GDPR and Data Protection
CartDNA respects the privacy and data protection rights of individuals. This page explains how personal information is handled in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
CartDNA aims to ensure transparency in how personal data is collected, used, stored, and protected.
Clear GDPR information for merchants, partners, and users
Table of Contents
1. What GDPR Means for Users
The General Data Protection Regulation (GDPR) is a European data protection law designed to give individuals greater control over their personal information.
GDPR requires organisations to:
- Process personal data lawfully
- Protect personal information
- Provide transparency about data usage
- Respect user privacy rights
CartDNA supports these principles when handling personal data through its website and services.
2. Who Controls Personal Data
CartDNA is operated by Nabeyond Ltd, which acts as the data controller for personal information collected through the CartDNA website.
Company name: Nabeyond Ltd
Company number: 13300129
Registered in: England and Wales
Website: https://www.cartdna.com
3. Personal Data That May Be Collected
CartDNA may collect limited personal information when users interact with the website.
Contact Information
- Name
- Email address
- Company or organisation name
- Shopify store URL (if submitted through forms)
Technical Information
- IP address
- Browser type
- Device information
- Usage and analytics data
4. Legal Grounds for Processing Personal Data
CartDNA processes personal data only where lawful grounds exist.
Typical legal bases include:
Legitimate Interests
Improving website functionality and responding to enquiries.
User Consent
When users voluntarily submit information through contact forms or sign-ups.
Legal Obligations
Where processing is required to comply with legal or regulatory obligations.
5. How Personal Data May Be Used
Personal information may be used to:
- Respond to enquiries
- Provide requested information
- Improve website performance
- Monitor website usage
- Maintain website security
Important Notice
CartDNA does not sell personal data.
6. Your Data Protection Rights
Under GDPR, individuals have several rights relating to their personal data.
These may include the right to:
- Access personal information – request copies of personal data held
- Correct inaccurate information – request rectification of incorrect data
- Request deletion of personal data – also known as the "right to erasure"
- Restrict data processing – limit how data is used in certain circumstances
- Object to data processing – object to certain types of processing activities
- Request data portability – receive data in a structured format where applicable
Users may exercise these rights by contacting CartDNA through the contact page.
7. Submitting a Data Request
If you wish to request access to personal data, request deletion, or ask questions regarding how personal data is handled, please contact CartDNA.
Requests can be submitted through the contact page:
CartDNA may request verification of identity before processing certain requests.
8. Protection of Personal Data
CartDNA takes reasonable technical and organisational measures to protect personal information.
Security measures may include:
- Secure hosting infrastructure
- Restricted access to sensitive information
- Monitoring for security threats
Although security practices are in place, no online system can guarantee absolute protection.
9. How Long Data Is Retained
Personal data is retained only for as long as necessary to fulfil the purpose for which it was collected.
Data may be retained for:
- Responding to enquiries
- Maintaining service records
- Compliance with legal obligations
When data is no longer required, it is securely deleted or anonymised.
10. Transfers Outside the UK or EEA
Where personal data is transferred outside the United Kingdom or European Economic Area, appropriate safeguards will be used to ensure data remains protected in accordance with GDPR requirements.
11. Updates to This GDPR Information
CartDNA may update this page periodically to reflect regulatory changes or operational updates.
Users are encouraged to review this page occasionally to remain informed about how personal data is handled.
12. Contact Regarding GDPR Matters
If you have questions regarding GDPR compliance or personal data handling, please contact:
Related legal pages
Clear rights information supports trust
Transparent processing
Explain how and why data is used in plain language.
User rights visibility
Help users understand their privacy rights with minimal legal friction.
Clear request pathways
Make it simple to request access, correction, or deletion where applicable.
Need help with a privacy or data request?
Contact CartDNA if you need clarification about data handling, GDPR rights, or a personal data request.