Privacy Policy

Last updated: September 2026

Introduction

NEUROPAC LIMITED (“NEUROPAC”, “we”, “us”) is committed to protecting your privacy. This policy explains what personal data we collect, how we use it, our lawful bases for processing, who we share it with, and the rights you have under UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

Who we are

NEUROPAC LIMITED is registered in England & Wales (Company No. 16673302).
Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.

How to contact us

NEUROPAC LIMITED is registered with the UK's Information Commissioner's Office under the Data Protection Act 2018.
The Data Controller is Paul Crouch, Director.
The ICO Reference number is: ZB993166.
For any privacy questions or to exercise your rights, contact: team@neuropac.co.uk.

What data we collect

We collect and process the following categories of personal data, as relevant to our relationship with you:

We do not intentionally collect special category (sensitive) data (e.g., health, religious beliefs) or criminal offence data. Please do not provide such information to us.

How we collect your data

How we use your data & lawful bases

We only process personal data where we have a lawful basis under UK GDPR:

Purpose Data types Lawful basis
Responding to enquiries and onboarding clients Identity, contact, engagement data Contract (pre-contract steps at your request); legitimate interests (business development)
Delivering consultancy/services and administering accounts Identity, contact, engagement, transactional Contract; legitimate interests (service quality, debt recovery); legal obligation (tax/accounting)
Maintaining records and improving our services/website Engagement, technical data Legitimate interests (operate and improve our business)
Sending marketing communications Identity, contact, preferences Consent (you can withdraw at any time); legitimate interests for B2B where appropriate
Legal, regulatory, and compliance purposes Relevant data as required Legal obligation; legitimate interests; establishment, exercise or defence of legal claims

Automated decision-making

We do not use your personal data for any solely automated decision-making, including profiling, that produces legal or similarly significant effects on you.

Marketing

We may send marketing communications if you have opted in (or where permitted for B2B on legitimate interests). You can opt out at any time by emailing team@neuropac.co.uk.

Sharing your data

We do not sell your personal data. We may share limited data with trusted processors who provide services to us (e.g., hosting, email, accounting, payment processing) under appropriate contracts. We may also share data where required by law or to protect our rights or those of others.

International transfers

This website is hosted by GitHub, Inc. (part of Microsoft) using GitHub Pages, which may process technical server log data outside the UK. GitHub participates in the UK Extension to the EU–U.S. Data Privacy Framework, which the UK Government has assessed as providing an adequate level of protection for this transfer.

Other processors we use (e.g., email, accounting, payment processing) may also be located outside the UK/EEA. Where that occurs, we rely on an appropriate safeguard recognised under UK GDPR, such as a UK adequacy regulation, the UK Extension to the EU–U.S. Data Privacy Framework, or UK-approved Standard Contractual Clauses (SCCs).

Children

Our website and services are directed at businesses and professionals, not children. We do not knowingly collect personal data from children.

Data retention

We retain general contact/engagement data for 6 years after your last interaction unless a different period is required or permitted by law. Transaction and accounting records are retained for up to 7 years to comply with tax and legal obligations.

Security

We implement appropriate technical and organisational measures to protect your data. If a personal data breach occurs, we will notify the ICO without undue delay (and where feasible, within 72 hours). If the breach is likely to result in a high risk to you, we will also inform you without undue delay.

Your rights

Under UK GDPR you have the right to: access your data; rectify inaccuracies; request erasure; restrict or object to processing; and data portability (in certain cases). You also have the right to withdraw consent where we rely on it. To exercise your rights, email team@neuropac.co.uk. We will respond within one month.

How to complain

If you are unhappy with how we have handled your personal data, please email team@neuropac.co.uk in the first instance, with “Data protection complaint” in the subject line and enough detail for us to look into it. We will acknowledge your complaint within 30 days, investigate it, and respond with the outcome without undue delay.

If you are not satisfied with our response, or would prefer not to raise it with us directly, you also have the right to complain to the UK Information Commissioner’s Office (ICO): ico.org.uk, or by calling 0303 123 1113.

Cookies

This website does not currently use cookies or similar tracking technologies. For details, and what would change if that changes in future, see our Cookies page.

Changes to this policy

We may update this policy from time to time. The “Last updated” date above will reflect the most recent changes. Material changes may be notified via our website or by email where appropriate.

Contact

For privacy questions or requests, contact: team@neuropac.co.uk.