Privacy

Privacy Statement

Version of 25 July 2026

NextForLab is an AI research and software development studio in the Netherlands. This statement explains how we handle personal data in running the business — on this website, in our dealings with clients, suppliers and collaborators, and on our social media profiles. It is written under the General Data Protection Regulation (GDPR), the Dutch implementing act (Uitvoeringswet AVG), and article 11.7a of the Dutch Telecommunications Act.

Scope note. This statement covers NextForLab as a business. Each application we publish has its own privacy statement, linked from its store listing and from within the application itself. If you are looking for how a specific product handles data, that statement is the one that governs.

01General information

1.1 Who is responsible

The controller within the meaning of art. 4(7) GDPR is:

NextForLab
Cruquiuskade 251
1018 AM Amsterdam
The Netherlands

Email: contact@nextforlab.nl
Business Register (KVK): KVK number
VAT identification number (btw-id): btw-id

NextForLab is a sole proprietorship (eenmanszaak) established in the Netherlands, operating as a software development studio and an applied AI research practice.

1.2 Data protection officer

We have not appointed a data protection officer, and are not required to. None of the grounds in art. 37(1) GDPR applies: we are not a public authority, our core activity does not consist of large-scale regular and systematic monitoring of individuals, and we do not process special categories of data on a large scale. Privacy correspondence goes to the address above and is handled by the owner of the business.

1.3 What this statement covers

  • Visitors to nextforlab.nl and its subdomains.
  • Clients, prospective clients, and anyone who contacts us about our work.
  • Suppliers, freelancers, and collaborators we engage.
  • Visitors to our company profiles on social media.

It does not cover our published applications, which have their own statements (section 4), nor the independent practices of platforms such as Apple, Google or LinkedIn, each of which acts as its own controller.

1.4 Legal bases we rely on

Each processing operation below names its basis under art. 6(1) GDPR:

  • Art. 6(1)(b) — performance of a contract, or steps taken at your request before entering one. This covers engagements, quotations, and supplier relationships.
  • Art. 6(1)(c) — legal obligation. Chiefly the retention of invoices and accounting records required by Dutch tax law.
  • Art. 6(1)(f) — legitimate interests. Keeping this website available and secure, and replying to enquiries addressed to us.
  • Art. 6(1)(a) — consent, where we ask for it. You may withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.

1.5 Processing outside the European Economic Area

We prefer providers established in the EEA. Where a transfer to a third country is unavoidable — for example when paying a collaborator outside the EU, or using a service hosted elsewhere — it takes place only on a basis permitted by Chapter V GDPR: an adequacy decision of the European Commission under art. 45, or the Standard Contractual Clauses under art. 46(2)(c), together with an assessment of the destination country and any supplementary measures needed. We will tell you on request which basis applies to a given provider.

1.6 Retention

Where a specific period is stated below, that period applies. Otherwise we erase personal data once the purpose for which it was collected has ended, unless a statutory retention obligation prevents erasure. The main such obligation is the seven-year period for accounting records under Dutch tax law. Where data must be retained on that basis but is no longer needed for its original purpose, we restrict its processing rather than use it for anything else.

1.7 Whether you have to give us data

You provide personal data voluntarily. In a business relationship we only ask for what is necessary to enter into, perform, or wind up the engagement, or what we are legally required to collect. Without that information we may be unable to conclude an agreement or to continue one. Where a form has mandatory fields, they are marked as such.

1.8 Automated decision-making

We do not carry out automated individual decision-making or profiling within the meaning of art. 22 GDPR. No decision that produces legal effects for you, or similarly significantly affects you, is taken by automated means.

02This website

2.1 Visiting the site

When you open a page, your browser transmits technical information so the page can be delivered. This may include your IP address, the date and time of the request, the page requested, the HTTP status code, the volume of data transferred, the referring page, and your browser type, operating system and language.

We process this to deliver the site and keep it stable and secure. The basis is our legitimate interest in operating a functioning website (art. 6(1)(f) GDPR). The entries are held in server logs and erased after 14 days. We do not use them to identify visitors and do not combine them with any other source.

2.2 Hosting

This website is hosted by Railway Corporation ("Railway"), United States, acting as our processor under a data processing agreement concluded pursuant to art. 28 GDPR. Railway processes the data described in 2.1 solely on our instructions.

Railway is established outside the European Economic Area, so hosting involves a transfer to a third country. That transfer takes place only on a basis permitted by Chapter V GDPR, as set out in section 1.5.

2.3 Cookies and device storage

Article 11.7a of the Telecommunicatiewet permits storing information on your device, or reading information from it, only where you have been clearly and fully informed and have given consent — unless the technique serves solely to carry out a communication, or is strictly necessary to deliver a service you requested.

This website places no cookies, local storage, tracking pixels or fingerprinting techniques beyond that strictly-necessary exception. There is accordingly no cookie banner, because there is nothing to consent to or refuse. If we later introduce analytical or marketing techniques, we will ask for consent in advance, make refusing as easy as accepting, and place nothing before consent has been given.

2.4 Getting in touch

When you email us or use a contact form, we process your contact details and the content of your message in order to respond, and where relevant to prepare a possible engagement. The basis is our legitimate interest in answering enquiries addressed to us (art. 6(1)(f) GDPR), or the taking of pre-contractual steps at your request (art. 6(1)(b) GDPR). We erase this correspondence when it no longer serves a purpose, and at the latest 24 months after the matter closes, unless a retention obligation applies.

03Business relationships

3.1 Clients and prospective clients

Where we take on commissioned work, we process the data needed to quote for, perform, invoice and support that engagement: names and roles of contact persons, business contact details, correspondence, project documentation, and payment particulars. The basis is performance of the contract or pre-contractual steps (art. 6(1)(b) GDPR), and for the financial records, our legal obligation (art. 6(1)(c) GDPR).

Where an engagement involves us processing personal data on a client's behalf — for instance while building or maintaining a system that holds their users' data — the client is the controller and we act as processor. That relationship is governed by a separate data processing agreement under art. 28 GDPR, not by this statement.

3.2 Suppliers, freelancers and collaborators

We process the contact, contractual and payment details of the people and businesses we engage, including freelancers and independent creators, in order to agree, perform and pay for that work. The basis is performance of the contract (art. 6(1)(b) GDPR). Invoices and related records are retained for seven years as Dutch tax law requires (art. 6(1)(c) GDPR). Where a collaborator is established outside the EEA, any transfer follows section 1.5.

3.3 Business administration

We keep the administration a Dutch business is required to keep, including invoices issued and received, bank records and VAT documentation. Personal data appearing in those records is retained for the statutory period, after which it is erased. The basis is our legal obligation (art. 6(1)(c) GDPR).

04Our products

NextForLab develops and publishes its own applications. Each has a separate privacy statement describing how that product handles data, published on its store listing and accessible from within the application, as required by the Apple App Store and Google Play. Those statements govern the products; this one does not.

Apple and Google act as their own controllers for downloads, purchases and platform analytics. Where an application is paid, they act as seller of record and we do not receive payment details. Aggregated platform statistics we receive about downloads, versions and territories contain nothing traceable to an individual.

05Research and development

Applied research is part of what we do, so it is worth stating plainly what we do not do with it. We do not use the personal data described in this statement to develop, train, fine-tune or evaluate models. We do not use client data for our own research purposes; anything we hold on a client's behalf is processed only on their documented instructions. Our experimental work is carried out on synthetic data, on data we are licensed to use, or on publicly available datasets.

Where a research activity would require personal data, we assess it beforehand — including, where art. 35 GDPR requires it, by carrying out a data protection impact assessment — and we do not begin until a lawful basis and appropriate safeguards are in place.

06Social media

We maintain a company page on LinkedIn to present our work. The platform is operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; its privacy policy is at linkedin.com/legal/privacy-policy.

LinkedIn processes visitors' data for its own purposes, including building profiles used to target advertising, partly by storing information on visitors' devices. We have no control over this and cannot disable it. You can object through LinkedIn's own advertising settings.

For the aggregated page statistics LinkedIn makes available to us, we and LinkedIn are joint controllers within the meaning of art. 26 GDPR. These statistics do not let us identify individual visitors. You may exercise your rights against either party; LinkedIn holds the underlying data, so approaching it directly is usually faster.

Messages you send us through a social platform are processed to reply to you, on the same terms as section 2.4.

07Children

Under art. 8 GDPR as implemented by art. 5 UAVG, the Netherlands sets at 16 the age from which a child can validly consent to processing of their own personal data. Below that age, consent must be given or authorised by the holder of parental responsibility.

This website and our business communications are directed at organisations and professional contacts, not at children. Where any of our products is used by people under 16, the applicable safeguards are described in that product's own privacy statement. If a child under 16 has sent us personal data and you hold parental responsibility for them, contact us and we will erase it.

08Security

Under art. 32 GDPR we apply technical and organisational measures appropriate to the risk: encrypted transport (TLS), encryption of stored data where applicable, data minimisation as a design principle, providers selected for their security posture, and access limited to those who need it.

Should a personal data breach occur, we will notify the Autoriteit Persoonsgegevens within 72 hours where art. 33 GDPR requires it, and inform affected individuals directly where art. 34 requires it.

09Your rights

In relation to personal data concerning you, you have the right to:

  • obtain confirmation of whether we process your data, and receive a copy (art. 15);
  • have inaccurate data rectified (art. 16);
  • have data erased (art. 17);
  • have processing restricted (art. 18);
  • receive data you provided in a structured, commonly used, machine-readable format (art. 20);
  • object to processing based on our legitimate interests (art. 21);
  • withdraw consent at any time (art. 7(3)).

Write to contact@nextforlab.nl. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.

We may need to establish that a request comes from you. If we ask for identification, protect yourself when sending it: obscure the photograph, the document number, the machine-readable strip, and your citizen service number (BSN).

You also have the right to lodge a complaint with the supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl. We would welcome the chance to resolve the matter with you first.

10Changes to this statement

We may amend this statement, with effect for the future, as our business or the law changes. The current version is the one published here, dated at the top.

11Questions

Questions or comments about this statement are welcome at contact@nextforlab.nl.