Legal // Vol. 02

Privacy Policy

Neon Next Generation PTY LTD is committed to protecting your privacy and handling your personal data with transparency and care. This Policy applies to all users worldwide, regardless of location or jurisdiction.

Version 2.2 | Effective Date: July 18, 2026

ABN: 86 686 080 704

Download .docx

By using our Services, you acknowledge that your personal data will be processed in accordance with this Privacy Policy, our Terms of Service, and our Fair Use Policy. Where your local law grants you rights beyond what is stated here, those rights are preserved. If you do not agree, please discontinue use of our Services immediately.

01

Introduction

Neon Next Generation PTY LTD ("we," "our," "us") is committed to protecting your privacy and handling your personal data with transparency and care. This Privacy Policy ("Policy") describes how we collect, use, disclose, retain, and protect the personal information of all users worldwide who access our website at neonnextgeneration.com and use our Services.

This Policy applies globally to all users, regardless of your location, nationality, or jurisdiction. We have designed our practices to meet a high global standard of privacy protection. Where your local law grants you rights greater than those described here, those rights are preserved and are not waived by this Policy.

This Policy forms part of our Terms of Service and is cross-referenced with our Fair Use Policy. By using our Services, you acknowledge that your personal data will be processed in accordance with this Policy. If you do not agree, please discontinue use of our Services immediately.

02

Who We Are & How to Contact Us

Neon Next Generation PTY LTD is the data controller and operator of this Site. We are a digital-first organisation and do not maintain physical walk-in locations or telephone support.

Privacy & Data

Privacy & Data Rights

privacy@neonnextgeneration.com

General Inquiries

info@neonnextgeneration.com

Legal / Contracts

contact@neonnextgeneration.com

Other Departments

Neon Next Generation PTY LTD  |  ABN: 86 686 080 704

neonnextgeneration.com

If you are unsatisfied with our response to a privacy concern, you have the right to lodge a complaint with the data protection or privacy authority in your country. Contact details for your local authority can typically be found on your government's official website.

03

Information We Collect

We collect only what is reasonably necessary to deliver and improve our Services.

3.1 Personal Information You Provide

  • Full name
  • Email address and phone number
  • Billing and mailing address
  • Company name (if applicable)
  • Username and password (stored in hashed form — never plain text)
  • Profile information (avatar, bio, preferences)
  • Communications you send us (support tickets, contact forms, feedback, surveys)

3.2 Account & Usage Data (Automatic)

  • IP address (used for approximate geolocation and security)
  • Browser type, version, and language settings
  • Operating system and device type
  • Login activity and session timestamps
  • Pages visited, features used, and navigation paths
  • Server usage and performance metrics
  • HTTP request metadata and referring URLs

3.3 Payment Information

Payment details are processed securely via our third-party payment processor. We do not store full payment card numbers or CVV codes on our systems. All payment data is tokenised and handled by our processor in accordance with PCI-DSS standards.

3.4 Sensitive Personal Information

We do NOT intentionally collect Sensitive Personal Information, including health or medical data, biometric data, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, government-issued identifiers, or financial account credentials. If you voluntarily include such information in a message or form submission, we will process it only to the extent necessary to respond to your request and will not use it for any other purpose without your explicit consent.

3.5 Information from Third Parties

  • Social media login data (if you authenticate via third-party providers)
  • Analytics data from our analytics provider(s)
  • Payment verification data from payment processors
  • Fraud prevention and security data
04

How We Collect Information

We collect information through:

  • (a)Direct Interactions: Account registration, purchases, form submissions, support communications, and User Content submissions.
  • (b)Automated Technologies: Cookies, web beacons, pixel tags, and server logs — see Section 8.
  • (c)Third-Party Sources: Analytics providers, social networks, payment processors, and fraud prevention services.
  • (d)Publicly Available Sources: Where permitted by applicable law.
06

How We Use Your Data

We use your data strictly for the following purposes:

Service Delivery

Account management, subscriptions, hosting, and VPN services.

Customer Support

Responding to inquiries and resolving issues.

Communications

Service updates, maintenance notices, and (with consent) marketing.

Security & Fraud

Detecting abuse, unauthorised access, DDoS attempts, and other threats.

Analytics & Improvement

Aggregate usage analysis, debugging, and performance optimisation.

Legal Compliance

Responding to regulatory, tax, and law enforcement obligations.

Policy Enforcement

Enforcing our Terms of Service and Fair Use Policy.

Payments

Processing transactions, invoices, and refunds.

We do not use your data for fully automated decision-making that produces legal or significant effects on you without human review. See Section 23.

07

Sharing & Disclosure

✓ We do NOT sell your personal data. We do not share your data for third-party advertising purposes.

We may share your data only with the following categories of recipients:

  • (a)Service Providers: Cloud infrastructure, payment processors, email delivery, analytics, and security monitoring services — all bound by written data processing agreements.
  • (b)Legal Requirements: Court orders, subpoenas, government or regulatory authority requests, or where necessary to protect our legal rights. Where permitted, we will notify you of such requests.
  • (c)Business Transfers: In the event of a merger, acquisition, or asset sale, you will be notified at least 30 days before your data is transferred to a new controller.
  • (d)With Your Consent: For any purpose not described above, only with your prior explicit consent.
  • (e)Anonymised / Aggregated Data: Data that has been irreversibly anonymised and cannot be used to identify you.

We do not share your data with data brokers or advertising networks. All service providers are contractually prohibited from using your data for their own independent purposes.

08

Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve our Services. We use the following tracking technologies:

  • Browser cookies (first-party and third-party)
  • Web beacons and pixel tags
  • Server-side logging

Cookie Categories

Type

Consent

Purpose

Strictly Necessary

No

Core functionality: login, security, load balancing. Cannot be disabled.

Analytics / Performance

Yes

Usage statistics and site improvement.

Functional

Yes

Saved preferences, language, and region settings.

Marketing / Targeting

Yes

Interest-based content (only if applicable and with consent).

Consent & Your Choices

On your first visit, a cookie consent banner allows you to accept or decline non-essential cookies by category. Your consent is recorded with a timestamp. You may update or withdraw cookie consent at any time via the cookie settings link in the Site footer, or by adjusting your browser settings. Withdrawing consent does not affect lawfulness of prior processing. Disabling essential cookies may impair Site functionality.

Analytics Provider

We use analytics tooling to analyse Site traffic under a data processing agreement. IP anonymisation is applied where required by law. You may opt out of analytics tracking via the cookie consent manager or your browser settings.

Do Not Track & Global Privacy Control

There is currently no universally accepted standard for Do Not Track (DNT) signals. We honour Global Privacy Control (GPC) signals as an opt-out of non-essential data sharing where required by applicable law. We will update this section if a uniform DNT standard is established.

09

Your Global Privacy Rights

Regardless of where you are located, you have the following rights with respect to your personal data:

Access

Request a copy of the personal data we hold about you.

Correction

Request correction of inaccurate or incomplete data.

Deletion / Erasure

Request deletion of your data, subject to legal retention obligations.

Restriction

Request that we limit how we use your data while a dispute is resolved.

Portability

Receive your data in a structured, commonly used, machine-readable format.

Objection

Object to processing based on legitimate interests, including direct marketing.

Withdraw Consent

Where processing is consent-based, withdraw at any time without penalty.

Opt-Out of Marketing

Unsubscribe from promotional communications at any time.

Non-Discrimination

You will not be penalised for exercising any privacy right.

Complaint

Lodge a complaint with the data protection authority in your country.

How to Submit a Request

Email: privacy@neonnextgeneration.com
Subject: "Privacy Rights Request — [Your Name]"
Include: Your name, account email, the right you wish to exercise, and your country/region.

We will acknowledge your request within 5 business days and respond in full within 30 days. Where your local law requires a shorter timeframe, we will comply. For complex requests, we may extend by a further 30 days with prior notice. We may verify your identity before processing. We will not charge a fee unless your request is manifestly unfounded or excessive, and only where permitted by law.

You may designate an authorised agent to submit requests on your behalf with written authorisation. We may verify the agent's identity independently.

10

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law:

Account data

Duration of account + 2 years post-closure

Transaction / billing

7 years (tax and legal compliance)

Server / access logs

90 days

Marketing consent records

Duration of consent + 3 years

Support communications

3 years from resolution

Analytics data

13 months

Legal hold data

Duration of proceedings + 1 year

After the applicable period, data is securely deleted or irreversibly anonymised. Deletion requests submitted under Section 9 may be subject to overriding legal retention obligations. We conduct periodic data audits to ensure compliance with these schedules.

11

Data Security

Technical Measures

  • TLS 1.2+ encryption for all data in transit (HTTPS)
  • AES-256 encryption for sensitive data at rest
  • Bcrypt (or equivalent) password hashing — passwords are never stored in plain text
  • Role-based access controls (RBAC)
  • Multi-factor authentication (MFA) for administrative access
  • Firewalls and intrusion detection systems
  • Regular vulnerability scanning and annual penetration testing
  • Encrypted backups with tested recovery procedures

Organisational Measures

  • Privacy and security training for all staff with data access
  • Data minimisation — we collect only what is necessary
  • Access limited strictly to staff who require it
  • Written security policies and documented incident response plan
  • Vendor due diligence and contractual security requirements for all processors

Despite these measures, no system is completely secure. We cannot guarantee absolute security, but we will act promptly to contain and communicate any incident that affects your data. See Section 17 for breach notification details.

12

International Data Transfers

Our primary servers are located in Australia. Your data may be transferred to, stored in, or processed in countries other than where you reside, including the United States and other jurisdictions where our service providers operate. Data protection laws in those countries may differ from your own.

Where your data is transferred internationally, we ensure appropriate safeguards are in place as required by applicable law. These safeguards may include:

  • (a)Standard Contractual Clauses (SCCs) or equivalent clauses approved by the relevant authority in your jurisdiction.
  • (b)Adequacy decisions or findings made by the relevant supervisory authority.
  • (c)Binding corporate rules or equivalent protections.
  • (d)Your explicit consent where no other mechanism applies.

You may request information about the specific safeguards we have in place for transfers from your jurisdiction by contacting privacy@neonnextgeneration.com.

13

Children's Privacy

Our Services are not directed at children below the minimum age of digital consent in their jurisdiction. Where no specific age is prescribed locally, our Services are not directed to children under 16. We do not knowingly collect personal data from children below the applicable minimum age without verifiable parental or guardian consent.

If you believe we have inadvertently collected data from a minor, contact us immediately at privacy@neonnextgeneration.com. We will delete the data promptly. Parents or guardians may contact us to request access to, correction of, or deletion of a minor's data using the process described in Section 9. See also Terms of Service, Section 3.

14

Marketing Communications

We send marketing communications only where you have explicitly opted in, or where permitted by applicable law on a soft opt-in basis following a purchase and you have not opted out. Every marketing email includes clear identification of Neon Next Generation PTY LTD as the sender, a one-click unsubscribe link, and our ABN.

To Opt Out

  • Click "Unsubscribe" in any marketing email; OR
  • Email info@neonnextgeneration.com with subject "Unsubscribe"; OR
  • Update your account preferences (if available).

Opt-out requests will be honoured within the timeframe required by applicable law in your jurisdiction, and no later than 10 business days. Opting out of marketing does not affect transactional or service-related communications.

15

VPN & Hosting Data Practices

VPN Services: No-Activity-Logging Policy

We operate a strict no-activity-logging policy for our VPN services. We do not log:

  • Browsing activity or visited websites
  • Traffic content or payload data
  • DNS queries or connection destinations
  • Originating IP addresses assigned to VPN sessions
  • Connection timestamps tied to individual users

We may collect minimal operational data (such as aggregate server load and uptime statistics) solely for performance and reliability purposes. This data is never linked to individual users. In the event of a valid legal order requiring disclosure, our no-logging policy means we have no activity data to disclose even if compelled by a court or authority.

Hosting & Network Monitoring

We monitor our hosting infrastructure solely to:

  • Maintain service integrity and uptime
  • Detect fraud, abuse, or security threats
  • Enforce our Terms of Service and Fair Use Policy
  • Comply with lawful obligations

All monitoring is limited, proportionate, and subject to strict internal access controls.

16

Third-Party Data Processors

We work with the following categories of third-party processors who may handle your personal data on our behalf. All processors are bound by written data processing agreements that require them to handle your data securely, use it only for specified purposes, and comply with applicable privacy law.

Payment Processing

Stripe — secure handling of subscription payments and refunds.

Cloud Infrastructure

Server and storage providers used to host our platforms.

Email Delivery

Transactional and notification email services.

Analytics

Aggregated, anonymised usage analytics to improve performance.

Security Monitoring

Infrastructure and threat detection services.

We do not share your data with processors beyond what is necessary. If you have questions about a specific processor, contact privacy@neonnextgeneration.com.

17

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights or interests, we will:

  • Take immediate steps to contain and mitigate the impact.
  • Notify affected users and relevant regulatory authorities within the timeframe required by applicable law in your jurisdiction (generally within 72 hours for EU/UK users).
  • Provide clear information about what happened, what data was affected, what we are doing about it, and what steps you can take to protect yourself.

We maintain an internal incident response plan and conduct regular reviews to ensure our breach response procedures remain effective.

18

Social Login & Third-Party Authentication

We may offer the option to register or log in using third-party authentication providers (such as Google or Discord). If you choose to use social login:

  • We receive a limited set of profile data from the provider (typically your name, email address, and profile picture) based on the permissions you grant at login.
  • We do not receive or store your password for the third-party service.
  • Information received is used solely to create or authenticate your account with us.
  • Your use of the third-party authentication service is governed by that provider's own terms and privacy policy.

You may disconnect a social login at any time via your account settings. Disconnecting does not delete your account, but you will need to set a password to continue accessing it. We are not responsible for the data practices of third-party authentication providers.

19

Do Not Sell or Share My Personal Data

✓ We do not sell your personal data. We do not share your data for cross-context behavioural advertising.

If you are a resident of a jurisdiction with specific opt-out rights (such as California under CCPA/CPRA, or similar laws elsewhere), you have the right to:

  • Opt out of the sale or sharing of your personal data (even though we do not engage in these practices).
  • Request disclosure of the categories of personal data collected, purposes for use, and any third parties it has been shared with.
  • Request deletion of your personal data, subject to legal exceptions.
  • Not be discriminated against for exercising any of these rights.

To exercise any of these rights, contact privacy@neonnextgeneration.com with the subject "Do Not Sell Request" or "Privacy Rights Request." We will respond within 30 days and will not charge a fee for reasonable requests.

20

Data Portability

You have the right to receive a copy of the personal data we hold about you in a structured, commonly used, and machine-readable format, and to transmit that data to another service provider where technically feasible.

What You Can Request

  • Account profile data (name, email, contact details)
  • Billing history and transaction records
  • Support ticket history
  • Any other personal data you have provided to us directly

Operational data such as server logs, anonymised analytics, and system-generated metadata may not be included as this data is not attributable solely to you.

How to Request

Email privacy@neonnextgeneration.com with subject "Data Portability Request." Include your full name and account email. We will provide your data export within 30 days in a standard format (JSON or CSV, depending on the data type). There is no charge for a data portability request unless it is manifestly excessive or repetitive.

21

Profiling & Tracking

What We Do

We may use certain usage data at an aggregate or anonymised level to:

  • Analyse feature usage patterns to prioritise product improvements.
  • Monitor performance and reliability metrics by service tier.
  • Identify and resolve issues affecting groups of users.

What We Do Not Do

  • We do not track your activity across third-party websites or services.
  • We do not build individual profiles for advertising or marketing segmentation.
  • We do not use behavioural data to make automated decisions with legal or significant effects on you without human review.
  • We do not use tracking pixels or third-party advertising tags without your explicit consent.

If you object to any form of usage analytics, contact privacy@neonnextgeneration.com to discuss available opt-out options.

22

Artificial Intelligence & Machine Learning

Current Use

We may use automated tools and ML-based systems to:

  • Detect abuse, spam, fraud, or security threats on our platform.
  • Monitor infrastructure performance and predict capacity needs.
  • Filter or flag content that may violate our Acceptable Use Policy.

These uses are operational in nature and are not used to make decisions about you personally. Any flagged activity is reviewed by a human before any action is taken against an account.

What We Do Not Do

  • We do not use your personal data to train external AI or ML models.
  • We do not sell or license your data to AI companies or data brokers.
  • We do not make fully automated decisions with legal or significant effects on you without human review.

Future Changes

If we introduce new AI-powered features that involve processing your personal data in a materially different way, we will update this Policy and notify you in accordance with Section 25 before those features are deployed.

23

Automated Decision-Making

We do NOT make solely automated decisions that produce legal or similarly significant effects on you, unless:

  • (a)It is necessary for entering into or performing a contract with you.
  • (b)It is authorised by applicable law with appropriate safeguards.
  • (c)You have given explicit consent.

Where automated processing is used (e.g., fraud detection or spam filtering), any flagged outcome is reviewed by a human before action is taken. You have the right to request human review of any automated assessment, contest the outcome, and receive a meaningful explanation of the logic involved. To exercise these rights, contact privacy@neonnextgeneration.com with the subject "Automated Decision Review Request."

24

Glossary

"Anonymised Data" — Data that has been irreversibly processed so that no individual can be identified from it.

"Controller / Business" — The entity that determines the purposes and means of processing personal data — that is Neon Next Generation PTY LTD.

"Data Subject / Consumer / User" — The identified or identifiable natural person whose personal data is processed — that is you.

"Personal Data / Personal Information" — Any information relating to an identified or identifiable natural person.

"Processing" — Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.

"Processor / Service Provider" — A party that processes personal data on behalf of the Controller under a written agreement.

"Pseudonymised Data" — Data that cannot be attributed to a specific individual without additional separately held information.

"Sensitive Personal Information" — Includes: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic or biometric data; health or medical data; sexual orientation or gender identity; precise geolocation; government-issued identifiers; financial account credentials; immigration status.

"Third Party" — Any entity other than you, Neon Next Generation PTY LTD, or our service providers acting on our instructions.

25

Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

  • Minor clarifications will be posted with an updated version number and effective date — no further notice required.
  • Material changes will be communicated via email or prominent in-service notice at least 30 days before taking effect.
  • Where a material change adversely affects your rights and local law requires it, you may request data deletion before the change takes effect without penalty.
  • Continued use after the effective date constitutes acceptance. If you disagree, discontinue use and request data deletion per Section 9.

Version History

  • v2.2April 12, 2026 — Added Who We Are contact card, How We Collect section, International Transfers, Marketing Communications, Automated Decision-Making, Glossary sections. Added legal basis table and data use table. Updated all emails. PHP-driven TOC.
  • v2.1April 12, 2026 — Added social login, do not sell, data portability, profiling, and AI/ML sections. Expanded rights request process, refined cookie withdrawal, updated retention schedule.
  • v2.0April 12, 2026 — Revised to global scope. Added cookie consent detail, expanded rights and VPN logging policy.
  • v1.0January 13, 2026 — Initial Privacy Policy.
26

Contact Us

Neon Next Generation PTY LTD operates as a digital-first organisation. We do not maintain physical walk-in locations or telephone support. For all privacy-related enquiries, requests, or concerns, please use the appropriate contact below.

Privacy & Data Rights

Privacy Requests & Data Rights

privacy@neonnextgeneration.com

DMCA & Copyright

dmca@neonnextgeneration.com

General Inquiries

info@neonnextgeneration.com

Other Contacts

Neon Next Generation PTY LTD  |  ABN: 86 686 080 704

We aim to acknowledge all privacy-related requests within 5 business days and respond in full within 30 days.

27

Complaints

If you believe we have not handled your personal data in accordance with this Policy, we encourage you to contact us first at privacy@neonnextgeneration.com so we can work to resolve the matter directly. We take all privacy complaints seriously and will respond within 30 days.

If you are not satisfied with our response, you have the right to escalate your complaint to the data protection or privacy regulatory authority in your jurisdiction. We will cooperate fully with any such investigation and will not penalise you for making a complaint in good faith.

Examples of Regulatory Authorities

  • AUOffice of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • EUYour national Data Protection Authority — edpb.europa.eu/members
  • UKInformation Commissioner's Office (ICO) — ico.org.uk
  • CAOffice of the Privacy Commissioner of Canada — priv.gc.ca
  • USYour state Attorney General's Office or the FTC — ftc.gov
  • AllContact your local government's official website for jurisdiction-specific authority details.
↑ Back to TOC
Privacy Framework // Global Edition // Vol. 02 // v2.2