This notice explains how Nordera Works Teknoloji ve Danışmanlık A.Ş. ("Nordera Works", "we") processes personal data in connection with the PickVend website and service. We follow the EU General Data Protection Regulation (GDPR) and, where it applies, the Turkish Personal Data Protection Law (KVKK).
Controller: Nordera Works Teknoloji ve Danışmanlık A.Ş., Metrocity, Esentepe, Şişli, 34394 Istanbul, Türkiye. Email: hello@norderaworks.com.
EU representative (Art. 27 GDPR): Nordera Holding Limited, Malta (EU representative under Art. 27 GDPR). You may contact the representative on any matter related to this notice.
For order and inventory data processed on behalf of a machine operator, the operator is the controller and Nordera Works acts as processor under the Data Processing Addendum.
| Context | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Website visit | Server logs: IP address, time, requested page, browser type | Security, abuse prevention, keeping the site running | Legitimate interest (Art. 6(1)(f)) | Logs kept by our hosting provider for up to 30 days |
| Contact request | Name, work email, company, country, machine details, message, IP, consent flag | Answering your request and preparing an offer | Consent (Art. 6(1)(a)); pre-contractual steps (Art. 6(1)(b)) | 24 months after last contact, or until you withdraw consent |
| Courier pickup page | Order code entered, time, machine, IP address | Opening the right machine for the right order; fraud prevention | Legitimate interest (Art. 6(1)(f)); contract with the operator | 12 months |
| Operator dashboard | Operator contact details, login session cookie, API credentials you enter (encrypted) | Providing the service | Contract (Art. 6(1)(b)) | Duration of the contract + 12 months; credentials deleted on termination |
| Orders (as processor) | Order ID, items, amounts, pickup status. No end-customer names, addresses or payment data are received from the delivery platform. | Fulfilling orders for the operator | Operator's contract with its customers; our DPA | As instructed by the operator; default 36 months for accounting |
Our servers and database run in Frankfurt, Germany (Vercel Inc. — Frankfurt (fra1) region; Neon Inc. — Frankfurt (AWS eu-central-1)). Both providers process data under standard contractual clauses and EU data-processing agreements. Nordera Works staff in Türkiye may access data for support; Türkiye is not covered by an EU adequacy decision, so such access is governed by the standard contractual clauses (Art. 46 GDPR) between Nordera Works and the EU entities concerned, and by internal access controls.
We do not sell personal data and we do not use advertising or analytics trackers.
The public website sets no cookies. The operator dashboard sets one strictly necessary session cookie after login. Details in the cookie policy.
You can ask for access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time. Write to hello@norderaworks.com. You also have the right to lodge a complaint with a supervisory authority — in Finland the Data Protection Ombudsman (tietosuoja.fi), or the authority of your member state; in Türkiye the Personal Data Protection Authority (KVKK).
Transport encryption everywhere; API credentials stored encrypted at rest (AES-256-GCM); access to the dashboard protected by authentication; webhooks verified by signature. See Security & data.
We will update this notice when the service changes. The date at the top tells you when.