NeuroBridge® Portal Privacy Policy
Effective Date: 2 May 2026
Version: 4.2.1
At NeuroBridge®, we take data protection seriously. This Privacy Policy explains how we collect, use, share and safeguard personal data when you use our Portal available at neurobridgeportal.com (the “System”) in accordance with applicable legislation, including the UK General Data Protection Regulation (UK GDPR).
If you are visiting our marketing or e-commerce website at neurobridge.co.uk, please see our separate Website Privacy Policy.
This Privacy Policy works in conjunction with our Terms of Service, End-User Licence Agreement, and other documents, as laid out in Section §11.
1. Who We Are
NeuroBridge® Limited is a UK-registered company (Company No. 14895457), operating as the data controller when we determine the purpose and manner of data processing for our System.
Our registered address is:
Suite 46, 24–28 St. Leonards Road, Windsor, Berkshire, SL4 3BB, United Kingdom
Email: [email protected]
We act as an independent data controller. We do not process data on behalf of a user’s employer. An employer acts only as financial sponsor for their employee’s private access to the System. Employers receive only privacy‑protecting anonymised aggregates, never user‑level personal data.
2. What Information We Collect
When you interact with the NeuroBridge® System, we collect certain personal data to provide you with access and ensure proper functioning of the service.
- Personal Information: Name, email address (your company email), country of residence, whether you have direct reports (as a team leader, supervisor or manager in your organisation), and any other personal details you choose to provide.
- Account Information: Login credentials (username, hashed password) and any preferences or settings within your account.
- Usage Data: Pages visited, modules accessed, time spent, search history, and learning progress.
- Device Data: IP address, browser type, operating system, and other technical data collected automatically when you access the System.
- Communications Data: Any enquiries, support tickets or feedback you provide.
- Analytics Records: Analytics contributions linked to your account and sponsoring organisation. These may include actively contributed survey results and user metrics derived server-side from logged-in activity, such as course or platform engagement metrics. Sponsors do not receive user-level records or raw attribution identifiers. We use them to produce sponsor-level aggregate insights, monitor platform effectiveness, improve survey design and improve the service.
- Optional Profile Data (including Special Category Data): Some profile fields (for example disability or long‑term health condition) may be treated as “special category” data under data protection law. Where we process any special category data, we do so only where you have provided it voluntarily and we have an appropriate legal basis (typically your explicit consent).
- Optional Adjustment-Support Tool Data (including Special Category Data): If you choose to use our optional adjustment-support tools, we process your quiz responses, derived profile scores, recommendations, adopted adjustments and optional review notes. Some of this information may reveal health or workplace-support needs and is protected with additional safeguards.
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us immediately.
3. How We Collect Your Data
We collect data through:
- Direct Input: When you register, update your profile, fill optional forms, or submit queries.
- Automated Tracking: Via essential cookies, security tools, analytics, and system logs.
- Third Parties: In some rare cases, your account may be set up for you by request of your organisation. In such instances, your employer may share your contact details to set up your account. We never collect your data from any sources outside of your organisation or designated point of contact.
4. Why We Process Your Data
We process your data to:
- Provide secure access to the NeuroBridge® System and Licensed Materials
- Personalise your experience and track learning progress
- Support organisational reporting (in anonymised and aggregated form)
- Provide our optional adjustment-support tools, including generating personalised workplace-adjustment recommendations and helping you track adopted adjustments
- Where you separately opt in, retain completed quiz responses and derived profile scores for a limited period so that approved internal statistical analyses can be run to validate and improve the quiz, profile scoring and recommendation logic
- Respond to user queries or support requests
- Maintain security, prevent abuse, and monitor System performance
- Meet our legal and regulatory obligations
We aim to keep System processing within the United Kingdom and/or the European Economic Area (EEA). We treat the EEA as our primary data residency boundary for the purposes of GDPR data transfers. Core System content (including user data) is hosted and stored within the UK and/or the EEA. We do not routinely transfer your personal data outside the UK or EEA as part of your use of the System. Some suppliers may process limited technical metadata outside the UK/EEA (for example, to provide global security, resilience, or support). Where an international transfer occurs, it is safeguarded using recognised mechanisms such as Standard Contractual Clauses (SCCs), the UK IDTA and/or adequacy decisions.
By default we do not use your personal data for any profiling or automated decision-making.
If you choose to use our optional adjustment-support tools, we use limited rule-based profiling based on information you provide to generate personalised workplace-adjustment recommendations. This does not involve solely automated decisions with legal or similarly significant effects.
5. Legal Grounds for Processing
We rely on several lawful bases to process personal data, including:
- Contractual necessity – For core system access and service delivery.
- Legitimate interests – for internal security, sponsor-level aggregate analytics, anonymised reporting, and service improvement.
- Explicit Consent – for special category data, our optional adjustment-support tools, separate optional research relating to those tools, and other optional features that require consent.
- Legal obligations – where compliance with statutory duties requires processing.
Where consent is our legal basis, you retain the right to withdraw it at any time.
6. Data Sharing
We only share your personal data where strictly necessary:
- With your employer: In anonymised, aggregated format.
- With regulators or law enforcement: Where legally required.
We operate the System on EEA-hosted infrastructure (primarily within EU Member States) and necessarily use a small set of vetted service providers (for hosting, email delivery, error monitoring, and analytics) under Data Processing Agreements.
If you separately opt in to research relating to our optional adjustment-support tools, approved internal statistical analysis is carried out on pseudonymised research-source data to validate and improve the quiz tool, profile scoring and recommendation logic. This may include aggregate analysis of how adjustment-support profile scores interact, which can help improve the tool’s scoring model. Workplace-outcome and workforce-performance analytics are not included. Research staff are not given participant-level views or exports for this purpose, and only anonymous or disclosure-controlled outputs may leave that workflow.
Where purchases or payments are made, these are handled and governed by independent terms and systems unconnected to the System. No payment or transactional data is stored or processed by the System.
We do not trade, sell or rent your personal data to ANY third parties.
7. Data Retention and Deletion
We retain personal data for as long as is necessary to provide the System, fulfil legal obligations, or support legitimate operational needs.
- Contract lifecycle: As a general rule, user account data is retained for the lifetime of the relevant sponsoring customer contract, then deleted or anonymised.
- Analytics records: While linked to your account, these user-contributed records are retained for as long as necessary for platform usage, sponsor-level aggregate analytics and service improvement. If your account is erased, the account-linking attribution identifier is deleted. De-linked records may be retained for the sponsor contract lifecycle and, for statistical analytics and service improvement, for no longer than necessary and in any event for no more than seven years; genuinely anonymised aggregate information may be retained longer.
- Optional adjustment-support tools: Completed quiz responses and derived profile scores are kept for up to 6 months only where you separately opt in to research; incomplete quiz drafts may also be kept for up to 6 months. Otherwise, completed quiz responses are deleted after recommendations are generated. Recommendation records may be retained for up to 6 months. Adopted adjustment records are retained until deleted, consent is withdrawn, erasure is requested, or the relevant account/contract ends. Genuinely anonymised aggregate outputs from approved internal statistical analyses may be retained indefinitely once they no longer relate to you as an identifiable user.
- User-requested deletion: Where applicable, you can request erasure and we will delete or anonymise your personal data unless an exception applies.
- Backups: Encrypted backups may be retained for a limited period for disaster recovery.
8. Your Rights
You have several rights under UK GDPR and, as applicable, under EU GDPR, including:
- Accessing the personal data we hold about you
- Requesting correction of inaccurate information
- Asking us to erase your data when appropriate
- Restricting or objecting to how we process your data
- Receiving your data in a portable format
- Withdrawing consent, where applicable
- Lodging a complaint with the Information Commissioner’s Office (ICO) (UK), or as applicable with your local EU supervisory authority
To exercise any of these rights, email: [email protected]. We aim to respond to all legitimate requests within one calendar month, in accordance with applicable data protection law.
9. Cookies and Analytics
The System uses essential cookies to maintain security and session functionality.
- Authentication (Essential, Always Active) – First‑party session and authentication cookies (e.g.
wordpress_logged_in_*, CSRF token) that let you sign in and keep your session intact. These expire when you sign‑out or automatically within a limited period (typically no longer than 14 days). - Security (Essential, Always Active) – Security cookies (e.g. firewall) protect the System. These typically expire within 48 hours.
- Interface Preferences (Essential, Always Active) – Device-local storage tokens to remember temporary interface preferences, such as dismissed or animated notifications. This information remains on your device, does not contain personally identifiable information, is not transmitted to our systems, and is automatically cleared on logout or after a limited period (typically no longer than 7 days).
9.1. Cookieless Analytics
- Cookieless Analytics (No Consent Needed) – Fathom Analytics processes visitor data without cookies; uses Extreme EU Isolation where all global traffic is routed through the EU; IP addresses processed in-memory only; no personal data stored. Fathom’s privacy policy.
10. Data Security
We use robust organisational and technical measures to protect your data:
- HTTPS and encrypted data storage.
- EEA-based System servers in compliance with GDPR.
- User-level personal data, and any sensitive special‑category data, are protected by strict access controls and encryption are not routinely accessible to NeuroBridge personnel except where required to provide support, comply with legal obligations, or fulfil data protection requests.
- Regular security audits and threat monitoring.
- Certified to Cyber Essentials (Certificate ID: 93d14246-6a12-4e7a-85c1-6f5a45b85210, valid until 21 April 2027)
We may send automated email reminders or nudges to support engagement with the System. These are generated without manual intervention and are never accessed by staff unless the user explicitly requests support. No individual-level behaviour or communications data is reviewed unless the user explicitly requests or grants access for support purposes.
11. Linked Policies & Changes to This Policy
This Privacy Policy is designed to be read in conjunction with our related documents, including:
- Terms of Service
- End-User Licence Agreement (EULA)
- Customer Order Form
- Service Definition Document (SDD)
- Framework Agreement(s)
- Scope of Work(s) (SOW)
We may update this Privacy Policy periodically to reflect changes in our System, services, or legal obligations. Where the changes are significant, we will notify you via the System or email. The most current version will always be available at: www.neurobridgeportal.com/privacy-policy
12. Contacting Us
If you have any concerns about this policy or wish to contact our Data Protection Officer, please reach out:
Data Protection Officer (DPO):
Josh Goodison (ICO-registered contact)
Email: [email protected] (please include “FAO DPO” in the subject line)
Address: NeuroBridge Ltd, Suite 46, 24–28 St. Leonards Road, Windsor, SL4 3BB, UK
12.1. EU Representative
If you are located in the EU/EEA, you may also contact our EU Representative:
Ludovico Saint Amour di Chanaz
Carrer de Malgrat 126, Sobreatico, Barcelona, 08016, Spain
Email: [email protected] (please include “FAO EU Representative” in the subject line)
12.2. Responsible Disclosure Policy
See our Responsible Disclosure Policy for reporting security vulnerabilities.