Next

LGPD and GDPR compliance

Version 2026-09-07. Next protects client documents, records the necessary processing operations, and answers data subject rights within clear deadlines.

This page summarises the roles, legal bases, and controls used in the service.

The compliance badge on the home page is a self-declaration, not a certification.

1. Roles

Client documents and content: Next is the processor and the client is the controller; the client decides which documents are uploaded and which legal basis authorises that use.

Account data: for name, e-mail, company, IP, keys, session, and support, Next is the controller and names a data protection contact.

2. When each law applies

The LGPD applies to processing carried out in Brazil and to services offered to people in Brazil.

The GDPR applies to clients that offer goods or services to people in the European Union, monitor behaviour in the European Union, or have an establishment in the European Union.

For GDPR-subject cases, as Brazil has no adequacy decision, the art. 28 contract and the Standard Contractual Clauses of Decision (EU) 2021/914, module 2, are incorporated into the Data Processing Addendum of the Terms; the representative in the European Union is named for the client subject to that requirement.

3. Obligations map

State legend: meets (control applied by Next); up to the client (control under the responsibility of the document controller).

ObligationLGPDGDPRWhat Next doesState
Legal basis and purposeart. 7art. 6Each processing has a stated basis: performance of a contract, legitimate interest for security and limits, and legal obligation for access logs.meets
Minimisationart. 6, IIIart. 5(1)(c)No password stored, content of questions is not stored, and e-mail enters the audit only as a hash.meets
Transparencyart. 9arts. 13-14Policy, Terms, and this page are public, date-versioned, and written in direct language.meets
Data subject rightsarts. 18-19arts. 15-22The support channel is in the portal; answers follow up to 15 days under LGPD and 1 month under GDPR.meets
Portability and erasureart. 18arts. 17, 20There is per-file download and folder sync, bulk export, My data, removed person deletion within 30 days, and space closure with purge within 7 days.meets
Record of processingart. 37art. 30This page, the Policy, and the internal record of processing describe processing, purposes, deadlines, and processors.meets
Securityart. 46art. 32All traffic uses TLS; the server is not exposed directly to the internet; each space is isolated; keys are stored only as a hash; sessions expire after 30 minutes without use and last at most 12 hours; there are per-IP and per-route limits, hardened isolated execution, tamper-evident audit, and code login.meets
Security incidentart. 48arts. 33-34The incident runbook defines triage, containment, record, communication to ANPD within 6 business days under the small-scale regime, and to the EU authority within 72 h.meets
Processors and sub-processorsart. 39art. 28Cloudflare, the e-mail provider (SMTP), and the AI tool the client connected act for specific service purposes.meets
AI tool and trainingart. 39art. 28Search snippets go to the tool chosen by the client. Next runs search, reranking, and OCR without training models on client data.meets
International transferart. 33ch. VNext servers and processors may be in Brazil or abroad; transfers use the safeguards stated in the Policy and Terms.meets
Retentionarts. 15-16art. 5(1)(e)Access logs are kept for 6 months with IP sanitised at the end of the period; a removed person is deleted within 30 days; mutation audit is rotated yearly and preserved.meets
Impact assessment (DPIA)art. 38art. 35Next keeps a short internal DPIA to document risks, controls, and legal bases.meets
Small-scale processing agentResolution CD/ANPD 2/2022art. 30(5)Next is a small-scale processing agent and adopts the simplified regime: simplified record of processing on this page and a named data protection contact; data subject rights are answered within the deadlines in this table.meets
Cookiesart. 8ePrivacy DirectiveOnly necessary cookies are used for language, session, and authentication. There is no advertising or tracking; audience measurement is cookieless.meets
Children and adolescentsart. 14art. 8The service is corporate (B2B) and is not directed at children or adolescents.meets
Automated decisionsart. 20art. 22Next takes no automated decision about people; it searches documents and returns snippets with source.meets
Backupart. 46art. 32(1)(c)There is a daily backup retained for 30 days, an operational restore path, and status visible to administration.meets
Client use of documentsarts. 7, 11 and 18arts. 6, 9 and 15-22The client defines the legal basis for uploaded documents, informs data subjects in the required cases, and chooses the AI tool connected to Next.up to the client

4. Contact

Questions about data protection and exercise of rights are handled by the data protection contact named in the footer of this page and in the Privacy policy. The data subject may also complain to the Brazilian data protection authority (ANPD) or, for GDPR-subject cases, to the competent supervisory authority in the European Union.