1. Who is responsible
Dr.CMO at cmo.doctor is operated by NEXTED GROUP S.L., NIF B56576259, VAT ID ESB56576259, Calle Gregal, 8, Betera, Valencia, Spain 46117. NEXTED GROUP S.L. is responsible for the personal data it processes to operate this website and provide the service.
Contact service@nextmba.com, with “Dr.CMO” in the subject, or write to NEXTED GROUP S.L., Calle Gregal, 8, Betera, Valencia, Spain 46117. For general enquiries, call +34 667 939 082.
This policy covers visitors, workspace users and people whose information appears in business material used for research. If you intend to submit personal data on behalf of another organisation, contact us first to agree any required processing instructions and contractual safeguards.
2. Information we process
| Information | Examples and sources |
|---|---|
| Workspace identity | A random browser identifier for guest workspaces. Supported ChatGPT sign-in supplies a user ID, email and, where available, a name. |
| Business and public-source information | The website address you submit; public page text, business details, brand images, search results and competitor or advertising research. These sources can include names and professional contact information. |
| Workspace content | Your messages, instructions, business preferences, research, tasks, generated text and images, revisions, approvals and records of requested actions. |
| Optional connections | For WordPress: the site address, username, application password and records of delivery or publication. |
| Support and transactions | Information you provide when contacting us, and order, invoice, cancellation or refund details where a transaction takes place. |
| Technical information | Request and browser information used by hosting infrastructure, including network information, and operational errors needed to deliver and protect the service. |
3. Purposes and legal bases
We use submitted websites and workspace material to analyse your business, prepare research, respond to instructions and produce marketing materials. We process information necessary to provide a service you request or perform our contract with you. Optional connections are used to carry out the actions you request.
Where you act for a business, our legitimate interests are to provide that business with its requested service and communicate with its representatives. We also rely on legitimate interests for proportionate public business research, service security and resolving technical problems, taking account of the rights and reasonable expectations of affected people.
We process records where necessary to meet applicable legal obligations, including accounting and responding to lawful requests. Where a separate optional activity requires consent, we request it for that activity. Reading this policy is not consent to unrelated marketing.
A website address and a workspace identifier are needed to create and retrieve a website-based workspace. Connections are optional, but their associated actions cannot operate without the connection information. Do not place passwords, sensitive personal data or customer databases in chat prompts.
4. AI and external providers
The CMO and nine specialist personas are AI software. Relevant instructions, website evidence, research and reference images are sent to AI services to produce responses and materials. The service supports marketing work; it is not designed to make decisions about an individual’s employment, credit or access to essential services.
Providers receive information when the corresponding feature is used. A public website researched by our servers receives a request for its public pages or assets. This is separate from browser tracking.
| Provider or destination | Purpose |
|---|---|
| Cloudflare and Sites hosting | Website delivery, request handling, workspace database and generated-media storage. |
| OpenAI | AI analysis and text/image generation from relevant instructions and evidence; optional ChatGPT identity. |
| Scrappa | Search and public research using domains, business names and research queries. |
| Apify | Collection of public advertising or website information using research parameters. |
| Connected WordPress site | Authentication and sending the specific content and action you approve. |
| MONEI, where you make a payment | Processing the transaction and related payment status, fraud-prevention and refund information. The payment flow identifies the information requested for that transaction. |
5. International processing
Our providers operate internationally, so information may be processed outside your country, including outside the European Economic Area. This service does not promise that all processing takes place in Spain or exclusively in the EEA.
Where GDPR protections for an international transfer apply, the transfer must have a valid basis, such as an applicable adequacy decision or appropriate contractual safeguards. You can contact us for information about the recipients and safeguards applicable to your use of the service, including how to obtain a copy where available. A provider’s location alone does not establish that a particular transfer is covered by an adequacy decision.
6. Retention and security
Workspace information is stored so you can return to your work. Retention depends on whether information remains necessary to provide the requested workspace, resolve a support or security issue, meet a legal obligation or establish or defend a legal claim. Information that is no longer required for those purposes should be deleted or anonymised.
The guest cookie expires after up to 30 days. This is not a server-data deletion period. Workspace records can remain after inactivity or loss of the cookie; clearing browser storage can remove your ability to reopen a guest workspace without erasing its server records. Contact us to request deletion.
Where a deletion request is granted, it covers information under our control, subject to applicable legal retention exceptions and the handling of backups and copies held by processors. Data already published to your own website or copied to a separate service is also subject to that destination’s controls.
Guest identifiers are issued by the server. WordPress application passwords are encrypted in application storage. Disconnecting WordPress removes the saved connection; you can also revoke the application password in WordPress. No internet service can promise absolute security.
7. Your rights
Subject to the conditions in applicable law, you may request access, correction, erasure, restriction or a portable copy of your personal data, and object to processing based on legitimate interests. If processing relies on consent, you may withdraw that consent without affecting the lawfulness of earlier processing.
Contact service@nextmba.com, with “Dr.CMO” in the subject, or write to NEXTED GROUP S.L., Calle Gregal, 8, Betera, Valencia, Spain 46117. For general enquiries, call +34 667 939 082. Include your workspace website and the email used for the service, where applicable. We may request proportionate evidence to verify your identity. Never send session cookies, application passwords or full card details.
For GDPR requests, we normally respond within one month. If the law permits an extension because of complexity or the number of requests, we will explain it within that first month. A refusal or limitation will be explained with the available complaint options.
You may complain to the Spanish Data Protection Agency (AEPD), or another competent authority, including the authority where you live or work in the EEA. You do not have to contact us first.