GDPR — Your Rights
Last updated: June 27, 2026
Regulation (EU) 2016/679 (the GDPR) grants you specific rights over your personal data. This page explains, in plain terms, what those rights are, how to exercise them with NeuralEdge by writing to [email protected], our response times, and how to lodge a complaint with the competent supervisory authority.
1. Data controller
NeuralEdge is a macro-financial intelligence and trading-analytics SaaS platform (web app and iOS app) aimed at retail traders and independent analysts. NeuralEdge is an information and analytics tool: it does not provide investment advice and does not act as a broker or financial intermediary.
The data controller is NexNow LTD, a company incorporated under Bulgarian (EU) law, with registered office at 3 Prof. Milko Bichev Str., 1527 Sofia, Bulgaria, company number (EIK) 208287942, VAT number BG208287942, website nexnow.eu. NexNow LTD operates NeuralEdge and is the data controller. For any data protection matter and to exercise your rights, you can write to [email protected].
The rights described on this page apply to the data we process to deliver the service: account data (email, name, hashed password, optional sign-in via Google OAuth — Google LLC, billing address), payment data handled by our processors (Stripe and Revolut Business), transactional emails sent via SMTP, and basic marketing and analytics data (Google Ads and Meta/Facebook Pixel and CAPI).
2. Right of access (Art. 15)
You have the right to obtain confirmation as to whether or not your personal data is being processed and, where it is, to access that data and the key information about it: the purposes of the processing, the categories of data, the recipients (for example our processors such as Stripe, Revolut, Google and Meta), the retention period, and the source of the data.
You may also request a copy of the personal data undergoing processing. The first copy is free of charge; for any further copies we may charge a reasonable fee based on administrative costs.
3. Right to rectification (Art. 16)
You have the right to have inaccurate personal data corrected and incomplete data completed. Much of this information — such as your name, email and billing address — can be updated directly from your account settings.
For information you cannot change yourself, write to us at [email protected] and we will update it, where possible notifying the recipients to whom the data has been disclosed.
4. Right to erasure (Art. 17)
You have the right to have your personal data erased (the «right to be forgotten»), for example where it is no longer necessary for the purposes for which it was collected, where you withdraw the consent on which processing was based, or where you object to the processing and there is no overriding legitimate ground for it.
Erasure is not an absolute right: we may retain certain data for as long as necessary to comply with legal obligations — in particular tax and accounting obligations relating to payments and invoicing — or to establish, exercise or defend a legal claim. In such cases we will explain which data we keep and for how long.
5. Right to restriction (Art. 18)
You have the right to obtain restriction of processing, i.e. to «freeze» the use of your data without deleting it. You may exercise this, for example, when you contest the accuracy of the data (for the time needed to verify it), when processing is unlawful but you prefer restriction to erasure, or when you need the data for a legal claim even though we no longer require it.
While processing is restricted, your data will be stored but not otherwise processed, except with your consent or to protect a legal claim. We will inform you before any restriction is lifted.
6. Right to data portability (Art. 20)
For data you have provided to us that we process on the basis of consent or for the performance of the contract, and by automated means, you have the right to receive it in a structured, commonly used and machine-readable format (for example JSON or CSV).
Where technically feasible, you also have the right to ask that this data be transmitted directly to another controller.
7. Right to object and withdrawal of consent (Arts. 21 and 7)
You have the right to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest. You also have the right to object at any time, and without giving any reason, to the processing of your data for direct-marketing purposes, including related profiling: in that case we will stop processing your data for those purposes.
Where processing is based on consent — as with cookies and analytics and marketing tools (Meta Pixel/CAPI, Google Ads) — you can withdraw it at any time, as easily as you gave it, through the cookie banner and preferences. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Strictly necessary cookies and tools (session and authentication, storage of your consent preferences) do not require your consent and cannot be disabled, as they are essential to the operation of the service.
8. How to exercise your rights and response times
You can exercise all of the rights above by writing to [email protected], stating which right you wish to invoke. To protect your security, we may ask for information that helps us confirm your identity before acting on the request.
We will respond without undue delay and in any case within one month of receiving the request. This period may be extended by a further two months for particularly complex or numerous requests: if so, we will inform you, together with the reasons, within the first month.
Exercising your rights is normally free of charge. Only where requests are manifestly unfounded or excessive, in particular because of their repetitive character, may we charge a reasonable fee or refuse to act on the request, giving reasons for our decision.
9. Lodging a complaint with a supervisory authority
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority. Because NexNow LTD is established in Bulgaria, the lead supervisory authority is the Bulgarian Commission for Personal Data Protection (CPDP/KZLD), based in Sofia (website www.cpdp.bg).
Without prejudice to any other administrative or judicial remedy, you may instead turn to the supervisory authority of the Member State of your habitual residence, place of work, or place of the alleged infringement. For Italy, the local authority is the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome; website www.garanteprivacy.it). You may therefore lodge a complaint with the Bulgarian CPDP and/or your local authority.
That said, we would welcome the chance to address any concern with you first, and we encourage you to contact us at [email protected].
10. Updates to this page
We may update this page to reflect changes in the law, our organisation or the service. The date of the last update is shown at the top of the document. We encourage you to review it from time to time; in the event of material changes, we may notify you through the contact channels associated with your account.