Neat and GDPR
Last updated September 20, 2026
Neat brings people together with beautifully simple video collaboration devices and experiences. Protecting the privacy and security of the people who use our products is core to how we build and run our business. This page explains how Neat complies with applicable privacy laws, including the EU General Data Protection Regulation (GDPR), US state privacy laws (including but not limited to the California Consumer Privacy Act (CCPA)), and similar laws, and where to find the legal details behind it.
Our data processing roles
Neat acts as a data processor (or “service provider”) when handling personal data on behalf of our customers through Neat devices and Neat Pulse — for example, meeting metadata, device usage data, and diagnostic information generated in the course of providing our services. Our customers act as the data controller for this data, since they determine why and how it is used.
Neat acts as a data controller (or “business”) for the personal data we collect directly, such as information about our own employees, and data collected through our marketing, sales, and support channels (for example, this website and our support portal).
Legal basis for processing
Where Neat processes personal data as a controller, we rely on one or more of the following legal bases, depending on the activity:
- Contract necessity — to provide products and services a customer has purchased.
- Legitimate interest — for security monitoring, fraud prevention, and product improvement, balanced against the rights of the individual.
- Consent — where required, such as certain marketing communications or optional data collection (for example, voice recordings collected during product testing).
- Legal obligation — where processing is required to comply with applicable law.
The specific legal basis for each processing activity is set out in our Privacy and Cookies Policies.
What data we process, and why
Depending on how a customer uses our products, Neat may process:
- Account and administrator information (name, email, organization).
- Device and meeting metadata (device IDs, usage statistics, diagnostic logs).
- Audio and video content passed through during a call, which Neat does not access or store as part of normal operation.
- Support and service data submitted when a customer contacts us for help.
Sub-processors
Neat uses a limited number of sub-processors to help deliver our services, such as cloud hosting and infrastructure providers. A current list of sub-processors is maintained in Exhibit C in Neat’s Data Processing Addendum (DPA).
We review our sub-processors regularly and will notify customers of material changes in accordance with the terms of our DPA.
International data transfers
Where European Economic Area or UK personal data is transferred outside the European Economic Area/UK, Neat relies on appropriate safeguards recognized under GDPR, such as the European Commission’s Standard Contractual Clauses (SCCs).
How we protect data
Neat maintains a security program built around recognized industry standards. Our technical and organizational measures include access controls, encryption, logging and monitoring, vulnerability management, and incident response processes.
Neat is certified to ISO 27001, the international standard for information security management, and is in the process of a SOC 2 Type II audit – available later in Q4 2026.
Further details on our security practices are available on request through our sales and security contacts, and in our published security documentation.
Data Subject Rights
Where Neat acts as a data controller, applicable law may afford individuals the right to request access to, correct, delete, or restrict the use of their personal data, and to object to certain processing or request data portability, subject to applicable exceptions.
To submit a request, data subjects can contact us at neat.privacy@neat.no. We will verify the request and respond within the timeframe required by applicable law.
Where Neat processes data as a processor on behalf of a customer, requests from that customer’s end users should generally be directed to the customer, who is best positioned to fulfill the request; Neat will support the customer as required under the DPA.
Breach notification
If Neat becomes aware of a personal data breach affecting customer data requiring notice under applicable law, we will notify affected customers without undue delay, consistent with our obligations under the DPA and applicable law.
The Data Processing Addendum
This page provides a summary. The legally binding terms governing Neat’s processing of personal data on behalf of customers are set out in our Data Processing Addendum (DPA). Where anything on this page conflicts with the DPA, the DPA governs.
Contact us
For any questions about data privacy or this statement, contact us at neat.privacy@neat.no.