PRIVACY POLICY
Effective Date: August 1, 2026
NADEL
Global Privacy Statement
How Nadel collects, uses, shares and protects personal information
Last updated: July 17, 2026
About this Privacy Statement
This Global Privacy Statement (this "Statement") explains how Jack Nadel Inc. and its relevant group entities (together, "Nadel," "we," "us," or "our") collect, process, retain, and disclose personal information about you when you visit nadel.com, contact us, request or purchase products or services, supply products or services to us, apply for a role, visit our locations, or otherwise interact with us, and our practices for using, maintaining, protecting and disclosing that information.
This Statement is designed as a layered, public-facing notice. Separate notices may apply to employees, job applicants, specific customer programs, cookies and tracking technologies, or processing performed solely on a customer's documented instructions. If a more specific notice applies, that notice supplements this Statement.
Please read this Statement carefully to understand our policies and practices regarding your information and how we treat it. By interacting with our services or providing us with your information, you agree to the collection, use, and sharing of your information as described in this Statement. This Statement may change from time to time (see Changes to this Statement). Your continued use of the services after we make changes as described here is deemed to be acceptance of those changes, so please check the policy periodically for updates.
Quick summary
- We collect personal information that is reasonably necessary to operate our business, deliver branded merchandise and related services, maintain security, communicate with you, and meet legal obligations.
- We do not sell personal information for monetary consideration.
- We use service providers, manufacturing partners, fulfillment providers, cloud and business systems, and professional advisers to support our operations.
- International transfers are protected through applicable adequacy mechanisms, contractual safeguards such as the EU Standard Contractual Clauses or UK transfer instruments, and risk-based supplementary measures where required.
- Nadel maintains an ISO/IEC 27001:2022-certified Information Security Management System and applies risk-based technical and organisational safeguards.
- You may have rights to access, correct, delete, restrict, object to, or obtain information about our use of your personal information, depending on your location and the applicable law.
Who we are and which entity is responsible
Nadel is a global provider of branded merchandise, promotional products, fulfillment, logistics coordination, creative support, and related marketing services. Depending on your location, relationship, and the processing activity, one or more of the following entities may act as the controller or business responsible for your personal information:
- Jack Nadel Inc. dba Nadel ("Nadel US"), with its principal place of business at 5820 Uplander Way, Culver City, CA 90230, United States.
- Jack Nadel International Ltd ("Nadel UK"), company number 03999489, with its registered office at Monmouth House, 87–93 Westbourne Grove, London W2 4UL, United Kingdom.
The Nadel entity with which you interact will normally be responsible for the relevant processing. Nadel entities may use shared systems, personnel, policies, and service providers. Where two entities jointly determine the purposes and means of a processing activity, they will allocate their responsibilities as required by applicable law. You may contact our Data Protection Officer to confirm the entity responsible for a particular activity.
When we act on a customer's instructions
For some services, a customer may provide Nadel with recipient, attendee, employee, shipping, or campaign data and instruct us how to use it. In those circumstances, the customer may be the controller or business, and Nadel may act as a processor, service provider, or contractor. If your information was provided to us by a Nadel customer, you may wish to contact that customer first. We will assist the customer in responding to privacy requests as required by contract and applicable law.
How to contact our Data Protection Officer
- United States and general privacy enquiries: privacy@nadel.com
- United Kingdom and EEA privacy enquiries: privacy@nadel.uk.com
- Data Protection Officer: Joe Fancher, Nadel, 5820 Uplander Way, Culver City, CA 90230, United States; telephone +1 310 815 5462.
Personal information we may collect
The information we collect depends on how you interact with us. It may include:
1. Identifiers and contact information: name, business or personal email address, postal address, telephone number, account or customer identifier, online identifier, IP address, and similar identifiers.
2. Business and professional information: employer, job title, department, business contact details, professional profile, and relationship with Nadel or a customer, supplier, or partner.
3. Commercial and transaction information: requests for quotations, orders, project details, product specifications, delivery information, purchase history, billing information, and service preferences.
4. Communications and content: messages, enquiries, support requests, survey responses, documents, images, creative materials, and other content you submit or that a customer provides for a project.
5. Website, device, and network information: browser and device type, operating system, IP-derived location, cookie identifiers, website interactions, log data, and security events.
6. Marketing and preference information: marketing choices, newsletter status, areas of interest, engagement, and communication preferences.
7. Recruitment and employment-related information: CV or résumé information, work history, references, right-to-work information, background-check information where lawful, and information needed to assess or administer an application.
8. Financial and accounting information: billing contacts, tax and transaction records, payment status, and payment confirmation. Nadel generally relies on payment processors and does not intentionally store full payment-card numbers.
9. Security and facility information: account and access records, authentication and audit logs, visitor records, key or access-card records, and CCTV or other physical-security information where used.
10. Sensitive or special-category information: only where necessary and lawful, such as accessibility or dietary information, health or accommodation information, government identifiers, background-check information, or other information requiring enhanced protection.
11. Inferences and analytics: basic preferences, likely interests, risk indicators, or operational insights derived from interactions, where permitted and subject to applicable rights.
Some of the information identified above may be considered sensitive data under certain laws. If required under applicable law, we will collect and process sensitive personal data only with your consent. If you choose not to provide or allow us to collect some information, we may not be able to provide you with certain requested features, services, or information.
We also collect:
1. Statistics or aggregated information: Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from personal information. For example, we may aggregate personal data to calculate the percentage of users accessing a specific services feature.
2. Technical information: Technical information includes information about your internet connection and usage details about your interactions with the services, such as clickstream information to, through, and from our services (including date and time), products that you view or search for; page response times, download errors, length of your visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), or methods used to browse away from a page.
If we combine or connect non-personal statistical or technical data with personal data so that it directly or indirectly identifies an individual, we treat the combined information as personal information.
How we use personal information
We use personal information only for defined business or legal purposes and rely on a lawful basis where UK or EU data-protection law applies. Typical activities are summarised below. Specific processing may be further described in a form, contract, cookie notice, recruitment notice, customer instruction, or other just-in-time notice.
| Purpose | Personal information | Lawful basis / business purpose | Typical retention | Recipients / systems |
|---|---|---|---|---|
| Operate, secure, and improve our website and online services | IP address, device and browser data, session and cookie identifiers, website interactions, security logs | Legitimate interests in secure and effective operations; consent for non-essential cookies where required | Generally up to 12 months for routine website data; security records may be kept longer when needed for investigation or legal compliance | Website host, content-delivery, security, analytics, and IT providers |
| Respond to enquiries, requests, and prospective-customer communications | Name, contact details, company, enquiry content, communication history | Pre-contractual steps; legitimate interests in responding and developing business relationships | Generally 24 months after the last meaningful contact unless a customer or supplier relationship begins | CRM, email, communications, and business-support providers |
| Provide branded merchandise, promotional products, fulfillment, logistics, creative, and related services | Customer and recipient contact details, order and project information, product specifications, delivery details, transaction records, customer-provided content | Performance of a contract; pre-contractual steps; legal obligations; legitimate interests in delivering and improving services | Generally 7 years after the last relevant transaction, or longer where required by law, contract, dispute, or legal hold | Manufacturers, decorators, warehouses, fulfillment and freight providers, payment providers, customer systems, accountants, auditors |
| Manage suppliers, partners, and service providers | Business contacts, due-diligence information, contracts, certifications, risk and performance records, payment details | Contract; legal obligations; legitimate interests in supplier governance, security, continuity, and procurement | Relationship term plus generally 7 years, subject to contract, law, or claims | Procurement, vendor-risk, finance, legal, security, and supplier-management systems |
| Billing, accounting, tax, audit, and financial administration | Customer and supplier details, invoices, payments, transaction and tax records | Contract; legal obligation; legitimate interests in financial administration and audit | Generally 7 years or the applicable statutory period | Banks, payment processors, accountants, auditors, tax authorities, finance systems |
| Marketing and relationship management | Business contact details, preferences, engagement, event or campaign interests | Consent where required; legitimate interests or applicable business-to-business marketing rules; soft opt-in where legally available | Until opt-out or generally after 24 months of inactivity, subject to suppression-list retention | Marketing platforms, CRM, event and communications providers |
| Recruit and evaluate applicants | Contact details, CV, employment history, references, right-to-work and background information where lawful | Pre-contractual steps; legal obligations; legitimate interests in recruitment; consent only where appropriate | Generally 12 months after the decision unless a longer period is authorised or legally required | HR, applicant tracking, recruitment, background-check, and professional-adviser providers |
| Protect people, facilities, systems, and information; prevent fraud and respond to incidents | Access records, authentication and audit logs, security events, visitor or CCTV records, investigation material | Legitimate interests; legal obligations; establishment, exercise, or defence of legal claims | Limited to the period necessary for security and investigation, then retained according to the approved retention schedule or legal hold | Security providers, SOC/NOC, IT providers, law enforcement, regulators, insurers, counsel |
| Manage legal, regulatory, contractual, compliance, and corporate matters | Contracts, communications, transaction records, audit evidence, claims and investigation information | Legal obligation; contract; legitimate interests in legal compliance, governance, and claims | Applicable limitation period plus any legal hold, regulatory, or contractual requirement | Legal counsel, regulators, courts, auditors, insurers, certification bodies |
| Use approved AI-assisted and automated tools to support work | Information appropriate to the underlying approved business activity; prompts, outputs, logs, or metadata where permitted | The lawful basis and purpose applicable to the underlying activity; legitimate interests where appropriate; consent where required | No longer than necessary for the underlying purpose and approved tool settings | Approved AI, cloud, security, productivity, or analytics providers subject to governance and contract controls |
Where personal information comes from
We collect personal information from the following sources, depending on the activity:
- directly from you, including through forms, emails, calls, meetings, orders, applications, registrations, and other interactions;
- from your employer, colleagues, representatives, or a Nadel customer that asks us to provide products or services involving you;
- from Nadel group entities and business systems used to manage shared operations;
- from suppliers, manufacturers, fulfillment partners, payment providers, recruitment providers, and other service providers;
- from publicly available sources, including company websites, professional networking platforms, corporate registries, and public records;
- automatically from websites, devices, applications, network systems, security tools, and cookies or similar technologies (to the extent any of these automated technologies are considered a personal information sale, targeted advertising, or profiling, under applicable laws, depending where you live, you may opt out from use of these automated technologies for such uses. Please note that some features may be unavailable as a result); and
- from marketing, analytics, or business-data providers where we have taken reasonable steps to ensure the data was obtained and may be used lawfully.
Where UK or EU law requires us to provide information because we did not collect the data directly from you, we will do so within the required period unless a lawful exception applies.
Who we disclose personal information to
We disclose personal information only where reasonably necessary and permitted by law. Recipient categories may include:
- Nadel subsidiaries, affiliates and personnel who need the information for the relevant purpose;
- manufacturers, decorators, warehouses, freight, logistics, and fulfillment providers;
- cloud, hosting, email, collaboration, CRM, business-application, security, and support providers;
- marketing, analytics, event, and communications providers, subject to consent and opt-out requirements where applicable;
- payment processors, banks, finance providers, accountants, and auditors;
- recruitment, HR, benefits, screening, and professional-services providers;
- legal counsel, insurers, consultants, certification bodies, and other advisers;
- regulators, supervisory authorities, courts, law enforcement, and government bodies where requested or required or permitted by law;
- a buyer, investor, successor, or adviser involved in a proposed or completed corporate transaction, subject to appropriate confidentiality and data-protection controls; and
- customers or other parties where you direct us to disclose the information or where disclosure is necessary to perform the requested service.
Where required, Nadel uses written agreements, confidentiality obligations, data-processing terms, security requirements, and vendor-risk controls. Additional information about principal service-provider categories or transfer safeguards may be provided during customer due diligence, subject to confidentiality and security considerations.
International transfers
Nadel operates globally and uses systems, group entities, and service providers in multiple countries, including the United States and the United Kingdom. Personal information may therefore be accessed, processed, or stored outside the country where it was collected.
Where UK GDPR, EU GDPR, or another applicable law restricts international transfers, Nadel uses an approved transfer mechanism as appropriate, which may include:
- an adequacy decision or regulation, including an applicable extension to the EU–US Data Privacy Framework or UK–US Data Bridge where the recipient is eligible;
- the European Commission's Standard Contractual Clauses for transfers subject to EU GDPR;
- the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses for transfers subject to UK GDPR;
- binding corporate rules, another approved contractual mechanism, or a permitted legal exception; and
- a transfer risk assessment or data-protection test, together with supplementary technical, organisational, or contractual measures where required.
You may request information about the relevant safeguard by contacting the Data Protection Officer. We may redact confidential or security-sensitive information before providing a copy.
How long we retain personal information
We retain personal information only for as long as reasonably necessary for the purposes described in this Statement, including to provide services, maintain business and financial records, meet legal and contractual obligations, resolve disputes, enforce agreements, protect security, and establish or defend legal claims.
Retention is determined by the nature and sensitivity of the information, the purpose and lawful basis, the relationship with you, statutory and contractual periods, limitation periods, security and audit needs, and whether a dispute, investigation, or legal hold applies. When information is no longer required, we delete, anonymise, aggregate, or securely dispose of it using approved methods.
How we protect personal information
Nadel maintains an ISO/IEC 27001:2022-certified Information Security Management System. We use risk-based technical and organisational measures designed to protect personal information against unauthorised or unlawful access, use, alteration, disclosure, loss, or destruction.
Depending on the system and risk, safeguards may include access controls and least privilege, multi-factor authentication, encryption in transit and where appropriate at rest, network and endpoint protection, security monitoring and logging, vulnerability management, penetration testing, backups and recovery controls, physical security, supplier due diligence, incident response, employee training, and periodic audit and review.
However, no website, mobile application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your personal information transmitted to, through, using, or in connection with the services. In particular, email, texts, and chats may not be secure, and you should carefully decide what information you send to us via such communications channels. Any transmission of personal data is at your own risk. If a personal-data breach occurs, we assess the incident and provide notifications to affected individuals, customers, regulators, or authorities where required by law or contract.
Cookies and similar technologies
Our website may use cookies, pixels, local storage, tags, software development kits, and similar technologies to operate securely, remember preferences, measure website performance, understand engagement, and support marketing.
Where required by applicable law, we request consent before using non-essential technologies and provide controls to accept, reject, or manage categories of cookies. Strictly necessary technologies may be used without consent where they are essential to provide a service you request, maintain security, or transmit communications.
Details of the technologies actually used, including provider, purpose, category, and duration, are described through our Cookie Notice and cookie preference controls. You may also use browser settings and, where applicable, recognised opt-out preference signals.
Marketing communications
We may send business and marketing communications about Nadel products, services, events, or content where permitted by applicable law. Depending on your location and relationship with us, we may rely on consent, legitimate interests, or an applicable existing-customer or business-contact rule. Every electronic marketing communication will include an appropriate method to unsubscribe or change preferences.
You may opt out at any time by using the unsubscribe mechanism in the message or contacting privacy@nadel.com or privacy@nadel.uk.com. We may retain limited suppression information so that we can respect your choice.
Artificial intelligence and automated processing
Nadel may use approved artificial-intelligence-assisted or automated tools to support internal productivity, content preparation, search, summarisation, analytics, security, customer support, or other business activities. Where such tools process personal information, the processing remains subject to this Statement, Nadel's Responsible Use of AI Policy, data-classification requirements, vendor controls, and applicable privacy and AI laws.
Nadel does not currently use solely automated decision-making to make decisions about individuals that produce legal or similarly significant effects. Meaningful human review is required for significant customer, employment, legal, compliance, financial, or public-facing decisions. If Nadel introduces regulated automated decision-making or an AI interaction that requires specific transparency, pre-use notice, opt-out, access, or appeal rights, we will provide the applicable notice and controls before use.
Your privacy rights
Depending on your location and the circumstances, you may have some or all of the following rights:
- to be informed about how your personal information is used;
- to request access to or a copy of personal information we hold about you;
- to request correction of inaccurate or incomplete information;
- to request deletion or erasure, subject to legal exceptions;
- to request restriction of processing;
- to object to processing based on legitimate interests and to object to direct marketing at any time;
- to receive certain information in a portable format where applicable;
- to withdraw consent where processing is based on consent;
- to obtain information about, opt out of, access, or appeal certain automated decision-making where applicable;
- to opt out of the sale or sharing of personal information and to limit certain uses of sensitive personal information where California law applies; and
- to lodge a complaint with a supervisory authority and to exercise rights without unlawful discrimination or retaliation.
You may withdraw consent or opt out of marketing as easily as you gave consent. The right to object to direct marketing is unconditional.
The exact scope of these rights varies by location. There are also several exceptions where we may not have an obligation to fulfil your request. We will explain any decision to not act where required.
How to submit a request
You may submit a privacy request by emailing privacy@nadel.com or privacy@nadel.uk.com, writing to either address listed under "Who we are," or calling +1 310 815 5462. Please describe your request and your relationship with Nadel. We may request information reasonably necessary to verify your identity, authority, or the scope of the request. An authorised agent may submit a request where permitted, subject to verification of the agent's authority.
We will respond within the period required by applicable law. This is generally one month under UK/EU GDPR, subject to a permitted extension for complex or numerous requests, and generally 45 calendar days under the CCPA, subject to a permitted extension.
California privacy disclosures
This section supplements the remainder of the Statement for California residents and is intended to provide a California Notice at Collection and privacy-policy disclosures. The categories below describe personal information Nadel may have collected, used, or disclosed during the preceding 12 months, depending on your interaction with us.
| California category | Examples Nadel may process | Purposes | Disclosed for business purposes to |
|---|---|---|---|
| Identifiers | Name, address, email, telephone, account/customer ID, IP address, online identifiers | Service delivery, communication, security, transactions, marketing, legal compliance | Affiliates, service providers, manufacturers, fulfillment/logistics, professional advisers |
| Customer records / personal information categories | Contact information, signatures, billing and transaction details, government identifiers where required | Contracting, order fulfillment, recruitment, finance, legal and regulatory obligations | Service providers, payment/finance providers, HR/recruitment providers, advisers |
| Commercial information | Products and services requested or purchased, order history, preferences, project and delivery details | Quoting, sales, fulfillment, customer service, analytics, relationship management | Manufacturing, fulfillment, logistics, CRM, analytics, finance providers |
| Internet or other electronic network activity | Device/browser data, website interactions, cookie identifiers, logs, authentication and security events | Website operation, security, analytics, service improvement, marketing where permitted | Hosting, security, analytics, marketing and communications providers |
| Approximate geolocation | Location inferred from IP address or regional settings | Security, localisation, analytics, appropriate website experience | Hosting, security, analytics providers |
| Professional or employment-related information | Employer, role, professional profile, CV, work history, references, applicant and workforce information | Business communications, recruitment, workforce administration, due diligence | HR, recruitment, background-check, benefits and professional-service providers |
| Sensitive personal information | Account credentials; government identifiers; health, accessibility, dietary, background-check, or immigration/right-to-work information where lawfully required | Security, account access, recruitment, accommodations, legal obligations; not used to infer characteristics for advertising | Authorised HR, security, legal, benefits, screening, and service providers |
| Inferences | Business interests, preferences, likely product or service interests, security or risk indicators | Personalisation, relationship management, security, analytics, service improvement | CRM, analytics, security and marketing providers where permitted |
| Communications and content | Emails, enquiries, support messages, documents, creative files, customer-provided content | Responding, service delivery, support, compliance, legal claims | Service providers, customers, suppliers, advisers as necessary |
Sale, sharing, and sensitive personal information
Nadel does not sell personal information for monetary consideration. Nadel may disclose personal information to service providers and contractors for business purposes such as to support our business functions. We only make these business purpose disclosures under written contracts that describe the purposes, require the recipient to keep the personal information confidential, prohibit using the disclosed information for any purpose except performing the contract, and meet the CCPA's other contract requirements for engaging service providers or contractors. Depending on the configuration of analytics or advertising technologies, certain disclosures of online identifiers or internet activity may constitute "sharing" for cross-context behavioural advertising under California law. Where applicable, Nadel will provide a "Your Privacy Choices" or equivalent mechanism, honour valid opt-out preference signals such as Global Privacy Control, and identify the relevant categories and recipients. Nadel does not knowingly sell or share personal information of consumers under 16 years of age.
Nadel uses or discloses sensitive personal information only for permitted business purposes, such as security, account access, recruitment, legal compliance, accommodations, and service delivery, unless additional notice and a right to limit are required.
California rights
California residents may have the right to know, access, delete, or correct personal information; opt out of sale or sharing; limit certain uses of sensitive personal information; receive information about and exercise rights related to covered automated decision-making technology; use an authorised agent; and receive equal service and pricing without unlawful discrimination. Requests may be submitted using the methods in "How to submit a request."
Individuals in the United Kingdom and European Economic Area
If UK GDPR or EU GDPR applies, you may complain to the supervisory authority in the country where you live or work, or where you believe an infringement occurred. For UK matters, you may contact the Information Commissioner's Office at ico.org.uk. You are encouraged to contact us first so we can try to resolve the concern.
Where required by applicable law, Nadel will identify an authorised UK or EU representative in the relevant notice or communication.
Children's information
Nadel's website and services are directed to adult business users and are not directed to children. We do not knowingly collect personal information from children under 18 through the website or intentionally run campaigns directed to children. If you believe a child has provided personal information to us, please contact the Data Protection Officer so we can assess and take appropriate action.
Third-party websites and services
Our website may link to websites, platforms, or services operated by third parties. Their privacy practices are governed by their own notices and we do not control these third parties' tracking technologies or how they may be used. We encourage you to review those notices before providing personal information.
Changes to this Statement
We review this Statement at least annually and may update it when our practices, technologies, legal obligations, or business operations change. The date this Statement was last updated is identified at the top of this Statement. We will notify you of changes to this policy by updating the "last updated" date and posting the updated policy. If a change materially affects how we use personal information, we will provide an appropriate additional notice before the change takes effect where required by law.
We do not treat continued website use alone as consent to a material change where applicable law requires affirmative consent.
Contact and complaints
For questions, requests, or complaints about this Statement or our privacy practices, contact:
- privacy@nadel.com — United States and general privacy enquiries
- privacy@nadel.uk.com — United Kingdom and EEA privacy enquiries
- Joe Fancher, Data Protection Officer, Jack Nadel Inc., 5820 Uplander Way, Culver City, CA 90230, United States; +1 310 815 5462
- Jack Nadel International Ltd, Monmouth House, 87–93 Westbourne Grove, London W2 4UL, United Kingdom
If you need this Statement in an accessible alternative format, please contact us using one of the methods above.