NEONIX SECURITY FABRICEXPOSURE / APPLICATION / IDENTITY

Legal

Privacy policy.

How Neonix Technologies collects, uses and protects personal data, and your rights under the GDPR.

Effective September 26, 2026

In short: we collect the minimum needed to respond to your enquiry or report, we never sell personal data, and you can exercise your GDPR rights at any time by contacting us.

1. Who we are

Neonix Technologies ("Neonix", "we", "us") is a cybersecurity technology company headquartered in Sweden, with operations in the United Arab Emirates, Bahrain, Qatar and India. We build Cybrmonk, CybrWAF and CybrIdentity, and operate this website. For the personal data described in this policy, Neonix Technologies is the data controller under the General Data Protection Regulation (GDPR) and, where applicable, under the data protection laws of the UAE, Bahrain, Qatar and India.

This policy covers personal data we collect through this website, product demo and trust-center requests, security vulnerability reports, and job applications. It does not cover data that our customers process using the Neonix platform once deployed, that processing is governed by the data processing agreement in each customer's contract, in which Neonix acts as a processor on the customer's instructions.

2. Information we collect

2.1 Information you provide directly

Name, work email, company, job title, country and message content when you request a demo, contact us, or submit a security vulnerability report. Company size and product interest when you tell us about your evaluation. Application materials if you apply for a role with us.

2.2 Information collected automatically

IP address, browser and device type, pages viewed, referring page and approximate location, collected through cookies and similar technologies as described in section 6. We do not currently run third-party analytics or advertising scripts on this website; if that changes, the cookie categories below will be updated before any such script loads.

2.3 Information from other sources

Where relevant to a specific security report or partnership discussion, we may receive information from publicly available sources or from the person who referred you to us.

4. How we use your information

  • Responding to demo requests, general enquiries and partnership discussions.
  • Triaging and responding to security vulnerability reports submitted through our responsible disclosure process.
  • Operating, securing and maintaining this website.
  • Understanding aggregate website usage to improve content and navigation.
  • Evaluating job applications.
  • Meeting our legal, tax and regulatory obligations.

5. Cookies and similar technologies

A cookie banner appears the first time you visit this site. Until you make a choice, only strictly necessary cookies are set.

  • Strictly necessary: required for the site to function (for example, remembering your cookie preference itself). These cannot be switched off.
  • Analytics: help us understand aggregate site usage. Off by default until you consent, and no analytics script runs before that.

You can change your choice at any time using the "Cookie preferences" link in the footer, or by clearing your browser's local storage for this site.

6. How we share information

We do not sell personal information. We share it only with:

  • Service providers who process data on our behalf under contract (for example, email delivery and hosting infrastructure), bound to use it only for the service they provide us.
  • Professional advisers, regulators or law enforcement, where required by law or to protect our rights, users or the public.
  • A successor entity, if Neonix is involved in a merger, acquisition or asset sale, subject to the commitments in this policy.

7. International data transfers

Neonix is headquartered in Sweden (European Union) and also operates in the United Arab Emirates, Bahrain, Qatar and India. Personal data may be transferred between Neonix offices and to service providers in these locations. Where personal data is transferred outside the EEA, we require safeguards recognized under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision, before that transfer takes place.

8. Data retention

We keep personal information only as long as needed for the purpose it was collected: demo and contact enquiries for as long as needed to progress the conversation and for a reasonable period after in case you follow up; security vulnerability reports for as long as needed to investigate and remediate, plus a record of the report itself; job application materials for the duration of the hiring process and a limited period after. Where we have no ongoing reason to keep it, we delete or anonymize it.

9. Your rights under the GDPR

If the GDPR applies to you, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("the right to be forgotten"), subject to legal exceptions.
  • Restrict or object to certain processing, including processing based on legitimate interests.
  • Receive your data in a portable format, where processing is based on consent or contract and carried out by automated means.
  • Withdraw consent at any time, without affecting processing carried out before withdrawal.
  • Lodge a complaint with a supervisory authority: Sweden's Integritetsskyddsmyndigheten (IMY) or the authority in your own EU/EEA member state, the UAE Data Office, Bahrain's Personal Data Protection Authority (PDPA), Qatar's Compliance and Data Protection Department, or India's Data Protection Board, depending on where you are located.

To exercise any of these rights, contact us using the details in section 13. We will respond within the timeframe required by the GDPR.

10. Data security

We use technical and organizational measures appropriate to the sensitivity of the information we hold, including access controls and encryption in transit. No method of transmission or storage is completely secure; if you believe you have found a weakness in how we protect data, please use our responsible disclosure process.

11. Children's privacy

This website is directed at businesses and security professionals. It is not directed at, and we do not knowingly collect personal data from, children under 16.

12. Changes to this policy

We will update the effective date below when this policy changes, and post a notice on this page for material changes.

13. Contact us

For any question about this policy or to exercise a data protection right, contact [email protected]. To report a security vulnerability, use our responsible disclosure process instead.