next2u S.à r.l. - S. ("Company" or "we") processes and protects personal data of registered and unregistered users of next2u – everyone who accesses our website, as well as those who contact the Company via all the means listed on the website ("users" or "you").
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and the laws of the Grand Duchy of Luxembourg. We are committed to protecting your privacy and ensuring your personal data is processed lawfully, fairly, and transparently in accordance with GDPR principles.
By providing us with personal data, you consent to its processing in accordance with this policy and applicable GDPR requirements.
Personal Data – any information related to a directly or indirectly identified or identifiable individual (data subject).
Processing of Personal Data – performing actions or a set of actions on personal data, including collection, recording, systematization, accumulation, storage, refinement, updating, and modification, retrieval, use, provision, access, blocking, deletion, and destruction – with or without automated data processing tools.
We may process your data in the ways listed for the purposes outlined in Section 4 of this Policy.
Personal Data Operator – a government body, municipal body, legal entity, or individual that independently or jointly with others organizes and/or carries out the processing of personal data, and also determines the purposes of processing personal data, the composition of personal data to be processed, and the actions (operations) performed on personal data.
The Company is the operator with respect to the personal data we may receive in connection with your use of next2u (including the website).
You provide us with personal data when:
Your device automatically transmits technical data:
We also collect the following data as part of our services:
Other useful links:
We process users personal data for the following purposes:
In accordance with Article 6 of the GDPR, we process your personal data based on the following legal grounds:
In compliance with GDPR Articles 44-49, we may transfer personal data to third parties when necessary to provide next2u services or with your consent. Data transfers include:
All data transfers outside the European Economic Area (EEA), if any, are conducted with appropriate safeguards in place, such as Standard Contractual Clauses approved by the European Commission, to ensure GDPR-level protection of your personal data.
When you publish listings, reviews or information in your account on next2u, personal data included in such information becomes available to an indefinite number of people. You disclose such data yourself, without providing us as a data operator with a separate agreement. The company does not transfer your personal data. We process such data for the purpose of fulfilling the agreement with you concluded at your initiative.
The purpose for which users post data on next2u is to establish contact with a potential buyer (client) who is interested in concluding a deal on the listing. Users do not process other users' data for any other purposes. This means that:
Responsible attitude to personal data is the company's standard of operation. In accordance with GDPR Article 32, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing personal data.
To protect personal data, we:
When taking measures to protect personal data, we rely on:
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33, and inform affected data subjects when required by Article 34.
We record, systematize, accumulate, store, clarify (update, change), and extract your personal data using databases located in the EU, ensuring compliance with GDPR data localization principles.
Our technical infrastructure is provided by OVH (OVHcloud), with all data stored in OVH data centers located within the European Union. This ensures that all data processing occurs within the European Economic Area (EEA), maintaining full GDPR compliance.
We store your data in accordance with the data processing periods necessary to achieve the processing purposes specified in Section 4 of this Policy, in line with the GDPR principle of storage limitation (Article 5(1)(e)).
In accordance with the GDPR principle of storage limitation, we retain your personal data only for as long as necessary to fulfill the purposes for which it was collected.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data (email, username, profile) | Until account deletion + 1 year | Legal requirement |
| Listings | Until deleted by user or account deletion | Service provision |
| Chat messages | 3 years after last activity | Contractual disputes |
| Payment records | 10 years | Luxembourg tax law |
| Reviews | Until account deletion | Service provision |
| Favorites | Until account deletion | Service provision |
| Link click analytics | 90 days, then anonymized | Legitimate interest |
| Support requests | 3 years | Legal claims limitation |
| Cookie consent records | 3 years | Compliance documentation |
We stop processing your personal data:
After the retention periods have expired, we automatically delete the data from our systems. Data processed without automated tools (e.g., paper requests) is securely destroyed.
To delete your next2u account and all the data in it, go to the "Privacy & Data" page on the website or in the application and select the account deletion option. If there are unfinished transactions, wait for them to be completed before proceeding with deletion.
We will stop processing your personal data and delete it in accordance with legal requirements. We will not be able to restore your data, even if you change your mind later.
The law requires that we store user information for at least a year after deleting an account.
Under the GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, withdraw consent, or inquire about data privacy, contact customer support.
Data Controller:
next2u S.à r.l. - S.
14A Rue du Bambusch
L-8213, Mamer, Luxembourg
For privacy inquiries, contact customer support through the website.
You have the right to lodge a complaint with a data protection authority. Depending on your country of residence, you may contact:
Luxembourg (Lead Authority)
Commission Nationale pour la Protection des Données (CNPD)
15, Boulevard du Jazz, L-4370 Belvaux
Website: cnpd.public.lu | Email: info@cnpd.lu
Belgium
Autorité de protection des données (APD/GBA)
Rue de la Presse 35, 1000 Brussels
Website: dataprotectionauthority.be | Email: contact@apd-gba.be
France
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Website: cnil.fr
Germany
Bundesbeauftragter für den Datenschutz (BfDI)
Graurheindorfer Str. 153, 53117 Bonn
Website: bfdi.bund.de | Email: poststelle@bfdi.bund.de
(Or contact your state data protection authority)
Last updated: December 2025