Know who is responsible
neo360's role depends on the context. For direct business contacts we determine how information is used; in customer deployments the commissioner or service may determine the purpose and instructions.
neo360 works in environments where information can be highly sensitive. Our approach is therefore based on clear responsibilities, data minimisation, appropriate security and transparency about how information is used.
This draft modernises neo360's existing App Privacy Policy and broadens it for the corporate website and customer deployments. Before publication, deployment-specific hosting locations, sub-processors, international-transfer arrangements, retention periods and privacy contacts should be checked against current contracts and information-governance documentation.
Different information is handled differently depending on whether you are visiting our website, contacting neo360, administering a customer account or using a commissioned neo360 deployment.
neo360's role depends on the context. For direct business contacts we determine how information is used; in customer deployments the commissioner or service may determine the purpose and instructions.
We aim to avoid unnecessary personal information and support configurable anonymity where a service model requires it.
Access controls, encrypted connections, logging, monitoring and other safeguards form part of the security approach.
People may have rights to information, access, correction, deletion, restriction, objection and portability, subject to the applicable law and processing context.
The answer depends on why the information is being processed.
neo360 Limited is registered in England and Wales under company number 06686993. For information provided directly to neo360 through enquiries, support, contractual discussions or other business interactions, neo360 will normally determine why and how that information is used.
Where you contact neo360 directly, we may act as controller for business contact information, correspondence, support records and necessary website/security information.
When a service, commissioner or public health programme uses neo360 to record information about service users, the relevant organisation may be the controller and neo360 may process information on its documented instructions. The contract and local privacy notice should explain the exact arrangement.
Because neo360 is deployed internationally, controller, processor and privacy-right arrangements can differ by jurisdiction. The applicable customer agreement and local privacy notice take precedence for deployment-specific processing.
Not every category applies in every context or deployment.
Name, work email, organisation, role, telephone number and information included in enquiries, support requests or contractual discussions.
Device, browser, IP address, security logs, session information and other technical details needed to operate and protect services.
User identifiers, organisation, permissions, access history, service configuration and administrative records associated with customer use.
Depending on the commissioned module, this can include demographics, harm-reduction activity, drug use, BBV information, treatment, risk, referrals and other health-related or special-category information.
Some neo360 workflows are specifically designed so customers can determine how much identifying information is required. For example, needle exchange functionality can be configured to be as anonymous as the service requires. The appropriate data set should be determined by the service, commissioner, local policy and applicable law.
Every use of personal information should have a defined purpose and an appropriate legal basis.
Set up accounts, configure deployments, provide support, maintain access, respond to requests and deliver contractual services.
Maintain availability, investigate faults, protect security, prevent misuse, maintain logs and support resilience and recovery.
Process information in accordance with the functionality configured by a customer and, where neo360 acts as processor, the customer's documented instructions.
Provide authorised reports, extracts and operational insight, and improve neo360 products and services using information in a lawful and appropriately minimised form.
Depending on the context, processing may rely on performance of a contract, steps requested before entering a contract, compliance with a legal obligation, legitimate interests, consent or another lawful basis available under the applicable data-protection law. Where special-category health information is processed, an additional legal condition must also apply. In commissioned deployments, the relevant controller determines and documents the appropriate legal bases.
Personal information should only be accessible or disclosed for a defined and authorised reason.
neo360 does not sell personal information. Information may need to be made available to authorised customer users, contracted technology or support providers, professional advisers, regulators or public authorities where this is necessary, contractually authorised or required by law. Where suppliers process personal information on our behalf, appropriate contractual and security controls should apply.
Security controls are reviewed and applied according to the relevant deployment, contractual requirements and risk profile. No internet-connected service can guarantee absolute security, but neo360 applies appropriate technical and organisational measures intended to reduce risk and protect information.
neo360 has deployment experience across the UK, Canada and United States, with previous deployments in Australia. Hosting, access and transfer arrangements should always be defined for the specific programme and jurisdiction.
The approved hosting region and data residency requirements should be specified for each customer deployment.
Where information is transferred across borders, the controller and neo360 should ensure that the required legal safeguards are in place.
Customer agreements, processor terms and local privacy notices should identify the relevant parties, purposes and responsibilities.
Information should not be kept for longer than there is a justified reason to retain it.
Retention periods can differ depending on the type of information, the relevant customer contract, statutory requirements, clinical or service-record requirements, audit needs, limitation periods and the purpose for which the information was collected.
For customer-controlled service-user information, retention and deletion requirements should be agreed with and directed by the relevant controller. For neo360's own business records, we retain information only for as long as reasonably required for the purpose, legal obligations, dispute management and legitimate business administration, then securely delete or anonymise it where appropriate.
Rights vary according to jurisdiction, legal basis and whether neo360 or one of our customers is responsible for the information.
Understand what information is used, why, by whom and for how long.
Request a copy of personal information where the right applies.
Ask for inaccurate or incomplete information to be corrected.
Ask for erasure where the legal conditions for deletion are met.
Ask for use of information to be limited in certain circumstances.
Object to particular processing where the relevant law provides that right.
Receive certain information in a reusable format where applicable.
Where processing relies on consent, withdraw it without affecting earlier lawful processing.
If your request relates to information recorded by a harm-reduction service or commissioner using neo360, that organisation may be the appropriate controller to contact. neo360 will support its customers in responding to rights requests where required by contract and law.
Online services may need limited technical information to function securely and reliably.
The neo360 website may process basic technical information needed for operation, security and performance. Any optional analytics, advertising or similar technologies should be described clearly and, where the applicable law requires it, activated only after an appropriate choice or consent.
Where the website links to another organisation's website or service, that organisation's privacy practices apply once you leave neo360's site. This policy does not control how independent third parties process information on their own services.
Privacy information should remain current as services, suppliers and legal requirements change.
We may update this policy from time to time. Material changes should be communicated where required, and the current version should show its effective date. Deployment-specific privacy notices may also be updated by the relevant customer or controller.
For privacy questions about information neo360 controls directly, contact us. If your question relates to a service-user record held within a customer deployment, we may direct you to the relevant service or commissioner as controller.