This policy explains what personal data Neptus Software Ltd collects through the website www.neptus.co.uk, why we collect it, how we use it, and your rights under UK data protection law.
If you are a patient whose data is processed by a clinic using our DentaAI products, please contact your clinic directly — they are the data controller for that data, not Neptus Software Ltd.
1. Who we are
Neptus Software Ltd is the data controller for personal data collected through this website.
Neptus Software Ltd
Demsa Accounts
565 Green Lanes
Haringey, London
England, N8 0RL
Contact: ncaglayan@neptus.co.uk
We are not currently required to register with the Information Commissioner's Office (ICO) as a data controller, but we comply fully with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data we collect
We only collect personal data that you actively provide to us via our website contact forms. We do not use analytics, tracking pixels, or profiling tools.
| Data | Where collected | Required? |
|---|---|---|
| Full name | Demo request form (neptus.co.uk & DentaAI page) | Yes |
| Email address | Demo request form | Yes |
| Practice type | Demo request form (neptus.co.uk) | Yes |
| Clinic name | Demo request form (DentaAI page) | No |
| Clinic size / appointment volume | Demo request form (DentaAI page) | No |
| Free-text message | Demo request form (optional notes field) | No |
| IP address & browser information | Automatically by our web hosting provider when you visit the site | N/A |
We do not collect special category data (such as health data, biometric data, or data revealing racial or ethnic origin) through this website.
3. How we use your data
- To respond to your demo or enquiry request — we use your name and email to arrange a product demonstration and answer any questions you have raised.
- To follow up after a demo — if you attended a demonstration and we have not yet heard from you, we may send a brief follow-up. You can opt out at any time by replying to any of our emails.
- To maintain website security — web server logs (including IP addresses) are used solely for security monitoring and diagnosing technical issues.
We do not sell, rent, or share your personal data with any third parties for marketing purposes.
4. Legal basis for processing
Under Article 6 of UK GDPR, we rely on the following lawful bases:
| Processing activity | Legal basis (UK GDPR Art. 6) |
|---|---|
| Responding to a demo or contact form submission | Legitimate interests (Art. 6(1)(f)) — we have a legitimate interest in responding to business enquiries, and this is not overridden by your privacy interests given the business context of the data. |
| Follow-up communications with prospective customers | Legitimate interests (Art. 6(1)(f)) — limited, proportionate follow-up with people who have proactively contacted us about our services. |
| Web server logging (IP addresses) | Legitimate interests (Art. 6(1)(f)) — security monitoring and technical maintenance of the website. |
5. Third-party services
We use the following third-party services on this website. Each is a data processor acting on our behalf under a data processing agreement (or equivalent terms).
| Service | Purpose | Data shared | Location |
|---|---|---|---|
| Formspree (formspree.io) | Receives and delivers contact form submissions to us by email | Name, email, form fields you submit | United States (see Section 7) |
| Google Fonts (fonts.googleapis.com) | Loads web fonts for page display | Your IP address and browser user agent are sent to Google's servers to serve the font files | Various (Google LLC, USA) |
| Web hosting provider | Hosts and serves the neptus.co.uk website | Standard server access logs (IP, timestamp, pages visited) | UK / EEA |
We do not use Google Analytics, Meta Pixel, or any other advertising or analytics trackers.
6. How long we keep your data
| Data | Retention period |
|---|---|
| Contact and demo form submissions | 12 months from the date of submission, or until the enquiry is concluded and you request deletion — whichever is sooner |
| Customer correspondence (email threads) | 3 years from last contact, in line with standard business record-keeping |
| Web server logs | 90 days, then deleted automatically by the hosting provider |
After these periods, data is securely deleted or anonymised.
7. International data transfers
When you submit a form on this website, your data is processed by Formspree Inc. (a US company). The UK does not yet have an adequacy decision for the United States. Formspree transfers personal data to the US using Standard Contractual Clauses (SCCs) in conjunction with the UK International Data Transfer Agreement (UK IDTA), providing appropriate safeguards under UK GDPR. For further details, see Formspree's Privacy Policy.
Google Fonts transfers font-serving request data (including IP addresses) to Google LLC servers. Google participates in the EU-US Data Privacy Framework and uses SCCs for UK transfers. For details, see Google's Privacy Policy.
All other data processing is carried out within the UK or EEA.
8. Cookies and tracking
We do not use cookies for analytics, advertising, or user tracking on neptus.co.uk.
Our website does not set any first-party cookies. Formspree may set a session cookie solely to process form submissions (used to prevent duplicate submissions and spam). This cookie does not track you across other websites and is discarded when your browser session ends.
As we do not use non-essential cookies, we are not required to display a cookie consent banner under PECR (Privacy and Electronic Communications Regulations 2003).
9. Your rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you (a Subject Access Request).
- Right to rectification — you may ask us to correct any inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — you may ask us to delete your personal data where we have no compelling reason to continue processing it.
- Right to restriction — you may ask us to restrict processing of your data in certain circumstances.
- Right to data portability — where processing is based on your consent or a contract, you may request your data in a structured, machine-readable format.
- Right to object — you may object at any time to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Rights related to automated decision-making — we do not carry out any automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any of these rights, please contact us at ncaglayan@neptus.co.uk. We will respond within one calendar month as required by UK GDPR. We may need to verify your identity before fulfilling a request.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, or legal obligations. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically.
For material changes, we will take reasonable steps to notify affected individuals (for example, by emailing people who have previously submitted a form).
11. Contact us
For any questions, requests, or concerns about this Privacy Policy or how we handle your personal data, please contact:
Neptus Software Ltd
Demsa Accounts, 565 Green Lanes, Haringey, London, England, N8 0RL
Email: ncaglayan@neptus.co.uk