Terms of use
Version 2026-09-07. By creating an account you accept these terms. The accepted version and the date of acceptance are recorded on the account.
1. The service
Next lets the AI you already use, such as Claude, Codex or any MCP-compatible client, search your company documents and answer citing the source. It is a corporate (B2B) service, not directed at children or adolescents. Documents are indexed in a space isolated per account and served only to the access keys of that account.
2. Account, administrator and users
- Whoever creates the account is the administrator and is responsible for the account, the contracted space and the people they invite.
- Each person receives a personal access key. The key is shown once, must not be shared, and can be replaced or revoked at any time.
- You are responsible for keeping keys secret and for all use made with them until they are replaced or revoked.
3. Plans and billing
The plan defines the contracted storage and usage limits for the account. Any billing depends on a commercial agreement accepted by the client, outside the portal's automatic flow.
4. Your documents
- Your documents are yours. You grant Next only the license needed to index them and serve them to the keys of your account.
- Documents are never used to train models and are never shared between accounts.
- You declare that you have the right to upload each document and to let the people of your account query it, and you are responsible for having a legal basis for the personal data you upload.
5. Acceptable use
You may not use Next to store or distribute illegal content, to attack the service or third parties, to try to reach other accounts' data, or to circumvent space and usage limits. A serious violation allows immediate suspension of the account, with notice to the administrator, and may lead to the closure described in section 7.
6. Availability and backups
Next keeps a daily backup retained for 30 days and an operational restore procedure. We recommend that you also keep the originals of your documents in your own environment.
7. Account closure and data deletion
Who can close the account. The company administrator, at any time, in the company area, confirming the name of the space. Next, for a serious violation of section 5.
Immediate effect. Closure shuts the space at once: the access keys stop working, sessions are ended and access through the sync client is refused.
Before the purge. As long as the account exists, the administrator can export the company documents in bulk and each person can export their own, in the corresponding area of the portal. After the purge there is no recovery.
Definitive purge within 7 days. The definitive deletion happens 7 days after closure. Within that window the closure can still be reversed; after it, it cannot.
What is deleted. In the purge, the following are permanently deleted from the service: the company's and each person's documents, the indexes generated from them, all access keys and tokens, the sync pairings, the usage record and the account's list of people.
What is kept. Only what the law requires, and without the documents: access logs for 6 months, under art. 15 of the Internet Civil Framework, and the internal mutation audit, which keeps the e-mail only as a hash, never in clear text. The IP address is removed from the log at the end of 6 months.
Person removed from the account. The administrator can remove a person at any time. That person's personal space is deleted within 30 days, and their keys stop working immediately.
8. Changes to these terms
Changes are announced to the administrator by e-mail at least 15 days in advance and get a new dated version. Continued use after the effective date counts as acceptance of the new version.
9. Governing law
These terms follow Brazilian law, including the General Data Protection Law (Law 13.709/2018, LGPD) and the Internet Civil Framework (Law 12.965/2014). For a client subject to the GDPR, the Data Processing Addendum in section 11 also applies.
10. Contact
The data protection officer's contact is shown in the footer of the public pages and in the Privacy policy. Other support channels are in the company area inside the portal.
11. Data Processing Addendum (DPA)
This addendum applies to a client subject to the GDPR (Regulation (EU) 2016/679) or to parties that adopt it in writing, and it supplements these Terms without replacing them.
- Roles. As to the client's documents and content, the client is the controller and Next is the processor (LGPD art. 5, VII; GDPR art. 4(8)). As to account data (name, e-mail, company, IP), Next is the controller, as set out in the Privacy policy.
- Subject matter, duration, nature and purpose. Next indexes and serves the client's documents so that the AI tool chosen by the client can answer citing the source, for as long as the account lasts.
- Types of data and data subjects. These are determined by the client, through the content they upload; Next does not determine them.
- Documented instructions. Next processes the documents only to provide the service and on the client's instructions, and informs the client if an instruction appears to infringe the law.
- Confidentiality and security. Everyone with access is bound by confidentiality; the security measures are those in section 7 of the Privacy policy.
- Sub-processors. The client authorises the sub-processors needed for the service: Cloudflare, the e-mail provider (SMTP), and the AI tool the client connects. Each processes data under a contract compatible with this addendum.
- Assistance to the controller. Next assists the client in meeting data subject requests, assessing impacts and responding to incidents, through the portal features and the incident runbook.
- Return and deletion. At the end of processing, the client exports their data and, on closure, the data is purged within 7 days, as set out in section 7.
- Audit. Next makes available, on reasonable request, the information needed to demonstrate compliance with this addendum.
- International transfer. As Brazil has no adequacy decision from the European Commission, the transfer of EU data subjects' data to Next relies on the Standard Contractual Clauses of Implementing Decision (EU) 2021/914 (module 2, controller to processor), incorporated into this addendum by reference. The EU representative (GDPR art. 27) is named for clients subject to that requirement.