01Scope
This Policy covers personal information collected through nes-agency.com and any associated forms. It does not cover engagements with NES under a signed services agreement — those are governed by the MSA and a Data Processing Addendum where applicable.
02What we collect
Minimum necessary:
— form submissions: name, work email, company, topic, message
— technical telemetry: IP, device & browser, referrer, pages visited (via Google Analytics 4)
— cookies you accept in the banner (analytics & preference)
We do not collect Social Security numbers, payment cards or government IDs through this site.
03Purposes
— reply to your inquiry and discuss a potential engagement
— improve the site through aggregated, anonymous analytics
— meet legal obligations
We do not sell or rent your data. We do not run behavioural advertising on this site.
04Legal basis
Form submissions: your explicit request. Analytics: your consent in the cookie banner. Contract performance and legal obligation where applicable. EU/UK visitors: GDPR Art. 6(1)(a)(b)(f). California residents: CCPA §1798.100 et seq.
05Sharing
We share data only with:
— infrastructure providers (hosting, email delivery, analytics) under DPAs
— Google LLC for analytics traffic statistics (after your consent)
— authorities when compelled by law
We do not sell personal information.
06Cookies & Google Analytics 4
Two categories:
— essential: language, theme, session state — set automatically, no consent required
— analytics: GA4, loaded only after you accept the cookie banner
GA4 collects pseudonymous interaction data and forwards it to Google LLC. Google's privacy practices: https://policies.google.com/privacy. You can withdraw consent any time by clearing cookies or re-opening this page — the banner returns.
07Retention
Form submissions: kept until the purpose is fulfilled (usually until negotiations end or a project closes), and no longer than 24 months after the last contact. Analytics data: per GA4 default retention (14 months).
08Your rights
GDPR (EU/UK): access, rectification, erasure, restriction, portability, objection, withdraw consent.
CCPA/CPRA (California): right to know, delete, correct, opt out of sale/share (we do neither), limit use of sensitive personal info, non-discrimination.
Exercise rights by emailing hello@nes-agency.com. We respond within 30 days (GDPR) / 45 days (CCPA).
09Security
HTTPS in transit, encryption at rest where applicable, role-based access control, regular infrastructure updates, vendor due diligence.
10Children
The site is not directed at children under 13 (COPPA) or under 16 (GDPR). We do not knowingly collect data from them.
11Changes
We may update this Policy. The current version always lives at this URL; the effective date appears at the top.