Privacy
This page explains, in plain English, what data Neumatics and the SoulMap consumer app collect, why, where it lives, and what you can do about it. The mechanics align with GDPR, the EU AI Act, and the EU Data Act.
Not a legal substitute. This is a first-version operator-drafted privacy policy. We will replace it with a lawyer-reviewed equivalent before scaled launch. If you have a specific question that isn't answered here, email lotus@neumatics.eu.
Who we are
Neumatics is operated by Fotis Dovas, sole proprietor, registered in Greece. The data controller for everything on this site is Fotis Dovas, reachable at lotus@neumatics.eu. Data-protection enquiries: lotus@neumatics.eu.
What we collect
| Category | What | Why |
|---|---|---|
| Account | Email, optional display name, sign-in metadata | To operate your account |
| Profile (optional) | Demographic facets you choose to share (age band, country, gender, language) | Used only with your consent, for marketplace demographic anchoring |
| Echo responses | Your forced-choice responses inside the 60-second daily micro-experience | Scored against psychometric instruments to build your profile |
| Profile inferences | Trait scores (Big Five, HEXACO, attachment, Schwartz values, EQ, moral foundations) with reliability metadata | Powers your SoulMap experience and (with your consent) the marketplace and dataset products |
| Operational telemetry | Performance, error rates, anonymous usage metrics | To keep the service running and improve it |
| Wallet metadata | Public XRPL address(es) you create inside the app | For royalty settlement; we never see your private keys |
We do not collect: clinical-grade health information, biometric identifiers, voice or physiological capture, or any data from anyone under 18.
Lawful bases
- Consent (Art. 6(1)(a), Art. 9(2)(a)) for special-category processing — sharing demographic facets, marketplace participation, ML-training-dataset licensing. Granular, separate toggles. Withdrawable at any time.
- Performance of a contract (Art. 6(1)(b)) for everything required to deliver your account and your Echo sessions.
- Legitimate interest (Art. 6(1)(f)) for operational security, fraud prevention, and aggregate usage analytics — balanced and overridden by your objection.
The ML-training-dataset compliance posture is detailed at /about/data-ethics.
How long we keep it
| Data | Default retention |
|---|---|
| Account + profile | Until you delete your account |
| Echo responses | 24 months rolling, or until you delete them individually |
| Aggregate dataset exports already licensed to a buyer | Per the buyer's data card; revocation cascades to future re-trains via Path-1 consent vintages |
| Operational logs | 90 days |
| DSAR audit trail | 6 years (regulatory requirement) |
Your rights
You can, at any time and at no cost:
- Access — request a copy of everything we hold about you.
- Rectify — correct anything that is wrong.
- Erase — delete your account; the deletion cascades across Firestore, BigQuery, and trace storage with an audit record.
- Restrict — pause specific processing while we investigate a complaint.
- Object — opt out of any legitimate-interest processing.
- Port — receive your data in a structured, machine-readable format.
Email lotus@neumatics.eu. Default turnaround is 30 days.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).
Children
The SoulMap consumer surface and every Neumatics product are 18+ only. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, please email lotus@neumatics.eu and we will delete the account immediately.
International transfers
The default hosting region is the EU (Google Cloud europe-west regions, with Enterprise tier pinned to europe-west12 / de-central1). Where a sub-processor (e.g., LLM provider) operates outside the EU, the transfer is governed by Standard Contractual Clauses and limited to the minimum necessary.
Cookies and similar
We use a small set of strictly-necessary cookies for authentication and session persistence. We do not run third-party advertising or behavioural cross-site tracking. A first-version cookie banner is on the roadmap.
Sub-processors
A current list of sub-processors (Firebase, Google Cloud, Gemini, XRPL infrastructure providers) is available on request via lotus@neumatics.eu. We will publish the list on this page in the next revision.
Updates
We will post material changes here and notify account holders via email. The "Last updated" date at the top of this page reflects the most recent revision.