Your data,
handled with care.
Who we are
NOCT is a direct-to-consumer sleep and recovery brand, incorporated in the Netherlands. We operate the online store at noct and are responsible for the personal data you share with us.
For the purposes of the General Data Protection Regulation (GDPR), NOCT acts as the data controller. Our business details are registered with the Dutch Chamber of Commerce (KvK).
Data we collect
We only collect what we need to provide you with the best sleep recovery experience possible. Here's an honest breakdown:
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, email address, shipping address | You, at checkout |
| Payment data | Transaction ID, payment method type | Payment processor (we never see card numbers) |
| Order information | Products ordered, quantities, order history | WooCommerce platform |
| Account data | Username, hashed password, preferences | You, if you create an account |
| Usage & analytics | Pages visited, time on site, device type | Cookies & analytics tools |
| Communications | Support messages, email responses | You, when you contact us |
| Quiz responses | Sleep audit answers, recovery scores | You, if you take our sleep audit |
How we use it
We use your personal data for specific, legitimate purposes only. We do not sell your data — ever.
Processing, shipping, and updating you on your orders. Handed off securely to our fulfilment partners.
Responding to questions, resolving issues, and making things right when needed.
Understanding how our store is used so we can make it better — anonymised where possible.
Sending relevant emails and product updates — only if you've opted in, and always easy to unsubscribe.
Meeting Dutch and EU tax, accounting, and consumer protection obligations.
Matching you with products suited to your recovery profile — only based on what you share with us.
Our legal basis
Under GDPR, we must have a lawful basis for processing your data. We rely on the following grounds:
| Processing purpose | Legal basis (GDPR Art.) |
|---|---|
| Order processing & fulfilment | Contract performance (Art. 6(1)(b)) |
| Customer support | Contract performance (Art. 6(1)(b)) |
| Tax and legal obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing emails | Consent (Art. 6(1)(a)) |
| Analytics & store improvement | Legitimate interests (Art. 6(1)(f)) |
| Fraud prevention | Legitimate interests (Art. 6(1)(f)) |
Who we share with
We share data only where strictly necessary. Our key processors include:
| Processor | Role | Location |
|---|---|---|
| DSers | Order fulfilment & logistics | China / Global |
| Supliful | Print-on-demand fulfilment | EU / US |
| Payment provider (e.g. Mollie) | Secure payment processing | Netherlands / EU |
| Email marketing platform | Transactional & marketing emails | EU / US |
| Analytics provider | Anonymised site analytics | EU / US |
| Hosting / WordPress | Website infrastructure | EU |
All processors are bound by data processing agreements. For transfers outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism.
How long we keep it
We hold data for as long as needed to deliver our service and meet legal obligations — and no longer.
| Data type | Retention period |
|---|---|
| Order & financial records | 7 years (Dutch tax law) |
| Account data | Until account deletion + 30 days |
| Marketing consent & history | Until unsubscribe + 3 years |
| Support communications | 2 years after resolution |
| Sleep audit responses | Session only (not stored server-side) |
| Analytics data | 26 months (anonymised) |
Cookies & tracking
We use cookies to keep the store running smoothly and to understand how people use it. We don't use cookies to build advertising profiles without your consent.
| Type | Purpose | Consent required |
|---|---|---|
| essential | Cart, session, login — store can't function without these | No |
| functional | Remembering preferences (currency, language) | No |
| analytics | Understanding traffic and page performance | Yes |
| marketing | Retargeting and ad performance tracking | Yes |
You can manage cookie preferences at any time via the cookie banner on our site, or by adjusting your browser settings. Note that disabling essential cookies will affect store functionality.
Your rights
As a data subject under GDPR, you have the following rights. We honour all of them — no unnecessary friction, no dark patterns.
-
Access
Right to access Request a copy of all personal data we hold about you, in a portable format.
-
Rectify
Right to rectification Ask us to correct inaccurate or incomplete personal data.
-
Erase
Right to erasure Request deletion of your personal data, subject to legal retention requirements.
-
Restrict
Right to restriction Ask us to pause processing your data in certain circumstances.
-
Object
Right to object Object to processing based on legitimate interests, including direct marketing.
-
Portability
Right to data portability Receive your data in a structured, machine-readable format for transfer elsewhere.
-
Withdraw
Right to withdraw consent Withdraw consent at any time for consent-based processing (e.g. marketing emails), without affecting prior processing.
-
Complain
Right to lodge a complaint File a complaint with the Dutch Data Protection Authority — Autoriteit Persoonsgegevens — at autoriteitpersoonsgegevens.nl
To exercise any right, email us at noct@getnoct.com. We will respond within 30 days as required by GDPR.
How we keep your data safe
We take security seriously. Measures in place include HTTPS/TLS encryption on all data in transit, access controls limiting who can view customer data internally, PCI-compliant payment processing (we never store card details), regular software and plugin updates, and monitoring for suspicious access patterns.
In the unlikely event of a data breach that poses a risk to your rights, we are obligated to notify the Autoriteit Persoonsgegevens within 72 hours and inform affected individuals without undue delay.
Get in touch
Questions about this policy, your data, or how we operate? We're a small, honest team — reach out directly.
Privacy enquiries
Email: noct@getnoct.com
We aim to respond within 5 business days. For formal GDPR requests, we are legally required to respond within 30 days.
This privacy statement was last updated 24 September 2026. We may update it from time to time — significant changes will be communicated via email or a notice on our website. Continued use of NOCT after changes constitutes acceptance of the revised policy.