Legal · GDPR
Privacy Policy
How nextaisuite handles personal data under the GDPR, Lei n.º 58/2019 and the ePrivacy rules of Lei n.º 41/2004 — what we collect, why, for how long, and every right you can exercise.
Last updated: 5 October 2026
The 30-second version
- Your files are never uploaded or stored — browser tools process them on your device only.
- No accounts, no advertising, no cross-site trackers, no fingerprinting on this site.
- We measure search visibility with Google Search Console (aggregate, cookie-free for you) and — only if you accept in the cookie banner — Google Analytics 4 for page statistics. Rejecting changes nothing about how the site works.
- Everything is hosted in the EU; questions and data requests: [email protected].
Plain-language orientation — the numbered sections below are the complete, legally binding text.
1. Who we are (data controller)
The data controller for this website is:
We are established in the European Union (Portugal), so no representative under Art. 27 GDPR is required. We have not appointed a Data Protection Officer because our core processing — operating a website where user files never reach a server — does not meet the thresholds of Art. 37. All privacy requests can be sent to the address above.
2. Privacy by design (Art. 25)
What this means in practice
- Our tools run in your browser — files are never uploaded
- No accounts, no profiles, no advertising trackers
- The least possible data is collected, used, and kept
- All infrastructure is hosted inside the EU
3. Personal data we process and why
a) When you use the tools
Nothing. The files you open and the results you download are processed entirely on your device. We receive no file names, no file contents, and no document metadata. Using a tool does not require an account or any identifier.
Lawful basis: None — we process no personal data to give you the tools.
b) Technical access data (server & security logs)
Like any website, our servers temporarily record technical access information: IP address (truncated or anonymized where possible), browser and operating system, requested page, referring site, and timestamp. We use this only to operate and secure the site — for example, to block abuse and diagnose errors. We do not merge it with other datasets or use it for advertising.
Lawful basis: Art. 6(1)(f) GDPR — legitimate interest in providing a secure and stable website.
c) Website measurement
We understand how the site is found and used through two deliberately minimal channels. First, Google Search Console tells us which searches on Google led to our pages — it reports queries, impressions and clicks that Google itself observed in its own search results. Search Console sets no cookies on your device through our site, loads no scripts on our pages (we verify ownership with a plain meta tag), and never gives us individual browsing profiles — only aggregate statistics. Because Google LLC is based in the United States, this limited relationship relies on the EU–US Data Privacy Framework, described in Sections 7 and 8, and on Google's own Search Console terms and privacy notice.
Second, we use Google Analytics 4 for on-site page statistics. Nothing of it runs on your device unless you press “Accept analytics” in the cookie banner: until then no GA script loads and no analytics cookie is set. If you accept, Google sets a random client identifier (_ga) to count visits and page views per device, and we receive aggregate reports on which tools are used. We do not enable advertising features, cross-site ad tracking, or any linkage to other Google services, and GA4 does not log or store your IP address. Your choice is stored locally on your device (localStorage) and can be changed at any time — clear site data or use the banner controls described in the Cookie Policy to withdraw consent for future visits.
Lawful basis: Google Search Console: Art. 6(1)(f) GDPR — legitimate interest in understanding aggregate search visibility, under the strict conditions of Recital 47. Google Analytics 4: Art. 6(1)(a) GDPR — consent, freely given and withdrawable at any time (Art. 7(3)).
d) When you contact us
If you email us — for feedback, tool requests, support, or a data subject request — we process the content of your message, your email address, and anything you choose to share, in order to reply and keep a record of the exchange.
Lawful basis: Art. 6(1)(b) GDPR (pre-contractual steps at your request) and Art. 6(1)(f) GDPR (documenting our replies).
4. Your files are yours
Our image, PDF and other client-side tools use WebAssembly and native browser APIs. Your files travel from your disk to our page and never leave your device. There is no upload queue on our side, nothing to breach, and nothing we could lawfully disclose to a third party — because we never see it.
5. Future server-side and AI features
Some advanced features may eventually require server-side processing (for example, AI tools). When that happens, and only for those features: uploaded inputs will be processed transiently and auto-deleted after a documented short period; you will be told before the first upload; the lawful basis (usually consent or contract) will be stated; and any sub-processors will be published with data processing agreements. Core free tools will remain client-side.
Not active today
7. Who receives data
Personal data is only disclosed to processors we have contracted in writing under Art. 28 GDPR — currently our EU-based hosting provider, (for email) a European business-mail provider within the EU/EEA, and Google Ireland Limited / Google LLC as the operator of Google Search Console (aggregate search-performance reporting only) and, where you have consented, Google Analytics 4 (page statistics), as described in Section 3c. We never sell personal data, and we never provide it for advertising. Lawful requests from authorities are honoured only where legally compelled, and we will say so plainly here if our practice changes.
8. Transfers outside the EU/EEA
We host and process your content inside the EU/EEA. The one exception is Google: Google LLC is established in the United States and is certified under the EU–US Data Privacy Framework, which the European Commission found adequate on 10 July 2023 — that certification is our basis for this limited, aggregate measurement (Arts. 44–45 GDPR), covering Search Console and, for visitors who consented, Analytics. Should any future processor sit outside the EU/EEA, the transfer will rely on an adequacy decision or Standard Contractual Clauses with supplementary measures, and will be disclosed here and in our sub-processor list.
9. How long we keep data (Art. 5(1)(e))
| Data | Retention |
|---|---|
| Files you process with our tools | Never stored on our servers — processing happens on your device |
| Technical access logs (IP, browser, page, timestamp) | Deleted or anonymized within 30 days |
| Emails and data subject requests | Up to 12 months after the conversation ends |
| Google Analytics 4 event data (only after consent) | Google's default 2-month rolling retention; aggregates kept up to 26 months; no individual profiles |
| Theme and UI preferences | Stored only in your browser until you clear site data |
When a retention period ends, data is deleted or anonymized irreversibly.
10. Your rights as a data subject
Under the GDPR you have the rights below in relation to any personal data we hold. Because our tools hold no data about you, these rights mainly concern contact emails and requests you send us. They are free of charge, and we respond within 30 days (Art. 12(3)); we may ask you to prove your identity where there is reasonable doubt.
Access
Know what personal data we hold about you (Art. 15).
Rectification
Have inaccurate or incomplete data corrected (Art. 16).
Erasure
Have your personal data deleted — the right to be forgotten (Art. 17).
Restriction
Temporarily limit how your data is processed (Art. 18).
Portability
Receive your data in a structured, machine-readable format (Art. 20).
Objection
Object to processing based on legitimate interests (Art. 21).
Withdraw consent
Where processing is based on consent (Art. 6(1)(a)), withdraw it at any time (Art. 7(3)).
No automated decisions
We do not use automated decision-making or profiling as defined in Art. 22.
11. Right to lodge a complaint (Art. 77)
If you believe our processing violates the GDPR, you can complain to a supervisory authority — in particular the Comissão Nacional de Proteção de Dados (CNPD), the data protection authority of Portugal where we are established — or the authority of your EU/EEA member state of residence. We would, of course, appreciate the chance to fix things first: [email protected].
12. Security (Art. 32)
All traffic is encrypted in transit with TLS. Access to production infrastructure is restricted and secrets never live in source code. Logging of technical access data is configured to minimize identifiers, retention is short, and the client-side architecture itself is a security measure: data that never reaches a server cannot be exfiltrated from one.
13. Children
This service is not directed at children under 14 — the age set by Portuguese Law n.o 58/2019 (Art. 16) for consent to information society services. We do not knowingly collect personal data from children; if you believe a child has provided us personal data (for example, by emailing us), please contact us and we will delete it.
14. Changes to this policy
We may update this policy to reflect new features or legal changes. Material changes to how we process personal data will be announced on this page with a revised date well before taking effect, and — where you have given us contact details — by email.
15. Questions
Email [email protected] or use our contact page. You can also read our Terms of Service and Imprint.
This policy is provided for transparency under Arts. 13 and 14 GDPR and is not legal advice; a court of law prevails over any summary.