Next Moca Privacy Policy
Last updated: July 31, 2026
This Privacy Policy explains how Next Moca Global, Inc. (“Next Moca,” “we,” “us”) collects, uses, and shares information when you visit nextmoca.com, request research access, or use the Needlepath API, the Agent Control Plane, and related services (the “Services”). Questions or requests: privacy@nextmoca.com.
1. What we collect
Information you give us.
- Website forms: if you request research access or contact us, we collect what you submit — typically name, work email, company, and your message.
- Accounts (when API accounts launch): registration details such as name, work email, organization, and role.
- Billing (when paid tiers launch): payments are processed by a payment processor (e.g., Stripe). We receive transaction records (amount, time, status, last card digits) but never store full card numbers — those go directly to the processor.
Information collected automatically.
- API usage metadata: for each API request we record operational metadata — request identifiers, API key identifier, token counts, timing, selected-record counts, and outcome codes (including stand-down reasons). This metadata powers metering, billing, rate limiting, abuse prevention, and the usage reports we show you.
- Website data: standard server logs (IP address, browser type, pages viewed) and the analytics described in Section 6 — our website uses PostHog (product analytics) and HubSpot (forms and visitor tracking), which collect usage data such as pages viewed, referrer, device information, and a visitor identifier cookie.
API Customer Content — processed, not persisted on the serving path. The records and queries you submit to the selection API (“Customer Content” — this term does not include account information, website form submissions, or usage metadata) are processed in memory to compute the response and are not written to persistent storage on the request-serving path, by design. Our logging records usage metadata — request identifiers (including any identifier you supply with a request, so do not place personal data or secrets in identifiers), token counts, timing, and outcome codes — not the records or queries themselves. We do not use Customer Content to train models. If you choose to use optional features that require content handling beyond the stateless path (for example, an interactive playground), we will say so where the feature appears, including how long content is retained there.
Agent Control Plane deployments. The Agent Control Plane typically runs in the customer’s own cloud environment: the customer’s business data, workflows, and agent state stay in the customer’s infrastructure, and we do not receive them. Information we do receive in connection with such deployments — account, contact, licensing, and support information, and any telemetry the customer’s agreement provides for — is handled under this policy and the customer’s agreement, whichever is more protective.
2. How we use information
We use information to: provide, secure, meter, and bill for the Services; respond to your requests; send service and account communications; send research or product updates you asked for (opt out anytime); improve our website; monitor for abuse and enforce our Terms of Service; and comply with law. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
3. How we share information
We share information only with: (a) service providers that process it for us under contract — currently our cloud infrastructure provider (Amazon Web Services, United States), our website/CRM forms and visitor-tracking provider (HubSpot), our product-analytics provider (PostHog), and, when billing launches, our payment processor (Stripe) and identity provider; (b) professional advisers (lawyers, accountants) under confidentiality; (c) authorities where required by law, and we will notify you where lawful and practicable; and (d) a successor in a merger, acquisition, or asset sale, under this policy’s protections. We do not share Customer Content with any third party except the infrastructure on which the Services run.
4. Retention
We keep website inquiries and research-access records while relevant to our relationship. API usage metadata is retained for billing, audit, and security purposes and then deleted or aggregated. Customer Content on the selection path is not retained after the response is returned. Account and billing records are kept as required for tax and accounting. You can ask us to delete information as described in Section 5.
5. Your rights
Where the GDPR applies, our legal bases are: performance of a contract (providing the Services you request), legitimate interests (securing, metering, and improving the Services and our website), consent (where we ask for it, such as marketing emails), and legal obligation (tax and accounting records). Depending on where you live (including under GDPR and the CCPA/CPRA), you may have rights to access, correct, delete, or export your personal information, to object to or restrict processing, and to withdraw consent. To exercise them, email privacy@nextmoca.com; we will verify the request and respond within the time required by law. We do not discriminate against you for exercising your rights. If you are in the EEA or UK, you may also lodge a complaint with your supervisory authority. Where we process personal information on behalf of an API customer as their processor, we will refer your request to that customer and assist them in honoring it. API customers who intend to submit personal data subject to the GDPR or UK GDPR must have a data processing agreement with us first — contact legal@nextmoca.com; until one is executed, do not submit such data.
6. Cookies and analytics
Our website uses: (a) cookies needed to operate the site and its forms; (b) HubSpot cookies (such as hubspotutk) that identify visitors and connect form submissions to a visitor record; and (c) PostHog product analytics, which uses cookies or similar storage to measure how the site is used (pages viewed, referrer, approximate location from IP, device type). We use this data to understand interest in our research and product; we do not use it for third-party advertising. Your browser’s settings let you block or delete cookies; the site remains usable without analytics cookies. We do not currently respond to browser Do Not Track signals. These providers may collect information about your activity on this site over time and, in HubSpot’s case, may associate that activity across different websites that use its services; PostHog, as we configure it, collects activity on this site only. See their own privacy documentation for details.
7. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, least-privilege access controls on production systems, secret scanning for leaked API keys, and audit logging of administrative actions. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you and regulators as required by law.
8. International transfers
We are a U.S. company and process information in the United States. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as standard contractual clauses.
9. Children
The Services are for business use and not directed to anyone under 16. We do not knowingly collect personal information from children; if you believe a child has provided it, contact privacy@nextmoca.com and we will delete it.
10. Changes
We will post updates to this policy here and revise the date above. For material changes we will give prominent notice (for example on the website or by email to account holders) before they take effect.
Contact: Next Moca Global, Inc. · privacy@nextmoca.com · legal@nextmoca.com