Privacy

This page explains, in plain English, what data Neumatics and the SoulMap consumer app collect, why, where it lives, and what you can do about it. The mechanics align with GDPR, the EU AI Act, and the EU Data Act.

Not a legal substitute. This is a first-version operator-drafted privacy policy. We will replace it with a lawyer-reviewed equivalent before scaled launch. If you have a specific question that isn't answered here, email lotus@neumatics.eu.


Who we are

Neumatics is operated by Fotis Dovas, sole proprietor, registered in Greece. The data controller for everything on this site is Fotis Dovas, reachable at lotus@neumatics.eu. Data-protection enquiries: lotus@neumatics.eu.


What we collect

CategoryWhatWhy
AccountEmail, optional display name, sign-in metadataTo operate your account
Profile (optional)Demographic facets you choose to share (age band, country, gender, language)Used only with your consent, for marketplace demographic anchoring
Echo responsesYour forced-choice responses inside the 60-second daily micro-experienceScored against psychometric instruments to build your profile
Profile inferencesTrait scores (Big Five, HEXACO, attachment, Schwartz values, EQ, moral foundations) with reliability metadataPowers your SoulMap experience and (with your consent) the marketplace and dataset products
Operational telemetryPerformance, error rates, anonymous usage metricsTo keep the service running and improve it
Wallet metadataPublic XRPL address(es) you create inside the appFor royalty settlement; we never see your private keys

We do not collect: clinical-grade health information, biometric identifiers, voice or physiological capture, or any data from anyone under 18.


Lawful bases

  • Consent (Art. 6(1)(a), Art. 9(2)(a)) for special-category processing — sharing demographic facets, marketplace participation, ML-training-dataset licensing. Granular, separate toggles. Withdrawable at any time.
  • Performance of a contract (Art. 6(1)(b)) for everything required to deliver your account and your Echo sessions.
  • Legitimate interest (Art. 6(1)(f)) for operational security, fraud prevention, and aggregate usage analytics — balanced and overridden by your objection.

The ML-training-dataset compliance posture is detailed at /about/data-ethics.


How long we keep it

DataDefault retention
Account + profileUntil you delete your account
Echo responses24 months rolling, or until you delete them individually
Aggregate dataset exports already licensed to a buyerPer the buyer's data card; revocation cascades to future re-trains via Path-1 consent vintages
Operational logs90 days
DSAR audit trail6 years (regulatory requirement)

Your rights

You can, at any time and at no cost:

  • Access — request a copy of everything we hold about you.
  • Rectify — correct anything that is wrong.
  • Erase — delete your account; the deletion cascades across Firestore, BigQuery, and trace storage with an audit record.
  • Restrict — pause specific processing while we investigate a complaint.
  • Object — opt out of any legitimate-interest processing.
  • Port — receive your data in a structured, machine-readable format.

Email lotus@neumatics.eu. Default turnaround is 30 days.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).


Children

The SoulMap consumer surface and every Neumatics product are 18+ only. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, please email lotus@neumatics.eu and we will delete the account immediately.


International transfers

The default hosting region is the EU (Google Cloud europe-west regions, with Enterprise tier pinned to europe-west12 / de-central1). Where a sub-processor (e.g., LLM provider) operates outside the EU, the transfer is governed by Standard Contractual Clauses and limited to the minimum necessary.


Cookies and similar

We use a small set of strictly-necessary cookies for authentication and session persistence. We do not run third-party advertising or behavioural cross-site tracking. A first-version cookie banner is on the roadmap.


Sub-processors

A current list of sub-processors (Firebase, Google Cloud, Gemini, XRPL infrastructure providers) is available on request via lotus@neumatics.eu. We will publish the list on this page in the next revision.


Updates

We will post material changes here and notify account holders via email. The "Last updated" date at the top of this page reflects the most recent revision.