Dokumen ini hanya tersedia dalam bahasa Inggris.
Privacy Policy
This Privacy Policy explains how we collect, use, share, and protect personal information when you visit nextbasket.com and contact us through this website. We serve customers globally, including in the United States. This policy addresses US state privacy laws — starting with the California Consumer Privacy Act, as amended by the CPRA (together, the "CCPA") — and, because our operating company is established in the Netherlands, the EU General Data Protection Regulation (GDPR).
Effective date: 23 July 2026
Document version: Version 1.0 — effective 23 July 2026
1. Who we are (the business / data controller)
The business responsible for your personal information under this policy — the "controller" under the GDPR and the "business" under the CCPA — is Next Basket Platform B.V. (trading as NEXT BASKET AI), a Besloten Vennootschap (B.V.) — a private limited company under the laws of the Netherlands. We have not established that the CCPA or another US state privacy law applies to us by its thresholds, and publishing this policy is not an admission that any such statute applies. As a voluntary baseline we extend the core rights described here — access, correction, and deletion — to California and other US residents wherever reasonably possible.
- Legal entity
- Next Basket Platform B.V.
- Brand
- NEXT BASKET AI is a trade name of Next Basket Platform B.V.
- Registered office
- Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands
- Company register
- Netherlands Chamber of Commerce (Kamer van Koophandel, KVK), no. 84479493
- General contact
- office@nextbasket.com
- Data protection / privacy contact
- privacy@nextbasket.com — dedicated privacy / data-protection intake, monitored by our Privacy & Compliance Lead. No individual is publicly designated as a statutory Data Protection Officer at this stage, and no GDPR Article 27 EU representative is required because the controller is established in the Netherlands.
2. Scope of this policy
This policy covers personal information processed through the nextbasket.com marketing website — the pages you browse here and the enquiry, demo-request, and newsletter forms you may submit. Our audience is primarily businesses, but our forms may be used by individuals, so this policy is written to protect individuals as well.
The NEXT BASKET AI merchant platform (used by store operators at my.nextbasket.shop) and the personal information of shoppers on stores we host for merchants are governed by separate agreements. Where we host a merchant’s store, the merchant is the controller/business and we act as its processor/service provider.
For the marketing website, Next Basket Platform B.V. is the controller (business) for visitor, lead, and newsletter data. For the merchant platform, the merchant is the controller (business) for its shopper and merchant-customer data, and we act as its processor (service provider) under our Data Processing Addendum — except for our own account, security, billing, and legal-compliance data, for which we act as controller.
3. What personal information we collect
- Contact and enquiry data you submit through our forms: your name, work email, company/store name, phone number (optional), and the content of your message.
- Newsletter data: your email address, when you subscribe.
- Technical data collected automatically: your IP address and standard request metadata (used for security, rate-limiting, and abuse prevention).
- Analytics data (only when analytics is enabled for the build): pseudonymous usage data such as pages viewed and approximate, IP-derived location, via Google Analytics 4. This runs in a cookieless mode — it sets no cookies, stores nothing on your device, anonymizes your IP, and its events never carry your form data.
We do not ask for sensitive or special-category data (for example government IDs, precise geolocation, health, biometric, racial, religious, or political data) through this website, and we ask that you do not include such data in free-text message fields.
4. Why we process your data, and (for the EEA/UK) our legal bases
Purpose, data used, and — for EEA/UK visitors — the GDPR Article 6 legal basis
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Respond to enquiries, demo requests, and quotes | Name, email, company, phone, message | Steps at your request prior to a contract (Art. 6(1)(b)); consent (Art. 6(1)(a)) |
| Send the newsletter / marketing you subscribed to | Email address | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Security, anti-spam, and abuse prevention | IP address, request metadata, Turnstile signal | Legitimate interests in protecting our service (Art. 6(1)(f)) |
| Measure and improve the website (cookieless analytics) | Pseudonymous, cookieless usage data (GA4), when enabled | Legitimate interests (Art. 6(1)(f)) — GA4 runs cookieless with no device storage and advertising features disabled, so limited measurement relies on legitimate interests, not consent |
Because our analytics is configured with no analytics cookies or device storage, advertising features disabled, no form data in events, and IP protections, we rely on legitimate interests for this limited measurement rather than consent. If we ever introduce non-essential storage, an advertising feature, a user identifier, or cross-site tracking, it will stay disabled until prior consent and the necessary consent controls are in place.
In all of this processing we follow the data-protection principles of GDPR Art. 5: we process personal data lawfully, fairly, and transparently; collect it only for the specific purposes set out above and do not further process it in a way incompatible with those purposes; limit it to what those purposes require (data minimisation); keep it accurate and up to date; store it no longer than the retention periods in this policy; and protect its integrity and confidentiality with appropriate security measures — and we remain accountable for demonstrating all of this.
5. Who we share data with (recipients, processors / service providers)
We do not sell your personal information for money. We disclose it only to the service providers (processors) that help us run this website and respond to you, each under a data processing / service-provider agreement and only for the purposes above. See the California and other-state sections below for how "sale" and "sharing" are defined under US law and the choices you have.
Service providers / sub-processors used for this website
| Recipient | Role | Data shared | Location | Transfer safeguard |
|---|---|---|---|---|
| Odoo | CRM — stores and manages your enquiry as a lead | Name, email, company, phone, message | European Economic Area | Processed within the EEA — no third-country transfer requiring safeguards |
| HubSpot | CRM synchronisation, where enabled | Name, email, company, phone, message | European Economic Area / United States | Data-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate |
| Resend | Transactional email — delivers our notification and response emails (Brevo is not used) | Email address and message metadata | United States | Data-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate |
| Cloudflare | CDN, edge hosting, and Turnstile anti-bot protection | IP address, request metadata, Turnstile challenge data | Global edge network | Data-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate |
| Fly.io | Hosting for the backend that receives form submissions | All submitted form data in transit and at rest | European Economic Area (primary application region, where configured) | Data-processing agreement and EU Standard Contractual Clauses for any processing outside the EEA, with supplementary measures where appropriate |
| Google (Analytics 4) | Website analytics — only when enabled; cookieless mode | Pseudonymous, cookieless usage data; no form data | European Economic Area / United States | Data-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate |
| Stripe | Payment processing (platform checkout / subscriptions) — PCI DSS Level 1 | Payment/card and billing data — handled by Stripe, not stored by us | European Economic Area / United States | Data-processing agreement and EU Standard Contractual Clauses, with supplementary measures where appropriate |
We may also disclose personal information when required by law, to enforce our terms, to protect our rights, users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will require the recipient to honor this policy).
Our current service providers for this website are Cloudflare (CDN, WAF, and Turnstile anti-bot), Fly.io (hosting for the form backend), Resend (transactional email; Brevo is not used), Odoo (CRM and lead management) and HubSpot (CRM synchronisation, where enabled), Google Analytics 4 (only when analytics is enabled in production), and Stripe (only for platform checkout and subscriptions, not for this marketing website). Processing may take place in the European Economic Area, the United States, or globally, as shown in the table above.
6. International data transfers
Some providers above may process personal information outside the European Economic Area (for example in the United States). Where that happens, we rely on the provider’s executed data-processing agreement and the European Commission’s Standard Contractual Clauses, together with supplementary security measures where appropriate. We do not rely on a generic "SCCs and/or Data Privacy Framework" statement: a provider’s EU–US Data Privacy Framework certification is cited only where we have verified it against the current DPF registry.
For each provider that processes personal information outside the EEA, the mechanism we rely on is that provider’s data-processing agreement and the EU Standard Contractual Clauses, with supplementary measures where appropriate. Where a provider processes only within the EEA, no third-country transfer safeguard is required.
7. How long we keep your data
We keep personal information only for as long as necessary for the purposes described above, and then delete or anonymise it. We determine retention by the type of data, why we hold it, and any legal obligation to keep it.
Retention schedule by data category.
| Data category | Retention | What sets the period |
|---|---|---|
| Enquiry / lead records (name, email, company, phone, message) | 24 months after the last meaningful contact, then deletion or anonymisation — unless the record is converted into a customer record. | Sales follow-up need and applicable limitation periods; owner-set 24-month follow-up window. |
| Newsletter subscription (email) | Until you unsubscribe; minimal consent and suppression evidence is then retained for 5 years. | Your consent — kept until withdrawn; a minimal post-unsubscribe suppression record proves the opt-out and honours it. |
| Marketing-consent record (proof the checkbox was ticked + wording version) | 5 years (retained with the newsletter consent / suppression evidence). | Accountability under GDPR Art. 7(1) and CAN-SPAM — evidence of what consent was given, in which wording, and when. |
| Security / IP / request logs | Ordinary logs: 90 days, then deletion. Incident-specific records: retained up to 12 months. | Fraud- and abuse-prevention need; the shortest window that still lets us investigate incidents. |
| Cookieless analytics data (GA4, when enabled) | 14 months, then automatic expiry (the GA4 data-retention maximum). | The GA4 data-retention configuration, set to 14 months; GA4 expires events automatically at that horizon. |
| Privacy-request records (verification and handling of your request) | 3 years. | Proof that we received, verified, and responded to your request, as our accountability obligations require. |
| Contracts, invoices, and tax / accounting records | 7 years, or the applicable statutory period where longer. | Mandatory retention under Dutch tax and accounting law and equivalent obligations. |
Where a legal obligation requires us to keep certain records for longer — for example contracts, invoices, and tax or accounting records — we retain those records for the applicable statutory period and then delete them.
8. Your California privacy rights (CCPA/CPRA)
This section applies to California residents and supplements the rest of this policy. It uses terms defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
Categories of personal information (Cal. Civ. Code § 1798.140) — collected in the last 12 months
| Statutory category | Examples | Collected on this site? |
|---|---|---|
| A. Identifiers | Name, work email, phone number, IP address, online identifiers | Yes |
| B. Customer records (§ 1798.80(e)) | Name, phone number (and any address you provide) | Yes |
| C. Protected classifications | Age, sex, race, etc. | No — not collected |
| D. Commercial information | Records of products/services you enquired about or requested a demo of | Yes (limited) |
| E. Biometric information | Fingerprints, faceprints, etc. | No |
| F. Internet / network activity | Pages viewed and interactions, via cookieless analytics (only when enabled) | Yes (limited) |
| G. Geolocation data | Approximate, IP-derived location — NOT precise geolocation | Yes (approximate only) |
| H. Sensory data | Audio, visual, thermal | No |
| I. Professional / employment information | Company/store name; that you contact us in a business capacity | Yes |
| J. Education information | Education records | No |
| K. Inferences | Profiles drawn from the above | No — we do not draw inferences or profiles from this data |
| Sensitive personal information (§ 1798.140(ae)) | Government IDs, precise geolocation, account log-ins, contents of private messages, etc. | No — not intentionally collected; do not submit it in free-text fields |
Sources. We collect personal information directly from you (when you complete a form), automatically from your device and our servers (IP and request metadata, cookieless analytics), and from our service providers (for example our anti-bot provider).
Business and commercial purposes. We use the categories above to respond to your enquiries and provide requested information or demos; to secure the site and prevent fraud and abuse; to measure and improve the site; to send communications you asked for; and to comply with law. We do not use sensitive personal information to infer characteristics.
Sale and sharing. We do not sell your personal information for monetary consideration, and we do not "share" it for cross-context behavioral advertising (we run no advertising or ad-personalization technologies — our analytics is cookieless with ad features disabled). We do not sell or share the personal information of consumers we know to be under 16. Even so, we offer a privacy-choice request route — see the "Your Privacy Choices" section below.
We have not established that we meet the CCPA applicability thresholds, and this policy is written to comply as a precaution regardless of whether the statute strictly applies. We do not sell personal information, and we do not share it for cross-context behavioural advertising: this website runs no advertising or ad-personalisation technologies, and its analytics is cookieless with advertising features disabled.
Your California rights. Subject to the CCPA’s conditions, you have the right to:
- Know / access — the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of recipients (12-month lookback).
- Delete — the personal information we collected from you, subject to legal exceptions.
- Correct — inaccurate personal information we hold about you.
- Opt out of sale/sharing — direct us not to sell or share your personal information (see "Your choices").
- Limit use of sensitive personal information — although we do not collect sensitive personal information to infer characteristics.
- Non-discrimination — we will not discriminate or retaliate against you for exercising these rights.
How to exercise. Submit a request by emailing privacy@nextbasket.com (subject line "California Privacy Request"). We will verify your identity by matching the information you give us against our records, and may ask for additional information to confirm you are the person the data relates to (or their authorized agent). We will respond within the timeframes the CCPA requires.
Authorized agents. You may use an authorized agent to submit a request. We may require the agent to provide proof of your written permission and may still verify your identity directly.
Financial incentives. We do not offer financial incentives or price/service differences in exchange for your personal information.
California "Shine the Light" (Civ. Code § 1798.83). We do not disclose personal information to third parties for those third parties’ own direct-marketing purposes.
Request methods. You may submit a California privacy request by email as described above; we may add a webform, but a webform is not a condition of making a request. Because we operate online and B2B, email is our primary channel and we do not designate a US toll-free privacy line. We verify your identity proportionately using information we already hold and do not ask for a government ID unless strictly necessary.
Categories in the last 12 months. Collected: identifiers and contact data; professional and company data; limited commercial enquiry data; IP and request-security data; and limited website-usage data when analytics is enabled. Disclosed for business purposes: to our hosting, security, CRM, communications, analytics, and payment providers, as applicable. Sold: none. Shared for cross-context behavioural advertising or targeted advertising: none. Sensitive personal information is not intentionally collected through this marketing website.
9. Other US state privacy rights
If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), or another US state with a comprehensive consumer-privacy law (as such laws take effect), you have rights that mirror those above, subject to each law’s conditions:
- Confirm whether we process your personal data and access it.
- Correct inaccuracies in your personal data.
- Delete personal data we hold about you.
- Obtain a portable copy of personal data you provided.
- Opt out of (a) targeted advertising, (b) the sale of personal data, and (c) certain profiling with significant effects — noting we do not sell personal data, do not conduct targeted advertising, and do not carry out such profiling through this website.
To exercise these rights, email privacy@nextbasket.com. If we decline your request, you may appeal by replying to our decision; we will respond to the appeal within the period your state law allows and, if we still decline, tell you how to contact your state Attorney General. You may exercise these rights free of charge, and we will not discriminate against you for doing so.
10. Your Privacy Choices
As explained above, we do not sell your personal information and do not share it for cross-context behavioural advertising or targeted advertising. Because there is no sale or share to opt out of, we do not publish a "Do Not Sell or Share" toggle; instead, to make your choice easy to exercise, we offer the privacy-choice request route below.
- Your Privacy Choices — email privacy@nextbasket.com with the subject "Privacy Choice" and we will apply your preference.
- Universal opt-out signals — because we do not sell or share personal information or conduct targeted advertising, no browser-based opt-out signal (such as Global Privacy Control) is currently required to exercise a choice here, and we make no claim that such a signal is detected today. If our practices ever change, we will implement and honour recognised opt-out signals before doing so.
- Marketing email — use the unsubscribe link in any marketing email, or email us, to stop marketing messages (see the CAN-SPAM section).
Our current intake mechanism for a privacy choice is email; we may add a linked webform or a preference control in future. We do not present any browser-based opt-out signal as an implemented control unless and until it is technically detected and honoured.
11. Your rights (EEA / UK — GDPR)
If you are in the European Economic Area or the UK, then under the GDPR, and subject to its conditions, you have the right to:
- Access the personal data we hold about you (Art. 15).
- Have inaccurate data corrected (Art. 16).
- Have your data erased in certain circumstances (Art. 17).
- Restrict processing in certain circumstances (Art. 18).
- Be told which recipients we have disclosed your data to, where you asked us to correct, erase, or restrict it (Art. 19).
- Receive your data in a portable format (Art. 20).
- Object to processing based on our legitimate interests, and object at any time to processing for direct marketing — in which case we stop that processing for marketing purposes (Art. 21).
- Withdraw consent at any time, without affecting processing already carried out (Art. 7(3)).
To exercise any of these rights, contact us at privacy@nextbasket.com. You also have the right to lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
Our lead supervisory authority is the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority), because our controlling entity is established in the Netherlands. You may also complain to the supervisory authority in your own EEA country or, in the UK, the Information Commissioner’s Office, where that applies to you. To exercise any right, email privacy@nextbasket.com.
12. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal or similarly significant effects on you (GDPR Art. 22), and we do not conduct profiling with significant effects under US state laws, through this website. Our anti-bot check (Cloudflare Turnstile) scores requests to protect our forms from abuse; it does not make decisions about you as an individual.
This holds for all processing connected to this website: we do not draw inferences or behavioural profiles, and we do not use lead scoring or other automated processing to make legal or similarly significant decisions about you. Ordinary CRM prioritisation and our anti-bot and security scoring are not used to make consequential decisions about individuals. Any automated processing on the NEXT BASKET platform is governed by our platform terms.
13. Marketing emails (CAN-SPAM)
- Our marketing emails identify Next Basket Platform B.V. as the sender, use accurate "from" and subject lines, and include our postal address (Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands).
- Every marketing email includes a working unsubscribe link. You can also opt out by emailing us. We honor opt-out requests promptly (within 10 business days, as CAN-SPAM requires) and do not sell or transfer your address to others after you opt out.
- Transactional or relationship messages — for example, our reply to an enquiry you sent us — are not marketing and may still be sent after you opt out of marketing.
The postal address shown in our marketing-email footers is our Netherlands registered office (Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands). We do not currently designate a US postal address or US registered agent; US establishment is planned for a later phase.
14. Children’s privacy (COPPA)
This website and our services are directed to businesses and adults, not to children. We do not knowingly collect personal information from children under 13 (as defined by the US Children’s Online Privacy Protection Act, COPPA), and we do not knowingly sell or share the personal information of consumers under 16. If you believe a child has provided us personal information, please contact us and we will delete it.
15. Cookies and similar technologies
This website is designed to set no non-essential cookies. Only strictly necessary / security technologies (provided by Cloudflare) may be used, and our analytics runs in a cookieless mode. Details of each category are set out in our Cookie Policy.
16. How we protect your data
- Data is transmitted over encrypted connections (TLS/HTTPS).
- Form submissions are protected by anti-bot verification (Cloudflare Turnstile), per-IP rate limiting, and honeypot fields.
- Payment card data (on the platform) is handled by Stripe, a PCI DSS Level 1 certified provider; we do not store full card numbers.
- Access to lead data is limited to the people and systems that need it to respond to you, and the people authorised to process it are committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay, as the GDPR requires (Art. 33). Where the breach is likely to result in a high risk to you, we will also inform you without undue delay and describe the measures we have taken or propose to take (Art. 34) — unless an applicable exception applies, for example where the affected data was already protected by appropriate technical measures such as encryption, where we have since taken measures that make the high risk unlikely to materialise, or where individual notice would involve disproportionate effort (in which case we will make a public communication instead).
17. How to make a privacy request (our process)
You can exercise any of the rights described above — under the CCPA/CPRA, the other US state laws, or the GDPR — by contacting us. This section explains the single process we follow so every request is handled consistently, whichever law applies to you.
Where to send it. Email us at privacy@nextbasket.com with "Privacy Request" in the subject line, and tell us what you would like us to do (know/access, delete, correct, opt out, or receive a portable copy). Email is our live request route; we may add a web request form in future, but it is not required to make a request.
- Acknowledge — we confirm we received your request.
- Verify your identity — we match the details you give us against our records and may ask for limited additional information to confirm the request truly comes from you (or your authorized agent). We use that information only to verify the request.
- Respond within the legal deadline — for GDPR requests, within one month, extendable by up to two further months only for complex or numerous requests (we tell you within the first month if we need the extension); for US state requests we handle voluntarily, we target 45 days with one permitted extension, and any appeal response within 45 days where the applicable law allows. Where a specific law sets a different deadline, that statutory deadline controls.
- No charge, no retaliation — we handle requests free of charge, save for the narrow exceptions the law permits, and we never discriminate or retaliate against you for exercising a privacy right.
- Authorized agents — you may use an authorized agent; we may require proof of your written permission and may still verify your identity directly.
- If we decline — we tell you why and how to appeal: US state residents may appeal by replying to our decision (see our U.S. State Privacy Notice at /us-state-privacy-notice/) and may contact their state Attorney General; EEA/UK residents may complain to a supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
For the simplest choices — unsubscribing from marketing, or asking us not to sell or share your information (we do neither) — see Your Privacy Choices (/privacy-choices/). State-specific details are set out in our U.S. State Privacy Notice (/us-state-privacy-notice/).
Our live intake route is the privacy@nextbasket.com mailbox; a web request form may be added later. We verify your identity proportionately and document how we did so, and we follow the statutory response and appeal deadlines set out above for each applicable law.
18. AI training and use of your data
We are transparent about how personal information relates to our artificial-intelligence features. We do not use merchant content, shopper personal data, or website lead data to train general-purpose AI models unless the customer has expressly opted in through a separate written agreement.
This website itself runs no AI features on your enquiry data — your form submissions are used only to respond to you and for the purposes described in this policy. The AI features of the NEXT BASKET platform are governed by our AI Features Terms (/ai-terms/), which set out the no-training commitment above, the limits of AI output, and your controls.
We do not use website lead or newsletter data — or, on the platform, merchant content or shopper personal data — to train or fine-tune general-purpose AI models, unless the relevant customer gives a separate, explicit written opt-in. The platform’s AI Features run on our own in-house trained AI agents, so your data is not shared with third-party foundation-model vendors for training. If we ever engaged an external model provider for a feature, we would first configure its business or API terms so it does not use submitted data for general model training, and list it at /subprocessors/ before enablement.
19. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you.
20. How to contact us
If you have questions about this policy or how we handle your data, or to exercise any privacy right, contact Next Basket Platform B.V., Fascinatio Boulevard 216, 3065 WB Rotterdam, Netherlands, or email privacy@nextbasket.com.