Skip to content

NeuroBridge® Website Privacy Policy

Effective Date: 21 January 2026
Version: 2.1

At NeuroBridge®, we take data protection seriously. This Privacy Policy explains how we collect, use, share and safeguard personal data when you visit and use our website and online store at neurobridge.co.uk (the “Website”).

If you are using our Neuroinclusion Support (NIS) System at neurobridgeportal.com, please see our separate Portal Privacy Policy.

1. Who We Are

NeuroBridge® Limited is a UK-registered company (Company No. 14895457), operating as the data controller when we determine the purpose and manner of data processing for the Website.

Our registered address is:
Suite 46, 24–28 St. Leonards Road, Windsor, Berkshire, SL4 3BB, United Kingdom
Email: [email protected]

2. What Information We Collect

When you visit the Website, contact us, or place an order, we may collect the following categories of personal data:

  • Website Usage Data: Pages visited, links clicked, approximate location (derived from IP address), referral source, and other browsing/technical information.
  • Device Data: IP address, browser type, operating system, device identifiers, and other technical data collected automatically.
  • Cookie & Consent Data: Your cookie preferences and related consent records.
  • Enquiry & Communications Data: Information you provide when you contact us (e.g., name, email address, company name, message content) including support tickets and feedback.
  • Customer / Order Data (if you purchase from our store): Name, company name, email, billing address, purchase history and other information needed to fulfil an order.
  • Payment Data: Card and payment details are processed by our payment provider. We do not store full card details on the Website.

Our Website is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us immediately.

3. How We Collect Your Data

We collect data through:

  • Direct Input: When you fill in forms, make a purchase, or communicate with us.
  • Automated Collection: Via cookies, server logs, security tools, and analytics.
  • Third Parties: For example, payment providers and embedded services that you choose to interact with.

4. Why We Process Your Data

We process your data to:

  • Operate and secure the Website
  • Respond to enquiries and provide customer support
  • Process orders, take payment, provide receipts and fulfil purchases
  • Maintain business records for accounting, tax and legal compliance
  • Measure Website performance and improve user experience (where analytics are enabled)
  • Send service communications (e.g., transactional emails)

We do not use Website data for profiling or automated decision-making that produces legal or similarly significant effects.

We rely on several lawful bases to process personal data, including:

  • Contractual necessity – to process and fulfil your purchases or respond to requests.
  • Legitimate interests – for website security, fraud prevention, and service improvement.
  • Consent – for non-essential cookies and any processing where consent is required.
  • Legal obligations – for tax, accounting and other legal compliance.

Where consent is our legal basis, you retain the right to withdraw it at any time.

6. Data Sharing

We share personal data only where strictly necessary, for example:

  • Service providers that help us operate the Website (hosting, security, email delivery, analytics and consent management) under appropriate contractual safeguards.
  • Payment providers to process payments.
  • Regulators or law enforcement where legally required.

We do not trade, sell or rent your personal data to ANY third parties.

7. International Transfers

We aim to keep Website processing within the UK and/or the EEA. Some suppliers may process limited metadata outside the UK/EEA (for example, to provide global security or resilience). Where an international transfer occurs, it is safeguarded using recognised mechanisms such as Standard Contractual Clauses (SCCs), the UK IDTA and/or adequacy decisions.

8. Data Retention

We retain personal data for as long as is necessary for the purposes described in this policy.

  • Orders and purchase records are typically retained for a period necessary to comply with tax and accounting obligations.
  • Enquiry records are retained for as long as necessary to respond and manage our relationship.
  • Cookie consent records are retained to demonstrate compliance and to remember your choices.

9. Your Rights

You have several rights under UK GDPR and, as applicable, under EU GDPR, including:

  • Accessing the personal data we hold about you
  • Requesting correction of inaccurate information
  • Asking us to erase your data when appropriate
  • Restricting or objecting to how we process your data
  • Receiving your data in a portable format
  • Withdrawing consent, where applicable
  • Lodging a complaint with the Information Commissioner’s Office (ICO) (UK), or as applicable with your local EU supervisory authority

To exercise any of these rights, email: [email protected].

10. Cookies and Analytics

The Website uses essential cookies to keep the site secure and (where relevant) to support checkout and account functionality.

We may also use optional cookies to improve user experience or analyse usage trends, but only with your explicit consent.

You can change or withdraw consent for functional or marketing cookies on neurobridge.co.uk at any time via the “Cookie settings” link (displayed as a fingerprint icon). Optional cookies are otherwise only loaded after you enabled “Functional” or “Marketing” cookies (or clicked “Accept All”) on our cookie banner.

  • Analytics (Optional) – Analytics tools (such as Google Analytics) may set cookies to create anonymous usage statistics on neurobridge.co.uk; lifespan typically 24 hours – 24 months (depending on the cookie).
  • Functional (Optional) – Third‑party tools (such as YouTube video embeds, fonts, and reCAPTCHA for form protection) may set cookies to enhance Website functionality but are not essential.
  • Consent (Essential, Always Active) – Our consent management platform (Cookiebot) stores your cookie choice so we remember the selection you made in the banner (typically for 12 months).
  • E‑commerce (Essential, Where Used) – If you use the store features, first‑party cookies may be used to keep track of basket/checkout state and help prevent fraud.
  • Security (Essential, Always Active) – Security cookies (e.g. firewall) help protect the Website. These typically expire within 48 hours.

10.2. Cookieless Analytics

  • Cookieless Analytics (No Consent Needed) – Fathom Analytics processes visitor data without cookies on neurobridge.co.uk; uses Extreme EU Isolation where all global traffic is routed through the EU; IP addresses processed in-memory only; no personal data stored. Fathom’s privacy policy.

11. Data Security

We use robust organisational and technical measures to protect Website data, including HTTPS encryption, access controls, and security monitoring.

12. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our Website, services, or legal obligations. Where the changes are significant, we will provide appropriate notice. The most current version will always be available at: www.neurobridge.co.uk/privacy-policy

13. Contacting Us

If you have any concerns about this policy or wish to contact our Data Protection Officer, please reach out:

Data Protection Officer (DPO):
Josh Goodison (ICO-registered contact)
Email: [email protected] (please include “FAO DPO” in the subject line)
Address: NeuroBridge Ltd, Suite 46, 24–28 St. Leonards Road, Windsor, SL4 3BB, UK

13.1. EU Representative

If you are located in the EU/EEA, you may also contact our EU Representative:

Ludovico Saint Amour di Chanaz
Carrer de Malgrat 126, Sobreatico, Barcelona, 08016, Spain
Email: [email protected] (please include “FAO EU Representative” in the subject line)

13.2. Responsible Disclosure Policy

See our Responsible Disclosure Policy for reporting security vulnerabilities.