(Privacy policy)

Privacy policy.

What we collect when you use this site or hire us, why we hold it, who else sees it, and how you get it back or get it deleted.

Last updated: Draft — not yet published

Draft — not binding. What follows is an outline of what each clause will cover, not the clauses themselves. The finished document is with counsel; until it is published here, nothing on this page forms part of an agreement. Questions in the meantime: info@thenexcraft.com.

(01)

Who we are

Identify the data controller: registered business name, address and contact address for privacy requests. Under GDPR this has to be a real, monitored route, not a generic inbox that nobody owns.

State whether an EU representative or a Data Protection Officer is required and, if so, name them. NexCRAFT is established in India and serves EU clients, so Article 27 representation needs checking.

(02)

What we collect

List the categories actually collected. On this site that is the estimate form: name, email, optional company, optional phone, and the project details, budget range and timeline the visitor selects. Note that no account is created and no payment details are taken through the site.

Cover anything collected automatically — server logs, IP address, and any analytics — and confirm what is and is not enabled in production before this page is published.

(03)

Why we hold it, and for how long

State the lawful basis for each purpose: responding to an enquiry, quoting for work, performing a contract, and any marketing follow-up. Marketing needs its own basis and, in most of the EU, its own opt-in.

Give a concrete retention period for each category rather than 'as long as necessary' — how long an unconverted enquiry is kept, and how long client project records are kept after an engagement ends.

(04)

Who else sees it

List the processors and sub-processors that handle personal data: hosting, form or email delivery, CRM, and any automation platform an enquiry passes through. Each needs a data processing agreement in place before this page goes live.

Cover international transfers. Data reaching a team in India from EU visitors is a transfer out of the EEA and needs a stated safeguard — Standard Contractual Clauses or equivalent.

Confirm that personal data is never sold, and state the narrow circumstances in which it would be disclosed (legal obligation, or a business transfer).

(05)

Cookies and tracking

Describe exactly what this site sets. Audit this before publishing: the site currently ships no analytics or advertising tags, and if that is still true at launch this section should say so plainly rather than describing cookies that do not exist.

If any non-essential cookie or tracker is added later, a consent banner meeting EU requirements has to ship with it — consent before the tag fires, and refusal as easy as acceptance. Record that decision here.

(06)

Your rights

Set out the GDPR rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. State how a request is made, how identity is verified, and the response deadline (one month under GDPR).

Name the supervisory authority a visitor can complain to, and add the equivalent rights notice for any US state law that applies to the client base.

(07)

Security and contact

Describe the safeguards in place — encryption in transit, access control, and who internally can read enquiry submissions — without overstating them. Cover the breach-notification commitment and its timeframe.

Give the contact route for privacy questions and requests, and state how changes to this policy are communicated.