauthorized access to our facilities.
- Application of pre-contractual measures at the data subject’s request in the event we receive a CV/resume for a specific recruitment process, and consent of the data subject to retain their data in our talent pool for future vacancies.
- Compliance with Spanish Law 2/2023, of February 20, regarding the whistleblowing channel.
- Patient consent for conducting clinical studies, protected under Article 9(2)(a) of the GDPR.
- Public interest in scientific research for conducting clinical studies on neurodegenerative diseases.
Data processing using Artificial Intelligence systems
We may use AI systems to provide automated assistance through virtual assistants, to generate certain content, or to optimize internal processes. On some occasions, the use of AI may involve the processing of personal data strictly necessary to provide such functionalities.
When the provision of these tools requires third-party technology, NeuronUP guarantees its use within private environments or under enterprise licenses, ensuring that the processed personal data is not used to train public language models.
The NeuronUP Academy training platform integrates AI tools designed to optimize learning and facilitate information retrieval. Students have the right to know that they are interacting with an AI, to request human oversight for decisions that significantly affect them, and to ensure their data is not used to train external models without their explicit consent. AI systems are support tools and may yield inaccurate results; therefore, they do not replace the critical judgment of the professional.
The lawful basis for processing this data will be the performance of a contract or legitimate interest, without prejudice to cases where obtaining consent is required. Users will be informed at all times that they are interacting with an AI system, especially if the interaction is not obvious.
The AI systems employed will be subject to human control and oversight. No automated decisions producing legal or significant effects will be made.
How long will we keep your data?
As a general rule, we will retain your data for the time necessary to fulfill the purposes described, and we will keep it during the statutory limitation periods for legal liabilities. Once this period has elapsed, the data will be kept blocked and will subsequently be deleted. If there are any ongoing claims, audits, or proceedings, these periods may be extended until their resolution.
In the specific case of job applications, CVs/resumes will be deleted within a maximum period of 1 year after the end of the recruitment process, or 2 years if the candidate has expressly consented to their inclusion in our talent pool.
To whom may we disclose your data?
NeuronUP does not transfer personal data to third parties without the data subject’s consent, unless it is necessary for the provision of the service or due to a legal obligation.
We use service providers who perform services on our behalf or help us provide a better service to you, such as communications, payment processing, etc. We do not authorize these providers to use or disclose your personal data, except in connection with the provision of their services (which may include maintaining and improving such services). Our service providers may process your personal data for the following purposes: hosting, maintenance, email, consulting, form creation, payment gateways, marketing campaigns, CRM, etc.
Training services are provided through the eLysa LCMS technological platform, owned by ADR Infor, S.L., made available to NeuronUP under a SaaS model.
At NeuronUP, we adopt the appropriate mechanisms and safeguards for the protection of your personal data. Furthermore, the personal data of the end user or patient remains on NeuronUP’s Google Cloud Platform servers, located in Europe. You can obtain more information about the processing of end user or patient data in Annex I: DPA.
International data transfers
For the proper functioning of our platform, we use services from providers located outside the European Economic Area (EEA) and the UK that are certified under the EU-U.S. Data Privacy Framework (and its UK Extension), or that provide appropriate safeguards such as the Standard Contractual Clauses (SCCs) adopted by the European Commission (along with the UK Addendum where applicable) for data processing activities to which the GDPR or UK GDPR applies.
The services used, whose privacy policies you may consult, are as follows:
- Intercom R&D Unlimited Company: https://www.intercom.com/legal/privacy. Purpose: chat and communication service for clients and professionals.
- Google LLC: https://www.google.es/intl/es/policies/privacy. Purpose: Google Analytics.
- Meta Platforms, Inc:
- Facebook: https://www.facebook.com/privacy/policy. Purpose: to measure advertising effectiveness.
- WhatsApp: https://www.whatsapp.com/legal/privacy-policy-eea#privacy-policy-eea. Purpose: contact.
What are your rights?
Anyone has the right to obtain confirmation as to whether NeuronUP is processing personal data concerning them:
- Right of access: The data subject may request the Data Controller to disclose the data being processed and, if applicable, the specific personal data involved.
- Right to rectification: The data subject may request the Data Controller to correct their personal data if it is inaccurate.
- Right to erasure (Right to be forgotten): The data subject may request the Data Controller to delete their personal data when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
- Right to object: The data subject may object to the Data Controller processing their personal data.
- Right to restriction of processing: The data subject may request the Data Controller to temporarily restrict the processing of their personal data in specific situations.
- Right to data portability: The data subject may request their automated data from the Data Controller in a structured, commonly used, and machine-readable format.
The data subject may withdraw their granted consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
You may exercise these rights using the postal and email addresses indicated in this document.
If you consider that the processing of your personal data violates data protection regulations, you may lodge a complaint with the NeuronUP DPO ([email protected]) or with the Spanish Data Protection Agency (*Agencia Española de Protección de Datos – AEPD*), through its postal address: Calle Jorge Juan, 6, 28001 Madrid (Spain), or through its electronic headquarters on the website www.aepd.es.
Additional rights for United States residents (CCPA/CPRA and applicable state laws)
If you reside in California or other U.S. states with applicable privacy laws, in addition to the rights outlined above, you are granted the following specific rights:
- Right to opt-out of the sale or sharing of personal data: NeuronUP does not sell your personal data. However, you have the right to direct us not to sell or share your personal information for cross-context behavioral advertising purposes.
- Right to non-discrimination: We will not discriminate against you (e.g., by denying services or charging different prices) for exercising any of your privacy rights.
- Right to limit the use of sensitive personal information: You have the right to request that we limit the use and disclosure of your sensitive personal information to that which is strictly necessary to perform our services.
Health data and exceptional circumstances
In the event of requesting a deferral of enrollment in NeuronUP Academy for health reasons, the student must provide official supporting documentation, expressly omitting or redacting any data related to their clinical diagnosis or medical history. NeuronUP will destroy said documents immediately after resolving the request.
Image authorization in recorded sessions
By participating in live sessions of NeuronUP Academy, the data subject authorizes NeuronUP to capture and reproduce their image and voice for educational and archival purposes. These recordings may be viewed by other students in the same or subsequent editions. This authorization is voluntary: if the student does not wish to be recorded, they must keep their camera and microphone disabled, participating through the written chat.
Telephone call recording
Telephone calls held with NeuronUP may be recorded for the purpose of guaranteeing service quality, for security reasons, and for the proper follow-up of the commercial relationship or technical support. These recordings will be retained for the time strictly necessary to fulfill these purposes or for the establishment, exercise, or defense of legal claims, after which they will be securely deleted.
Data processing through instant messaging channels
At NeuronUP, we use automated channels (web chat and WhatsApp) to manage user inquiries, provide support, and send personalized commercial information, operated by human agents and virtual assistants. Through these channels, we process your telephone number, profile name, email address, and conversation history.
The lawful basis for this processing is the user’s explicit consent, granted by checking the corresponding box on the website or by voluntarily initiating the chat and accepting the virtual assistant’s legal greeting.
The use of WhatsApp implies that the user accepts its terms and policies. The service utilizes Cloud infrastructure covered under the secure EU-U.S. Data Privacy Framework.
The data collected is integrated through automations into our management system, guaranteeing its processing under strict confidentiality agreements.
Security measures
NeuronUP is certified in ISO/IEC 27001:2022, complying with all the requirements necessary to maintain this standard, with the main objective of ensuring the confidentiality, integrity, and availability of information. In addition to the aforementioned obligations, the Data Controller complies with all the technical and organizational security measures required by the GDPR and applicable national data protection laws.
Acting as a Data Processor
In those cases where NeuronUP must access and/or process personal data whose responsibility and ownership belong to its clients, acting as a Data Processor in accordance with current regulations, it commits to meticulously regulating the content of the DPA.
Date of last update: 31 August 2026