Compliance Document

Privacy Policy

Last Updated: August 8, 2026

At NextStrategy, your privacy is our priority. This Privacy Policy explains how Next Technology AS ("we", "us", or "our") collects, uses, and protects your personal and organizational data when you use our platform.

We operate under the strict data protection guidelines of the European Union’s General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.

1. Data Sovereignty & Hosting

We take the sovereignty of your strategic data seriously. All personal and organizational data is hosted and processed within the European Economic Area (EEA).

Cloud Infrastructure: Our platform is hosted on Google Cloud Platform / Firebase. Your database and storage are specifically located in the Europe North 2 (Netherlands)and Europe West 1 (Belgium) regions. We also utilize Europe North (Nordic)infrastructure for specific governance, compliance, and accounting data to ensure optimal regional alignment with EEA privacy standards.

2. Information We Collect

Personal Identity

  • Name and contact information
  • Authentication credentials
  • Professional profile and photos

Strategic Data

  • SWOT analysis & Industry models
  • Corporate roadmaps & Topic definitions
  • Member lists & Access permissions

B2B Communication: We may contact potential business representatives via professional B2B email addresses based on our legitimate interest (GDPR Art. 6(1)(f)) to introduce our platform. For this outreach, we process names, professional titles, and email addresses sourced from Apollo.io and Snov.io databases, which are retained for a maximum of 3 months. Recipients can opt out at any time via the unsubscribe link or by replying directly to the email.

3. Use of Generative AI

When you utilize the AI features of the platform (e.g., SWOT Generation, Strategic Reports, Strategy Coach), relevant analysis prompts are processed by the Google Gemini API via the Firebase Genkitframework.

  • Confidentiality: We utilize paid enterprise-tier API access where data sent for inference is not used to train the underlying foundation models of the AI provider.
  • Data Minimization: We only transmit the strategic context necessary to generate the requested output. No personal user data is sent for inference unless explicitly required by the prompt context.

4. Your Rights under GDPR

You possess comprehensive rights regarding your personal data:

  • Right to Access: You can request a summary of the data we hold on you.
  • Right to Erasure (Right to be Forgotten): You may permanently delete your account, which triggers our "Danger Zone" purge logic.
  • Right to Portability: You can request a machine-readable export of your strategic dossiers and models.
  • Right to Rectification: You may update your information via your Profile settings.

5. Security Governance

We employ enterprise-grade security controls to protect your workspace:

  • Encryption-at-rest for all strategic documents.
  • TLS 1.3 encryption for data-in-transit.
  • Multi-tenant isolation using advanced Firestore Security Rules.
  • Granular role-based access control (RBAC) within organizations.
  • System-level audit logging of workspace modifications, retained for security auditing and compliance verification for up to 365 days. Personal identifiable information (PII) is automatically redacted from these audit payloads prior to storage.

6. Contact & Data Protection Officer

If you have questions about this policy or wish to exercise your data rights, please contact our Data Protection Office:

Next Technology AS — Data Compliance Dept.

N5314 Kjerrgarden, Norway

Registration No: NO 938 182 469

Email: support@nextstrategy.eu

We aim to respond to all formal GDPR inquiries within 30 days.

Copyright © 2026 Next Technology AS. All rights reserved.