LGPD and GDPR compliance
Version 2026-09-07. Next protects client documents, records the necessary processing operations, and answers data subject rights within clear deadlines.
This page summarises the roles, legal bases, and controls used in the service.
The compliance badge on the home page is a self-declaration, not a certification.
1. Roles
Client documents and content: Next is the processor and the client is the controller; the client decides which documents are uploaded and which legal basis authorises that use.
Account data: for name, e-mail, company, IP, keys, session, and support, Next is the controller and names a data protection contact.
2. When each law applies
The LGPD applies to processing carried out in Brazil and to services offered to people in Brazil.
The GDPR applies to clients that offer goods or services to people in the European Union, monitor behaviour in the European Union, or have an establishment in the European Union.
For GDPR-subject cases, as Brazil has no adequacy decision, the art. 28 contract and the Standard Contractual Clauses of Decision (EU) 2021/914, module 2, are incorporated into the Data Processing Addendum of the Terms; the representative in the European Union is named for the client subject to that requirement.
3. Obligations map
State legend: meets (control applied by Next); up to the client (control under the responsibility of the document controller).
| Obligation | LGPD | GDPR | What Next does | State |
|---|---|---|---|---|
| Legal basis and purpose | art. 7 | art. 6 | Each processing has a stated basis: performance of a contract, legitimate interest for security and limits, and legal obligation for access logs. | meets |
| Minimisation | art. 6, III | art. 5(1)(c) | No password stored, content of questions is not stored, and e-mail enters the audit only as a hash. | meets |
| Transparency | art. 9 | arts. 13-14 | Policy, Terms, and this page are public, date-versioned, and written in direct language. | meets |
| Data subject rights | arts. 18-19 | arts. 15-22 | The support channel is in the portal; answers follow up to 15 days under LGPD and 1 month under GDPR. | meets |
| Portability and erasure | art. 18 | arts. 17, 20 | There is per-file download and folder sync, bulk export, My data, removed person deletion within 30 days, and space closure with purge within 7 days. | meets |
| Record of processing | art. 37 | art. 30 | This page, the Policy, and the internal record of processing describe processing, purposes, deadlines, and processors. | meets |
| Security | art. 46 | art. 32 | All traffic uses TLS; the server is not exposed directly to the internet; each space is isolated; keys are stored only as a hash; sessions expire after 30 minutes without use and last at most 12 hours; there are per-IP and per-route limits, hardened isolated execution, tamper-evident audit, and code login. | meets |
| Security incident | art. 48 | arts. 33-34 | The incident runbook defines triage, containment, record, communication to ANPD within 6 business days under the small-scale regime, and to the EU authority within 72 h. | meets |
| Processors and sub-processors | art. 39 | art. 28 | Cloudflare, the e-mail provider (SMTP), and the AI tool the client connected act for specific service purposes. | meets |
| AI tool and training | art. 39 | art. 28 | Search snippets go to the tool chosen by the client. Next runs search, reranking, and OCR without training models on client data. | meets |
| International transfer | art. 33 | ch. V | Next servers and processors may be in Brazil or abroad; transfers use the safeguards stated in the Policy and Terms. | meets |
| Retention | arts. 15-16 | art. 5(1)(e) | Access logs are kept for 6 months with IP sanitised at the end of the period; a removed person is deleted within 30 days; mutation audit is rotated yearly and preserved. | meets |
| Impact assessment (DPIA) | art. 38 | art. 35 | Next keeps a short internal DPIA to document risks, controls, and legal bases. | meets |
| Small-scale processing agent | Resolution CD/ANPD 2/2022 | art. 30(5) | Next is a small-scale processing agent and adopts the simplified regime: simplified record of processing on this page and a named data protection contact; data subject rights are answered within the deadlines in this table. | meets |
| Cookies | art. 8 | ePrivacy Directive | Only necessary cookies are used for language, session, and authentication. There is no advertising or tracking; audience measurement is cookieless. | meets |
| Children and adolescents | art. 14 | art. 8 | The service is corporate (B2B) and is not directed at children or adolescents. | meets |
| Automated decisions | art. 20 | art. 22 | Next takes no automated decision about people; it searches documents and returns snippets with source. | meets |
| Backup | art. 46 | art. 32(1)(c) | There is a daily backup retained for 30 days, an operational restore path, and status visible to administration. | meets |
| Client use of documents | arts. 7, 11 and 18 | arts. 6, 9 and 15-22 | The client defines the legal basis for uploaded documents, informs data subjects in the required cases, and chooses the AI tool connected to Next. | up to the client |
4. Contact
Questions about data protection and exercise of rights are handled by the data protection contact named in the footer of this page and in the Privacy policy. The data subject may also complain to the Brazilian data protection authority (ANPD) or, for GDPR-subject cases, to the competent supervisory authority in the European Union.