PRIVACY POLICY
Effective July 27, 2026
This Privacy Policy explains how NEURONETIX LLC, doing business through NerveLab (“NerveLab,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information in connection with our websites, the NerveLab autonomous operating system (“AOS”), Artemis, demonstrations, trials, customer accounts, and related communications and services (collectively, the “Services”).
1. Scope and roles
This Policy applies when you visit a NerveLab website, request information or access, communicate with us, participate in a demonstration or trial, use the Services, or interact with Artemis on behalf of a NerveLab customer.
NerveLab may process personal information in different roles:
For website visitors, prospective customers, account administrators, and NerveLab’s own business contacts, NerveLab generally determines the purposes and means of processing.
For prospect, lead, customer, and relationship information supplied or connected by a business customer, NerveLab generally processes information on that customer’s behalf and under its instructions. The customer’s privacy notice and instructions may also apply.
Customers determine which approved relationships, pipelines, facts, channels, contact periods, and authority the Services may use. Customers remain responsible for the lawful basis for their instructions.
2. Categories of information we collect
Information you provide
We may collect:
Identifiers and contact details, including name, business name, email address, postal address, telephone number, username, and account identifiers.
Professional or employment information, including employer, role, industry, brokerage or agency affiliation, and professional licensing status.
Account, profile, and authentication information.
Sales, company, offer, workflow, pipeline, prospect, and customer information that an authorized customer submits or connects.
Communications, requests, feedback, support records, and information submitted during demonstrations, trials, onboarding, or use.
Billing and transaction information. Payment-card information may be handled directly by a payment processor rather than stored by NerveLab.
Communication preferences, contact restrictions, consent records, recording-consent status, and opt-out or do-not-contact requests.
Information collected through the Services
Depending on the enabled features and customer instructions, we may process:
Voice, SMS, email, and other authorized communication content and metadata.
Call direction, date, time, duration, delivery status, channel, sender, recipient, and outcome.
Recordings and transcripts when enabled and when required notice and consent conditions have been satisfied.
Approved business facts, product or service information, conversation history, preferences, objections, commitments, questions, outcomes, summaries, next steps, handoff records, and relationship context.
System-generated inferences or classifications used to provide relationship continuity, workflow suggestions, escalation, safeguards, or customer-authorized actions.
Audit, access, security, suppression, delivery, and compliance events.
Information collected automatically
We may collect device type, browser, operating system, IP address, approximate location derived from IP, referral source, pages viewed, feature use, timestamps, logs, diagnostic information, cookie identifiers, and security events. We may use cookies and similar technologies for essential operation, preferences, measurement, fraud prevention, and security. If we later use advertising or cross-context behavioral technologies, we will update this Policy and provide required choices before doing so.
Sources of information
Information may come from:
You, an account administrator, or another authorized user.
A NerveLab business customer.
Customer-authorized CRM, calendar, email, telecommunications, or other connected systems.
Communications with Artemis or NerveLab.
Service providers supporting the Services.
Publicly available professional or business sources when used for a lawful business purpose.
Automated collection through NerveLab websites and Services.
3. How we use information
We may use personal information to:
Provide, configure, personalize, operate, secure, and support the Services.
Establish accounts, process access requests, provide demonstrations and trials, and administer subscriptions.
Carry out customer-authorized communications and workflows.
Maintain approved relationship context and activity history across enabled channels.
Generate summaries, alerts, workflow suggestions, safeguards, escalation, handoffs, and other configured outputs.
Authenticate users, enforce permissions, maintain audit records, and prevent fraud, misuse, and security incidents.
Process payments and manage subscriptions.
Troubleshoot, test, maintain, and improve reliability, safety, and product performance.
Comply with law, enforce agreements, resolve disputes, and protect users, prospects, customers, NerveLab, and others.
Send service communications and, where permitted, NerveLab marketing. You may opt out of marketing communications.
NerveLab will not use customer-provided prospect or relationship content to train a generally available model unless the applicable customer agreement expressly authorizes that use. Aggregated or de-identified information may be used to operate, analyze, secure, and improve the Services when it cannot reasonably be used to identify an individual.
4. Automated systems and human authority
AOS and Artemis use automated and generative processes. Depending on configuration, the Services may analyze approved information, maintain relationship context, generate communications, suggest or select a next step, and perform customer-authorized actions within configured boundaries.
Automated outputs may contain errors, omissions, or inaccuracies. Customers are responsible for providing accurate approved facts, defining authority and safeguards, and maintaining qualified human review for proposals, contracts, financing, regulated advice, licensed acts, binding coverage, showings, and other actions that require human authority.
The Services are not intended to make decisions that determine an individual’s eligibility for employment, housing, credit, insurance, medical treatment, or another legal or similarly significant right. Customers may not configure or use the Services for prohibited high-impact decisions.
5. How we disclose information
We may disclose personal information:
To the NerveLab customer that authorized the relevant account, data connection, workflow, or Artemis interaction.
To service providers and contractors supporting hosting, telecommunications, email, messaging, analytics, security, payments, customer support, and other business operations.
To connected services at the customer’s direction.
To professional advisers subject to appropriate duties of confidentiality.
During a financing, merger, acquisition, reorganization, sale of assets, or similar transaction.
When required by law, subpoena, court order, or legal process.
When reasonably necessary to protect rights, safety, property, security, or the integrity of the Services.
We contractually restrict service providers from retaining, using, or disclosing personal information outside the services they provide to us, except as permitted by law. We do not sell personal information for money. We do not knowingly share personal information for cross-context behavioral advertising.
6. Communications, consent, and recording
Customers must have the authority and legally required consent to provide information to NerveLab and direct the Services to contact a person. Consent to receive a call, artificial or prerecorded voice communication, text, or email is distinct from consent to record a communication.
Where recording or transcription is enabled, the applicable customer must configure and use required notices and consent controls. NerveLab may prevent, suspend, or terminate recording or communication features when required consent, notice, or configuration is absent.
Recipients may revoke consent or request no further contact through any reasonable method that clearly communicates the request. Replying STOP to an SMS is one supported method. Suppression and consent records may be retained to ensure that the request continues to be honored.
7. Data retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, based on:
The duration of the account and business relationship.
The nature, amount, and sensitivity of the information.
Customer configuration and instructions.
Security, suppression, fraud-prevention, audit, and dispute needs.
Contractual, tax, accounting, regulatory, and legal obligations.
Customer data is deleted, returned, or de-identified following termination or a valid customer instruction, subject to applicable law, backup cycles, security needs, and records that must be retained to honor opt-outs or establish compliance. Product-specific retention settings for recordings, transcripts, and derived content will be disclosed before those features are activated.
8. Security
We use administrative, technical, and organizational measures designed to protect personal information. No transmission or storage method is completely secure, and we cannot guarantee absolute security. If a security incident triggers a legal notification duty, we will provide required notices within the applicable time.
9. Your choices and rights
Depending on your location and our role, you may have rights to:
Know or access personal information.
Correct inaccurate personal information.
Delete personal information, subject to exceptions.
Obtain a portable copy of certain information.
Object to or limit certain processing.
Opt out of a sale, sharing, targeted advertising, or certain automated processing when applicable.
Withdraw consent when processing relies on consent.
Appeal a denied privacy request where applicable.
Exercise rights without unlawful discrimination.
To submit a privacy request, email privacy@nervelab.io or write to the address in Section 15. We may verify your identity, authority, and relationship to the information. An authorized agent may submit a request where permitted by law, subject to verification. If we process information solely for a customer, we may direct the request to that customer.
10. California disclosures
California residents may have rights under applicable California law to know, access, correct, delete, and obtain information about collection and disclosure; to opt out of sale or sharing; to limit certain uses of sensitive personal information; and to receive equal service and pricing.
During the preceding 12 months, NerveLab may have collected the categories described in Section 2, used them for the purposes described in Section 3, and disclosed them to the recipient categories described in Section 5. We do not knowingly sell personal information or share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes requiring a right to limit unless disclosed otherwise before that processing begins.
We will generally respond to a verified California request within 45 days, subject to a permitted extension with notice. If we deny a request, we will explain the basis and any available appeal or regulatory recourse.
11. Other U.S. state rights
Residents of states with applicable comprehensive privacy laws may have additional rights, including appeal rights. We will honor applicable rights based on residency, our legal role, and statutory exceptions.
12. Children
The Services are intended for businesses and adults. They are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Customers may not use the Services to target children or submit children’s information without lawful authority.
13. International use
NerveLab is based in the United States. Information may be processed in the United States or other locations where our providers operate, subject to applicable safeguards.
14. Changes
We may update this Policy as the Services or legal obligations change. We will post the revised version with a new effective date and provide additional notice where required.
15. Contact
NEURONETIX LLC / NerveLab
130 W. Corona Mall, Suite 203
Corona, California 92879
privacy@nervelab.io