Privacy Policy

Last updated: March 25, 2026

1. Who is responsible for processing?

The data controller is:

Lixsir EURL
2 rue Boyer-Barret, 75014 Paris, France
SIREN : 893 958 686
Contact email: [email protected]
Support email: [email protected]

2. Scope

The purpose of this policy is to inform users of the NeuroMap website about the conditions under which their personal data may be collected and processed.

3. Data processed

Depending on the user journey followed, NeuroMap may process the following categories of data:

  • the email address of the customer or prospect;
  • the age range of the person concerned by the questionnaire;
  • first name, if provided on an optional basis;
  • responses given to the questionnaire;
  • technical and browsing data necessary for the operation of the website;
  • payment- and transaction-related data, via the Stripe service provider;
  • data related to audience measurement, advertising, and marketing, depending on the consents given.

NeuroMap is not intended to collect health data in the sense that such data would be explicitly requested as such in its forms.

The user agrees not to enter excessive or unnecessary information in any free-text fields, if such fields exist.

4. Purposes and legal bases

4.1 Provision of the service

Purposes:

  • to operate the questionnaire;
  • to generate a teaser result;
  • to send the report after payment;
  • to ensure the technical management of the service.

Legal basis: performance of pre-contractual measures and of the contract.

4.2 Payment management and administrative obligations

Purposes:

  • to collect payment;
  • to manage proof of the transaction;
  • to comply with accounting, tax, and legal obligations.

Legal basis: performance of the contract and compliance with legal obligations.

4.3 Support and security

Purposes:

  • to respond to requests sent to support;
  • to prevent, detect, and handle technical or security incidents;
  • to protect the website, its systems, and its users.

Legal basis: Lixsir EURL’s legitimate interest and, where applicable, performance of the contract.

4.4 Commercial prospecting by email

Purposes:

  • to send marketing, promotional, or follow-up emails to persons who have consented to them or where permitted by applicable regulations;
  • to measure the performance of marketing campaigns.

Legal basis: consent, or where applicable, legitimate interest where permitted by law.

4.5 Audience measurement and advertising

Purposes:

  • to measure the website audience;
  • to analyse browsing activity;
  • to improve website performance;
  • to measure the effectiveness of advertising campaigns.

Legal basis: consent where required for the relevant trackers.

5. Distinction between service, marketing, and cookies

Processing related to the provision of the service, payment management, security, or the sending of emails strictly necessary for the performance of the service is separate from:

  • marketing processing;
  • audience measurement trackers;
  • advertising trackers.

Service communications, such as sending the report, technical information, or order-related confirmations, do not constitute marketing communications.

6. Data recipients

Personal data is accessible, within the limits of their respective needs, to authorised persons within Lixsir EURL and to its service providers and processors acting on its behalf.

Depending on the circumstances, these recipients may in particular fall within the following categories:

  • payment service provider;
  • hosting provider;
  • emailing and CRM provider;
  • audience measurement providers;
  • advertising providers;
  • technical or maintenance providers.

As of the latest update of this policy, NeuroMap uses services provided in particular by Stripe, Brevo, Google Analytics, Meta, and IONOS.

7. Transfers outside the European Union

Some service providers, or their onward subprocessors, may be located outside the European Union or may transfer certain data outside the European Union.

Where such transfers exist, Lixsir EURL ensures that they are governed in accordance with applicable regulations, in particular through adequacy decisions, standard contractual clauses, or any other recognised mechanism.

8. Retention periods

Data is kept for limited periods appropriate to its purpose.

8.1 Questionnaire, teaser, and report

  • Questionnaire responses: up to a maximum of 2 hours from the end of the user journey, unless temporarily required for technical reasons or unless a legal obligation requires otherwise.
  • Optional first name: up to a maximum of 2 hours as part of the relevant user journey.
  • Age range: up to a maximum of 2 hours as part of the relevant user journey.
  • Report or intermediate elements: up to a maximum of 2 hours as part of the technical provision of the result.

8.2 Prospects and follow-ups

  • Prospect data in Brevo: up to 2 months from collection or from the last contact initiated by the data subject.
  • Follow-up emails in the event of an incomplete payment: up to a maximum of 1 hour depending on the relevant scenario.

8.3 Data related to purchase, invoicing, and proof

  • Data necessary for transaction management, accounting, invoicing, and proof: for the period required by applicable law, in particular where a longer retention period is imposed on Lixsir EURL.

Certain data may therefore not be deleted immediately where a legal retention obligation applies.

9. Cookies and other trackers

The website may use:

  • trackers strictly necessary for the operation of the website or the requested service;
  • audience measurement trackers;
  • advertising or marketing trackers;
  • trackers related to third-party services integrated into the website.

Where required by law, non-essential trackers are only placed after consent has been obtained.

Users may manage their preferences via the cookie management tool made available on the website.

10. Minors or third parties concerned

NeuroMap is not intended for independent use by a minor.

Where a user completes a questionnaire on behalf of another person or a minor, they declare that they are authorised to do so and to provide the information necessary in that context.

Lixsir EURL limits collection to the data strictly necessary for the operation of the service.

11. Security

Lixsir EURL implements appropriate technical and organisational measures to protect personal data against destruction, loss, alteration, unauthorised disclosure, or unauthorised access.

Despite these precautions, no system offers absolute security.

12. Your rights

Depending on the applicable regulations and subject to the conditions they provide, you may have the following rights:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to object;
  • right to data portability where this right applies;
  • right to withdraw your consent at any time for processing based on that consent.

You may exercise your rights by writing to: [email protected].

Where there is reasonable doubt as to your identity, proof of identity may be requested where necessary.

You also have the right to lodge a complaint with the competent supervisory authority, in particular in France with the CNIL.

13. Changes to the policy

Lixsir EURL may amend this privacy policy at any time in order to reflect legal, regulatory, technical, or operational developments.

The applicable version is the one published on the website on the date of consultation.

14. Contact

For any question relating to this privacy policy, you may write to: [email protected].