Privacy policy

Privacy that reflects the sensitivity of harm reduction data.

neo360 works in environments where information can be highly sensitive. Our approach is therefore based on clear responsibilities, data minimisation, appropriate security and transparency about how information is used.

neo360 LimitedCompany No. 06686993UK & international deployments
neo360Privacy at a glance
Clear rolesController and processor responsibilities defined
Data minimisationOnly information needed for a defined purpose
ProtectedTechnical and organisational safeguards
TransparentRights and choices explained clearly

Publication review recommended

This draft modernises neo360's existing App Privacy Policy and broadens it for the corporate website and customer deployments. Before publication, deployment-specific hosting locations, sub-processors, international-transfer arrangements, retention periods and privacy contacts should be checked against current contracts and information-governance documentation.

Privacy, in straightforward terms.

Different information is handled differently depending on whether you are visiting our website, contacting neo360, administering a customer account or using a commissioned neo360 deployment.

Know who is responsible

neo360's role depends on the context. For direct business contacts we determine how information is used; in customer deployments the commissioner or service may determine the purpose and instructions.

Collect what is needed

We aim to avoid unnecessary personal information and support configurable anonymity where a service model requires it.

Protect sensitive information

Access controls, encrypted connections, logging, monitoring and other safeguards form part of the security approach.

Respect individual rights

People may have rights to information, access, correction, deletion, restriction, objection and portability, subject to the applicable law and processing context.

Who is responsible for personal information?

The answer depends on why the information is being processed.

neo360 Limited is registered in England and Wales under company number 06686993. For information provided directly to neo360 through enquiries, support, contractual discussions or other business interactions, neo360 will normally determine why and how that information is used.

Website & direct contact

neo360 as controller

Where you contact neo360 directly, we may act as controller for business contact information, correspondence, support records and necessary website/security information.

Customer deployments

Deployment-specific roles

When a service, commissioner or public health programme uses neo360 to record information about service users, the relevant organisation may be the controller and neo360 may process information on its documented instructions. The contract and local privacy notice should explain the exact arrangement.

Because neo360 is deployed internationally, controller, processor and privacy-right arrangements can differ by jurisdiction. The applicable customer agreement and local privacy notice take precedence for deployment-specific processing.

Information we may process

Not every category applies in every context or deployment.

Contact & professional details

Name, work email, organisation, role, telephone number and information included in enquiries, support requests or contractual discussions.

Technical information

Device, browser, IP address, security logs, session information and other technical details needed to operate and protect services.

Account & administration data

User identifiers, organisation, permissions, access history, service configuration and administrative records associated with customer use.

Service-user information

Depending on the commissioned module, this can include demographics, harm-reduction activity, drug use, BBV information, treatment, risk, referrals and other health-related or special-category information.

Configurable anonymity

Some neo360 workflows are specifically designed so customers can determine how much identifying information is required. For example, needle exchange functionality can be configured to be as anonymous as the service requires. The appropriate data set should be determined by the service, commissioner, local policy and applicable law.

How and why information is used

Every use of personal information should have a defined purpose and an appropriate legal basis.

Provide and administer services

Set up accounts, configure deployments, provide support, maintain access, respond to requests and deliver contractual services.

Operate and protect systems

Maintain availability, investigate faults, protect security, prevent misuse, maintain logs and support resilience and recovery.

Support commissioned workflows

Process information in accordance with the functionality configured by a customer and, where neo360 acts as processor, the customer's documented instructions.

Reporting and service improvement

Provide authorised reports, extracts and operational insight, and improve neo360 products and services using information in a lawful and appropriately minimised form.

Lawful bases

Depending on the context, processing may rely on performance of a contract, steps requested before entering a contract, compliance with a legal obligation, legitimate interests, consent or another lawful basis available under the applicable data-protection law. Where special-category health information is processed, an additional legal condition must also apply. In commissioned deployments, the relevant controller determines and documents the appropriate legal bases.

Sharing, suppliers and security

Personal information should only be accessible or disclosed for a defined and authorised reason.

neo360 does not sell personal information. Information may need to be made available to authorised customer users, contracted technology or support providers, professional advisers, regulators or public authorities where this is necessary, contractually authorised or required by law. Where suppliers process personal information on our behalf, appropriate contractual and security controls should apply.

Security measures

  • Controlled user access and permission management.
  • Encryption for data transferred between supported devices, services and hosting environments.
  • Logging, monitoring and auditability appropriate to the service.
  • Backup, continuity and recovery arrangements.
  • Security, vulnerability and change-management processes.
  • Contractual controls over authorised processors and support access.

Security controls are reviewed and applied according to the relevant deployment, contractual requirements and risk profile. No internet-connected service can guarantee absolute security, but neo360 applies appropriate technical and organisational measures intended to reduce risk and protect information.

International deployments require clear data arrangements.

neo360 has deployment experience across the UK, Canada and United States, with previous deployments in Australia. Hosting, access and transfer arrangements should always be defined for the specific programme and jurisdiction.

Hosting location

The approved hosting region and data residency requirements should be specified for each customer deployment.

International transfers

Where information is transferred across borders, the controller and neo360 should ensure that the required legal safeguards are in place.

Contractual clarity

Customer agreements, processor terms and local privacy notices should identify the relevant parties, purposes and responsibilities.

Retention and deletion

Information should not be kept for longer than there is a justified reason to retain it.

Retention periods can differ depending on the type of information, the relevant customer contract, statutory requirements, clinical or service-record requirements, audit needs, limitation periods and the purpose for which the information was collected.

For customer-controlled service-user information, retention and deletion requirements should be agreed with and directed by the relevant controller. For neo360's own business records, we retain information only for as long as reasonably required for the purpose, legal obligations, dispute management and legitimate business administration, then securely delete or anonymise it where appropriate.

Your data-protection rights

Rights vary according to jurisdiction, legal basis and whether neo360 or one of our customers is responsible for the information.

01

Be informed

Understand what information is used, why, by whom and for how long.

02

Access

Request a copy of personal information where the right applies.

03

Correction

Ask for inaccurate or incomplete information to be corrected.

04

Deletion

Ask for erasure where the legal conditions for deletion are met.

05

Restriction

Ask for use of information to be limited in certain circumstances.

06

Object

Object to particular processing where the relevant law provides that right.

07

Portability

Receive certain information in a reusable format where applicable.

08

Withdraw consent

Where processing relies on consent, withdraw it without affecting earlier lawful processing.

If your request relates to information recorded by a harm-reduction service or commissioner using neo360, that organisation may be the appropriate controller to contact. neo360 will support its customers in responding to rights requests where required by contract and law.

Website, cookies and links

Online services may need limited technical information to function securely and reliably.

The neo360 website may process basic technical information needed for operation, security and performance. Any optional analytics, advertising or similar technologies should be described clearly and, where the applicable law requires it, activated only after an appropriate choice or consent.

Where the website links to another organisation's website or service, that organisation's privacy practices apply once you leave neo360's site. This policy does not control how independent third parties process information on their own services.

Changes to this policy

Privacy information should remain current as services, suppliers and legal requirements change.

We may update this policy from time to time. Material changes should be communicated where required, and the current version should show its effective date. Deployment-specific privacy notices may also be updated by the relevant customer or controller.

Document statusDraft for review
VersionDraft 1.0
PreparedAugust 2026

Questions about privacy?

For privacy questions about information neo360 controls directly, contact us. If your question relates to a service-user record held within a customer deployment, we may direct you to the relevant service or commissioner as controller.

support@neo360.uk

Talk to neo360

Tell us about your service, programme or monitoring requirements. This prototype form does not submit data.