DATE: Nov 10, 2025 | Posted_by: tad sørensen
The NEST Global OTA
Privacy Policy (Comprehensive Version)
Last updated: 06 November 2025
Note: This comprehensive Privacy Policy has been developed to align with leading global privacy and data protection standards followed by major Online Travel Agencies (OTAs) and digital platforms. It is designed to ensure compliance with applicable international and regional frameworks, including the EU General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA/CPRA), ePrivacy Directive, Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and other comparable global laws.
This policy forms an integral part of The NEST Global OTA Master Policy Suite, ensuring a unified, transparent, and legally compliant approach to the collection, processing, and safeguarding of personal data across all our operations and platforms.
1. Introduction
At The NEST Global OTA AS (“The NEST”, “we”, “our”, “us”), your privacy and trust are paramount. We are committed to protecting your personal information transparently, responsibly, and in full compliance with applicable data protection laws globally.
This Privacy Policy describes how we collect, use, disclose, transfer, and safeguard your information when you use our websites, mobile applications, APIs, or services that reference this Policy (collectively, the “Platform”).
2. Who We Are & Contact Details
Controller: The NEST Global OTA AS
Registered Office: [Insert full legal address, Norway]
Company Registration No.: [Insert]
Email: privacy@thenestglobal.com
DPO (if appointed): dpo@thenestglobal.com
Website: https://the-nest.no
If you are located in the EEA/UK, we act as the data controller for the processing of your personal data, except where we act purely as an agent on behalf of independent travel Suppliers (e.g., airlines, hotels, car rental agencies). In such cases, those Suppliers are separate controllers for their processing.
3. Scope of Policy
This Policy applies to:
It does not apply to third-party websites, mobile applications, or services linked to or integrated into our Platform. We recommend reviewing their respective privacy policies.
4. What Personal Data We Collect
We collect the following categories of information depending on your interactions:
a. Identity & Contact Information
b. Booking & Transaction Data
c. Technical & Device Data
d. Usage & Preference Data
e. Communication Data
f. Marketing & Profiling Data
g. Sensitive Data (Special Category Data)
Only where strictly necessary and with explicit consent, e.g.:
5. How We Collect Your Information
We collect personal data through the following means:
6. How We Use Your Information (Purposes & Legal Bases)
|
Purpose |
Legal Basis |
Examples |
|
Booking & service fulfillment |
Contract (Art. 6(1)(b)) |
Completing hotel/flight/car/tour/visa bookings |
|
Payment processing & fraud prevention |
Legitimate interest; legal obligation |
Verify transactions, prevent unauthorized use |
|
Customer support & communication |
Legitimate interest; contract |
Respond to inquiries, manage complaints |
|
Account management |
Contract |
Create and maintain your user account |
|
Marketing & personalization |
Consent; legitimate interest |
Send offers, newsletters, recommendations |
|
Analytics & improvements |
Legitimate interest |
Analyze site usage, improve experience |
|
Legal compliance & recordkeeping |
Legal obligation |
Tax, accounting, sanctions screening |
|
Security & incident management |
Legitimate interest; legal obligation |
Detect and mitigate breaches |
Where consent is the legal basis (e.g., cookies, direct email marketing, or processing sensitive data), you may withdraw consent at any time without affecting prior lawful processing.
7. Sharing of Information
We only share personal data where necessary and under proper safeguards:
a. Suppliers & Service Providers
b. Business Partners
c. Legal & Regulatory
d. Corporate Transactions
We do not sell personal information to third parties. In jurisdictions where “sale” includes data sharing for targeted advertising (e.g., under CCPA/CPRA), we provide opt-out rights.
8. International Data Transfers
As a global OTA, we and our partners operate in multiple countries. Your data may be transferred to and processed outside your country of residence, including locations not deemed to provide equivalent data protection.
Where transfers occur from the EEA/UK to non-adequate countries, we implement safeguards such as:
9. Retention of Personal Data
We retain personal data only as long as necessary for the purposes collected:
|
Category |
Typical Retention |
Purpose |
|
Booking & transactional data |
7–10 years |
Accounting, disputes, tax compliance |
|
Account & profile data |
Duration of account + 2 years |
Re-engagement, legal defense |
|
Marketing data |
Until withdrawal of consent |
Marketing operations |
|
Support communications |
3 years |
Complaint handling, service quality |
|
Cookie & analytics logs |
13–24 months |
Service improvement, performance |
When no longer needed, data is securely deleted or anonymized.
10. Security Measures
We use industry-standard security measures to protect your personal data, including:
11. Your Rights (EEA, UK & Similar Jurisdictions)
You have the following rights under GDPR and similar laws:
Requests can be made to privacy@thenestglobal.com. We may require ID verification to protect your data.
12. Children’s Privacy
Our services are not directed at children under 16. Bookings involving minors must be made by a parent or guardian. We process children’s data only as necessary for travel fulfillment and with adult consent.
13. Cookies & Tracking Technologies
We use cookies and similar technologies for authentication, analytics, personalization, and advertising. Please refer to our detailed Cookie Policy for full information about cookie categories, consent mechanisms, and preference management.
14. Automated Decision-Making & Profiling
We may use automated tools for:
You may request human review or contest automated decisions where legally required.
15. Marketing Communications
16. Third-Party Links & Integrations
Our Platform may include links to third-party sites or embedded services (e.g., Google Maps, payment gateways). We do not control their data practices and encourage you to review their privacy policies.
17. Data Processors & Vendor Management
We only use vendors that meet our data protection and security standards. All vendors undergo due diligence and sign Data Processing Agreements (DPAs) compliant with Article 28 GDPR.
18. International-Specific Rights
a. United States (California, Virginia, etc.)
b. Canada (PIPEDA)
You may request access, correction, and challenge our compliance with the Privacy Commissioner of Canada.
c. Australia, Singapore, and Others
We comply with applicable laws (Privacy Act 1988, PDPA, etc.) and maintain comparable protections.
19. Changes to This Policy
We periodically update this Policy to reflect changes in law, technology, or business operations. Material changes will be communicated through our Platform or email notifications at least 7 days before the new policy takes effect.
20. Contact Us
For questions or concerns regarding privacy, contact:
If unresolved, you may contact Datatilsynet (Norwegian Data Protection Authority) or your local supervisory authority.
Versioning & Change Log
