Last updated: January 2026
When we deliver services, our client is the controller of end-customer personal data and NextWave is the processor. We process personal data only on the client's documented instructions and for the purposes of providing the agreed services.
Our personnel are bound by confidentiality obligations and trained on data protection. Access to personal data is limited to those who need it to deliver the service.
We implement appropriate technical and organisational measures — including access controls, encryption in transit, network security, monitoring and secure facilities — proportionate to the risk, and we maintain an incident-response process with client notification as required.
We engage subprocessors only where permitted by the client agreement, under contracts imposing equivalent data-protection obligations, and we remain responsible for their performance. We maintain a list of subprocessors available to clients on request.
Where personal data is transferred across borders between our delivery locations, we apply appropriate safeguards, such as standard contractual clauses, in line with the client agreement and applicable law.
We assist clients, taking into account the nature of processing, with data-subject requests, security, breach notification and any required assessments, as set out in the DPA.
On termination of services, we return or delete personal data in accordance with the client agreement, save where retention is required by law.
We use one local key to remember your cookie choice. See our cookie notice.