Effective Date: January 12, 2026
Last Updated: August 28, 2026
1. Who We Are
Nesteal (“we,” “us,” or “our”) operates nesteal.com and provides two services: individual Frequency Therapy sessions (“Mind Reprogramming”) and a hospital-facing nurse-retention program (“Ne Ste Al for Hospitals”). We are committed to protecting your privacy and being transparent about how we collect, use, and safeguard personal data.
Data Controller: Ne Ste Al OOD, Bulgaria”
Business Address: Boulevard 6th September 160
Data Protection Officer / Privacy Contact: [Ne Ste Al OOD, Bulgaria
Contact: contact@nesteal.com
This policy applies to two different groups of people, covered separately below because the data involved is genuinely different:
-
Section 3–4: Individual visitors and consumer clients booking a personal session
-
Section 5: Nurses and hospital staff participating in a Ne Ste Al for Hospitals program, and the hospital administrators who oversee it
2. Website Data We Collect
Comments: If you leave a comment, we collect your name, email address, website URL (if provided), and comment content, along with your IP address and browser user agent for spam and security purposes. If you use Gravatar, an anonymized hash of your email may be sent to Gravatar to display your profile picture, which becomes publicly visible with your approved comment. Legal basis: legitimate interest in managing site content and security.
Media Uploads: If you upload images, avoid including embedded location data (EXIF GPS coordinates) — visitors can extract this from downloaded images. Remove location metadata before uploading if privacy is a concern.
Cookies:
-
Comment cookies (name, email, website URL) — expire after 1 year, only if you opt in
-
Authentication cookies — set on login; login cookies last 2 days (2 weeks with “Remember Me”); a temporary cookie confirming your browser accepts cookies is deleted on browser close
-
Screen options cookies — 1 year
-
Editing cookies (post ID) — no personal data, expires after 1 day
-
Analytics and advertising cookies — see Section 6
You can control cookies through your browser settings; disabling them may limit site functionality.
Embedded Content: Articles may embed content (videos, images) from other sites. Embedded content behaves as if you visited the source site directly and may collect data, use cookies, and track your interaction with it, especially if you’re logged into that service. We do not control these third-party practices.
3. Booking and Session Data (Individual Clients)
If you book an individual Frequency Therapy session, we collect the information you provide to schedule and deliver it: your name, email address, and any details you share about the state or concern you want addressed (for example, stress, a specific fear, or a habit you want to change).
Important — Special Category Data: Some of what you may choose to share (references to a mental health condition, past diagnosis, or a health concern) is classified as “special category data” under GDPR Article 9. We only collect this where you volunteer it as part of describing your session goals, and we rely on your explicit, opt-in consent — given at the point of booking — as the legal basis for processing it. You are never required to disclose a diagnosis or medical history to book a session; share only what you’re comfortable with.
What we do with it:
-
Schedule and deliver your session
-
Internal records of session history if you book again
-
With your separate consent, your testimonial may be used in marketing (see Section 8)
What we do not do: We do not sell this data, and we do not share the content of what you disclose in a session with any third party outside the practitioner delivering it, except as required by law.
Retention: We keep the nurse and treatment data as long as they are active clients. After that, it’s removed from our internal systems and database.
4. Payment Data
Payments are processed by Stripe. We do not store your full card details on our servers — they are handled directly by our payment processor under its own security standards and privacy policy. We retain a record of the transaction (amount, date, service purchased) for accounting purposes.
5. Hospital Program Data (Nurses and Hospital Administrators)
This section covers data collected through a Ne Ste Al for Hospitals program and is designed to be read alongside the data-handling terms of the signed pilot or service agreement with the contracting hospital, which controls in the event of any conflict.
What we collect from participating nurses: Responses submitted through the check-in form (self-rated stress, burnout, and motivation levels, and the state requested for a session), and session usage (frequency and timing of requests) — collected to deliver the session and to generate program-level reporting for the hospital.
Our current stated policy, consistent with how the program is marketed elsewhere on this site, is:
An individual nurse’s check-in responses and session content are never shown to hospital management, supervisors, or HR in identifiable form. Hospital leadership receives only aggregated, unit-level reporting (for example, average stress trends across a unit) once a minimum group size is reached, so no individual nurse’s data can reasonably be identified from it.
What we collect from hospital administrators: Name, work email, and role, for the purpose of account setup, reporting access, and billing.
Retention: Retention period for nurse check-in data and aggregated reports — typically tied to the length of the pilot/program agreement plus a defined post-termination period.
Not a Crisis-Monitoring Tool: The check-in data described above is not monitored in real time for crisis intervention. If a nurse indicates severe distress, the hospital’s own escalation pathway — not Nesteal — is responsible for responding. This should also be disclosed to nurses at the point of check-in.
6. Analytics and Advertising
We may use the following tools to understand site usage and run advertising campaigns:
-
Google analytics to understand how visitors use the site
-
Advertising pixels Meta— to measure ad performance and show relevant ads to past visitors
-
Email marketing Kit.com — if you subscribe to updates or enter your email through a form, it is added to our mailing list for the communications described in Section 9
-
Messaging: WhatsApp Business, that conversation is stored within WhatsApp Business per its own privacy terms
Each of these tools may set its own cookies or collect data per its own privacy policy; we link to the relevant policy in our cookie banner/consent tool where required by law.
7. Who We Share Your Data With
We do not sell, trade, or rent your personal data.
We share data only:
-
With service providers who help us operate the site, deliver sessions, or process payments (hosting provider, payment processor, email/messaging tools listed in Section 6), under confidentiality obligations
-
For password resets: your IP address is included in the reset email for security
-
When required by law, or to protect our rights, safety, or property
-
With a contracting hospital, limited to the aggregated reporting described in Section 5, under the terms of that hospital’s signed agreement
8. Testimonials
If you provide a testimonial, we ask for your separate, explicit consent before publishing it. You may request removal at any time by contacting us. We will not publish your full name or other identifying details without your specific agreement (see also Section 13 of our Terms of Service).
9. Communications
If you provide your email or opt in to messaging, we may send booking confirmations, service updates, and (if you’ve opted in) marketing communications. You can unsubscribe from marketing emails at any time via the link provided; service-related communications (like appointment confirmations) are not optional while you have an active booking.
10. How Long We Retain Data
-
Comments: retained indefinitely to support comment moderation, unless you request deletion
-
User accounts: retained until you request deletion, except where we’re legally required to keep records longer (e.g., accounting)
-
Booking/session data: see Section 3
-
Hospital program data: see Section 5
-
We do not retain personal data longer than necessary for the purpose it was collected, or as required by law
11. Your Rights
Under GDPR and other applicable data protection laws, you have the right to:
-
Access — request a copy of the personal data we hold about you
-
Rectification — correct inaccurate data
-
Erasure — request deletion, except where we’re legally required to retain it
-
Restriction — limit how we process your data in certain circumstances
-
Portability — receive your data in a structured, commonly used format
-
Object — object to certain processing, including direct marketing
-
Withdraw Consent — where processing relies on consent (including the health-data consent in Section 3), withdraw it at any time without affecting past processing
To exercise these rights, contact us at contact@nesteal.com. Nurses in a hospital program should also be able to raise data requests through their hospital’s designated contact, per the program agreement.
12. International Data Transfers
Our site is hosted at Namecheap.com servers.
13. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Children’s Privacy
This Website is not directed at individuals under 16. We do not knowingly collect personal data from children. If you believe we’ve inadvertently collected such data, please contact us so we can remove it.
15. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Updates will be posted here with a revised “Last Updated” date. For material changes affecting hospital program data, we will also notify the contracting hospital directly per the program agreement.
16. Legal Compliance and Contact
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR), the ePrivacy Directive, and [CONFIRM: any other applicable law for your jurisdiction].
Contact: contact@nesteal.com
Address: Business Address: Boulevard 6th September 160

