eNextGen
IT
What we do ▾
Products nxbase The database of databases CBAManager Frictionless CBAM compliance MARIO Input-output analysis, open source nxsut Global supply-use table in physical units
Services Training Tailored programmes, on site or online Carbon footprint Organisation and product footprint Long-term decarbonization strategy Roadmap, scenarios and monitoring
Projects
Research ▾
Our analyses Methodology Publications
About us IT Sign in Personal area Get in touch
Legal information

Privacy Policy

Last updated: July 2026

Data Controller

eNextGen S.R.L.
Via Principe Eugenio 9, 20155 Milan, Italy
VAT 12692290963
Email: info@enextgen.it

Types of Data Collected

Depending on how you use the site and our services, we may collect:

  • Browsing data: IP address, browser and device type, pages visited.
  • Contact-form and “pre-assessment” form data (sector, country, revenue/employee ranges, energy/fuel data, optional email).
  • Account registration data:
    • Individuals: first name, last name, email, date of birth, gender, profession, country of residence.
    • Companies: email, company name, VAT / tax ID, registered office, sector of activity.
  • Authentication data: credentials managed by our authentication provider, or — if you sign in with Google — the identifier and email provided by Google.
  • Service usage data: a log of calls to our APIs/tools (volumes, timestamps) for security and usage-limit purposes.
  • Data you upload into the tools (e.g. data for CBAM calculations): see “Data uploaded into the tools”.

Purpose of Processing

  • Respond to contact requests and deliver the “pre-assessment” preliminary estimate.
  • Create and manage your account and give you access to tools and datasets.
  • Deliver and maintain the services (nxbase, cbamanager and future tools).
  • Ensure security, abuse prevention and usage limits.
  • Comply with legal obligations.

Legal Basis

  • Consent (e.g. registration, optional marketing communications).
  • Performance of a contract or pre-contractual measures (use of the tools under the Terms of Service).
  • Legal obligations.
  • Legitimate interest for security, abuse prevention and service improvement.

For the “pre-assessment” form, processing is solely to deliver the requested preliminary estimate; the email is optional and used only if provided.

Registration and account

Registration is reserved for adults (18+): accounts may not be created by minors. You can register with email and password or via Google; in the latter case you will be asked to complete your profile with the data listed above. Fields marked as optional (e.g. marketing consent) do not affect access to the services.

Data uploaded into the tools

Some tools (e.g. cbamanager) let you upload data for processing and reports. For such data:

  • The user (or the company) remains the controller of the uploaded data; eNextGen processes it as a data processor, following the user’s instructions and the Terms of Service.
  • For business users processing personal data of third parties, a Data Processing Agreement (DPA) under Art. 28 GDPR is available on request.
  • We do not request and do not wish to receive special categories of data (Art. 9 GDPR, e.g. health data): please do not upload them into the tools.

Where data is hosted

Data is hosted on infrastructure within the European Union (Frankfurt, Germany). We do not transfer data outside the European Economic Area, except through providers offering adequate safeguards (e.g. standard contractual clauses).

Providers and external processors

We rely on providers that process data on our behalf, as processors:

  • Supabase — authentication, database and hosting (EU region, Frankfurt).
  • Netlify — website hosting and delivery.
  • Render — application hosting (nxbase, cbamanager).
  • Google — only if you choose to sign in with Google.

This list may be updated; the current version is available on request.

Security

We apply appropriate technical and organizational measures, including: encryption of data in transit (TLS) and at rest, database-level access isolation (row-level security) so that each user/company can access only its own data, and control and minimization of internal access.

Data Retention

Data is retained for the time necessary to fulfil the stated purposes and, for account data, for as long as the account remains active. On account closure, the associated data is deleted or anonymized, subject to legal obligations.

User Rights

You may at any time request: access, rectification, erasure, restriction, objection to processing, data portability, and withdrawal of consent (without affecting processing already carried out). You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante).

To exercise your rights: info@enextgen.it

Changes

This policy may be updated; material changes will be communicated via the website or by email.

← Back to home
eNextGen
eNextGen S.R.L. · P.IVA 12692290963
Via Principe Eugenio 9, 20155, Milan, Italy · Capitale sociale: 10’000€
Contatti Privacy Cookies