Privacy Policy
Policy Purpose
Next Gate Tech S.A. and its subsidiaries ("Next Gate Tech", "NGT", "we", "our", or "us") are committed to protecting personal data and ensuring transparency in how it is processed.
This Privacy Notice explains how we collect, use, disclose, and safeguard personal data when you:
- Visit our websites
- Use our services
- Interact with us as a customer, prospect, vendor, or job applicant
- Engage with us in any other applicable context
Our goal is to provide transparency about our data processing activities and inform you of your rights under applicable data protection laws, including the General Data Protection Regulation (GDPR) and other global regulations.
If you are applying for a role with us, please also see our Candidate Privacy Notice, which explains how we handle personal data during recruitment.
Roles and Scope of Processing
Depending on the context, Next Gate Tech acts as:
- Data Controller: when processing personal data for its own purposes (e.g. website usage, marketing, business operations)
- Data Processor: when processing personal data on behalf of customers
Where Next Gate Tech acts as a data processor, personal data is processed strictly in accordance with the instructions of the relevant customer (data controller), and such processing is governed by contractual agreements, including data processing agreements.
Data We Collect
We collect personal data about you through various means. The type of data we collect depends on your interaction with us.
Data You Provide
- Identity and contact data (name, email, phone, address, job title)
- Account credentials
- Financial and billing data
- Communication content
Data Collected Automatically
- IP address, device information, browser type
- Usage data (pages visited, timestamps, interactions)
- Cookies and tracking data
Data from Third Parties
- Employers or affiliated organizations
- Service providers (e.g. CRM, authentication providers)
- Publicly available sources
Purposes, Legal Basis, and Data Mapping
We process personal data as follows:
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Service delivery and account management | Identity, account, usage | Contract |
| Customer support | Contact, communication | Contract |
| Security and fraud prevention | Technical, usage | Legitimate Interest |
| Platform improvement and analytics | Technical, usage | Legitimate Interest |
| Marketing communications | Contact data | Consent / Legitimate Interest |
| Legal compliance | Any relevant data | Legal Obligation |
How We Use Your Data
We use your personal data for the following purposes:
- Service Delivery: To provide, maintain, and improve our services
- Customer Support: To respond to inquiries and provide technical assistance
- Personalization: To tailor our services to your preferences
- Marketing and Communication: To send promotional materials and inform you about events, offers, and services (with your consent where required)
- Security and Fraud Prevention: To monitor and analyze activities to prevent unauthorized access and misuse
- Legal and Regulatory Compliance: To comply with legal obligations, court orders, and government requests
- Analytics and Research: To conduct data analysis and research to improve our services and monitor usage trends
Marketing
Where permitted by applicable law, we may use your personal data to send you communications about our products, services, events, and updates that may be relevant to you.
You may receive such communications where:
- You have requested information from us or engaged with our services; or
- You are an existing customer and we are contacting you about similar products or services; or
- You have provided your consent to receive marketing communications
We may also use certain personal data, including contact details, business information, and usage data, to better understand your interests and tailor communications accordingly.
Third-Party Marketing
We do not share your personal data with third parties for their own direct marketing purposes without your prior explicit consent.
Opting Out of Marketing Communications
You may opt out of receiving marketing communications from us at any time by:
- Using the unsubscribe link included in our communications; or
- Contacting us using the details provided in this Privacy Notice
If you opt out of marketing communications, we will still send you communications that are necessary for the provision of our services, including:
- Service-related notifications
- Administrative messages
- Updates to terms, policies, or security information
Legal Basis for Processing
We rely on:
- Contractual necessity
- Legitimate interests (service improvement, security, fraud prevention)
- Legal obligations
- Consent, where required
Where we rely on legitimate interests, we assess whether such processing is necessary and balanced against your rights and freedoms.
How We Share Your Data
We only share personal data with approved recipients under controlled conditions.
Categories of recipients:
- Cloud hosting and infrastructure providers
- Authentication and identity providers
- CRM and communication tools
- Professional advisors and legal authorities
Key subprocessors include (non-exhaustive list):
- Google Cloud Platform
- Auth0
- HubSpot
- Google Workspace
- Zoho
These service providers process your data under our instructions and are bound by contractual agreements, security and data protection obligations to ensure the protection of your data.
Legal Obligations and Protection: We may also disclose personal data to comply with laws, protect rights, or respond to lawful requests
Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred to the acquiring entity
Use of External Systems and Data Sharing Controls
We enforce strict controls governing external systems in line with security and regulatory requirements.
Authorized Use
External systems may only be used where:
- Approved through formal risk assessment
- Covered by a Data Processing Agreement
- Subject to security controls (encryption, access control, monitoring)
Restrictions
Unless explicitly authorized:
- Personal data must not be stored, processed, or transmitted outside approved environments
- Unauthorized systems or networks may not be used
- Data must not leave controlled environments without safeguards
Subprocessor Governance
All subprocessors:
- Act only on documented instructions
- Are subject to due diligence and monitoring
- Must implement appropriate security controls
Authorized Individuals
Access is limited to:
- Employees and contractors with a defined need
- Approved third parties
- Regulatory authorities where legally required
All access is logged, authenticated, and controlled.
Customer Transparency
Where customer data is shared:
- Sharing is aligned with contractual and legal requirements
- Safeguards are applied
- Customers may request additional details
International Data Transfers
Where data is transferred outside the EEA:
- Standard Contractual Clauses (SCCs) are used
- Supplementary safeguards (e.g. encryption) are applied
- Data Processing Agreements are in place
You may request further details on these safeguards.
Security Measures
We implement appropriate technical and organizational measures, including:
- Encryption (in transit and at rest)
- Access controls and authentication
- Monitoring and logging
- Regular security assessments
- Incident response procedures
In case of a data breach, we will notify affected individuals and authorities as required.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Customer data: duration of contract + up to 6 months backup retention
- Marketing data: until consent is withdrawn
- Logs: up to 12 months
Your Rights
You have the following rights with regards to your data:
- Right to Be Informed: You have the right to be informed about the collection and use of your personal data, including the purposes for processing, retention periods, and who it will be shared with.
- Right to Access: Request confirmation of whether we process your personal data and access to it
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure (Right to Be Forgotten): Request deletion of your personal data under certain conditions
- Right to Restrict Processing: Request limitation of processing your personal data under specific circumstances
- Right to Data Portability: Receive your personal data in a structured, commonly used format and have it transmitted to another controller
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
Requests can be made via: privacy@nextgatetech.com
We will respond to your request within one month, as required by law.
You have the right to lodge a complaint with the Luxembourg National Commission for Data Protection (CNPD) or your local supervisory authority.
Children's Privacy
Our services are not intended for individuals under 16. We do not knowingly collect data from children without appropriate consent.
Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by:
- Posting a Notice: On our website or within our services
- Direct Communication: Email notification if you have provided us with your contact information
Please review this policy periodically for the latest information on our privacy practices.
Cookies
Cookies record device, browser, and preference information. Processing occurs per the Cookie Policy.
Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Next Gate Tech S.A. 26A Boulevard Royal L-2449 Luxembourg
Email: privacy@nextgatetech.com
Governance
This Privacy Notice is owned by the Executive Committee and maintained by designated operational and compliance functions. It is reviewed regularly to ensure alignment with legal and regulatory requirements.