Next Mission
Labs

Privacy and data protection

Privacy policy

This privacy policy explains which personal data Next Mission Systems processes through nextmissionlab.com, why we process it, how long we keep it, and which rights you have.

Last updated: August 4, 2026

Who is responsible?

Next Mission Systems is responsible for processing personal data through the Next Mission Lab website. Next Mission Lab is a concept by Next Mission Systems.

You can reach us at support@nextmissionlabs.com or by post at Herengracht 124–128, Amsterdam, the Netherlands.

What information do we process?

When you visit the website, our hosting and security systems may process technical request information such as the IP address, requested URL, date and time, referring page, browser type, device category, and user agent. This information is necessary to provide the website securely and reliably.

Through the contact form, we receive the information you enter: first and last name, organization, email address, organization type, intended application, and message. Job title, telephone number, estimated participant count, and installation preference are optional. We also process the source page, language, submission time, privacy consent, and a random idempotency key used to prevent duplicate submissions.

Purposes and legal bases

We process personal data only for specific purposes and on an appropriate legal basis under the General Data Protection Regulation (GDPR).

  • Website delivery, language preference, security, and abuse prevention: our legitimate interest in providing a secure and usable website.
  • Contact requests and project exploration: your consent, taking steps at your request before entering into a contract, and, for business communications, our legitimate interest in answering enquiries.
  • Compliance with legal obligations and establishing, supporting, or defending legal claims where necessary.
  • Planned Google Analytics measurement: consent only, after the website provides a separate consent choice.

Contact form and abuse prevention

Contact requests are sent through a secured server integration to the designated Microsoft Exchange mailboxes. Only staff who need to handle the request receive access. We do not use form information for unsolicited marketing or sell it.

To limit automated abuse, the application temporarily creates a one-way hash of the IP address and user agent when a form is submitted. The application does not retain the raw IP address for this purpose. The hash remains in application memory for no more than 15 minutes. A random submission key remains in memory for no more than 24 hours to recognize duplicates; an in-progress claim expires after 2 minutes.

Google Analytics 4 — planned, not active

The current website does not load a Google Analytics tag or set Google Analytics cookies. We plan to use Google Analytics 4 to obtain aggregated insight into website visits and understand which pages and actions are useful.

Before activation, we will implement a consent choice and basic consent mode. Without consent, the Google tag will not load and no analytics data will be sent to Google. After consent, the page URL and title, referring page, session and interaction information, device category, browser, and approximate location may be processed. Names, email addresses, telephone numbers, and contact-form content will not be sent to Google Analytics.

The planned configuration will not use Google Signals, advertising features, advertising links, or granular location and device data. User-level and event-level data will have a 2-month retention period. Google Ireland Limited is the European service provider; processing may also take place outside the European Economic Area subject to applicable contractual and legal safeguards.

Cookies

The website currently uses only the necessary language-preference cookie. The two Google Analytics cookies below are planned and may be set only after consent. The listed duration is the maximum default lifetime; browser settings or withdrawal of consent may shorten it.

Overview of current and planned cookies
CookieProviderPurposeCategoryDuration
nms-localeNext Mission LabRemembers the selected language.Necessary1 year
_gaGoogle Analytics — plannedDistinguishes browsers after consent.AnalyticsUp to 2 years
_ga_<container-id>Google Analytics — plannedRetains session state after consent.AnalyticsUp to 2 years

Recipients and international transfers

We share personal data only when necessary for the purposes described above. Recipients may include our hosting and security providers, Microsoft for the Exchange environment, authorized staff, and professional advisers. Google will become a recipient only if Google Analytics is activated after consent.

Some providers may process data outside the European Economic Area. In that case, we use a valid transfer mechanism, such as an adequacy decision or European Commission-approved standard contractual clauses, and assess supplementary safeguards where necessary. We also disclose information when required by law or a binding order.

How long do we keep information?

We keep contact requests and related correspondence for up to 12 months after the last substantive contact. If a request leads to a project or contract, information may be retained longer where needed to perform the agreement, meet statutory record-keeping duties, or handle potential claims.

The security hash is retained for no more than 15 minutes, an in-progress submission claim for no more than 2 minutes, and the duplicate-prevention key for no more than 24 hours. The language-preference cookie expires after 1 year. Technical hosting and security logs are kept only as long as necessary for operation and security, according to the provider's configured and contractual periods. Once activated, Google Analytics will retain user-level and event-level data for 2 months; Analytics cookies may remain for up to 2 years.

Security

We take appropriate technical and organizational measures to protect personal data against loss, unauthorized access, alteration, and disclosure. These measures include encrypted HTTPS connections, restricted access, server-side validation, abuse prevention, and protection of mail and server credentials.

No method is entirely risk-free. If a personal data breach occurs, we assess it under the GDPR and notify the supervisory authority and affected individuals where legally required.

Your privacy rights

Depending on the circumstances, you may request access to, correction, erasure, restriction, or portability of your personal data. You may object to processing based on legitimate interests and withdraw previously given consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Send your request to support@nextmissionlabs.com. To keep information secure, we may request reasonable information to verify your identity. We generally respond within one month. You may also lodge a complaint with the Dutch Data Protection Authority or the supervisory authority where you live or work.

Changes and contact

We update this policy when our website, providers, or processing activities change. The date above shows when the policy was last updated. For material changes, we will provide an additional website notice where appropriate.

Questions about this policy or our handling of personal data can be sent to support@nextmissionlabs.com or to Next Mission Systems, Herengracht 124–128, Amsterdam, the Netherlands.