Privacy Policy.
01General Information
1.1. NextGen Connectivity OÜ, a company duly incorporated and registered under the laws of Estonia, with registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 7, 10117, and registered with the Estonian Register of Legal Entities under company number 17218111 (hereinafter ⎼ “NextGen Connectivity OÜ”, “Company”, “Us”, “We”, and “Our”), understands that your privacy is important to you and are committed to being transparent about the technologies it uses.. Therefore, We adopt this Privacy Policy (hereinafter referred to as the “Policy”). This Policy defines how your Personal Data may be collected, stored, processed, used, and disclosed by NextGen Connectivity OÜ while you use Our Website located at [WEBSITE URL — pending domain] (hereinafter ⎼ the “Website”) and interact with Us regarding Our Services.
1.2. By and/or interacting with the Company through the Contact Form or other communication channels, you this Policy, any annexes to the Policy, and any other documents referred to herein. In addition to Users acting as legal entities, the provisions of the Data Processing Agreement (the “DPA”) may apply where required by applicable law or contractual arrangements.
1.3. If you do not carefully read, do not fully understand, or do not agree with this Policy, you must immediately leave the Website and stop using Services.
1.4. This Privacy Policy, together with the Terms of Use and Acceptable Use Policy, forms a single binding agreement (“Agreement”) between you and the Company. These documents must be read and interpreted as one. By using the Services, you acknowledge that you have reviewed and accepted this Agreement in its entirety, and all of its terms.
1.5. This Policy applies to the people collectively referred to as “Personal Data Subjects” (hereinafter referred to as “Subjects”), namely:
1.5.1. User: 1) an individual who has reached the age of 18 and accepts this Policy on their own behalf, or 2) a legal entity represented by an individual acting on behalf of such legal entity, that visits, browses, accesses, or otherwise interacts with the Website, including by submitting information through the Contact Form regarding a potential partnership and integration of the Company's SDK.
1.5.2. Visitor - an individual who visits and browses the Website without submitting any inquiry or otherwise communicating with the Company.
1.6. You may be referred to as “you” or the “Subject” in this Policy.
02Definitions
2.1. Review the terms We use in order to fully understand the text and meaning of this Policy.
2.1.1. “Consent” — a clear, freely given, specific, informed, and unambiguous indication of the Subject’s wishes by which they, through a statement or a clear affirmative action, agree to the processing of their Personal Data and other terms of this Privacy Policy.
2.1.2. “Applicable Data Protection Laws” — all applicable international, federal, state, provincial, and local laws, rules, regulations, directives, and governmental requirements relating in any way to the privacy, confidentiality, protection, transfer, or security of Personal Data, including, without limitation: the EU General Data Protection Regulation 2016/679; the e-Privacy Directive 2002/58/EC (as amended and replaced from time to time) and their national implementing legislations; the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (“CCPA”), laws regulating unsolicited email communications; security breach notification laws; laws imposing minimum security requirements; laws requiring the secure disposal of records containing certain Personal Data; and all other similar applicable international, federal, state, provincial, and local requirements and privacy regulations, as amended from time to time.
2.1.3. “EU Data Protection Law” — means General Data Protection Regulation (EU) 2016/679 (“GDPR”) and e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC), and all other data protection laws of the European Union, European Economic Area (“EEA”), and their respective member states, each as applicable, and as may be amended or replaced from time to time.
2.1.4. “IP address” — a unique numerical label assigned to a device connected to the Internet, which can sometimes be used to identify the approximate geographic location of the device and track online interactions.
2.1.5. “Personal Data” — information or a set of information about an individual who is identified or can be specifically identified.
2.1.6. “Third parties” — any individuals, organizations, or entities that are not part of the Company, its affiliates, officers, directors, employees, agents, or subsidiaries, but may have access to Personal Data as described in this Privacy Policy, such as service providers, business partners, and other external entities with whom the Company may share or receive data under specified circumstances.
2.2. Capitalized terms used but not defined herein have the meanings given to them in the Terms of Use, Acceptable Use Policy, and their appendices.
03The Subject of This Policy
3.1. By visiting the Website, submitting information through the Contact Form, or otherwise communicating with the Company regarding potential cooperation and integration of the SDK, you acknowledge that the Company may collect, store, process, use, and disclose your Personal Data in accordance with this Policy and Applicable Data Protection Laws.
3.2. By using any part of the Website and/or Services, the Subject grants NextGen Connectivity OÜ the right to receive, store, process, use, and disclose the Subject's Personal Data in accordance with the terms of this Policy.
3.3. The purpose of obtaining, storing, processing, and using the Personal Data of the Subject is to provide them the opportunity to use the Website and/or Services, as well as to protect the rights and legitimate interests of the Subjects of Personal Data prescribed by law.
3.4. The Company does not provide SDK licensing, deployment, monetization, or partnership services directly through the Website. Any further processing activities related to the onboarding, verification, or contractual relationship with Partner-developers may be governed by separate agreements, including Partnership Agreements, Data Processing Agreements, and applicable compliance documentation.
04Principles of Data Processing
4.1. We follow all necessary principles to protect your Personal Data.
4.2. According to the current legislation of Estonia and GDPR, and other Applicable Data Protection Laws, We adhere to the following principles to protect your privacy:
4.2.1. Principle of lawfulness, fairness, and transparency - We process Personal Data lawfully, fairly, and transparently concerning the data subject.
4.2.2. Principle of purpose limitation - We collect Personal Data for specified, explicit, and legitimate purposes and do not further process it in a manner that is incompatible with those purposes.
4.2.3. Principle of data minimization -We collect Personal Data that is adequate, relevant, and limited to what is necessary concerning the purposes for which such Personal Data is processed.
4.2.4. Principle of data accuracy - We take reasonable steps to ensure that Personal Data is accurate and, where necessary, kept up to date. We take every reasonable step to ensure that inaccurate Personal Data, having regard to the purposes for which they are processed, are erased or rectified without delay.
4.2.5. Principle of storage limitation - We keep Personal Data in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the Personal Data are processed.
4.2.6. Principle of integrity and confidentiality - We process Personal Data in a manner that ensures appropriate security of the Personal Data, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage, using appropriate technical or organizational measures.
05Personal Data that we Collect and Process
5.1. To fulfill Our obligations to provide you with the opportunity to use the Website and Services, We may ask you to provide Us with your Personal Data.
5.2. Subjects. NextGen Connectivity OÜ may collect, record and analyze information of Subjects of Our Website.
5.2.1. We collect Personal Data when a User submits an inquiry through the Contact Form available on the Website or otherwise contacts Us through available communication channels. Such Personal Data may include your name, business email address, company details, application store links (Google Play, App Store, Microsoft Store), platform information, active user metrics, country of registration/residence, messenger contact details, and any other information voluntarily provided in connection with a potential partnership or SDK integration request.
5.2.2. We use the collected Personal Data only to communicate with you, evaluate potential business relationships, respond to your requests, and provide information regarding Our Services. If you do not want Us to collect your Personal Data, please do not submit information through the Contact Form or otherwise contact Us.
5.2.3. While processing Personal Data of Our Visitors and Users, We may rely on your consent as a legal basis for processing your Personal Data. You may withdraw such consent at any time by contacting Us at [EMAIL — pending domain]. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal. Please note that We may continue to process certain Personal Data where required by applicable law or where another lawful basis for processing applies.
5.2.4. If you contact Us through the Contact Form or other communication channels, We may record your request and Our reply in order to improve the efficiency of Our communications and facilitate the review of potential partnership opportunities. We may keep personally identifiable information associated with such communications, including your name, email address, company information, and correspondence history, in order to maintain business communications and provide high-quality support.
5.2.5. Usage Data is collected automatically through Our Website, which may include:
the IP addresses of devices accessing the Website;
connection type information;
ASN-level geolocation data;
anonymized device identifiers;
URI addresses (Uniform Resource Identifier);
request timestamps;
browser type and operating system information;
session duration and traffic metrics;
server response status codes;
records relating to consent collection and consent receipts;
security and compliance logs;
other technical information relating to the operation, security, and performance of the Website.
5.2.6. We use this information in aggregate to assess Website performance, improve the quality and functionality of Our Website, maintain records of User consent, protect Our infrastructure and digital assets from malicious activity, including DDoS attacks, monitor traffic patterns, comply with legal and regulatory obligations, and improve Our Services. We may also collect statistical and analytical information relating to the general activity of Users and Visitors on the Website.
5.2.7. Processing of Usage Data is based on Our legitimate interests. Such processing is necessary for ma intaining the security, integrity, functionality, and compliance of the Website and business operations.
5.2.8. Following the submission of an inquiry and prior to entering into any Partnership Agreement, Users may be required to undergo identity verification, compliance screening, and Know Your Customer (KYC) procedures conducted by Third Party providers, including Sumsub. Such processing may include identification data, document verification data, and other information required for compliance purposes. The processing of such data may be governed by separate policies, notices, contractual arrangements, or compliance documentation provided during the onboarding process. You should refer to the latest version of Our KYC Policy for the details on how the verification process is handled.
5.2.9. Wherever required by applicable law, We obtain your Сonsent before processing your Personal Data.
5.3. Partner-developers. In order to facilitate the conclusion, performance, and administration of Partnership Agreements, We may collect and process additional Personal Data of Partner-developers.
5.3.1. When a User enters into a Partnership Agreement with the Company and becomes a Partner-developer, We may process Personal Data necessary to perform Our contractual obligations, maintain business communications, comply with applicable legal requirements, and administer the business relationship between the parties.
5.3.2. We may verify your identity by requesting identification documents and other information necessary to complete identity verification, compliance screening, Know Your Customer (KYC), anti-money laundering (AML), sanctions screening, and other onboarding procedures. We process this information on the basis of Our legitimate interests, compliance with legal obligations, and the performance of contractual and pre-contractual obligations. We use such information to identify Partner-developers, prevent and detect fraud, protect Our intellectual property rights, comply with applicable laws and regulations, and maintain the security and integrity of Our business operations. We use such data in ways you would reasonably expect and which have a minimal privacy impact.
5.3.3. We may obtain certain Personal Data from Third Parties involved in the onboarding, verification, compliance, or business due diligence process, including KYC providers, sanctions screening providers, publicly available corporate registers, and other lawful sources. The categories of Personal Data obtained may vary depending on the nature of the verification or compliance process.
5.3.4. We may store your Personal Data and other information to the extent and for the period necessary to achieve the purposes specified in this Policy, comply with applicable legal obligations, resolve disputes, enforce Our agreements, and protect Our legitimate interests, or within the time limits established by the current legislation of the Republic of Estonia, international law or the legislation of the country of your residence, or until the moment you request the deletion of this data.
If your Personal Data changes or becomes inaccurate, We encourage you to notify Us and provide updated information. We may not be responsible for consequences resulting from inaccurate, incomplete, or outdated information provided by you.
06Legal Basis and Purpose of Data Processing
6.1. We process Personal Data in accordance with Applicable Data Protection Laws, including the laws of Estonia, the European Union, and the generally recognized principles and norms of international law.
6.2. The Сompany collects and processes Website Users’ Personal Data for the following purposes:
6.3. If you reside outside the EEA, you have privacy rights, and all Personal Data processing is governed by the local legislation on Personal Data protection adopted by the jurisdiction you reside in.
08Consent to Personal Data Processing
8.1. Where required by applicable law, We obtain your consent before processing Personal Data.
8.2. Consent to Personal Data Processing
8.2.1. By accessing the Website, submitting information through the Contact Form, communicating with Us regarding potential cooperation, or otherwise providing Personal Data to the Company, you confirm that you have reached the age of majority or the legal age required in your jurisdiction (generally 18 years of age or older), are legally capable of providing such information, are solely responsible for your actions, and fully understand the statements outlined in this Privacy Policy.
8.3. EU Persons Consent to Personal Data Processing
8.3.1. If you are an EU Person, and to process your Personal Data We need to receive your Сonsent, as it is prescribed by GDPR, We will process your Personal Data only in the case We have received from you a freely given, specific, informed, and unambiguous indication of your wishes by which you signify agreement to the processing of your Personal Data.
8.3.2. You may provide Consent by submitting information through the Contact Form, selecting any consent mechanisms made available on the Website, responding to Our communications, or otherwise clearly indicating your agreement to the processing of Personal Data for the specified purpose.
8.3.3. Where processing is based on Consent, your Consent shall apply only to the specific processing activities and purposes for which it was obtained. Where multiple processing purposes exist, We may request Consent separately where required by applicable law.
8.3.4. You may withdraw your Consent at any time by contacting Us using the contact details specified in this Privacy Policy. Withdrawal of Consent shall not affect the lawfulness of processing carried out before such withdrawal.
8.3.5. For the avoidance of doubt, not all processing activities performed by the Company are based on Consent. We may process Personal Data on other lawful grounds, including the performance of pre-contractual measures requested by you, the performance of a contract, compliance with legal obligations, and Our legitimate interests, where permitted by applicable law.
8.4. Non-EU Persons Consent to Personal Data Processing
8.4.1. If you are not an EU Person, by voluntarily providing Personal Data through the Website, Contact Form, email communications, business correspondence, compliance procedures, or otherwise, you acknowledge and agree that We may collect, store, use, disclose, transfer, and otherwise process such Personal Data in accordance with this Privacy Policy and applicable law.
8.4.2. Where required by applicable law, We will obtain any additional consent necessary for specific processing activities.
8.4.3. The Company may also process technical and usage-related information automatically collected through the Website, including IP addresses, connection information, anonymized device identifiers, consent records, security logs, and other technical metadata, as described in this Privacy Policy.
09The Rights of Subjects
9.1. Please read this chapter carefully. To exercise any of the rights described below, you may contact Us using the contact details specified in this Privacy Policy. We may request additional information reasonably necessary to verify your identity before responding to your request. We reserve the right to refuse requests that are manifestly unfounded, excessive, repetitive, or otherwise permitted to be refused under applicable law.
9.2. Right to access. You have the right to obtain confirmation as to whether We process your Personal Data and, where such processing takes place, to request access to your Personal Data. Subject to applicable law, We may provide information regarding the categories of Personal Data processed, the purposes of processing, the categories of recipients to whom Personal Data has been or may be disclosed, the envisaged retention period, and other information required by Applicable Data Protection Law.
9.3. Right to withdraw consent. Where the processing of your Personal Data is based on your Consent, you have the right to withdraw such Consent at any time by contacting Us using the contact details provided in this Privacy Policy. Withdrawal of Consent shall not affect the lawfulness of processing carried out prior to such withdrawal. Please note that We may continue to process certain Personal Data where required by applicable law or where another lawful basis for processing applies. Withdrawal of Consent may limit Our ability to communicate with you, evaluate your inquiry, provide information regarding potential cooperation, or otherwise perform activities for which such Consent was obtained.
9.4. Right to object. Where We process your Personal Data based on Our legitimate interests, you have the right to object to such processing at any time on grounds relating to your particular situation. In such case, We will cease the processing unless We demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where the processing is necessary for the establishment, exercise, or defense of legal claims. You also have the right to object at any time to the processing of your Personal Data for direct marketing purposes.
9.5. Right to restriction of the processing. You have the right to request restriction of the processing of your Personal Data in circumstances provided by applicable data protection laws, including where you contest the accuracy of Personal Data, where the processing is unlawful, or where you require the Personal Data for the establishment, exercise, or defense of legal claims. Restriction of processing may affect Our ability to review your inquiry, communicate with you, perform compliance procedures, or administer certain contractual relationships.
9.6. Right to data portability. Where applicable under relevant data protection laws, you have the right to receive Personal Data concerning you in a structured, commonly used, and machine-readable format and to transmit such data to another controller, where the processing is based on Consent or contract and carried out by automated means.
9.7. Right to rectification. You have the right to request that We correct inaccurate Personal Data concerning you and, taking into account the purposes of processing, complete incomplete Personal Data.
9.8. Right to erasure. Subject to applicable legal and regulatory requirements, You may request the deletion of your Personal Data where there is no longer a lawful basis for its processing. This right is not absolute and may be limited where We are required to retain Personal Data to comply with legal obligations, resolve disputes, enforce agreements, or protect Our legitimate interests.
9.9. Right to lodge a complaint. If you believe that the processing of your Personal Data violates applicable data protection laws, you may have the right to lodge a complaint with the competent supervisory authority in your jurisdiction
9.10. If you are a California resident, you have the right to opt out of the sale or sharing of your personal data as defined under the California Consumer Privacy Act (CCPA). CCPA defines "sale" as disclosing or making available to a third-party personal data in exchange for monetary or other valuable consideration, and “sharing” as disclosing or making available personal data to a third party for purposes of cross-context behavioral advertising. While We do not sell personal data in the traditional sense, the use of certain analytical cookies and similar technologies may be considered "sharing" under the CCPA/CPRA. You may exercise your right to opt out of the sale or sharing of your personal data at any time by contacting Us. Once you make this choice, We will stop using such cookies and technologies for targeted advertising or cross-context behavioral purposes.
10Data Storing and Deletion
10.1. We store your Personal Data for as long as necessary to fulfill the purposes described in this Privacy Policy,
10.2. We may retain certain information for longer periods where required by applicable law, regulatory requirements, accounting obligations, compliance procedures, legal claims, dispute resolution, or enforcement of contractual rights. Where reasonably possible, We may anonymize or aggregate information so that it can no longer be associated with an identified or identifiable individual.
10.3. EU Territory. If you are located within the European Union or European Economic Area, We retain Personal Data only for as long as necessary to achieve the purposes for which it was collected and processed, unless a longer retention period is required or permitted by applicable law. Technical and usage-related information, including security logs, consent records, and traffic-related metadata, may be retained for security, compliance, fraud prevention, audit, and legal purposes. Where possible and appropriate, such information may be anonymized or aggregated.
10.4. If you exercise your right to erasure, We will review your request in accordance with Applicable Data Protection Laws and delete Personal Data where We are not required or permitted to retain it for legal, regulatory, contractual, compliance, dispute resolution, fraud prevention, or legitimate business purposes.
10.5. US Territory. If you are located in the United States, We retain Personal Data for the period reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law.
10.6. Retention periods may vary depending on the nature of the Personal Data, the purpose of processing, applicable legal requirements, contractual obligations, and the jurisdiction in which the data is processed. In all cases, We strive to retain Personal Data only for as long as necessary and proportionate for the relevant purpose.
10.7. The Website and Services are intended exclusively for individuals who have reached the age of majority or the legal age required under the applicable laws of their jurisdiction. We do not knowingly collect Personal Data from children. If We become aware that Personal Data has been provided by a person who has not reached the legally required age, We may take reasonable steps to delete such information. If you believe that a child has provided Personal Data to Us, please contact Us using the contact details specified in this Privacy Policy.
11Data Security
11.1. We care to ensure the security of Personal Data.
11.2. We follow generally accepted industry standards to protect the information submitted to Us, both during transmission and once We receive it. We maintain technical, physical, and administrative security measures to provide reasonable protection for your Personal Data. When We or Our contractors process your information, We also make sure that your information is protected from unauthorized access, loss, manipulation, falsification, destruction, or unauthorized disclosure. This is done through appropriate administrative, technical, and physical measures.
11.3. You agree that there is no 100% secure method of transmission over the Internet or method of electronic storage. Therefore, We cannot guarantee its absolute security.
11.4. As a general rule, We do not intentionally collect or process special categories of Personal Data, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health-related data, data concerning a person's sex life or sexual orientation, or criminal offence data. However, certain information may be processed where required for identity verification, Know Your Customer (KYC), anti-money laundering (AML), compliance procedures, legal obligations, or other lawful purposes in connection with the onboarding and administration of Partner-developers.
12Third Parties
12.1. We work with third-party service providers who provide website hosting, maintenance, development, compliance, communication, analytics, and other services for Us. They may be located outside of the European Economic Area ("EEA"). Such contractors may have access to or process Personal Data on Our behalf as part of providing those services. We limit the information provided to such service providers to that which is reasonably necessary for them to perform their functions.
12.2. All data transfers are performed in accordance with applicable data protection laws and appropriate security measures. Where required by applicable law, We implement appropriate safeguards for international transfers of Personal Data.
12.3. All data processed by Us is stored using secure hosting and infrastructure providers selected in accordance with applicable security and compliance requirements.
12.4. We may share Personal Data with Our insurers, professional advisers, lawyers, accountants, auditors, bankers, compliance providers, corporate finance advisers, and other professional consultants in connection with the services they provide to Us. Where Personal Data is shared with such parties, We require them to maintain appropriate confidentiality and security measures.
12.5. We may also share Personal Data with third-party compliance, identity verification, Know Your Customer (KYC), anti-money laundering (AML), sanctions screening, and business due diligence providers where necessary to evaluate, establish, administer, or maintain potential or existing business relationships with Users and Partner-developers.
12.6. Where applicable, We may engage third-party analytics, security, infrastructure, communication, and technology providers to assist in operating, maintaining, improving, protecting, and securing the Website and Our business operations.
13Other Provisions
13.1. Check out Our other provisions to make sure you do not miss anything. If you have any questions regarding this Privacy Policy or the processing of your Personal Data, please contact Us using the contact details provided below.
13.2. Application of this Policy. This Privacy Policy applies to the Website. Once you leave the Website or are redirected to a third-party website, this Privacy Policy no longer applies, and the privacy practices of such third parties shall be governed by their respective policies.
13.3. Acceptance of this Policy. We assume that all Users and Visitors have carefully read this Privacy Policy and agree to its contents. If you do not agree with this Privacy Policy, you should not use the Website.
13.4. Changes and Updates to Our Policy. From time to time, We may update this Privacy Policy. We encourage you to periodically review this Privacy Policy so that you remain informed about what Personal Data We collect, how We use it, and with whom We may share it.
13.4.1. This Privacy Policy may be amended or supplemented by Us at any time without prior notice. The updated version of the Privacy Policy shall become effective from the moment it is published on the Website.
13.4.2. If you continue to use the Website after such amendments or updates become effective, you acknowledge and agree to the updated Privacy Policy.
13.5. Limitation of Liability. We are not responsible for any harm, loss, or damage suffered by you or any third party as a result of an erroneous understanding or misunderstanding of the provisions of this Privacy Policy. Before relying on this Privacy Policy, any Subject may contact Us for clarification regarding its provisions.
13.6. Severability. If any provision of this Privacy Policy is held by a court or competent authority to be invalid, unlawful, or unenforceable, such provision shall be deemed severed, and the remaining provisions of this Privacy Policy shall remain in full force and effect.
13.7. Jurisdiction and Disputes Resolution
13.7.1. This Privacy Policy, and any disputes or claims arising out of or relating to it, shall be governed by, construed, and interpreted in accordance with the laws of Estonia. Personal Data shall be processed in accordance with applicable data protection laws and regulations relevant to the respective Subject.
13.7.2. All disputes or disagreements between the parties regarding the execution of the Agreement shall be resolved through negotiations.
If the Parties do not reach an agreement within 30 (thirty) days, the dispute may be referred to the Estonian Chamber of Commerce and Industry. The number of arbitrators shall be one. The seat shall be Tallinn, Estonia. The language to be used shall be English.
13.8. Our details:
NextGen Connectivity OÜ
E-mail: _________________
Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 7, 10117, Estonia