Next Up

Privacy Policy

Last updated: 2 August 2026

1. The short version

You give us your name, your email, a sentence describing your business idea, your logo, and sometimes a PDF. We use those things to do the work you paid for, and for nothing else.

We treat your business idea as confidential information, not as marketing data. We do not sell it, share it, publish it or train AI on it.

Your card details go straight to Stripe. We never see them.

2. Who we are

Duque LTD is the data controller for the personal data described here. We trade as Next Up.

Our team operates from Dubai, United Arab Emirates. The controller is still Duque LTD in the UK.

Data Protection Officer: we are below the threshold that requires one to be appointed. Privacy questions go to hello@nextup.ae, and are answered by the company's director.

EU representative (Article 27 GDPR): The First 72 is sold to businesses. Where we offer it to businesses established in the European Economic Area, an EU representative may be required; that appointment is under review and this section will name the representative once it is made.

3. Which law applies

We follow the UK GDPR and the Data Protection Act 2018.

Where we offer the Service to people in the European Economic Area, we also follow the EU GDPR.

4. What we collect, why, and on what legal basis

DataWhat it isWhy we have itLegal basisHow long we keep it
Identity and contactYour name, email address, and company name if you give oneTo take your order, send your deliverables, and talk to you about themPerformance of a contract3 years after your last order
Your napkinThe sentence describing your business ideaTo produce your First Version, Technical Scope and Fixed Build QuotationPerformance of a contractSee clause 7
Your logoThe image file you uploadTo design the First VersionPerformance of a contractSee clause 7
Your PDFThe optional document explaining your productTo understand the product we are shapingPerformance of a contractSee clause 7
Payment dataHandled by Stripe. We receive only: a payment reference, the amount, the currency, the last four digits and brand of your card, the card country, the result, and your billing name and countryTo take payment, issue your invoice, handle refunds and disputesPerformance of a contract, and legal obligation for tax and accounting records6 years from the end of the relevant financial year, for UK tax and company law
Account dataIf you sign in with Google to view your delivery: your name, email address, Google account identifier, and profile pictureTo let you log in and see your own delivery, and to keep other people out of itPerformance of a contract12 months after your last sign-in, then deleted
CorrespondenceEmails and messages between usTo answer you and keep a record of what was agreedLegitimate interests — running the business and being able to evidence what happened3 years
Marketing emailsYour email address, if you opt inTo send you occasional updates about Next UpConsentUntil you unsubscribe, plus a suppression record kept indefinitely so we do not email you again
Technical logsIP address, browser, device type, pages visited, timestamps — collected by our hosting providerSecurity, fraud prevention, and keeping the site workingLegitimate interests — securing our systems30 days at the hosting layer
Fraud signalsInformation Stripe collects to screen the paymentPreventing fraud and chargebacksLegitimate interests, and legal obligation on our payment providerHeld by Stripe under its own policy

We do not collect special category data. Please do not send us any. If your napkin or your PDF necessarily involves health data, biometric data, or similar, tell us before you upload so we can handle it properly.

A note on legitimate interests

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded ours does not override yours. We use it only for security, record-keeping and answering you. Ask us at hello@nextup.ae and we will explain the assessment.

5. Your business idea is confidential

We want to be specific about this, because it is the thing you are most likely to worry about.

Your napkin, and anything in your uploaded PDF, is confidential information. We treat it under the confidentiality obligations in our Terms of Service, not as ordinary customer data.

Concretely:

Access is limited to the members of our team who are working on your project.

6. Who we share data with

We do not sell your personal data. We do not share it with advertising networks or data brokers.

We share it only with the following, and only as far as they need it:

WhoWhat they doWhat they get
StripeProcesses your paymentYour name, email, billing details, card details entered directly with them, the amount, and technical fraud signals. Stripe is an independent controller for parts of this. Its policy: stripe.com/privacy
GoogleSign-in, if you choose to use itConfirms your identity to us and gives us your name, email, Google account ID and profile picture. Google's policy: policies.google.com/privacy
ResendSends your order confirmation, your delivery notice, and our repliesYour email address and the content of those messages. Its policy: resend.com/legal/privacy-policy
VercelHosts the websiteTechnical request logs
Google Cloud / FirebaseStores your napkin, your uploaded files and your account recordEverything you submit through the form. Its policy: cloud.google.com/terms/cloud-privacy-notice
Our accountants and professional advisersBookkeeping, tax filing, legal advice if neededInvoice and payment records
AuthoritiesWhere the law requires itOnly what the law requires

Each provider we use is bound by a written contract that meets Article 28 UK GDPR, requires them to act only on our instructions, and requires appropriate security.

If we are ever acquired or merged, your data may transfer to the buyer. We would tell you first, and the buyer would be bound by this policy.

7. How long we keep your files

Your uploaded logo and PDF, and your napkin, are kept:

Financial records connected to your payment are kept for 6 years from the end of the relevant financial year, because UK tax and company law requires it. Those records contain your name, the amount and the date — not your napkin or your files.

8. International transfers

This is worth explaining, because our setup crosses borders.

The UAE is not covered by a UK adequacy decision or an EU adequacy decision. So when data is accessed from or transferred to the UAE, or to any other country without adequacy, we rely on:

Where a country does have an adequacy decision, or a provider is covered by the EU-US Data Privacy Framework and its UK extension, we rely on that instead.

You can ask us for a copy of the transfer mechanism we rely on for any specific provider. Email hello@nextup.ae.

9. Security

We protect your data with:

No system is perfectly secure. If a breach happens that is likely to put your rights at risk, we will tell the ICO within 72 hours and tell you without undue delay.

10. Your rights

Under the UK GDPR and the EU GDPR you have the right to:

How to exercise them

Email hello@nextup.ae. Say what you want. We may ask you to confirm your identity so we do not hand your data to the wrong person.

We respond within one month. If your request is complex we may extend that by up to two further months, and we will tell you why within the first month.

It is free. We only charge if a request is manifestly unfounded or excessive, and we would explain first.

Automated decisions

We do not make automated decisions with legal or similarly significant effects about you.

Stripe runs automated fraud screening on payments, which can cause a payment to be declined. If that happens to you, contact us and we will look at it manually.

Complaining

If you think we have handled your data badly, tell us first — we would rather fix it.

You also have the right to complain to a supervisory authority:

Complaining to a regulator does not stop you also going to court.

11. Cookies and tracking

What is true today

The Next Up site is a static site with no analytics, no advertising pixels, and no third-party tracking.

The only cookies and similar storage in use are the strictly necessary ones:

WhatWho sets itWhy
Session cookieUsKeeps you signed in if you log in with Google to see your delivery
Google sign-in cookiesGoogleAuthenticates you when you use "Sign in with Google"
Stripe cookiesStripeSet on the Stripe payment page. Used to process the payment and detect fraud. Stripe considers these necessary for its service

Strictly necessary cookies do not need your consent under the UK Privacy and Electronic Communications Regulations (PECR) or the EU ePrivacy rules, so we do not show a cookie banner. You can block cookies in your browser, but sign-in and payment will stop working.

What changes if we add analytics

Adding analytics, advertising, heat maps, live chat or any other third-party script would mean three things happen first: this table gains a row naming the provider, the purpose, the cookie lifetime and the country; a consent banner goes up with a real option to decline, because PECR requires consent before a non-essential cookie is set; and the date at the top of this document changes.

Until all three are done, the site stays as it is.

12. Marketing

We only email you about your order unless you opt in to something else.

If you do opt in, every email has an unsubscribe link and it works immediately.

13. Children

The Service is for people aged 18 and over. We do not knowingly collect data about children. If you think a child has given us data, tell us at hello@nextup.ae and we will delete it.

14. Changes to this policy

We update this policy when what we do changes. The current version is always at https://nextup.ae/privacy, with the date at the top.

If a change materially affects you — a new processor holding your files, a new purpose, a new legal basis — we will email you before it takes effect.

Duque LTD International House, 12 Constance Street, London, E16 2DQ, United Kingdom Registered in England and Wales, company number 13122478 Trading as Next Up — nextup.ae