Skip to Content
Built in Zimbabwe | Africa market experience | Global service delivery+263 242 496 172 | WhatsApp +263 790 050 483 | hello@nxt-workforce.com
Data protection

GDPR Information

Information about NXT Workforce processes where the General Data Protection Regulation applies.

GDPR Information
GDPR Information

Data protection

Last updated: 26 September 2026

The GDPR may apply to certain NXT Workforce activities depending on the people, clients, locations and processing involved. This page explains how we approach GDPR-related responsibilities when the regulation applies.

Controller and processor roles

For website enquiries and NXT Workforce's own business administration, NXT Workforce may act as a controller. When processing personal data only on a client's documented instructions as part of a contracted service, NXT Workforce may act as a processor. The exact role depends on the activity.

Lawful processing

Where NXT Workforce acts as a controller, we identify an appropriate lawful basis for the processing. Where we act as a processor, the client is responsible for determining the lawful basis and providing lawful documented instructions.

Data processing agreements

A data processing agreement may be used where required. It can address processing instructions, confidentiality, security, sub-processors, assistance with data-subject requests, incident notification, deletion or return of data and international transfers.

Data minimisation and purpose limitation

Personal data should be limited to what is relevant for the defined business purpose. We do not intend to use client-controlled personal data for unrelated purposes.

Data-subject rights

Where applicable, individuals may have rights including access, correction, erasure, restriction, objection and portability. Requests should be verified and handled according to the role NXT Workforce has in the processing. If we act as a processor, requests relating to client-controlled data may need to be referred to the client.

International transfers

If GDPR-covered personal data is transferred to a country that does not have an applicable adequacy decision, an appropriate safeguard may be required. The correct mechanism depends on the processing arrangement and should be documented before transfer where required.

Sub-processors

Service delivery may use hosting, communications, CRM, form-processing, cloud or other approved service providers. Where GDPR requires sub-processor controls, those requirements should be addressed in the client agreement or data processing terms.

Retention and deletion

Retention should be based on the purpose, client instructions, contractual needs and legal obligations. Processor-held client data should be returned or deleted at the end of the service where required by the agreement and subject to lawful retention obligations.

Contact

For GDPR-related questions, email hello@nxt-workforce.com.