Privacy Policy
This policy explains exactly what data Nextware Technologies accesses, how we use it, who we share it with, how long we keep it and how you can delete it, including data we access through Google and Meta APIs on behalf of our clients.
Effective / last updated: 20 July 2026
Contents
- Who we are
- Short summary
- Data we collect
- Google user data
- Meta (Facebook and Instagram) data
- How and why we use data
- Sharing and sub-processors
- Artificial intelligence processing
- How we protect data
- How long we keep data
- Your rights, deletion and revoking access
- International transfers
- Cookies
- Children
- Changes to this policy
- Contact us
1. Who we are
Nextware Technologies (“Nextware”, “we”, “us”) is a digital marketing and software engineering agency operating the website nextwaretech.co. We provide search engine optimisation (SEO), answer engine optimisation (AEO), generative engine optimisation (GEO), AI integration, web development and app development services to business clients.
We are the data controller for information about our website visitors and our direct clients. When we access a client’s marketing platforms on their instruction, we act as a data processor on that client’s behalf. Contact: info@nextwaretech.co.
- Dubai, UAE: IFZA Property FZCO, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. Tel: +971 58 697 0330
- Faisalabad, Pakistan: Chak # 189 RB Rasoolpur, Chak Jhumra Road, Near Wapda City Canal Road, Faisalabad, Pakistan. Tel: 0311 4010806
2. Short summary
- We only connect to a Google or Meta account when an authorised person clicks “connect” and grants permission.
- We request the narrowest set of permissions needed to deliver the service, and we tell you what each one does.
- We use that data only to run and report on the marketing work you hired us to do.
- We never sell your data, never share it with data brokers, and never use it for advertising or to train generalised AI models.
- You can disconnect at any time, and you can ask us to delete your data at any time, free of charge.
3. Data we collect
3.1 Website visitors
If you submit our contact form we collect the name, email address, company, website and message you provide, so we can reply to your enquiry. We also collect limited technical data (IP address, browser type, pages viewed) through server logs and privacy-friendly analytics to keep the site secure and understand which pages are useful.
3.2 Client and account data
For clients we hold business contact details, billing information, the websites and brands in scope, our correspondence, and the deliverables we produce for you.
3.3 Data from platforms you connect
To deliver our services we may ask you to connect accounts you own or lawfully manage, such as Google Search Console, Google Analytics, Google Business Profile, Facebook Pages and Instagram business accounts. We access this data through the platforms’ official APIs, using OAuth, and only after you grant consent. Sections 4 and 5 describe exactly what we access and why.
4. Google user data
This section describes how our application accesses, uses, stores and shares Google user data. It applies whenever you connect a Google Account to Nextware.
4.1 Scopes we request and why
We request only the scopes needed for the services you have engaged us for:
| Google OAuth scope | What it lets us access | Why we need it |
|---|---|---|
openid, userinfo.email, userinfo.profile | Your name, email address and profile picture | To identify which account is connected and display it in your dashboard and reports |
auth/webmasters.readonly | Google Search Console data: search queries, clicks, impressions, click-through rate, average position, indexing and coverage status for properties you own | To report your search performance, track keyword rankings and diagnose technical SEO and indexing problems |
auth/webmasters (only where sitemap and indexing support is included) | Submit and manage sitemaps for your verified properties | To submit sitemaps and help get corrected pages indexed as part of technical SEO work |
auth/analytics.readonly | Read-only access to your Google Analytics (GA4) reports and property configuration | To report sessions, traffic sources, conversions and channel performance alongside your search data |
auth/business.manage | Your Google Business Profile locations: business information, posts, photos, reviews, questions and answers, and performance insights | To publish Business Profile posts, keep business information accurate, respond to reviews on your instruction and report local performance |
If a service you have not purchased is not in scope, we do not request the related permission. You may grant a subset of permissions, though some features will not work without them.
4.2 Actions we take on your behalf
Where you have enabled the relevant service, we may act on your behalf to: submit sitemaps; publish, edit or remove Google Business Profile posts; update business information such as hours, description, services and photos; and publish replies to reviews that you or your team have approved. We keep a log of actions taken so you can audit them.
4.3 Limited Use commitment
Nextware Technologies’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we confirm that:
- We limit our use of Google user data to providing and improving the user-facing features that are prominent in the Nextware dashboard, reports and deliverables you receive.
- We do not transfer or sell Google user data to third parties such as advertising platforms, data brokers or information resellers.
- We do not use Google user data for serving advertisements, including retargeting, personalised or interest-based advertising.
- We do not use Google user data to determine credit-worthiness or for lending purposes.
- We do not use Google user data to develop, train or improve generalised artificial intelligence or machine learning models.
4.4 Human access to Google user data
We do not allow humans to read your Google user data except in these limited cases: (a) where you have given specific affirmative agreement, for example when you ask our support team to investigate an issue in your account; (b) where it is necessary for security purposes, such as investigating abuse or a suspected breach; (c) where we are required to do so to comply with applicable law; or (d) where the data is aggregated and anonymised, and used for internal operations in line with applicable privacy law. Access is restricted to authorised personnel on a least-privilege basis and is logged.
4.5 Storage and deletion of Google user data
We store OAuth tokens encrypted at rest and never expose them in reports or to other clients. We cache report data (for example rankings and traffic history) so your dashboard loads quickly and so we can show trends over time. When you disconnect your Google Account or terminate your engagement, we revoke the tokens and delete the associated Google user data within 30 days, except where we are legally required to keep a record. Residual copies in encrypted backups are purged within 90 days.
You can revoke our access at any time from your Google Account permissions page, or by disconnecting the integration with us, or by emailing us. Revoking access stops all future data access immediately.
5. Meta (Facebook and Instagram) data
Where social media management is part of your engagement, you may connect Facebook Pages and Instagram business accounts so we can schedule and publish content and report on performance.
5.1 Permissions we request and why
| Meta permission | What it lets us access | Why we need it |
|---|---|---|
public_profile, email | Basic profile of the person connecting | To identify who authorised the connection |
pages_show_list | The list of Pages you manage | So you can choose which Page to connect |
pages_read_engagement, read_insights | Page content, engagement and insights | To report reach, engagement and post performance |
pages_manage_posts | Create, edit, schedule and delete posts on your Page | To publish the content calendar we produce for you |
pages_manage_metadata | Page settings and webhook subscriptions | To receive updates about your Page and keep the connection healthy |
instagram_basic, instagram_manage_insights | Your Instagram business account profile, media and insights | To connect the account and report performance |
instagram_content_publish | Publish content to your Instagram business account | To publish scheduled posts and reels on your behalf |
business_management | Assets your business manages in Meta Business Manager | To connect Pages and Instagram accounts that are held in a client Business Manager |
5.2 How we use Meta data
We use this access solely to schedule and publish content you or your team has approved, to respond to messages and comments where you have asked us to, and to produce performance reports. We do not read or export private messages beyond what is needed for an agreed community-management service, we do not sell Meta data, we do not use it for advertising unrelated to your own campaigns, and we do not use it to train generalised AI models. We comply with the Meta Platform Terms and Developer Policies.
5.3 Storage, deletion and revoking access
Access tokens are encrypted at rest. Published content and performance metrics are retained for the life of the engagement so we can report on trends. You can remove our access at any time in Facebook Settings, Business Integrations or from your Instagram account settings. To request deletion of the data we hold, see our data deletion instructions. Deletion is free of charge.
6. How and why we use data
We use data to:
- deliver the services you engaged us for, including audits, optimisation, content, publishing and reporting;
- build the dashboards and reports that show your search, AI-visibility and social performance;
- communicate with you about your project, support requests and invoices;
- keep our systems secure, prevent abuse and debug faults;
- meet our legal, tax and accounting obligations.
Where the UK GDPR or EU GDPR applies, our legal bases are: performance of a contract (delivering our services), legitimate interests (running, securing and improving our business, where not overridden by your rights), consent (where you connect a platform account or accept non-essential cookies), and legal obligation (accounting and compliance).
7. Sharing and sub-processors
We do not sell your personal data, and we do not share it with data brokers or advertising networks. We share data only with service providers who help us run our business, under contract, and only to the extent needed. These currently include categories such as cloud hosting and infrastructure, email delivery, error monitoring and analytics, and, where relevant to your service, AI model providers (see section 8). A current list of sub-processors is available on request at info@nextwaretech.co.
We may also disclose data where required by law, to enforce our agreements, to protect our rights or users’ safety, or in connection with a merger or acquisition, in which case we will give notice before your data becomes subject to a different privacy policy. Any transfer of Google user data in a merger or acquisition will only occur with your explicit prior consent.
8. Artificial intelligence processing
We use AI tools to help draft content, analyse data and produce recommendations. Where content or data is processed by a third-party AI provider, we use business or enterprise tiers configured so that your data is not used to train the provider’s models. We do not send Google user data or Meta user data to AI providers for the purpose of model training, and we do not use it to develop or improve generalised AI or machine learning models. Human review is applied to AI-assisted output before it is published on your behalf.
9. How we protect data
- All data is transmitted over encrypted connections (TLS/HTTPS).
- OAuth tokens and credentials are encrypted at rest and are never displayed in reports or shared between clients.
- Access is restricted to authorised personnel on a least-privilege basis, protected by strong authentication.
- We log administrative access and actions taken on your accounts.
- We review permissions periodically and remove access that is no longer required.
No system is perfectly secure. If a breach affects your personal data we will notify you and any relevant regulator without undue delay, as required by applicable law.
10. How long we keep data
| Data | Retention |
|---|---|
| Contact form enquiries | 24 months from last contact, then deleted |
| OAuth access and refresh tokens | Deleted immediately on disconnection or termination |
| Google and Meta platform data (reports, metrics, cached data) | Deleted within 30 days of disconnection or termination |
| Encrypted backups | Purged within 90 days |
| Invoices and accounting records | As required by law, typically 6 to 7 years |
11. Your rights, deletion and revoking access
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent at any time. If you are in the EU or UK you may lodge a complaint with your supervisory authority. If you are a California resident, we confirm that we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising your rights.
To exercise any right, email info@nextwaretech.co. We respond within 30 days. We never charge a fee for deleting your data. Full step-by-step instructions, including how to disconnect Google and Meta and how to have your data erased, are on our data deletion page.
12. International transfers
We and our service providers may process data in countries other than your own. Where personal data protected by the EU or UK GDPR is transferred outside those areas, we rely on appropriate safeguards such as Standard Contractual Clauses, or on another lawful transfer mechanism.
13. Cookies
Our website uses essential cookies needed for the site to function and, where you consent, analytics cookies that help us understand which content is useful. We do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings.
14. Children
Our services are for businesses. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
15. Changes to this policy
If we change how we access, use, store or share your data, we will update this page and change the “last updated” date above. Where the change is material, or where we intend to use data in a way that differs from what you originally consented to, we will notify you and, where required, obtain renewed consent before the change takes effect.
16. Contact us
Questions, requests or complaints about privacy: info@nextwaretech.co. We aim to respond within 30 days. You can also write to us at either office:
- Dubai, UAE: IFZA Property FZCO, Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. Tel: +971 58 697 0330
- Faisalabad, Pakistan: Chak # 189 RB Rasoolpur, Chak Jhumra Road, Near Wapda City Canal Road, Faisalabad, Pakistan. Tel: 0311 4010806