Privacy Policy
Last updated: 2 August 2026
1. The short version
You give us your name, your email, a sentence describing your business idea, your logo, and sometimes a PDF. We use those things to do the work you paid for, and for nothing else.
We treat your business idea as confidential information, not as marketing data. We do not sell it, share it, publish it or train AI on it.
Your card details go straight to Stripe. We never see them.
2. Who we are
Duque LTD is the data controller for the personal data described here. We trade as Next Up.
- Company number: 13122478
- Registered office: International House, 12 Constance Street, London, E16 2DQ, United Kingdom
- Website: nextup.ae
- Privacy contact: hello@nextup.ae
Our team operates from Dubai, United Arab Emirates. The controller is still Duque LTD in the UK.
Data Protection Officer: we are below the threshold that requires one to be appointed. Privacy questions go to hello@nextup.ae, and are answered by the company's director.
EU representative (Article 27 GDPR): The First 72 is sold to businesses. Where we offer it to businesses established in the European Economic Area, an EU representative may be required; that appointment is under review and this section will name the representative once it is made.
3. Which law applies
We follow the UK GDPR and the Data Protection Act 2018.
Where we offer the Service to people in the European Economic Area, we also follow the EU GDPR.
4. What we collect, why, and on what legal basis
| Data | What it is | Why we have it | Legal basis | How long we keep it |
|---|---|---|---|---|
| Identity and contact | Your name, email address, and company name if you give one | To take your order, send your deliverables, and talk to you about them | Performance of a contract | 3 years after your last order |
| Your napkin | The sentence describing your business idea | To produce your First Version, Technical Scope and Fixed Build Quotation | Performance of a contract | See clause 7 |
| Your logo | The image file you upload | To design the First Version | Performance of a contract | See clause 7 |
| Your PDF | The optional document explaining your product | To understand the product we are shaping | Performance of a contract | See clause 7 |
| Payment data | Handled by Stripe. We receive only: a payment reference, the amount, the currency, the last four digits and brand of your card, the card country, the result, and your billing name and country | To take payment, issue your invoice, handle refunds and disputes | Performance of a contract, and legal obligation for tax and accounting records | 6 years from the end of the relevant financial year, for UK tax and company law |
| Account data | If you sign in with Google to view your delivery: your name, email address, Google account identifier, and profile picture | To let you log in and see your own delivery, and to keep other people out of it | Performance of a contract | 12 months after your last sign-in, then deleted |
| Correspondence | Emails and messages between us | To answer you and keep a record of what was agreed | Legitimate interests — running the business and being able to evidence what happened | 3 years |
| Marketing emails | Your email address, if you opt in | To send you occasional updates about Next Up | Consent | Until you unsubscribe, plus a suppression record kept indefinitely so we do not email you again |
| Technical logs | IP address, browser, device type, pages visited, timestamps — collected by our hosting provider | Security, fraud prevention, and keeping the site working | Legitimate interests — securing our systems | 30 days at the hosting layer |
| Fraud signals | Information Stripe collects to screen the payment | Preventing fraud and chargebacks | Legitimate interests, and legal obligation on our payment provider | Held by Stripe under its own policy |
We do not collect special category data. Please do not send us any. If your napkin or your PDF necessarily involves health data, biometric data, or similar, tell us before you upload so we can handle it properly.
A note on legitimate interests
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded ours does not override yours. We use it only for security, record-keeping and answering you. Ask us at hello@nextup.ae and we will explain the assessment.
5. Your business idea is confidential
We want to be specific about this, because it is the thing you are most likely to worry about.
Your napkin, and anything in your uploaded PDF, is confidential information. We treat it under the confidentiality obligations in our Terms of Service, not as ordinary customer data.
Concretely:
- It is used only to produce your deliverables.
- It is not used for market research, trend analysis, product development or anything else internal.
- It is not shared with any other client.
- It is not sold, licensed or traded.
- It is not used to train any AI or machine learning model, ours or anyone else's.
- It is published nowhere, unless you give specific written permission for that use. See the Terms of Service, clause 13.2.
- It is not used for marketing to you or to anyone else.
Access is limited to the members of our team who are working on your project.
6. Who we share data with
We do not sell your personal data. We do not share it with advertising networks or data brokers.
We share it only with the following, and only as far as they need it:
| Who | What they do | What they get |
|---|---|---|
| Stripe | Processes your payment | Your name, email, billing details, card details entered directly with them, the amount, and technical fraud signals. Stripe is an independent controller for parts of this. Its policy: stripe.com/privacy |
| Sign-in, if you choose to use it | Confirms your identity to us and gives us your name, email, Google account ID and profile picture. Google's policy: policies.google.com/privacy | |
| Resend | Sends your order confirmation, your delivery notice, and our replies | Your email address and the content of those messages. Its policy: resend.com/legal/privacy-policy |
| Vercel | Hosts the website | Technical request logs |
| Google Cloud / Firebase | Stores your napkin, your uploaded files and your account record | Everything you submit through the form. Its policy: cloud.google.com/terms/cloud-privacy-notice |
| Our accountants and professional advisers | Bookkeeping, tax filing, legal advice if needed | Invoice and payment records |
| Authorities | Where the law requires it | Only what the law requires |
Each provider we use is bound by a written contract that meets Article 28 UK GDPR, requires them to act only on our instructions, and requires appropriate security.
If we are ever acquired or merged, your data may transfer to the buyer. We would tell you first, and the buyer would be bound by this policy.
7. How long we keep your files
Your uploaded logo and PDF, and your napkin, are kept:
- Files uploaded to a checkout you did not complete: deleted automatically 30 days after upload. Nothing is ever sent to you about them, and no account is created.
- Working copies: deleted 90 days after we deliver, unless you ask us to keep them because we are quoting for follow-on work.
- Delivery archive: we keep a copy of your deliverables and the napkin they were based on for 12 months so you can ask us to resend them, and so we can defend a complaint or dispute.
- On request: you can ask us to delete them earlier, at any time, and we will, unless we need to keep something for a legal reason. We will tell you if that is the case.
Financial records connected to your payment are kept for 6 years from the end of the relevant financial year, because UK tax and company law requires it. Those records contain your name, the amount and the date — not your napkin or your files.
8. International transfers
This is worth explaining, because our setup crosses borders.
- Duque LTD is established in the United Kingdom.
- Our team works from the United Arab Emirates, so personal data is accessed from there.
- Some of our providers are in the United States or the European Economic Area.
The UAE is not covered by a UK adequacy decision or an EU adequacy decision. So when data is accessed from or transferred to the UAE, or to any other country without adequacy, we rely on:
- the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, for transfers out of the UK;
- the EU Standard Contractual Clauses for transfers of data covered by the EU GDPR;
- a transfer risk assessment for each of these; and
- supplementary measures where the assessment calls for them, including encryption in transit and at rest, and access limited to named people.
Where a country does have an adequacy decision, or a provider is covered by the EU-US Data Privacy Framework and its UK extension, we rely on that instead.
You can ask us for a copy of the transfer mechanism we rely on for any specific provider. Email hello@nextup.ae.
9. Security
We protect your data with:
- encryption in transit (HTTPS) and at rest;
- access limited to the team members who need it, with individual accounts;
- two-factor authentication on the accounts that hold your data;
- no storage of card details anywhere in our systems;
- deletion on the schedule set out above.
No system is perfectly secure. If a breach happens that is likely to put your rights at risk, we will tell the ICO within 72 hours and tell you without undue delay.
10. Your rights
Under the UK GDPR and the EU GDPR you have the right to:
- Be told what we do with your data — that is this document.
- Access a copy of the personal data we hold about you.
- Rectify anything that is wrong or incomplete.
- Erase your data ("right to be forgotten"), where we have no overriding reason to keep it.
- Restrict how we use it while a dispute about it is resolved.
- Portability — receive the data you gave us in a common machine-readable format, or have us send it to someone else.
- Object to processing based on legitimate interests, including a general right to object to direct marketing at any time.
- Withdraw consent at any time, where we rely on consent — for publication permissions and for marketing emails. Withdrawing does not undo what we did lawfully before you withdrew.
How to exercise them
Email hello@nextup.ae. Say what you want. We may ask you to confirm your identity so we do not hand your data to the wrong person.
We respond within one month. If your request is complex we may extend that by up to two further months, and we will tell you why within the first month.
It is free. We only charge if a request is manifestly unfounded or excessive, and we would explain first.
Automated decisions
We do not make automated decisions with legal or similarly significant effects about you.
Stripe runs automated fraud screening on payments, which can cause a payment to be declined. If that happens to you, contact us and we will look at it manually.
Complaining
If you think we have handled your data badly, tell us first — we would rather fix it.
You also have the right to complain to a supervisory authority:
- United Kingdom: the Information Commissioner's Office, at ico.org.uk, where you will find its current address, phone number and online complaint form.
- European Economic Area: the data protection authority in the country where you live or work, or where you think the problem happened.
Complaining to a regulator does not stop you also going to court.
11. Cookies and tracking
What is true today
The Next Up site is a static site with no analytics, no advertising pixels, and no third-party tracking.
The only cookies and similar storage in use are the strictly necessary ones:
| What | Who sets it | Why |
|---|---|---|
| Session cookie | Us | Keeps you signed in if you log in with Google to see your delivery |
| Google sign-in cookies | Authenticates you when you use "Sign in with Google" | |
| Stripe cookies | Stripe | Set on the Stripe payment page. Used to process the payment and detect fraud. Stripe considers these necessary for its service |
Strictly necessary cookies do not need your consent under the UK Privacy and Electronic Communications Regulations (PECR) or the EU ePrivacy rules, so we do not show a cookie banner. You can block cookies in your browser, but sign-in and payment will stop working.
What changes if we add analytics
Adding analytics, advertising, heat maps, live chat or any other third-party script would mean three things happen first: this table gains a row naming the provider, the purpose, the cookie lifetime and the country; a consent banner goes up with a real option to decline, because PECR requires consent before a non-essential cookie is set; and the date at the top of this document changes.
Until all three are done, the site stays as it is.
12. Marketing
We only email you about your order unless you opt in to something else.
If you do opt in, every email has an unsubscribe link and it works immediately.
13. Children
The Service is for people aged 18 and over. We do not knowingly collect data about children. If you think a child has given us data, tell us at hello@nextup.ae and we will delete it.
14. Changes to this policy
We update this policy when what we do changes. The current version is always at https://nextup.ae/privacy, with the date at the top.
If a change materially affects you — a new processor holding your files, a new purpose, a new legal basis — we will email you before it takes effect.
Duque LTD International House, 12 Constance Street, London, E16 2DQ, United Kingdom Registered in England and Wales, company number 13122478 Trading as Next Up — nextup.ae
