NEWThe Nextfirma customer portal is launching soon.Reserve access →
Privacy at Nextfirma

Privacy.
Clearly explained.

What data we process, why we need it and which rights you have — explained clearly and transparently.

Deutsche Fassung →
01
EU core infrastructureCustomer data in EU regions
02
No advertising trackingCurrently no analytics or Meta Pixel
03
Forms after approvalPipedrive loads only after your click
Applies tonextfirma.com
Updated20 August 2026

1. Controller and EU representative

The controller under the General Data Protection Regulation (GDPR) is:

NEXTFIRMA L.L.C FZ
Meydan Grandstand, 6th Floor
Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates

Authorised representative: Stefanie Sanders
Privacy contact: datenschutz@nextfirma.com

Representative in the European Union under Article 27 GDPR:

Alsterstein UG (haftungsbeschränkt)
Anckelmannstr. 15
20537 Hamburg, Germany

2. Purposes, data categories and legal bases

We process personal data only where necessary to operate the website, respond to enquiries, take steps before entering into and performing contracts, process payments, provide the portal or comply with legal obligations.

Depending on the process, this may include identity and contact data, company and case data, communications, contract and payment data, uploaded documents, and technical usage and log data.

The main legal bases are Article 6(1)(a) GDPR (consent), Article 6(1)(b) GDPR (pre-contractual steps and contract), Article 6(1)(c) GDPR (legal obligations) and Article 6(1)(f) GDPR (legitimate interests in secure and efficient operations and communications).

3. Website operation, hosting and security logs

The website is delivered using Cloudflare infrastructure. When you visit, data such as IP address, date and time, requested URL, referrer, browser and device details, security events and error information may be processed.

This processing is necessary to deliver and secure the website and diagnose errors. It is based on Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our online services.

More information: Cloudflare Privacy Policy ↗

4. EU data infrastructure and international transfers

Under our current configuration, core databases for customer and platform processes are hosted in European Union regions. This does not mean that every technical processing operation takes place exclusively within the EU.

Cloudflare operates a global network, and Pipedrive, Stripe, WhatsApp/Meta and other providers may process data outside the EEA. Where required, transfers rely on adequacy decisions, the EU-U.S. Data Privacy Framework or Standard Contractual Clauses under Article 46 GDPR, together with supplementary safeguards.

5. Contact forms and CRM – Pipedrive

We use Pipedrive for enquiries and portal registrations. Embedded forms are loaded only after you actively choose to load them. No connection to the form provider is established beforehand.

Loading may transmit technical data such as your IP address, browser information and cookies. When you submit the form, we process the contact details, company information, enquiry and other content you provide to respond and assign the request in our CRM.

Loading the external form is based on consent under Article 6(1)(a) GDPR and, where device information is accessed, section 25 TDDDG. The subsequent handling of your enquiry is based on Article 6(1)(b) or (f) GDPR. The loading choice is not stored permanently.

More information: Pipedrive Privacy Notice ↗

6. Portal, customer account and service delivery

When you register, use the portal or place an order, we may process contact and account data, company and shareholder information, case data, documents, status information, appointments, communications and payment data.

Processing is necessary to create and secure the account, prepare and perform the relevant service, document approvals and coordinate partners. The legal bases are Article 6(1)(b), (c) and (f) GDPR.

7. Payments – Stripe and bank transfer

If you open a Stripe payment page or pay through Stripe, Stripe processes the identification, device, payment and transaction data needed for the payment. Nextfirma generally receives the payment status, amount, reference and limited payment details, but not your full card or bank account information.

The legal bases are Article 6(1)(b) and (c) GDPR. For bank transfers, the participating banks process the required payment data under their own responsibility.

More information: Stripe Privacy Policy ↗

8. WhatsApp and external links

A connection to WhatsApp is established only after you click a WhatsApp link. From that point, WhatsApp or Meta Platforms Ireland Limited processes data under its own terms. This may include telephone number, profile information, communications and technical data.

You initiate this communication. Processing by us is based on Article 6(1)(b) or (f) GDPR. You may use telephone, email or our contact form instead.

More information: WhatsApp Privacy Policy – EEA ↗

9. Service providers, professional partners and recipients

We use selected providers for hosting, databases, CRM, communications, email, document processing and payments. Processors are appointed under Article 28 GDPR where required.

Notaries, lawyers, tax advisers, banks, financing partners, public authorities and other authorised bodies may receive data where necessary for your requested process, contractually intended, approved by you or legally required. For their regulated professional work, these recipients generally act under their own responsibility.

10. Cookies, analytics and advertising

The current website does not use our own analytics or advertising trackers such as Google Analytics or Meta Pixel. The hosting provider may use technically necessary security identifiers.

After your active approval, external Pipedrive forms may use their own cookies or similar technologies. If analytics or marketing services are added in the future, they will be activated only after any required consent and this notice will be updated.

11. Retention

We retain personal data only for as long as necessary for the relevant purpose. Enquiry data is deleted or anonymised when there is no further business relationship and no retention or evidence obligation applies.

Contract, billing and business records are retained for the periods required by applicable law. Data may also be retained where needed to establish, exercise or defend legal claims.

12. Your rights

Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, portability and objection. You may withdraw consent at any time with effect for the future.

Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without giving specific reasons.

You may also lodge a complaint with a competent data protection authority, particularly in the EU Member State of your habitual residence, place of work or the alleged infringement. To exercise your rights, contact datenschutz@nextfirma.com or our EU representative.

13. Required data and automated decisions

Certain data is required where necessary for an enquiry, registration, payment or performance of a contract. Without it, the relevant process may not be available.

This website does not make solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR.

14. Updates to this privacy notice

We update this notice when services, processes or legal requirements change. The version published on this page applies. Last updated: 20 August 2026.