By making a purchase, becoming a Nest member, using our website, entering a Nest competition, or providing your details to us in-store or over the phone, then you acknowledge that your personal data may be used according to the practices set out in this policy.
In order to provide you with our services, sometimes we might need to collect some personal data from you. When it comes to privacy, why we’re different comes down to something simple; we care.
Here at Nest we promise to be transparent with you about how we collect, process, store and share your personal data:
We may also need to share your information with third parties who help us to provide our services, such as our couriers so they can deliver your items to you. We will make sure that all third parties we are engaged with treat your personal data with as much respect as we do.
9 Parkway Rise
Phone number: 0114 243 3000
Email address: email@example.com
Registered company number: 04709529
ICO registration number: ZA363410
This section explains how and when we collect your personal data.
Data you give to us:
Data we collect when you use our services:
Data from 3rd parties we work with:
We have to collect some information from you so that we can provide you with our services, for example when you order items from us. We do our best to make sure that we do not collect excessive information from you and limit it to only what is necessary for us to provide the service you require.
We do not collect any special category personal data from any of our customers. This includes information about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
Data we collect about you
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
We will only use personal information about you if we have a legal basis to do so, and we will tell you what that legal basis is. We have set out in the table below: the personal information which we collect from you, how we use it, and the legal ground on which we rely when we use the personal information. In some circumstances, we can use your personal information if it is in our legitimate interest to do so, provided that we have told you what that legitimate interest is. A legitimate interest is when we have a business or commercial reason to use your information which, when balanced against your rights, is justifiable. If we are relying on our legitimate interests, we have set that out in the table below.
|What we use your personal information for||What personal information we collect||Our legal grounds for processing||Our legitimate interests (if applicable)|
|To register you as a new member and create your nest.co.uk account||Identity
|Performance of a contract with you|
|To process your transactions and deliver your items||Identity
|Performance of a contract with you|
|To manage payments and recover any money owed to us||Identity
|Performance of a contract with you Legitimate interests||To recover any debts owed to us|
|To make suggestions and recommendations to you about items that may be of interest to you||Identity
Marketing and communications
|Legitimate interests Consent||To better tailor our services to our customers and grow our business|
|To manage our relationship with you, including notifying you about changes to our terms or privacy notices||Identity
|Performance of a contract with you Necessary to comply with a legal obligation Legitimate interests||To keep our records up to date|
|To enable you to partake in a prize draw, competition or to complete a survey||Identity
|Performance of a contract with you Legitimate interests Consent||To study how customers use our services and to grow our business|
|To administer and protect our business and our website||Transaction
|Legitimate interests||Running our business, provision of administration and IT services, network security|
|To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you||Identity
Marketing and communications
|Legitimate interests||To study how customers use our services, to develop them, to grow our business and to inform our marketing strategy|
|To use data analytics to improve our website, products/services, marketing, customer relationships and experiences||Technical
|Legitimate interests||To define types of customers for our services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy|
|To carry out session recordings to improve our website, products/services, marketing, customer relationships and experiences||Identity
|Legitimate interests Consent||To study how customers use our website, to develop and improve our website (including bug-fixing) and to inform our marketing strategy|
We use MailChimp to help manage our marketing database and send out information to you, so your data, including your name, email address and phone number will be stored within the MailChimp system.
MailChimp may process some of your personal data outside of the EEA and we have ensured that there are appropriate safeguards in place for doing so. MailChimp is Privacy Shield certified and also use Standard Contractual Clauses to ensure the security of processing outside of the EEA.
We will share your name, address, email address and phone number with our couriers so that they can deliver your items to you and contact you with delivery updates. We use different couriers depending on the size of the item you have ordered, how quickly you have requested your delivery, and where you live, but we will always tell you who will be delivering your order.
To help us manage our customer relations, we use systems Pipedrive and Trello, so your name, contact details and any information relating to your orders with us may be stored within these systems.
Both Pipedrive and Trello may process your personal data outside of the EEA.
Pipedrive’s US entity is in the process of obtaining their Privacy Shield certification.
We use third-party payment providers, Datacash (Mastercard Payment Gateway service), PayPal and Sprint to securely process our transactions, so information relating to your transactions, including your card details, will be shared with these providers.
Datacash and PayPal may all process your personal data outside of the EEA.
We are working closely with Sprint to ensure that any personal data transferred outside of the EEA is done so using appropriate safeguards.
Our live-chat function is provided by Intercom, Inc. Personal data transferred via this mechanism may include your name, contact details and order details.
Intercom may process your personal data outside of the EEA. The organisation is Privacy Shield certified and you can view their certification here.
We work hard to ensure that we do not keep your personal data for longer than is necessary to fulfil the purpose for which it was collected. Generally, we will not keep your personal details for longer than 6 years as this is the statutory retention period for HMRC records.
We will protect the data you entrust to us with appropriate measures and controls, as well as ensuring that the companies we work with are just as careful with your data.
You have the following rights with regards to your personal data:
1. Where the personal data is no longer necessary in relation to the purpose for which it was originally collected or processed;
2. When you withdraw consent;
3. When you object to the processing and there is no overriding legitimate interest for continuing the processing;
4. When the personal data was unlawfully processed;
5. When the personal data has to be erased in order to comply with a legal obligation.
1. where you contest the accuracy of your personal data, we will restrict the processing until you have verified the accuracy of your personal data;
2. where you have objected to processing and we are considering whether our legitimate grounds override your legitimate grounds;
3. when processing is unlawful and you oppose erasure and request restriction instead;
4. where we no longer need the personal data but you require the data to establish, exercise or defend a legal claim.
1. Direct marketing – remember you can opt out at any time from our marketing communications using the preference centre in your Nest account, by using the ‘unsubscribe’ function in our marketing emails or by contacting us at firstname.lastname@example.org or on 0114 243 3000;
2. Where the processing is based on legitimate interests; and
3. Processing for purposes of scientific/historical research and statistics.
You also have the right not to be subject to a decision that is based solely on automated processing. Nest.co.uk does not conduct any automated decision making, including profiling, on our customers.
Sign up for our emails and we'll deliver exclusive content direct to your inbox covering all things design. From new arrivals and limited editions, to leading design events, promotions and more - you'll be kept firmly in the loop.
Thanks for signing up to Nest. We will keep you up-to-date with all of our latest offers, stories, new releases and events. Look out for your 10% off promo code in your inbox.