Stormkestrel
Start free

Legal

Privacy Policy

This policy explains how Stormkestrel Limited (“Stormkestrel”, “we”, “us”) handles personal data across our website at stormkestrel.com and our crisis-exercising platform, Nest (the “Platform”), available at nest.stormkestrel.com. It is written to meet the UK GDPR and the Data Protection Act 2018.

1. Who we are

Stormkestrel Limited is a company registered in England & Wales (company number 13440339), with its registered office at St Mary’s House, Netherhampton Road, Salisbury, Wiltshire SP2 8PU, United Kingdom. We are the makers of Nest.

For any question about this policy, or your personal data, contact us at enquiries@stormkestrel.com.

2. Our role: controller and processor

Data-protection law distinguishes the controller (who decides why data is processed) from the processor (who handles it on a controller’s instructions). Our role depends on the data:

  • We are the controller for the personal data of the people who hold accounts with us and for our billing records — we decide why we hold it (to provide and administer the service).
  • We are a processor for the personal data an organisation puts into the Platform to run its exercises — including the people it invites as participants and the content they generate. The organisation that runs the exercise is the controller of that data; we process it only to provide the Platform to them, under a data processing agreement.

Where an individual signs up and runs an exercise purely for themselves rather than on behalf of an organisation, we are the controller for that activity.

3. The personal data we handle

Visitors to this website

Our website uses privacy-friendly analytics so that we can see which pages and languages people find useful. It sets no cookies and stores nothing on your device. It does not identify you, build a profile of you, or follow you across other websites.

We use no advertising or data-broker tools. Our analytics and hosting providers are located in the European Union and process this information only on our instructions. Our hosting provider processes the technical information your browser sends with each request (such as your IP address) so that we can serve pages and keep the site secure.

Account holders

When you create or are added to a Nest account, we hold:

  • your name and email address;
  • your preferred language and the date you were last active;
  • the organisation (account) you belong to and your role within it;
  • sign-in credentials — we do not store your password in a readable form.

Exercise participants

When an organisation invites people into an exercise, the Platform holds each participant’s name, an optional email address, the role they are assigned, and the content they generate while the exercise runs — such as the messages they send, the decisions they take and any reflections they record. This is captured in the exercise report. We handle this as a processor, on behalf of the organisation running the exercise.

Billing

We hold subscription and billing records (such as plan, status and renewal dates). We invoice organisations directly and do not collect or store payment-card details.

4. Cookies and tracking

We do not use cookies for tracking or advertising, and we display no cookie banner because there is nothing to consent to. Within the Platform we store a small amount of information on your device to keep you signed in and to remember your preferences. This stays on your device, is not used to track you, and is not shared with anyone.

5. How and why we use data

Where we are the controller, we rely on these lawful bases:

  • To provide the service — creating and running your account, delivering exercises and reports (performance of our contract with you).
  • To communicate with you — service messages, support and account notices (contract, or our legitimate interest in running the service).
  • To take payment — invoicing and keeping financial records (contract and our legal obligations).
  • To keep the service secure and working — diagnosing faults and preventing abuse (our legitimate interest in a secure, reliable service).
  • To improve the Platform — producing anonymised, aggregated statistics from use of the Platform (our legitimate interest in improving and developing the service). This creates no data that identifies anyone.

Where we are a processor, we use the data only to provide the Platform to the organisation and on its documented instructions.

6. Who we share data with

We do not sell personal data and we do not share it with advertisers or data brokers. We use a small number of service providers (sub-processors) to run our website and the Platform. They process personal data only on our instructions and never for their own purposes. Our current list of sub-processors, and where each is located, is available on request.

We may also disclose data where the law requires it.

7. Where your data is held

The Platform’s data is stored and processed in the European Union (Paris, France). Transfers between the UK and the EEA are covered by the UK’s adequacy decision for the EEA. If we ever need to transfer personal data outside the UK or EEA, we will put appropriate safeguards in place (such as the UK International Data Transfer Agreement or Addendum).

8. How long we keep it

Where we are the controller, we keep your personal data for as long as your account is active, and delete or anonymise it on request or within 30 days of your account being closed — except where we must keep certain records longer to meet legal obligations (for example, billing records for tax purposes).

Where we are a processor, we keep exercise and participant data for as long as the controlling organisation needs it, and delete or return it on their instruction or when our agreement ends.

Anonymised aggregated statistics are not personal data and are retained after that point.

9. How we protect it

Data is encrypted in transit and held on infrastructure that encrypts data at rest, within the EU. Access is restricted to those who need it, and we minimise the personal data recorded in our operational logs. No system can be guaranteed completely secure, but we take appropriate technical and organisational measures to protect your information.

10. Your rights

Under UK data-protection law you have the right to access your data; to have it corrected or erased; to restrict or object to how we use it; to data portability; and, where we rely on consent, to withdraw it. You will not be subject to solely automated decisions with legal or similarly significant effects.

To exercise any of these rights, please email enquiries@stormkestrel.com. If your data relates to an exercise you took part in, we usually act as processor — please contact the organisation that invited you (the controller), and we will support them in responding.

11. Children

Nest is a tool for organisations and is not directed at children. Where a customer uses it in an educational setting, that customer is the controller and is responsible for the appropriate handling and consents for any participants who are children.

12. Complaints

If you have a concern, we would like the chance to resolve it — please contact us first. You also have the right to complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk. If you are in the EU/EEA, you may instead complain to your local supervisory authority.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will let account holders know where appropriate.

Stormkestrel Limited

St Mary’s House, Netherhampton Road, Salisbury, Wiltshire SP2 8PU, United Kingdom

Company number 13440339

ICO registration number: ZB293430

enquiries@stormkestrel.com