Privacy Policy
Dealsparrow Limited, trading as NeuroClo (“NeuroClo”, “we”, “our”, or “us”), is committed to protecting the privacy, confidentiality, and security of personal information. This Privacy Policy explains how we collect, use, disclose, store, transfer, and safeguard information when individuals visit our website, communicate with us, use our products and services, or otherwise interact with NeuroClo.
This Privacy Policy is intended to support our obligations under applicable privacy and healthcare data protection laws, including:
- UK GDPR;
- EU GDPR;
- The Data Protection Act 2018;
- Applicable U.S. state privacy laws;
- HIPAA, where applicable; and
- Other applicable healthcare privacy and data protection laws.
This Privacy Policy describes our privacy practices. It should be read together with our Terms of Service and any other notices we provide at the time information is collected.
1. Who We Are
NeuroClo is a healthcare technology platform operated by:
Dealsparrow Limited (trading as NeuroClo)
- Privacy Contact: hello@neuroclo.com
- Website: https://neuroclo.com
- Registered Office / Service Address: 395 Clapham Road, London, SW9 9BT, United Kingdom
- Company Number: 07415063
- ICO Registration Number: to be published when available
2. Definitions
For the purposes of this Privacy Policy:
- Personal Data means information relating to an identified or identifiable natural person as defined by applicable data protection laws.
- Protected Health Information (PHI) means Protected Health Information as defined under HIPAA.
- Data Controller means the person or organisation that determines the purposes and means of processing personal data.
- Data Processor means the person or organisation that processes personal data on behalf of a Data Controller.
- Healthcare Provider means a clinic, healthcare organisation, practitioner, or other customer using the NeuroClo platform.
3. Our Role: Controller and Processor
NeuroClo performs different privacy roles depending on the context.
Website Visitors and Business Contacts
For personal data collected through:
- our website;
- contact forms;
- demo or early-access requests;
- sales enquiries;
- newsletters and marketing communications;
- customer account administration; and
- general business communications,
NeuroClo acts as the data controller. This means NeuroClo determines how and why that personal data is processed.
Healthcare Platform Data
NeuroClo provides B2B software to healthcare providers. Patients’ contractual and care relationship is with their healthcare provider, not with NeuroClo.
When healthcare providers use the NeuroClo platform (including any patient portal made available through NeuroClo) to process patient information, NeuroClo acts as:
- a data processor under UK GDPR and EU GDPR;
- a service provider where applicable under U.S. privacy laws; or
- a business associate under HIPAA where applicable.
In these circumstances, the healthcare provider is typically the data controller (or equivalent legal role under applicable law) and determines the purposes and means of processing.
Where NeuroClo acts as a processor, NeuroClo processes personal data only on documented instructions from the healthcare provider unless otherwise required by law.
NeuroClo enters into Data Processing Agreements (“DPAs”) where required by UK GDPR or EU GDPR.
Separate Environments
Our public marketing website may be hosted separately from the NeuroClo application environment used to process healthcare platform data. Website analytics and marketing technologies described in this Policy apply to the marketing website unless otherwise stated. Healthcare platform data is processed in the application environment subject to applicable customer agreements, BAAs, and DPAs.
4. Healthcare Information and HIPAA
NeuroClo provides software and related technology services to healthcare providers. NeuroClo does not provide healthcare services directly to patients.
Where NeuroClo provides services to HIPAA Covered Entities or their Business Associates, and a Business Associate Agreement (“BAA”) is in effect, NeuroClo processes Protected Health Information (PHI) in accordance with:
- HIPAA;
- the applicable Business Associate Agreement;
- healthcare provider instructions; and
- applicable healthcare privacy laws.
HIPAA applies only where NeuroClo acts as a Business Associate to a HIPAA Covered Entity or another Business Associate and an applicable Business Associate Agreement is in effect.
NeuroClo maintains Business Associate Agreements with covered subprocessors where required for the services provided (including relevant Amazon Web Services offerings used to process PHI).
Patients seeking information about how their healthcare information is collected, used, or disclosed should contact their healthcare provider directly. If a patient contacts NeuroClo with a privacy request relating to healthcare platform data, NeuroClo will direct the individual to their healthcare provider and may forward the request to that provider so it can be handled appropriately.
5. Information We Collect
Information You Provide
We may collect information you voluntarily provide, including:
- Name;
- Job title;
- Clinic or organisation name;
- Email address;
- Telephone number;
- Message content;
- Customer support requests;
- Demo or early-access requests;
- Contractual or billing information;
- Account information; and
- Other information you choose to provide.
Platform Information
Depending on the services used by our customers, the NeuroClo platform may process:
- Patient records;
- Appointment information;
- Healthcare documentation;
- Insurance and coverage information;
- Referral source information;
- Clinical assessments;
- Treatment records;
- Audio recordings;
- Video recordings (including session and call recordings);
- Transcriptions;
- Payment and billing-related information; and
- Other healthcare-related information.
Such information is generally processed on behalf of healthcare providers. Payment card details, where collected in connection with services, are processed through payment service providers that support major card schemes. NeuroClo does not use full payment card numbers for unrelated purposes.
Session recording and call recording features may be enabled as part of normal platform use. Healthcare providers remain responsible for their patient relationships and for ensuring that recording and related processing are lawful under applicable requirements. Where the platform supports consent or notice workflows, those mechanisms assist the provider; they do not transfer the provider’s legal responsibilities to NeuroClo.
Information Collected Automatically
When you visit our website or use our services, we may automatically collect information including:
- IP address;
- Device identifiers;
- Browser type;
- Operating system;
- Session information;
- Approximate geographic location derived from IP address;
- Referral source;
- Usage data;
- Performance metrics; and
- Security and diagnostic information.
6. How We Use Personal Data and Our Legal Bases
Where UK GDPR or EU GDPR applies, the legal basis we rely upon depends on the purpose of processing.
| Purpose | Examples | Legal Basis |
|---|---|---|
| Website enquiries | Contact forms, demo requests, sales discussions | Legitimate Interests and/or steps prior to entering a contract |
| Customer contracts | Account creation, onboarding, service delivery | Contract |
| Customer support | Support requests, troubleshooting, account assistance | Contract and Legitimate Interests |
| Security and fraud prevention | Monitoring, logging, incident response, abuse prevention | Legitimate Interests |
| Product improvement | Analytics, diagnostics, service enhancement | Legitimate Interests |
| Billing and accounting | Invoicing, payment processing, tax compliance | Legal Obligation and Contract |
| Marketing communications | Product updates, events, newsletters, promotions | Consent and/or Legitimate Interests where permitted by law (including PECR soft opt-in where applicable) |
| Analytics cookies | Website analytics and performance measurement | Consent (where required) |
| Healthcare platform processing | Patient information processed for customers | Customer instructions; see Sections 3 and 8 |
Where consent is relied upon, it may be withdrawn at any time.
7. Providing Personal Data
Providing personal data to NeuroClo is generally voluntary.
However, certain information may be necessary for us to:
- respond to enquiries;
- provide demonstrations;
- create and administer accounts;
- enter into contracts;
- provide services;
- verify identity; or
- comply with legal obligations.
If required information is not provided, we may be unable to respond to requests, provide services, enter into agreements, or fulfil contractual obligations.
In most cases there is no statutory requirement to provide personal data to NeuroClo. However, contractual requirements may apply where services are requested.
8. Special Category Data
Some information processed through the NeuroClo platform may constitute special category data under UK GDPR and EU GDPR, including health information.
Where NeuroClo acts as a processor, such information is processed solely:
- on documented instructions from healthcare providers;
- pursuant to Article 28 UK GDPR and/or EU GDPR;
- under applicable contractual safeguards; and
- in accordance with applicable healthcare privacy laws.
Healthcare providers are responsible for identifying and relying upon the appropriate lawful basis and relevant Article 9 condition for processing patient health information.
Healthcare Provider Responsibilities
Healthcare providers are responsible for:
- determining the lawful basis for processing patient information;
- satisfying any applicable Article 9 condition;
- providing required privacy notices;
- obtaining required consents or authorisations;
- maintaining the accuracy of patient records; and
- complying with applicable healthcare and privacy laws.
NeuroClo processes patient information on behalf of healthcare providers in accordance with applicable agreements and documented instructions.
9. AI-Assisted Features
NeuroClo may offer optional or integrated AI-assisted features including:
- Speech-to-text transcription (AWS-hosted, where enabled);
- Clinical note assistance;
- Document summarisation;
- Search and retrieval functions;
- Workflow assistance; and
- Other machine-assisted functionality using large language models and related AI services hosted by Amazon Web Services or other approved providers.
Where these features are enabled by a customer:
- AI-generated content is intended solely to assist healthcare professionals.
- AI-generated content does not replace professional clinical judgement.
- Healthcare professionals remain responsible for reviewing, editing, and approving AI-generated content before relying upon it or incorporating it into a medical record.
- AI-generated content may contain errors, omissions, or inaccuracies and should not be relied upon without appropriate human review.
- NeuroClo implements contractual, technical, and organisational safeguards when engaging third-party AI service providers.
- AI providers process data to deliver the contracted services and in accordance with applicable laws, contracts, BAAs/DPAs, and customer instructions.
- Customer and patient data is not used to train publicly available AI models unless expressly authorised by the customer in writing. Customers should review the relevant product documentation, DPA, and BAA for the AI features they enable.
NeuroClo does not use personal data for solely automated decision-making that produces legal or similarly significant effects on individuals unless otherwise disclosed.
10. Cookies and Similar Technologies
NeuroClo uses cookies and similar technologies on our website.
Necessary Cookies
Used for:
- Security;
- Authentication;
- Session management; and
- Core website functionality.
These cookies are generally required for the website to function and do not require consent where applicable law permits.
Analytics Cookies
Used to understand website usage and improve performance. We may use:
- Google Analytics; and
- Vercel Analytics.
These tools may collect information such as IP address, device/browser details, pages visited, and approximate location. Where required by law, we obtain consent before placing non-essential analytics cookies.
Marketing Cookies
We may use marketing-related cookies for attribution, campaign measurement, and website optimisation. We do not currently use third-party cross-site behavioural advertising cookies. Further detail is in our Cookie Policy.
Managing Cookies
You can control cookies through your browser settings and, where available, through any cookie preference tools we provide on the website. Blocking some cookies may affect website functionality.
Where required by law, NeuroClo obtains consent before placing non-essential cookies on a user’s device.
11. Marketing Communications
NeuroClo may send:
- Product announcements;
- Service updates;
- Educational materials;
- Invitations to events;
- Newsletters;
- Promotional offers; and
- Other marketing communications.
Where required by law, we will obtain consent before sending marketing communications.
Because NeuroClo is a B2B service, we may also rely on legitimate interests and, where UK PECR soft opt-in rules apply, send marketing about similar products or services to existing customers or individuals whose details were obtained in connection with a sale or negotiations for a sale, provided a clear unsubscribe option is offered at collection and in each message.
Individuals may unsubscribe at any time using the unsubscribe mechanism provided in communications or by contacting us at hello@neuroclo.com.
Service-related communications necessary to provide services may continue even where marketing communications have been declined.
12. Sharing Personal Information
NeuroClo does not sell personal information.
We may share information with the following categories of recipients.
Service Providers and Subprocessors
Including providers of:
- Cloud infrastructure;
- Hosting services;
- Analytics services;
- Email and communications services;
- Security monitoring services;
- Customer support services;
- Video conferencing services;
- Speech recognition and transcription services;
- AI infrastructure and machine learning services;
- Payment and billing services; and
- Professional advisory services.
NeuroClo enters into written agreements with appropriate subprocessors where required by law and maintains contractual safeguards relating to confidentiality, security, and privacy.
A current list of subprocessors is published at Subprocessors.
Healthcare Providers
Where information is processed on behalf of healthcare providers, authorised personnel acting on behalf of those providers may access information in accordance with applicable laws and agreements.
Corporate Transactions
Information may be transferred in connection with:
- Mergers;
- Acquisitions;
- Financing transactions;
- Reorganisations;
- Asset sales; or
- Similar corporate transactions.
Legal Requirements
We may disclose information where reasonably necessary to:
- Comply with legal obligations;
- Respond to lawful requests;
- Protect rights and property;
- Protect safety and security;
- Prevent fraud or misuse; or
- Enforce agreements.
13. International Transfers
Personal data may be transferred to and processed in countries outside the United Kingdom, European Economic Area, or an individual’s home jurisdiction, including the United States where Amazon Web Services and other providers operate.
Where such transfers occur, NeuroClo relies upon appropriate legal safeguards, including:
- UK International Data Transfer Agreements (IDTAs);
- The UK Addendum to the EU Standard Contractual Clauses;
- European Commission Standard Contractual Clauses (SCCs);
- Adequacy decisions; or
- Other lawful transfer mechanisms permitted by applicable law.
A copy of applicable transfer safeguards may be requested using the contact details below, subject to confidentiality, legal, security, and commercial limitations.
14. Security
NeuroClo implements technical and organisational measures designed to safeguard information, including:
- Encryption in transit;
- Encryption at rest;
- Role-based access controls;
- Least-privilege access controls;
- Audit logging;
- Security monitoring;
- Backup and recovery procedures;
- Infrastructure security controls;
- Vulnerability management processes; and
- Workforce access controls.
NeuroClo maintains a risk-based security programme. Security measures are regularly reviewed, assessed, tested, and updated to reflect changes in technology, emerging threats, customer requirements, applicable legal obligations, and organisational risk assessments.
While no system can guarantee absolute security, NeuroClo implements measures designed to protect personal data from unauthorised access, disclosure, alteration, and destruction.
15. Data Retention
NeuroClo retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Website enquiries, business communications, demo requests, and related records may be retained for up to seven (7) years, unless a longer retention period is required by law, contractual obligations, or regulatory requirements, or unless earlier deletion is requested and we are able to comply.
Healthcare information processed on behalf of healthcare providers is retained according to:
- Customer instructions;
- Contractual obligations;
- Applicable laws; and
- Regulatory requirements.
16. Children’s Privacy
NeuroClo’s website is not directed to children. NeuroClo does not knowingly collect personal information through its website from children under the age of 13.
Healthcare providers may lawfully treat children and use the NeuroClo platform in connection with that care. In those cases, NeuroClo processes related information solely as a processor (or equivalent role) on the healthcare provider’s instructions. The patient relationship and any parental or guardian consent requirements remain with the healthcare provider.
17. Your Privacy Rights
Subject to applicable law, individuals may have rights including:
- Access;
- Correction;
- Rectification;
- Restriction of processing;
- Erasure;
- Data portability;
- Objection to processing;
- Withdrawal of consent; and
- Complaint to a supervisory authority.
To exercise rights relating to information NeuroClo controls (for example, website or business contact data), contact hello@neuroclo.com.
To exercise rights relating to patient or healthcare platform data, contact your healthcare provider. If you contact NeuroClo instead, we will direct you to your provider and may forward your request to them.
Individuals located in the United Kingdom may lodge a complaint with the Information Commissioner’s Office (ICO) at https://ico.org.uk/.
Individuals located in the European Economic Area may also lodge complaints with the supervisory authority in their country of residence, workplace, or location of the alleged infringement.
18. U.S. State Privacy Rights
Residents of certain U.S. states, including California, Colorado, Virginia, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Jersey, New Hampshire, Nebraska, Tennessee, Minnesota, and Maryland, may have additional rights under applicable privacy laws.
These rights may include:
- Access;
- Correction;
- Deletion;
- Data portability;
- Appeals;
- Opt-out rights (including opt-out of sale or sharing of personal information, where applicable); and
- Restrictions on certain forms of processing, including sensitive personal information where provided by law.
NeuroClo does not sell personal information and does not share personal information for cross-context behavioural advertising as those terms are commonly defined under California law.
We may collect categories of personal information described in Section 5, including identifiers, commercial information, internet or electronic network activity, professional information, and, when acting for healthcare providers, health-related information. Categories disclosed to service providers are described in Section 12.
To submit a request, email hello@neuroclo.com. We may need to verify your identity before fulfilling a request. You may use an authorised agent where permitted by law. We will not discriminate against you for exercising privacy rights.
Patient requests concerning healthcare platform data should be directed to the relevant healthcare provider as described in Sections 4 and 17.
19. Automated Decision-Making
NeuroClo does not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals unless specifically disclosed to the relevant customer or individual and supported by an appropriate legal basis.
20. Medical Disclaimer
NeuroClo provides software and technology services.
NeuroClo does not provide medical advice, diagnosis, treatment, or healthcare services and does not practice medicine.
Content made available through NeuroClo is not a substitute for professional medical advice, diagnosis, treatment, or clinical judgement.
Healthcare decisions should always be made by appropriately qualified healthcare professionals.
If you believe you are experiencing a medical emergency, contact emergency services or seek immediate medical assistance.
21. Changes to this Privacy Policy
NeuroClo may update this Privacy Policy from time to time.
Where changes are material, we may provide notice through:
- Our website;
- Email communications; or
- Other appropriate means.
The version in effect at the time information is collected governs that information unless otherwise required by law.
22. Contact Us
Dealsparrow Limited (trading as NeuroClo)
Privacy enquiries, data protection requests, GDPR requests, and related questions may be directed to:
- Email: hello@neuroclo.com
- Registered Office / Service Address: 395 Clapham Road, London, SW9 9BT, United Kingdom
- Company Number: 07415063
- ICO Registration Number: to be published when available
