Privacy Policy
This Privacy Policy explains how NeoEvolution AI ("NeoEvolution", "we", "us", "our") collects, uses, shares, and protects personal information when you visit neoevolution.ai (the "Site"), contact us, or otherwise interact with our services. It is written to align with the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD, and Canada's PIPEDA.
Who we are
The data controller is NeoEvolution AI, headquartered at Suite 200, 2020 Winston Park Drive, Oakville, ON L6H 6X7, Canada. For privacy questions or to exercise any right described below, contact us at hello@neoevolution.ai.
Information we collect
We collect the following categories of personal information:
- Identifiers and contact data — name, email address, phone number, company, job title, and similar details you provide when contacting us, requesting a proposal, booking a call via our scheduling tool, or messaging the Nova chat assistant.
- Commercial information — records of inquiries, proposals, contracts, and engagements you initiate with us.
- Internet and device activity — IP address, browser type and version, device identifiers, operating system, referring URL, pages viewed, time on page, and click events. Collected automatically via Cloudflare and (with your consent) Google Analytics 4 and Microsoft Clarity.
- Inferences — high-level patterns about how visitors engage with the Site (e.g., which content drives interest), used in aggregate.
We do not knowingly collect special-category personal data (health, biometric, racial or ethnic origin, religious beliefs, etc.) and ask that you do not send such information through our website or chat.
How we collect it
- Directly from you when you fill out a form, send an email, book a call, or chat with us.
- Automatically through cookies, pixels, and similar technologies — see our Cookie Policy.
- From service providers acting on our behalf (e.g., Cloudflare for traffic data, Google Analytics for engagement data, Microsoft Clarity for session-level interaction).
How we use information
- To respond to inquiries and deliver requested services.
- To negotiate, enter into, and perform contracts with you or your organization.
- To measure and improve Site performance, content, and conversion.
- To detect, prevent, and address technical, security, or fraud issues.
- To comply with legal obligations and respond to lawful requests from public authorities.
- To send transactional or relationship communications (e.g., proposal follow-ups). We do not send unsolicited marketing.
Legal bases for processing (EEA, UK, Brazil)
Where the GDPR, UK GDPR, or LGPD applies, we rely on these legal bases:
- Consent — for analytics cookies and similar technologies. You can withdraw consent at any time via our Cookie Policy.
- Performance of a contract — to respond to your inquiry, prepare a proposal, and deliver our services.
- Legitimate interests — to maintain Site security, prevent abuse, measure aggregate engagement, and develop our services. Where we rely on this basis, we balance it against your rights and freedoms.
- Legal obligation — to retain records and respond to lawful requests.
Who we share information with
We do not sell personal information for monetary consideration. We share data only with service providers who process it on our behalf under written data-protection terms:
- Cloudflare, Inc. — hosting, CDN, and infrastructure security.
- Google LLC — Google Analytics 4 and Google Tag Manager (loaded only after consent).
- Microsoft Corporation — Clarity (heatmaps and anonymized session replay; loaded only after consent).
- ElevenLabs Inc. — Nova AI chat assistant (transcripts of your conversations with Nova).
- Cal.com, Inc. — embedded scheduling for booking calls with our team.
- Professional advisors (lawyers, accountants, auditors) on a need-to-know basis.
- Authorities and courts when required by applicable law, to enforce our terms, or to protect our rights, property, or safety.
- Successors in the event of a merger, acquisition, financing, or asset sale, subject to confidentiality.
International data transfers
We are based in Canada and most of our service providers are located in the United States or the European Economic Area. When we transfer personal data out of the EEA, UK, Switzerland, or Brazil to a country that has not received an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or equivalent mechanisms. A copy of the relevant safeguards is available on request.
Retention
We keep personal information only as long as necessary for the purposes described above:
- Inquiry and proposal records — up to 24 months after our last interaction, then deleted or anonymized.
- Customer and contract records — for the duration of the engagement and up to 7 years afterwards, as required by Canadian tax and corporate law.
- Analytics data — Google Analytics 4 retention is set to 14 months (the maximum on the standard tier); Cloudflare and Clarity follow their own retention schedules.
- Chat transcripts — up to 12 months for service improvement, unless you request earlier deletion.
Security
We use technical and organizational measures appropriate to the risk — including TLS in transit, encryption at rest where feasible, least-privilege access controls, audit logging, and vendor due diligence. No method of transmission or storage is 100% secure, so we cannot guarantee absolute protection.
Your rights
Depending on where you live, you may have the following rights regarding your personal information. To exercise any right, email hello@neoevolution.ai. We will respond within 30 days (GDPR / LGPD) or 45 days (CCPA), and we will not retaliate or discriminate against you for exercising a right.
EEA, UK, Brazil, and similar jurisdictions
- Access — confirm whether we process your data and obtain a copy.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion ("right to be forgotten") subject to legal retention requirements.
- Restriction — limit how we process your data while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Object — to processing based on legitimate interests or for direct marketing.
- Withdraw consent — at any time, without affecting prior lawful processing.
- Lodge a complaint with your local supervisory authority.
California (CCPA / CPRA)
- Right to know what categories of personal information we collect, the sources, the business purposes, and the categories of third parties with whom we share it (all disclosed above).
- Right to delete personal information we hold about you, with limited exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell personal information and do not share it for cross-context behavioral advertising. There is therefore no "Do Not Sell or Share" link to action; if this changes, we will update this notice and provide one.
- Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined by CPRA.
- Right to non-discrimination for exercising any right.
Canada (PIPEDA)
You may access, correct, and challenge the accuracy of personal information we hold about you. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing or profiling.
Children
Our services are intended for business users and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have collected such information, please contact us and we will delete it promptly.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be highlighted, and where required by law we will obtain renewed consent.
Contact us
NeoEvolution AI
Suite 200, 2020 Winston Park Drive
Oakville, ON L6H 6X7, Canada
hello@neoevolution.ai
