Last updated: October 24, 2022
to read it carefully.
We provide economic infrastructure for the internet. Businesses of all sizes use our software
and services to accept payments and manage their businesses online. Neural Formula cares about
the security and privacy of the personal data that is entrusted to us.
about you, how we use it, how we share it, your rights and choices, and how you can contact us
about our privacy practices. This Policy also outlines your data subject rights, including the
right to object to some uses of your Personal Data by us. Please visit the Neural Formula
Privacy Center for more information about our privacy practices.
“Neural Formula”, “we”, “our” or “us” means the Neural Formula entity responsible for the collection and use of personal data under
“Personal Data” means any information that relates to an identified or
identifiable individual, and can include information about how you engage with our Services
(e.g. device information, IP address).
“Services” means the products and services that Neural Formula indicates are
covered by this Policy, which may include Neural Formula-provided devices and apps. Our “Business Services” are Services provided by Neural Formula to entities (“Business Users”) who
directly and indirectly provide us with “End Customer” Personal Data in connection with those
Business Users’ own business and activities. Our “End User Services” are those
Services which Neural Formula directs to individuals (rather than entities) so that those
individuals do business directly with Neural Formula. “Sites” means Neural
Formula.com and the other websites that Neural Formula indicates are covered by this Policy.
Collectively, we refer to Sites, Business Services and End User Services as “Services”.
1. Personal data that we collect and how we use and share it
To provide Business Services, we collect, use and share Personal Information from
Representatives of our Business Users (e.g. a business owner). If the Representative is the only
employee of a Business User, please see the End User and End Customer sections to understand
additional ways in which we can collect and use your Personal Data when you use our Services.
Contact us for further information on the legal bases
which we rely on for using (processing) your Personal Data.
a. Personal data that we collect about Representatives
- Registration and Contact Information. If you register for a Neural Formula
account for a Business User (including incorporation of a Business), we collect your name and
account log-in credentials. If you register for an event that Neural Formula organizes or
attends or if you sign up for Neural Formula communications, we collect your registration and
profile information. If you are a Representative of a potential Business User, we receive your
Personal Data from third parties (including data providers) in order to advertise to, market
and communicate with you as described further below and in Section 2.
- Identification Information. If you are an owner of a Business User or you are
expected to be a shareholder, officer or director of a Business User, we require that you
provide your contact details, such as name, postal address, telephone number, and email
address to fulfill our financial partner and regulatory requirements. We may also collect
financial and personal information about you, such as your ownership interest in the Business
User, your date of birth and government identifiers associated with you and your Business User
(such as your social security number, tax number, or Employer Identification Number). You may
also choose to provide bank account information.
b. How we use and share personal data of Representatives
We generally use Personal Data of Representatives to provide the Business Services to the
associated Business Users, as well as for the purposes described.
- Business Services. We use and share Personal Data of Representatives with
Business Users to provide the Services. For users of our tax Business Services, we may use
your Personal Data to file taxes on behalf of your associated Business User. If your Business
User uses Atlas, we may use your Personal Data to submit forms to the IRS on your behalf and
to file documents with other governmental authorities (e.g. articles of incorporation in your
state of incorporation).
- We share data with parties directly authorized by a Business User to receive Personal Data
(e.g. financial partners servicing the financial product). The use of Personal Data by a
some cases our Business Service will require us to submit your Personal Data to a
government entity (e.g. incorporating a business, or paying applicable sales tax).
- Advertising. With your permission or where allowed by applicable law, we use
and share Representative Personal Data with others so that we may advertise and market our
products and services to you, including through interest-based advertising subject to any
consent requirements under applicable law. We do not sell Representative Personal Data.
1.2 Visitors (e.g. visitors to Neural Formula sites who are not an End User, End Customer or
a. Visitor personal data that we collect
When you visit our Sites, we generally receive your Personal Data either from you providing it
- Forms. When you choose to fill in a form on the Site or on third party
websites featuring our advertising (e.g. LinkedIn or Facebook), we will collect the
information included in the form, usually your contact information and other information about
your question related to our Services.
b. How we use and share visitor personal data
- Personalization. We use information about you that we gather from cookies and
similar technologies to measure engagement with the content on the Sites, to improve relevancy
and navigation, to personalize your experience and to tailor content about Neural Formula and
our Services to you.
- Advertising. With your permission or where allowed by law, we use and share
Visitor Personal Data with others so that we may advertise and market our products and
services to you, including through interest-based advertising where allowed by applicable law,
including subject to any consent requirements.
2. More ways we collect, use and share personal data
In addition to the ways we collect, use and share Personal Data that are described above, we
also process your Personal Data as follows.
a. Personal Data Collection
- Online Activity. Depending on the Service you use and the Business Users’
implementation of our Business Services, we will collect information about:
- Devices and browsers across our Sites and third-party websites, apps and other online
services (“Third-Party Sites”),
- Usage data associated with those devices and browsers, including IP address, plug-ins,
language used, time spent on Sites and Third-Party Sites, pages visited, links clicked,
and the pages that led or referred you to Sites and Third-Party Sites. For example,
activity indicators, like mouse activity indicators, help us detect fraud.
- Communication and Engagement Information. We will collect any information you
choose to provide to us, for example, through support tickets, emails or social media. When
you respond to Neural Formula emails or surveys, we collect your email address, name and any
other information you choose to include in the body of your email or responses. If you contact
us by phone, we will collect the phone number you use to call Neural Formula, as well as other
information you may provide during the call. We will also collect your engagement data such as
your registration for, attendance of, or viewing of Neural Formula events and other
interaction with Neural Formula personnel.
- Forums and Discussion Groups. Where our Sites allow you to post content, we
will collect Personal Data that you provide in connection with the post.
b. Personal Data Usage. In addition to the ways described above in which we use
Personal Data, we use Personal Data in the following ways:
- Improving and Developing our Services. We use analytics on our Sites to help
us analyze your use of our Sites and Services and diagnose technical issues. We also collect
and process Personal Data through our different Services, whether you are an End User, End
Customer, Representative or Visitor, to improve our Services, develop new Services and support
our efforts to make our Services more relevant and more useful to you.
- Communications. We will use the contact information we have about you to
perform the Services, which may include sending codes via SMS to authenticate you. If you are
an End User, Representative or Visitor, we may communicate with you using the contact
information we have about you (e.g. using email, phone, text message or videoconference) to
provide information about our Services and our affiliates’ services, invite you to participate
in our events or surveys, or otherwise communicate with you for our marketing purposes,
provided that we do so in accordance with applicable law, including any consent or opt-out
requirements. For example, when you submit your contact information to us or when we collect
your business contact details through our participation at trade shows or other events, we may
use the information to follow-up with you regarding an event, send you information that you
have requested on our products and services and include you on our marketing information
- Social Media and Promotions. If you choose to submit Personal Data to us to
participate in an offer, program or promotion, we will use the Personal Data you submit to
administer the offer, program or promotion. Based on your permission or opt-out, we will also
use that Personal Data and Personal Data you make available on social media to market to you.
- Fraud Prevention and Security. We collect and use Personal Data to help us to
detect and manage the activity of fraudulent and other bad actors across our Services, to
enable our fraud detection Business Services, and to otherwise seek to secure our Services and
transactions against unauthorized access, use, modification or misappropriation of Personal
Data, information and funds. In connection with fraud and security monitoring, prevention,
detection, and compliance activities for Neural Formula and its Business Users, we receive
information from service providers (including credit bureaus), third parties, and the Services
we provide. We may collect information from you, and about you, from Business Users, financial
parties and in some cases third parties. For example, to protect our Services, we may receive
information from third parties about IP addresses that malicious actors have compromised. This
Personal Data (e.g. name, address, phone number, country) helps us to confirm identities, run
credit checks subject to applicable law and prevent fraud. We may also use technology to
assess the fraud risk associated with an attempted transaction by an End Customer or End User
with a Business User or financial partner.
- Compliance with Legal Obligations. We use Personal Data to meet our
contractual and legal obligations related to anti-money laundering, Know-Your-Customer ("KYC")
laws, anti-terrorism, export control and prohibitions on doing business with restricted
persons or in certain business areas, and other legal obligations. We strive to make our
Services safe, secure and compliant, and the collection and use of Personal Data is critical
to this effort. For example, we may monitor patterns of payment transactions and other online
signals and use those insights to reduce the risk of fraud, money laundering and other
activity that is harmful to Neural Formula, our End Users and their End Customers.
- Minors. The Services are not directed to minors, including children under the
age of 13, and we request that they do not provide Personal Data through the Services. In some
countries, we may impose higher age limits as required by applicable law. We do not sell any
Personal Data of End Customers, Representatives, Visitors or End Users, including those aged
between 13 to 16.
c. Personal Data Sharing. In addition to the ways described above, we share Personal
Data in the following ways:
- Neural Formula Affiliates. We share Personal Data with other Neural Formula
affiliated entities. When we share with these entities, it is for purposes identified in this
- Service Providers or Processors. In order to provide Services to our Business
Users and End Users and to communicate, market and advertise to Visitors, Representatives and
End Users regarding our Services, we will rely on others to provide us services. Service
providers (provide a variety of critical services, such as hosting (storing and delivering),
analytics to assess the speed, accuracy and/or security of our Services, identity
verification, customer service, email and auditing. We authorize such service providers to use
or disclose the Personal Data of our Users that we make available to perform services on our
behalf and to comply with applicable legal requirements. We require such service providers to
contractually commit to protect the security and confidentiality of Personal Data they process
on our behalf. Our service providers are predominantly located in the European Union, the
United States of America and India.
- Financial Partners. “Financial Partners” are financial
institutions that we partner with to offer the Services (including payment method acquirers,
banks and payout providers). We share Personal Data of our Users with certain Financial
Partners to provide the Services to the associated Business Users and to offer certain
Services in partnership with our Financial Partners. For example, we share certain Personal
Data of Representatives (e.g. loan repayment data and contact information) with institutional
investors who purchase the Capital loans that we have made to the associated Business Users.
- Others with Consent. In some cases we may not provide a service, but instead
refer you to, or enable you to engage with, others to get services (e.g. professional services
firms that we partner with to deliver Atlas). In these cases, we will disclose the identity of
the third party and the information that will be shared with them, and seek your consent to
share the information.
- Corporate Transactions. In the event that we enter into, or intend to enter
into, a transaction that alters the structure of our business, such as a reorganization,
merger, sale, joint venture, assignment, transfer, change of control, or other disposition of
all or any portion of our business, assets or stock, we may share Personal Data with third
parties in connection with such transaction. Any other entity which buys us or part of our
business will have the right to continue to use your Personal Data, but subject to the terms
of this Policy.
- Compliance and Harm Prevention. We share Personal Data as we believe
necessary: (i) to comply with applicable law, (ii) to comply with rules imposed by payment
method in connection with use of that payment method (e.g. network rules for Visa); (iii) to
enforce our contractual rights; (iv) to secure or protect the Services, rights, privacy,
safety and property of Neural Formula, you or others, including against other malicious or
fraudulent activity and security incidents; and (v) to respond to valid legal process requests
from courts, law enforcement agencies, regulatory agencies, and other public and government
authorities, which may include authorities outside your country of residence.
3. Legal bases for processing data
For the purposes of the General Data Protection Regulation, we rely upon a number of legal bases
to enable our processing of your Personal Data.
a. Contractual and Pre-Contractual Business Relationships. We process Personal Data
for the purpose of entering into business relationships with prospective Business Users and End Users
and to perform the respective contractual obligations that we have with these Users. Activities include:
- Creation and management of Neural Formula accounts and Neural Formula account credentials,
including the evaluation of applications to commence or expand the use of our Services;
- Creation and management of Neural Formula Checkout accounts;
- Accounting, auditing, and billing activities; and
- Processing of payments, including fraud detection and prevention, optimizing valid
transactions, communications regarding such payments, and related customer service.
b. Legal Compliance. We process Personal Data to verify the identity of our Users
in order to comply with fraud monitoring, prevention and detection obligations, laws associated with
the identification and reporting of illegal and illicit activity, such as "Anti-Money Laundering
("AML") and Know-Your-Customer ("KYC")" obligations, and financial reporting obligations. For example,
we may be required to record and verify a User’s identity for the purpose of compliance with legislation
intended to prevent money laundering and financial crimes. These obligations are imposed on us by
the operation of law, industry standards, and by our financial partners, and may require us to report
our compliance to third parties, and to submit to third party verification audits.
c. Legitimate Business Interests. Where allowed under applicable law, we rely on
our legitimate business interests to process Personal Data about you. The following list sets out
the business purposes for which we have a legitimate interest in processing your data:
- Detect, monitor and prevent fraud and unauthorized payment transactions;
- Mitigate financial loss, claims, liabilities or other harm to End Customers, End Users,
Business Users and Neural Formula;
- Respond to enquiries, send Service notices and provide customer support;
- Promote, analyze, modify and improve our Services, systems, and tools, and develop new
products and services, including reliability of the Services;
- Manage, operate and improve the performance of our Sites and Services by understanding their
effectiveness and optimizing our digital assets;
- Analyze and advertise our Services;
- Conduct aggregate analysis and develop business intelligence that enable us to operate,
protect, make informed decisions, and report on the performance of, our business;
- Share Personal Data with third party service providers that provide services on our behalf and
business partners which help us operate and improve our business
- Enable network and information security throughout Neural Formula and our Services; and
- Share Personal Data among our affiliates.
d. Consent. We may rely on consent to collect and process Personal Data as it relates
to how we communicate with you and for the provision of our Services like Link, Atlas and Identity.
When we process data based on your consent, you have the right to withdraw your consent at any time
without affecting the lawfulness of processing based on such consent before the consent is withdrawn.
4. Your rights and choices
You may have choices regarding our collection, use and disclosure of your Personal Data:
a. Opting out of receiving electronic communications from us
If you no longer want to receive marketing-related emails from us, you may opt-out via the
unsubscribe link included in such emails. We will try to comply with your request(s) as soon as
reasonably practicable. Please note that if you opt-out of receiving marketing-related emails
from us, our Business Users may still send you messages and direct us to send you messages on
b. Your data protection rights
- The right to request confirmation of whether Neural Formula processes Personal Data relating
to you, and if so, to request a copy of that Personal Data;
- The right to request that Neural Formula rectifies or updates your Personal Data that is
inaccurate, incomplete or outdated;
- The right to request that Neural Formula erase your Personal Data in certain circumstances
provided by law.
- The right to request that Neural Formula restrict the use of your Personal Data in certain
circumstances, such as while Neural Formula considers another request that you have submitted
(including a request that Neural Formula make an update to your Personal Data);
- The right to request that we export your Personal Data that we hold to another company, where
- Where the processing of your Personal Data is based on your previously given consent, you have
the right to withdraw your consent at any time; and/or
- Where we process your information based on our legitimate interests, you may also have the
right to object to the processing of your Personal Data. Unless we have compelling legitimate
grounds or where it is needed for legal reasons, we will cease processing your information
when you object.
c. Process for exercising your data protection rights
To exercise your data protection rights please contact us.
5. Security and retention
We make reasonable efforts to provide a level of security appropriate to the risk associated
with the processing of your Personal Data. We maintain organizational, technical and
administrative measures designed to protect Personal Data covered by this Policy against
unauthorized access, destruction, loss, alteration or misuse. Personal Data is only accessed by
a limited number of personnel who need access to the information to perform their duties.
Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
To help us protect personal data, we encourage you to use a strong password and never share your
password with anyone or use the same password with other sites or accounts. If you have reason
to believe that your interaction with us is no longer secure (e.g. you feel that the security of
your account has been compromised), please contact us immediately. >.
We retain your Personal Data as long as we are providing the Services to you or our Business
Users (as applicable) or for a period during which we reasonably anticipate providing the
Services. Even after we stop providing Services directly to you or a Business User with which
you are doing business, and even if you close your Neural Formula account or complete a
transaction with a Business User, we retain your Personal Data in order to comply with our legal
and regulatory obligations. We may also retain it to allow for fraud monitoring, detection and
prevention activities. We also keep Personal Data to comply with our tax, accounting, and
financial reporting obligations, where we are required to retain the data by our contractual
commitments to our financial partners, and where data retention is mandated by the payment
methods you used. In cases where we keep Personal Data, we do so in accordance with any
limitation periods and records retention obligations that are imposed by applicable law. >.
6. International data transfers
We are a global business. Personal Data may be stored and processed in any country where we do
business, where our service providers do business or if you use an international payment method
or financial partner service, the countries in which that payment method or financial partner
operates. We may transfer your Personal Data to countries other than your own country, including
to the United States. These countries may have data protection rules that are different from
your country. When transferring data across borders, we take measures to comply with applicable
data protection laws related to such transfer. In certain situations, we may be required to
disclose Personal Data in response to lawful requests from Officials (such as law enforcement or
If you are located in the European Economic Area (“EEA”), the "United Kingdom ("UK")" or
Switzerland, please contact us for more information.
Where applicable law requires a data transfer mechanism, we use one or more of the following: EU
Standard Contractual Clauses with a data recipient outside the EEA, Switzerland or the UK, verification
that the recipient has implemented Binding Corporate Rules, or other legal methods available to us
under applicable law. For transfers to third countries we have entered into Standard Contractual
Clauses, approved by the European Commission, to ensure an adequate level of protection for the transfer
of your Personal Data to those entities outside the EEA. You can obtain a copy of the relevant Standard
While Neural Formula Inc. remains self-certified under the E.U.-U.S. Privacy Shield and the
Swiss-U.S. Privacy Shield, it is not currently relying on these frameworks for the transfer of
personal data to the U.S. For more information, please see Neural Formula Privacy Center.
7. Updates and notifications
We may change this Policy from time to time to reflect new services, changes in our privacy
practices or relevant laws. The “Last updated” legend at the top of this Policy indicates when
this Policy was last revised. Any changes are effective when we post the revised Policy on the
We may provide you with disclosures and alerts regarding the Policy or Personal Data collected
by posting them on our website and, if you are an End User or Business User, by contacting you
through your Neural Formula Dashboard, email address and/or the physical address listed in your
Neural Formula account.
If applicable law requires that we provide notice in a specified manner prior to making any
changes to this Policy applicable to you, we will provide such required notice.
8. Jurisdiction-specific provisions
- Australia. If you are an Australian resident, and you are dissatisfied with
our handling of any complaint you raise under this Policy, you may wish to contact the Office
of the Australian Information Commissioner.
- EEA and UK. To exercise your rights, you may
contact us. If you are a resident of the EEA or
we have identified Neural Formula Payments Europe Limited as your data controller, and believe
we process your information within the scope of the General Data Protection Regulation (GDPR),
you may direct your questions or complaints to the Irish Data Protection Commission. If you
are a resident of the UK, you may direct your questions or concerns to the UK Information
Commissioner’s Office. Where Personal Data is used for regulated financial activities in
Europe, Neural Formula Payments Europe Limited and Neural Formula local regulated entities
(defined as those who are licensed, authorized or registered by a Local Regulatory Authority)
are considered joint controllers.
- Indonesia. As used in this Policy, “applicable law” includes Law No. 11 of
2008 as amended by Law No. 19 of 2016 on Electronic Information and Transactions, Government
Regulation No. 71 of 2019 on the Implementation of Electronic Systems and Transactions, and
Minister of Communication and Informatics Regulation No. 20 of 2016 on Personal Data
Protection in Electronic Systems and “Personal Data” includes “personal data” as defined under
- Malaysia. If you have any questions or complaints about this Policy, please
contact our DPO.
- Thailand. Thailand residents may have additional rights under applicable
laws. If we process your Personal Data due to a legal obligation or contractual right, and you
do not provide us with personal Information, we may not be able to lawfully provide you
- United States - California. If you are a consumer located in California, we
process your personal information in accordance with the California Consumer Privacy Act
("CCPA"). You have a right to receive notice of our practices at or before collection of
personal information. This section provides additional details about the personal information
we collect and use for purposes of CCPA.
- How We Collect, Use, and Disclose your Personal Information. The Personal Data We Collect
section further describes the personal information we may have collected about you,
including the categories of sources of that information. We collect this information for
the purposes described in the How We Use Personal Data section. We share this information
- Your CCPA Rights and Choices. As a California consumer and subject to certain limitations
under the CCPA, you have choices regarding our use and disclosure of your personal
- Exercising the right to know: you may request that we disclose to you the personal
information we have collected about you. You also have a right to request additional
information about categories of their personal information collected, sold, or
disclosed; purposes for which this personal information was collected or sold;
categories of sources of personal information; and categories of third parties with
whom we disclosed this personal information.
- Exercising the right to delete: you may request that we delete the personal
information we have collected from you, subject to certain limitations under
- Exercising the right to opt-out from a sale: We do not sell Personal Data as defined
by the CCPA and have not done so in the past 12 months.
- Non-discrimination: The CCPA provides that you may not be discriminated against for
exercising these rights.
- To submit a request to exercise any of the rights described above, please contact us using
the methods described in the Contact Us section below. You may designate, in writing or
through a power of attorney, an authorized agent to make requests on your behalf to
exercise your rights under the CCPA. Before accepting such a request from an agent, we
will require the agent to provide proof you have authorized it to act on your behalf, and
we may need you to verify your identity directly with us.
- Further, to provide or delete specific pieces of personal information we will need to
verify your identity to the degree of certainty required by law. We will verify your
request by asking you to send it from the email address associated with your account or
requiring you to provide information necessary to verify your account.
- An authorized agent may submit a request on your behalf by contacting us using the methods
described in the Contact Us section below. We may still require you to directly verify
your identity and confirm that you provided the authorized agent permission to submit the
9. Contact us
If you have any questions or complaints about this Policy, please contact us. If you are an End Customer (i.e. an individual doing business or transacting with a Business
regarding the Business User’s privacy practices, choices and controls, or contact the Business