Tech Conciergeby NewGen

Privacy Policy

About this policy

Tech Concierge by NewGen International — Privacy Policy. Version 1.12, effective 7 October 2026.

This policy applies to newgen.market, the client portal at app.newgen.market, the Tech Concierge app for iOS and Android, the Telegram Mini App and the Concierge on WhatsApp and Telegram. Questions and requests: [email protected].

1. Who we are and what this policy covers

NewGen International Inc. ("NewGen", "we") is a corporation organised in the State of Florida, United States of America. With our affiliates we operate Tech Concierge, a technical department for small and medium businesses run by a named engineer together with an automated assistant. This policy explains how we collect and use personal data about the people who visit our websites, open an account, use the portal, the app or the Telegram Mini App, or write to the Concierge ("you").

The controller of your personal data is the NewGen entity that contracts, or would contract, with your organisation:

  • the United Arab Emirates and every country not listed below: NewGen International Inc., 1221 Brickell Center, Miami, FL 33131, United States of America;

  • the European Economic Area, the United Kingdom and Switzerland: NewGen Europe OÜ, Tallinn, Estonia, our establishment in the European Union;

  • the United Arab Emirates, from the date announced on newgen.market: NewGen's affiliate in the United Arab Emirates.

Until your organisation adds its company details to its account, the controller is NewGen International Inc. We apply the standards of the EU General Data Protection Regulation (GDPR) and of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) to everyone, and the law of your own country where it gives you more.

If you are a customer of one of our clients: when a business uses a website, an app or a WhatsApp assistant that NewGen runs for it, that business is the controller of your data and NewGen is its processor, acting on its instructions under clause 10 and Schedule 4 of our Agreement with it. That business's privacy notice applies. Please contact the business; if we receive your request, we pass it on.

2. What we collect

  • Account and sign-in: your name, business email address, mobile number, role and language. If you sign in with Google or Apple, the name and email address the provider shares with us and the identifier it gives us for you (Apple may give a private relay address instead of your own). One-time codes, which we keep only in scrambled (hashed) form; a password hash if you set a password; and sign-in sessions for your browser or device.

  • Free trial: when you open an account, the free trial that starts with it — its days, the work done and the allowance used. Until your organisation gives its details, its account carries your name. We ask for no trade licence, tax number or payment details during the trial.

  • Organisation and verification: your organisation's legal name, country, address, trade licence (the document you upload and the details on it), licence number and tax registration number (TRN), and the result of our review of the licence.

  • Contract and billing: the order form, the signed Agreement and the evidence of signature (the time, the IP address, the browser or device, and a fingerprint of the document), invoices, credit notes, payment status, the brand and last four digits of a saved card, and bank-transfer references. Card numbers are entered on Stripe's payment page and never reach us.

  • Using the service: requests, messages exchanged with the Concierge and our team (on WhatsApp, Telegram, email, the portal or the app), attachments, approvals, token ledger entries, disputes, satisfaction ratings and the videos you order.

  • Linked channels: your WhatsApp number or Telegram user ID when you link a channel, and the messages sent through it.

  • The app: a push-notification token, the platform, the app version and build, the operating-system version, the device model and your time zone (no advertising or device identifier), and the photos or files you choose to attach — the app asks for the camera or your photos only when you use them. Face ID and fingerprint unlock happen on your device; we receive only whether they succeeded.

  • Technical: IP address, browser and device type, and logs.

  • How our websites, the portal and the app are used (our own analytics, on our own servers): the pages and screens you open, the buttons and links you press, how far you scroll, the forms you start and send — never what you type in them — errors, how fast pages load, where a visit came from (the site that linked to us and a campaign's tags), and your country (read from your IP address, which we do not keep for this), device, system, browser and language. On newgen.market and on the portal's sign-in pages this is kept under an id your browser keeps only if you accept analytics, and then the visit may also be recorded — what the page showed and where you clicked and scrolled, with everything you type hidden; if you do not accept, visits are only counted, under a code that changes every day, and nothing is recorded. Once you are signed in to the portal or the app, your use is kept under your account, and a portal visit may be recorded with every text on the screen hidden; you can switch this off in Settings. When we learn who a visitor is — they sign in, write to us in the website chat, or open the plan we sent their business from a browser that accepted analytics — their earlier visits are linked to them.

  • Records of activity: to keep the platform secure and to be able to say who did what, we record every action taken in our systems — requests to the portal, the app, the API and our console with what was sent, sign-ins (including refused ones), sign-outs and password resets, each change to a record with its old and new values, the emails we send (address and subject) and our calls to outside services — with who acted, their role, the organisation, the time, the IP address, the browser or device and the app version. We never record passwords, access tokens, one-time codes, card details or signatures, and long values are cut short. Separately, a readable journal of activity (messages in and out with a short quote, requests, website chats, sign-ups, invoices and payments) lets our administrators follow what is happening. Only NewGen administrators can read either.

  • Website chat: if you use the assistant on newgen.market, the messages you write and its replies, and any name, email address, phone number and company you choose to give it. We do not keep your IP address, only a one-way scrambled (hashed) form of it, used to limit abuse.

  • Enquiries, referrals and outreach: what you send through the contact form on newgen.market (name, email, phone, company and message); the name and business details of a business a client refers to us; and, when we approach a business ourselves, the business contact details it publishes — on its own website or its Google Maps listing (such as its name, address, phone number, website, rating, and an owner's name, role and email), and, for a business we may offer our service to, the name, title, professional profile (such as LinkedIn), work email and mobile number of its owner or the person who runs it, which we look up by the business's website address in business-contact databases — how long it took to answer a customer-style question we sent to its public number, the messages we exchange with it, whether it opened the plan we prepared for it and which links in it were clicked, and our notes of that contact.

  • Test drive: if your business takes our free test drive, what its customers write to the assistant we set up for it — their messages, names, numbers and enquiries. For that data we act as your business's processor, under the Test Drive Terms (newgen.market/test-drive-terms).

  • Sales partners: if you apply to be one of our sales partners or are one — your name, email address, phone number, company, country and city, what you tell us about your experience, the Partner Agreement you signed (the time, the address it was signed from and the name you typed), your certification of tax residence (your name, country, address and, if you give them, your date of birth and tax number), the businesses you register with us, and the commission and payouts on your statements. Your bank details and identity documents go to Stripe on its own pages and never reach us. If a sales partner told us about your business, the name, email address and phone number they gave us.

  • Waiting list: when we cannot yet serve your country, your business name and country, so that we can tell you when we can.

We do not knowingly collect special categories of personal data, such as health, biometric or religious data.

3. Why we use your data and on what basis

The lawful bases below are those of GDPR Article 6 and UAE PDPL Article 4:

  • Opening and running your account and its free trial before your organisation signs, including the set-up tasks and messages about them: steps taken at your request before entering into a contract.

  • Providing the service once your organisation has signed — the portal, the app, the Concierge, requests and deliverables: performance of a contract with you or your organisation.

  • Verifying a business and its signatory, including reviewing the trade licence and the TRN: legal obligations (know-your-customer, tax) and our legitimate interest in knowing who we contract with.

  • Billing, invoicing, tax records and collections: contract and legal obligations under tax and accounting law in the United States and, where it applies, the UAE.

  • Security, fraud and abuse prevention, and audit logs: legitimate interests in protecting the platform and our clients.

  • Records of activity and the journal of activity: legitimate interests in keeping the platform and our clients secure, preventing fraud, putting things right when they go wrong, and being accountable for who did what.

  • Improving the platform, using aggregated or pseudonymised data: legitimate interests.

  • Service messages — codes, invoices, incidents, approvals, renewals: contract, or steps before a contract.

  • Our own analytics on newgen.market and on the portal's sign-in pages, and Google Analytics: your consent, which you can withdraw at any time. Counting visits without cookies, which tells us nothing about who you are: our legitimate interest in knowing how our site is used. Our own analytics of signed-in clients in the portal and the app, and linking a visitor's earlier visits once we know who they are: our legitimate interests in understanding how our service is used and how businesses come to us, to improve both; you can object at any time, and switch it off in Settings.

  • Marketing messages and case studies: your consent, which you can withdraw at any time.

  • Answering you in the website chat, and following up when you leave your contact details: steps you ask us to take before a contract, and our legitimate interest in answering an enquiry you started.

  • Approaching businesses that may benefit from Tech Concierge — using the contact details they publish, measuring how quickly they answer a customer-style question and seeing whether they opened the plan we sent: for a business in the UAE, the PDPL's exception for data the person has made public (Article 4), and their consent once they reply; elsewhere, legitimate interests. A person at NewGen approves every message before it is sent or, when one of our administrators has switched on automatic approval, it is approved after the automated check described in section 4 and stays on record for a person to review; we write only on working days between 09:00 and 18:00 UAE time, and we stop the moment you say no or reply STOP — a refusal is final.

  • Finding the owner of a business we may offer our service to, or the person who runs it, and writing to them — one business offer and the conversation that follows — using the details we look up by the business's website address in business-contact databases: our legitimate interest in offering a business service to the person who decides on it, and their consent once they reply. A no or STOP from them or from the business stops all our messages to both: the owner's details are deleted, and both numbers are kept only in scrambled form on our do-not-contact list so that we never write again; our record of the messages exchanged is kept as the law requires.

  • Running the sales partner programme — your application, the Partner Agreement, commission, statements and payouts: steps at your request before a contract, then performance of the contract; your tax certification and payout records: legal obligations. Contacting a business a sales partner registered with us, using the details the partner gave: legitimate interests. You can object at any time and we will stop.

  • Running a test drive for your business: steps at your request before a contract; for your customers' data, your instructions as controller (Test Drive Terms, clause 5).

  • Complying with the law and answering lawful requests: legal obligation.

4. The Concierge and artificial intelligence

  • The Concierge is an automated assistant. It classifies your requests, estimates their cost in tokens, answers questions from your account data and hands anything else to a named person. You can ask for a person at any time.

  • The Concierge's answers are written with the help of a large language model provided by Hangzhou DeepSeek Artificial Intelligence Co., Ltd. ("DeepSeek"), a company in the People's Republic of China, through DeepSeek's API. When you write to the Concierge we send DeepSeek your message, up to the last ten messages of the conversation, your name, your organisation's name, and the account information the Concierge needs to answer — for example your token balance, ledger entries, invoices, the status of your requests and notes about your account. We do not send passwords, one-time codes or card details. When your organisation uploads its trade licence, we send DeepSeek the text we extract from it — not the file itself — so that it can read the company name, licence number, expiry date and business activities; a person at NewGen checks the result against your application.

  • DeepSeek processes and stores this data in the People's Republic of China (see section 6). We have instructed DeepSeek, as its terms allow, not to use the data we send it to train or improve its models.

  • In the app and the portal we ask you, before your first message to the Concierge, whether its replies may be written with this model; you can choose a person only, and change your choice at any time in Settings, and then nothing you write to the Concierge is sent to DeepSeek.

  • When a business we approached replies, DeepSeek reads the reply to sort it and drafts our answer. Before any message to a business we approach is sent, the first one included, DeepSeek may also check the draft. For that check we send it the draft, the business's details from section 2 (its name, trade, area and website, and what we measured, such as how quickly it answers and how fast its website loads), up to the last ten messages with the business, what is already waiting to be sent to it, and the terms of our offer. We do not send it the details we found about an owner or anyone else at the business, such as their mobile number or email; the draft and the messages themselves may contain the name of the person we are writing to. A member of our team reads, corrects and approves each message before it is sent, unless one of our administrators has switched on automatic approval: then a message the check passes is approved without a person and sent under the same rules, and one it does not pass waits for a person. Every message, the result of the check and who or what approved it are recorded, and our team can review them at any time. Reply STOP, or tell us no in any words, and we stop all messages to you.

  • Either of you can choose to read the conversation translated into your own language: when you tap Translate in the app or the portal, or a member of our team does so on their side, we send DeepSeek the messages being translated. When you write to us on WhatsApp, Telegram or by email in a different language from the member of our team answering you, we send DeepSeek your recent messages and their reply, and their reply reaches you with a translation into the language you wrote in above what they wrote. Messages are kept exactly as they were sent, with any translation beside them. If you have chosen a person only, nothing you write is sent for translation.

  • We also use DeepSeek to show you, in your own language, what is written for you on the platform: the titles, descriptions and reports of your requests, Autopilot tasks and reports, notes, notifications, invoice line descriptions and the assistant's summaries; and to show our team, in theirs, what you write in your requests, captions and disputes. We never send the Agreement, tax documents, statements, names, file names or code for translation. Translations are stored, so the same text is not sent twice. If you have chosen a person only, nothing about you is sent for translation.

  • The assistant in the chat on newgen.market works the same way for visitors without an account: we send the language model your messages in that chat, up to the last ten, and any contact details you gave in it, so that it can reply. If you ask for a person, a member of our team reads the chat and answers you.

  • Decisions with a legal or similarly significant effect on you or your organisation, such as suspending the service or ending a contract, are taken under the rules of the Agreement and reviewed by a person before they take effect, unless your organisation agreed to automatic execution in the Agreement.

  • The details the model reads from a trade licence are checked by a person at NewGen before we rely on them.

  • Conversations with the Concierge are logged, and a sample is reviewed by our staff for quality. We do not use your conversations to build advertising profiles.

5. Who we share data with

Service providers that process personal data for us (sub-processors), what for, and where:

  • DigitalOcean — our servers, database and backups in the United Kingdom (London), and our file storage in the United States (San Francisco), which also holds the recordings of visits (section 2).

  • Cloudflare — delivery and protection of our websites and API — its global network.

  • Google — our business email (Google Workspace), sign-in with Google, push notifications on Android (Firebase Cloud Messaging), business listings from Google Maps (Google Places) and, only with your consent, website analytics (Google Analytics) — United States and its global network.

  • Apple — sign-in with Apple and push notifications on iOS — United States and its global network.

  • Stripe — card payments, and payouts to our sales partners (Stripe Connect), for which Stripe also checks the partner's identity — United States and European Union.

  • Meta — WhatsApp messaging — its global network.

  • Telegram — Telegram messaging and the Telegram Mini App — its global network.

  • DeepSeek — the language model behind the Concierge, the translation of conversations with our team and of what you read on the platform, and sorting, drafting and checking our messages to businesses we approach (section 4) — People's Republic of China.

  • Slack — internal alerts to our team about errors and website enquiries — United States.

We also share data with your organisation (its account owner can see the requests, approvals and activity under its account); with our professional advisers, auditors and insurers, under confidentiality; with authorities and regulators where the law requires it, including tax authorities in the United States and the United Arab Emirates and data protection authorities; and with a buyer or successor of our business, under the same obligations and with notice to you.

We do not sell personal data and we do not share it with advertising networks.

6. International transfers

Our servers are in the United Kingdom and our file storage is in the United States. Our team works from the United States, the United Arab Emirates, Portugal and Estonia, and some of the providers in section 5 process data in other countries — including DeepSeek, in the People's Republic of China, whose terms are governed by Chinese law.

Where data leaves the European Economic Area or the United Kingdom, we rely on an adequacy decision where one exists (the United Kingdom has one) or on the European Commission's standard contractual clauses, or the UK equivalent, with providers that accept them. Where data leaves the United Arab Emirates we rely on Articles 22 and 23 of the UAE PDPL, including where a transfer is necessary to perform the contract you or your organisation asked for. The People's Republic of China has no adequacy decision from the EU or the UK, and its laws may give you less protection than your own. You can ask us for details of the safeguards for any transfer.

7. How long we keep data

  • An account whose organisation never signs an Agreement: deleted after 12 months without activity, or straight away if you delete it in Settings.

  • Your organisation's data once it is a client: for the life of the Agreement; then erased from our live systems 30 days after it ends and from backups within 90 days, except the records below.

  • Signed Agreements, invoices, credit notes and payment records: 7 years after the end of the tax year they relate to, as tax law in the United States and the UAE requires.

  • Requests, messages, deliverables and ledger entries: for the life of the account, exported to your organisation on request, then erased as above.

  • One-time codes: 30 days. Sign-in sessions not used for 180 days are ended and deleted.

  • Technical logs: 14 days. Records of activity: in full for 24 months; after that what was sent and changed, the IP address and the device are removed, and the record of who did what and when is kept for the life of the service. The journal of activity: the quotes and email addresses in it are removed after 90 days. If you ask us to erase your data, your entries in both keep only a record that an action took place — its type, time and internal references — and nothing of what was sent or changed, from where, or your name. Backups: no more than 90 days.

  • Our own analytics: the record of visits and of the pages, screens and clicks in them, 13 months after the visit, after which it is anonymised; recordings of visits, 30 days.

  • Enquiries sent through the contact form: 24 months.

  • Website chats in which you left no contact details: 90 days after the last message. Chats in which you left contact details, and those details: 24 months after the last message, like an enquiry through the contact form.

  • Businesses we approached that did not become clients, and the records of our messages to them: 12 months after the last contact. If you asked us not to contact you, after that we keep only a one-way scrambled (hashed) form of your number or email address, for as long as we approach businesses, so that we never contact you again.

  • Details of the owner of a business, or the person who runs it, that we looked up in business-contact databases: 180 days after we obtained them, unless they reply to us, after which the conversation is kept as for businesses we approached, above. If they or the business asked us not to contact them, their details are deleted at once and we keep only the scrambled form described above.

  • A test drive that did not become a subscription: its data, including your customers' conversations, 60 days after it ends.

  • Sales partner applications we decline: 12 months. A sales partner's account, statements and payout records: for the life of the partnership, and payout records then for 7 years after the end of the tax year of the last payout, as tax law requires. The contact details of a business a partner registered that did not sign: 12 months after the registration lapsed.

  • The waiting list for a country we do not serve yet: until 30 days after we tell you we have opened there, and in any case no more than 182 days after you last updated your entry.

  • Marketing consent and preferences: until you withdraw them, and a record of the withdrawal for 3 years.

8. Your rights

Depending on where you are, under the GDPR, the UAE PDPL or the law of your state you have the right to:

  • access the personal data we hold about you and receive a copy;

  • have inaccurate data corrected and incomplete data completed;

  • have your data erased where it is no longer needed or was processed unlawfully;

  • restrict processing in certain circumstances;

  • receive the data you gave us in a portable format;

  • object to processing based on legitimate interests, and to direct marketing at any time;

  • withdraw consent at any time, without affecting processing before the withdrawal;

  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects, except as the law permits;

  • complain to a data protection authority: in the European Economic Area, the authority of your country or the Estonian Data Protection Inspectorate (aki.ee), which supervises NewGen Europe OÜ; in the United Kingdom, the Information Commissioner's Office (ico.org.uk); in the United Arab Emirates, the UAE Data Office.

Residents of California and other US states with privacy laws: we do not sell personal data or share it for cross-context behavioural advertising, and you may exercise the rights above in the same way.

To exercise a right, write to [email protected]. You can delete your own account in Settings in the portal or the app (section 9). We answer within one month and may ask you to confirm your identity. Where a request concerns data we process for one of our clients, we refer it to that client and help them answer it.

9. Deleting your account

You can delete your account in Settings in the portal or the app. If your organisation has not signed an Agreement, the account is deleted straight away, together with its sign-in sessions, linked channels and Google or Apple sign-in links, and an organisation that never signed is closed. If your organisation has signed, deleting is handled as a request to erase your data: we deal with it within 5 business days and keep only what the law or the Agreement requires us to keep, such as invoices and the signed Agreement.

10. Security

We protect personal data with access controls, encryption in transit, private storage for documents such as licences, invoices and agreements, separation of each client's data, logging of privileged actions, regular backups and confidentiality obligations for our staff. If a personal data breach is likely to put you at risk, we notify the competent authority and, where required, you, without undue delay and within 72 hours of becoming aware of it.

11. Cookies and similar technologies

  • newgen.market keeps your language and your cookie choice in your browser's local storage. These are needed for the site to work and are always on.

  • The chat on newgen.market keeps the id of your conversation, whether you have left your contact details and whether you have turned its sound off, in your browser's local storage, so that you can pick up the same conversation later. Clear this site's data to start afresh.

  • If you come to newgen.market through a sales partner's link, the site keeps that partner's code in your browser's local storage (newgen.partner), so that the partner is recognised if you sign up. Clear this site's data to remove it.

  • The client portal keeps your sign-in session and your language in your browser's local storage. These are needed for the portal to work.

  • Our own analytics, on newgen.market and in the portal: if you accept analytics, or once you are signed in to the portal, the site keeps an id for your browser (ng_vid, 13 months) and one for your visit (ng_sid, 30 minutes) in first-party cookies on newgen.market and its subdomains. If you decline or make no choice, neither is set and your visits are only counted. Our own team's browsers keep a cookie (ng_staff) so that their visits are left out.

  • Google Analytics runs on newgen.market and in the portal only if you accept analytics in the cookie banner. If you decline or make no choice, it does not load and sets no cookies. To change your choice, clear this site's data in your browser and we will ask again.

  • Cloudflare, which protects our websites, may set a short-lived security cookie (__cf_bm) to tell people from automated traffic. It is needed for that protection to work.

  • To support the Telegram Mini App, our websites load a script from Telegram, which lets Telegram see your IP address.

  • The app uses no cookies. It keeps your sign-in in your device's secure storage (the iOS Keychain or the Android Keystore) and, unless you switch usage analytics off in Settings, an id it makes for itself when installed, with which it sends the screens you open and the buttons you tap.

  • When we send a business its plan, the link is its own: our page records when it is opened and which links in it are clicked, with a cookie for that link alone and without any third party. If the browser opening it has accepted analytics on newgen.market, its visits to our site are linked to that business.

  • We do not use advertising or cross-site tracking cookies.

12. Messaging platforms

When you write to us on WhatsApp or Telegram, the platform processes your data under its own terms and privacy policy, and we receive your identifier and the messages you send. We message you there only about your account and, outside WhatsApp's free-form window, only with templates the platform has approved. You can unlink a channel at any time on the Team screen.

13. Children

Our services are for businesses and their staff. They are not directed at, and we do not knowingly collect data from, anyone under 18.

14. Changes to this policy

We publish any new version at newgen.market/privacy with its effective date and, for material changes, tell account holders by email at least 14 days before they take effect.

15. Contact

Privacy questions and requests: [email protected].

NewGen International Inc., 1221 Brickell Center, Miami, FL 33131, United States of America. Establishment in the European Union: NewGen Europe OÜ, Tallinn, Estonia.