GDPR
Last updated
NKable serves nine languages and actively invites European visitors, so this page sets out your GDPR rights properly rather than as a formality — including the one area where our retention practice currently falls short of what the regulation expects.
1. Who this applies to
This page covers you if you are in the United Kingdom, the European Union or the European Economic Area. It sits alongside the privacy policy, which describes what NKable collects; this page explains the legal basis for each use and the rights you have over it.
NKable is the controller for that data. Contact: [email protected].
2. Data minimisation by design
The strongest thing we can say under Article 5(1)(c) is architectural: the majority of NKable's tools execute in your browser and transmit nothing. For those tools there is no processing by us at all — no lawful basis is needed, no rights request is necessary, and a breach of our systems could not expose your data because we never received it. The sections below concern only the minority of tools that use our server, plus accounts and the contact form.
3. Legal basis for each purpose
| Processing | Lawful basis | Note |
|---|---|---|
| Processing a file you uploaded to a server-side tool | Article 6(1)(b) — performance of a contract | You asked for the conversion; doing it is the service |
| Logging IP and user-agent on server-side tool use | Article 6(1)(f) — legitimate interests | Abuse prevention and fault diagnosis. See section 6 on retention |
| Holding your account record | Article 6(1)(b) — performance of a contract | Only if you chose to create one |
| Replying to your contact form message | Article 6(1)(b) / 6(1)(f) | You contacted us in order to get a reply |
| Rate-limiting the contact form by IP | Article 6(1)(f) — legitimate interests | In memory for ten minutes; never written to disk |
| Analytics | Not applicable — none is running | If enabled, it would require your consent first, not legitimate interests |
4. Your rights
Under UK and EU GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted (“right to be forgotten”).
- Restriction — have us pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable format.
- Object — object to processing carried out under legitimate interests, including the usage logging in section 3.
- Withdraw consent — at any time, where processing relies on consent.
5. How to exercise them
Email [email protected] with the subject “GDPR request”, or use the contact form. Tell us which right you are exercising and enough detail to find the data:
- If you have an account — the email address on it is enough.
- If you do not — the IP address you used and the approximate date and tool, since a usage row is not otherwise linked to a person.
We respond within 30 days, free of charge. We may ask for confirmation of identity before disclosing or deleting data, so that a request cannot be used to obtain someone else's information.
6. Retention
Article 5(1)(e) requires personal data to be kept no longer than necessary. Uploaded files are deleted a few minutes after processing, and contact form rate-limiting holds an IP in memory for ten minutes and never writes it down.
Server-side tool usage rows — the ones carrying an IP address and browser user-agent — are deleted 90 days after they are written, by a sweep that runs daily on our server. Anonymous SEO audit and speed test reports go on the same schedule. Nothing has to be requested for this to happen.
An earlier version of this page said those rows had no expiry at all, and that was true when it was written. The sweep now exists; this paragraph will change again if the period does.
You can still ask us to erase data before the 90 days elapse — email [email protected] with the IP address and rough date. Reports attached to a signed-in account are excluded from the sweep and last until you delete them or close the account. See also the privacy policy.
7. International transfers
Our infrastructure providers, including Cloudflare and our host, may process data outside the UK and EEA. Where that happens, transfers rely on the appropriate safeguards those providers maintain, such as Standard Contractual Clauses. Because browser-side tools transmit nothing, the majority of what you do on NKable is never transferred anywhere at all.
8. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. The tools compute what you ask them to compute; they do not score, rank or make decisions about you.
9. EU and UK representative
We have not appointed an Article 27 representative in the EU or UK. We are stating that rather than leaving it unsaid. If you are in the UK or EEA and need to raise something, email [email protected] and it will reach a person directly.
10. Complaints
If you are unhappy with how we have handled your data, please tell us first — most issues are quicker to fix directly. You also have the right to complain to a supervisory authority:
- UK — the Information Commissioner's Office (ICO).
- EU/EEA — the data protection authority in your country of residence.
You do not need our permission, and complaining costs you nothing.
11. Breach notification
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell affected people directly where the risk is high.