Legal

Privacy
Policy

Last Updated: 23 August 2026  ·  Visionmill Limited

This Privacy Policy explains how Visionmill Limited ("Visionmill", "we", "our", "us") handles personal data when you visit the NextNote website, contact us, purchase or download NextNote, or use a NextNote desktop or mobile application (together, "NextNote"). Visionmill is the controller for the website, licensing, account, support, and other personal data described below. Google, Apple, Stripe, and other named providers also act as independent controllers for some processing they determine themselves. This Policy applies alongside the UK GDPR and Data Protection Act 2018 and, where their territorial rules apply, the EU GDPR and other applicable privacy laws.

Contents
  1. Data We Collect
  2. Presentations and Local Networks
  3. Purposes and Legal Bases
  4. Sharing and Providers
  5. International Transfers
  6. Retention and Security
  7. Rights and Complaints
  8. Cookies and Website Technologies
  9. Regional Information
  10. Changes to This Policy
  11. Contact
01

What Data We Collect

We collect the following categories where they are relevant to your use of NextNote:

We obtain this data directly from you; from NextNote apps and devices when they activate, validate a licence, check in, or report Helper compatibility; from Stripe and Apple for payment, entitlement, and transaction-status records; from Google for presentations you deliberately select; from browser and server request logs; and from IP-location and network-owner services used when an installer is requested.

We do not automatically receive presentation content, speaker notes, feature-interaction analytics, performance traces, debug logs, or crash reports from the installed apps. Some apps create diagnostic buffers or crash information locally. Visionmill receives it only if you deliberately provide it for support. If that changes, we will update this Policy and provide any notice or obtain any consent required before the new processing begins.

02

Presentations and Local Networks

Google Slides access

The Google Slides Helper uses Google OAuth with the per-file https://www.googleapis.com/auth/drive.file scope. Google's file-selection screen lets you choose each presentation that NextNote may access; other files in your Google Drive remain inaccessible to NextNote. Although this scope can permit an application to manage selected files, NextNote uses Google APIs only to read the presentations you select and never creates, edits, or deletes them.

NextNote's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google controls its own processing of Google account and Slides data under its own terms and privacy policy.

Trusted local-network transport

NextNote's Helper-to-Display presentation transport is designed for local-network use. It does not intentionally route slide images, speaker notes, presentation names, live video, or control state through Visionmill or a Visionmill cloud service. While a Helper is running, it advertises itself using local-network discovery and makes that presentation data available over local HTTP, WebSocket, and, for LiveView, UDP connections to compatible NextNote Displays that can reach the Helper's address.

Trusted network required. The Helper-to-Display protocol does not require a NextNote account, per-Display pairing, or an access code. This preserves automatic discovery, but a compatible device with network reachability may be able to request presentation data or send presentation controls. Use Helpers only on a private, trusted, access-controlled LAN; do not expose the Helper ports through internet port-forwarding or use them on an untrusted public or guest network. A routed network or VPN with access to the Helper can extend reachability beyond the immediate Wi-Fi/Ethernet segment. Closing the Helper stops its presentation service. RemoteView is a separate feature and supports individual access codes.

Visionmill does not receive, read, sell, use for advertising, or otherwise disclose the presentation content exchanged on that network.

03

Purposes and Legal Bases

Our purposes and the UK/EU GDPR legal bases we rely on are:

Account, billing, purchase, and licence information marked as required is needed to enter into or administer the relevant contract. If it is not provided, we may be unable to create the account, take payment, issue a licence, or provide the requested service. Google Slides access is optional, but is necessary if you choose that Helper. Optional analytics is never required.

We do not sell personal data, use it for targeted advertising, or make decisions about you based solely on automated processing that produce legal or similarly significant effects.

04

Sharing and Providers

We do not sell or rent personal data. Access inside Visionmill is limited to people who need it for their work. We disclose data to the following recipients where necessary:

Presentation content sent between a Helper and Display on your network is a user-directed local transfer, not a disclosure to Visionmill or one of the website providers above.

05

International Transfers

Visionmill is established in the United Kingdom. Some providers operate internationally and may process data in the United Kingdom, European Economic Area, United States, or other countries in which they and their approved subprocessors operate.

Before making a restricted transfer, we must identify the destination and recipient and rely on a lawful transfer route. Depending on the particular data flow, this may be a UK adequacy regulation or EU adequacy decision; the European Commission's Standard Contractual Clauses together with a transfer impact assessment; the UK International Data Transfer Agreement or UK Addendum together with a transfer risk assessment; or a limited statutory exception where the law permits it. Contractual clauses may be supplemented by encryption, access controls, data minimisation, and other measures where needed.

The mechanism can differ by provider, service, account configuration, and destination. Contact our Privacy Lead for the current mechanism applying to a particular recipient and for a copy or description of the relevant safeguard, subject to permitted redactions. This Policy is a transparency notice and is not itself a transfer safeguard.

06

Retention and Security

We apply the following periods and criteria, subject to a legal hold, dispute, regulatory request, or a longer mandatory period:

Your Google refresh credential is retained in OS secure storage until you sign out, remove the app data, or Google revokes it. The dedicated Chrome profile, settings, and last presentation URL remain on the device until you remove the relevant app data. Temporary slide images are normally removed when NextNote closes.

Application preferences and diagnostic information created locally remain on the device. In-memory debug buffers are cleared when diagnostic logging is disabled or the relevant diagnostic window closes. Locally written crash logs remain until you delete them or remove the relevant application data. They are not sent to Visionmill automatically.

We use measures appropriate to the risk, including HTTPS, access controls, one-way password hashing, hashed reset and event tokens, two-factor authentication for administration, restricted administration interfaces, provider security controls, and local OS secure storage for app credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. The trusted-LAN limitation in section 2 is an important part of safely operating the installed apps.

07

Rights and Complaints

Depending on the processing and the law that applies to you, you may have rights to:

Your right to object: you may object at any time to processing based on our legitimate interests. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims. You may object to direct marketing at any time, and we will stop that marketing.

These rights are not absolute; exemptions and conditions can apply. We may ask for information reasonably needed to verify your identity and locate the relevant records. We do not charge a fee in ordinary cases. We normally respond to UK/EU rights requests within one month, subject to a lawful extension for a complex or numerous request.

How to complain to us

Email support@nextnote.co.uk with the subject “Data Protection Complaint”, or write to the registered office in section 11. Our Privacy Lead will acknowledge the complaint within 30 days, investigate it appropriately, and tell you the outcome without undue delay.

If you remain dissatisfied, you can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint. If the EU GDPR applies, you may also complain to the supervisory authority in the EU/EEA country of your habitual residence, place of work, or the alleged infringement. Other local regulators may be available under applicable law.

08

Cookies and Website Technologies

We use cookies and equivalent browser storage as follows:

Optional Cloudflare Web Analytics is off until you make a positive choice. Rejecting or withdrawing leaves essential features working. Withdrawing permission stops future script loading; aggregate statistics that Cloudflare cannot associate with you cannot be selectively reversed. Website fonts and Tabler icons are hosted by Visionmill. We do not use advertising cookies, advertising pixels, or cross-site behavioural tracking.

Because optional analytics is off by default and we do not sell or share data for cross-context behavioural advertising, a browser Do Not Track or Global Privacy Control signal does not cause additional advertising-data disclosure. Where applicable law gives such a signal a broader mandatory effect, we honour it. Stripe may independently recognise a device or activity across merchant sites for payment security, fraud/loss prevention, authentication, and its own payment-service analytics as described in Stripe's policy; Visionmill does not use those signals for advertising.

Review privacy choices

09

Regional Information

European Union and European Economic Area

Where we offer NextNote to people in the EU/EEA and process their data in connection with that offering, the EU GDPR may apply even though Visionmill is established in the United Kingdom. EU/EEA individuals have the rights and complaint routes described in section 7. Where Article 27 requires it, Visionmill will maintain a written mandate with a representative established in an EU Member State in which relevant individuals are located and publish that representative's contact details in section 11.

California and other United States privacy laws

In the preceding 12 months, the categories we may have collected are identifiers and contact details; customer, transaction, and commercial information; internet/network and device activity; approximate geolocation from IP address; and professional or employment-related information you provide, such as company name. Account-login credentials are security-sensitive and are used only to authenticate and protect the account. Sources, purposes, recipients, and retention criteria are described in sections 1–8. We do not sell personal information, share it for cross-context behavioural advertising, or use/disclose sensitive personal information to infer characteristics. We do not knowingly sell or share personal information of anyone under 16.

If a US state privacy law applies to Visionmill and to your data, you may have rights to know/access, correct, delete, obtain a portable copy, opt out of covered sale/sharing or profiling, and appeal a refusal. We will not discriminate against you for exercising an applicable right. You or an authorised agent may submit a request using section 11; we may verify the request and the agent's authority.

Other countries

Applicable laws in countries including Canada, Brazil, and Australia may provide additional access, correction, deletion, consent-withdrawal, objection, portability, or complaint rights. Submit a request to our Privacy Lead. You may also contact the privacy regulator in your country where local law permits.

Children

NextNote is professional presentation software and is not directed to children. We do not knowingly collect personal data from a child who cannot lawfully provide it without parental authorisation. Contact us if you believe that has occurred.

10

Changes to This Policy

We may update this Privacy Policy from time to time. Updated versions will be published at nextnote.co.uk/legal/privacy with a revised date. We encourage you to review this page periodically.

Where a change materially affects existing processing or your choices, we will provide an appropriate additional notice and, where required, seek fresh consent before the change takes effect.

11

Contact

Controller and Privacy Lead: Visionmill Limited
Company number 03495202
Registered in England and Wales
Registered office: Rookhurst, Forest Road, Effingham, Leatherhead, Surrey, KT24 5HD, United Kingdom

Email: support@nextnote.co.uk
Website contact form: nextnote.co.uk/#contact

For a rights request, use the subject “Privacy Rights Request”. For a complaint, use “Data Protection Complaint”.

All legal documents including our End User Licence Agreement (EULA) and Purchase Terms and this Privacy Policy are available at nextnote.co.uk/legal.