NextSafe
Privacy Policy, NextSafe
Privacy Policy

Your privacy, in plain language.

Last updated: July 2026

With a VPN, everything comes down to trust. That’s why we keep it simple: we don’t store what you do online, and we only collect what we actually need to make your account work. We never sell your data. Below is the short version; below that, the full policy.

privacy.config
1# what we DON’T store
2websites_visited: never
3dns_lookups: never
4ip_activity: never
5bandwidth_logs: never
6
7# what we DO process
8email_address: “to log in”
9payment_status: “active / expired”
10support_messages: “if you contact us”

01 Who is responsible for your data?

NextSafe is a brand of Nextmac B.V. Nextmac B.V. is the data controller for the personal data processed through NextSafe. If you have questions about your privacy or want to exercise a right, please contact us using the details at the bottom of this policy.

02 What data we process

We deliberately keep it minimal. We process:

  • Account data, your email address and an encrypted (hashed) version of your password, so you can log in.
  • Subscription and payment, which plan you have and your payment status. Payments via iDEAL and Wero are handled by our payment provider; we don’t receive or store full payment details.
  • Contact and support, if you email or message us, we keep those messages so we can help you.
  • Limited technical data, to prevent abuse, we may, for example, keep track of the number of simultaneous connections per account. This never concerns the content or destination of your traffic.

03 What we don’t store

This is our core principle. We don’t keep a log of your online activity. So we do not store:

  • which websites, apps, or services you visit;
  • your DNS lookups;
  • the IP address you get via NextSafe, linked to what you do;
  • how much bandwidth you use per session;
  • timestamps that could be used to trace your activity.

In short: we can’t share or lose what we don’t have.

04 What we use your data for

  • to create and manage your account;
  • to process your payment and billing;
  • to help you when you contact us;
  • to secure our service and prevent abuse;
  • to comply with legal obligations.

05 On what legal basis we do this

We process your data based on the legal grounds under the GDPR:

  • Performance of the contract, to provide you with the service you pay for.
  • Legal obligation, for example, for our financial administration.
  • Legitimate interest, to keep our service secure and prevent abuse.
  • Consent, for things you choose yourself, such as an optional newsletter or non-essential cookies. You can always withdraw your consent.

06 Sharing with others

We never sell your data. We do work with parties that help us deliver the service. They process data solely on our instructions, under a data processing agreement. Think of our payment provider, the technical partner that supplies our server infrastructure, our hosting provider, and tools for email and support.

NextSafe offers servers in multiple countries. Because we don’t log your activity, no usage data about what you do is stored when you connect. We only provide data to authorities when we are legally required to do so, and even then: what we don’t store, we can’t hand over.

07 How long we keep data

We keep your account data for as long as you have an active account. After cancellation, we delete your personal data within a reasonable period, except for data we are legally required to keep longer. We keep invoices and our financial records for seven years, as required by Dutch tax law.

08 How we secure your data

We take appropriate technical and organizational measures to protect your data, including data encryption, limited access for staff, and secured systems. No service is completely risk-free, but we do everything we can to keep your data safe.

09 Cookies

Our website uses cookies that are necessary for it to function properly, and, only with your consent, any cookies for statistics. You can read more about this in our cookie policy. Our “What is my IP” tool may use an external lookup service to show your location; in doing so, your IP address is processed to perform the lookup.

10 Your rights

Under the GDPR, you have the right to:

  • access your data;
  • have incorrect data corrected;
  • have your data deleted;
  • restrict the processing;
  • object to processing;
  • have your data transferred (data portability);
  • withdraw previously given consent.

Would you like to exercise one of these rights? Email us using the details below; we respond within a month. If you disagree with how we handle your data, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

11 Changes to this policy

We may update this privacy policy from time to time. The date at the top of the page shows when it was last updated. For significant changes, we will let you know.

12 Contact

Questions about your privacy or this policy? Contact us:

Data controllerNextmac B.V.
BrandNextSafe
Chamber of Commerce (KvK) number98868950
AddressHerengracht 320, Amsterdam
Emailprivacy@nextsafe.nl