Last updated: [DATE] · Version 0.1 (draft)
Your safety means trusting us with sensitive information. This policy explains exactly what we collect, why, and the control you keep over it.
NeoAria is a project operated by Scilacci Ltd ("Scilacci", "we", "us", "our"), a company registered in England and Wales (company number 15455827), incorporated on 31 January 2024, with its registered office at 18 Rye Mews, Waterbeach, Cambridge, CB25 9RS. Our VAT registration number is GB460016239. We are the data controller responsible for your personal data when you use our website, the NeoAria app, and NeoBand devices (together, the "Services").
We are registered with the UK Information Commissioner's Office (ICO) under registration number [ICO REGISTRATION NUMBER]. Our Data Protection contact can be reached at privacy@neoaria.co.uk.
This policy explains what personal data we collect, why, how we protect it, and the choices and rights you have. We have tried to keep it clear. If anything is unclear, contact us and we will explain.
This policy applies to personal data we process about:
NeoAria is based in the United Kingdom and offers its Services worldwide. We comply with the UK GDPR and the Data Protection Act 2018. Where we offer Services to people in the European Economic Area, we also act consistently with the EU GDPR. If you use our Services from another country, local data protection laws may also give you rights — see section 10.
We collect different categories of data depending on how you interact with us:
| Category | Examples |
|---|---|
| Account & identity | Name, email address, phone number, password (stored encrypted), profile photo. |
| Safety circle | Names and contact details of the trusted contacts you choose to add, and the sharing permissions you set for each. |
| Device data | NeoBand serial number, pairing status, battery level, connection and readiness status. |
| Location data | Your device location when you trigger an SOS, use live tracking, check-in, or journey planning (see section 4). |
| Audio & evidence | Optional, opt-in audio recordings and event logs captured during an SOS (see section 4). |
| Community reports | Risk reports you submit to NeoSense, including incident type and area (submitted without your name where possible). |
| Usage & technical | App and website interactions, device type, operating system, IP address, and diagnostic logs. |
| Communications | Messages you send us, support requests, and early-access form submissions. |
Personal safety inherently involves sensitive data. We treat location, audio, and any data that may reveal health or safety circumstances with the highest level of care, and we collect it only when necessary for the safety feature you are using.
We process your location only to deliver safety features you choose to use — sending your position during an SOS, sharing live location with your trusted contacts, supporting check-in and arrival alerts, and journey planning. You control location permissions on your device and can withdraw them at any time, though some features will not work without them.
Audio recording is opt-in and is only intended to capture short clips during an SOS event to support investigation. Evidence logs are stored securely and are auto-deleted after 30 days unless you choose to save them. You can review, save, export, or delete evidence in the app.
Some data we process (for example, information that could reveal a safety incident or vulnerability) may constitute special category data under UK GDPR. Where this is the case, we rely on an appropriate condition under Article 9 — typically your explicit consent, or processing necessary to protect someone's vital interests in an emergency. Before piloting features involving high-risk processing, we complete a Data Protection Impact Assessment (DPIA).
Under UK GDPR we rely on one or more of the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Providing the Services you sign up for | Performance of a contract |
| Sending alerts and sharing location/audio | Consent; and/or vital interests in an emergency |
| Special category (safety/health-related) data | Explicit consent; and/or vital interests (Article 9) |
| Improving and securing the Services | Legitimate interests |
| Marketing and early-access updates | Consent |
| Meeting legal and regulatory duties | Legal obligation |
Where we rely on consent, you can withdraw it at any time without affecting processing carried out before withdrawal. Where we rely on legitimate interests, we balance those interests against your rights and you can object (see section 10).
NeoAria is based in the UK and serves users worldwide, so your data may be transferred to and processed in countries outside your own, including outside the UK and EEA. Where we transfer personal data internationally, we use appropriate safeguards recognised under UK data protection law, such as:
You can request more information about the safeguards we use by contacting privacy@neoaria.co.uk.
We keep personal data only as long as necessary for the purposes set out above:
| Data | Typical retention |
|---|---|
| Account data | For as long as your account is active, then deleted or anonymised within [X] months of closure. |
| SOS evidence (audio/logs) | Auto-deleted after 30 days unless you save it. |
| Alert & location history | [RETENTION PERIOD], unless needed for an ongoing safety or legal matter. |
| Community reports | [RETENTION PERIOD], held in de-identified form where possible. |
| Support & marketing | Until you unsubscribe or for [PERIOD] after last contact. |
Subject to applicable law, you have the right to:
To exercise any right, contact privacy@neoaria.co.uk. We will respond within the timeframes required by law (usually one month under UK GDPR). Depending on where you live, you may have additional rights — for example, under the EU GDPR, or, for California residents, under the CCPA/CPRA.
We use technical and organisational measures designed to protect your data, including encryption in transit and at rest, access controls, and data minimisation. No system is perfectly secure, but we work to protect your data and will notify you and the ICO of a personal data breach where required by law.
NeoBand can be used by families to help protect children, but accounts are intended to be managed by an adult. Where a child uses the Services, a parent or guardian must set up and oversee the account and provide any required consent. We do not knowingly collect data from children except through a supervising adult. If you believe a child has provided us data without appropriate consent, contact us and we will take appropriate steps.
We may update this policy as our Services and the law evolve. We will post the updated version here with a revised "last updated" date, and where changes are significant we will take reasonable steps to notify you.
For any privacy question or to exercise your rights, contact us at privacy@neoaria.co.uk or write to Scilacci Ltd, 18 Rye Mews, Waterbeach, Cambridge, CB25 9RS.
If you are unhappy with how we handle your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or to your local supervisory authority if you are outside the UK. We would, however, appreciate the chance to address your concerns first.