GDPR

Last updated

NKable serves nine languages and actively invites European visitors, so this page sets out your GDPR rights properly rather than as a formality — including the one area where our retention practice currently falls short of what the regulation expects.

1. Who this applies to

This page covers you if you are in the United Kingdom, the European Union or the European Economic Area. It sits alongside the privacy policy, which describes what NKable collects; this page explains the legal basis for each use and the rights you have over it.

NKable is the controller for that data. Contact: [email protected].

2. Data minimisation by design

The strongest thing we can say under Article 5(1)(c) is architectural: the majority of NKable's tools execute in your browser and transmit nothing. For those tools there is no processing by us at all — no lawful basis is needed, no rights request is necessary, and a breach of our systems could not expose your data because we never received it. The sections below concern only the minority of tools that use our server, plus accounts and the contact form.

4. Your rights

Under UK and EU GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted (“right to be forgotten”).
  • Restriction — have us pause processing while a dispute is resolved.
  • Portability — receive your data in a machine-readable format.
  • Object — object to processing carried out under legitimate interests, including the usage logging in section 3.
  • Withdraw consent — at any time, where processing relies on consent.

5. How to exercise them

Email [email protected] with the subject “GDPR request”, or use the contact form. Tell us which right you are exercising and enough detail to find the data:

  • If you have an account — the email address on it is enough.
  • If you do not — the IP address you used and the approximate date and tool, since a usage row is not otherwise linked to a person.

We respond within 30 days, free of charge. We may ask for confirmation of identity before disclosing or deleting data, so that a request cannot be used to obtain someone else's information.

6. Retention

Article 5(1)(e) requires personal data to be kept no longer than necessary. Uploaded files are deleted a few minutes after processing, and contact form rate-limiting holds an IP in memory for ten minutes and never writes it down.

Server-side tool usage rows — the ones carrying an IP address and browser user-agent — are deleted 90 days after they are written, by a sweep that runs daily on our server. Anonymous SEO audit and speed test reports go on the same schedule. Nothing has to be requested for this to happen.

An earlier version of this page said those rows had no expiry at all, and that was true when it was written. The sweep now exists; this paragraph will change again if the period does.

You can still ask us to erase data before the 90 days elapse — email [email protected] with the IP address and rough date. Reports attached to a signed-in account are excluded from the sweep and last until you delete them or close the account. See also the privacy policy.

7. International transfers

Our infrastructure providers, including Cloudflare and our host, may process data outside the UK and EEA. Where that happens, transfers rely on the appropriate safeguards those providers maintain, such as Standard Contractual Clauses. Because browser-side tools transmit nothing, the majority of what you do on NKable is never transferred anywhere at all.

8. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. The tools compute what you ask them to compute; they do not score, rank or make decisions about you.

9. EU and UK representative

We have not appointed an Article 27 representative in the EU or UK. We are stating that rather than leaving it unsaid. If you are in the UK or EEA and need to raise something, email [email protected] and it will reach a person directly.

10. Complaints

If you are unhappy with how we have handled your data, please tell us first — most issues are quicker to fix directly. You also have the right to complain to a supervisory authority:

  • UK — the Information Commissioner's Office (ICO).
  • EU/EEA — the data protection authority in your country of residence.

You do not need our permission, and complaining costs you nothing.

11. Breach notification

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell affected people directly where the risk is high.