Privacy policy.
Last updated 21 July 2026
This notice explains how NextFluent Italia SRL (“NextFluent”, “we”) processes personal data collected through this website, in accordance with Regulation (EU) 2016/679 (GDPR), the Italian Codice in materia di protezione dei dati personali (D.lgs. 196/2003 as amended) and, for visitors in France, the Loi n° 78-17 Informatique et Libertés.
1. Data controller
NextFluent Italia SRL, registered office in Turin, Italy. Contact for any privacy matter: privacy@nextfluent.it. We have not appointed a Data Protection Officer as we are not required to do so under Art. 37 GDPR.
2. What we collect and why
- Contact form: full name, organisation, work email, role, the supply chain you mention and the content of your message. We process this to reply to your enquiry and, where relevant, to discuss a pilot or research collaboration.
- Email correspondence: if you write to us directly, we retain the message and the metadata your email client sends.
- Server logs: our hosting provider records the IP address, user agent and timestamp of each request for security and abuse-prevention purposes. We do not use these logs for analytics or profiling.
This site does not set analytics or advertising cookies and does not embed third-party trackers, so no cookie consent banner is required. Only strictly necessary technical state may be stored in your browser to render the site correctly.
3. Legal basis
- Contact form and email: your consent (Art. 6(1)(a) GDPR) and, where you write on behalf of an organisation, our legitimate interest in responding to business enquiries (Art. 6(1)(f)).
- Server logs: legitimate interest in securing the service (Art. 6(1)(f)).
4. Retention
Contact-form submissions and related correspondence are kept for up to 24 months from the last interaction, after which they are deleted or anonymised. Server logs are retained for up to 12 months. You can ask us to delete your data earlier at any time.
5. Recipients and processors
We rely on a small number of vendors that act as data processors on our behalf under Art. 28 GDPR: our website hosting provider, our email provider and, where applicable, a form-delivery service. All are bound by written data-processing agreements and are selected for their EU/EEA hosting or Standard Contractual Clauses coverage. A current list is available on request at privacy@nextfluent.it.
6. Transfers outside the EEA
We aim to keep personal data within the European Economic Area. Where a processor operates outside the EEA, transfers are covered by the European Commission's Standard Contractual Clauses and, where necessary, supplementary technical and organisational measures.
7. Your rights
You have the right to access, rectify, erase, restrict and object to the processing of your personal data, and to data portability. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise these rights, email privacy@nextfluent.it. You may also lodge a complaint with a supervisory authority: the Garante per la protezione dei dati personali in Italy (garanteprivacy.it) or the CNIL in France (cnil.fr).
8. Security
We apply reasonable technical and organisational measures to protect personal data, including transport encryption (HTTPS), access controls and vendor due diligence. No online service can be guaranteed absolutely secure.
9. Changes
We may update this notice as the service evolves. Material changes will be highlighted on this page with a new “last updated” date.