NeoBox Privacy Policy

Released on August05, 2025

Effective from August 05, 2025

Thank you for using NeoBox.

NeoBox is provided to you by SITAYAM MINDTECH PRIVATE LIMITED (here in after referred to as "SITAYAM MINDTECH PRIVATE LIMITED", "we", or "us"). We are dedicated to protecting your privacy.

This Privacy Policy outlines how we collect, store, process, share, and use your information when you access our website, software, and services (the "Services").

We collect and use your personal information solely for lawful, legitimate, and essential purposes. Specifically, we process your personal data to deliver our services and features effectively. If you use another person's personal information to access our services, you must ensure you have proper authorization. We also reserve the right to verify the legality of such usage at any time.

In certain situations, we will seek your explicit consent in compliance with applicable laws and regulations. Beyond this Privacy Policy, we may provide additional explanations about how we handle your personal information through product page notifications, pop-up messages, push alerts, and similar methods. The processing of personal information for each specific service or feature will follow detailed rules, which hold the same validity as this Privacy Policy.

Please note: Your prior authorization or consent is not required for the collection, use, sharing, transfer, or disclosure of your personal information in the following circumstances:

What Information Is Collected and Why We Collect It

The below outlines the types of information you provide when using our Services and the purposes for which we utilize it. We collect and process this information to deliver, enhance, secure, and promote the Services effectively.

Type of Information and Purpose of Collection

Account Information:

We collect details such as your email address and phone number when you register for an account. If you log in using a social networking service (SNS) account, we will also receive your nickname and SNS profile image, which will be linked to your account.

Account Purpose of Collection

We may use this information to verify your identity as the account owner and ensure the security of your account. This information may be collected each time you log in to your account.

User Data:

This refers to the data you store on NeoBox, including files, documents, photos, videos, audio, and other content ("user data").

We may store, process, and transfer user data and related information to ensure the proper functioning of the Services. This allows you to collaborate with others and access your data across devices and Services. User data includes information such as file details, size, upload date and time, and usage of your configuration files.

Usage Information:

This refers to data about how you interact with the Services, including actions performed in your account such as editing, viewing, creating, and moving files or folders.

Usage Purpose of Collection:

We use this information to deliver, enhance, and promote the Services, as well as to protect NeoBox users.

Device Information:

This refers to details about the device you use to access the Services, which may include your IP address, browser type, device specifications, web pages visited before accessing NeoBox, device identifiers, and location information, depending on your device settings.

Device Purpose:

We may use this information to optimize the Services and ensure their security.

Cookies:

Cookies are small text files sent to your browser by the website when you visit NeoBox. You can configure your browser to reject cookies, but please note that doing so may impact the functionality of the Services.

Cookies Purpose:

We may use cookies and similar technologies to deliver, optimize, protect, and promote the Services. Cookies help us remember your username between logins, understand how you use the Services, and improve the Services based on this data. Our third-party service providers may also use cookies and similar technologies for similar purposes.

Contact Information:

You may share data and information through the Share function of NeoBox, or by using the contacts, mobile phone numbers, and email addresses (including those from Facebook and Twitter) stored on your phone. This information is considered sensitive personal data. If you choose not to provide it, you will not be able to use the aforementioned functions, but you can still access and use other NeoBox features and related services normally.

Contact Purpose:

You can choose to allow NeoBox to access your contact information to facilitate certain operations, such as sharing data, collaborating with others to process data, sending messages, and inviting others to use NeoBox via email. These functions are available once you grant us permission to access your contacts. We store this information on our server for your convenience. Before sharing any data, please ensure the recipient is trustworthy. Additionally, we recommend reviewing the privacy statements of SNS or third-party service providers to understand how they handle your information.

Clipboard:

When you register a NeoBox account using someone's invitation code, access file links shared by other users, add friends via passwords, or redeem membership services using redemption codes, we may read the information stored in your clipboard.

Clipboard Purpose:

We will access your clipboard information solely to assist you in opening files corresponding to shared links, verifying the user linked to the password or invitation code, or redeeming membership services on your behalf. We will never access your clipboard for any other purpose.

Provision of Personal Information to Third Parties

We will not disclose your personal information to any third party without your prior consent, except in the following circumstances:

In these exceptional cases, we will log the basis for processing your information, the scope of the information processed, and details of the recipient, in accordance with the principles of minimization and necessity to protect your legitimate rights and interests. This will include:

Sharing data with other users

When you use the Teamwork or Share functions of NeoBox, the Services display your nickname, device information, email address, and usage information to the users you collaborate with, or any information you permit to be shared. This enables you to stay updated on information about the team you join and allows other users to share files and folders with you.

We may share your information with third parties

We may collaborate with trusted third parties (such as customer support or IT service providers) to help us deliver, optimize, protect, and promote the Services. These third parties may have access to your information to perform tasks on our behalf. However, we remain responsible for ensuring that these third parties handle your information in accordance with our requirements and privacy standards.

We may share infrastructure, systems, and technology with NeoBox affiliates to deliver, optimize, protect, and promote the Services. These affiliates will use your information, alongside the data listed in the "What information is collected and for what purpose" section, for the purposes described therein. We will be responsible for granting these affiliates access to your information.

You may choose to connect your NeoBox account through a third-party service. By doing so, you allow both the third parties and us to exchange the information listed in the "What information is collected and for what purpose" section of this Privacy Policy. This enables both parties to deliver, optimize, protect, and promote their services. In such cases, the use of your information will be governed by the privacy policies and terms of service of the third parties whose services you connect through.

We will establish an output mechanism for cross-border data transfers in accordance with the requirements of the GDPR and update it as necessary. Our processing of personal data will be based on the fundamental principles of the GDPR, the valid consent of data subjects, or other legitimate reasons. Additionally, we will implement further mechanisms to protect data and comply with the substantive requirements of the GDPR for data processing.

How we protect and store your information

We have a dedicated team focused on securing your information and identifying vulnerabilities. In addition to two-factor authentication, encryption of files at rest, and alerts when new devices and apps are linked to your account, we continually strive to ensure the security of your data. We also use automated technology to detect abusive behaviour and harmful content that could impact you, other users, or the Services.

After you sign up for a NeoBox account, we will retain the information you store in the Services for as long as your account remains active or as long as necessary to provide you with the Services. If you wish to delete your account, please send an email to [email protected] with your request, and we will delete your account within 30 days of receiving it. However, please note:

We will store your personal information for the duration necessary to provide the Services. However, if required by laws and regulations, or if you agree to retain the information for a longer period, we may do so. Additionally, if it is necessary to ensure the security and quality of the Services, resolve disputes, or if it is technically impractical to process the information as required, we will extend the retention period in accordance with the law, the agreement, or to a reasonable extent after the expiration of the original retention period.

Once the retention period expires, we will delete your personal information or de-identify it in accordance with applicable laws and regulations.

We will collect, use, store, and transfer your information based on the principle of "minimization," ensuring that only the necessary information is collected. We will inform you of the purpose and scope of use of your information through user agreements, privacy policies, rules, pop-up notifications, notices, and other means.

We place a high priority on information security. We have a dedicated team responsible for developing and implementing various security technologies and programs. Security background checks are conducted for personnel involved in security management and other critical security roles. We have established a comprehensive information security management system and internal procedures for handling security incidents. We implement appropriate security measures and technical safeguards in line with industry standards to protect your personal information from loss, unauthorized access, disclosure, use, alteration, or destruction. Additionally, we use encryption technology to ensure data confidentiality and apply trusted protection mechanisms to prevent malicious attacks on your data. We are committed to taking all reasonable and feasible measures to safeguard your personal information.

We invest in training and evaluating our employees to enhance their awareness of data security and their ability to protect personal information. We authenticate the identity of employees who handle personal data and strictly control their access to it. Employees and partners with access to your personal information are required to sign nondisclosure agreements, and we clearly define their job responsibilities and code of conduct to ensure that only authorized individuals can access your information. In the event of a violation of these nondisclosure agreements, the employment of the violator will be terminated immediately, and they will be held accountable under the law. Additionally, confidentiality requirements are enforced for relevant personnel even after they leave their positions.

We kindly remind you that the Internet is not entirely secure. Therefore, we advise you to exercise caution and protect your personal information when interacting with other users through third-party social software, emails, SMS, or other services integrated into NeoBox, especially if you are unsure whether your information is fully encrypted during transmission.

We also appreciate your understanding that, due to technical limitations, rapid advancements, and the potential for latent or malicious attacks in the Internet industry, we may not be able to guarantee 100% security for your information, despite our continuous efforts to enhance security measures. As a result, the systems and communication networks through which you access our product and/or Services may encounter security issues in other processes that are beyond our control.

Our security management system treats the disclosure, damage, or loss of personal information as the most severe security event. In the event such an incident occurs, we will activate our highest-level emergency plan, with multiple departments working together as a unified emergency response team to address and resolve the issue.

We have developed an emergency plan for network security events to quickly respond to system vulnerabilities, computer viruses, cyber-attacks, network intrusions, and other security risks. In the event of a network security breach, we will immediately implement the plan, take corrective actions, and report the incident to the relevant authorities as required.

The disclosure, damage, and loss of personal information are considered the most severe security events. To prevent such occurrences, we regularly organize drills with our working groups to practice security plans. In the event that these incidents do occur, we will prioritize the implementation of our emergency plan, forming an emergency response team to quickly identify the cause and mitigate losses as efficiently as possible.

In the event of a personal information security breach, we will notify you promptly, as required by applicable laws and regulations, with essential details about the incident and its potential impact. We will also inform you of the measures we have already implemented or will take, as well as provide recommendations for actively mitigating and preventing risks. Additionally, we will outline any remedial actions available to you. Communication will be made through our notifications or the contact information you have provided, including SMS, phone number, or email. If individual notifications are not feasible, we will issue a public announcement through an appropriate and effective method. Furthermore, we will report the resolution of the security incident to the relevant regulatory authorities. Please note that in accordance with laws and regulations, if the actions we have taken effectively prevent harm from the disclosure, alteration, or loss of your information, we may choose not to notify you of the event, unless required by a regulatory authority.

We appreciate your understanding.

In compliance with the GDPR, we implement appropriate technical security measures tailored to the nature, scope, context, and purpose of data processing, as well as the risks posed to individuals. These measures are designed to ensure the confidentiality, integrity, and availability of personal data. We regularly test and evaluate the effectiveness of these security measures to ensure they remain robust and suitable in addressing potential risks.

In the event of accidental data disclosure, we will notify the affected individuals as promptly as possible and report the incident to the relevant authorities within 72 hours. If, for any reason, it is not possible to make the report within the 72-hour window, we will provide a clear explanation for the delay.

We implement appropriate technical and organizational measures to uphold our data protection objectives, including the principle of data minimization. This involves ensuring that only the necessary data is collected and processed for a specific purpose. We also integrate necessary safeguards into our data processing practices to protect the rights of data subjects and ensure that any data processed is essential for the defined purpose by default.

Where we store and process your information

While providing the Services, we may store, process, and transfer your information in Japan, and by using the Services, you consent to the storage, processing, and transfer of your information to India. Additionally, your information may be stored locally on the device you use to access the Services. We ensure that appropriate security measures are in place to protect your information throughout this process.

How you control and access your information

In accordance with the applicable laws, regulations, standards, and established practices of the relevant country and region, we guarantee that you can exercise the following rights with respect to your personal information. If you have any questions or concerns regarding the exercise of these rights, you may contact us at [email protected].

You have the right to view, modify, download, delete, or share your personal information from your NeoBox account at any time. We are committed to ensuring your rights are upheld and will assist you with any requests related to your personal information.

1. The right of access

If you would like to know the extent to which your personal information is collected, stored, and shared by NeoBox, as well as the purposes for which it is processed, please feel free to contact us for further details. We are happy to provide you with the information you need regarding the processing of your personal data.

2. The right of rectification and supplementation

If you identify any inaccuracies or omissions in your personal information processed by us, you have the right to request rectification or supplementation of the data. After we verify your identity, you can submit your request for correction or addition through feedback, error reporting, or by contacting us using the provided contact information. We will respond to your request as soon as possible after receiving it and ensure the necessary updates are made.

3. The right of erasure

You may request the deletion of your personal information under the following circumstances:

If any of these conditions apply, you can contact us to request the deletion of your personal information, and we will handle your request in accordance with applicable laws and regulations.

Other circumstances required by laws and administrative regulations.

When you delete information from the Services, please note that it may not be immediately removed from our backup systems. We will delete the information from the backup once it has been updated. We appreciate your understanding that if the retention period for your personal information has not yet expired as required by applicable laws and regulations or as specified in this Privacy Policy, or if it is technically challenging to delete your personal information, we will cease processing it, except for storage and necessary security protection measures.

The right of withdrawal of consent

The implementation of each service or function requires certain basic personal information. For any additional collection or use of your personal information, you have the right to provide or withdraw your consent at any time. We will respect your choices and ensure that your personal information is handled in accordance with your preferences.

You can directly disable access to your contacts, photos, camera, and other system features on your device. Additionally, you can modify the scope of your consent or withdraw your authorization at any time through your device's settings. We respect your decisions and will adjust our services accordingly based on the permissions you grant.

Following your withdrawal of consent, we will no longer be able to provide you with the service related to the withdrawn consent, and we will cease using the relevant personal information. However, please note that your decision to withdraw consent will not affect the processing of your personal information that was carried out prior to the withdrawal, which was based on your previous consent.

The right of account deletion

You may delete the account you have created. To delete your account in NeoBox, you can follow the instructions provided within the platform or contact us for assistance. Please ensure that you back up any data you wish to retain before deleting your account, as this action may be irreversible.

Once you have deleted your account, you will no longer be able to use the Services of NeoBox, so we encourage you to carefully consider this decision before proceeding. To protect the legitimate rights and interests of you and other users, we may evaluate your account usage before accepting your deletion request. For instance, if you have unused Premium benefits or any remaining data in your account, we may not process your request immediately. Unless otherwise required by laws and regulations, we will cease providing you with the product and services and will delete your personal information in accordance with your request after your account has been deleted.

The right of copy and data portability

You have the right to obtain a copy of your personal information collected by us. In accordance with applicable laws and regulations, and subject to the instructions and conditions set by competent authorities, as well as technical feasibility, you may request us to transfer your personal information to another designated entity. We will assist you in transferring your data as required, within the scope of legal and technical limitations.

When you exercise your rights as a personal information subject, we will promptly update any relevant third parties with the necessary information to ensure that these rights are respected and exercised in accordance with applicable laws, regulations, and technical feasibility. This will help ensure that your rights are upheld across all systems and processes involved in handling your personal information.

If your request is manifestly unjustified or excessive, particularly if it is repetitive, we may:

Change

In the event of a reorganization, merger, or acquisition of NeoBox, or the sale of our assets, your information may be transferred to the surviving entity, acquirer, or successor of the transaction. We will notify you of such a transaction, for example, by sending a message to the email address associated with your account, and provide details of your options in such cases. This ensures that you are aware of how your information may be handled and your rights regarding the transfer.

This Privacy Policy may be updated periodically. In the event of any revisions, we will publish the latest version on NeoBox's website. If any revision materially affects your rights, we will notify you directly, ensuring you are aware of any significant changes and how they may impact your personal information.

Contact Us

If you have any questions or concerns about NeoBox, the Services, or your privacy, please feel free to contact us at : [email protected].