Privacy Policy
Effective Date: August 1, 2026 | Last Updated: August 15, 2026
1. Introduction
This Privacy Policy describes how Next Soft, operating at NEXTMYSOFT.COM (“Company,” “we,” “us,” or “our”), collects, uses, stores, shares, and protects personal information when you visit our website, create an account, purchase our software products, or otherwise interact with our services. We are committed to safeguarding your privacy and processing your data in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant regional regulations.
2. Information We Collect
2.1 Information You Provide Directly
- Account Registration Data: Full name, email address, company name, job title, phone number, and billing address provided during account creation or checkout.
- Payment Information: Credit/debit card number, expiration date, CVV, and billing address. This data is collected and processed exclusively by our PCI DSS Level 1 compliant payment processor (Stripe, Inc.) and is never stored on our servers. We retain only a tokenized reference and the last four digits of the card for transaction identification.
- Support Communications: Messages, files, and information you provide when contacting our support team or submitting a request through our contact form.
- Survey & Feedback Data: Responses to optional surveys, product feedback forms, or beta testing programs.
2.2 Information Collected Automatically
- Usage Data: Feature usage patterns, session duration, pages visited, click events, search queries, and error reports generated during your use of our software products.
- Device & Technical Data: IP address, browser type and version, operating system, device type, screen resolution, language preferences, and time zone.
- Log Data: Server access logs, API request logs, authentication events, and security audit trails.
- Cookies & Tracking Technologies: We use essential cookies for session management and optional analytics cookies to understand website usage. See Section 9 for details.
2.3 Information from Third Parties
- Payment Processor: Transaction status, payment confirmation, and fraud screening results from Stripe, Inc.
- Analytics Providers: Aggregated and anonymized website usage data from analytics services.
3. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contractual Necessity: Processing required to fulfill our obligations under the Terms of Service (e.g., account creation, payment processing, service delivery).
- Legitimate Interest: Processing necessary for our legitimate business interests, such as product improvement, fraud prevention, and security monitoring, provided these interests do not override your rights.
- Consent: Where you have explicitly consented to specific processing activities, such as receiving marketing communications.
- Legal Obligation: Processing required to comply with applicable laws, regulations, or legal proceedings.
4. How We Use Your Data
- Service Delivery: Providing, maintaining, and improving our software products and platform functionality.
- Transaction Processing: Processing purchases, managing subscriptions, issuing invoices, and handling payment disputes.
- Account Management: Administering your account, authenticating access, and managing your subscription status.
- Customer Support: Responding to inquiries, troubleshooting issues, and providing technical assistance.
- Product Improvement: Analyzing usage patterns and feedback to enhance features, fix bugs, and develop new functionality.
- Security & Fraud Prevention: Detecting, preventing, and investigating unauthorized access, fraud, abuse, and security incidents.
- Communications: Sending transactional emails (receipts, service updates, security alerts) and, with your consent, promotional communications.
- Legal Compliance: Meeting regulatory requirements, responding to legal requests, and enforcing our terms and policies.
5. Data Sharing & Disclosure
We do not sell, rent, lease, or trade your personal information to third parties. We may share your data only in the following limited circumstances:
- Payment Processor (Stripe, Inc.): Payment information is transmitted directly to Stripe for transaction processing, fraud detection, and chargeback management. Stripe’s privacy policy governs their handling of this data.
- Infrastructure Providers: Hosting and cloud service providers that store and process data on our behalf under strict data processing agreements (DPAs) with appropriate security certifications.
- Legal Requirements: When required by law, regulation, legal process, or governmental request, or when necessary to protect the rights, property, or safety of our company, users, or the public.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.
6. Data Security
We implement comprehensive security measures to protect your personal data, including:
- Encryption: 256-bit AES encryption for data at rest and TLS 1.2+ encryption for data in transit.
- Access Controls: Role-based access controls with multi-factor authentication for all administrative access to production systems.
- Infrastructure Security: Firewalls, intrusion detection systems, and continuous vulnerability scanning.
- Security Audits: Regular third-party penetration testing and security audits.
- Employee Training: All employees with access to personal data undergo security awareness training.
- Incident Response: A documented incident response plan with defined escalation procedures and notification timelines.
While no system can guarantee absolute security, we take every commercially reasonable precaution to safeguard your data.
7. Data Retention
We retain your personal data for as long as is necessary to fulfill the purposes for which it was collected:
- Active Accounts: Data is retained for the duration of your active subscription or account.
- Closed Accounts: Account data is deleted or anonymized within 90 days of account closure, unless retention is required for legal, regulatory, or compliance purposes.
- Transaction Records: Financial transaction records are retained for a minimum of 7 years as required by applicable tax and commercial laws.
- Security Logs: Access logs and security audit trails are retained for a minimum of 12 months.
8. Your Rights
Depending on your jurisdiction, you may exercise the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to Restriction: Request that we limit the processing of your data under certain circumstances.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interest or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at support@nextmysoft.com. We will respond to verified requests within 30 days.
9. Cookies & Tracking Technologies
Essential Cookies: Required for core functionality, including session management, authentication, and security. These cannot be disabled.
Analytics Cookies: Used to understand how visitors interact with our website, including page views, navigation paths, and feature usage. These are optional and can be managed through your browser settings.
Third-Party Cookies: We do not use third-party advertising cookies or cross-site tracking pixels. We do not participate in behavioral advertising networks.
10. International Data Transfers
Your data may be processed and stored in jurisdictions outside your country of residence. When transferring data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other legally recognized transfer mechanisms.
11. Children’s Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take immediate steps to delete such information.
12. California Residents (CCPA)
If you are a California resident, you have additional rights under the CCPA, including: (a) the right to know what personal information we collect and how it is used; (b) the right to request deletion of your personal information; (c) the right to opt out of the sale of personal information (we do not sell personal information); (d) the right to non-discrimination for exercising your CCPA rights.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. Material changes will be communicated via email or a prominent notice on our website at least fourteen (14) days before taking effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
14. Contact Us
For questions, concerns, or requests related to this Privacy Policy or our data handling practices, please contact our Data Protection team: