CurNext · Legal
GDPR Policies
How CurNext applies the EU General Data Protection Regulation (GDPR) to personal data processed through curnext.app, the CurNext dashboard, APIs, and related services - including roles, legal bases, data subject rights, retention, transfers, and how to contact us.
Controller for CurNext account, marketing, and website data: CurNext (Finland). Processor for Client Data instructed through the platform: CurNext under a DPA. Core production hosting: Germany / Frankfurt. Privacy requests: [email protected].
This page explains CurNext's GDPR-oriented policies for transparency under Articles 12-14 and related obligations. It is not a substitute for a signed Data Processing Agreement, or legal advice. Where this page and a signed contract conflict, the signed contract controls for that relationship.
Last updated: 11 August 2026
Purpose of this policy
CurNext builds construction site intelligence - sensors, gateways, cloud dashboards, and readiness evidence. That stack inevitably involves personal data: invitees, admins, support contacts, website visitors, and job applicants. GDPR is the primary privacy regime for our EU-anchored platform processing.
- - Explain who is responsible for which processing (controller vs processor).
- - Describe categories of personal data, purposes, and legal bases at a policy level.
- - Set out data subject rights and a clear channel to exercise them.
- - Summarise retention themes, international transfers, security posture, and breach handling.
- - Point to related documents (DPA, Security, Compliance, Audit Trail, Cookie Policy) without duplicating every clause.
We do not claim ISO 27001 or SOC 2 certification for CurNext on public pages. Standards named elsewhere are design alignment unless separately confirmed in writing.
Controller identity and contact
For personal data where CurNext determines the purposes and means of processing (for example website analytics with consent, marketing subscriptions, career applications, and CurNext's own B2B account administration), the controller is:
- CurNext
- Registered in Finland
- Business ID Coming soon
- Website: https://curnext.app
GDPR / privacy inbox
[email protected]Legal / DPA
[email protected]Security incidents and vulnerability disclosure
[email protected]Use [email protected] for access, rectification, erasure, restriction, portability, objection, and other data subject requests. Use [email protected] for Data Processing Agreements. Use [email protected] for vulnerability disclosure and confirmed security incidents - not for routine DSRs.
Roles under GDPR
Clarity on roles avoids wrong expectations about who answers a request.
CurNext as controller
CurNext is typically the controller for: the public marketing website; newsletter and product update subscriptions; contact and quote forms when you write to CurNext directly; careers and recruitment; CurNext's own CRM and sales records; invite-only account identities CurNext maintains as part of providing access to the Services; and telemetry needed to operate, secure, and improve CurNext's own products (subject to contracts and product settings).
CurNext as processor
When a customer (the Client) uses CurNext to monitor sites and manage project users, CurNext generally acts as processor for Client Data - personal data the Client uploads, invites, or generates through the Services under the Client's instructions. The Client remains the controller for that Client Data. Processor terms are set out in the Data Processing Agreement.
Joint or mixed situations
Some operational logs and security events may contain identifiers that serve both Client accountability and CurNext's legitimate interest in securing the platform. We design for accountability (RBAC, audit events, invite-only access) and document the split in the DPA and Security materials. If you are unsure who should answer your request, write to [email protected] and we will route it.
Scope of processing covered
These policies apply to personal data processed in connection with:
- - curnext.app and localized marketing pages
- - dash.curnext.app and related dashboard experiences
- - CurNext APIs, SDKs, and developer portals where personal data appears (for example API keys tied to accounts)
- - Mobile applications published under CurNext branding, when linked to the same identity plane
- - Support, Docs, Knowledge Base interactions that identify a person
- - Email, forms, and CRM systems used to respond to commercial and support requests
Field sensors primarily measure environmental and structural conditions. Personal data risk usually arises at the cloud, identity, and collaboration layer (who can see which project), not from temperature or humidity readings alone. BIM maps and uploaded plans may contain personal data depending on what the Client includes.
Legal bases (Article 6)
Depending on the processing, CurNext relies on one or more of the following bases. Exact mapping for a specific product feature may be refined in the Privacy Policy and customer contracts.
| Legal basis | Typical use |
|---|---|
| Contract (Art. 6(1)(b)) | Creating and administering accounts, delivering the Services a customer ordered, authenticating invitees, providing contracted support, and processing information needed to perform a quote or order workflow. |
| Legitimate interests (Art. 6(1)(f)) | Securing the platform (fraud, abuse, intrusion detection), improving reliability, B2B relationship management with existing and prospective customers, limited product analytics that do not override rights and freedoms, and defending legal claims. We balance interests and offer objection where required. |
| Consent (Art. 6(1)(a)) | Non-essential cookies and similar technologies where consent is required; optional marketing emails where consent is the chosen basis; Knowledge Base AI chat where product flows require explicit GDPR consent before sending a question; other optional features that we mark as consent-based. |
| Legal obligation (Art. 6(1)(c)) | Tax, accounting, and regulatory record-keeping; responding to lawful requests from competent authorities; breach notification duties where CurNext is the controller. |
We do not seek to process special categories of personal data (Art. 9) as part of core site monitoring. Please do not submit health, biometric, or other special-category data through general contact forms. If a customer project requires such data, it must be scoped in writing with appropriate safeguards.
Categories of personal data
Categories vary by product surface. Typical examples:
Identity and contact
Name, work email, phone, company, role, locale preference, and similar business contact details.
Account and access
Invite status, organisation / project membership, roles and permissions, authentication metadata, session and device signals used for security, and MFA status for privileged roles.
Commercial and support
Messages sent via contact, quote, demo, or support channels; ticket history; contract and billing references needed to serve the account.
Usage and technical
IP addresses, approximate location derived from network data, browser/user-agent, diagnostic logs, rate-limit and WAF events, and product usage metrics needed to operate the Services.
Recruitment
CV / résumé content, application answers, interview notes, and related communications for open roles.
Client-controlled project content
User-generated content inside projects (notes, uploads, BIM-linked annotations, collaborator lists) that the Client controls as controller. CurNext processes this as processor under documented instructions.
Your rights under GDPR
Where GDPR applies and CurNext is the controller (or must assist as processor), you may have the following rights, subject to statutory limits and exemptions:
| Right | What it means |
|---|---|
| Access (Art. 15) | Obtain confirmation of whether we process your personal data and receive a copy together with relevant information about the processing. |
| Rectification (Art. 16) | Have inaccurate personal data corrected and incomplete data completed. |
| Erasure (Art. 17) | Request deletion where a ground applies (for example withdrawal of consent or data no longer needed). Retention and audit requirements may limit full deletion of certain security or financial records; we explain when that is the case. |
| Restriction (Art. 18) | Request that processing be limited in specific circumstances (for example while accuracy is contested). |
| Portability (Art. 20) | Receive personal data you provided to us in a structured, commonly used, machine-readable format, and transmit it where the processing is based on consent or contract and carried out by automated means. |
| Objection (Art. 21) | Object to processing based on legitimate interests, including profiling related to such processing, and object to direct marketing at any time. |
| Withdraw consent | Where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal. |
| Complaint | Lodge a complaint with a supervisory authority, in particular in the EEA state of your habitual residence, place of work, or place of the alleged infringement. |
If your request concerns data inside a customer's CurNext project (for example a collaborator invited by a Client admin), the Client is usually the right first contact. CurNext will assist the Client under the DPA and can help route requests received at [email protected].
How to exercise your rights
We prefer written requests so we can authenticate the requester and keep an accountable record.
- Email [email protected] from the address associated with your account or with enough detail for us to identify you.
- State which right you wish to exercise and the context (website, newsletter, dashboard account, job application, or customer project).
- Include your full name, company (if any), and any project or organisation name shown in the dashboard.
- For Client Data inside a customer tenant, tell us the customer organisation if known - we may need to involve the Client controller.
We aim to respond without undue delay and within one month of receipt, extendable by two further months for complex or numerous requests as permitted by Art. 12(3). If we need more time or cannot fulfil a request, we will explain why.
We may ask for reasonable additional information to confirm identity and authority (for example that you act for a company admin). We will not fulfil a request that would unjustifiably disclose another person's data.
You may also select "GDPR / privacy" on the contact form at /contact - that topic routes to the same inbox.
[email protected]Retention
We keep personal data only as long as needed for the purposes described, including legal, accounting, and security needs.
Account and service data
Retained for the life of the customer relationship and a wind-down period needed for offboarding, dispute handling, and contractual close-out, then deleted or anonymised according to product and DPA schedules.
Marketing contacts
Kept until you unsubscribe or object, or until the list is cleaned under routine hygiene, unless a longer retention is required for suppression (so we remember not to email you again).
Support and sales correspondence
Retained as needed to complete the request and maintain a reasonable business record, then reduced or deleted under internal schedules.
Recruitment
Application materials are retained for the hiring process and a limited post-process period (or longer with your consent for future roles), then deleted or archived with restricted access.
Security and GDPR audit events
Security logs and GDPR-oriented audit events may be retained longer, sometimes in append-only or pseudonymised form, to investigate incidents and demonstrate accountability. See Audit Trail.
Backups
Encrypted backups follow rolling retention. Deletion from live systems may take effect in backups only after the backup cycle expires.
International transfers
Core application and database hosting for the platform is designed around Germany / Frankfurt (EU). Commercial markets today include Finland, Canada, and Cameroon - selling into a market is not the same as hosting a local production region there.
- - EEA / EU processing is the default for Client Data on the production stack unless a written enterprise residency addendum says otherwise.
- - Access by authorised CurNext personnel or subprocessors outside the EEA, if any, is governed by transfer tools such as the European Commission Standard Contractual Clauses (SCCs), adequacy decisions where applicable, and contractual / technical safeguards described in the DPA.
- - Canadian and Cameroon customers access EU-hosted Client Data as instructed; the Client remains controller for that Client Data.
- - Some support, email, or AI assistance vendors may process limited personal data outside the EEA - see the public subprocessor list on the DPA page.
Details of subprocessors, locations, and transfer mechanisms are maintained on the Data Processing Agreement page and may change with notice as described there.
Processors and subprocessors
When CurNext acts as processor, we engage subprocessors under written terms that impose data-protection obligations consistent with Art. 28. When CurNext acts as controller, we use processors under appropriate contracts.
- - Hosting and database infrastructure in the EU (Germany / Frankfurt orientation).
- - Optional object storage with EU jurisdiction options where enabled.
- - Email delivery, error monitoring, and observability vendors as listed publicly.
- - Assisted AI features (for example Gemini or Groq when enabled) under product and contractual controls - concrete curing prediction uses an in-house TensorFlow.js model and is not the same as chat assistance.
Security measures
Security is part of GDPR accountability (Art. 32). CurNext's publicly described posture includes:
- - Invite-only access to the product plane
- - Role-based access control (RBAC) and privileged MFA
- - Encryption in transit; encryption at rest for core data stores
- - Edge protections such as WAF and rate limiting
- - Field and building connectivity controls (including LoRaWAN AES-128 themes, WireGuard / MQTT mTLS for CN-BC as documented on Security)
- - Signed OTA practices for firmware where applicable
- - GDPR-oriented audit, export, and erasure paths in product design
Architecture detail lives on the Security page. Report vulnerabilities to [email protected] using coordinated disclosure - do not send exploit details to support@ or gdpr@.
Personal data breaches
CurNext maintains processes aimed at detecting, assessing, and responding to personal data breaches.
When CurNext is controller
We assess risk to rights and freedoms and notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach that requires notification under Art. 33. We communicate to affected individuals when Art. 34 requires it.
When CurNext is processor
We notify the Client without undue delay after becoming aware of a personal data breach affecting Client Data, and assist with information the Client needs for its own obligations. Enterprise contracts may set a tighter target (for example 24 hours to the Client security contact).
What to include if you report an incident
Time observed, systems affected, whether personal data is involved, and how to reach you. Use [email protected] for suspected breaches and vulnerability reports.
Cookies, marketing, and AI assistants
Non-essential cookies and similar technologies are handled under our Cookie Policy and consent tools where required. Marketing emails include unsubscribe controls.
- - Essential cookies support security, load balancing, and preference storage needed to deliver the site.
- - Analytics or marketing tags, if used, run only with a valid legal basis (often consent in the EEA).
- - Knowledge Base AI chat requires explicit GDPR consent in the product flow before your question is processed.
- - You can withdraw consent for optional tools without losing access to core informational pages, though some features may be unavailable.
Children and age eligibility
CurNext Services are designed for professional construction and B2B use. They are not directed at children. Under CurNext internal policies, we do not onboard, invite, or register product users under 18 years of age. We also do not knowingly collect personal data from children under 16 for CurNext products. If you believe someone under 18 has been onboarded, or that a child has provided personal data, contact [email protected] and we will take appropriate steps.
Automated decision-making and profiling
CurNext provides readiness predictions and assisted insights for construction surfaces (for example concrete curing timelines). Those outputs support professional judgement; they are not intended as solely automated decisions that produce legal or similarly significant effects about an individual under Art. 22.
- - Site readiness signals concern materials and environments, not creditworthiness or employment of a natural person.
- - Account security may use automated risk signals (for example rate limits or anomaly detection) to protect the service.
- - If we introduce features that make solely automated decisions with legal or similarly significant effects about you, we will provide meaningful information and a way to obtain human review where required.
Supervisory authority
Without prejudice to any other administrative or judicial remedy, you may lodge a complaint with a supervisory authority. For CurNext as a Finnish controller, the lead supervisory authority context is typically:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
tietosuoja.fiYou may also contact the authority in your country of residence or work if you are in the EEA. We encourage you to contact [email protected] first so we can try to resolve concerns directly.
Changes to these policies
We may update this page to reflect product, legal, or organisational changes. The "Last updated" date at the top will change when we publish material revisions. For processor relationships, material subprocessor or transfer changes follow the notice process in the DPA. Continued use of the marketing site after an update constitutes awareness of the revised public policy text; contractual customers are governed by their agreements.
Need help with a privacy request?
Write to [email protected] for data subject requests, or use the contact form topic GDPR / privacy. For a signed DPA, use [email protected].
Translations are provided for convenience. Where a signed agreement exists, the English instrument controls.