1. Who is responsible for your data
NEXTCOG, a Société par actions simplifiée (SAS) with share capital of €1,000, is the controller of the personal data described in this policy.
- Registered office
- 73 Boulevard de Strasbourg, 34000 Montpellier, France
- Registration
- 888 436 672 RCS Montpellier
- SIREN / SIRET
- 888 436 672 / 888 436 672 00024
2. Scope of this policy
This policy applies when you browse the public NextCog marketing website, contact us using the protected contact form or email address published on it, or make a data-protection request concerning those activities.
It does not govern Lead Research Agent or another product application reached from this website. A product may process account, usage, customer-provided, and billing information under its own privacy information and contractual terms. Please review that information before using the product.
3. Data we process and why
| Activity and data | Purpose and legal basis | Retention |
|---|---|---|
| Website delivery and security. IP address, date and time, requested resource, response status, user-agent, referring page, and related server or security-log data. | Deliver the website, diagnose faults, maintain availability, and detect or respond to abuse. Our legal basis is our legitimate interest in operating a reliable and secure public website. | Normally no longer than 12 months. Relevant records may be kept longer where needed to investigate an incident or establish, exercise, or defend legal claims. |
| Contact requests and email correspondence. Your name, role, company, email address, phone number, request, attachments, and normal delivery metadata. | Respond to your enquiry, discuss a requested business relationship, and keep an appropriate record. Our legal basis is our legitimate interest in handling correspondence or taking steps at your request before entering a contract. | Up to three years after our last substantive exchange, unless the correspondence becomes part of a contract or must be kept longer for a legal obligation or claim. |
| Form security. IP address, browser and device signals, challenge outcome, and a short-lived Turnstile verification token. | Distinguish legitimate visitors from automated abuse and protect the contact service. Our legal basis is our legitimate interest in maintaining the security and availability of the Website and its communication channel. | The verification token is checked once and expires within five minutes. Security events may be retained with technical logs for up to 12 months. Cloudflare applies the retention periods described in its Turnstile privacy information. |
| Privacy requests and compliance. Contact details, request content, correspondence, and limited identity-verification information where necessary. | Verify and answer the request, demonstrate compliance, and protect against fraudulent requests. Our legal bases are compliance with legal obligations and our legitimate interest in protecting personal data and legal rights. | For the time needed to handle the request, then for the applicable limitation period as a compliance record. Any identity document requested is deleted as soon as verification is complete, unless the law requires otherwise. |
Technical data is sent automatically by your browser and the network services used to deliver the site. Using the contact form is optional, but all marked fields are required if you choose to submit it so that we can understand and answer your request. Please do not send passwords, credentials, or unnecessary sensitive personal data.
We do not use personal data covered by this policy for solely automated decisions that produce legal or similarly significant effects.
4. Cookies and similar technologies
The public website does not use analytics, advertising, or marketing cookies. The contact page loads Cloudflare Turnstile, a security service that processes limited browser and device signals to distinguish people from automated abuse. Turnstile’s standard widget does not use information for advertising. For details, see Cloudflare’sTurnstile Privacy Addendum.
If non-essential cookies or tracking technologies are introduced, we will update this policy and, where required, obtain consent before they are used.
5. Who receives personal data
Personal data is disclosed only where needed to:
- authorized NEXTCOG personnel responsible for the website or your enquiry;
- DigitalOcean, LLC, which provides the Website’s hosting infrastructure, and other network, security, and email providers acting for us;
- Cloudflare, Inc., which provides Turnstile bot protection for the contact form;
- professional advisers where necessary to obtain legal or other specialist advice; and
- courts, regulators, public authorities, or another party where disclosure is required by law or necessary to protect legal rights.
We do not sell personal data and do not share website visitor information for third-party advertising.
6. International transfers
DigitalOcean and Cloudflare are United States providers and may process hosting or security data outside the European Economic Area. Their data-processing terms provide transfer safeguards where applicable. For these and other providers, we use an applicable safeguard such as an adequacy decision or the European Commission’s standard contractual clauses, together with supplementary measures where appropriate. You may contact us for information about the safeguards relevant to your data.
7. Your rights
Subject to the conditions and exceptions in applicable law, you may ask for access to, correction of, or deletion of your personal data; restriction of processing; portability of data you provided; or object to processing based on legitimate interests. If processing is based on consent, you may withdraw that consent at any time without affecting earlier processing.
Send a request through the contact form or by post to our registered office. Describe the request and provide only the information reasonably needed to locate the relevant data. We may ask for additional proof of identity if we have reasonable doubts about who is making the request.
You may also complain to the French data-protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), throughwww.cnil.fr or by post at 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
8. Security and changes
We use proportionate technical and organizational measures intended to protect personal data against unauthorized access, alteration, loss, or disclosure. No internet transmission or storage system can be guaranteed completely secure.
This website is intended for business audiences and is not directed to children. We may update this policy when the website, our providers, or legal requirements change. The effective date above identifies the current version.