This Privacy Policy explains how Next Gen Coding Company, Inc. ("NextGen Coding Company," "we," "us," or "our") handles personal information in connection with nextgencodingcompany.com (the "Site") and the professional services we provide.
This policy is maintained by NextGen Coding Company. It describes our current practices and is not a certification, audit report, or legal advice. For our technical and organizational security controls, see our security and compliance page.
1. Who we are and what this policy covers
Next Gen Coding Company, Inc. is a United States software development and technology staffing firm headquartered in New York, NY, with an office at 150 Wrenn Dr, PO Box 187, Cary, NC 27513.
This policy applies to personal information we collect as a controller — through the Site, our contact and scheduling forms, marketing communications, and our sales and recruiting activities.
It does not govern personal information we process on behalf of a client inside that client's systems or project scope. In those cases we act as a processor (or service provider), and our handling is governed by the applicable master services agreement, statement of work, and data processing addendum with that client. See Section 10.
2. Information we collect
Information you provide. When you submit a contact or project-request form, book a call through our scheduling tool, download a resource, subscribe to updates, or apply for a role, we collect the information in that submission — typically name, business email address, phone number, company name, role, and any project details you choose to share.
Information collected automatically. When you visit the Site, we and our analytics providers may collect IP address, approximate location derived from IP, browser and device type, operating system, referring URL, pages viewed, time on page, and interaction events. This is collected through cookies, pixels, and similar technologies.
Business-audience identification and enrichment. We use third-party business-intelligence and visitor-identification services that may associate your visit with a company or, where the provider has an independent lawful basis and its own consent framework, an individual business contact. We also use business contact data from commercial data providers and public professional sources for B2B outreach. You may opt out at any time using the contact details in Section 13.
Candidate information. If you apply to work with us, we collect your résumé, work history, references, and any information you submit during the interview process.
We do not intentionally collect government identifiers, financial account numbers, biometric data, health data, precise geolocation, or other sensitive categories of personal information through the Site. Please do not submit them through our forms.
3. How we use personal information
- Respond to inquiries, prepare proposals, and schedule and conduct sales conversations.
- Deliver, support, and improve our services and this website.
- Send business communications, service updates, and marketing content you can unsubscribe from at any time.
- Measure website performance, understand which content is useful, and improve our search and content strategy.
- Evaluate candidates and manage recruiting.
- Maintain security, prevent fraud and abuse, and investigate suspected misuse of the Site.
- Comply with legal obligations, enforce our agreements, and establish or defend legal claims.
We do not use personal information collected through the Site to make decisions that produce legal or similarly significant effects about you through solely automated means.
4. Legal bases for processing (EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on the following legal bases under Article 6:
- Contract (Art. 6(1)(b)) — to take steps at your request before entering into a contract and to perform a contract with you or your organization.
- Legitimate interests (Art. 6(1)(f)) — to operate and secure our website, understand how it is used, and conduct business-to-business marketing to relevant professional audiences, balanced against your rights and freedoms.
- Consent (Art. 6(1)(a)) — for non-essential cookies and analytics where consent is required, and for marketing emails where consent is the applicable basis. You may withdraw consent at any time without affecting prior processing.
- Legal obligation (Art. 6(1)(c)) — to meet tax, accounting, and other statutory requirements.
7. International data transfers
We are based in the United States, and our infrastructure and personnel are primarily located in the United States. If you access the Site or contact us from outside the United States, your personal information will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary measures where appropriate. Copies of the relevant transfer mechanism are available on request.
8. Data retention
We keep personal information only as long as needed for the purposes described in this policy, and then delete or de-identify it. Our general practice:
- Inquiry and prospect records: retained for the duration of the sales relationship and up to 24 months after the last meaningful interaction.
- Client contract and engagement records: retained for the term of the engagement plus the period required by our contractual, tax, and legal obligations.
- Website analytics data: retained in identifiable form for up to 26 months, then aggregated.
- Candidate records: retained for up to 24 months after a hiring decision unless you ask us to delete them sooner.
- Marketing preference and suppression records: retained indefinitely so we can continue to honor your opt-out.
We may retain information longer where required to comply with law or to establish, exercise, or defend legal claims.
9. How we protect information
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, least-privilege and role-based access control, mandatory multi-factor authentication for our personnel, centralized logging, dependency and code scanning, and a documented incident response process. These controls are described in detail on our security and compliance page. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law.
10. Client data — our role as a processor
When we build, maintain, test, or operate software for a client, we may access personal information that belongs to that client's users, customers, employees, or patients. In that context the client is the controller and we act as a processor or service provider.
- We process client data only on the client's documented instructions and within the scope of the applicable agreement.
- We sign a Data Processing Addendum covering GDPR Article 28 processor obligations and CCPA service-provider terms, and a Business Associate Agreement for engagements involving protected health information.
- We do not sell, share, or use client data for our own marketing, product development, or model training.
- We return or delete client data at the end of an engagement in accordance with the agreement's offboarding terms.
If you believe a client of ours holds your personal information, please direct your request to that organization. We will support them in responding.
11. Your rights under GDPR and UK GDPR
If you are in the EEA, UK, or Switzerland, you have the right to request access to your personal information; rectification of inaccurate data; erasure; restriction of processing; portability of data you provided to us; and to object to processing based on our legitimate interests, including direct marketing. Where processing is based on consent, you may withdraw consent at any time.
To exercise a right, email admin@nextgencodingcompany.com. We will respond within one month, and may extend by two further months for complex requests, in which case we will tell you why. We may need to verify your identity before acting. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).
12. Your rights under CCPA/CPRA and other US state privacy laws
If you are a California resident, or a resident of another US state with a comprehensive privacy law (including Colorado, Connecticut, Virginia, Utah, Texas, and Oregon), you may have the right to:
- Know the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties we disclose it to.
- Delete personal information we collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell personal information for money.
- Limit the use of sensitive personal information. We do not collect sensitive personal information through the Site for purposes requiring this right.
- Appeal a denied request, and to be free from discrimination for exercising any of these rights.
Submit a request by emailing admin@nextgencodingcompany.com with the subject line "Privacy Request." We will confirm receipt within 10 business days and respond within 45 days, with one 45-day extension where permitted. An authorized agent may submit a request on your behalf with proof of authorization.
13. Third-party sites, marketing preferences, and children
The Site links to third-party websites, tools, and documentation we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.
You may unsubscribe from marketing email at any time using the link in any message or by emailing us. We will still send transactional and engagement-related communications where you are an active client contact.
Our services are directed to businesses, not to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this policy and how to contact us
We may update this policy to reflect changes in our practices or in the law. The "last updated" date at the top reflects the most recent revision. Material changes will be highlighted on this page, and where required by law we will seek your consent.
Next Gen Coding Company, Inc.
150 Wrenn Dr, PO Box 187, Cary, NC 27513, USA
admin@nextgencodingcompany.com
(919) 342-7602
For questions about our terms of engagement, see our Terms of Service.

