Privacy Policy
This policy explains how NEXT EDGE LABS LTD handles personal data across every product we build. It is written to be read, not to be survived. If anything in it is unclear, email hello@nextedge.dev and we will explain it.
- Who we are
- What this policy covers
- The two roles we play
- Data we hold as controller
- Why we use it, and our lawful basis
- Data we process for our customers
- Who else is involved
- Where your data is stored
- Transfers outside the UK
- How long we keep things
- How we keep it safe
- Your rights
- Cookies and similar storage
- Children and young people
- Changes to this policy
- Contact and complaints
01Who we are
NEXT EDGE LABS LTD ("Next Edge Labs", "we", "us", "our") is a company registered in England and Wales, company number 12408102, with its registered office in London SE23 2PS. Our VAT number is GB473996724.
We are the data controller for the personal data described in section 4, and a data processor for the personal data described in section 6.
For anything to do with this policy or your personal data, contact us at hello@nextedge.dev.
02What this policy covers
This policy covers the website at nextedge.dev and every product we operate. Each of the following is a product of NEXT EDGE LABS LTD:
| Product | Where it lives | What it does |
|---|---|---|
| Opsly | opslytech.com | Hospitality and retail operations: stock, production, people, compliance and forecasting |
| Checkly | checkly-app.com | Food safety and compliance records |
| Scoutly | scoutly-app.com | Site selection and location analysis |
| 2cents | 2cents-app.com | Guest feedback, reviews and reputation |
| Opsriva | opsriva.co.uk | Field service management for trades |
Where a product publishes its own privacy notice, that notice gives the product-specific detail and this policy gives the company-level position. If the two ever conflict, this policy governs the identity of the controller and the contact route, and the product notice governs the product detail.
03The two roles we play
This is the most important section, because the answer to "who do I ask about my data" depends on it.
We are the controller for our own customer relationships
When a business signs up, we decide what account, billing, support and website data we need in order to run the service and get paid. For that data we are the controller. Section 4 covers it.
We are a processor for everything our customers put into the products
Our products are tools that businesses use to run their own operations. When a bakery records its staff rota, or a restaurant logs a guest complaint, that business decides what to collect and why. They are the controller. We hold and process it on their instructions under our agreement with them. Section 6 covers it.
If you are an employee, a guest or a customer of one of our customers and you want to see, correct or delete your data, your first contact is that business, not us. They control the data and they can act on it directly. If you contact us instead, we will tell you and, where we can identify the business, help them respond. We cannot act on their data without their instruction.
04Data we hold as controller
- Account data. Your name, work email address, business name, job title, and a securely hashed password. We never store passwords in a readable form.
- Billing data. Your plan, number of sites, invoices, and payment status. Card details are handled entirely by Stripe. We do not see, receive or store card numbers.
- Usage data. Which pages and features are used, device and browser type, and IP address. We use this to keep the service secure and to understand which features earn their place.
- Support data. Messages, tickets, screenshots and attachments you send us, and our replies.
- Business contact data. Contact details for people at businesses who ask about our products, book a demo, or who we approach about them.
We do not sell, rent or trade personal data. We have never done so and we do not plan to.
05Why we use it, and our lawful basis
| What we do | Lawful basis |
|---|---|
| Provide and run the products you have subscribed to | Performance of a contract |
| Take payment and keep accounting records | Contract, and legal obligation |
| Answer support requests | Contract, and our legitimate interest in supporting customers |
| Keep the service secure, prevent fraud and investigate misuse | Our legitimate interest in protecting the service and its users |
| Understand which features are used, and improve them | Our legitimate interest in building a product that works |
| Tell existing customers about changes to a product they use | Our legitimate interest in keeping customers informed |
| Market our products to business contacts | Our legitimate interest in business-to-business marketing, or your consent where the law requires it |
| Send alerts by WhatsApp, email or push notification | Your consent, recorded with the date you gave it |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and you can object at any time using the contact details in section 16.
Marketing messages always carry a way to stop them, and we act on it. If you are a sole trader or a partnership rather than a limited company, we treat you as an individual for marketing purposes and ask for consent first.
06Data we process for our customers
Our customers use the products to record information about their own people and operations. Depending on the product and how they use it, that can include:
- Employee records. Names, contact details, job titles, contracts, pay rates, right to work documents, training and certification records, attendance and clock-in times, leave and absence, performance and disciplinary notes.
- Compliance records. Food safety checks, temperature readings, incident and accident reports, and the name of the person who completed each one.
- Guest and customer data. Bookings, orders, loyalty records, reviews and feedback, and anything a guest writes in a review, including the names of staff they mention.
- Operational data. Suppliers, deliveries, stock, recipes, production plans, sales and financial figures.
Some of this is special category data. A right to work document can reveal nationality, and a sickness absence record is health data. Our customers decide to collect it as employers, and they are responsible for having a lawful basis and an appropriate condition for doing so. We hold it securely and use it only to run the product for them.
We do not use customer content for our own purposes. We do not read it except where it is necessary to provide support that a customer has asked for, to investigate a security problem, or where the law requires it. We do not use it to train artificial intelligence models for anyone else's benefit.
07Who else is involved
We use a small number of suppliers to run the products. Each is bound by a contract that limits them to acting on our instructions.
| Supplier | What they do for us | Where |
|---|---|---|
| Supabase | Database, sign-in and file storage. This is the primary store for customer data. | United Kingdom (London) |
| Vercel | Application hosting and delivery | United States, configured to run in London |
| Stripe | Subscription payments and card handling | United States and EEA |
| Anthropic, OpenAI | Artificial intelligence features such as document drafting and analysis | United States |
| Resend, Brevo | Sending service and notification email | United States, and EEA |
| Microsoft | Our own company email, and the Teams integration where a customer enables it | United Kingdom and EEA |
| Maps, place and location data, sign-in, and Business Profile where a customer connects it | United States | |
| Meta | WhatsApp Business messaging, and Instagram publishing where a customer connects it | United States and Ireland |
Integrations a customer chooses to connect
Several products can connect to systems our customers already use. Data moves to or from those systems only when a customer connects them, and their own privacy terms then apply to their side of it. These currently include Square, Deliveroo, Xero, Slerp, SumUp, Zettle, LinkedIn, BigChange, Companies House and OpenStreetMap.
Other disclosures
We may also share data with our professional advisers, such as our accountant and our lawyers, where they need it to advise us; with authorities where the law requires it; and with a buyer if the business or a product is ever sold, in which case we will tell affected customers first.
08Where your data is stored
The primary store for customer data is a database hosted in the United Kingdom, in Supabase's London region. Our applications are configured to run in Vercel's London region.
Some of the suppliers listed in section 7 are based outside the UK and will process data in other countries. Section 9 explains how we handle that.
09Transfers outside the UK
Where a supplier processes personal data outside the United Kingdom, principally in the United States, we rely on one or more of the following: an adequacy decision made by the UK government, the UK extension to the EU Standard Contractual Clauses (the UK Addendum), or the UK-US Data Bridge where the supplier is certified under it. In each case the supplier is contractually bound to protect the data to UK standards.
You can ask us for details of the safeguards that apply to a particular supplier.
10How long we keep things
| What | How long |
|---|---|
| Customer content held on a customer's behalf | For as long as their agreement runs. After it ends we delete or return it in line with that agreement. |
| Account and billing records | Seven years after the relationship ends, because tax and company law require us to keep accounting records. |
| Support conversations | Three years, so we can see the history of an issue. |
| Security and access logs | Twelve months. |
| Business contact data for marketing | Until you ask us to stop, or until it has been clear for two years that there is no interest. |
11How we keep it safe
- Data is encrypted in transit and at rest.
- Every table that holds customer data is protected by row-level security, so one customer's data cannot be read by another. We run automated checks against the live database that fail loudly if a gap appears.
- Access to live customer data is limited to named people who need it, and is logged.
- Passwords are stored hashed. We can never read yours.
- Access tokens for connected systems are encrypted before they are stored.
- We run automated security and data-integrity checks continuously, and before every release.
No system is perfect. If we ever discover a breach that puts your rights at risk, we will tell you and the Information Commissioner's Office within the time the law allows, and we will tell you what we know rather than waiting until we know everything.
12Your rights
Under UK data protection law you have the right to:
- ask what personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have data erased, in some circumstances;
- restrict how we use it, in some circumstances;
- receive data you gave us in a portable format;
- object to processing we carry out on the basis of legitimate interests, including direct marketing; and
- withdraw consent at any time, where consent is what we relied on.
Email hello@nextedge.dev to use any of these. We will respond within one month. We will not charge you, and we will not ask why.
If your data is held in one of our products by a business that uses us, see the note in section 3: they are the controller and you should ask them.
13Cookies and similar storage
We use cookies and similar browser storage for a small number of things:
- Signing you in and keeping you signed in. These are essential. The products do not work without them.
- Remembering your preferences, such as your chosen theme, site or filter.
- Understanding which features are used, so we know what to improve.
We do not use advertising cookies, and we do not allow third parties to track you across other websites from our products. You can block cookies in your browser, but the products will not be able to sign you in if you do.
14Children and young people
Our products are sold to businesses and are not intended for children. We do not knowingly collect personal data directly from anyone under 16.
Hospitality employs young people, so a customer may hold employment records in our products for staff aged 16 or 17. That is their decision as an employer and their responsibility as controller. We hold those records to the same standard as any other.
15Changes to this policy
When we change this policy we will update the date at the top. If a change materially affects your rights or how we use your data, we will tell customers directly rather than relying on you noticing.
16Contact and complaints
Email hello@nextedge.dev, or write to NEXT EDGE LABS LTD, London SE23 2PS, United Kingdom.
If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the UK regulator:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk/make-a-complaint · 0303 123 1113