Security & Privacy at Neoma
Security & Privacy
Your trust is our foundation. We protect your data with industry-leading security measures and privacy-by-design principles.
Certifications & Compliance
Independently verified security and privacy standards
ISO 27001
Information Security Management System certified
RGPD
EU General Data Protection Regulation compliant
PDPA
Singapore & Thailand Personal Data Protection Act compliant
AES-256
Bank-grade encryption for all data at rest and in transit
Our Approach Security by Design
Security isn't an afterthought at Neoma—it's built into every layer of our platform. From architecture to deployment, we follow industry best practices to ensure your data remains protected.
End-to-End Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
Role-Based Access Control
Granular permissions ensure users only access what they need
Regular Security Audits
Third-party penetration testing and vulnerability assessments
24/7 Monitoring
Real-time threat detection and incident response
Infrastructure
SOC 2 Type II Compliant
Data Centres
Multi-Region Redundancy
Uptime SLA
99.9% Guaranteed
Privacy by Design
Data protection is embedded into every feature we build
Data Minimisation
We collect only the data necessary for the specific purpose. No more, no less.
Automatic Data Retention
Guest data is automatically deleted after checkout or event completion—no manual intervention needed.
Geofencing Protection
Biometric and personal data becomes inaccessible when devices leave the designated premises.
Consent Management
Built-in tools for obtaining, tracking, and managing user consent with ~90% opt-in rates.
Transparency
Clear privacy notices explain what data is collected, why, and how long it's retained.
Right to Erasure
One-click data deletion for complete removal of all personal information on request.
How We Handle Your Data
Understanding our roles and responsibilities
Neoma as Data Processor
Gaia Platform & App
When you use Gaia, Neoma acts as a Data Processor. Your organisation remains the Data Controller.
- Personal data is encrypted by the application and not accessible to Neoma
- Data can be stored locally or in our secure cloud environment
- Geofencing ensures data protection if devices leave premises
- Processing occurs only under your defined instructions
Neoma as Data Controller
Marketing & Business Operations
For marketing, sales, and legal compliance, Neoma acts as the Data Controller.
- Contact information for sales and marketing communications
- Business partner and vendor information
- Information required for legal and tax obligations
- All data protected with AES-256 encryption per ISO 27001
Your Rights
Under GDPR and PDPA, you have the following rights regarding your personal data
Access
Request a copy of your data
Rectification
Correct inaccurate data
Erasure
Right to be forgotten
Portability
Transfer your data
Restriction
Limit processing
Objection
Withdraw consent
We respond to all requests within 30 days. Complex requests may require up to 60 additional days.
Essential Cookies Only
We only use cookies necessary for site security and performance. No tracking cookies without consent.
Analytics Opt-Out
You can opt out of analytics at any time via our cookie preferences or by visiting retention.com/optout
No Third-Party Sharing
We never sell your data to third parties for marketing purposes.
Website Visitors Cookies & Tracking
When you visit our website, we respect your privacy choices. We only collect essential cookies for site functionality and security.
If you opt in to analytics, we may use cookies to understand how you interact with our site to improve your experience. You can change your preferences at any time.
Contact Our Data Protection Officer
Have questions about how we handle your data? Want to exercise your privacy rights? Our DPO is here to help.
General Enquiries
contactus@neoma.aiNeoma Ltd
Unit 510, 5W Enterprise Place
Hong Kong Science Park
Sha Tin, Hong Kong
Phone: +852 3970 5670
Last Updated: February 2026
We update this policy as necessary. Significant changes will be posted on our website before taking effect. We encourage you to periodically review this page.





