1. Data Controller Identification
In compliance with Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) and Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights (LOPDGDD), you are informed that personal data collected through the Nextaur platform is processed by:
Owner: Erik Armenteros del Castillo
Tax ID (NIF): 51988106X
Registered address: Calle Pico de los Artilleros, Madrid, 28030, Spain
Privacy and legal contact: legal@nextaur.com
2. Our Role in Data Protection (B2B SaaS)
Nextaur is a software-as-a-service (B2B SaaS) platform. It is essential to distinguish our legal role depending on the origin and type of data:
Nextaur as Data Controller: We process as controllers user account data (email, name), Organization billing data, and platform usage analytics.
Nextaur as Data Processor (B2B DPA): When an Organization uploads videos, clips, or generates assessment activities that include third-party data (for example, students, athletes, employees, or minors), the Organization is solely responsible for that data. Nextaur only hosts and processes it following their instructions. The conditions for this processing on behalf of third parties are detailed in Annex 1: Data Processing Agreement (DPA) at the end of this document.
3. What Data We Process, Why, and on What Legal Basis?
| Data Category | Purpose of Processing | Legal Basis (GDPR) |
|---|---|---|
| Account Data: Email, name, date of birth, country, preferred language. | Create the account, authenticate the user, and provide the SaaS service in a personalized way. | Art. 6.1.b (Contract performance / pre-contract) |
| Organization and Billing Data: Company/club name, member roles, data managed through Stripe. | Subscription management, plan limits, payments, non-payment handling, and technical support. | Art. 6.1.b (Contract performance) and Art. 6.1.c (Legal accounting/tax obligation) |
| Usage Data and Telemetry: Session logs, feature usage, active time per module. | Platform security maintenance (abuse prevention, MFA) and internal analytics for service improvement. | Art. 6.1.f (Legitimate interest) |
| Marketing Data: Email and preferences. | Sending commercial communications, news, and Nextaur updates. | Art. 6.1.a (Explicit consent — revocable at any time) |
4. Data Retention Periods
| Scenario | Retention period and action |
|---|---|
| Active account | Retained for the duration of the contractual relationship or until the user deletes their account. |
| Account deletion (personal) | Requesting deletion of your account opens a recoverable 14-day grace period: your account is disabled immediately, but you can reactivate it using the link we send you by email. If you do not reactivate within 14 days, your account and associated data (including organizations you solely own) are permanently and irreversibly deleted. |
| Organization cancellation | 30-day security retention for Organizations on paid plans before definitive and irreversible purge. For the Free plan inactive for more than 30 days, organization deletion will be executed automatically. |
| Billing and payments | At least 5 years as required by law (Spanish General Tax Law). |
| Product telemetry | Retained in identifiable form for 24 months. After that period, granular records are deleted after materializing fully anonymized aggregated statistics (without user or organization identifiers), which are kept indefinitely for internal analytics. |
5. Providers, Servers, and International Transfers
To provide the service with maximum quality and security, Nextaur relies on first-tier technology infrastructure providers. We guarantee that the core of our servers and video storage are located within the European Economic Area (EEA), strictly complying with European regulatory safeguards:
- Video and image storage (AWS S3) and Database (Supabase): Hosted on servers in the European Union.
- Payments and billing (Stripe): Secure processing with PCI-DSS certification. Nextaur does not store or have access to your full credit card number.
- Email delivery (Brevo): European provider for transactional communications.
6. Minimum Age and Minors
To register as an individual user on Nextaur, you must be at least 14 years old. To register an Organization as "Owner" and subscribe to a plan, the user must be at least 18 years old and have legal capacity to contract.
If an Organization uses Nextaur infrastructure to process data, videos, or assessments of minors under 14, it is the exclusive and non-delegable responsibility of that Organization to obtain prior explicit consent from parents or legal guardians.
7. Your Privacy Rights
You may exercise your data protection rights by sending an email to legal@nextaur.com. You have the right to:
- Access and Rectification: Know what data we hold and correct it directly from your profile panel.
- Erasure (Right to be forgotten): Delete your account autonomously from platform settings or by requesting it by email.
- Objection and Restriction: Withdraw your consent for marketing or object to processing based on legitimate interest.
- Portability: Request a copy of your personal data provided in a structured, readable format.
If you believe your rights have been violated, you have the right to lodge a complaint with the competent supervisory authority, which in Spain is the Spanish Data Protection Agency (AEPD).
8. Changes to This Policy
Nextaur reserves the right to modify this policy to adapt it to legislative updates, case law requirements, or structural changes to the service. We will notify registered users of any material change with reasonable advance notice.
Annex 1: Data Processing Agreement (B2B DPA)
This Annex forms an integral and inseparable part of the Terms and Conditions and Privacy Policy of Nextaur, and governs the processing of personal data by Nextaur (the "Processor") on behalf of and for the contracting Organization (the "Controller").
1. Purpose and Nature of the Processing
The Controller contracts Nextaur to use its SaaS platform. In this process, the Controller may upload, host, and manage videos, images, metadata (arbitration or sports-related), and assessment data containing personal data of third parties (students, athletes, staff). Nextaur will act solely as Data Processor, providing hosting, access management, and requested software functionality.
2. Nextaur's Obligations (The Processor)
- Process personal data only following the Controller's documented instructions. The Organization's own configuration and use of the platform shall be considered documented instructions.
- Ensure that persons authorized to process data have committed, expressly or by legal obligation, to respect confidentiality.
- Adopt all technical and organizational security measures required by Art. 32 GDPR, including encryption in transit (HTTPS), secure databases with role-based access control (RLS), and signed URLs for audiovisual media access.
- Not engage another processor (sub-processor) without prior authorization. By accepting this agreement, the Controller generally authorizes Nextaur to use Amazon Web Services (AWS) and Supabase services as EU hosting sub-processors.
- Assist the Controller, through platform technical tools or manual support, to fulfill its obligation to respond to data subject rights requests (students, athletes).
- Notify the Controller, without undue delay and within a maximum of 48 hours of becoming aware, of any personal data breach.
- Once the service ends (voluntary cancellation, Free plan inactivity, or prolonged non-payment), delete all Controller personal data (including copies) according to retention periods defined in the Terms and Conditions, unless legal retention is required.
3. Organization's Obligations (The Controller)
- Ensure it has a valid legal basis (such as consent or contract performance) to process personal data uploaded to the platform.
- Obtain and safeguard image rights and necessary privacy authorizations from all identifiable persons in videos, paying special attention to regulations on minors.
- Hold Nextaur harmless from any third-party claim or administrative penalty arising from the Controller's lack of legal basis for processing data uploaded to the service.