Skip to content
Neos Meet is in public beta.3 months of any paid plan free for every beta user — and permanent perks for the first 100.See the beta terms

Data Processing Addendum

Last updated July 18, 2026

Status: these are our standard terms, offered as-is and not yet reviewed by outside counsel. They are published so you can assess them before you sign up. If your legal team needs redlines, a countersigned copy, or wants to work from your own paper, email legal@neos.network.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer identified in the account ("Customer") and RSpond Inc, a Delaware corporation with registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, United States, which operates the Neos Meet service ("Neos Meet", "we"), and applies to the extent Neos Meet processes Personal Data on Customer's behalf in providing the Service.

1. Definitions

"Applicable Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws including the California Consumer Privacy Act as amended, each to the extent it applies. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR. "Sub-processor" means a third party engaged by Neos Meet to process Personal Data in providing the Service.

2. Roles of the parties

Customer is the Controller of the Personal Data it submits to the Service, including the details of the invitees who book time through Customer's booking links. Neos Meet is the Processor of that data and processes it only on Customer's documented instructions. Neos Meet is an independent Controller for a limited set of data it determines the purposes of — account administration, billing, security, and product analytics — which is described in the Privacy Policy rather than in this DPA.

3. Scope of processing

Neos Meet processes Personal Data only (a) as necessary to provide, secure, and support the Service, (b) as further instructed by Customer through the Service's features and settings, and (c) as required by applicable law, in which case Neos Meet will inform Customer of the requirement unless prohibited from doing so. The subject matter, duration, nature, and purpose of the processing, and the categories of Personal Data and Data Subjects, are set out in Annex A. Neos Meet will notify Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

4. Confidentiality

Neos Meet limits access to Personal Data to personnel who need it to provide or support the Service, and requires those personnel to be bound by confidentiality obligations that survive the end of their engagement.

5. Security

Neos Meet implements and maintains the technical and organisational measures set out in Annex C, taking into account the state of the art, the costs of implementation, and the nature and risk of the processing. Neos Meet may update those measures provided the level of security is not materially reduced.

6. Sub-processors

Customer authorises Neos Meet to engage the Sub-processors listed at meet.neos.network/subprocessors (Annex B). Neos Meet imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA and remains liable for their performance. Neos Meet will update that page before a new Sub-processor begins processing Customer Personal Data, and — on request to the address below — will notify Customer by email so that Customer may object on reasonable data protection grounds. If Customer objects and the parties cannot agree on a resolution, Customer may terminate the affected part of the Service.

7. Data subject rights

The Service provides self-serve tools that let Customer access, export, correct, and delete Personal Data directly: a JSON export of booking links, availability, event types, bookings and invitee details (invoices and receipts are not included — download those from the billing portal) and an account deletion that cascades across every record in our production database, subject to the retention exceptions in section 9, are available in account settings, and individual bookings can be cancelled or amended at any time. Where those tools are insufficient, Neos Meet will provide reasonable assistance with a Data Subject request at Customer's cost. If Neos Meet receives a request directly from a Data Subject relating to Customer's Personal Data, it will not respond substantively and will refer the request to Customer, unless legally required to respond.

8. Personal data breach

Neos Meet will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide the information reasonably available to it about the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. Notification is not an acknowledgement of fault.

9. Deletion and return

Customer may delete its account at any time from account settings, which removes booking links, availability, event types, bookings and invitee details from our production database, cancels any upcoming meetings and notifies their invitees, and asks Google to revoke our Calendar access. Google's revocation endpoint is called on a best-effort basis: if it does not confirm, the deletion still completes and the Service tells Customer to remove the grant at myaccount.google.com/permissions. On termination Neos Meet will delete remaining Customer Personal Data within 30 days, except that (a) encrypted backups age out on their normal retention cycle, and (b) invoices, payment records, and other financial records are retained by us and by our payment processor for as long as tax and accounting law requires. We say this plainly rather than promising an erasure we cannot perform.

10. Audits and information

Neos Meet will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to a reasonable security questionnaire no more than once in any twelve-month period. Neos Meet does not currently hold a SOC 2 or ISO 27001 report; where an audit is required by Applicable Data Protection Law, the parties will agree its scope, timing, and cost in advance, and it will be conducted so as not to disrupt the Service or compromise other customers' data.

11. International transfers

The Service is operated from the United States. Where Customer transfers Personal Data subject to the GDPR, UK GDPR, or Swiss FADP to Neos Meet, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two, controller to processor) by reference, with the UK International Data Transfer Addendum where the UK GDPR applies and the equivalent Swiss adaptations where the FADP applies. Annex A serves as the description of processing, Annex B as the list of authorised Sub-processors, and Annex C as the technical and organisational measures required by those Clauses.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. In the event of a conflict, this DPA prevails over the Terms of Service in respect of the processing of Personal Data, and the Standard Contractual Clauses prevail over this DPA in respect of transfers they govern.

13. Term

This DPA takes effect when Customer begins using the Service and continues until Neos Meet has ceased all processing of Customer Personal Data in accordance with section 9.

Annex A — Description of processing

  • Subject matter:provision of a scheduling service that publishes a host's bookable times and records meetings booked against them.
  • Duration:for the term of Customer's account, plus the deletion periods in section 9.
  • Nature and purpose: collection, storage, organisation, retrieval, transmission (calendar events and transactional email), and erasure, for the purpose of scheduling meetings and notifying their participants.
  • Categories of Data Subjects:Customer's hosts and team members, and the invitees who book meetings through Customer's booking links.
  • Categories of Personal Data:name, email address, profile photo, timezone, meeting times and titles, free/busy intervals from the host's connected calendar, notes and answers an invitee chooses to provide when booking, and billing contact details. Note that the calendar grant the Service holds is broader than the data it collects: it permits reading the events a host organises, which the Service does not do. See Annex C, which describes that as an organisational control rather than a technical one.
  • Special category data: none is requested. The Service must not be used to collect special category data through booking questions, and it is not designed for health, financial, or other regulated data. We are not a HIPAA business associate and do not sign BAAs.
  • Frequency: continuous, for the duration of the account.

Annex B — Authorised sub-processors

The current list, with each provider's purpose, the data it receives, and its location, is maintained at meet.neos.network/subprocessors and forms part of this DPA.

Annex C — Technical and organisational measures

  • Least-privilege calendar access (technical).Availability is read through Google's granular free/busy scope, which returns busy intervals only and is incapable of returning event titles, guests, descriptions, locations, or attachments. Writes use the narrowest scope Google publishes for this purpose, which covers events the host organises; it does not extend to calendars merely shared with the host.
  • Calendar data minimisation (organisational).Google offers no Calendar scope restricted to events an application itself created, so the write scope above also technically permits reading the host's other organised events. We do not exercise that: the application only creates, updates, and cancels the events it books, and never lists or reads the titles, guests, or contents of a host's other events. This is a control we operate and can be audited against, not a restriction the Google API enforces.
  • Authentication. Hosts sign in with Google. We never receive, store, or reset a password.
  • Tenant isolation.Every application query is scoped to the authenticated account, so one customer's data cannot be returned to another.
  • Encryption.All traffic to the Service uses TLS. Data at rest is encrypted by our database and hosting providers. Calendar credentials are held server-side only — never sent to the browser, never included in a data export, and deleted from our store when a calendar is disconnected or an account deleted, at which point we also call Google's revocation endpoint. That call is best-effort: where Google does not confirm it, the Service says so and directs the user to revoke the grant themselves.
  • Access control. Administrative access to production systems is limited to personnel who require it.
  • Resilience. Managed database backups with point-in-time recovery, plus a documented restore procedure.
  • Abuse protection. Rate limiting on public endpoints and database-level constraints that make double-booking impossible.
  • Monitoring. Application error and availability monitoring with alerting, and structured logs that exclude request bodies, cookies, and credentials.
  • Deletion. Self-serve account deletion that cascades across every record in our production database in a single transaction, attempts revocation of third-party grants, and removes the billing profile from our payment processor. Backups and financial records are out of its reach — see section 9.

Executing this DPA

By using the Service, Customer accepts these terms. If your organisation requires a signed copy naming your legal entity, email legal@neos.network with the entity name and address and we will return a countersigned version.