Privacy and Personal Data Protection Policy

1. Introduction

We, Neuro Event Labs (NEL), believe that your privacy is critically important. That is why we handle your personal data with great care.

This document describes what personal data we gather, why we gather it, and how we manage and store the data.

Depending on your relationship with us and your location, the entity handling your personal data may vary. Within the European Union, our relevant local entity is Neuro Event Labs Oy; in the UK it is Neuro Event Labs UK Ltd.; and in the United States it is Neuro Event Labs Inc. Personal data may be transferred within our group entities where necessary, and only in accordance with applicable data protection laws and requirements governing international data transfers.

Nelli is a medical device intended for the detection and counting of motor seizures. ‘Recording support and medical review’ refer to services provided by NEL.

2. Our principles for privacy and personal data

We apply these basic principles to all personal data that NEL stores and processes. The data can broadly be categorized as follows:

  • raw media of patients captured by Nelli
  • summary biomarker data derived from the raw media in Nelli
  • data about users and patients (e.g., contact information) within Nelli
  • data used in NEL’s business processes about NEL employees, applicants, business associates, and prospective customers.

In each of these categories, we gather and store only the personal data that is required to provide the recording support and medical review services and conduct NEL’s business operations. Personal data is disclosed only to parties and persons on a need-only basis and only for the purpose it was collected. Each NEL or contractor employee who has access to the personal data is contractually obligated to safeguard and maintain the confidentiality of such data.

No personally-identifiable information is retained or transferred to a third party beyond the data processors mentioned in this document. Where possible, data is stored in such a manner (e.g., encrypted) that the third-party service provider cannot derive any meaningful information from data which is stored or processed by that provider.

We follow all applicable local and regional laws for data protection, including the European General Data Protection Regulation (GDPR) and the US Health Insurance Portability and Accountability Act (HIPAA).

This policy applies to all of our personal data handling activities in all regions with the exception of Section 2.1 which only applies in the United States.

2.1 United States / HIPAA

When we process Protected Health Information (‘PHI’) on behalf of healthcare providers, hospitals, clinics, or other Covered Entities in the United States, we act as a HIPAA Business Associate and comply with applicable provisions of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.

HIPAA protections apply only to information maintained or transmitted in connection with healthcare services provided on behalf of Covered Entities. Information submitted through general website forms, marketing pages, recruitment pages, or non-clinical inquiries may not constitute PHI and may instead be governed by general privacy laws.

We may disclose PHI to subcontractors and service providers who perform functions on our behalf, provided that such parties agree in writing to appropriately safeguard PHI in accordance with HIPAA requirements.

You have the right to request an electronic or paper copy of your PHI maintained by us when required by applicable law and contractual arrangements with the relevant healthcare provider.

In the event of an unauthorized acquisition, access, use, or disclosure of unsecured PHI, we will assess the incident in accordance with the HIPAA Breach Notification Rule and notify affected Covered Entities without unreasonable delay and within applicable legal timeframes.

When PHI is no longer required for the provision of services or legal compliance purposes, we securely delete or destroy PHI using industry-standard methods designed to prevent reconstruction or recovery.

Access to PHI is restricted to authorized personnel who require such access to perform assigned job responsibilities, and Neuro Event Labs applies the HIPAA ‘minimum necessary’ standard to workforce access and disclosures whenever applicable.

We do not use your data for product improvement without your express permission.

Neuro Event Labs maintains Business Associate Agreements or equivalent contractual safeguards with third-party service providers that create, receive, maintain or transmit PHI on our behalf where required under HIPAA.

We have implemented reasonable and appropriate administrative, technical and physical safeguards.

You may file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your privacy rights have been violated. We will not retaliate against any individual for filing a complaint.

NEL does not use cookies to track its users’ usage of the NEL website or Nelli. Cookies are used only for functional purposes, e.g., to manage a secure user session with Nelli.

3. Data we collect, why, and what

3.1 Patient data

Patient data, also known as Protected Health Information (PHI), is collected by NEL in order to provide source material for the recording support and medical review services, which provide an analysis of epilepsy patient recordings which occur in an inpatient (e.g., hospital) or an outpatient (e.g., home) setting. The analysis results in a summary report that aims to track and quantify seizure activity. This report serves as a medical record and presents the results of the analyses requested by the clinician.

Patient data includes:

  • Patient identification: name and birthdate: needed to identify the patient uniquely in the system
  • Optionally, patient contact information, including residence address: needed in the case of outpatient home examination
  • Optionally, caregiver contact information: needed in the case of outpatient home examination
  • Requested examination periods: needed as input for examination planning and execution
  • Raw video, audio and other sensory data from examination periods: needed as input data for analysis
  • Analysis data: the results of automatic and manual analysis. Analysis data may contain automatically-detected neurological events (like seizures) and vital measures (e.g., breathing rhythm and pulse) as well as manually-added annotations
  • Analysis reports: processed summaries of analysis data. Reports are available for online viewing and as PDF documents for Nelli users.

All data collection by the recording support and medical review services is volunteered by the NEL customer (hospital/clinic) and the patient as a part of the healthcare plan of the patient. For the purposes of these services, NEL serves as a data processor and assumes no legal ownership of the raw data. Depending on the jurisdiction, the data may be considered controlled by the customer organization (e.g., in the form of public health records) or the patient.

Derived summary biomarker data is considered to be an artifact of Nelli, which, when detached from its patient profile, is considered to be non-sensitive and non-personally-identifiable. This data can be detached from all identifying characteristics and retained for the continuous improvement and quality assurance of Nelli. Such terms are made in agreement with every NEL customer.

3.2 User data

Users of Nelli are doctors and clinicians from the customer organization, as well as NEL personnel providing the recording support and medical review services for the customer. User data is collected by NEL in order to give controlled and audited access to Nelli.

Data collected about users of Nelli includes:

  • User identification: name and email address. Needed to identify the user in the system.
  • User access rights: patient registers and privileges within registers
  • User activity logs: all user access to the system and read or write of patient data is logged for auditing purposes.

4. Data storage and processing

Nelli consists of dedicated recording equipment (Personal Recording Unit - PRU), a cloud-based server infrastructure for data analysis, and a web-based dashboard for viewing the results of analysis.

The PRU is designed by NEL using industry-standard components and security measures to protect collected patient media before sending it to the cloud for processing. Media on the PRU is encrypted at rest and in transit, with temporary storage only. Additionally, the hard drive is also encrypted.

Nelli is implemented using Amazon Web Services (AWS). AWS as a data processor uses the shared security responsibility model and is compliant with HIPAA requirements for PHI.

Personal data is encrypted at rest in AWS cloud services and transmitted over secure channels (TLS 1.2/TLS 1.3) between data processing steps.

Data storage and processing are done in a private network with no public internet access.

Personal data is stored and processed in the most suitable AWS data center in relation to customer operations.

4.1 Automatic deletion of certain clinically non-relevant recordings

Our medical review service is designed to identify and document clinically relevant events from audio/video recordings. In routine clinical use, any recording segment that is deemed not to contain clinically relevant material will be automatically and permanently deleted approximately 90 days after the results have been shared with the treating clinician and the order status is ‘Completed’; or 180 days after the recording period has ended and the order status is ‘Processing’. No automatic deletion will take place if the patient has given their consent for the use of their data for our research and development purposes, or if the patient was monitored in the context of a clinical trial.

5. Personal data we collect in NEL business processes, why, and what

5.1 NEL business associates and prospective customers

NEL business associates and prospective customers may contact NEL via the NEL website (or email) to ask questions and request more information about NEL’s products and services. NEL stores the email address of the contacting person and any other contact information that has been disclosed as part of the request. This contact information enables NEL to respond to the request.

This information is kept on file at least one year or as long as there is an active dialogue ongoing with the person.

5.2 NEL employees

Employees’ personal data is used to manage the employee-employer relationship. NEL collects and stores personal data that is needed to manage this relationship and is partially based on legal obligations, in addition to the information that is required in the company processes (payroll, occupational healthcare, insurance, performance management, etc.).

Employee data is stored during the employment period. Local legislation requires archival of employee data after employment has ended.

5.3 Applicants

Applicant personal data is used solely for the purposes of the recruitment and employee selection process of Neuro Event Labs. By applying, the applicant consents to the processing and storing of their data in the applicant CV database.

The collected data includes some or all of the following:

  • applicant’s name, birthdate, and contact information
  • education, work history, and information related to professional skills
  • applicant’s expectations of the applied position
  • job application with the attachments (e.g., CV, photo, certificates) and any other information provided by the applicant

Additionally, the evaluations of the applicant’s suitability for the position and the possible recruitment assignment are stored in the register.

An application will be kept on file for a maximum of six (6) months from the application date. During this period, the application can be reviewed and used to fill open positions. After 6 months, the data will be deleted permanently. Upon the applicant’s request, the data will be removed from the file prior to that date.

6. NEL business data storage and processing

The service provider processing and storing NEL business data is Google, namely, Gmail and Google Drive, which are used in daily business operations. Please refer to Google’s Privacy Policy for more information.

7. Right to verify, correct, stop data processing, and/or remove personal data

In compliance with the European General Data Protection Regulation, everyone is entitled to verify the data regarding him/her that is contained in the personal data file.

Furthermore, the data subject is entitled to request rectification of erroneous or incomplete data contained in the personal data file. The request for rectification shall identify the error to be rectified, and provide the correct information.

Also, the data subject has the right to withdraw his/her consent about the use and processing of his/her personal data and ask for removal of the data. If the data subject requests the removal of their data, all data will be removed without undue delay. The request should be made primarily to the data controller. The data controller (e.g., the hospital) then instructs the data processor (NEL) to take the required action. Removal of the data may have limitations from other legislation that requires retention of the data even after processing has been stopped for the purpose it has been gathered.

Requests shall be made in writing, e.g., by email. The NEL Data Protection Officer (DPO) can be contacted at: dpo@neuroventlabs.com

8. Changes to this Privacy and Personal Data Protection Policy

We will continue to evaluate these policies as we update our services, and we may make changes to these policies accordingly. We will post any changes here and revise the last updated date above. If we make significant changes to policies concerning patient and uses of personal data in Nelli, we will notify affected parties as required by the law.

This policy was last updated on 2 September 2026.

9. Questions About this Privacy and Security Policy

If you have any questions about this Privacy and Security Policy, you can contact us at: contact@neuroeventlabs.com.

For more specific matters, you can use contacts listed in Contact Information.

10. Contact Information

Security Officer: Andrew Knight, security@neuroventlabs.com

Data Privacy Officer: Heidi Hinkka, dpo@neuroventlabs.com