NOBL UK Privacy Section
FOR UK RESIDENTS
If you are a resident of the United Kingdom, the following provisions apply to you in addition to the general terms of this Privacy Policy. Where there is any conflict between this section and the general terms, this section prevails for UK residents.
This section explains how NOBL Travel processes your Personal Data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
1. Data Controller
Nysonian, Inc. (d/b/a NOBL Travel) is the controller of Personal Data collected through our Services for UK residents.
Registered office: Nysonian Inc., 2967 Dundas St W # 272d, Toronto ON M6P 1Z2, Canada.
2. Representative
In accordance with Article 27 of the UK GDPR, we have appointed a UK Representative to act on our behalf in matters relating to UK data protection law. You may contact our UK Representative directly:
[UK Representative Name]
[UK Address]
[Email Address]
[UK Phone Number, if applicable]
You may contact our UK Representative for any matter relating to the processing of your Personal Data, including to exercise your rights under UK data protection law.
3. Personal Data We Collect
We collect the categories of Personal Data described in Section 2 of this Privacy Policy. For UK residents specifically, this includes:
- Contact identifiers (name, email, postal address, telephone number)
- Account credentials and authentication information
- Transaction and purchase history
- Payment information (processed by third-party payment processors)
- Device and technical data (IP address, device identifiers, browser information)
- Internet activity (browsing history on our Services, interactions, purchases considered)
- Inferred preferences and characteristics
- Communications you send to us (customer service correspondence, reviews, feedback)
Specific to NOBL Air™ users: location data generated by your NOBL Air™ device and processed through our crowd-sourced location network. This includes approximate location data of the device when it interacts with the network. Full details of location data processing are set out in our NOBL Air™ Privacy Notice.
4. Lawful Basis for Processing
We process your Personal Data on the following lawful bases under Article 6 of the UK GDPR:
| Processing Purpose | Lawful Basis |
|---|---|
| To fulfil your orders and provide products and services | Performance of a contract (Art. 6(1)(b)) |
| To create and manage your account | Performance of a contract (Art. 6(1)(b)) |
| To process payments | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| To send marketing communications | Consent (Art. 6(1)(a)) |
| To personalize your experience and provide recommendations | Legitimate interests (Art. 6(1)(f)) providing a relevant service |
| To conduct targeted advertising | Consent (Art. 6(1)(a)) |
| To prevent fraud and protect our Services | Legitimate interests (Art. 6(1)(f)) protecting our business and consumers |
| To comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
| To operate NOBL Air™ location tracking functionality | Performance of a contract (Art. 6(1)(b)) with the registered owner |
| To facilitate unwanted tracker detection and anti-stalking features | Legitimate interests (Art. 6(1)(f)) protecting individuals from misuse |
| To retain records for accounting and tax purposes | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, you have the right to object as described in Section 8 below.
5. Retention Periods
We retain Personal Data only for as long as necessary for the purposes set out in this Privacy Policy. Specific retention periods for UK residents include:
- Order and transaction data: __ years from the date of transaction (UK tax and accounting requirements)
- Account data: for the duration of your account, plus 2 years thereafter
- Marketing communications data: until you withdraw consent, plus 30 days for processing the withdrawal
- Customer service correspondence: 3 years from the date of last contact
- Cookies and similar technologies: as specified in our UK Cookie Policy
- NOBL Air™ location data: as specified in the NOBL Air™ Privacy Notice
- Data subject rights requests records: 6 years from the date of the request, for compliance demonstration
- Marketing preferences and consent records: for the duration of the relationship plus 6 years
Where retention is required by law (for example, tax records), the legal retention period prevails.
6. International Transfers of Your Personal Data
We are based in the United States and Canada. Your Personal Data will be transferred outside the United Kingdom for processing. We use the following safeguards under Chapter V of the UK GDPR:
- Transfers to the United States: We rely on the UK-US Data Bridge where the recipient is a certified participant. For non-certified recipients, we use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, as appropriate.
- Transfers to Canada: Canada has been deemed to provide adequate protection by the UK Government (adequacy decision), allowing transfers without additional safeguards.
- Transfers to other countries: We rely on the IDTA, UK Addendum, or other lawful transfer mechanisms permitted under UK GDPR.
You may request a copy of the safeguards in place for transfers of your Personal Data by contacting our UK Representative.
7. Cookies and Similar Technologies
We use cookies and similar technologies on our Services. Under PECR, we will only place non-essential cookies on your device after obtaining your consent. You can manage your cookie preferences via the cookie consent banner on our Services and may withdraw consent at any time through the same mechanism. Withdrawing consent is as easy as giving consent.
Strictly necessary cookies required for the operation of our Services do not require consent.
Full information on our cookie use is set out in our UK Cookie Policy.
8. Your Rights Under UK Data Protection Law
You have the following rights under the UK GDPR. To exercise any of these rights, contact our UK Representative or email us at hello@nobltravel.com.
- Right of access: Request a copy of the Personal Data we hold about you and information about how we process it.
- Right to rectification: Request correction of inaccurate or incomplete Personal Data.
- Right to erasure ("right to be forgotten"): Request deletion of your Personal Data, subject to certain legal exceptions.
- Right to restrict processing: Request that we limit how we use your Personal Data in defined circumstances.
- Right to data portability: Request a copy of your Personal Data in a structured, commonly used, and machine-readable format, or request that we transfer it to another controller where technically feasible.
- Right to object: Object to processing based on our legitimate interests (Art. 6(1)(f)) or for direct marketing purposes. We will cease processing for direct marketing on receipt of any such objection.
- Right to withdraw consent: Where we process your Personal Data on the basis of your consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Rights related to automated decision-making and profiling: Where we make decisions about you that have legal or similarly significant effects using solely automated processing, you have the right to request human review, to express your point of view, and to contest the decision.
We will respond to your request within one month of receipt. We may extend this period by a further two months for complex requests, and will notify you if this is necessary. We do not charge a fee for responding to requests unless they are manifestly unfounded or excessive.
To verify your identity before processing a request, we may ask you to provide reasonable information confirming who you are.
9. Right to Lodge a Complaint with the ICO
If you are not satisfied with how we have handled your Personal Data or a request you have made, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Online: www.ico.org.uk/make-a-complaint
We would appreciate the opportunity to address your concerns before you approach the ICO. Please contact our UK Representative or email hello@nobltravel.com first.
10. NOBL Air™ Specific Disclosures
NOBL Air™ is a Bluetooth tracking device that processes location data. This processing has the following characteristics:
- What is processed: Approximate location data of the registered NOBL Air™ device when it interacts with our crowd-sourced location network. Devices in proximity may anonymously contribute location signals to enable lost item recovery.
- Who controls the data: Nysonian, Inc. acts as data controller for location data generated by NOBL Air™.
- Purpose: To enable the registered owner to locate their NOBL Air™ device.
- Lawful basis: Performance of a contract with the registered owner of the NOBL Air™ device (Art. 6(1)(b)), and legitimate interests in supporting anti-stalking detection features (Art. 6(1)(f)).
- Anti-stalking features: NOBL Air™ devices emit an audible alert when separated from the registered owner for a defined period, and unwanted tracker detection is available for both iOS and Android devices to help individuals identify whether an unfamiliar NOBL Air™ is travelling with them. Full details are set out in the NOBL Air™ user manual and Privacy Notice.
- Data Protection Impact Assessment: We have conducted a Data Protection Impact Assessment for NOBL Air™ location data processing under Article 35 of the UK GDPR. A summary is available on request.
- Retention of location data: As specified in the NOBL Air™ Privacy Notice.
If you believe you are being tracked by an unknown NOBL Air™ device, please consult the NOBL Air™ user guidance for detection and disabling instructions. If you require urgent assistance, please contact local law enforcement.
11. Subscription Services NOBL Air+
If you subscribe to NOBL Air+, additional disclosures apply regarding subscription data, renewal processing, and cancellation. These are set out in the NOBL Air+ Subscription Privacy Notice.
12. Children's Privacy
Our Services are not directed at children under the age of 13. We do not knowingly collect Personal Data from children under the age of 13 in the UK. If we become aware that we have collected Personal Data from a child under 13 without verified parental consent, we will delete that information. If you believe we may have collected Personal Data from a child under 13, please contact our UK Representative.
13. Changes to This Section
We will notify UK residents of any material changes to this UK section by email where we hold a current contact email, and by prominent notice on our Services. Material changes will take effect no sooner than 30 days after notification, unless an immediate change is required by law. Continued use of our Services after a material change will indicate acceptance, subject to your right to object or withdraw consent where applicable.
14. Contact
For any matter relating to your Personal Data as a UK resident, please contact:
UK Representative: [Name and UK address]
Email: [UK contact email]
NOBL Travel: Nysonian, Inc. (d/b/a NOBL Travel)
Email: help@nobltravel.com