Skip to content
Neiro Labs

Privacy policy

This page explains in plain language what data we process about you, why and for how long, who we share it with and how to use your rights. It also covers cookies.

Last updated:

Who we are

Neiro Labs is a brand of SIA Blusa Entertainment. The controller of your data is SIA Blusa Entertainment, registration No. 40203726725, registered address: Dārza iela 6, Zālīte, Iecavas pag., Bauskas nov., LV-3913, Latvia.

For anything about your data, write to hello@neirolabs.com. A person will reply, not a bot.

In short

  • The public website uses no cookies, analytics, ad pixels or third-party scripts.
  • We use what you write in the contact form to reply to you and prepare a quote.
  • We do not sell your data or use it for advertising.
  • Our servers and e-mail are in the European Union.
  • You can ask to see, correct or delete your data at any time.

Contact form

What we receive: your name, e-mail and the message you write in the form, plus the page language and the time it was sent. The AI demo button "Request this solution" only puts text into the message field. Nothing is sent until you press "Send message" yourself. The demo answers are prepared in advance and run in your browser, so we do not receive what you type in the demo.

Why: to answer your question and, if you wish, prepare a quote. The legal basis is taking steps at your request before entering into a contract (GDPR Article 6(1)(b)). If your question is not about working together, the basis is our legitimate interest in replying to a message we received (GDPR Article 6(1)(f)).

How: we store the message on our server and send a notification to our mailbox through Zoho Mail (EU data centre). The time, your name and e-mail are also written to the server's technical log. To protect against spam, one IP address can send no more than 5 messages in 10 minutes. For this limit the IP address is held only in the server's working memory and is not saved to a file.

We may use an AI tool (Anthropic Claude) to draft a reply. A person always checks and sends the reply.

How long: if we do not start working together, we delete the message 12 months after our last contact. If you become a client, the data is kept as client data (see "Clients").

Server and technical logs

The website runs on Hetzner servers in the European Union. Like almost every web server, ours records the IP address, time, requested address and browser name for each request. We use these logs only for security (for example, to block attacks) and to find errors. The basis is our legitimate interest in keeping the website secure (GDPR Article 6(1)(f)). The logs are deleted automatically after a set period, and we do not use them to identify you.

Cookies

The public website (home page, service and case study pages, in both languages) uses no cookies, analytics, ad pixels or third-party scripts. Fonts are loaded from our own server too, not from Google or other services. That is why we do not ask for consent and there is no cookie banner. The same applies to our sample design pages.

Birojs (/birojs) is an internal system used only by the company owner for invoicing. It uses only strictly necessary cookies to keep the login secure. They do not need consent:

  • __Host-birojs_pre — login step between the password and the e-mail code, 10 minutes
  • __Host-birojs_sess — login session, up to 7 days
  • __Host-birojs_dev — remembers a trusted device, up to 30 days

If we ever add analytics or other non-essential cookies, we will ask for your consent first and update this policy.

If we write to you first (businesses)

Sometimes we write first to businesses that our services could help. We only write to legal entities at a work e-mail address they have published. We do not send marketing e-mails to private individuals without their prior consent.

What data: the company name, its public e-mail, website address and what we noticed on your public website. The source is publicly available information, such as your website or the business register. We name the exact source in the first e-mail.

Basis: our legitimate interest in offering services to other businesses (GDPR Article 6(1)(f)). Before writing, we check that the message would not be unreasonably intrusive.

Opting out: just reply "no" or "stop". We stop writing straight away. You also have the right to object at any time to the use of your data for direct marketing, and we will then no longer use it for that purpose (GDPR Article 21).

How long: if you do not reply, we remove your contact from our list after 6 months. If you opt out, we keep only the company name, e-mail and date in a do-not-contact list so that we never write to you again. We keep that entry for as long as we send outreach e-mails.

Clients

If we work together, we process company details and contact person data: name, e-mail, phone, bank account, contracts, invoices and project correspondence. The basis is performing the contract (GDPR Article 6(1)(b)) and our legal obligation to keep accounting records (GDPR Article 6(1)(c)). We keep invoices and accounting documents for as long as Latvian accounting and tax law requires. Everything else is deleted after the work ends, once it is no longer needed for the contract or possible disputes.

We send invoices by e-mail through Zoho Mail. If you pay by card, Stripe processes the payment. We never see or store your card details. If you pay by bank transfer, we match the payment to the invoice using the bank statement. We do not keep the statement file itself.

If we maintain or host your system and it contains personal data of your customers, we process that data on your behalf as a processor. For this we sign a separate data processing agreement.

Who we share data with

We share data only with service providers we cannot work without, and only as much as needed:

  • Hetzner Online GmbH — servers in the European Union (website, contact form messages, Birojs, backups)
  • Zoho — e-mail, EU data centre
  • Stripe — card payments
  • Anthropic — AI tool for drafting replies and documents
  • our bank — bank transfers
  • public authorities — only when the law requires it

Stripe and Anthropic may also process data outside the European Union. In that case they use safeguards allowed by the GDPR, such as the European Commission's standard contractual clauses. We do not sell data, and we do not make automated decisions that have a legal effect on you.

How long we keep data

  • Contact form messages — 12 months after our last contact, if we do not start working together
  • Outreach list — 6 months, if you do not reply
  • Do-not-contact list — for as long as we send outreach e-mails
  • Invoices and accounting documents — as long as Latvian law requires
  • Server logs — deleted automatically after a set period
  • Birojs cookies — from 10 minutes to 30 days (see "Cookies")

Your rights

You have the right to:

  • find out what data we hold about you and get a copy
  • have inaccurate data corrected
  • have your data deleted
  • restrict how it is processed
  • receive your data in a machine-readable format (portability)
  • object to processing based on legitimate interests, including direct marketing

Write to hello@neirolabs.com. We will reply within one month at the latest. If needed, we will ask you to confirm that the request comes from you. If you think we are handling your data incorrectly, you can complain to the Latvian Data State Inspectorate: www.dvi.gov.lv or to the data protection authority in your own EU country.

How we protect data

The website works only over an encrypted connection (HTTPS). Only the company owner can access contact form messages and Birojs. Logging in to Birojs takes a password and a code sent by e-mail. Backups are kept in an EU server environment with restricted access.

Changes to this policy

If anything changes, we will publish the new version here and update the date at the top and bottom of this page.

Last updated:

Let's talk about your business

Tell us what slows you down. We'll reply with a concrete suggestion and a price range — free of charge.

hello@neirolabs.com

Riga, UTC+2/+3 · Prices in EUR · card or bank transfer

We use your details only to reply to you. Privacy policy