1. Who we are
Neuridion ("we", "us") is operated by Neuridion, registered at [TO BE ADDED], Germany. We provide an AI-assisted post-market surveillance screening platform for medical device manufacturers and their regulatory teams.
2. What data we collect
- Account data: email address, full name, company name
- Device profiles: device names, EMDN codes, intended use descriptions you enter
- Search data: search queries, date ranges, results, AI filter decisions
- Generated reports: HTML, PDF and Excel reports stored on our servers
- Usage data: page views, feature usage, session timestamps (audit log)
- Technical data: IP address, browser/OS (user-agent), session cookies
- Billing data: processed by Stripe; we do not store card details
3. Why we process your data
- To provide and operate the Neuridion platform
- To generate, store and deliver FSN search reports
- To manage your account, subscription and billing
- To send transactional notifications (search completion, account security)
- To maintain security, traceability and decision-history records used to provide the service
- To prevent fraud and abuse (rate limiting, security monitoring)
4. Legal basis
- Art. 6(1)(b) GDPR — Contract: processing necessary to deliver the service you subscribed to
- Art. 6(1)(f) GDPR — Legitimate interest: security monitoring, fraud prevention, improving service reliability
- Art. 6(1)(a) GDPR — Consent: optional analytics cookies (only where you have accepted)
- Art. 6(1)(c) GDPR — Legal obligation: only where a specific obligation applicable to us requires the processing; customer regulatory duties do not automatically establish our legal basis
5. Who we share data with
- Supabase (EU region): database and authentication infrastructure
- Anthropic (US): AI filtering of FSN content — see Section 8 for international transfers
- PDFShift (FR): PDF report generation
- Render (US): application hosting — see Section 8
- Stripe (US): payment processing — see Section 8
- Resend (US): transactional email delivery
- Upstash (US): rate limiting infrastructure — see Section 8
We do not sell your data to third parties.
6. Data retention
- Search runs & reports: retained under the platform retention policy and applicable service agreement. On account closure, account identifiers may be anonymised while regulated traceability records are retained. Confirm the agreed period before relying on Neuridion for record retention
- Account data: deleted within 30 days of account deletion request, subject to the retention period above
- Audit logs: retained under the security and traceability schedule stated in the applicable service agreement; the customer remains responsible for determining its own MDR/IVDR and QMS retention requirements
- Marketing communications: until consent is withdrawn
7. Your rights (GDPR)
Under GDPR you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion ("right to be forgotten")
- Portability: receive your data in machine-readable format
- Objection: object to processing based on legitimate interest
- Restriction: request restricted processing in certain circumstances
- Complaint: lodge a complaint with your supervisory authority — in Germany: Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI)
To exercise your rights, use the account settings page or contact us at info@neuridion.eu.
8. International transfers
Some of our sub-processors are based outside the EU/EEA. Where personal data is transferred to the US (Anthropic, Render, Stripe, Resend, Upstash), we rely on the EU Standard Contractual Clauses (SCCs) as the transfer mechanism under Art. 46 GDPR. Screening requests are intended to contain device-profile fields and relevant public source text, not customer patient or clinical records. Public safety and adverse-event records can nevertheless contain incidental personal or sensitive information, so source-specific minimisation and transfer controls remain necessary.
9. Cookies
We use essential cookies required to authenticate your session. Optional analytics cookies are only set if you consent via the cookie banner. You can withdraw cookie consent at any time via the "Manage cookies" link in the footer.
| Cookie | Provider | Purpose | Duration | Type |
|---|
| sb-*-auth-token | Supabase (1st party) | Authentication session JWT | Session | Essential |
| sb-*-auth-token.0/.1 | Supabase (1st party) | Chunked auth token (large JWTs) | Session | Essential |
| __stripe_mid | Stripe (3rd party) | Fraud prevention identifier | 1 year | Essential |
| __stripe_sid | Stripe (3rd party) | Fraud prevention session | 30 minutes | Essential |
| neuridion_cookie_consent | Neuridion (1st party) | Stores your cookie preference | 1 year | Essential |
No third-party tracking, marketing, or advertising cookies are used.
10. Automated decision-making (Art. 22 GDPR)
Neuridion uses AI to classify Field Safety Notices as "relevant", "uncertain", or "excluded" relative to your device profile. This constitutes automated processing but does not produce legal or similarly significant effects on individuals — it classifies publicly available regulatory notices, not personal data.
All AI classifications are advisory. The manufacturer defines the qualified and authorised reviewer, approval meaning, and downstream regulatory decision under its own procedure. If you wish to disable AI-assisted filtering for your account, contact us at info@neuridion.eu. For full details on our AI system, see the AI Transparency page.
11. Data Protection Officer
Based on our current processing activities and scale, a Data Protection Officer (DPO) has not been formally appointed under Art. 37 GDPR. We keep this assessment under review as our organisation grows. For all data protection inquiries, please contact us at info@neuridion.eu.