Legal

Data Processing Summary

Last updated: January 2026

Note: This is a plain-language summary for transparency. The binding terms for any engagement are set out in the Data Processing Agreement (DPA) that forms part of our client contract.

1. Roles

When we deliver services, our client is the controller of end-customer personal data and NextWave is the processor. We process personal data only on the client's documented instructions and for the purposes of providing the agreed services.

2. Confidentiality & staff

Our personnel are bound by confidentiality obligations and trained on data protection. Access to personal data is limited to those who need it to deliver the service.

3. Security measures

We implement appropriate technical and organisational measures — including access controls, encryption in transit, network security, monitoring and secure facilities — proportionate to the risk, and we maintain an incident-response process with client notification as required.

4. Subprocessors

We engage subprocessors only where permitted by the client agreement, under contracts imposing equivalent data-protection obligations, and we remain responsible for their performance. We maintain a list of subprocessors available to clients on request.

5. International transfers

Where personal data is transferred across borders between our delivery locations, we apply appropriate safeguards, such as standard contractual clauses, in line with the client agreement and applicable law.

6. Assisting the controller

We assist clients, taking into account the nature of processing, with data-subject requests, security, breach notification and any required assessments, as set out in the DPA.

7. Return & deletion

On termination of services, we return or delete personal data in accordance with the client agreement, save where retention is required by law.

We use one local key to remember your cookie choice. See our cookie notice.