Privacy Policy
The information below explains the type, scope and purpose of collecting, using and processing personal data on our website: https://studio.netnest.be
1. Controller
1.1 Controller within the meaning of the GDPR
The controller within the meaning of Art. 4(7) GDPR is:
NetNest
Belgium
1.2 Contact
If you have questions about data protection, or wish to exercise rights relating to your personal data, you can reach us using the contact details above or via email at sales@netnest.be.
When you contact us (for example by email or phone), we store the information you provide so we can handle your request and follow up if needed. The legal basis is Art. 6(1)(b) GDPR where your request relates to a contract or pre-contractual steps, otherwise Art. 6(1)(f) GDPR. We delete this data when it is no longer required, or restrict processing where statutory retention obligations apply (see section 15.2).
2. Data we process
2.1 Legal bases
Personal data is only processed where permitted by law. Under Art. 6(1) GDPR, this includes where:
- you have given consent;
- processing is necessary for the performance of a contract with you;
- processing is necessary to take steps at your request before entering into a contract;
- processing is necessary to protect vital interests of you or another person;
- processing is necessary for our legitimate interests or those of a third party, unless your interests or fundamental rights override those interests.
Personal data is deleted once the purpose of collection no longer applies (see section 15.2).
2.2 What is personal data?
Personal data means any information relating to an identified or identifiable natural person (Art. 4 GDPR). This can include identity data (such as name and email address), contract data (services used, billing information), usage data (pages visited, features used) and content data (information you upload to sites or send to us).
When you visit our website, technical data may also be processed, such as IP address, browser type, operating system, referrer URL, access time and error logs. We generally use technical data only as needed to operate and secure the platform under Art. 6(1)(f) GDPR.
2.3 What does processing mean?
Processing means any operation performed on personal data, including collection, storage, adaptation, use, disclosure, restriction, erasure or destruction (Art. 4 GDPR).
3. Data security
Protecting your personal data is a priority. We use technical and organisational measures to comply with data protection law and reduce the risk of loss, misuse or unauthorised access. Staff who process personal data are bound by confidentiality obligations.
4. SSL encryption
Our website uses SSL/TLS encryption when personal data or account content is transmitted. You can recognise an encrypted connection when the browser address bar switches from "http://" to "https://". Only submit confidential information when SSL encryption is active.
5. Hosting and infrastructure
5.1 Platform hosting
NetNest Studio is hosted on cloud infrastructure that provides computing capacity, storage, security and maintenance services. Access and server data required to operate the website are processed for this purpose on the basis of Art. 6(1)(f) GDPR.
5.2 Supabase
We use Supabase for authentication, database hosting and related backend services. Supabase may process account identifiers, login metadata, IP addresses and data you store in the platform. Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR. Further information: supabase.com/privacy.
6. Data collected when visiting our website
When you use our website for information only (without registering or submitting data), we collect the data your browser sends to our servers that is technically required to display the site and maintain stability and security (Art. 6(1)(f) GDPR), such as:
- IP address of the requesting device;
- date and time of access;
- requested page or file;
- HTTP status code and transferred data volume;
- referrer URL, browser and operating system.
Security-related log data is retained for a limited period and then deleted, unless longer retention is required for evidence purposes.
Cookies may also be stored on your device (see section 12). We do not use the collected data to draw conclusions about your identity for marketing profiling on this marketing site.
7. Disclosure to third parties
We only share personal data where legally permitted, including where:
- you have given explicit consent (Art. 6(1)(a) GDPR);
- disclosure is necessary to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR);
- a legal obligation requires disclosure (Art. 6(1)(c) GDPR); or
- disclosure is necessary for contract performance with you (Art. 6(1)(b) GDPR).
We share data only with carefully selected processors bound by contract to protect personal data in line with applicable law.
8. Where your data is stored
Personal data is generally stored within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure appropriate safeguards, such as EU Standard Contractual Clauses or an adequacy decision, so that a level of protection comparable to the GDPR is maintained.
9. Contracts and user accounts
When you create an account or use NetNest Studio, we collect and process the data you provide to establish and perform the service relationship (Art. 6(1)(b) GDPR). Required fields are shown during registration and typically include name, email address and workspace or site details.
We may also store your IP address and timestamps of registration and sign-in to protect against misuse (Art. 6(1)(f) GDPR). When you delete your account, associated personal data is deleted unless retention is required by law (see section 15.2).
If you sign in with Google, authentication is handled via Supabase OAuth. Google's privacy policy applies to that sign-in flow in addition to this policy.
10. External payment providers
For paid plans we use Stripe to process subscriptions and billing (Art. 6(1)(b) and Art. 6(1)(f) GDPR). Stripe may process identity, contact, payment and transaction data required to complete payments. We do not receive full payment card details; we receive confirmation of payment status. Stripe's privacy policy applies: stripe.com/privacy.
11. Email and notifications
We send service-related emails such as account notices, invitations, billing updates and security messages (Art. 6(1)(b) and Art. 6(1)(f) GDPR). Transactional email is delivered via Resend. Further information: resend.com/legal/privacy-policy.
If you subscribe to a newsletter or marketing list, we process your email address only with your consent (Art. 6(1)(a) GDPR). You can unsubscribe at any time using the link in the email or by contacting us.
12. Cookies
We use cookies and similar technologies where necessary to operate the service, keep you signed in and protect the platform. Strictly necessary cookies cannot be disabled individually without affecting core functionality.
Where non-essential cookies require consent, the legal basis is Art. 6(1)(a) GDPR. Otherwise our legitimate interest in secure and efficient operation applies (Art. 6(1)(f) GDPR). You can restrict or delete cookies in your browser settings; some features may then not work correctly.
13. Social media and external links
Our website may link to external services such as social networks (for example Instagram). These links are ordinary HTML links, not embedded plugins. No connection to the provider's servers is established until you click the link and open their site.
The provider's own privacy policy applies once you leave our website. Legal basis for displaying links on our site: Art. 6(1)(f) GDPR.
14. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR): request information about data we process about you.
- Rectification (Art. 16 GDPR): request correction of inaccurate data.
- Erasure (Art. 17 GDPR): request deletion where legal requirements are met.
- Restriction (Art. 18 GDPR): request limited processing in certain cases.
- Data portability (Art. 20 GDPR): receive data you provided in a structured, machine-readable format where applicable.
- Withdraw consent (Art. 7(3) GDPR): withdraw consent at any time for future processing based on consent.
- Complaint (Art. 77 GDPR): lodge a complaint with a supervisory authority, for example the Belgian Data Protection Authority (dataprotectionauthority.be).
To exercise your rights, contact us at sales@netnest.be. No fee is charged for legitimate requests.
14.1 Right to object
Where we process data on the basis of legitimate interests, you may object on grounds relating to your situation. We will assess the objection and stop or adjust processing unless compelling legitimate grounds override your interests.
You may object at any time to processing for direct marketing purposes.
14.2 Deletion and retention
We delete personal data when it is no longer needed for the purpose for which it was collected. Statutory retention obligations may require us to block rather than delete certain data (for example billing and tax records). Retention periods depend on the type of data and applicable Belgian and EU law.
15. Changes to this privacy policy
This privacy policy is current as of August 2026. We may update it when legal requirements or our processing activities change. Material changes that affect consent or contractual terms will be communicated separately where required.