Security & Privacy at Neoma

Enterprise-Grade Security

Security & Privacy

Your trust is our foundation. We protect your data with industry-leading security measures and privacy-by-design principles.

Certifications & Compliance

Independently verified security and privacy standards

ISO 27001

Information Security Management System certified

RGPD

EU General Data Protection Regulation compliant

PDPA

Singapore & Thailand Personal Data Protection Act compliant

AES-256

Bank-grade encryption for all data at rest and in transit


Our Approach Security by Design

Security isn't an afterthought at Neoma—it's built into every layer of our platform. From architecture to deployment, we follow industry best practices to ensure your data remains protected.

End-to-End Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256)

Role-Based Access Control

Granular permissions ensure users only access what they need

Regular Security Audits

Third-party penetration testing and vulnerability assessments

24/7 Monitoring

Real-time threat detection and incident response

Infrastructure

SOC 2 Type II Compliant

Data Centres

Multi-Region Redundancy

Uptime SLA

99.9% Guaranteed


Privacy by Design

Data protection is embedded into every feature we build

Data Minimisation

We collect only the data necessary for the specific purpose. No more, no less.

Automatic Data Retention

Guest data is automatically deleted after checkout or event completion—no manual intervention needed.

Geofencing Protection

Biometric and personal data becomes inaccessible when devices leave the designated premises.

Consent Management

Built-in tools for obtaining, tracking, and managing user consent with ~90% opt-in rates.

Transparency

Clear privacy notices explain what data is collected, why, and how long it's retained.

Right to Erasure

One-click data deletion for complete removal of all personal information on request.

How We Handle Your Data

Understanding our roles and responsibilities

Neoma as Data Processor

Gaia Platform & App

When you use Gaia, Neoma acts as a Data Processor. Your organisation remains the Data Controller.

  • Personal data is encrypted by the application and not accessible to Neoma
  • Data can be stored locally or in our secure cloud environment
  • Geofencing ensures data protection if devices leave premises
  • Processing occurs only under your defined instructions

Neoma as Data Controller

Marketing & Business Operations

For marketing, sales, and legal compliance, Neoma acts as the Data Controller.

  • Contact information for sales and marketing communications
  • Business partner and vendor information
  • Information required for legal and tax obligations
  • All data protected with AES-256 encryption per ISO 27001

Your Rights

Under GDPR and PDPA, you have the following rights regarding your personal data

Access

Request a copy of your data

Rectification

Correct inaccurate data

Erasure

Right to be forgotten

Portability

Transfer your data

Restriction

Limit processing

Objection

Withdraw consent

We respond to all requests within 30 days. Complex requests may require up to 60 additional days.

Essential Cookies Only

We only use cookies necessary for site security and performance. No tracking cookies without consent.

Analytics Opt-Out

You can opt out of analytics at any time via our cookie preferences or by visiting retention.com/optout

No Third-Party Sharing

We never sell your data to third parties for marketing purposes.

Website Visitors Cookies & Tracking

When you visit our website, we respect your privacy choices. We only collect essential cookies for site functionality and security.

If you opt in to analytics, we may use cookies to understand how you interact with our site to improve your experience. You can change your preferences at any time.


Contact Our Data Protection Officer

Have questions about how we handle your data? Want to exercise your privacy rights? Our DPO is here to help.

General Enquiries

contactus@neoma.ai

Neoma Ltd

Unit 510, 5W Enterprise Place
Hong Kong Science Park
Sha Tin, Hong Kong
Phone: +852 3970 5670

Last Updated: February 2026

We update this policy as necessary. Significant changes will be posted on our website before taking effect. We encourage you to periodically review this page.