Skip to content
NEXT MISSIONSYSTEMS
SolutionsFor educationFor Defense and securityPilot programAbout usContactSchedule a meeting
Schedule a meeting
Legal information

Privacy statement

This statement explains which personal data Next Mission Systems processes, why we process it, and what choices and rights you have.

Last updated: August 4, 2026.

On this page

  • 1. Who is responsible?
  • 2. When does this statement apply?
  • 3. What personal data do we process?
  • 4. Purposes and legal bases
  • 5. Contact form, transmission, and storage
  • 6. Cookies and local storage
  • 7. Who do we share data with?
  • 8. Transfers outside the European Economic Area
  • 9. Retention periods
  • 10. Security
  • 11. Your privacy rights
  • 12. Automated decision-making
  • 13. Changes
On this page
  • 1. Who is responsible?
  • 2. When does this statement apply?
  • 3. What personal data do we process?
  • 4. Purposes and legal bases
  • 5. Contact form, transmission, and storage
  • 6. Cookies and local storage
  • 7. Who do we share data with?
  • 8. Transfers outside the European Economic Area
  • 9. Retention periods
  • 10. Security
  • 11. Your privacy rights
  • 12. Automated decision-making
  • 13. Changes

1. Who is responsible?

Next Mission Systems is the controller of the personal data described in this statement.

Next Mission Systems
Herengracht 124-128
Amsterdam, The Netherlands
support@nextmissionsystems.com

2. When does this statement apply?

This statement applies when you visit our website, save your language or privacy preference, use our contact form, or communicate with us for business purposes.

3. What personal data do we process?

When you submit an inquiry, we process your name, organization, job title, business email address, optional phone number, organization type, area of interest, message, source page, and submission reference. If the communication leads to a business relationship, we may also process information needed for proposals, agreements, performance, invoicing, and administration.

For security and abuse prevention, technical data may be processed, such as browser information and a temporarily hashed combination of IP address and user agent. Our contact code does not store or log the raw IP address. Hosting and infrastructure providers may maintain their own access and security logs.

4. Purposes and legal bases

We process personal data for the following purposes:

  • responding to your inquiry and staying in contact with you;
  • preparing proposals and taking steps at your request before entering into an agreement;
  • performing agreements and maintaining our business records;
  • securing the website and limiting spam, abuse, and duplicate submissions;
  • remembering your language and privacy preferences;
  • complying with legal obligations and handling legal claims.

Depending on the circumstances, we rely on your consent, steps taken at your request before entering into an agreement, performance of an agreement, a legal obligation, or our legitimate interests in business communication, security, and the proper operation of the website. You may withdraw consent at any time; this does not affect the lawfulness of processing carried out before withdrawal.

5. Contact form, transmission, and storage

The contact form sends your information through a server-side connection to Microsoft Exchange Web Services. The received email and the copy in the sending mailbox’s Sent Items folder form the durable record of the inquiry. The contact endpoint does not store your inquiry in Supabase or another application database.

For rate limiting, the application stores a non-reversible technical fingerprint in server memory for no more than 15 minutes. After a successful submission, a submission reference remains in server memory for no more than 24 hours to prevent duplicate delivery.

6. Cookies and local storage

The website uses only the following functional storage while no separate analytics provider is active:

  • nms-locale: a first-party cookie that stores your language choice (Dutch or English) for one year. The cookie is HTTP-only, SameSite Lax, and sent securely over HTTPS only.
  • nms-cookie-choice: local browser storage that remembers whether you selected necessary storage only or also analytics. This value remains until you clear the website data in your browser.

No analytics provider is currently active, and the website does not set tracking or advertising cookies. Non-essential analytics will be activated only after you have consented and this statement has been updated with the relevant provider, data, purposes, and retention periods.

You can change your language with the language selector. You can make your privacy choice again by clearing the website’s local data in your browser. Refusing non-essential storage does not restrict access to the website.

7. Who do we share data with?

We do not sell your personal data. Access is limited to employees and service providers who need the data for their work. These may include hosting, infrastructure, security, email, and professional-support providers. They may process the data only under our instructions, an agreement, or a legal obligation. We may share data with competent authorities when required by law.

8. Transfers outside the European Economic Area

If a service provider processes personal data outside the European Economic Area, we use a legally permitted transfer mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, and take additional measures where necessary.

9. Retention periods

  • We delete inquiries that do not result in an agreement no later than 12 months after the last substantive contact.
  • We retain data that becomes part of an agreement or tax records for the term of the agreement and for seven years afterward, or longer when required by law or an ongoing legal claim.
  • We retain technical abuse-prevention data for no more than 15 minutes for rate limiting and no more than 24 hours to recognize a duplicate successful submission.
  • The language cookie is retained for one year. The local privacy preference remains on your device until you clear the website data.

10. Security

We take appropriate technical and organizational measures to protect personal data against loss, unauthorized access, alteration, and disclosure. No internet connection or storage method is entirely risk-free.

11. Your privacy rights

To the extent provided by the GDPR, you may request access to, correction, deletion, restriction, or portability of your personal data. You may object to processing based on a legitimate interest and withdraw consent. Send your request to support@nextmissionsystems.com. We may request additional information to verify your identity and generally respond within one month.

You may also lodge a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl.

12. Automated decision-making

We do not make decisions that produce legal or similarly significant effects based solely on automated processing of personal data.

13. Changes

We may update this statement when our practices, website, or legal obligations change. The most recent version is always available on this page. We will clearly announce material changes on the website.

NEXT MISSIONSYSTEMS

Technology for tomorrow's missions

Modern learning, simulation, and training environments for education, Defense and security, and technology partners.

Solutions

  • Drone Mission Lab
  • For education
  • For Defense and security
  • Pilot program

Organization

  • About us
  • Partners
  • Contact

Legal

  • Privacy statement
  • Terms and conditions

Contact

124-128 Herengracht,
Amsterdam, The Netherlands

support@nextmissionsystems.comSchedule a meeting
© 2026 Next Mission Systems. All rights reserved.
Enter the Next Mission.