01 / Legal
Legal.
Notice, privacy, terms and security disclosure. Last updated August 2026.
Legal notice
This site is published by Neuryn Systems, a simplified joint-stock company registered in Rennes, France, under number 908 442 117, with share capital of 45,000 euros.
Registered office: 12 rue de la Monnaie, 35000 Rennes, France. VAT number: FR 62 908442117. Contact: hello@neuryn.com.
Publication director: the President of Neuryn Systems. Hosting is provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, United States.
Privacy
We collect the minimum needed to run the service and to answer messages you send us. This notice describes what that means in practice rather than restating the regulation.
What we collect
- Account data. Name, work email, company. Kept while the account exists, deleted 90 days after closure.
- Contact messages. What you write in the contact form, plus your email so we can reply. Kept 24 months.
- Service telemetry. Row counts, rule outcomes and timings. Aggregated, and never the row contents themselves.
- Site analytics. Page views without cookies, without cross-site identifiers, and without a consent banner because there is nothing to consent to.
What we do not collect
We do not read the contents of the records you validate. The validator runs on your ingest nodes and reports outcomes, not payloads. Quarantined rows stay in your storage under your keys.
Your rights
Access, rectification, erasure, portability, restriction and objection, under Articles 15 to 22 of the GDPR. Write to privacy@neuryn.com. We answer within 30 days. If our answer does not satisfy you, you may complain to the CNIL.
Terms
Using the service means accepting these terms. They are short on purpose, and the commercial agreement signed by Enterprise customers takes precedence over anything here.
The service
We provide data validation, quarantine, encryption and audit infrastructure. We commit to 99.9 percent monthly availability on paid tiers, measured at the ingest endpoint. Credits for missed availability are set out in the commercial agreement.
Your obligations
- Do not use the service to process data you have no lawful basis to hold.
- Keep your credentials scoped. Shared root credentials are a breach of these terms and of common sense.
- Tell us within 72 hours if you believe your account has been compromised.
Liability
Our aggregate liability is capped at the fees paid over the twelve months preceding the claim. We do not exclude liability for fraud, wilful misconduct, or anything that cannot lawfully be excluded.
Termination
You may cancel at any time, effective at the end of the current billing period. Ledger and quarantine exports remain available for 90 days after cancellation, after which we delete your data and send you a certificate confirming it.
Security
We run a coordinated disclosure policy. If you find a vulnerability, tell us before you tell anyone else and we will work with you.
Reporting
Email security@neuryn.com. Encrypt with our PGP key if the report contains anything sensitive. We acknowledge within one business day and give you a substantive answer within five.
Scope
- In scope: the application, the API, the self-hosted build, and this site.
- Out of scope: social engineering of our staff, physical attacks, and denial of service testing.
Our commitments
- We will not pursue legal action against good-faith research within this scope.
- We will credit you in the advisory unless you prefer otherwise.
- We publish an advisory for every issue rated medium or above, within 90 days of the fix.
Certifications
SOC 2 Type II, renewed annually. GDPR-aligned processing with a DPA available on request. HIPAA BAA available on Enterprise. The current SOC 2 report is available under NDA through sales@neuryn.com.