Legal
Privacy policy.
How Neonix Technologies collects, uses and protects personal data, and your rights under the GDPR.
Effective September 26, 2026
1. Who we are
Neonix Technologies ("Neonix", "we", "us") is a cybersecurity technology company headquartered in Sweden, with operations in the United Arab Emirates, Bahrain, Qatar and India. We build Cybrmonk, CybrWAF and CybrIdentity, and operate this website. For the personal data described in this policy, Neonix Technologies is the data controller under the General Data Protection Regulation (GDPR) and, where applicable, under the data protection laws of the UAE, Bahrain, Qatar and India.
This policy covers personal data we collect through this website, product demo and trust-center requests, security vulnerability reports, and job applications. It does not cover data that our customers process using the Neonix platform once deployed, that processing is governed by the data processing agreement in each customer's contract, in which Neonix acts as a processor on the customer's instructions.
2. Information we collect
2.1 Information you provide directly
Name, work email, company, job title, country and message content when you request a demo, contact us, or submit a security vulnerability report. Company size and product interest when you tell us about your evaluation. Application materials if you apply for a role with us.
2.2 Information collected automatically
IP address, browser and device type, pages viewed, referring page and approximate location, collected through cookies and similar technologies as described in section 6. We do not currently run third-party analytics or advertising scripts on this website; if that changes, the cookie categories below will be updated before any such script loads.
2.3 Information from other sources
Where relevant to a specific security report or partnership discussion, we may receive information from publicly available sources or from the person who referred you to us.
3. Our legal bases for processing
Where the GDPR applies, we rely on one of the following legal bases for each processing activity:
- Consent, for non-essential cookies and any marketing communications you opt into. You can withdraw consent at any time.
- Contract, to respond to a demo request or otherwise take steps you ask for before entering an agreement with us.
- Legitimate interests, to operate, secure and improve this website, and to triage security vulnerability reports, balanced against your rights and interests.
- Legal obligation, where we must retain or disclose information to comply with the law.
4. How we use your information
- Responding to demo requests, general enquiries and partnership discussions.
- Triaging and responding to security vulnerability reports submitted through our responsible disclosure process.
- Operating, securing and maintaining this website.
- Understanding aggregate website usage to improve content and navigation.
- Evaluating job applications.
- Meeting our legal, tax and regulatory obligations.
7. International data transfers
Neonix is headquartered in Sweden (European Union) and also operates in the United Arab Emirates, Bahrain, Qatar and India. Personal data may be transferred between Neonix offices and to service providers in these locations. Where personal data is transferred outside the EEA, we require safeguards recognized under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision, before that transfer takes place.
8. Data retention
We keep personal information only as long as needed for the purpose it was collected: demo and contact enquiries for as long as needed to progress the conversation and for a reasonable period after in case you follow up; security vulnerability reports for as long as needed to investigate and remediate, plus a record of the report itself; job application materials for the duration of the hiring process and a limited period after. Where we have no ongoing reason to keep it, we delete or anonymize it.
9. Your rights under the GDPR
If the GDPR applies to you, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("the right to be forgotten"), subject to legal exceptions.
- Restrict or object to certain processing, including processing based on legitimate interests.
- Receive your data in a portable format, where processing is based on consent or contract and carried out by automated means.
- Withdraw consent at any time, without affecting processing carried out before withdrawal.
- Lodge a complaint with a supervisory authority: Sweden's Integritetsskyddsmyndigheten (IMY) or the authority in your own EU/EEA member state, the UAE Data Office, Bahrain's Personal Data Protection Authority (PDPA), Qatar's Compliance and Data Protection Department, or India's Data Protection Board, depending on where you are located.
To exercise any of these rights, contact us using the details in section 13. We will respond within the timeframe required by the GDPR.
10. Data security
We use technical and organizational measures appropriate to the sensitivity of the information we hold, including access controls and encryption in transit. No method of transmission or storage is completely secure; if you believe you have found a weakness in how we protect data, please use our responsible disclosure process.
11. Children's privacy
This website is directed at businesses and security professionals. It is not directed at, and we do not knowingly collect personal data from, children under 16.
12. Changes to this policy
We will update the effective date below when this policy changes, and post a notice on this page for material changes.
13. Contact us
For any question about this policy or to exercise a data protection right, contact [email protected]. To report a security vulnerability, use our responsible disclosure process instead.