1 Nubikk
1.1 We are Nubikk Retail B.V., located at Raadhuisplein 2A, 5141 KG Waalwijk, the Netherlands, registered in the Dutch Chamber of Commerce under number (“Nubikk”, “we”, “us” or “our”). You can reach us via e-mail
1.2 When you visit our website (“Website”), when you create an account, when you are a (potential) customer, provide services to us, contact us or apply for a job with us, we process your personal data. We are the “data controller” for the processing of your personal data as further described in this Privacy Statement (“Privacy Statement“). In this Privacy Statement, we explain why and how we process your personal data.
1.3 Our Website uses cookies. You can find more information about the use of cookies in our Cookie Statement.
2 Categories of personal data being processed
2.1 When you visit our Website, create an account, when you are a (potential) customer, provide services to us, apply for a position with us, visit us or contact us, we process your personal data. Below we inform you about the categories of personal data we process for each category of data subjects. The personal data mentioned under 2.3, 2.4, 2.5 and 2.6 are necessary to fulfill a statutory or contractual obligation or is a necessary condition to enter into a contract with you, unless indicated otherwise.
2.2 Website visitors – When you visit our Website, we may process the following personal data:
2.2.1 IP address;
2.2.2 Most visited pages and searches within the Website;
2.2.3 Website usage and browser data;
2.2.4 Items in your basket;
2.2.5 Interactions with our Website after receiving notifications or e-mails and how you have reached our website;
2.2.6 Data about your device with which you visit our Website;
2.2.7 Automatically collected personal data through the use of cookies and/or similar technologies.
2.3 Account holders – When you create an account via our Website, we may process the following personal data:
2.3.1 First and last name;
2.3.2 Address;
2.3.3 E-mail address;
2.3.4 Phone number;
2.3.5 Date of birth;
2.3.6 Password (in pseudonymized form).
2.4 Customers – When you become a customer by purchasing an item via our Website, we may process the following personal data:
2.4.1 First and last name, company name if applicable;
2.4.2 Shipping address;
2.4.3 E-mail address
2.4.4 Billing address;
2.4.5 Bank account information;
2.4.6 Order notes (optional).
2.5 Service providers – When you provide services to us, we may collect:
2.5.1 Contact person’s name, business e-mail address and/or phone number.
2.6 Job applicants – When you apply for a position with us, we may collect:
2.6.1 Name, address and contact details;
2.6.2 Your latest and desired salary;
2.6.3 Interview notes, if applicable;
2.6.4 CV, employment history, qualifications.
2.7 Marketing and other communications – For marketing and other communications, we may collect:
2.7.1 Name, e-mail address, phone number;
2.7.2 Any other information you provide to us when you contact us.
2.8 Visitors – When you visit our premises, we may collect:
2.8.1 Name and contact details,
2.8.2 Your image.
3 Source of personal data
3.1 We collect and receive the personal data under 2 directly from you or the organization you represent. We do not use further or public sources to collect your personal data unless otherwise expressly provided.
4 Purposes of the processing
4.1 Personal data as mentioned under 2 will be processed for the following purposes:
4.1.1 To offer you our Website, to measure your use thereof and to improve them (see 2.2);
4.1.2 To offer and promote our products and services to you or to promote the products and services of our group companies, to the extent you provided consent for such data processing (see 2.3, 2.4 and 2.7);
4.1.3 To inform you about new items which may be of interest to you based on your previous use of our Website (see 2.3, 2.4 and 2.7);
4.1.4 To receive services from you or to collaborate with you (see 2.5);
4.1.5 To execute any other agreement between Nubikk and you;
4.1.6 For internal administrative purposes;
4.1.7 To fulfill our obligations under statutory law, such as the fiscal retention obligation;
4.1.8 To assess and review your job application (see 2.6);
4.1.9 To secure our employees and our assets (see 2.8);
4.1.10 To handle any requests you may have submitted to us.
5 Lawful bases of the processing
5.1 The lawful bases for processing personal data as listed under 2 are:
5.1.1 The necessity of the processing for the performance of an agreement to which you are a party or to take measures at your request prior to the conclusion of an agreement;
5.1.2 To comply with any statutory provisions applicable to us;
5.1.3 The necessity of the processing to serve a legitimate interest of ours that outweighs your privacy interest, which is our interest in measuring website usage, to secure our personnel and assets, to improve our products and services and to promote our products and services to you;
5.1.4 Your express consent to the processing of your personal data, to the extent no other lawful basis applies.
6 Retention periods
6.1 In principle, your personal data will not be kept longer than necessary for the purpose for which your data was collected, unless a legal obligation obliges us to keep the data for a longer period, such as the seven-year fiscal retention period.
7 Automated decision-making and profiling
7.1 We do not take decisions about you based solely on automated processing and do not engage in profiling.
8 Recipients of personal data
8.1 To the extent necessary for any of the aforementioned purposes of processing, we share your personal data with third parties (“recipients“). The following categories of recipients may have access to your personal data:
8.1.1 Affiliated group companies, if necessary for compliance, internal reporting, audit or security purposes, or for the performance of an agreement with data subjects;
8.1.2 Our auditor, legal advisors and other professional service providers engaged by us for compliance reasons;
8.1.3 Government agencies, courts, supervisory authorities, law enforcement or intelligence agencies, if we have a legal obligation to provide personal data to them;
8.1.4 IT service providers we use for our systems or for our website, such as our provider for data analytics services and customer engagement;
8.1.5 Service providers we use to send you e-mails about our products and services;
8.1.6 Service providers assisting us in executing the agreement with you;
8.1.7 Third parties buying or interested in buying (a stake in) Nubikk and professional service providers involved.
8.2 When transferring personal data to the categories of recipients listed above, we always strive to transfer as little personal data as possible.
8.3 The recipients who receive or have access to your data may be located outside the European Economic Area (EEA). When we transfer data for which we are responsible to countries outside the EEA (so-called “third countries“), we provide appropriate safeguards. More specifically, we impose contractual obligations on the recipients of personal data to protect your personal data using the Standard Clauses (SCCs) as approved by the European Commission. We will assess in advance (where necessary with the assistance of third-country recipients) on a case-by-case basis whether the legislation or practice of the third country compromises the effectiveness of the SCCs. In such cases, we will take additional measures to fill the protection gaps and bring them up to the level required by EU law. You may consult the SCCs we have concluded with recipients by sending an e-mail
9 Security
9.1 Nubikk is committed to secure the processing of your personal data, by relevant maintaining administrative, technical and physical controls with are designed to protect your personal data against loss or theft, as well as against any unauthorized access, risk of loss, disclosure, copying, misuse or modification. Therefore, we implement security measures where appropriate and applicable, such as, but not limited to:
9.1.1 using a reliable SSL Certificate to ensure the safety of your personal data;
9.1.2 Pseudonymization and encryption of personal data;
9.1.3 The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
9.1.4 The ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident; and
9.1.5 A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures to ensure security of processing.
10 Your right to object
10.1 You have the right to object to the processing of personal data because of your specific situation, but only insofar as this processing is carried out on the basis of one of our legitimate interests. We will then cease processing your personal data unless our interest in processing your data outweighs your interests or when our interest is related to the establishment, exercise or enforcement of a legal claim. Furthermore, you have the right to object to the processing of your personal data for direct marketing purposes, for example the promotion of our products and services.
10.2 You can object to the processing of your personal data by sending an e-mail clearly describing your request. Please note that we need to establish your identity before we can respond to your request. The manner in which we do this depends on your specific situation.
11 Other rights regarding the processing of your personal data
11.1 Right of access – You have the right to request access to the personal data we process about you, more specifically about the purposes, the categories of personal data concerned, the (categories of) recipients, the retention periods or the criteria for establishing them, the source of the personal data and the appropriate safeguards in case of transfer of the data outside the EEA.
11.2 Right to rectification of data and restriction of processing – You have the right to have incorrect data that we process about you rectified and to have incomplete data completed by us. Furthermore, you have the right, at your request, to restrict data processing in the following cases:
11.2.1 If you dispute the accuracy of the data, you may ask us to restrict the data processing for the period during which we verify the accuracy of the data;
11.2.2 If the processing is unlawful and you request us, instead of deleting the data, to restrict the use of the data;
11.2.3 In case we no longer need your personal data for the processing purposes, but you still need them for the establishment, exercise or substantiation of a legal claim;
11.2.4 If you have objected to the processing of your data, and you are awaiting our response as to whether our legitimate interests outweigh your interests.
11.3 Right to the deletion of data – In the following cases, you may have the right to have personal data deleted by us at your request:
11.3.1 If we no longer need the data for the purposes for which it was collected or obtained;
11.3.2 If you have withdrawn your consent, insofar as your data are processed on the basis of consent, and we also have no other legal basis for processing your data;
11.3.3 If you have objected to the processing of your data and we have no overriding interest, or if you have objected to the processing of your data for direct marketing purposes;
11.3.4 If we need to delete personal data in order to comply with a statutory obligation.
Please note that the above does not apply in all cases. We do not have to delete your personal data if we need it for, for example, the establishment, exercise or substantiation of a legal claim.
11.4 Right to data transfer – If we process your personal data pursuant to your consent or in execution of an agreement with you and the processing is automated, you have the right to obtain your data from us or have us transfer it to a third party in a commonly used file format.
11.5 Right to withdraw given consent – If your personal data is processed on the basis of consent, you have the right to withdraw your consent. Please note that withdrawing consent does not affect data processing that took place before you withdrew your consent.
You can exercise all of the aforementioned rights by sending an e-mail clearly describing your request. Please note that we need to establish your identity before we can respond to your request. How we do this depends on your specific situation.
11.6 Right to file a complaint – If you disagree with the way Nubikk processes your personal data, you have the right to file a complaint with the competent Data Protection Authority.
12 Third party websites
12.1 This Privacy Statement does not apply to third-party websites that are connected to our Website by hyperlinks. We cannot guarantee that these third parties will handle your personal data in a reliable or secure manner. We advise you to read the privacy statement of these websites before using them.
13 Changes in this Privacy Statement
13.1 We may change this Privacy Statement from time to time. We encourage you to check this page regularly to ensure that you are aware of any changes to this Privacy Statement.
13.2 This Privacy Statement has last been updated on […] November 2024.