This policy covers neondeerdata.com and the Neon Deer platform at app.neondeerdata.com, including its associated apps, operated by Neon Deer Data Labs Inc. Other websites and platforms we operate have their own privacy policies:
Information we process
Customer data
Neon Deer processes customer data to provide the platform’s services, following customers’ instructions under the DPA. This includes contact and business records, workflow information, and service results.
Account and usage information
- Account information: contact details, sign-in information, workspace memberships, and records of agreement acceptance.
- Billing information: billing contacts, subscriptions, and invoices. The checkout provider handles payment details under its own terms.
- Communications: information provided through forms, bookings, email, and support requests.
- Technical and usage information: website visits, service activity, diagnostic reports, IP addresses, browser and device information, and approximate location.
How we use information
We use information to provide and secure the service, carry out customer instructions, manage accounts and billing, respond to inquiries, improve our services, and meet legal obligations.
We do not sell or rent personal data. We do not use the contents of customer CRM or workflow records for our own marketing. We may use account details and service usage to send users relevant product information and offers, including information about paid plans. Recipients can opt out of marketing messages by contacting us or using the unsubscribe option in a message.
Workspace administrators can turn off the use of workflow usage statistics for product improvement in the platform’s privacy settings. This is on by default. Turning it off does not stop the activity records needed to provide and secure the service.
Where data-protection law requires a legal basis, we use account and business-contact information to fulfill our contracts, comply with legal obligations, or pursue legitimate interests in providing, securing, and improving our services and communicating with customers. We obtain consent where required, including for marketing.
AI features
Our AI features may use Anthropic, OpenAI, and Google Gemini to process relevant customer data and generate results. The subprocessor list describes their roles and processing locations.
AI assessments process the records being reviewed. Related records and notes are included only when the corresponding privacy settings are enabled. A separate setting controls whether details extracted from notes are retained for reuse in later assessments. These options are enabled by default; workspace administrators can disable each in the platform’s privacy settings.
We use AI services under terms that restrict use of customer data to train general-purpose AI models. Providers may retain and review information for security, abuse monitoring, and legal compliance, including improving systems that enforce their usage policies.
Domain checks
Duplicate detection sends company website domains and non-personal-email-provider domains from CRM email addresses to our Checkredirects.io service to check redirects. These requests contain domains, not complete email addresses or CRM records. Domain checks are enabled by default when available through your plan or a Checkredirects.io API key you provide. Workspace admins can turn them off on any plan. Both services are operated by Neon Deer Data Labs Inc.
Third-party services
Our providers page lists platform subprocessors, website vendors, and other recipients, their purposes and locations. Customer-connected services such as Attio receive information under the customer’s own account arrangements. We may also disclose information to professional advisers, a successor in a business transaction, or authorities where required by law.
International processing
Our primary platform database is in the United States. Our team may access customer data from the United States, Brazil, and Mexico. Service providers may process information in other countries, as described in our subprocessor list. Those countries may have different privacy laws, and information may be subject to lawful government access.
Where required, we use safeguards for international transfers, including the EU, UK, and Swiss contractual protections described in our DPA. Details or copies of the applicable safeguards are available on request, with confidential information removed where necessary.
Cookies and browser storage
We and our providers use cookies and similar technologies to support sign-in, remember preferences, understand website use, and provide features such as forms and embedded media. Embedded services may receive browser and device information when they load.
How long we keep information
The main retention periods for information stored in the Neon Deer platform are:
| Information | Why we keep it | Retention | Example |
|---|---|---|---|
| Temporary copies of CRM information | Compare records, show results for customer review, and preview changes to matching rules without repeatedly retrieving the same information. | Extra information collected for rule previews: one hour. Information used for comparisons: up to 90 days, with shorter periods depending on the task and plan. | A company’s name and website copied during a duplicate detection scan. |
| Details extracted from notes for AI assessments | Reuse relevant details in later assessments without repeatedly processing the same notes, when reuse is enabled. | Up to 24 hours. Deleted when reuse is disabled. | A company’s previous name mentioned in a note, extracted for an AI assessment. |
| Copies of records made before a merge | Help customers review the original information and assist attempts to reconstruct records after a merge. These copies do not undo merges or provide a complete CRM backup. | 90 days, or earlier if the workspace’s pre-merge backup setting is disabled. | The original field values of two records you approved for merging. |
| Field contents showing what changed in a record | Let customers inspect changes made through the platform and investigate unexpected results. | 90 days. The record that an action occurred may remain longer. | A company’s website before and after an update. |
| Detailed service activity | Show workflow activity, investigate failures, and avoid processing the same event twice. | Up to 90 days from the original activity or receipt, with shorter 30- or 45-day periods for some records. Retries and unfinished work do not extend these periods. | When a workflow step ran and whether it succeeded. |
| Monthly usage totals | Track service usage and plan allowances. | 13 months. | How many scans your workspace used that month. |
| CRM field copies and written summaries saved with AI assessments | Explain assessment results and support reuse of recent assessments. | 90 days after the assessment is saved, or earlier through applicable deletion controls. After expiry, this information is unavailable for viewing or reuse and is removed by scheduled cleanup. | The names compared and the AI’s written explanation of their similarities. |
| Assessment scores and reasons that do not contain CRM field values | Preserve assessment outcomes for customer review. | Until removed through an available control or the workspace-deletion process. | A duplicate score and an indication that the names agree. |
| Workflow lookup values | Provide values selected for use in customer workflows. | Until removed through an available control or the workspace-deletion process. | A saved Member Metadata value selected for use in a workflow. |
| Workspace and app settings | Apply the configuration your workspace chooses. | Until removed through an available control or the workspace-deletion process. | Your matching rules and scan schedules. |
| Saved review decisions, including record values kept with decisions that records are not duplicates | Preserve your review choices and avoid repeatedly suggesting rejected matches. | Until removed through an available control or the workspace-deletion process. | Your decision to keep two records separate, along with record values saved with that decision. |
| Credentials used to access connected services | Access connected accounts to perform customer-authorized functions. | While connected. Disconnecting removes the credentials we can use; customers can also revoke access in the connected service. | The authorization token used to access your Attio workspace. |
These periods run from the relevant collection or activity. Newly collected information may have its own retention period; retrying an existing event does not restart its period. Deletion runs periodically and may be delayed by service interruptions.
Account, billing, communications, and security records may need to be kept longer to administer accounts, meet legal requirements, prevent abuse, or resolve disputes. We assess retention and deletion requests based on those purposes, applicable legal periods, and whether the information is still needed.
Access and deletion requests
Workspace administrators can request deletion in the platform. Once the request is accepted, workspace access ends and the deletion process begins without waiting for the paid period to end. We request immediate cancellation of the workspace’s own paid subscription. Deleting one workspace does not cancel a shared-billing subscription used by other workspaces. Cancelling a subscription alone does not delete customer data.
Deletion completes through background processing, including disconnecting services and removing stored data. If a service is unavailable, we retry and use an operator procedure where needed; a billing-service outage does not justify keeping customer data indefinitely. Backup copies and information retained for a justified purpose are handled as described below and in the retention section. Requests already scheduled under the earlier end-of-period process keep their confirmed date unless the administrator requests earlier deletion.
Requests for access to personal information, account deletion, or help with workspace deletion can be sent to privacy@neondeerdata.com. Neon Deer verifies the requester’s identity and authority and handles requests within applicable legal deadlines. A valid privacy deletion request does not have to wait until a paid period ends.
Backup and recovery copies may retain deleted information until their scheduled expiry. During that period, the information is protected from ordinary use, and deletion instructions must be reapplied before restored data is used. Copies held by service providers may follow different retention schedules, depending on the service, account settings, security and abuse-prevention needs, and legal requirements. Deleting information from our platform does not by itself confirm deletion of every provider-held copy. We use applicable deletion controls and request procedures and track remaining copies and justified retention when handling a request. Provider-held customer data remains subject to our obligations under the DPA and applicable law.
We keep limited deletion records separately from database backups to prevent deleted information from returning after a restore. These records are retained while recoverable copies could restore that information and for any additional period required by law. Their retention is reviewed against the backup and recovery-copy inventory.
Data security
We use access controls, encrypted connections, and encryption for stored CRM credentials. We filter common identifiers and secrets from error reports. Our DPA states our security commitments for customer personal data.
Privacy rights
Depending on applicable law, individuals may request access, correction, deletion, portability, or restriction, object to processing, withdraw consent, or complain to the relevant privacy regulator. Withdrawal does not affect earlier lawful processing. Authorized agents and appeals are available where applicable. We do not unlawfully discriminate for exercising these rights.
Age and data restrictions
The platform is intended for business use by people aged 18 or older. Customers must not submit health information. Personal data about anyone under 18 is also prohibited. Suspected submissions of this information should be reported to privacy@neondeerdata.com.
Contact
Privacy requests, questions, or complaints can be sent to privacy@neondeerdata.com; DPA matters can be sent to legal@neondeerdata.com. For personal information in customer records, Neon Deer refers requests to the customer and assists with the response under the DPA.
Neon Deer Data Labs Inc.
100 N Howard St Ste R
Spokane, WA 99201, United States
We give notice of material changes where required. Subprocessor changes follow the DPA notice process.