Legal
Terms, privacy and data processing for a Fieldlock desk
NextFluent BV. Registered office: Lange Gasthuisstraat 29, 2000 Antwerp. VAT BE 0760.605.308. Belgian law. This page was last updated on 4 October 2026.
Terms of Service
Company terms: Terms of Service. Fieldlock is an invite-only desk under those terms, with this addition:
- There is no public sign-up. We create an invite login after you write to us from the contact page.
- A Fieldlock desk is €2,400 per year for one seat, unless we agree otherwise in writing.
- A client page for one client is €1,200 per year, on top of the desk. The desk with that page is €3,600 per year. Each further client is another €1,200 per year. We agree the client page in writing before access is opened.
- You choose, study by study, whether a client may ask questions on their page. A client who asks receives question wording and counts for that study only. The response file is never sent to the client page. Every question a client asks is recorded on your desk.
- You remain the controller of codebook and response files you upload. You confirm that you may upload them and that they carry no more personal data than the study needs. Strip direct identifiers such as respondent names, email addresses and phone numbers before you upload. The desk counts answers, not people.
- Upload those files in Fieldlock over HTTPS. Do not send codebook or response files by email.
- The data processing agreement on this page is part of these terms and governs how we handle personal data in your studies.
- We load the study, bind each question to one field, and return a number or refuse. We do not sell your study.
- You may load more than one study on that login. The same English may run across those studies. Each study keeps its codebook. Percentages are not blended across studies.
- If we cannot load a file so that it answers from its own fields, we do not take the money.
- Either party may end a desk at the end of the paid year. Unused time is not refunded unless we fail to provide the service.
- Belgian law applies. Disputes go to the courts of Antwerp.
Privacy
This is the privacy notice for the Fieldlock site, the Fieldlock desk and the client page. It says what we hold about you, why, for how long, who else touches it, and what you can ask of us. NextFluent BV also publishes a company-wide privacy statement that covers its other work.
Who is responsible
NextFluent BV, Lange Gasthuisstraat 29, 2000 Antwerp, Belgium. VAT BE 0760.605.308. Write to hello@nextfluent.com for anything about your data, or to trust@nextfluent.com for security. We have not appointed a data protection officer; the law does not require one at our size, and the people who answer those two addresses handle every request themselves.
What we process, why, and for how long
| When | What | Why and on what basis | How long |
|---|---|---|---|
| You visit this site | The host records each request: IP address, time, page, browser type. Nothing else. No analytics, no tracking cookies, no fonts or scripts from third parties. | To serve the pages and stop abuse. Legitimate interest (Art. 6(1)(f) GDPR). | The host keeps request logs for a matter of hours on our plan. We do not export them. |
| You try the sample or your own file | The Harborline sample and the “your own file” desk run in your browser tab. Your file is read and counted there and is never sent to us. | Nothing reaches us. No legal basis is needed because no processing by us takes place. | Held in the tab’s memory. Close the tab and it is gone. |
| You write to us | First and last name, work email, company, what you are writing about, your message. | To reply and to set up a desk if you ask for one. Your consent, given with the box on the form (Art. 6(1)(a)), and the steps you ask us to take before a contract (Art. 6(1)(b)). You can withdraw consent at any time by writing to us; we then delete the request. | Twelve months after our last exchange about it, then deleted. If a desk is opened, the request becomes part of that account record. |
| You have a desk | Account email, sign-in events, and the records you create: studies, fields, pairs, pins, waves, receipts, and the cards you send to a client page. | To run the desk you pay for. Performance of the contract with your agency (Art. 6(1)(b)). | For the paid year of the desk and until you ask us to delete it, then deleted within 30 days. Invoicing records are kept for as long as Belgian accounting and VAT law requires. |
| You use a client page | Your work email for the sign-in link, the cards sent to you, the questions you type and what came back. | We process this for the agency that gave you the page. The agency is the controller and its own privacy notice applies next to this one. Legal basis: the agency’s contract with you or its legitimate interest in reporting to you. | For as long as the agency keeps the page open, and until the agency asks us to delete it. |
| Your agency uploads a study | Codebooks and response files. These may contain personal data of the people who answered the survey. | We process them only on the agency’s instructions, as processor, under the data processing agreement below. The agency is the controller for its respondents. | As set out in the data processing agreement. |
The contact form is the only form on this site. The fields marked required are the ones we need to answer you; without them we cannot reply. Do not put a codebook or a response file in the message. We do not accept study files by email.
Who else touches the data
- Supabase, for the database, sign-in and file storage. The project is in Frankfurt, Germany.
- Vercel, for hosting. Server code for the desk runs in Vercel’s Frankfurt region. Pages are served from the location nearest to you.
- No advertising network, no analytics company, no form-hosting company and no language-model provider. We do not sell data and we do not share it for marketing.
- A public authority, when the law obliges us to.
Transfers outside the European Economic Area
Supabase and Vercel are companies with a head office in the United States. The data itself is stored and processed in the EU as described above. Where their staff could reach it from outside the EU, for example for support, our contracts with them include the EU Standard Contractual Clauses, and Vercel is also certified under the EU-US Data Privacy Framework. We do not transfer your data outside the EEA on our own account.
Your rights
You can ask us for a copy of the data we hold about you, to correct it, to delete it, to limit what we do with it, to hand it over in a usable format, and to object to processing we base on legitimate interest. Where we rely on your consent you can withdraw it at any time, without affecting what was done before. Write to hello@nextfluent.com. We answer within one month and may ask you to confirm who you are first. Where we act as processor for an agency, we pass your request to the agency without undue delay and help it answer.
If you think we have handled your data wrongly, you can complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, +32 (0)2 274 48 00, contact@apd-gba.be, www.gegevensbeschermingsautoriteit.be, or to the authority in the country where you live or work.
What we do not do
- No decision about you is made automatically, and we do not build profiles of visitors or users.
- We do not send codebook or response data to ChatGPT or any other language model to produce a number. Receipts are marked
model=noneon that path. - The site and the desk are for businesses. We do not knowingly process data of children.
How we protect it
TLS on every connection. Encryption at rest with the host. Invite-only accounts. Row-level isolation per organisation in the database. Access to production systems is limited to named people at NextFluent and is logged by the hosts. When this page changes we update the date at the top.
Trust
This is the Fieldlock trust note. It covers the desk and, if we open one, the client page.
- CSA STAR Level 1, as published with the company.
- The founder holds the Cloud Security Alliance Trusted AI Safety Expert (TAISE) certificate.
- Database, auth, and file storage in the EU (Supabase, Frankfurt). Server code runs in Vercel’s Frankfurt region.
- Invite-only accounts. No public registration. You write to us, we open a login, and you upload in the desk. Never by email.
- Row-level isolation per organisation in Supabase.
- TLS in transit. Encryption at rest with the host.
- Access to production systems is limited to named people at NextFluent and logged by the hosts.
- No ChatGPT, and no other language model, on the Fieldlock number path.
- Subprocessors that process study data: Supabase (EU, Frankfurt) and Vercel. Not a language-model provider.
- If we learn of a breach that touches your data, we tell you without undue delay, with what we know at that point.
- We keep a record of our processing activities and make it available to customers on request.
- SOC 2 Type I is in progress at company level. It is not a claim for this app yet.
Security: trust@nextfluent.com.
Data Processing Agreement
This is the Fieldlock data processing agreement under Article 28 of the GDPR. It applies to the desk and, if we open one, the client page, and it forms part of the terms above. Belgian law. NextFluent BV, Lange Gasthuisstraat 29, 2000 Antwerp.
- Roles. You, the agency with the desk, are the controller of personal data in a codebook or response file you upload and of the people you give access to. NextFluent BV is the processor.
-
Subject, duration, nature and purpose. We
load your study, bind each English question to one field or
refuse, count rows of the file, print the figure with its
wording and base, and keep a SHA-256 receipt marked
model=none. We do this for the paid term of the desk and until the data is deleted under clause 11. - Data and people concerned. Account emails and sign-in events of your staff. Codebook fields, pairs, pins, waves, receipts and sent cards. Response files, and whatever personal data of your survey respondents they contain. On a client page: the work email of your client’s staff, the cards you sent, the questions they typed and what came back. You strip direct identifiers from response files before upload.
- Instructions. We process personal data only on your documented instructions: this agreement, the functions of the desk as you use them, and written instructions sent to trust@nextfluent.com. We tell you if we believe an instruction breaks the law. We do not use your data for our own purposes, do not train anything on it, and do not send it to a language model.
- Confidentiality. Only named people at NextFluent who need access to run the service have it, and each is bound by a duty of confidentiality.
- Security. TLS in transit. Encryption at rest with the host. Invite-only accounts with no public registration. Row-level isolation per organisation. Logged access to production. Study files never leave the EU hosts described here, and we never accept them by email.
- Subprocessors. You authorise Supabase (EU, Frankfurt: database, authentication, file storage) and Vercel (application hosting, server code in the Frankfurt region). We will tell you in writing at least 30 days before adding or replacing a subprocessor that processes your study data. You may object on reasonable grounds; if we cannot resolve the objection, you may end the desk and we refund the unused time. We bind every subprocessor in writing to obligations no weaker than these.
- Transfers. Data is stored and processed in the EU. Our contracts with Supabase and Vercel include the EU Standard Contractual Clauses for any access from outside the EU, and Vercel is certified under the EU-US Data Privacy Framework. We make no transfer outside the EEA on our own account.
- Help with your duties. We forward any request from a data subject that reaches us to you without undue delay and help you answer it within the limits of the desk. We help with a data protection impact assessment or a consultation with the authority where it concerns our processing.
- Personal data breach. If we become aware of a breach that touches your data, we tell you without undue delay, with what we know at that point, and follow up as we learn more, so that you can meet your own 72-hour deadline.
- End of the service. When the desk ends, or earlier if you ask, we delete your study data, or return it to you first if you ask before the end, within 30 days, except records the law requires us to keep. The hosts’ backups roll off on their own schedule after that.
- Showing compliance. On request we give you the information needed to show that we meet this agreement, including our hosts’ independent reports. You, or an auditor you appoint who is bound by confidentiality, may audit once a year on 30 days’ written notice, at your cost, or sooner after a breach.
For a signed copy of this text, write trust@nextfluent.com.