Privacy Policy

Last updated: 1 September 2026

1. Scope and roles

This Policy describes personal data processing by A2Display for the NeuroDisplay website and platform.

A2Display is a controller for accounts, security, commercial relations, billing, Support and legal duties. A2Display is a processor for Client content, Client data, journeys, delivery and configurations handled on Client instructions; those operations are governed by the DPA.

2. Controller

A2Display, a French simplified joint-stock company, 1 rue de la Caillardière, 49070 Beaucouzé, France, operates NeuroDisplay.

Use the NeuroDisplay form for product, commercial or data-protection requests. Authenticated Clients use NeuroDisplay Support. A2Display does not claim to have appointed a data protection officer.

3. Data processed

  • Professional identity, contact details, Organization, role and language.
  • Account, authentication, security and contract-acceptance evidence.
  • Billing information and payment references; card data is processed by Stripe.
  • Content, media, configurations, journeys and contextual data selected by the Client.
  • Support tickets and attachments.
  • Technical logs, request_id, IP address, browser, device and Player state needed for operation and security.
  • Prompts and necessary context only when a User explicitly triggers an AI feature.

4. Purposes and legal bases

  • Provide the Service and manage the agreement: performance of contract.
  • Create and secure accounts, prevent abuse and diagnose: legitimate interests and security duties.
  • Bill and retain evidence: contract and legal obligations.
  • Provide Support: contract and legitimate interests.
  • Commercial communications: consent or legitimate interest where permitted, with an opt-out right.
  • Process Client data: documented Client instructions and the DPA.

5. Recipients and providers

Internal access is limited to authorized people. Active providers are Supabase, Vercel, Resend and OpenAI when AI features are used. Stripe acts in its own or contextual roles for payment, security and fraud.

Usercentrics manages privacy choices on the public website. Open-Meteo is temporarily disabled while no commercial subscription is configured and then receives no production data. The versioned subprocessor list describes purposes without exposing secrets.

6. International transfers

Some providers may process data or allow access from countries outside the EEA. Transfers rely, as applicable, on an adequacy decision, Standard Contractual Clauses or another applicable safeguard.

We do not claim EEA-only residence where the active Plan or configuration does not establish it.

7. Retention

  • Content and configurations: contract term, thirty-day export window, then active deletion within the following thirty days.
  • Temporary files and abandoned uploads: twenty-four hours.
  • Application logs: ninety days; security and authentication logs: one hundred and eighty days.
  • Player technical state and heartbeat: ninety days.
  • Organization-identifiable analytics: no more than thirteen months.
  • Support tickets and attachments: ticket handling plus twelve months after closure, unless a dispute or legal duty applies.
  • Unsaved AI prompts: transient; redacted technical logs: no more than thirty days.
  • Contract evidence, invoices and accounting: applicable statutory periods.

8. Artificial intelligence features

Data is sent to OpenAI only after an explicit User action and only as needed for the request. Do not submit sensitive data unnecessarily.

NeuroDisplay does not reuse Client prompts for its own purposes and retains an output only when the User saves it. The provider processes under the DPA and terms applicable to the API account.

9. Your rights

Depending on the processing and applicable law, you may request access, rectification, erasure, restriction, objection and portability, and withdraw consent without affecting prior processing.

Use the NeuroDisplay form, category “Data protection”, or NeuroDisplay Support when authenticated. Reasonable identity verification may be required. You may also complain to the competent supervisory authority.

10. Security and incidents

Established measures include RLS, RBAC, multi-tenant isolation, server controls, server-side secrets, encryption in transit, signed URLs, redacted logs, Test/Production separation, rate limiting, cross-org protections and incident management.

No system is absolutely secure. Incidents are assessed, contained and notified according to applicable roles and duties.

11. Cookies, privacy choices and measurement

Usercentrics is used on the public website to collect and manage privacy choices according to purpose, region and applicable law. Strictly necessary technologies support operation, security and storage of those choices.

No Analytics or Marketing tool is currently active. Future optional measurement, improvement or marketing tools may be enabled only after disclosure in the preference center and according to the required choice. Usercentrics lists the services that are actually active.

You can change your choices at any time using the “Manage privacy preferences” link on this page and in the footer. Test, internal and demo data must remain excluded from production indicators.

12. Versions and related documents

This Policy may change prospectively. The active version date appears on this page. See also the DPA, subprocessor list, security measures and transfer schedule.