// legal

Privacy Policy

How we collect, use, share, and protect personal information across this website and our client engagements — and how you can exercise your privacy rights.

Last updated
August 4, 2026

This Privacy Policy explains how Next Gen Coding Company, Inc. ("NextGen Coding Company," "we," "us," or "our") handles personal information in connection with nextgencodingcompany.com (the "Site") and the professional services we provide.

This policy is maintained by NextGen Coding Company. It describes our current practices and is not a certification, audit report, or legal advice. For our technical and organizational security controls, see our security and compliance page.

1. Who we are and what this policy covers

Next Gen Coding Company, Inc. is a United States software development and technology staffing firm headquartered in New York, NY, with an office at 150 Wrenn Dr, PO Box 187, Cary, NC 27513.

This policy applies to personal information we collect as a controller — through the Site, our contact and scheduling forms, marketing communications, and our sales and recruiting activities.

It does not govern personal information we process on behalf of a client inside that client's systems or project scope. In those cases we act as a processor (or service provider), and our handling is governed by the applicable master services agreement, statement of work, and data processing addendum with that client. See Section 10.

2. Information we collect

Information you provide. When you submit a contact or project-request form, book a call through our scheduling tool, download a resource, subscribe to updates, or apply for a role, we collect the information in that submission — typically name, business email address, phone number, company name, role, and any project details you choose to share.

Information collected automatically. When you visit the Site, we and our analytics providers may collect IP address, approximate location derived from IP, browser and device type, operating system, referring URL, pages viewed, time on page, and interaction events. This is collected through cookies, pixels, and similar technologies.

Business-audience identification and enrichment. We use third-party business-intelligence and visitor-identification services that may associate your visit with a company or, where the provider has an independent lawful basis and its own consent framework, an individual business contact. We also use business contact data from commercial data providers and public professional sources for B2B outreach. You may opt out at any time using the contact details in Section 13.

Candidate information. If you apply to work with us, we collect your résumé, work history, references, and any information you submit during the interview process.

We do not intentionally collect government identifiers, financial account numbers, biometric data, health data, precise geolocation, or other sensitive categories of personal information through the Site. Please do not submit them through our forms.

3. How we use personal information

  • Respond to inquiries, prepare proposals, and schedule and conduct sales conversations.
  • Deliver, support, and improve our services and this website.
  • Send business communications, service updates, and marketing content you can unsubscribe from at any time.
  • Measure website performance, understand which content is useful, and improve our search and content strategy.
  • Evaluate candidates and manage recruiting.
  • Maintain security, prevent fraud and abuse, and investigate suspected misuse of the Site.
  • Comply with legal obligations, enforce our agreements, and establish or defend legal claims.

We do not use personal information collected through the Site to make decisions that produce legal or similarly significant effects about you through solely automated means.

5. How we share information and our subprocessors

We do not sell personal information for money. We share personal information only as described here:

  • Service providers and subprocessors who host, secure, analyze, or support our operations, under written contracts limiting their use of the data to our instructions.
  • Professional advisors such as counsel, auditors, insurers, and accountants.
  • Corporate transactions, including a merger, acquisition, financing, or sale of assets, subject to this policy's continued application.
  • Legal and safety disclosures required by law, subpoena, or a valid governmental request, or necessary to protect our rights, users, or the public.

Our current categories of subprocessors and the vendors we use for infrastructure, communications, monitoring, and compliance are listed on our security page. We maintain a current subprocessor list for client engagements and will provide it on request.

6. Cookies and tracking technologies

We use the following categories of cookies and similar technologies:

  • Strictly necessary — required for the Site to load, route, and remain secure. These cannot be disabled through our Site.
  • Analytics and performance — help us understand traffic, page performance, and content engagement in aggregate.
  • Marketing and business identification — help us understand which companies engage with our content and measure campaign effectiveness.

You can block or delete cookies through your browser settings; doing so may degrade parts of the Site. Where required by law, we present a consent mechanism before setting non-essential cookies. We honor Global Privacy Control (GPC) and similar opt-out preference signals as a valid request to opt out of sharing for cross-context behavioral advertising where applicable law requires it.

7. International data transfers

We are based in the United States, and our infrastructure and personnel are primarily located in the United States. If you access the Site or contact us from outside the United States, your personal information will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction. Where we transfer personal information out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary measures where appropriate. Copies of the relevant transfer mechanism are available on request.

8. Data retention

We keep personal information only as long as needed for the purposes described in this policy, and then delete or de-identify it. Our general practice:

  • Inquiry and prospect records: retained for the duration of the sales relationship and up to 24 months after the last meaningful interaction.
  • Client contract and engagement records: retained for the term of the engagement plus the period required by our contractual, tax, and legal obligations.
  • Website analytics data: retained in identifiable form for up to 26 months, then aggregated.
  • Candidate records: retained for up to 24 months after a hiring decision unless you ask us to delete them sooner.
  • Marketing preference and suppression records: retained indefinitely so we can continue to honor your opt-out.

We may retain information longer where required to comply with law or to establish, exercise, or defend legal claims.

9. How we protect information

We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, least-privilege and role-based access control, mandatory multi-factor authentication for our personnel, centralized logging, dependency and code scanning, and a documented incident response process. These controls are described in detail on our security and compliance page. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law.

10. Client data — our role as a processor

When we build, maintain, test, or operate software for a client, we may access personal information that belongs to that client's users, customers, employees, or patients. In that context the client is the controller and we act as a processor or service provider.

  • We process client data only on the client's documented instructions and within the scope of the applicable agreement.
  • We sign a Data Processing Addendum covering GDPR Article 28 processor obligations and CCPA service-provider terms, and a Business Associate Agreement for engagements involving protected health information.
  • We do not sell, share, or use client data for our own marketing, product development, or model training.
  • We return or delete client data at the end of an engagement in accordance with the agreement's offboarding terms.

If you believe a client of ours holds your personal information, please direct your request to that organization. We will support them in responding.

11. Your rights under GDPR and UK GDPR

If you are in the EEA, UK, or Switzerland, you have the right to request access to your personal information; rectification of inaccurate data; erasure; restriction of processing; portability of data you provided to us; and to object to processing based on our legitimate interests, including direct marketing. Where processing is based on consent, you may withdraw consent at any time.

To exercise a right, email admin@nextgencodingcompany.com. We will respond within one month, and may extend by two further months for complex requests, in which case we will tell you why. We may need to verify your identity before acting. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).

12. Your rights under CCPA/CPRA and other US state privacy laws

If you are a California resident, or a resident of another US state with a comprehensive privacy law (including Colorado, Connecticut, Virginia, Utah, Texas, and Oregon), you may have the right to:

  • Know the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties we disclose it to.
  • Delete personal information we collected from you, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell personal information for money.
  • Limit the use of sensitive personal information. We do not collect sensitive personal information through the Site for purposes requiring this right.
  • Appeal a denied request, and to be free from discrimination for exercising any of these rights.

Submit a request by emailing admin@nextgencodingcompany.com with the subject line "Privacy Request." We will confirm receipt within 10 business days and respond within 45 days, with one 45-day extension where permitted. An authorized agent may submit a request on your behalf with proof of authorization.

13. Third-party sites, marketing preferences, and children

The Site links to third-party websites, tools, and documentation we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.

You may unsubscribe from marketing email at any time using the link in any message or by emailing us. We will still send transactional and engagement-related communications where you are an active client contact.

Our services are directed to businesses, not to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

14. Changes to this policy and how to contact us

We may update this policy to reflect changes in our practices or in the law. The "last updated" date at the top reflects the most recent revision. Material changes will be highlighted on this page, and where required by law we will seek your consent.

Next Gen Coding Company, Inc.
150 Wrenn Dr, PO Box 187, Cary, NC 27513, USA
admin@nextgencodingcompany.com
(919) 342-7602

For questions about our terms of engagement, see our Terms of Service.

// let's build something

Start your project request

Tell us what you're building — engineering capacity, AI, QA, cloud, or a fixed-scope software engagement. Our NYC team responds within one business day.

// what to expect
  • Response within 1 business day
  • 30-minute discovery conversation
  • Recommended engagement model & pricing
  • NYC-focused — in-person available
Start Project Request

Inbound sales only. All form information is encrypted in transit.