Testing Phase Notice

NEIMUS360 Privacy Policy

Version 0.1 · Effective May 20, 2026

1.Who this applies to

This Privacy Notice explains how NEIMUS360 handles personal data, platform data, sensor data, and administrative data generated by users, tenant administrators, and authorised account holders while using the NEIMUS360 Platform. This notice applies to production use of the Platform. It does not replace any separate agreement entered into between NEIMUS360 and a customer, tenant, or organisation.

2.What we collect

  • Account informationthe email, display name, tenant assignment, and authentication factors you provide when accepting an invite.
  • Authentication metadatasign-in timestamps, IP address of the request, the user-agent string, and 2FA enrolment state, recorded for security auditing.
  • Sensor and environmental datareadings ingested from devices you connect to the Platform (e.g. temperature, humidity, motion, air-quality). These are attributed to your tenant.
  • Platform activitypages you visit, actions you take (creating rooms, acknowledging alerts, submitting feedback), and the timestamps of those actions, for audit-log and product-improvement purposes.
  • Feedback you submitthe subject and message of any in-app issue report, along with the page URL and app version captured automatically to help triage.

3.How we use it

We use the data above to:

  • operate the Platform and serve your requests;
  • authenticate you and protect your account from unauthorised access (2FA, rate limits, anomaly detection);
  • investigate and fix defects you report or that we detect ourselves;
  • aggregate anonymised metrics so we can measure platform performance and roadmap progress;
  • comply with our legal obligations and respond to lawful requests.

We do not sell your data, your sensor readings, or your feedback to third parties.

4.Tenancy and access boundaries

Data you generate is stored against your tenant. Other tenants cannot see it. Sub-tenants of a parent tenant are visible to administrators of that parent tenant (this is the whole point of the sub-tenant model), but sibling tenants are isolated from each other.

5.Where data lives

Platform data is hosted on Amazon Web Services in the United States (region us-east-2 at the time of writing). Email notifications are delivered via Brevo (Sendinblue). Sensor data may transit through MQTT brokers configured by your tenant administrator.

6.Retention

During the testing phase we retain data for the duration of your account plus 90 days after deactivation, primarily so we can investigate post-hoc issues. Audit-log entries (authentication, security-sensitive actions) are kept longer for compliance.

7.Your choices

  • Account deletionask your tenant administrator to deactivate your account. They can also request a full deletion via the in-app feedback flow.
  • Data exportreach out to your tenant administrator; bulk export is supported on the admin side via the Data Management endpoints.
  • Withdrawing consentstop using the Platform and ask for deactivation. Audit records of your past acceptance remain for compliance.

8.Security

We use industry-standard transport encryption (TLS) for all traffic to and from the Platform, hashed passwords (bcrypt), mandatory 2FA for all human accounts, scoped API tokens, and audit logging of security-relevant actions. No system is perfectly secure; please report any suspected vulnerability via the in-app feedback button with severity critical.

9.Changes

We may update this notice during the testing phase. Material changes will trigger a re-prompt on your next sign-in so you can review and re-accept. The version number and effective date at the top of this page indicate which version is in effect.

10.Contact

For privacy questions or data-handling concerns, contact your tenant administrator first. Platform-wide concerns can be raised via the in-app “Report an issue” button so they are logged.