Privacy Policy

NEXTCAP platform — nextcap-pro.com

Last updated: April 23, 2026

This policy describes how HUMAN KNOWLEDGE - NEXTCAP, the publisher of the NEXTCAP platform, collects, uses, retains and protects your personal data in accordance with the European General Data Protection Regulation (Regulation EU 2016/679 — GDPR) and the French Data Protection Act.

An authoritative French version of this policy is available at /confidentialite. In case of interpretation conflict, the French version prevails.

1. Data controller

Personal data collected on the NEXTCAP platform is processed by:

HUMAN KNOWLEDGE - NEXTCAP

French simplified joint-stock company (SAS, société par actions simplifiée)

Registered office: 30, rue de Lattre de Tassigny, 67300 Schiltigheim-Strasbourg, France

SIREN: 890 798 317 — SIRET (head office): 890 798 317 00024

Trade & Companies Register: 890 798 317 R.C.S. Strasbourg — VAT: FR52890798317

Represented by: Bruno COURTIN, legal representative

Contact: contact@nextcap-pro.com

2. Data Protection Officer (DPO)

A Data Protection Officer has been appointed to oversee compliance and handle all requests relating to your rights.

DPO: Bruno COURTIN

DPO contact: dpo@nextcap-pro.com

Please include "GDPR" in the subject line for priority handling.

3. Categories of data collected

Depending on how you use the platform, we may collect:

  • Identity and account data: name, email, encrypted password, language preference.
  • Usage data: answers to the self-guided career modules, results, consolidated profiles, journey history, favourites, career hypotheses.
  • User-generated content: chats with the AI assistant, notes, files you upload (CV, experiences).
  • Sensitive data (where applicable): some specific modules deal with wellbeing, mental-health vigilance or personal situation. They are activated only with your prior explicit consent, given separately from general terms.
  • Payment data: email, price, currency, transaction identifiers. Card numbers are never stored on our servers; they are processed directly by our PCI-DSS certified payment provider.
  • Technical data: IP address, user-agent, timestamps, authentication logs, cookies strictly necessary for the session.

4. Purposes and legal bases

Each processing activity relies on an explicit legal basis, matched to its sensitivity. Our approach combines two complementary logics:

a) Standard career-guidance modules

Legal basis: performance of the contract you enter into with NEXTCAP (Article 6-1-b GDPR). Covers account management, running the guided journeys, producing career recommendations and syntheses, billing, security and support.

b) Sensitive modules or modules with significant profiling

Legal basis: explicit consent (Articles 6-1-a and 9-2-a GDPR). Applies to modules addressing mental health, wellbeing vigilance, vulnerability situations, or any processing that could produce significant effects on you. These modules are activated individually, their consent is separate from the acceptance of general terms, and you can withdraw this consent at any time without justification.

c) Legal obligations

Legal basis: compliance with legal obligations (Article 6-1-c GDPR) — retention of accounting records, fraud prevention, judicial requests.

d) Service improvement and security

Legal basis: legitimate interest (Article 6-1-f GDPR), balanced by minimisation safeguards — security logging, anomaly detection, anonymised usage statistics.

A more granular mapping of legal bases per module will be progressively published as the platform evolves.

5. Recipients and subprocessors

Your data is accessible only to authorised HUMAN KNOWLEDGE - NEXTCAP staff and a limited number of technical subprocessors, each bound by a data processing agreement compliant with Article 28 GDPR.

SubprocessorRoleLocation
MongoDB AtlasDatabase hostingParis, France (EU)
Emergent LabsApplication hostingEU / United States
CloudflareContent delivery, network protectionGlobal edge network
StripePayment processingIreland (EU) / United States
OpenAIConversational AIUnited States
AnthropicConversational AIUnited States
Google (Gemini)AI & translationEU / United States
AdzunaJob listings reference (anonymous queries)United Kingdom
EventbriteEvents reference (anonymous queries)United States

No personal data is sold or transferred to third parties for commercial purposes.

6. Transfers outside the European Union

Some technical subprocessors are established outside the European Union, mainly in the United States and the United Kingdom. To ensure an adequate level of protection, transfers rely on:

  • the Standard Contractual Clauses approved by the European Commission;
  • the European Commission's adequacy decision for the United Kingdom (UK-GDPR);
  • the security commitments set out in Article 28 GDPR (DPAs).

Regarding AI providers, prompts and outputs transmitted are subject to each provider's usage policy; we favour plans that guarantee no user data is used to train their models.

7. Retention periods

  • User account: for the duration of the account, then up to 3 years after the last activity if not deleted beforehand.
  • Career results and syntheses: 36 months from generation, unless earlier deletion is requested.
  • AI assistant conversations: 12 months, then anonymised or deleted.
  • Accounting records and transactions: 10 years (French Commercial Code Article L123-22).
  • Authentication logs: 12 months (security purpose, French CNIL recommendation).
  • Session and reset tokens: from 15 minutes to 7 days depending on the token type.

8. Security

We implement technical and organisational measures appropriate to the sensitivity of the data processed, pursuant to Article 32 GDPR:

  • TLS encryption on all network traffic;
  • at-rest encryption of the database;
  • cryptographic hashing of passwords (never stored in clear text);
  • role separation and logging of administrator access;
  • automated backups and disaster recovery plan;
  • documented data-breach notification procedure within 72 hours.

9. Automated decisions and profiling

The platform produces recommendations, syntheses and career suggestions based on the information you provide. These outputs are generated algorithmically but do not by themselves produce legal effects or significantly affect you: they are a decision-support tool which you remain free to use, ignore or challenge.

You may request an explanation of the logic applied, challenge a result, or request a new evaluation at any time.

10. Cookies and trackers

NEXTCAP uses only strictly necessary cookies for the platform to function:

  • session authentication token (HttpOnly, Secure);
  • refresh token (HttpOnly, Secure);
  • language preference (stored locally).

These cookies are exempted from prior consent under Article 82 of the French Data Protection Act (CNIL 2020 recommendation). We use no advertising tracker, no third-party behavioural analytics tool, and no embedded social network.

11. Your rights

Pursuant to Articles 15 to 22 of the GDPR, you have the following rights:

  • right of access to your data (Art. 15);
  • right to rectification of inaccurate data (Art. 16);
  • right to erasure ("right to be forgotten", Art. 17);
  • right to restriction of processing (Art. 18);
  • right to data portability — retrieval of your data in a structured, machine-readable format (Art. 20);
  • right to object to processing (Art. 21);
  • right to withdraw consent at any time, without affecting processing already performed (Art. 7-3);
  • right to set directives about the fate of your data after death (French Data Protection Act, Article 85).

To exercise your rights:

Email dpo@nextcap-pro.com with "GDPR" in the subject line. Proof of identity may be requested where reasonable doubt exists, per Article 12-6 GDPR. We reply within one month, potentially extended by two months for complex requests.

12. Lodging a complaint

If, after contacting us, you believe your rights are not respected, you may lodge a complaint with the French supervisory authority:

CNIL — 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07, France

www.cnil.fr/en

EU/EEA users may also lodge a complaint with the supervisory authority of their member state of residence.

13. Updates to this policy

This policy may be updated to reflect regulatory, technical or functional evolutions. Substantial changes will be communicated by email and/or a banner on the platform. The date of last update appears at the top of this document.