Update — September 2026: GraphAware is now part of Neo4j.
On 5 August 2026, Graph Aware Limited became a wholly-owned subsidiary of Neo4j, Inc. We have updated this notice to explain how personal data is shared within the Neo4j group, including with Neo4j, Inc. in the United States, and the safeguards that protect it.
Your rights, your existing marketing preferences, and our contact address (gdpr@graphaware.com) are unchanged. See “Sharing Your Data” and “International Transfers” below.
Graph Aware Limited, a UK-based international software company with entities in the EU (Italy and the Czech Republic) and Australia, acts as the controller for personal data processed through our website, client services, recruitment activities, events, and related operations.
Since 5 August 2026, Graph Aware Limited has been a wholly-owned subsidiary of Neo4j, Inc. (400 Concar Drive, San Mateo, CA 94402, USA) and, together with its affiliates, is part of the Neo4j group of companies, which also includes Neo4j UK Limited, Neo4j Sweden AB and Neo4j Germany GmbH. Where this notice refers to the “Neo4j group”, it means Neo4j, Inc. and its subsidiaries. Neo4j’s own privacy notice, which applies where a Neo4j group company processes your personal data for its own purposes, is available at neo4j.com/privacy-policy
This policy complies with UK GDPR and EU GDPR, covers customers, prospects, website users, job applicants, and candidates and — in relation to intra-group data sharing — employees and contractors (not intended for children), and explains how personal data is collected, used, shared, protected, transferred, and what rights individuals have under applicable data protection laws; where relevant, specific controllers are identified at the point of collection.
Our compliance team oversees data protection matters and can be contacted at gdpr@graphaware.com for all privacy-related queries, including requests to exercise data subject rights or obtain further information about this notice.
We may collect the following categories of personal data, depending on how you interact with us:
We also generate aggregated or anonymised statistics for analytics and reporting, which do not identify individuals; such data is not treated as personal data where irreversibly anonymised. No special category data is intentionally collected for general marketing purposes.
We collect personal data from a range of sources:
Directly from you:
Forms on our website or landing pages (including mandatory marketing consent checkboxes where required), emails and correspondence, business cards, event badge scans or attendee lists when you register for or attend our events, job applications (including CVs, cover letters, references), account registrations, support tickets, meetings, interviews, and calls (which may be recorded for training, quality, or evidential purposes).
Automatically:
Cookies and similar technologies (see Cookies below), server and application logs, usage data from our website and online services, and information about how you interact with our emails, such as the links you click.
Third parties:
Advertising and analytics providers (such as Google, LinkedIn, Microsoft Advertising and Reddit Advertising) for clicks, conversions, and campaign performance; partners; event badge scans or attendee lists when you register for or attend an event we have organised or participated in, public and professional sources (including prior employers and online professional profiles); regulators and public authorities where legally permitted or required; recruitment vendors and background-check providers (such as DBS and Access NI checks); processors used for HR, timesheets, CRM and marketing (including BambooHR, Harvest, HubSpot); and reputable marketing lists or data aggregators, always in line with applicable law and contractual assurances. In many cases, data from these sources is synchronised into HubSpot or other systems we use for centralised management and analysis.
Cookies and similar technologies are used to support site functionality, analytics, marketing (including Microsoft Ads and Reddit Ads), and security.
These technologies allow us to recognise your browser or device, understand how our services are used, improve the user experience, and measure the effectiveness of our communications. Cookie use is managed via a Cookiebot banner that enables granular consent by category (strictly necessary cookies are non-optional because they are required for core functionality).
Cookie details are reviewed and updated periodically, and you can request further information by contacting gdpr@graphaware.com.
Cookie categories
| Category | Purpose | Examples/vendors | Typical duration |
| Strictly necessary | Security, load balancing, login, form submissions, captcha validation, and core performance | Cloudflare, Google reCAPTCHA, HubSpot (bot detection and forms), essential session cookies | Session to 1 year |
| Statistics/performance | Usage analytics, service improvement, performance measurement, and video support | HubSpot tracking cookies, Google Analytics (aggregated reporting), Vimeo, Spotify (podcast embeds), YouTube | Up to 14 months (reset on visit) |
| Marketing | Measuring advertising effectiveness, lead scoring and profiling (e.g., job title, email domain, country, engagement), campaign tracking, and personalisation | HubSpot (user tracking), YouTube, Google Analytics, Google Ads, Microsoft Ads, Reddit Ads. | Until opt-out plus 30 days |
| Functional/preferences | Remembering consent settings, preferences, and supporting embeds or widgets | Cookiebot, Breezy (job adverts), Microsoft Teams (webinar data) | Up to 12 months |
Alongside Cookies, similar technologies can be used to understand how readers interact with marketing emails. This is what we do:
We do not use your clicks to score or profile you. You can update your email preferences at any time using the ‘Manage preferences’ link in any marketing email you receive from us, or by contacting gdpr@graphaware.com. Cookie choices can be changed at any time through Cookiebot.
The table below summarises the main purposes for which we process personal data, the categories of data involved, the corresponding legal bases under UK/EU GDPR, legitimate interests where applicable, and typical retention periods.
| Purpose | Data types | Legal basis (UK/EU GDPR) | Legitimate interests (where applicable) | Retention period |
| Provide and improve products and services; | Identity, contact, financial/transaction, customer representative employment details where relevant, video call recordings, account data, product usage | Contract; Consent; Legal obligation (e.g., tax) | Ensuring service quality, understanding usage, and responding to enquiries | Contractual relationship plus 6 years (tax/legal) |
| Recruitment (applications, vetting, onboarding) | Identity, contact, CV and employment history, education, references, right-to-work documentation, criminal convictions and background-check data, National Insurance number, copies of ID | Contract; Legal obligation (employment, right-to-work); Consent where required for specific checks | Conducting fair and effective recruitment, ensuring suitability/trustworthiness for high-risk roles, protecting IP and preventing fraud | Up to 6 months after recruitment process closure for unsuccessful candidates (unspent criminal data only), or up to 6 years where needed for legal claims or record-keeping |
| Operate accounts; handle queries, complaints, and claims | Identity, contact, financial, purchase history, support and call data, location, communications | Contract; Legal obligation; Legitimate interests | Maintaining accurate records, customer service operations, and resolving disputes | As needed during relationship plus up to 6 years |
| Marketing, newsletters, and updates (including HubSpot sequences); process forms (demos, webinars, e-books, trials); analytics and lead scoring / profiling | Identity, contact, usage, marketing and preference data | Consent; Legitimate interests | Business growth, informing customers about relevant products/services, and tailoring communications | Until opt-out plus 30 days; disengaged/hard-bounce contacts are suppressed earlier where appropriate |
| Crime prevention, security, fraud/abuse detection | Identity, technical, location, profile and engagement data | Legitimate interests; Legal obligation | Ensuring network and information security, protecting IP and confidential information, improving site performance, and assessing lead quality | Analytics data (e.g., cookies) generally up to 14 months; profile and suppression lists retained as long as necessary for security and suppression purposes |
| Research, product development, surveys, and events follow-up | Identity, contact, usage, profile information, feedback, survey responses | Consent; Legitimate interests | Developing and improving products and services, understanding customer needs, and evaluating events | Typically up to 12 months after the relevant event or project, unless longer retention is legally required |
Retention periods may be extended where required by law (e.g., tax or accounting rules) or where necessary to establish, exercise, or defend legal claims. After the applicable period, data is securely deleted, anonymised, or archived in accordance with our retention schedule.
You can opt out of marketing at any time using unsubscribe links in our communications, updating your preferences, or contacting us directly. Sales emails are normally addressed to specific business contacts and respect applicable soft opt-in and objection rules.
We share personal data only as necessary and proportionate for the purposes described above, subject to appropriate contractual and security safeguards.
Sharing within the Neo4j group: following the acquisition of GraphAware by Neo4j, Inc. on 5 August 2026, we share personal data within the Neo4j group where necessary for the purposes below. Where a Neo4j group company processes your personal data for its own purposes, it does so as a separate controller under Neo4j’s privacy notice; where it processes data on our behalf, it acts as our processor under a written agreement. We only share what is necessary for these purposes, the retention periods in this notice continue to apply, and your existing marketing opt-outs are preserved.
Marketing and sales contacts (including our CRM records): identity and contact details, company information, marketing preferences and consent records, and engagement history are shared for continuity of sales and marketing relationships, a consolidated CRM, and joint go-to-market activity, on the basis of our legitimate interests and, where the communications themselves require it, consent. In countries where marketing requires a prior opt-in, Neo4j will only send you marketing once you have confirmed your opt-in; you can object or unsubscribe at any time.
Job candidates: your application data (CV, contact details, interview notes, references and assessment outcomes) is processed in the Neo4j group’s recruitment systems, and recruitment is administered on a group basis. Neo4j group companies may therefore access your application to run the recruitment process, and we may consider you for other suitable roles within the Neo4j group. We rely on the steps taken at your request before entering a contract and on our legitimate interests in running an efficient group-wide recruitment process; you can object at any time by contacting gdpr@graphaware.com. Where a role requires it, right-to-work documentation, security-clearance and criminal-records information relating to candidates and employees is also processed in the group’s recruitment and HR systems and may be accessed by Neo4j group companies performing those checks or administering employment — strictly on a need-to-know basis, only under the conditions that permit employment-related processing of such data (including UK GDPR Articles 9 and 10 and Schedule 1 to the Data Protection Act 2018), and never for any other purpose.
Employees and contractors: HR records (contract and payroll data, benefits, performance, absence, and IT account and directory data) are shared for group HR and payroll administration, benefits, IT systems and security, management reporting, and legal compliance, on the basis of the employment contract, our legal obligations, and our legitimate interests in intra-group administration.
Customers, users and their representatives: account and contract data, support tickets and correspondence, product usage information, and billing data may be shared within the Neo4j group for delivering and supporting our products and services (including shared support and engineering escalation), account management, contract administration and invoicing, on the basis of our contract with you and our legitimate interests in operating group-wide service delivery. Where a Neo4j group company provides support on our behalf, it does so as our processor; if your contract is transferred to a Neo4j group company, that company becomes the controller and its privacy notice applies.
Processors and affiliates acting under our instructions:
Other recipients (typically independent controllers or joint recipients in a specific context):
We require service providers processing personal data on our behalf to enter into written data processing agreements that include confidentiality, security obligations, restrictions on sub-processing, and requirements to act only on our documented instructions. They may not use personal data for their own independent purposes without a separate lawful basis and appropriate transparency. For a current list of sub-processors, or details about particular recipients, you can contact us at gpdr@graphaware.com.
These recipients may act either as processors (following our instructions) or as independent controllers under their own privacy notices. In each case, we aim to ensure GDPR-compliant contracts are in place, including appropriate security measures, limits on sub-processing without our approval, and safeguards for international transfers.
Business transfers: if we are involved in a merger, acquisition, financing, reorganisation, or a sale of some or all of our business or assets, personal data may be disclosed to the parties involved and their professional advisers under confidentiality obligations, and may be transferred to a successor or acquirer as part of the transaction. Any such recipient will continue to protect personal data in line with this notice, and we will inform you of material changes to how your data is used.
Because GraphAware operates internationally, personal data may be transferred and accessed across borders as necessary to provide services and run group operations.
Transfers within the EEA/UK:
Transfers between the UK and EEA (for example to entities in Ireland or other EU Member States, and vice versa) take place under the UK adequacy regulations and the EU–UK adequacy decision, meaning that an essentially equivalent level of protection is recognised between these jurisdictions.
Transfers to other countries (e.g., US and Australia):
Where personal data is transferred to countries that do not benefit from an adequacy decision, we rely on appropriate safeguards under UK GDPR and EU GDPR Chapter V. These typically include:
Recipients include certain service providers (e.g., HubSpot, Google, Microsoft, and other cloud or SaaS vendors), Neo4j group companies, and affiliates providing support from outside the UK/EEA.
Transfers within the Neo4j group: because Graph Aware Limited is part of the Neo4j group, personal data described in this notice may be transferred to Neo4j, Inc. in the United States and accessed by other Neo4j group companies. These transfers are protected by Neo4j, Inc.’s certification under the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. DPF, and the Swiss–U.S. DPF, and/or by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with the UK International Data Transfer Addendum or Agreement, supported by transfer impact assessments where needed. You can request a copy of the relevant safeguards by contacting gdpr@graphaware.com.
We periodically review transfer arrangements and safeguards in light of evolving legal requirements and guidance. You can request further details about specific international transfers, or copies of relevant safeguards (subject to redactions for security and confidentiality), by contacting gdpr@graphaware.com.
We take the security of personal data seriously and implement appropriate technical and organisational measures designed to protect it against unauthorised or unlawful processing, accidental loss, destruction, or damage.
Security measures
Depending on the systems and data involved, these measures may include:
If a personal data breach occurs that is likely to result in a risk to individuals’ rights and freedoms, we will assess the incident promptly and, where required, notify competent supervisory authorities (such as the ICO) within the applicable time limits and, in high-risk cases, inform affected individuals without undue delay
Data subjects have the following rights under UK GDPR and EU GDPR (Articles 15-22), which can be exercised free of charge (unless requests are manifestly unfounded or excessive) with identity verification.
Below is a summary of these rights and how to exercise them.
Right of access (SAR)
You can confirm whether we process your data, access a copy, and get processing details (purposes, categories, recipients, retention, safeguards). Email a written request to gdpr@graphaware.com
Rectification, erasure, restriction, portability
Right to object
You can object at any time to processing based on our legitimate interests, profiling, or direct marketing—we’ll stop unless we have compelling reasons that override your rights, or we need the data for legal claims. Objections to marketing will always be honoured. To opt out, use the unsubscribe links in our emails, adjust your preferences in Cookiebot, or contact us at gdpr@graphaware.com
Right to withdraw consent
You can withdraw your consent at any time. This will not affect the lawfulness of processing carried out before you withdrew consent. To update your cookie preferences, use Cookiebot; to stop marketing emails, use the unsubscribe link in our emails; or contact us at gdpr@graphaware.com
Automated decisions and profiling
No significant automated decisions; limited profiling occurs.
How we handle requests
To exercise any of these rights or raise questions about our handling of personal data, contact gdpr@graphaware.com.
Your rights are not affected by GraphAware becoming part of Neo4j. You can exercise any of the rights above by contacting gdpr@graphaware.com, whichever Neo4j group company holds your data, and we will coordinate the response. For marketing sent by Neo4j, you can also unsubscribe using the link in any Neo4j email or manage your preferences at neo4j.com/manage-subscriptions.
If you have concerns about how we handle personal data, you are encouraged to contact our compliance team at gdpr@graphaware.com in the first instance so that we can seek to resolve the issue. You also have the right to lodge a complaint with your local supervisory authority; for the UK, this is the Information Commissioner’s Office (ICO), which can be contacted at:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint
This privacy notice may be updated periodically to reflect changes in our processing activities, technologies, services, or legal requirements. The effective date will be indicated at the top of the notice. Where changes are material, we will take reasonable steps to inform you (for example, by email or prominent notice on our website). This notice does not cover third-party websites or services that have their own privacy notices; users are encouraged to review those notices when interacting with third-party content or services.
September 2026 — this notice was updated to reflect the acquisition of Graph Aware Limited by Neo4j, Inc. on 5 August 2026 (new provisions on sharing within the Neo4j group and on business transfers, and updated international-transfer safeguards covering transfers to the United States) and to make email tracking consent-based.