Legal

Privacy Policy

Last updated 14 August 2026

Neolen is in active pre-launch development. This policy describes our current practices and will be finalized with legal counsel before commercial launch and before any Evidence Engine deployment involving patient data. Contact support@neolen.com with any questions.

1. Scope

This policy covers information collected through the public Neolen website (neolen.com) and the Neolen research platform used by registered account holders. It does not cover patient health information processed by the Evidence Engine, which is governed by separate agreements (including Business Associate Agreements, where applicable) with each deploying institution and never leaves that institution's own environment.

2. Information we collect

On the public website: information you voluntarily provide, such as name, email address, and organization, when you contact us or request access. On the research platform: account information (name, email), authentication data, uploaded research files and data source connections, and usage data such as session activity, needed to operate the product.

3. Information we do not collect on the public website

The public marketing pages do not use third-party advertising trackers. We may use privacy-respecting, aggregate analytics to understand which pages are useful, without building individual advertising profiles.

4. How we use information

To respond to inquiries and design-partner applications, to operate and improve the research platform for registered users, to maintain security and audit logs required for a regulated-adjacent product, and to communicate important product or policy updates.

5. The PHI boundary

Neolen's architecture is deliberately split: the Discovery Engine processes only public biomedical data. The Evidence Engine, where deployed, processes de-identified or protected health information inside the customer's own VPC or on-premise environment under that customer's data governance and applicable agreements — never in Neolen's multi-tenant infrastructure.

6. Data sharing

We do not sell personal information. We share information only with service providers who help us operate the platform (e.g. cloud infrastructure, email delivery), under confidentiality obligations, or where required by law.

7. Data retention & security

We retain account and platform data for as long as an account is active, plus a reasonable period thereafter for legal and operational purposes. We apply role-based access control, encryption in transit, and audit logging.

8. Your choices

You may request access to, correction of, or deletion of your personal information by contacting us. Registered users can manage most account information directly within the platform.

9. Grievance officer

In accordance with the Information Technology Act, 2000 and rules made thereunder, and the Digital Personal Data Protection Act, 2023, grievances regarding this policy or your personal data can be directed to our grievance contact at support@neolen.com or +91 76785 11552. We aim to acknowledge grievances within 24 hours and resolve them within 15 days.

10. Changes to this policy

We will update this page as the product and our data practices evolve, particularly ahead of the Evidence Engine's first hospital deployment, and will note the effective date of material changes above.

11. Contact

Questions about this policy can be sent to support@neolen.com or +91 76785 11552. Registered office: Neolen Services Private Limited (CIN: U72900UP2021PTC156376), Keshav Market, Rajaram Ki Bagiya, Shamshabad Road, Agra, Uttar Pradesh, India - 282001.