Data Privacy Notice
Last updated May 5, 2026. The detailed companion to our Privacy Policy, covering processing detail and your rights as a data subject.
Draft: this notice is a working draft pending legal review. Bring it under counsel review before launching the site publicly. Specific obligations and language vary by jurisdiction (GDPR, CCPA/CPRA, state laws).
1. Data controller
Nextekk, LLC is the data controller for personal information collected through this site. You can reach us at info@nextekk.com or 469-558-3188.
2. Categories of personal data we process
| Category | Examples | Source |
|---|---|---|
| Identifiers | Name, email address, phone number | Provided by you on the contact form |
| Commercial / professional | Company name, role, type of inquiry | Provided by you on the contact form |
| Conversation content | The message you write, follow-up emails | Provided by you |
| Technical | IP address, user-agent string, request URL, timestamp | Automatically collected by the web server |
| Authentication | Hashed admin password, session cookie (admin only) | Created when an authorized administrator signs in |
3. Purposes of processing and legal bases
- Respond to inquiries: lawful basis: performance of a contract or pre-contractual steps at your request (GDPR Art. 6(1)(b)) / business purpose (CCPA).
- Maintain a record of communications: legitimate interest in business continuity and consistent service (GDPR Art. 6(1)(f)).
- Site security and abuse prevention: legitimate interest in protecting our systems and users (GDPR Art. 6(1)(f)).
- Comply with legal obligations: lawful basis: legal obligation (GDPR Art. 6(1)(c)).
We do not engage in profiling, automated decision-making, or behavioral advertising on this site.
4. Sub-processors and recipients
We use the following sub-processors to operate the site. They are contractually bound to process personal data only on our instructions and with appropriate security measures.
| Provider | Purpose | Region |
|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Hosting, application server, data storage | United States |
| Postmark (Wildbit, LLC) | Transactional email delivery from our contact form | United States |
| Google Analytics / GA4 (Google LLC) | Aggregate site analytics (production environment only). IP anonymization enabled; no personal identifiers collected. | United States |
5. International transfers
We are based in the United States. If you contact us from outside the U.S., your information is transferred to and processed in the U.S. We rely on appropriate transfer mechanisms (such as the EU-U.S. Data Privacy Framework and Standard Contractual Clauses, where applicable) for our sub-processors.
6. Retention
- Active conversations: retained for the duration of the discussion plus a reasonable follow-up window (typically up to 24 months).
- Inactive contact-form submissions: archived or deleted on a periodic schedule.
- Server access logs: short rolling window (typically 30-90 days) sufficient for security review.
- Admin account records: retained while the account is active; deleted on offboarding or upon account-holder request.
We may retain certain records longer when legally required (for example, in response to a regulatory inquiry, audit, or pending claim).
7. Your rights
Depending on where you live, you may have some or all of the following rights with respect to your personal data:
- Access the data we hold about you.
- Correct inaccurate or incomplete data.
- Delete data we hold about you ("right to erasure" / "right to be forgotten").
- Restrict or object to certain processing.
- Data portability — receive a copy of your data in a structured, machine-readable format.
- Withdraw consent for any processing based on consent (no effect on processing already done).
- Opt out of "sale" or "sharing" of personal information (under U.S. state laws). We do not sell or share personal information.
- Lodge a complaint with a supervisory authority (such as a state Attorney General or a European Data Protection Authority).
8. How to exercise your rights
Email info@nextekk.com with the subject line "Data privacy request" and tell us which right you are exercising. We will:
- Acknowledge receipt within a reasonable timeframe.
- Verify your identity to the extent reasonably necessary (typically by confirming you control the email address that submitted the data).
- Respond substantively, typically within 30 days. If we need more time we will tell you why and how long.
We will not discriminate against you for exercising any of these rights.
9. Children
This site is not directed to children under 13 (or the equivalent age of digital consent in your jurisdiction). We do not knowingly collect data from children. If you believe a child has submitted data through our site, contact us and we will delete it promptly.
10. Changes to this notice
We may update this notice when our practices change or when required by law. The "Last updated" date at the top of this page shows the most recent revision.
11. Contact
- Email: info@nextekk.com
- Phone: 469-558-3188
- Mail: Nextekk, LLC, Addison, TX, USA