Privacy Statement — NOCT
Legal · Privacy

Your data,
handled with care.

Effective date: 24 September 2026  ·  GDPR compliant  ·  Netherlands

01 —

Who we are

NOCT is a direct-to-consumer sleep and recovery brand, incorporated in the Netherlands. We operate the online store at noct and are responsible for the personal data you share with us.

For the purposes of the General Data Protection Regulation (GDPR), NOCT acts as the data controller. Our business details are registered with the Dutch Chamber of Commerce (KvK).

Data Controller

NOCT
The Netherlands

Email: noct@getnoct.com

02 —

Data we collect

We only collect what we need to provide you with the best sleep recovery experience possible. Here's an honest breakdown:

Category Examples Source
Identity & contact Name, email address, shipping address You, at checkout
Payment data Transaction ID, payment method type Payment processor (we never see card numbers)
Order information Products ordered, quantities, order history WooCommerce platform
Account data Username, hashed password, preferences You, if you create an account
Usage & analytics Pages visited, time on site, device type Cookies & analytics tools
Communications Support messages, email responses You, when you contact us
Quiz responses Sleep audit answers, recovery scores You, if you take our sleep audit
03 —

How we use it

We use your personal data for specific, legitimate purposes only. We do not sell your data — ever.

📦 Order fulfilment

Processing, shipping, and updating you on your orders. Handed off securely to our fulfilment partners.

💬 Customer support

Responding to questions, resolving issues, and making things right when needed.

📊 Analytics & improvement

Understanding how our store is used so we can make it better — anonymised where possible.

📩 Marketing

Sending relevant emails and product updates — only if you've opted in, and always easy to unsubscribe.

⚖️ Legal compliance

Meeting Dutch and EU tax, accounting, and consumer protection obligations.

🎯 Personalisation

Matching you with products suited to your recovery profile — only based on what you share with us.

05 —

Who we share with

We share data only where strictly necessary. Our key processors include:

Processor Role Location
DSers Order fulfilment & logistics China / Global
Supliful Print-on-demand fulfilment EU / US
Payment provider (e.g. Mollie) Secure payment processing Netherlands / EU
Email marketing platform Transactional & marketing emails EU / US
Analytics provider Anonymised site analytics EU / US
Hosting / WordPress Website infrastructure EU

All processors are bound by data processing agreements. For transfers outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism.

06 —

How long we keep it

We hold data for as long as needed to deliver our service and meet legal obligations — and no longer.

Data type Retention period
Order & financial records 7 years (Dutch tax law)
Account data Until account deletion + 30 days
Marketing consent & history Until unsubscribe + 3 years
Support communications 2 years after resolution
Sleep audit responses Session only (not stored server-side)
Analytics data 26 months (anonymised)
07 —

Cookies & tracking

We use cookies to keep the store running smoothly and to understand how people use it. We don't use cookies to build advertising profiles without your consent.

Type Purpose Consent required
essential Cart, session, login — store can't function without these No
functional Remembering preferences (currency, language) No
analytics Understanding traffic and page performance Yes
marketing Retargeting and ad performance tracking Yes

You can manage cookie preferences at any time via the cookie banner on our site, or by adjusting your browser settings. Note that disabling essential cookies will affect store functionality.

08 —

Your rights

As a data subject under GDPR, you have the following rights. We honour all of them — no unnecessary friction, no dark patterns.

  • Access
    Right to access Request a copy of all personal data we hold about you, in a portable format.
  • Rectify
    Right to rectification Ask us to correct inaccurate or incomplete personal data.
  • Erase
    Right to erasure Request deletion of your personal data, subject to legal retention requirements.
  • Restrict
    Right to restriction Ask us to pause processing your data in certain circumstances.
  • Object
    Right to object Object to processing based on legitimate interests, including direct marketing.
  • Portability
    Right to data portability Receive your data in a structured, machine-readable format for transfer elsewhere.
  • Withdraw
    Right to withdraw consent Withdraw consent at any time for consent-based processing (e.g. marketing emails), without affecting prior processing.
  • Complain
    Right to lodge a complaint File a complaint with the Dutch Data Protection Authority — Autoriteit Persoonsgegevens — at autoriteitpersoonsgegevens.nl

To exercise any right, email us at noct@getnoct.com. We will respond within 30 days as required by GDPR.

09 —

How we keep your data safe

We take security seriously. Measures in place include HTTPS/TLS encryption on all data in transit, access controls limiting who can view customer data internally, PCI-compliant payment processing (we never store card details), regular software and plugin updates, and monitoring for suspicious access patterns.

In the unlikely event of a data breach that poses a risk to your rights, we are obligated to notify the Autoriteit Persoonsgegevens within 72 hours and inform affected individuals without undue delay.

10 —

Get in touch

Questions about this policy, your data, or how we operate? We're a small, honest team — reach out directly.

Privacy enquiries

Email: noct@getnoct.com

We aim to respond within 5 business days. For formal GDPR requests, we are legally required to respond within 30 days.

This privacy statement was last updated 24 September 2026. We may update it from time to time — significant changes will be communicated via email or a notice on our website. Continued use of NOCT after changes constitutes acceptance of the revised policy.