Nerve III — back to the home page

Legal

Privacy
Policy

Version 2.2 · Last updated: 12 August 2026

This policy sets out what personal data Nerve III collects, the purposes for which it is processed, the legal bases relied on, the parties with whom it is shared, the periods for which it is retained, and the rights available to you under the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG). Sections 1 to 7 concern this website. Sections 8 to 10 concern personal data handled in the course of an engagement.

1. Controller

The controller responsible for the processing described in this policy is:

Nerve III has not appointed a Data Protection Officer, being under no obligation to do so pursuant to Article 37 GDPR. Enquiries concerning data protection may be sent to the email address above.

Where an engagement involves personal data, the role of Nerve III is determined by the facts of that engagement and may be that of controller or of processor. Section 8 explains how the roles are allocated.

2. Personal data collected through this website

Contact form. The contact form requests your name, email address and message. Optional fields are provided for telephone number, business name and the engagement of interest. You determine what information you submit. Fields marked optional may be left blank without affecting the response.

Technical data. This website is hosted by Cloudflare, which automatically records standard server information including IP address, browser and device type, referring page and the time of each request. This data is processed to deliver the pages you request and to protect the site against attack and abuse.

Correspondence. Where you contact Nerve III by email, your email address and the content of that correspondence are processed in order to respond and, where relevant, to administer the engagement that follows.

Fonts. The typeface used on this website is served from this website’s own domain. Displaying it causes no request to any third party and discloses nothing about you to anyone other than the host named above.

The logo, the script and every other asset are served from this website’s own domain. Contact form submissions are received by this website’s own endpoint and passed to the provider named in section 5 from the server, so your browser is never directed to another company’s server in order to send them. The one thing loaded from a third party is Google Analytics, and only where you have allowed it under section 3.4. Until you choose, and permanently if you refuse, no request is made to Google and nothing is loaded from it. Where a further third-party provider is introduced, section 3.3 and section 5 are updated before it goes live.

No special categories of personal data within the meaning of Article 9 GDPR, and no criminal conviction data within the meaning of Article 10 GDPR, are requested through this website or knowingly processed through it.

3. Cookies, local storage and similar technologies

3.1 Scope of this section

This section covers cookies and every comparable technology capable of storing information on, or reading information from, your device. That includes local storage, session storage, IndexedDB, tracking pixels, web beacons, SDKs, device fingerprinting and any equivalent technique, whichever party places it. The rules set out below apply to all of them, and references to "cookies" should be read accordingly.

3.2 Categories

Cookies used on this website fall into one of four categories. The treatment of each category is fixed and does not change:

3.3 Cookies currently in use

The table below is the complete inventory of cookies set when you visit this website. It is reviewed whenever the website changes and was last verified on the date stated at the top of this policy.

Cookie inventory
NameCategorySet byPurpose and duration
__cf_bm Strictly necessary Cloudflare Distinguishes automated traffic from human traffic so the website stays available. Expires after at most 30 minutes of inactivity. Not used to profile visitors or to follow them between websites.
_cfuvid, __cfruid Strictly necessary Cloudflare Set only where rate limiting is active, to distinguish visitors sharing a single IP address. Session duration.
nerve-iii (Cache Storage) Strictly necessary Nerve III Holds copies of this website’s own pages, fonts and script so that the site remains readable if your connection fails. It stores no information about you, is never read for any purpose other than serving those files back, and is replaced whenever the website is updated. Removed when you clear site data for this website.
nerve-consent (local storage) Strictly necessary Nerve III Records the choice you made in the consent notice and the date you made it, so that you are not asked again and so that the choice can be demonstrated under Article 7(1) GDPR. It holds that choice and its date and nothing else. Persists until you clear site data for this website, or until you change your choice.
Functional None in use.
_ga, _ga_<property> Analytics Google Placed only after you have allowed analytics under section 3.4. Google Analytics 4 uses them to distinguish one visit from another and to count visitors and sessions in aggregate. Each expires two years after it is last set. Processed by Google Ireland Limited, with transfer to the United States on the basis described in section 6. Where you refuse, or before you have chosen, neither cookie is set and no request is made to Google. Where you later withdraw, both are deleted.
Marketing and tracking None in use.

Nerve III sets no cookie of its own. What it places on your device is the offline cache and the record of your consent choice described above, neither of which holds information about you. The analytics cookies are set by Google and only where you have allowed them. Where the table records a category as not in use, no cookie of that category is placed, by Nerve III or by anyone else, at the date stated at the top of this policy.

3.4 Consent

Where consent is required under section 3.2, it is obtained before the cookie is placed, by means of a consent notice presented on your first visit. That notice meets the following conditions, and will continue to meet them if the cookies in use change:

Consent may be withdrawn at any time, with effect for the future and without affecting the lawfulness of processing carried out before withdrawal. Withdrawal is made as easy as giving consent. Where no consent notice is displayed, this is because no cookie requiring consent is in use, and no consent is being relied on.

3.5 Refusing and deleting cookies

Independently of any choice made in a consent notice, your browser can be set to refuse cookies, to delete them on closing, or to warn before one is placed. Blocking strictly necessary cookies may prevent parts of this website from working. Cookies already stored can be deleted through your browser settings at any time.

No cookie wall is used. Access to this website is not made conditional on accepting cookies.

3.6 Changes to this section

Cookies, analytics or similar technologies may be introduced in future. Where that occurs, section 3.3 is updated and the version and date at the top of this policy are changed before the technology is deployed, and no cookie requiring consent is placed until consent has been obtained in accordance with Article 11.7a of the Dutch Telecommunications Act and Article 6(1)(a) GDPR.

3.7 Technologies that may be introduced

The studio may in future introduce measurement or operational technologies, including web analytics, error and uptime monitoring, and tools that report how this website performs in search results. Naming a possibility here does not authorise its deployment. No such technology is put into operation until section 3.3 has been updated to identify the specific provider, what it places on your device, how long it persists and where the data is processed, and, for anything outside the strictly necessary category, until consent has been obtained under section 3.4.

Some measurement tools operate without placing anything on your device and without receiving data from it. A search engine console, for example, reports aggregated statistics that the search engine has already collected through its own service; it neither reads nor writes anything on your device when you visit this website, and it does not receive your identity from the studio. Tools of that kind fall outside this section and outside the consent requirement, and are dealt with in section 5.

4. Purposes and legal bases

Processing carried out through this website
PurposeLegal basis
Responding to enquiries and discussing prospective work Article 6(1)(b) GDPR: steps taken at the request of the data subject prior to entering into a contract
Performing an engagement once agreed, and administering it Article 6(1)(b) GDPR: performance of a contract
Maintaining the security, availability and integrity of the website, and preventing spam and abuse of the contact form Article 6(1)(f) GDPR: the legitimate interest in operating a secure and functioning website and in not receiving fraudulent or automated messages
Compliance with statutory accounting and tax obligations where an engagement proceeds Article 6(1)(c) GDPR: compliance with a legal obligation
Establishing, exercising or defending legal claims Article 6(1)(f) GDPR: the legitimate interest in protecting the studio’s legal position

Personal data collected through this website is not processed for marketing purposes, is not used to build a profile, and is not added to any mailing list.

5. Recipients and processors

Personal data collected through this website is disclosed only to the processors listed below, each of which acts on documented instructions under a data processing agreement concluded pursuant to Article 28 GDPR. Processors engaged for a specific engagement are dealt with separately in section 8.

Processors engaged for the operation of this website
ProcessorRole
Cloudflare Website hosting and content delivery, protection against attack and abuse, and Email Routing, which forwards messages addressed to the studio to the mailbox described below
Web3Forms Transmission of contact form submissions. Operates on Amazon Web Services infrastructure, with submissions encrypted in transit and at rest
CleanTalk and Akismet Spam filtering. Web3Forms may transmit the sender’s IP address and email address to these services in order to assess whether a submission is automated
Google Gmail, the mailbox to which enquiries are delivered and from which correspondence is sent. Separately, and only for visitors who have allowed analytics under section 3.4, Google Analytics 4 measures use of this website in aggregate, as described in section 3.3

Parties that are not processors of your data. The studio uses operational services, such as accounting and invoicing software, and measurement services that report on the studio’s own activity rather than on you, such as a search engine console. Where such a service does not receive personal data collected through this website, it is not a recipient of your data and is not listed above. Where any service does receive such data, it is added to the table before it goes into use, together with its role.

Personal data may in addition be disclosed to the studio’s accountant and to the Dutch tax authorities, to the extent required for the statutory accounting and tax obligations referred to in section 4.

Personal data is not sold, rented, licensed or otherwise disclosed to any third party, except where disclosure is required by law, by order of a competent authority, or is necessary to establish, exercise or defend a legal claim.

6. Transfers outside the EEA

Certain processors named in section 5 are established outside the European Economic Area or process data on infrastructure located outside it. Where personal data is transferred outside the EEA, that transfer takes place on the basis of an adequacy decision of the European Commission, the European Commission’s Standard Contractual Clauses, or another transfer mechanism permitted under Chapter V GDPR, together with supplementary technical measures including encryption in transit and at rest. Information on the safeguards applied to a specific transfer is available on request.

Where an engagement requires that personal data be kept within the EEA, that requirement is agreed in advance and reflected in the choice of tools for that engagement.

A record of the transfer mechanism relied on for each processor is maintained and reviewed when a processor changes or when the legal basis for a transfer is affected by a decision of the European Commission or of a competent court.

7. Retention

Personal data is retained no longer than is necessary for the purposes for which it was collected.

8. Personal data handled during an engagement

8.1 How the roles are allocated

An engagement may or may not involve personal data. Where it does, the role of Nerve III depends on who decides the purposes and means of the processing, and is established in writing before the processing begins:

The allocation is a question of fact and not of preference. Where an engagement does not fit cleanly into one of the categories above, the roles are set out expressly in the proposal or in the data processing agreement for that engagement.

8.2 Client obligations

Where the client is the controller, it is for the client to establish a lawful basis for the processing, to inform the individuals concerned, and to respond to any request they make in exercise of their rights. Nerve III assists with such requests to the extent required by Article 28(3) GDPR.

8.3 Data minimisation

Only the personal data necessary to answer the research question is requested. Where a question can be answered from pseudonymised or aggregated data, that is what is asked for. Direct access to production systems and to live customer records is requested only where the work cannot be carried out without it, and is limited to the narrowest access that will do.

8.4 Tools used during an engagement

Research, analysis and collaboration tools are selected for each engagement rather than fixed in advance, and the tools that will handle personal data are identified in the proposal or in the data processing agreement before the engagement begins. No personal data belonging to a client is placed in a tool that has not been agreed for that engagement. Each such provider acts as a sub-processor, is bound by an agreement meeting the requirements of Article 28(2) and (4) GDPR, and is disclosed to the client, who may object to a proposed sub-processor on reasonable grounds. A current list of the sub-processors used on a given engagement is available to that client on request.

Client material is not entered into any tool that would acquire the right to use it to train models or for its own purposes.

8.5 Recordings

Sessions, interviews and usability tests are recorded only where recording has been agreed for that engagement and the person recorded has been informed and has consented before recording begins. Recording is not carried out as a matter of course. Where a session is recorded, the participant is told what is recorded, why, how long it is kept and who will see it, and may ask for the recording to stop or be deleted at any time. Recordings are stored in the tools agreed under section 8.4 and are deleted at the end of the engagement, or earlier where the agreement for that engagement so provides.

8.6 Reporting

Findings are reported in a form that does not identify individual participants. Quotations and clips are attributed by role or pseudonym rather than by name, and are used only where the participant has consented to their use.

Client materials, screens and deliverables are not published. The studio may identify a client by name and describe the general character of the work, as set out in section 11 of the terms and conditions, which also records how a client may object to that use. Nothing in that section permits the publication of personal data or of confidential information.

8.7 Return and erasure

At the end of an engagement, personal data processed on behalf of the client is returned or erased as the client directs, save where retention is required by law. Anonymised or aggregated material that can no longer be related to an identifiable person may be retained.

9. Research participants

Where Nerve III recruits research participants directly, rather than receiving them from the client, Nerve III is the controller in respect of that recruitment and of the data collected from those participants. In that case, each participant is given a separate privacy notice at the point of recruitment, before any data is collected, setting out who is collecting the data, for what purpose, on what legal basis, how long it will be kept, who will receive it, and how to withdraw.

Participation is voluntary in every case. Consent to take part, and consent to be recorded, are requested separately, may be refused without consequence, and may be withdrawn at any time, including after the session, in which case the contribution is removed from the analysis so far as it remains identifiable.

At the date of this version, Nerve III does not recruit research participants directly. This section applies from the moment it does, and the participant notice described above is provided before any participant is approached.

10. Collaborators and confidentiality

Nerve III is a one-person studio and engagements are carried out personally by the studio owner by default. Where an engagement calls for another person, such as an independent designer or researcher, that person may be engaged for that engagement. The client is told before the collaborator begins work, and is told who they are.

A collaborator with access to client material or personal data is bound in writing to confidentiality and to instructions no less protective than those in this policy, and, where they process personal data on behalf of a client, acts as a sub-processor under section 8.4. Nerve III remains responsible to the client for the work performed.

Client information is treated as confidential as a matter of course, whether or not a separate confidentiality agreement has been signed. Where a client prefers to put a non-disclosure agreement in place, Nerve III is willing to enter into one, and this is agreed alongside the engagement.

11. Children

This website is directed at businesses and is not intended for children. Nerve III does not knowingly collect personal data from any person under the age of 16 through this website. Where it becomes apparent that such data has been submitted, it will be erased without undue delay.

Where an engagement would involve research with participants under the age of 16, the additional requirements of Article 8 GDPR apply, including consent given or authorised by the holder of parental responsibility. Such research is undertaken only where those requirements have been provided for in writing for that engagement.

12. Rights of the data subject

Subject to the conditions set out in the GDPR, you have the right to:

Requests may be sent to [email protected] and will be answered within one month of receipt. That period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case you will be informed within the first month together with the reasons for the delay. No fee is charged unless a request is manifestly unfounded or excessive. Where there is reasonable doubt as to the identity of the person making a request, further information may be requested in order to confirm it.

Where Nerve III acts as processor rather than controller, a request relating to that processing is passed to the client without undue delay, and the client answers it. You will be told that this has been done.

The studio is established in the Netherlands and applies the standard set out in this policy to every individual whose personal data it processes, wherever that person is located. Where the law of your own country grants you a right that the GDPR does not, that right is honoured in addition, so far as it applies to a controller established in the Netherlands.

You have the right to lodge a complaint with a supervisory authority in the member state of your residence, place of work or the place of the alleged infringement. The competent authority in the Netherlands is the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ The Hague.

13. Security

This website is served exclusively over HTTPS and form submissions are encrypted in transit. A content security policy, transport security enforcement and a spam trap on the contact form are in place.

Access to enquiry correspondence and to client material is limited to the studio owner and to any collaborator engaged under section 10 for that particular engagement. Accounts are protected by unique credentials and multi-factor authentication where the provider supports it, devices are encrypted at rest, and access to a client’s material is removed at the end of the engagement.

Technical and organisational measures appropriate to the risk are maintained and reviewed in accordance with Article 32 GDPR. Measures specific to an engagement are agreed for that engagement and recorded in the data processing agreement.

14. Personal data breaches

In the event of a personal data breach in respect of which Nerve III is the controller, and which is likely to result in a risk to the rights and freedoms of natural persons, the Autoriteit Persoonsgegevens will be notified without undue delay and, where feasible, within 72 hours of the breach becoming known. Where the breach is likely to result in a high risk to those rights and freedoms, the affected individuals will be informed without undue delay.

Where Nerve III acts as processor, the client is notified without undue delay after the breach becomes known, so that the client can meet its own obligations under Articles 33 and 34 GDPR, and is given the information it needs to do so.

A record of all breaches is maintained in accordance with Article 33(5) GDPR.

15. Automated decision-making

No automated decision-making or profiling producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 GDPR, is carried out. The spam filtering described in section 5 assesses whether a submission is automated and has no legal or similarly significant effect on any individual; a message wrongly identified as spam may be resent by email to the address given in section 1.

16. Provision of data

Provision of the personal data requested in the contact form is voluntary and is neither a statutory nor a contractual requirement. Where the required fields are not completed, it will not be possible to respond to your enquiry. There is no obligation to use the contact form; enquiries may be sent by email instead.

17. Amendments

This policy may be amended from time to time. The version applicable at any given moment is the version published on this page, identified by the version number and date stated above. Amendments materially affecting an ongoing engagement will be communicated to the client directly. Where a data processing agreement for an engagement conflicts with this policy, that agreement prevails for that engagement.

Questions about this policy, or about how a particular piece of information is handled, can be sent to [email protected]. See also the terms and conditions.