Privacy Policy

Last updated: February 2026

1. Introduction

NextSteps Consulting (“we”, “our”, or “us”) operates the website www.nextsteps-consulting.com (the “Website”). This Privacy Policy explains how we collect, use, and protect your personal data when you visit our Website or contact us.

We are committed to protecting your personal data and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and Spanish data protection regulations.

2. Data Controller

Company name: NextSteps Consulting
Registered office: Barcelona, Spain
Contact email: it@nextsteps-consulting.com

3. Personal Data We Collect

We may collect the following personal data:

  • Contact data: name, email address, phone number (when you contact us via the contact form or email)
  • Professional information: company name, role (if provided voluntarily)
  • Technical data: IP address, browser type, operating system, pages visited, date and time of access

We do not collect sensitive personal data.

4. Purpose of Processing

We process your personal data for the following purposes:

  • To respond to inquiries submitted via the contact form or email
  • To communicate with you regarding our services
  • To ensure the proper functioning and security of the Website

To improve the Website’s performance and user experience

5. Legal Basis for Processing

Under the GDPR, our legal bases for processing your personal data are:

  • Consent: when you submit a contact form
  • Legitimate interest: to ensure website security, functionality, and basic analytics
  • Legal obligation: where applicable

6. Cookies

Our Website uses only essential technical cookies required for its proper operation.

We do not use analytics cookies, advertising cookies, or any form of user tracking or profiling.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy or to comply with legal obligations. Contact form submissions are not stored in the Website database and are only sent by email to allow us to respond to inquiries.

8. Data Sharing

We do not sell or rent your personal data.

Your data may be shared with trusted service providers (e.g. hosting providers or IT service providers) solely for technical or operational purposes. These providers are contractually bound to comply with data protection obligations.

9. Data Transfers

Personal data is processed within the European Economic Area (EEA). We do not intentionally transfer personal data outside the EEA.

10. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. However, no method of transmission over the Internet is completely secure.

11. Your Rights

Under GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure (“right to be forgotten”)
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time

To exercise these rights, please contact us at [CONTACT EMAIL].

You also have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD).

12. Third-Party Links

The Website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites.

13. Children’s Privacy

Our Website is not directed at children under the age of 16. We do not knowingly collect personal data from minors.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.

Contact

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at:

Email: it@nextsteps-consulting.com