Controller Information
Controller: Next Generation Access SL
Contact: support@ng-key.com
If a dedicated data protection officer or representative is appointed for a specific customer project, regulated provision, or public sector engagement, the relevant contact details will be provided in the associated contract or privacy policy.
Categories of Personal Data
- Identity and account data, such as names, usernames, business email addresses, and details of administrative roles.
- Device and technical data, such as IP addresses, telemetry data, browser details, logs, and security event records.
- Operational access data such as reader assignments, time profiles, audit logs, credential references, and support actions.
- Commercial or communication data, such as support requests, onboarding messages, contract contact details, and transaction-related correspondence.
Purposes and Legal Bases
- To provide and secure the platform based on contract fulfillment or pre-contractual measures.
- To maintain service integrity, fraud prevention, incident response, and platform security based on legitimate interests and, where applicable, legal obligations.
- To manage customer support, account administration, and product communication based on contract fulfillment and legitimate interests.
- To comply with accounting, tax, regulatory, cybersecurity, and data protection requirements based on legal obligations.
- To send electronic marketing only where consent, soft opt-in, or another lawful basis under the GDPR and Spanish LSSI regulations is validly available.
Recipients and International Transfers
Personal data may be processed by hosting providers, cloud infrastructure partners, email or communication providers, support tools, security providers, and carefully selected subcontractors acting on documented instructions and subject to appropriate confidentiality and security obligations.
When personal data are transferred outside the European Economic Area, Next Generation Access SL aims to use an appropriate transfer mechanism in accordance with Chapter V of the GDPR, such as an adequacy decision, standard contractual clauses, or another recognized safeguard. Additional information may be provided upon request where legally required.
Retention
We retain personal data only as long as necessary for the respective service purpose, security requirements, support needs, legal retention periods, or the contractual lifecycle. Retention periods vary depending on the type of record, customer provision, and regulatory context.
When data are no longer required, they are deleted, anonymized, or restricted in accordance with our internal retention and security procedures.
Your Rights
Subject to the conditions set out in the GDPR and applicable Spanish law, you may request access, rectification, deletion, restriction, data portability, or objection, and withdraw your consent if processing is based on consent.
You may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) or another competent supervisory authority in the EU member state of your habitual residence, workplace, or the alleged infringement.
To exercise your rights, contact us at support@ng-key.com and describe your request clearly enough for us to verify and process it securely.
Security and Updates
We apply technical and organizational measures designed to protect confidentiality, integrity, availability, and resilience, taking into account the nature of processing and associated risks. No system can guarantee absolute security, but we strive to maintain safeguards appropriate to the context of access control and identity management.
This policy may be updated to reflect legal, operational, or product-related changes. The most recently published version on this page is effective from the publication date unless a stricter legal regulation requires otherwise.