Every time you interact with NESTKARTER — placing an order, contacting support, browsing our site — data flows into our systems. Here’s exactly why, how, and under what limits that happens.
Handle data only to fulfill operational and legal obligations
We handle your data to deliver orders, respond to inquiries, prevent fraud, and comply with binding legal requirements. When you reside within the European Economic Area (EEA), any processing requiring your prior express consent is justified solely under Article 6(1) of the General Data Protection Regulation (EU) (“GDPR”). We do not process data beyond what is strictly necessary for these purposes — no speculative or secondary uses.
Collect only what’s needed to complete your request or uphold legal duties
We receive data directly from you: name, email, billing and shipping addresses, payment details (including card number and verification data), and authentication information when you create an account or make a purchase. We also collect technical data automatically — device type, IP address, operating system, browser type, usage patterns, diagnostic logs, and approximate location (derived from IP or GPS where available) — solely to maintain service integrity, troubleshoot issues, and improve functionality. We do not collect biometric, genetic, or sensitive personal data unless explicitly required by law to fulfill a transaction or legal obligation.
Limit transfers to service-critical partners and enforce purpose-bound use
Your data moves only to entities essential to delivering what you’ve requested: payment processors, logistics providers, customer support platforms, and advertising technology vendors acting strictly on our behalf. We share data only to provide or improve our products, services, and advertising. We will not share your personal data with third parties for their own marketing purposes without your prior express consent. Where transfers occur outside the EEA, we rely on legally valid mechanisms — including Standard Contractual Clauses — to ensure equivalent protection. We do not permit downstream sharing or repurposing by partners.
Retain data no longer than required to achieve its defined purpose
We keep your personal data for as long as it is necessary to fulfill the purposes outlined in this Privacy Statement — such as fulfilling orders, resolving disputes, enforcing agreements, or meeting audit or tax obligations. We do not retain data indefinitely. If a longer retention period is required or permitted by law — for example, for financial recordkeeping or regulatory reporting — we retain only what is mandated, and only for the duration specified.
Enable you to act — not just know — on your rights
You may access, correct, or delete your personal data. You may restrict or object to further processing. You may receive your personal data in a structured, commonly used, and machine-readable format. You may lodge a complaint with the competent data protection authority. To verify your identity and ensure data security, we may ask for confirmation — such as your order ID or registered email — before fulfilling your request. We will respond to your request within less than 30 days, unless applicable laws or regulatory requirements allow or require us to refuse. There are no discretionary delays or subjective exceptions.
Disclose only when legally compelled or operationally unavoidable
We disclose personal data only when required by law, legal process, litigation, or requests from public and governmental authorities — including those outside your country of residence. We also disclose data when necessary for national security, law enforcement, or other issues of public importance. We do not disclose data based on internal policy preferences, commercial convenience, or unverified risk assessments.
Protect data in active custody — not just at rest
We protect personal data while it is in our active systems — during transmission, processing, and storage — using measures aligned with industry standards for confidentiality, integrity, and availability. This includes encryption in transit and at rest, role-based access controls, and regular review of system permissions. We do not claim broad or undefined safeguards; our protections are specific, actionable, and tied to functional necessity.
If you’ve asked us to act on your rights, we’ll confirm receipt within 48 hours and complete your request within 30 days — unless law prevents it. No exceptions. No delays. Contact cs@nestkarter.com with your order ID or account email to begin.