Legal
Privacy Policy
Last updated 20 September 2026
NeuraCap is an investment banking intelligence platform. This policy explains what we collect when you use the platform or read our research, why we hold it, where it lives, who else touches it, and what you can ask us to do with it.
In short
- We collect the details you give us when you create an account, the company information you submit for analysis, and ordinary usage data about how the platform is used.
- We use it to run the platform, produce your analysis, keep the service secure, bill you and answer your questions. We do not sell personal information.
- Data is stored on Amazon Web Services in the US East (N. Virginia) region, encrypted in transit and at rest, and reachable only by named people who need it.
- You can ask to see your data, correct it, export it or have it deleted. Write to info@neuracap.ai and we will act on it.
- Reading the free industry research in the reports library requires no account and no email address.
1. Scope of this policy
This policy applies to neuracap.ai, to the free research published in our reports library, and to the NeuraCap platform, including company search, valuation analysis, peer benchmarking, M&A precedent transactions, sector intelligence, the Financial Assistant and the Research Hub. It applies whether you are a subscriber, a prospective customer, an advisory client or simply a reader.
NeuraCap is the controller of the personal information described here. Where we act as a processor on behalf of a customer — for example, when a firm submits information about its own client companies for evaluation — that customer remains the controller, and the terms of their agreement with us govern how we handle it.
Separate documents cover the rules for using the product and the limits of the analysis itself. Read the Terms of Use for your licence and report-sharing rights, and the disclaimer for why nothing we publish is investment advice.
2. Information we collect
We collect four kinds of information, and no more than we need for each.
Account and contact details
Your name, work email address, employer, job title, and the credentials used to sign in. Passwords are handled by our authentication provider and are never stored by us in plain text. If you contact us, we keep the message and our reply so we can follow up properly.
Company information you submit
To evaluate a private company, you may enter or upload financial statements, revenue and EBITDA history, headcount, customer concentration, capital structure, ownership detail and similar operating information. We treat everything you submit as confidential. It is used to produce your analysis and is not pooled into published research or shown to any other customer. Our coverage and data page explains how submitted private data sits alongside the public sources.
Usage data
Pages viewed, reports opened, searches run, features used, questions asked of the Financial Assistant, timestamps, IP address, browser and device type, and the approximate location derived from your IP address. We use this to keep the service working, to detect abuse, and to understand which analysis is actually useful.
Billing information
If you subscribe or commission advisory work, a third-party payment processor takes the payment. We receive the billing contact, the invoice record and confirmation that payment succeeded. We do not store full payment card numbers on our systems.
3. How we use information
- To create and administer your account, and to authenticate you.
- To produce the analysis you ask for: valuation ranges, comparable company sets, KPI benchmarks, precedent transactions, sector context and the reports built from them.
- To answer questions you put to the Financial Assistant about your own company’s analysis, and to return the supporting figures behind each answer.
- To deliver, export and store the reports you generate.
- To provide support, and to respond when you write to us.
- To keep the platform secure: rate limiting, fraud and abuse detection, audit logging and incident investigation.
- To bill you, collect payment and keep the accounting records we are required to keep.
- To improve the product: which features are used, where analysis fails, which sectors readers open most often. We work from aggregated usage wherever aggregated usage will answer the question.
- To send service messages, and — only if you have asked for them — research alerts and product updates. Every marketing message carries an unsubscribe link.
Analysis on the platform is produced with AI models operating over the structured data described above. The providers of those models are sub-processors, covered in section 7. The limits of AI-assisted interpretation are set out in the disclaimer, and the verification steps we apply are described in our methodology.
4. Legal bases for processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract — to give you access to the platform, produce your analysis and deliver reports you have asked for.
- Legitimate interests — to secure the service, prevent abuse, understand product usage in aggregate, and to contact business users about work relevant to their role. We balance these against your interests and stop where yours prevail.
- Consent — for non-essential cookies, analytics where consent is required, and marketing email. You may withdraw consent at any time.
- Legal obligation — to keep tax, accounting and anti-fraud records.
In Canada, we rely on your consent under PIPEDA, which may be express or implied depending on the sensitivity of the information and the purpose.
5. Where data is stored, and how it is protected
NeuraCap runs on Amazon Web Services. Application data, submitted company information and generated reports are stored in the US East (N. Virginia) region. Data is encrypted in transit using TLS and encrypted at rest using AWS-managed keys.
Access inside NeuraCap is role-based and granted on a least-privilege basis. Administrative access is limited to named personnel, requires individual accounts with multi-factor authentication, and is logged. Customer environments are logically separated so that information one customer submits is not visible to another. Access rights are reviewed when someone changes role and revoked when they leave.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal information and is likely to cause real risk of significant harm, we will notify you and the relevant regulator as required by law. Our security page describes the controls in more detail.
6. How long we keep information, and deletion
We keep information for as long as it is needed for the purpose it was collected for, and then delete it. As drafted, our periods are:
- Account and contact details — for the life of the account, and for twelve months after it is closed, so the account can be restored if closure was a mistake.
- Company information you submit — while your account is active, and for as long as we need to be able to reproduce the reports already delivered to you. You can ask us to delete it sooner.
- Generated reports — retained in your Research Hub until you delete them or the account is closed.
- Usage and security logs — thirteen months on a rolling basis.
- Billing and tax records — seven years, as required by law.
- Backups — expire on their own cycle within thirty-five days; deletion requests are applied to live systems immediately and work through backups as they roll off.
To have your data deleted, write to info@neuracap.ai. We verify who you are, act within thirty days, and confirm when it is done. We may keep the minimum needed to meet a legal obligation, resolve a dispute or enforce our agreements, and we will tell you if that applies.
7. Sub-processors and disclosure
We use a small number of service providers to run the platform. Each is bound by contract to act only on our instructions, to protect the data and to delete it when the engagement ends. They fall into these categories:
- Cloud hosting, storage and database services — Amazon Web Services.
- AI model providers, used to generate narrative interpretation of the analysis.
- Market and financial data providers that supply the underlying sourced data.
- Product analytics and error monitoring.
- Transactional and marketing email delivery.
- Payment processing and invoicing.
- Customer support tooling.
A current list of named sub-processors is available on request from info@neuracap.ai. Beyond these, we disclose personal information only to our professional advisers under a duty of confidence, to an acquirer or successor if the business is sold or reorganised, and where we are required to by law, court order or a valid request from a public authority. Where we can lawfully tell you about such a request, we will.
8. We do not sell personal information
We do not sell personal information. We do not rent or trade it, and we do not share it for cross-context behavioural advertising. We do not sell, license or publish the company financial information you submit, and we do not use it to produce the free industry research at the reports library, which is built from public sources.
9. Your rights, and how to exercise them
Under PIPEDA, if you are in Canada, you have the right to access the personal information we hold about you, to ask that it be corrected if it is wrong or incomplete, to withdraw consent subject to legal and contractual limits, and to challenge our compliance with this policy.
Under the GDPR and UK GDPR, if you are in the EEA or the United Kingdom, you have the right to access your data, to have it rectified, to have it erased, to restrict or object to processing, to receive it in a portable machine-readable format, and to withdraw consent where consent is the basis we rely on.
To exercise any of these, email info@neuracap.ai with “Privacy request” in the subject line and tell us what you want. We will ask for enough information to be satisfied you are who you say you are — we will not hand your data to someone else — and we respond within thirty days, or within one month for GDPR requests. There is no charge unless a request is manifestly unfounded or excessive, in which case we will explain why before doing anything.
If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada, or to your local supervisory authority in the EEA or the Information Commissioner’s Office in the UK. We would rather you came to us first so we can put it right.
10. Cookies and analytics
We use three kinds of cookie, and no advertising cookies:
- Strictly necessary — sign-in sessions, security tokens and load balancing. The platform cannot work without them.
- Preference — remembering choices such as the sectors you filter to or how you last viewed a report.
- Analytics — aggregate measurement of which pages and reports are used, so we know what to publish next.
Where consent is required, analytics cookies are set only after you give it, and you can change your mind at any time. Reading the free industry research does not require you to accept analytics cookies. You can also block or delete cookies in your browser settings; strictly necessary cookies cannot be switched off without breaking sign-in. Where the law requires us to treat a browser privacy signal such as Global Privacy Control as a valid opt-out, we do.
11. International transfers
Our infrastructure is in the United States. If you are in Canada, the EEA, the United Kingdom or elsewhere, the information described in this policy is transferred to and processed in the United States, and may be accessed by our staff and sub-processors there.
For transfers out of the EEA and the UK we rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we apply the technical measures described in section 5. For customers in Canada, PIPEDA requires us to say plainly that information held in the United States is subject to United States law, including lawful access requests by United States courts and government authorities.
12. Children’s data
NeuraCap is a business tool for finance professionals and company operators. It is not directed at children, and we do not knowingly collect personal information from anyone under eighteen. If you believe a child has given us personal information, write to info@neuracap.ai and we will delete it.
13. Changes to this policy
We update this policy when our practices change or the law requires it. The date at the top of the page always shows the current version. If a change materially affects how we handle your personal information, we will tell you by email or by a notice inside the platform before it takes effect. Continuing to use NeuraCap after a change takes effect means you accept the updated policy.
14. How to contact us
For any privacy question, access request, correction, deletion request or complaint, write to info@neuracap.ai. Put “Privacy request” in the subject line and we will route it to the right person. We answer every privacy enquiry, including ones that turn out to be about something else.
If your question is about the rules for using the product, see the Terms of Use. If it is about what the analysis does and does not claim, see the disclaimer and our methodology.
This document is a draft. It is subject to review and approval by counsel before launch, and the retention periods, sub-processor categories and regulator references above may change as a result.