// SKIP TO CONTENT
NEICRONE
// Legal
0305

Data Processing

What Neicrone does with partner data when acting as a processor, and how to get a signed Data Processing Agreement in place. This page states our standing position; the executed DPA is the instrument that binds.

// LAST REVIEWED 2026-09-28


Status of this page

This is a summary of our data processing position, published so a prospective partner can assess it before engaging. It is not itself an executed agreement. Where we process personal data on a partner’s behalf, we enter a written DPA that incorporates the terms below, and standard contractual clauses where a transfer requires them. Request one at privacy@neicrone.com.

Roles

For operational data flowing through a deployment — sensor streams, vehicle and machine telemetry, positional traces, site imagery — the partner is the controller and Neicrone is the processor. We act on the partner’s documented instructions and do not determine the purposes of that processing.

For our own website visitors and intake contacts we are the controller; that is covered by the Privacy Policy instead.

Subject matter and duration

  • Subject matter — collection, transport, storage, and processing of field and telemetry data for validation and evaluation of the partner’s systems.
  • Duration — the term of the engagement, plus any agreed retention window for evidentiary records.
  • Categories of data subject — typically operators, drivers, and personnel present in instrumented environments, and incidental members of the public captured by sensors in public space.
  • Categories of personal data — where present: imagery and video that may contain identifiable individuals or vehicles, location traces tied to an operator or asset, and operator identifiers in machine logs.

Chain of custody

Chain of custody is the product, not a policy afterthought. Records carry their origin — which unit, which sensor, which run — from capture through to the point a dataset is handed over, so a partner can establish where a given observation came from and what happened to it in between. Transformations are recorded rather than applied silently.

Where a deployment operates in public space, minimisation at the edge is available and is the default we recommend: redact or drop identifying detail before it leaves the unit, rather than collecting it and deleting it later.

Security measures

  • Encryption in transit for all data leaving a field unit or crossing a network boundary, and encryption at rest for stored datasets.
  • Access to partner data scoped per engagement; console access is granted per city or dataset, not globally.
  • Least-privilege credentials for infrastructure, rotated on personnel change.
  • Operational logging of access to partner datasets.
  • Documented restore path for stored datasets.

Specific technical and organisational measures are scheduled to the executed DPA, so they can be assessed against the deployment they actually apply to rather than in the abstract.

Sub-processors

We use infrastructure sub-processors for hosting and edge delivery, managed database services, and email delivery. Each is bound by written terms no less protective than ours. A current list is provided with the DPA on request, and we give notice before adding a sub-processor that touches partner data, so the partner can object.

Personnel, assistance, and deletion

  • Personnel with access to partner data are bound by confidentiality obligations.
  • We assist the controller with data-subject requests, impact assessments, and regulator consultation to the extent the processing is ours.
  • We notify the controller without undue delay on becoming aware of a personal data breach affecting their data.
  • On termination we delete or return partner data at the controller’s election, subject to any retention the law requires of us.

Audit

We make available the information needed to demonstrate compliance with these obligations and accommodate audits by the controller or an appointed auditor, on reasonable notice and subject to confidentiality.

Contact

DPA requests and data protection questions: privacy@neicrone.com.