Privacy Policy
Your privacy is important to us. Learn how we handle your data.
1. Introduction
NextSoftware ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services at nextsoftware.dev.
2. Data We Collect
We collect the following types of personal data:
- Account Information: Name, email address, and password when you create an account.
- Billing Information: Payment details are processed securely by our Merchant of Record, Paddle. We do not store credit card numbers on our servers.
- Usage Data: Download history, extension update checks, and support interactions.
- Technical Data: IP address, browser type, and Joomla version (collected during update checks).
- Newsletter Subscription: Email address and preferences when you subscribe to our newsletter.
3. How We Use Your Data
We use your personal data to:
- Process orders and deliver purchased extensions.
- Provide customer support and respond to inquiries.
- Send transactional emails (order confirmations, download links, license information).
- Validate Download IDs and manage extension updates.
- Improve our products based on aggregated usage analytics.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Cookies
Our website uses cookies to enhance your experience. The types of cookies we use include:
- Essential Cookies: Required for the site to function properly, including session management and authentication tokens. These cannot be disabled.
- Analytics Cookies: Help us understand how visitors interact with our website, including pages visited and time spent. This data is aggregated and anonymous.
- Preference Cookies: Remember your settings and preferences, such as language selection and display options, to provide a personalized experience.
You can control cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the website.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:
- Account Data: Retained while your account is active and for 2 years after account closure.
- Billing and Transaction Records: Retained for 7 years to comply with tax and accounting obligations.
- Server Logs: Automatically deleted after 90 days.
- Support Data: Support tickets and related correspondence are retained for the duration of your account plus 2 years.
You may request earlier deletion of your data by contacting us, subject to legal retention requirements.
6. Third-Party Services
We use the following third-party services that may process your data:
- Paddle: Paddle.com Market Ltd. acts as our Merchant of Record and handles all payment processing, subscription management, invoicing, tax calculation, and refunds. Paddle processes billing data in accordance with its own privacy policy, available at paddle.com/legal/privacy.
- Email Service Provider: Transactional and marketing email delivery, including order confirmations, license notifications, and newsletter communications.
Each third-party service has its own privacy policy governing how it handles your data. We encourage you to review those policies.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption: All data transmitted between your browser and our servers is encrypted using SSL/TLS protocols.
- Access Controls: Access to personal data is restricted to authorized personnel who require it to perform their duties.
- Security Audits: We conduct regular security reviews and audits of our systems and processes.
While we strive to protect your personal data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
8. International Data Transfers
Your personal data may be processed and stored in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your data in accordance with applicable data protection laws.
9. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your personal data.
- Right to Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to the processing of your personal data.
To exercise any of these rights, please contact us using the details below.
10. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will notify you by posting the updated policy on this page with a revised "Effective date". We encourage you to review this policy periodically.
12. Contact
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at [email protected].
Last updated: 2026-03-11