Neo4j acquires GraphAware. Learn more about this exciting new chapter.

Our privacy policy

September 2026

Update — September 2026: GraphAware is now part of Neo4j.

On 5 August 2026, Graph Aware Limited became a wholly-owned subsidiary of Neo4j, Inc. We have updated this notice to explain how personal data is shared within the Neo4j group, including with Neo4j, Inc. in the United States, and the safeguards that protect it.

Your rights, your existing marketing preferences, and our contact address (gdpr@graphaware.com) are unchanged. See “Sharing Your Data” and “International Transfers” below.

Who we are and scope

Graph Aware Limited, a UK-based international software company with entities in the EU (Italy and the Czech Republic) and Australia, acts as the controller for personal data processed through our website, client services, recruitment activities, events, and related operations.

Since 5 August 2026, Graph Aware Limited has been a wholly-owned subsidiary of Neo4j, Inc. (400 Concar Drive, San Mateo, CA 94402, USA) and, together with its affiliates, is part of the Neo4j group of companies, which also includes Neo4j UK Limited, Neo4j Sweden AB and Neo4j Germany GmbH. Where this notice refers to the “Neo4j group”, it means Neo4j, Inc. and its subsidiaries. Neo4j’s own privacy notice, which applies where a Neo4j group company processes your personal data for its own purposes, is available at neo4j.com/privacy-policy

This policy complies with UK GDPR and EU GDPR, covers customers, prospects, website users, job applicants, and candidates and — in relation to intra-group data sharing — employees and contractors (not intended for children), and explains how personal data is collected, used, shared, protected, transferred, and what rights individuals have under applicable data protection laws; where relevant, specific controllers are identified at the point of collection.

Our compliance team oversees data protection matters and can be contacted at gdpr@graphaware.com for all privacy-related queries, including requests to exercise data subject rights or obtain further information about this notice.

Personal data we collect

We may collect the following categories of personal data, depending on how you interact with us:

  • Identity: name, username, title, date of birth, gender, pronouns.
  • Contact: corporate/personal email address, phone number, postal address, company/employer details.
  • Financial/transaction: payment details, invoicing information, transaction history in relation to our products and services.
  • Technical: IP address, browser type and version, operating system, device identifiers, cookie identifiers, time zone, approximate location, and other information from server logs.
  • Profile/usage: interests, interaction history with our website, services, and communications, feedback, employment details, job title, project information, education history, references, and communication preferences.
  • Marketing data: marketing preferences, subscription and unsubscribe information, engagement metrics, and campaign interaction data.
  • Special categories and criminal data (recruitment/compliance only): information relating to criminal convictions, security clearances, right-to-work documentation, and related vetting information where required by law or our legitimate interests in protecting our business (e.g., fraud and IP protection), subject to appropriate safeguards and data minimisation.

We also generate aggregated or anonymised statistics for analytics and reporting, which do not identify individuals; such data is not treated as personal data where irreversibly anonymised. No special category data is intentionally collected for general marketing purposes.

How we collect data

We collect personal data from a range of sources:

Directly from you:
Forms on our website or landing pages (including mandatory marketing consent checkboxes where required), emails and correspondence, business cards, event badge scans or attendee lists when you register for or attend our events, job applications (including CVs, cover letters, references), account registrations, support tickets, meetings, interviews, and calls (which may be recorded for training, quality, or evidential purposes).

Automatically:
Cookies and similar technologies (see Cookies below), server and application logs, usage data from our website and online services, and information about how you interact with our emails, such as the links you click.

Third parties:
Advertising and analytics providers (such as Google, LinkedIn, Microsoft Advertising and Reddit Advertising) for clicks, conversions, and campaign performance; partners; event badge scans or attendee lists when you register for or attend an event we have organised or participated in, public and professional sources (including prior employers and online professional profiles); regulators and public authorities where legally permitted or required; recruitment vendors and background-check providers (such as DBS and Access NI checks); processors used for HR, timesheets, CRM and marketing (including BambooHR, Harvest, HubSpot); and reputable marketing lists or data aggregators, always in line with applicable law and contractual assurances. In many cases, data from these sources is synchronised into HubSpot or other systems we use for centralised management and analysis.

Cookies

Cookies and similar technologies are used to support site functionality, analytics, marketing (including Microsoft Ads and Reddit Ads), and security.

These technologies allow us to recognise your browser or device, understand how our services are used, improve the user experience, and measure the effectiveness of our communications. Cookie use is managed via a Cookiebot banner that enables granular consent by category (strictly necessary cookies are non-optional because they are required for core functionality).

Cookie details are reviewed and updated periodically, and you can request further information by contacting gdpr@graphaware.com.

Cookie categories

CategoryPurposeExamples/vendorsTypical duration
Strictly necessarySecurity, load balancing, login, form submissions, captcha validation, and core performanceCloudflare, Google reCAPTCHA, HubSpot (bot detection and forms), essential session cookiesSession to 1 year
Statistics/performanceUsage analytics, service improvement, performance measurement, and video supportHubSpot tracking cookies, Google Analytics (aggregated reporting), Vimeo, Spotify (podcast embeds), YouTubeUp to 14 months (reset on visit)
MarketingMeasuring advertising effectiveness, lead scoring and profiling (e.g., job title, email domain, country, engagement), campaign tracking, and personalisationHubSpot (user tracking), YouTube, Google Analytics, Google Ads, Microsoft Ads, Reddit Ads.Until opt-out plus 30 days
Functional/preferencesRemembering consent settings, preferences, and supporting embeds or widgetsCookiebot, Breezy (job adverts), Microsoft Teams (webinar data)Up to 12 months

Alongside Cookies, similar technologies can be used to understand how readers interact with marketing emails. This is what we do:

  • Tracking pixels – a tiny invisible image in an email that tells the sender whether, when and on what device a particular person opened it. We do not currently use tracking pixels in the emails we send you, and we do not measure whether you personally open our emails. If we introduce them in future, we will only do so with your agreement, which you will be able to withdraw at any time while still receiving our emails.
  • Personalised URLs – some emails you receive from us may contain personalised URLs. This means they contain a unique set of numbers and letters that tie your website behaviour to specific email campaigns, helping us to evaluate the effectiveness of our communications and marketing campaigns.

We do not use your clicks to score or profile you. You can update your email preferences at any time using the ‘Manage preferences’ link in any marketing email you receive from us, or by contacting gdpr@graphaware.com. Cookie choices can be changed at any time through Cookiebot.

Purposes, legal basis, and retention

The table below summarises the main purposes for which we process personal data, the categories of data involved, the corresponding legal bases under UK/EU GDPR, legitimate interests where applicable, and typical retention periods.

PurposeData typesLegal basis (UK/EU GDPR)Legitimate interests (where applicable)Retention period
Provide and improve products and services; Identity, contact, financial/transaction, customer representative employment details where relevant, video call recordings, account data, product usageContract; Consent; Legal obligation (e.g., tax)Ensuring service quality, understanding usage, and responding to enquiriesContractual relationship plus 6 years (tax/legal)
Recruitment (applications, vetting, onboarding)Identity, contact, CV and employment history, education, references, right-to-work documentation, criminal convictions and background-check data, National Insurance number, copies of IDContract; Legal obligation (employment, right-to-work); Consent where required for specific checksConducting fair and effective recruitment, ensuring suitability/trustworthiness for high-risk roles, protecting IP and preventing fraudUp to 6 months after recruitment process closure for unsuccessful candidates (unspent criminal data only), or up to 6 years where needed for legal claims or record-keeping
Operate accounts; handle queries, complaints, and claimsIdentity, contact, financial, purchase history, support and call data, location, communicationsContract; Legal obligation; Legitimate interestsMaintaining accurate records, customer service operations, and resolving disputesAs needed during relationship plus up to 6 years
Marketing, newsletters, and updates (including HubSpot sequences); process forms (demos, webinars, e-books, trials); analytics and lead scoring / profilingIdentity, contact, usage, marketing and preference dataConsent; Legitimate interestsBusiness growth, informing customers about relevant products/services, and tailoring communicationsUntil opt-out plus 30 days; disengaged/hard-bounce contacts are suppressed earlier where appropriate
Crime prevention, security, fraud/abuse detection Identity, technical, location, profile and engagement dataLegitimate interests; Legal obligationEnsuring network and information security, protecting IP and confidential information, improving site performance, and assessing lead qualityAnalytics data (e.g., cookies) generally up to 14 months; profile and suppression lists retained as long as necessary for security and suppression purposes
Research, product development, surveys, and events follow-upIdentity, contact, usage, profile information, feedback, survey responsesConsent; Legitimate interestsDeveloping and improving products and services, understanding customer needs, and evaluating eventsTypically up to 12 months after the relevant event or project, unless longer retention is legally required

Retention periods may be extended where required by law (e.g., tax or accounting rules) or where necessary to establish, exercise, or defend legal claims. After the applicable period, data is securely deleted, anonymised, or archived in accordance with our retention schedule.

You can opt out of marketing at any time using unsubscribe links in our communications, updating your preferences, or contacting us directly. Sales emails are normally addressed to specific business contacts and respect applicable soft opt-in and objection rules.

Sharing your data

We share personal data only as necessary and proportionate for the purposes described above, subject to appropriate contractual and security safeguards.

Sharing within the Neo4j group: following the acquisition of GraphAware by Neo4j, Inc. on 5 August 2026, we share personal data within the Neo4j group where necessary for the purposes below. Where a Neo4j group company processes your personal data for its own purposes, it does so as a separate controller under Neo4j’s privacy notice; where it processes data on our behalf, it acts as our processor under a written agreement. We only share what is necessary for these purposes, the retention periods in this notice continue to apply, and your existing marketing opt-outs are preserved.

Marketing and sales contacts (including our CRM records): identity and contact details, company information, marketing preferences and consent records, and engagement history are shared for continuity of sales and marketing relationships, a consolidated CRM, and joint go-to-market activity, on the basis of our legitimate interests and, where the communications themselves require it, consent. In countries where marketing requires a prior opt-in, Neo4j will only send you marketing once you have confirmed your opt-in; you can object or unsubscribe at any time.

Job candidates: your application data (CV, contact details, interview notes, references and assessment outcomes) is processed in the Neo4j group’s recruitment systems, and recruitment is administered on a group basis. Neo4j group companies may therefore access your application to run the recruitment process, and we may consider you for other suitable roles within the Neo4j group. We rely on the steps taken at your request before entering a contract and on our legitimate interests in running an efficient group-wide recruitment process; you can object at any time by contacting gdpr@graphaware.com. Where a role requires it, right-to-work documentation, security-clearance and criminal-records information relating to candidates and employees is also processed in the group’s recruitment and HR systems and may be accessed by Neo4j group companies performing those checks or administering employment — strictly on a need-to-know basis, only under the conditions that permit employment-related processing of such data (including UK GDPR Articles 9 and 10 and Schedule 1 to the Data Protection Act 2018), and never for any other purpose.

Employees and contractors: HR records (contract and payroll data, benefits, performance, absence, and IT account and directory data) are shared for group HR and payroll administration, benefits, IT systems and security, management reporting, and legal compliance, on the basis of the employment contract, our legal obligations, and our legitimate interests in intra-group administration.

Customers, users and their representatives: account and contract data, support tickets and correspondence, product usage information, and billing data may be shared within the Neo4j group for delivering and supporting our products and services (including shared support and engineering escalation), account management, contract administration and invoicing, on the basis of our contract with you and our legitimate interests in operating group-wide service delivery. Where a Neo4j group company provides support on our behalf, it does so as our processor; if your contract is transferred to a Neo4j group company, that company becomes the controller and its privacy notice applies.

Processors and affiliates acting under our instructions:

  • CRM, marketing, and communication tools such as HubSpot for forms, email campaigns, tracking, lead scoring, and related processing.
  • HR and people platforms such as BambooHR (HR and recruitment records), BreezyHR (recruitment workflows), and Harvest (time tracking and billing).
  • Cloud infrastructure, analytics, and collaboration services such as Google (Analytics, Ads, reCAPTCHA, Google Workspace), LinkedIn, Slack, Microsoft Teams, Vimeo, Spotify, YouTube, Breezy, Cloudflare, Cookiebot, and Atlassian Confluence.
  • Graph Aware Limited affiliates from Italy, Czech Republic, and Australia (Graph Aware S.R.L., Graph Aware s.r.o., GraphAware APAC Pty Ltd.), and Neo4j group companies, which may act as processors or sub-processors for group-wide services such as shared support, development, and coordinated recruitment, under binding instructions and appropriate safeguards.

Other recipients (typically independent controllers or joint recipients in a specific context):

  • Group entities where they determine their own purposes and means.
  • Professional advisers (legal, accounting, audit), insurers and insurance intermediaries, regulators, supervisory authorities, courts and tribunals, and law-enforcement agencies where necessary.
  • Event partners, sponsors, and recruitment agencies/vendors involved in co-hosted events, referrals, or candidate placement.
  • We may also share your details with a trusted local partner who will contact you directly to provide requested services or information.

We require service providers processing personal data on our behalf to enter into written data processing agreements that include confidentiality, security obligations, restrictions on sub-processing, and requirements to act only on our documented instructions. They may not use personal data for their own independent purposes without a separate lawful basis and appropriate transparency. For a current list of sub-processors, or details about particular recipients, you can contact us at gpdr@graphaware.com.

These recipients may act either as processors (following our instructions) or as independent controllers under their own privacy notices. In each case, we aim to ensure GDPR-compliant contracts are in place, including appropriate security measures, limits on sub-processing without our approval, and safeguards for international transfers.

Business transfers: if we are involved in a merger, acquisition, financing, reorganisation, or a sale of some or all of our business or assets, personal data may be disclosed to the parties involved and their professional advisers under confidentiality obligations, and may be transferred to a successor or acquirer as part of the transaction. Any such recipient will continue to protect personal data in line with this notice, and we will inform you of material changes to how your data is used.

International transfers

Because GraphAware operates internationally, personal data may be transferred and accessed across borders as necessary to provide services and run group operations.

Transfers within the EEA/UK:
Transfers between the UK and EEA (for example to entities in Ireland or other EU Member States, and vice versa) take place under the UK adequacy regulations and the EU–UK adequacy decision, meaning that an essentially equivalent level of protection is recognised between these jurisdictions.

Transfers to other countries (e.g., US and Australia):
Where personal data is transferred to countries that do not benefit from an adequacy decision, we rely on appropriate safeguards under UK GDPR and EU GDPR Chapter V. These typically include:

  • UK International Data Transfer Agreements (IDTAs) or Addenda;
  • Standard Contractual Clauses (SCCs) adopted by the European Commission;
  • Binding Corporate Rules (BCRs) where applicable; and
  • Supplementary technical and organisational measures, guided by transfer impact assessments (TIAs), to address local legal risks and ensure equivalent protection.

Recipients include certain service providers (e.g., HubSpot, Google, Microsoft, and other cloud or SaaS vendors), Neo4j group companies, and affiliates providing support from outside the UK/EEA.

Transfers within the Neo4j group: because Graph Aware Limited is part of the Neo4j group, personal data described in this notice may be transferred to Neo4j, Inc. in the United States and accessed by other Neo4j group companies. These transfers are protected by Neo4j, Inc.’s certification under the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. DPF, and the Swiss–U.S. DPF, and/or by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) together with the UK International Data Transfer Addendum or Agreement, supported by transfer impact assessments where needed. You can request a copy of the relevant safeguards by contacting gdpr@graphaware.com.

We periodically review transfer arrangements and safeguards in light of evolving legal requirements and guidance. You can request further details about specific international transfers, or copies of relevant safeguards (subject to redactions for security and confidentiality), by contacting gdpr@graphaware.com.

Data security

We take the security of personal data seriously and implement appropriate technical and organisational measures designed to protect it against unauthorised or unlawful processing, accidental loss, destruction, or damage.

Security measures

Depending on the systems and data involved, these measures may include:

  • Encryption of data in transit (e.g., TLS) and at rest where appropriate.
  • Role-based access controls and least-privilege principles, with need-to-know access, multi-factor authentication, and centralised identity management.
  • Network and application security measures, including firewalls, intrusion detection/prevention, DDoS mitigation (e.g., through Cloudflare), and secure software development practices.
  • Endpoint security measures applied to company-managed laptops and mobile devices.
  • Regular monitoring, logging, and review of access and activity.
  • Vendor due diligence and contractual security obligations for third-party service providers.
  • Employee and contractor training on data protection, confidentiality, and information security policies.
  • Incident and breach response plans, including procedures for investigation, containment, and remediation.

If a personal data breach occurs that is likely to result in a risk to individuals’ rights and freedoms, we will assess the incident promptly and, where required, notify competent supervisory authorities (such as the ICO) within the applicable time limits and, in high-risk cases, inform affected individuals without undue delay

Your rights

Data subjects have the following rights under UK GDPR and EU GDPR (Articles 15-22), which can be exercised free of charge (unless requests are manifestly unfounded or excessive) with identity verification.

Below is a summary of these rights and how to exercise them.

Right of access (SAR)

You can confirm whether we process your data, access a copy, and get processing details (purposes, categories, recipients, retention, safeguards). Email a written request to gdpr@graphaware.com

Rectification, erasure, restriction, portability

  • Rectification: ask us to correct inaccurate data, or add information where our data is incomplete
  • Erasure (“right to be forgotten”): instruct us to delete personal data that is no longer needed for our purposes, if you withdraw your consent (and we have no other legal basis to keep it), if you successfully object to our processing, or if we’ve processed it unlawfully..
  • Restriction: we’ll pause processing your personal data if you contest its accuracy (while we verify it), if processing is unlawful but you don’t want it deleted, if we need it to defend or pursue legal claims, or while we’re reviewing your objection.​
  • Portability: obtain your data in a portable format.​

Right to object

You can object at any time to processing based on our legitimate interests, profiling, or direct marketing—we’ll stop unless we have compelling reasons that override your rights, or we need the data for legal claims. Objections to marketing will always be honoured. To opt out, use the unsubscribe links in our emails, adjust your preferences in Cookiebot, or contact us at gdpr@graphaware.com

Right to withdraw consent

You can withdraw your consent at any time. This will not affect the lawfulness of processing carried out before you withdrew consent. To update your cookie preferences, use Cookiebot; to stop marketing emails, use the unsubscribe link in our emails; or contact us at gdpr@graphaware.com 

Automated decisions and profiling

No significant automated decisions; limited profiling occurs.

How we handle requests

  • Requests can be made free of charge, unless manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse the request, as permitted by law).
  • We may ask for additional information to verify your identity before responding, particularly where sensitive data or large volumes of data are involved.
  • We aim to respond within one month of receipt. For particularly complex or numerous requests, this period may be extended by up to two further months; if so, we will inform you of the extension and reasons.
  • Some rights may not apply in particular contexts (for example, where retention is required by law, or where disclosure would adversely affect others’ rights). In such cases, we will explain the legal basis relied upon.

To exercise any of these rights or raise questions about our handling of personal data, contact gdpr@graphaware.com.

Your rights are not affected by GraphAware becoming part of Neo4j. You can exercise any of the rights above by contacting gdpr@graphaware.com, whichever Neo4j group company holds your data, and we will coordinate the response. For marketing sent by Neo4j, you can also unsubscribe using the link in any Neo4j email or manage your preferences at neo4j.com/manage-subscriptions.

Complaints and changes

If you have concerns about how we handle personal data, you are encouraged to contact our compliance team at gdpr@graphaware.com in the first instance so that we can seek to resolve the issue. You also have the right to lodge a complaint with your local supervisory authority; for the UK, this is the Information Commissioner’s Office (ICO), which can be contacted at:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
Website: https://ico.org.uk/make-a-complaint

This privacy notice may be updated periodically to reflect changes in our processing activities, technologies, services, or legal requirements. The effective date will be indicated at the top of the notice. Where changes are material, we will take reasonable steps to inform you (for example, by email or prominent notice on our website). This notice does not cover third-party websites or services that have their own privacy notices; users are encouraged to review those notices when interacting with third-party content or services.

September 2026 — this notice was updated to reflect the acquisition of Graph Aware Limited by Neo4j, Inc. on 5 August 2026 (new provisions on sharing within the Neo4j group and on business transfers, and updated international-transfer safeguards covering transfers to the United States) and to make email tracking consent-based.