
Effective Date: July 23, 2026
Last Updated: July 23, 2026
Neuzenix LLC ("Neuzenix," "we," "us," or "our") respects your privacy and is committed to protecting the personal data we collect, use, and share. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and the rights you have over your data.
This Policy applies to:
Our websites at https://neuzenix.com, https://neuzenix.us, and any subdomains (collectively, the "Websites")
Our AI automation services, including the AI Client Acquisition Engine, AI Employee Pro, Voice AI, Conversation AI, Review AI, Website in a Day, and AI Growth Website (collectively, the "Services")
All prospective clients, active clients, website visitors, and end-users interacting with systems Neuzenix has deployed on behalf of our clients
We designed this Policy to comply with the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK-GDPR), the California Consumer Privacy Act (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and Australia's Privacy Act 1988 (including the Australian Privacy Principles).
1. WHO WE ARE (DATA CONTROLLER)
For the purposes of GDPR and UK-GDPR, the data controller is:
Neuzenix LLC
1209 Mountain Road PL NE, STE R
Albuquerque, NM 87110, USA
Email: [email protected]
Phone: (515) 368-9900
For matters relating to personal data, you may reach our privacy team at [email protected] with the subject line "Privacy Request."
Controller vs. Processor Note: When you visit our Websites, book a call, or become our client, we act as the data controller of your personal data. When we operate AI systems on behalf of our clients (such as their Voice AI receptionist processing calls from their customers), we act as the data processor and our client acts as the data controller of that end-user data. Where we act as processor, our obligations are governed by the applicable Service Agreement and Data Processing Addendum, not solely by this Policy.
2. PERSONAL DATA WE COLLECT
We collect personal data in several ways, depending on how you interact with us.
2.1 Data You Provide Directly
When you book a diagnostic call, request a proposal, become a client, subscribe to communications, or otherwise contact us, we may collect:
Identity data: Name, business name, job title
Contact data: Email address, phone number, postal address
Business data: Industry, company size, revenue range, business challenges
Financial data: Payment card information (processed by Stripe — we do not store full card numbers), billing address
Communication data: Emails, chat messages, call recordings, meeting transcripts, notes exchanged during your engagement with us
Preference data: Marketing preferences, service interests, timezone
2.2 Data Collected Automatically
When you visit our Websites, we automatically collect:
Device data: IP address, browser type and version, operating system, device identifiers
Usage data: Pages visited, time spent, referral source, clicks, scroll depth, exit pages
Location data: Approximate location derived from IP address (city or region level)
Cookie data: As described in our Cookie Policy
2.3 Data From Third Parties
We may receive personal data about you from:
Payment processors (Stripe) confirming transactions
Marketing platforms and lead-enrichment services
Public sources such as LinkedIn, business directories, or public records (for prospecting and business intelligence)
Affiliate partners who refer you to us via our Affiliate Program
Analytics providers such as Google Analytics
Referral sources — if someone refers you to us, we may receive your name and contact information
2.4 Data Collected Through Client Deployments
When Neuzenix deploys AI systems for our clients, those systems may process personal data of the client's own customers, leads, and contacts (voice recordings, SMS messages, chat conversations, form submissions, etc.). For that data, our client is the data controller and Neuzenix is the data processor. We only process such data under the instructions of our client and under a Data Processing Addendum where required by law.
2.5 Sensitive Categories
We do not intentionally collect special-category (sensitive) personal data such as health information, genetic data, biometric data, racial or ethnic origin, political opinions, religious beliefs, or sexual orientation. If our clients' AI deployments handle such data (for example, medical clinics), the client is responsible for lawful processing and must have appropriate legal bases under GDPR Article 9 or equivalent frameworks.
3. HOW WE USE YOUR DATA (PURPOSES AND LEGAL BASES)
We use your personal data for the purposes listed below. Under GDPR and UK-GDPR, we must have a lawful basis for each use.
PurposeLegal Basis (GDPR / UK-GDPR)Provide, operate, and improve our ServicesContract performance (Article 6(1)(b)); legitimate interests (Article 6(1)(f))Process payments and manage billingContract performance; legal obligationCommunicate with you about your engagementContract performance; legitimate interestsRespond to inquiries and provide customer supportContract performance; legitimate interestsSend marketing communications about our ServicesConsent (Article 6(1)(a)) — where required; legitimate interests where lawfulPersonalize your website experienceConsent (where required by cookies law); legitimate interestsAnalyze website usage and improve our WebsitesLegitimate interests; consent (for analytics cookies where required)Prevent fraud, abuse, and security threatsLegitimate interests; legal obligationComply with legal, tax, and regulatory obligationsLegal obligation (Article 6(1)(c))Enforce our Terms of Service and legal rightsLegitimate interestsTrain and improve our AI systems on aggregated, de-identified data onlyLegitimate interests
For CCPA/CPRA purposes, we collect personal data for the "business purposes" of providing services, managing transactions, security, and compliance. For PIPEDA, our processing is based on consent (express or implied) and business necessity. For the Australian Privacy Act, processing aligns with the Australian Privacy Principles.
We do not sell your personal data and do not engage in "sharing" as defined by the CCPA (i.e., cross-context behavioral advertising) without your consent.
4. HOW WE SHARE YOUR DATA
We share your personal data only when necessary and with appropriate safeguards. We may share your data with:
4.1 Service Providers (Subprocessors)
We rely on trusted third parties who process personal data on our behalf under written agreements. Our current key subprocessors include:
ProviderPurposeLocationStripePayment processingUSA / globalOpenAIAI language model processingUSAAnthropicAI language model processingUSAGoogle (Google AI, Analytics, Ads)AI processing, analytics, advertisingUSA / globalTwilioVoice, SMS, and messaging infrastructureUSA / globalMake (Integromat)Workflow automationCzech Republic (EU)Perplexity AIResearch and content assistanceUSAWordPress hosting providersWebsite hostingUSA
The list of subprocessors may change as our operations evolve. We maintain a current list and, where required by law, will notify Clients of material subprocessor changes.
4.2 Affiliate Partners
If you were referred to us by an affiliate through our Affiliate Program, we may share limited data with that affiliate (e.g., that a referral converted) for the purpose of commission tracking. We do not share your personal details with affiliates beyond what is necessary.
4.3 Professional Advisors
Our attorneys, accountants, auditors, and insurers may access personal data as needed to advise us or protect our legal interests.
4.4 Legal and Regulatory
We may disclose personal data when required by law, court order, subpoena, or government request; to enforce our Terms of Service; to protect our rights, property, or safety, or that of our clients, users, or others; or to investigate fraud or security incidents.
4.5 Business Transfers
If Neuzenix is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected data subjects and provide options where required by law.
4.6 With Your Consent
We may share your data for other purposes with your explicit consent.
We do not sell your personal data to third parties for their own marketing purposes.
5. INTERNATIONAL DATA TRANSFERS
Neuzenix is based in the United States, and our subprocessors operate globally. If you are located in the European Union, United Kingdom, EEA, Canada, Australia, or another jurisdiction outside the United States, your personal data may be transferred to, stored in, and processed in the United States and other countries whose data protection laws may differ from your own.
When we transfer personal data outside the EU, UK, or EEA, we use appropriate safeguards, including:
Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Addendum for UK transfers)
Adequacy decisions where applicable
Supplementary technical and organizational measures to protect data during transfer
For Canadian data subjects, we rely on PIPEDA's provisions for cross-border transfers and take steps to ensure comparable protection. For Australian data subjects, we take reasonable steps to ensure overseas recipients handle data in accordance with the Australian Privacy Principles.
You may request a copy of the transfer safeguards in place by emailing [email protected].
6. DATA RETENTION
We keep personal data only as long as necessary for the purposes described in this Policy, or as required by law.
Data TypeRetention PeriodProspect / lead data (not converted to client)Up to 24 months from last contactActive client account dataFor the duration of the engagement + 7 years after termination (for tax, legal, and audit purposes)Payment / billing records7 years (US tax law)Website analytics dataUp to 26 monthsMarketing preferences and consent recordsUntil consent is withdrawn + 3 years for evidentiary purposesCall recordings and transcripts12 months, unless longer is required by contract or lawSupport and communication logs3 years after last contactBackupsRolling 90-day cycle
When personal data is no longer required, we delete or anonymize it. Some data may be retained longer to comply with legal obligations, resolve disputes, or enforce agreements.
7. YOUR PRIVACY RIGHTS
Depending on your jurisdiction, you have various rights over your personal data. Neuzenix respects and honors these rights regardless of where you live.
7.1 Rights Under GDPR and UK-GDPR (EU/UK/EEA Residents)
You have the right to:
Access your personal data and receive a copy
Rectify inaccurate or incomplete personal data
Erase your personal data (the "right to be forgotten"), subject to legal retention requirements
Restrict processing in certain circumstances
Object to processing based on legitimate interests or for direct marketing
Data portability — receive your data in a structured, machine-readable format and transmit it to another controller
Withdraw consent at any time (without affecting the lawfulness of prior processing)
Not be subject to solely automated decision-making with legal or significant effects, except under certain conditions
Lodge a complaint with your local supervisory authority (see Section 15)
7.2 Rights Under CCPA/CPRA (California Residents)
California residents have the right to:
Know what personal information we collect, use, disclose, and sell/share
Access the specific pieces of personal information we hold about you (twice per 12-month period)
Delete your personal information, subject to exceptions
Correct inaccurate personal information
Opt-out of the sale or sharing of personal information (Neuzenix does not sell personal information)
Limit the use and disclosure of sensitive personal information
Non-discrimination for exercising your rights
To exercise these rights, email [email protected] with the subject line "California Privacy Request."
7.3 Rights Under PIPEDA (Canada)
Canadian residents have the right to:
Access personal information Neuzenix holds about them
Challenge the accuracy and completeness of their personal information and have it corrected
Withdraw consent, subject to legal or contractual restrictions
Know how their personal information is being used and to whom it has been disclosed
File a complaint with the Office of the Privacy Commissioner of Canada
7.4 Rights Under the Australian Privacy Act
Australian residents have the right to:
Access their personal information
Correct inaccurate personal information
Opt-out of direct marketing
Complain to the Office of the Australian Information Commissioner (OAIC)
7.5 How to Exercise Your Rights
To exercise any privacy right, email [email protected] with the subject line "Privacy Request." Please include:
Your full name
Your email address (the one associated with your Neuzenix account or communications)
The right you are exercising
A brief description of your request
For security, we may need to verify your identity before responding. We will respond within the timeframe required by applicable law — generally within 30 days under GDPR/UK-GDPR (extendable by two months for complex requests), within 45 days under CCPA (extendable once), and within 30 days under PIPEDA (extendable in limited circumstances). Requests are free of charge unless manifestly unfounded, repetitive, or excessive.
You may designate an authorized agent to submit requests on your behalf, subject to reasonable verification.
8. AUTOMATED DECISION-MAKING AND AI
Some of our AI-powered services involve automated processing of personal data — for example, categorizing leads, generating suggested responses, or routing conversations.
Where we deploy such systems for our clients, the client (as data controller) is responsible for ensuring that any automated decision with legal or significant effects on an individual complies with GDPR Article 22 or equivalent regulations, including appropriate safeguards, human oversight, and the right to human review.
For prospects and clients interacting with Neuzenix directly, we do not use automated decision-making to produce legal or significant effects on you without appropriate human review.
9. DATA SECURITY
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
Encryption of data in transit (TLS/SSL)
Encryption of sensitive data at rest where appropriate
Access controls and role-based permissions
Regular security reviews of our subprocessors
Employee training on data protection
Incident response procedures
No security system is impenetrable. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected data subjects and applicable regulators within the timeframes required by law (72 hours under GDPR/UK-GDPR where feasible).
If you believe your account or data has been compromised, please contact us immediately at [email protected].
10. COOKIES AND TRACKING
Our Websites use cookies and similar tracking technologies. For details on what cookies we use, their purposes, and how to manage them, please see our separate Cookie Policy at https://neuzenix.com/cookie-policy.
You can also control cookies through your browser settings and through the cookie consent banner on our Websites.
11. MARKETING COMMUNICATIONS
We may send you marketing emails about our Services if you have consented (where consent is required) or if permitted under the "soft opt-in" rules of your jurisdiction (typically, existing clients whose email was obtained during a transaction and who were given a clear opportunity to opt out).
You can opt out of marketing at any time by:
Clicking the "unsubscribe" link in any marketing email
Emailing [email protected] with the subject line "Unsubscribe"
Updating your preferences in any preference center we provide
Transactional and service-related communications (e.g., billing notices, account updates, security alerts) will continue even after you opt out of marketing.
12. CHILDREN'S PRIVACY
Our Services are directed exclusively at businesses and are not intended for children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children. If we learn that we have collected data from a child without appropriate consent, we will delete it promptly.
If you believe a child has provided personal data to us, please contact [email protected].
13. DO NOT TRACK AND GLOBAL PRIVACY CONTROL
Our Websites recognize the Global Privacy Control (GPC) browser signal where required by CCPA/CPRA. When we detect a GPC signal, we treat it as an opt-out of sale/sharing.
Because there is no consensus industry standard for "Do Not Track" (DNT) signals, we do not currently respond to DNT signals separately. We treat GPC signals as our primary automated opt-out mechanism.
14. THIRD-PARTY LINKS
Our Websites may contain links to third-party websites, tools, or services (e.g., social media, analytics dashboards). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing personal data.
15. REGULATORY COMPLAINTS
If you believe we have not complied with applicable data protection law, we encourage you to contact us first at [email protected] so we can attempt to resolve the concern.
You also have the right to lodge a complaint with the supervisory authority in your jurisdiction:
EU/EEA: Your local Data Protection Authority. A list is available at https://edpb.europa.eu/about-edpb/board/members_en
United Kingdom: Information Commissioner's Office (ICO) — https://ico.org.uk
United States (California): California Privacy Protection Agency — https://cppa.ca.gov
Canada: Office of the Privacy Commissioner of Canada — https://www.priv.gc.ca
Australia: Office of the Australian Information Commissioner (OAIC) — https://www.oaic.gov.au
16. EU/UK REPRESENTATIVES
If required by GDPR Article 27 or UK-GDPR Article 27, Neuzenix will appoint an EU and/or UK representative. As of the effective date, our threshold under Article 27 does not require such appointment, but this position will be reviewed periodically as our EU and UK client base grows. If you require immediate contact for GDPR or UK-GDPR matters, please email [email protected] and we will respond within the statutory timeframe.
17. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations.
Minor changes will be posted on this page with an updated "Last Updated" date
Material changes affecting your rights will be communicated through our Websites and, where feasible, by email to active clients and subscribers at least 30 days before taking effect
Your continued use of our Websites or Services after the effective date of any updated Policy constitutes acceptance of the changes. If you do not agree, please stop using our Services and contact us to exercise your rights.
18. CONTACT US
For any privacy-related question, request, or complaint, please contact:
Neuzenix LLC
Attention: Privacy Team
1209 Mountain Road PL NE, STE R
Albuquerque, NM 87110, USA
Email: [email protected]
Phone: (515) 368-9900
Website: https://neuzenix.com
We are committed to resolving privacy concerns quickly and transparently.
End of Privacy Policy.