At a glance
- Two regimes: NeuralShift processes personal data as controller (this Notice) and as processor for personal data in User Content and Outputs, on the Client’s documented instructions under a separate DPA.
- No training, no selling, no marketing: NeuralShift does not use User Content or Outputs to train or fine-tune generative AI or foundation models, does not sell personal data, and does not use personal data covered by this Notice for direct marketing.
- Integrations: a provider does not become NeuralShift’s processor or subprocessor merely because its service is used with the Software; its own terms and privacy information govern (see §5).
- International transfers: personal data may be processed outside the EEA where a recipient or Third-Party Service operates in another jurisdiction, relying on recognized transfer mechanisms such as adequacy decisions or Standard Contractual Clauses (see §7).
- Your rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint (see §9).
- Contact: no Data Protection Officer has been appointed, as the Article 37 GDPR conditions do not apply; questions and requests go to privacy@neuralshift.ai (see §13).
This Privacy Notice (the “Notice”) explains how Deep Learning Services, Lda., trading as NeuralShift (“NeuralShift”, “we”, “us”), processes personal data as controller in connection with the Software, the webpages through which the Software is offered, and any Integration made available through the Software, and provides the information required by Regulation (EU) 2016/679 (the “GDPR”) and applicable Portuguese data protection law (together, “Applicable Law”).
§ 1Scope & definitions
This Notice is a transparency notice, not a contract, and does not constitute consent to processing.
NeuralShift also processes personal data contained in User Content and Outputs on the Client’s documented instructions. For that processing, the Client is the controller and NeuralShift is the processor, and the applicable data processing agreement (the “DPA”) governs it. The Client remains responsible for providing the information required by Applicable Law to the data subjects concerned.
This Notice applies only to processing for which NeuralShift determines the purposes and means, whereas a Third-Party Service processes personal data under its own terms, privacy information, and arrangements with the Client or Authorized User. Accordingly, the availability or use of an Integration does not, by itself, make that provider NeuralShift’s processor or subprocessor.
For this Notice:
- Authorized User
- A natural person authorized to access or use the Software under the Client’s Subscription Plan, whether through a User Account or an Integration.
- Client
- The natural or legal person that has purchased a Subscription Plan.
- Integration
- Any feature, connection, interface, protocol, connector, extension, add-in, or other technical mechanism that enables the Software to be accessed or used from, connected to, or exchange information with a Third-Party Service.
- Output
- Any result, analysis, suggestion, summary, or other material generated by the Software in response to User Content or another authorized use of the Software, whether initiated directly by an Authorized User or through an Integration on the Client’s behalf.
- Platform
- The Software together with the technological infrastructure on which it operates.
- Public Data
- Information lawfully available to the public, including legislation, officially published judicial or administrative decisions, and administrative guidance. Public Data may contain personal data.
- Software
- Affine, a web-based application developed by NeuralShift and made available on a Software-as-a-Service basis under a valid Subscription Plan, including the components of any Integration provided by NeuralShift.
- Subscription Plan
- The Software access and service package specified in the Order Form.
- Third-Party Service
- Any third-party software, application, platform, marketplace, interface, service, or other environment with which the Software interoperates through an Integration.
- User Account
- An account created for an Authorized User to access the Software under the Client’s Subscription Plan.
- User Content
- Any data, information, document, text, image, prompt, request, or other material uploaded, entered, submitted, transmitted through an Integration, or otherwise made available to the Software by or on behalf of the Client or an Authorized User, and processed or stored on the Platform in connection with use of the Software.
§ 2Personal data we process as controller
NeuralShift obtains personal data covered by this Notice directly from Clients, Client representatives, Authorized Users, and website visitors; from the Client when it creates or administers an account; automatically through use of the Software or our website; and, where an Integration is used, from the relevant Third-Party Service or identity provider.
Depending on the interaction, NeuralShift processes the following categories:
| Category | Personal Data and Source | Purposes | Lawful Basis |
|---|---|---|---|
| Account and Professional Data | Name, job title, professional contact details, account identifier, employer or organization, and details of authorized Client representatives. Obtained from the data subject or the Client. | Create and administer accounts; manage the Client relationship; provide support; communicate about the Software. | Contractual necessity where the data subject is the Client; otherwise, NeuralShift’s and the Client’s legitimate interests in administering and providing the Software. Core account data is required to provide access; other contact details may be voluntary. |
| Integration Identity and Access Data | Depending on the Integration, account or user identifiers, professional email address, organization or tenant identifiers, authentication assertions, authorization information, access scopes, and connection-status data. Obtained from the relevant Third-Party Service or identity provider. | Authenticate and authorize access; route an exchange; administer and secure the Integration; provide support; diagnose access failures. | Contractual necessity where the data subject is the Client; otherwise, legitimate interests in providing, administering, and securing the Software. This data is processed only if an Integration is used, and technically necessary fields are required to complete the requested exchange. |
| Billing Data | Client name, tax identification number, billing address, payment method details, and transaction and invoicing records. Obtained from the Client or payment channels. | Invoice and receive payment; maintain accounting, tax, and commercial records. | Compliance with legal obligations and, where the data subject is the Client, contractual necessity. Required for billing and statutory record-keeping. |
| Communications and Feedback Data | Professional contact details and the content of support requests, product feedback, surveys, or other correspondence. Obtained directly from the sender. | Respond to requests; provide support; diagnose recurring issues; improve the Software; conduct internal quality assurance. | Contractual necessity where applicable and legitimate interests in supporting and improving the Software. Voluntary, except for information needed to resolve a request. |
| Security and Operational Data | IP address, device and browser information, session and request identifiers, authentication events, timestamps, routing and status information, error events, and security logs. Generated automatically through use of the Software, a website, or an Integration. This category does not include substantive User Content merely because it appears in a diagnostic record. | Operate and secure the Software; maintain sessions; detect and investigate misuse, fraud, incidents, and vulnerabilities; troubleshoot faults; enforce applicable terms; establish, exercise, or defend legal claims. | Legitimate interests in operating and securing the Software and compliance with legal obligations where applicable. Generated automatically and technically necessary for these purposes. |
| Software Analytics Data | Feature or command used, interaction frequency and duration, usage volume, latency, performance data, and aggregated or pseudonymized usage patterns. Generated automatically. NeuralShift does not use the substance of User Content or Outputs for its own analytics. | Understand feature use; monitor performance; prioritize improvements; produce aggregate service statistics. | Legitimate interests in understanding and improving the Software. Generated automatically; data subjects may object as described in Section 9. |
| Publicly Available Legal Information | Names and other personal data appearing in legislation, officially published decisions, administrative guidance, and other official legal sources. Obtained from the relevant public source. | Build and maintain the legal-research corpus; enable search, classification, and entity extraction; assess accuracy and relevance. | Legitimate interests in providing and improving a professional legal-research service. Where Articles 9 or 10 GDPR apply, NeuralShift processes the data only if an additional condition under Applicable Law is satisfied. Data subjects do not provide this information to NeuralShift. |
NeuralShift does not use personal data covered by this Notice for direct marketing.
§ 3Who we share personal data with
NeuralShift discloses personal data only where necessary for the relevant purpose and, as applicable, to:
- The Client: Client administrators may receive account, access, security, and usage information needed to administer the Client’s subscription and Authorized Users.
- Processors engaged by NeuralShift: These include providers of hosting, authentication, security, observability, logging, analytics, communications, customer support, customer-relationship management, invoicing, accounting, and contract-management services. They process personal data on NeuralShift’s instructions and under appropriate contractual safeguards.
- Third-Party Services: When an Authorized User uses an Integration, a Third-Party Service may send substantive request content to the Software and receive substantive response content from the Software. NeuralShift also exchanges the minimum technical information needed to route and complete the request; the provider’s subsequent processing is governed by its arrangements with the Client or Authorized User and its own privacy information.
- Professional advisers and public authorities: NeuralShift may disclose personal data where reasonably necessary to obtain professional advice, comply with law or a binding request, investigate unlawful activity, or establish, exercise, or defend legal claims.
- Transaction recipients: Personal data may be disclosed under appropriate safeguards to advisers, counterparties, or successors in connection with a proposed or completed corporate reorganization, financing, merger, acquisition, or transfer of business.
NeuralShift does not sell personal data.
§ 4Generative AI & personal data
NeuralShift engages generative AI providers to operate functions such as document analysis, semantic search, text generation, and speech-to-text. Where those functions process personal data contained in User Content or Outputs, NeuralShift acts as processor and the DPA applies.
The ordinary flow is:
- Input: The Authorized User submits a prompt, instruction, or file, directly in the Software or through an Integration.
- Context: The Software retrieves relevant content from the materials available to the Authorized User or, where appropriate, from Public Data.
- Transmission: The Software combines the instruction, relevant context, and system instructions, and transmits the resulting input to the selected model provider using encryption in transit.
- Generation: The model provider processes the input to generate an Output in accordance with NeuralShift’s instructions and the applicable subprocessor terms.
- Delivery: The Software returns the Output through the interface used by the Authorized User and stores it only as configured for the Software and as governed by the DPA.
NeuralShift does not use User Content or Outputs to train or fine-tune generative AI or foundation models and requires model providers engaged to operate the Software not to do so. This commitment does not, however, govern processing carried out independently by a Third-Party Service supplied under the Client’s or Authorized User’s own arrangements.
NeuralShift may use Public Data and anonymous or appropriately aggregated Software Analytics Data to improve search, classification, entity extraction, model evaluation, and Software performance, but does not attempt to re-identify anonymous data.
§ 5Third-party integrations
An Authorized User may use any Integration that NeuralShift makes available through the Software; the data exchanged depends on the functionality used and the action requested by the Authorized User.
A Third-Party Service may send the Software a request containing a prompt, instruction, query, selected context, document or extract, record, input parameter, and the identifiers or access-rights information needed to route and process the request; in turn, the Software may return an answer, search result, citation, extract, file or record, source reference, output metadata, and status or error information.
NeuralShift may process Integration Identity and Access Data and Security and Operational Data for the purposes described in Section 2; NeuralShift determines those limited purposes, which include authenticating users, administering and securing the Software, operating the Integration, troubleshooting errors, preventing misuse, providing support, and measuring performance.
If a technical or diagnostic record contains substantive User Content or an Output, NeuralShift continues to process that content on the Client’s behalf under the DPA; its appearance in a log or diagnostic record does not convert it into data used for NeuralShift’s own analytics.
NeuralShift processes personal data in the substantive content of Integration requests and responses, including User Content and Outputs, on the Client’s documented instructions under the DPA, whereas this Notice separately governs identity, access, security, and operational data that NeuralShift processes for its own limited purposes (Sections 2 and 5.3).
Where NeuralShift separately engages a provider to process that data on its behalf, that provider is treated as a subprocessor under the DPA; however, a provider does not become NeuralShift’s subprocessor merely because a Client or Authorized User uses its Third-Party Service with the Software.
The Client or Authorized User is responsible for any third-party account, subscription, license, authorization, or configuration required to use a Third-Party Service. That provider may process requests, Outputs, account data, and technical data to provide, secure, test, or monitor its own service, as described in its terms and privacy information; NeuralShift does not determine the provider’s independent purposes, retention periods, international transfers, or security practices.
A marketplace, directory, identity provider, or Third-Party Service may also collect personal data directly when an Authorized User accesses or uses an Integration; that collection is governed by the relevant provider’s privacy information. Authorization or access granted through a Third-Party Service is a technical instruction; it is not treated by NeuralShift as consent under the GDPR unless NeuralShift expressly requests consent for a specified controller purpose.
§ 6Security
NeuralShift uses technical and organizational measures designed to provide a level of security appropriate to the risk, available here.
These measures apply to systems controlled by NeuralShift and processors it engages, whereas the security of a Third-Party Service supplied under the Client’s or Authorized User’s arrangements is governed by that provider’s terms and security information.
§ 7International data transfers
Personal data covered by this Notice may be processed outside the European Economic Area where a recipient or Third-Party Service operates in another jurisdiction. Where NeuralShift is responsible for such a transfer, it relies on a mechanism recognized by Applicable Law, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, and applies supplementary measures where required. Information about the relevant safeguards, including how to obtain a copy, is available on request.
Transfers of User Content and Outputs by NeuralShift as processor are governed by the DPA, while a Third-Party Service provider’s subsequent transfers are governed by its arrangements with the Client or Authorized User and described in its own privacy information.
§ 8Retention
NeuralShift retains personal data covered by this Notice only for as long as needed for the purposes described here, to comply with legal obligations, and to establish, exercise, or defend legal claims, after which it deletes or anonymizes the data. Where immediate deletion from a backup is not technically feasible, NeuralShift isolates the data from further use until deletion.
| Data Category | Retention Period | Notes |
|---|---|---|
| Account and Professional Data | Five years after the Client relationship ends. | Limited to account administration, audit, and legal-claims needs. |
| Integration Identity and Access Data | For as long as needed to authenticate or complete the relevant exchange. Authorization data is deleted or rendered unusable when no longer required; related audit records follow the Security and Operational Data period. | Data is not retained merely because an Integration remains generally available through the Software. |
| Billing Data | Ten years from issue of the relevant invoice or for any longer period required by law. | Reflects Portuguese tax and accounting obligations. |
| Communications and Feedback Data | Two years from submission or until the Client relationship ends, whichever occurs first, unless longer retention is required to resolve a live request or claim. | Feedback used for improvement is subject to the right to object. |
| Security and Operational Data | Twelve months on a rolling basis, unless a longer period is necessary to investigate an incident, comply with law, or establish, exercise, or defend claims. | Records containing substantive User Content or Outputs remain governed by the DPA. |
| Software Analytics Data | Twelve months on a rolling basis. | Anonymous aggregate statistics may be retained because they are no longer personal data. |
| Publicly Available Legal Information | For as long as the source remains lawfully public and the information is needed for the legal-research purposes described above. | NeuralShift reviews affected records if an official source is corrected, restricted, or withdrawn. |
Retention and deletion of User Content and Outputs processed on the Client’s behalf are governed by the DPA, while a Third-Party Service applies its own retention rules to data it processes under its arrangements with the Client or Authorized User.
§ 9Data subject rights
Subject to the conditions and exceptions in Applicable Law, a data subject may exercise the following rights in relation to personal data covered by this Notice:
| Right | What It Means |
|---|---|
| Access | Obtain confirmation of processing and access to the personal data and relevant processing information. |
| Rectification | Correct inaccurate personal data and complete incomplete personal data. |
| Erasure | Request deletion where the statutory conditions are met. |
| Restriction | Request that processing be restricted in the circumstances set out in the GDPR. |
| Portability | Receive personal data provided to NeuralShift in a structured, commonly used, machine-readable format where processing is automated and based on consent or contract. |
| Objection | Object, on grounds relating to the data subject’s particular situation, to processing based on legitimate interests; NeuralShift will stop unless it demonstrates compelling legitimate grounds or needs the data for legal claims. |
| Withdraw Consent | Withdraw consent at any time where consent is the lawful basis. Withdrawal does not affect earlier processing. |
| Complaint | Lodge a complaint with the CNPD or the supervisory authority for the data subject’s habitual residence, place of work, or place of the alleged infringement. |
NeuralShift normally responds within one month but may extend that period by a further two months where necessary, taking account of complexity and volume, and will explain any extension within the first month. NeuralShift may charge a reasonable fee or refuse to act on a request that is manifestly unfounded or excessive, as allowed by Article 12(5) GDPR.
Requests concerning Account and Professional Data, Integration Identity and Access Data, Security and Operational Data, Software Analytics Data, or other personal data covered by this Notice should be sent to NeuralShift using the details in Section 13.
Requests concerning personal data in User Content or Outputs should ordinarily be directed to the Client, as controller; NeuralShift assists the Client under the DPA. Requests concerning a Third-Party Service provider’s independent processing should be directed to that provider.
The Portuguese supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD):
Address: Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal
Telephone: +351 213 928 400
Email: geral@cnpd.pt
Website: www.cnpd.pt
§ 10Cookies & similar technologies
The Software and NeuralShift’s websites use cookies and similar technologies that are necessary for authentication, session management, and security. Where NeuralShift uses non-essential analytics or preference technologies, it does so only after obtaining consent where required by applicable electronic-communications law; consent may be withdrawn as easily as it is given. The relevant interface or cookie notice provides more detailed information about the technologies used, their purposes, and their duration.
§ 11Automated decision-making
NeuralShift does not, as controller, make decisions based solely on automated processing of personal data that produce legal effects concerning the data subject or similarly significantly affect the data subject, within the meaning of Article 22 GDPR.
§ 12Changes to this Notice
NeuralShift may update this Notice to reflect changes to its processing activities, the Software, or Applicable Law; when it does, NeuralShift will update the version and effective date above and, where a change materially affects data subjects, provide notice through an appropriate channel before the change takes effect.
§ 13Contact
NeuralShift has not appointed a Data Protection Officer because the conditions in Article 37 GDPR that require an appointment do not apply. Questions and requests concerning this Notice or personal data for which NeuralShift acts as controller may be sent to:
Rua João Saraiva, 38, 4.º andar, 405 AI HUB
1700-051 Lisboa, Portugal
Attn. António Lopes dos Santos