Effective and last updated September 12, 2026
1. Who we are and what this policy covers
The Neurovirtual legal entity identified in your Organization's executed order or written research agreement provides its Cloud service. That entity must be identified before service access is provided. Contact info@neurovirtual.com for its identity and contact details, or to identify the entity responsible for an account, website, or support interaction. References in this policy to "Neurovirtual," "we," "us," or "our" refer to the responsible entity. This policy describes personal information used to operate Neurovirtual Cloud, its public website, and connected services.
2. Our role and your organization's role
We manage account, security, service administration, and support information for our own operational purposes. Your clinic, laboratory, or other organization determines why patient and study information is entered into Neurovirtual Cloud and who may use it. We process that information to provide the service under the organization's instructions and applicable agreements. Ask your organization about its patient privacy notice and the legal basis for its use of patient information. This policy does not replace that notice, a data processing agreement, a Business Associate Agreement (BAA), or research consent.
3. Information we handle
Account and access information includes names, email addresses, organization and site memberships, roles, password hashes, authentication credentials, security settings, and records of terms acceptance. Service content may include patient identifiers and demographics, physiological recordings, study details, annotations, scores, reports, schedules, referrals, and equipment records supplied by authorized users or connected devices. Technical information includes access and activity logs, IP addresses, browser or device information, timestamps, and diagnostic information. Support information includes requests, feedback, and any attachments you choose to provide. Information comes from you, your organization, authorized colleagues, connected devices, and operation of the service.
4. How we use information
We use information to create and authenticate accounts; enforce organization and site permissions; store, display, transfer, and process studies; provide requested workflows and reports; maintain security and audit records; troubleshoot problems; respond to support requests; and meet applicable contractual and legal duties.
Under Section 7.5 of the Terms of Use, we may also use properly de-identified or, where required, anonymized uploaded content and derived data for research, statistical analysis, and the development, training, testing, validation, benchmarking, and improvement of algorithms, models, products, and services. This can include information from recordings, study details, annotations, scores, reports, and associated metadata. We may commercialize resulting products and improvements and publish findings that do not identify individuals or disclose your organization's confidential information. Affiliates and contractors may perform this work on our behalf under equivalent confidentiality, security, and no-re-identification obligations.
These uses begin only after acceptance of the revised Terms and satisfaction of applicable legal and contractual requirements. Preparing de-identified data must itself be lawful and authorized, including under any required BAA or data processing agreement. We must not attempt to re-identify individuals. Replacing names with codes or aggregating records does not by itself meet the required standard. Acceptance of the Terms is not blanket consent to process personal information, authorize secondary use of identifiable health information, or enroll someone in research; any required notices, consents, and approvals remain necessary.
5. Legal bases where applicable
Where data protection law requires a legal basis, account and service administration may rely on performance of a contract, legal obligations, or legitimate interests in operating and securing the service, subject to the protections required by law. Where consent is required for a distinct optional purpose, it must be requested separately and may be withdrawn for future processing. Your organization is responsible for establishing the necessary legal basis and any additional condition for processing health information. A contract or acceptance of these terms alone does not authorize all processing of health information.
6. Who can receive information
Authorized members of your organization receive information according to their permissions. Railway provides hosting infrastructure for the current hosted service. Other service providers may process information needed for storage, delivery of service emails, security, maintenance, or support under appropriate instructions and agreements. Your Organization can request the applicable provider list, processing locations, and transfer safeguards through the contact in Section 14 before supplying personal information. We may disclose information when legally required, to address security threats or protect legal rights, or in a business transfer subject to applicable safeguards. Organization administrators control invitations and access; avoid including unnecessary patient information in support requests.
7. Health information and research
Do not upload HIPAA-regulated protected health information unless Neurovirtual has expressly confirmed that the deployment is enabled for that use and the required customer and downstream BAAs and safeguards are in place. Otherwise, use data appropriately de-identified under applicable law. Research use alone does not remove privacy duties. Replacing names with codes may leave information identifiable; recordings, dates, metadata, and attachments also require review before upload. Your organization is responsible for required patient notices, research approvals, and consents. No statement in this policy represents that an investigational feature is cleared or approved for clinical use.
8. Storage locations and international transfers
Storage and processing locations depend on the deployment and its service providers. Before using a deployment, your organization should confirm its hosting locations and any cross-border access. Where international-transfer restrictions apply, the relevant transfer mechanism and safeguards must be documented in the applicable service or data processing agreement.
9. Retention and deletion
Retention depends on the type of information, the organization's instructions, the service agreement, and applicable legal obligations. Relevant criteria include the period of active service, clinical recordkeeping duties, security and audit needs, dispute resolution, and backup expiry. Account closure does not necessarily erase records your organization must retain. Your organization can request available export and deletion arrangements. Data and results used under Section 7.5 of the Terms may be retained after account closure only while they remain lawfully de-identified or anonymized and retention is permitted by applicable law and controlling agreements. This does not override mandatory deletion rights or permit indefinite retention of identifiable source records for those purposes.
10. Security and your responsibilities
Neurovirtual Cloud uses access controls and authenticated sessions to limit access. Security also depends on deployment configuration, organizational permissions, and user practices. Protect your credentials, use available account security features, share information only with authorized people, and report suspected unauthorized access promptly. No system can guarantee absolute security. Neurovirtual Cloud has not completed its own SOC 2 Type II examination. A hosting provider’s assurance report or HIPAA arrangement does not certify Neurovirtual or automatically establish compliance for the service. We remain responsible for the security and privacy duties that apply to our activities.
11. Cookies and device storage
Neurovirtual Cloud uses session cookies to authenticate requests and renew signed-in sessions. Choosing to stay signed in can extend cookie persistence. Browser storage also supports session coordination, language and appearance preferences, and local application state. When enabled, local recording caches can store study data on your device; use trusted devices and your organization's security procedures. The public website may send your IP address to ipwho.is to select a regional language when you have not selected one; it temporarily stores the language result in your browser. Pages that load Google Fonts also send the request information, including an IP address, to Google. Choosing a demo booking link may open the external scheduling service identified by that link. These functions are separate from advertising or cross-site tracking. The application does not include advertising or third-party analytics trackers. If optional tracking is introduced, we will provide the disclosures and choices required by applicable law before activating it.
12. Your rights and choices
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to processing of, or obtain a portable copy of your information, withdraw consent where processing relies on consent, and complain to a supervisory authority. These rights have limits and may require identity verification. For patient or study records controlled by your organization, contact that organization first; we will assist it as required by our agreements and law. For account, service administration, or support information, contact Neurovirtual through the contact channels in Section 14.
13. Age and automated outputs
Neurovirtual Cloud accounts are intended for adult professional and institutional users. Organizations may process records about younger patients only with the necessary authority and safeguards. Automated study outputs support the functions described in the Terms of Use; organizations remain responsible for lawful use, required oversight, and any additional notices about automated processing.
14. Changes and contact
We will update the date above and provide notice of material changes through the application or other appropriate channels. New processing requiring consent will require a separate choice; continued use or terms acceptance does not replace that consent. Send privacy requests, questions, or complaints to info@neurovirtual.com and identify your Organization and country so we can direct the request to the responsible Neurovirtual entity. Describe the right you wish to exercise; we may request proportionate information to verify your identity and locate the records. Report suspected security incidents to support@neurovirtual.com. Do not include patient records or other sensitive information in an initial email. These channels do not limit your right to complain to the competent data-protection authority.
