Last revised: 25 May 2026
This Cookie Policy explains how Nano Advanced Services Limited (“NAS”, “we”, “us”) uses cookies, local storage, and similar technologies on nas.cards and on the Partner-facing web Surfaces (the Business Portal, the Support Portal, and the Admin Back-office). It is published alongside our Privacy Policy and our Partner Privacy Policy, which describe how we handle personal data more generally.
This Cookie Policy is written to comply with the ePrivacy Directive (Directive 2002/58/EC, as amended) and corresponding national implementations in the EU/EEA, the UK Privacy and Electronic Communications Regulations 2003, and the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486).
1. What are cookies and similar technologies?
A cookie is a small text file that a website stores on your browser or device. Local storage and session storage are browser-provided storage mechanisms similar in purpose to cookies. Pixel tags (or web beacons) are tiny images included in web pages or emails that allow a site or sender to detect activity. We refer to all of these collectively as “cookies” in this Policy.
Cookies can be either:
- First-party cookies — set by the site you are visiting (nas.cards or a Partner-branded Surface).
- Third-party cookies — set by a different organisation, typically when content from that organisation is included on the page (for example, a third-party anti-bot service).
They can also be either:
- Session cookies — deleted when you close the browser.
- Persistent cookies — kept on your device for a defined period or until you delete them.
2. Our default position
We do not set any cookies on first visit other than as required to deliver the page you requested. We do not use analytics, marketing, or advertising cookies by default.
If you make a choice in our cookie banner, we record that choice in your browser’s local storage (not in a cookie). Storing the choice this way is permitted under the ePrivacy rules where the storage is strictly necessary to comply with your expressed preference.
If you later choose to enable analytics or marketing tracking (for example, by adjusting your preferences via the “Cookie preferences” link in the footer), additional cookies may be set, and we will describe them transparently before enabling them.
3. Categories of cookies we may use
3.1 Strictly necessary
These cookies and storage entries are required to deliver the Services you have requested. We do not need your consent for these.
- The cookie-preference record kept in browser local storage (described in Section 2).
- The session-management cookie set when you sign in to a Partner-facing Surface (Business Portal, Support Portal, Admin Back-office), required to keep you signed in for the duration of your session.
- A short-lived CSRF-protection cookie used on form submissions, including the contact form on nas.cards.
3.2 Anti-bot / fraud-prevention
We use Google reCAPTCHA Enterprise on our contact form (and may use it on other interactive forms across our Surfaces) to detect and deter automated abuse. The service may set cookies on your device and may collect technical information about your interaction with the page (such as mouse-movement patterns, timing data, and a token issued by the service).
There are two legal bases at work, and they are separate:
- Storage of, and access to, information on your device (the reCAPTCHA cookies and any equivalent local-storage entries it places) is treated as strictly necessary under the EU ePrivacy Directive and the UK PECR, because the function cannot be performed without it and the storage is what makes form-abuse protection workable. No prior consent is required for strictly-necessary storage.
- The subsequent processing of any personal data that the anti-bot service receives (IP address, device fingerprint, interaction signals, etc.) is carried out on the basis of our legitimate interest in protecting our forms from automated abuse (Art. 6(1)(f) EU GDPR / UK GDPR). If you object to this processing for reasons relating to your particular situation, please contact privacy@nas.cards.
reCAPTCHA Enterprise is provided by Google LLC (United States). Transfers of personal data to Google in the United States are made under the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Agreement / UK Addendum to the SCCs as applicable), supplemented by additional technical and organisational measures.
3.3 Functional preferences
If you customise any aspect of a Partner-facing Surface (for example, language preference, theme, or table-view settings), we may store that preference in browser local storage on the device you are using. These preferences are not transmitted off your device except to apply your preference when the page reloads.
3.4 Analytics — currently not used by default
We do not use first-party or third-party analytics cookies on nas.cards by default. If we introduce analytics in future, we will require consent through the cookie banner before the analytics cookies are set, and we will update this Cookie Policy to describe the analytics provider and the cookies in question.
3.5 Marketing and advertising — not used
We do not use marketing or advertising cookies on nas.cards.
4. Cookies set on Partner-branded Customer Surfaces
The Consumer Web client, Business Portal, and other Partner-branded Surfaces operated by NAS on behalf of a Partner may set cookies and use local storage to enable authentication, session management, customer-preference recording, and security functions. These cookies are set in the operation of the Services on the Partner’s behalf, and the Partner’s own customer-facing privacy notice is the primary place to look for the cookies set in respect of the Partner’s Customers.
We may also use the third-party anti-bot service on Customer-facing forms (registration, sign-in, password recovery) on these Surfaces, on the legitimate-interests basis described above.
5. How to control cookies
5.1 In our cookie banner
You can decline non-essential cookies in our cookie banner when it appears (typically on first visit). You can change your choice at any time via the “Cookie preferences” link in the page footer.
5.2 In your browser
Most browsers let you view, manage, delete, and block cookies through the browser settings. Restricting or blocking cookies may break Services that depend on strictly-necessary cookies (for example, you may not be able to stay signed in to the Business Portal). The Help section of your browser explains how. Useful starting points:
- Chrome: https://support.google.com/chrome/answer/95647
- Firefox: https://support.mozilla.org/kb/cookies-information-websites-store-on-your-computer
- Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471
- Edge: https://support.microsoft.com/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
5.3 Opting out of tracking signals (Do Not Track, Global Privacy Control)
We respect the Global Privacy Control (GPC) signal where it is recognised under Applicable Law. If your browser sends a GPC signal, we treat it as a request not to be subject to non-essential tracking, even where you have not made an explicit choice in our cookie banner. We do not currently honour the legacy “Do Not Track” signal because it is not consistently defined; we apply the GPC standard instead.
6. Cookie list
Because we operate a default-off posture, the cookie list below is intentionally short. We will update this list as Surfaces and integrations evolve.
| Name | Type | Set by | Purpose | Duration |
|---|---|---|---|---|
nas-cookie-consent |
local-storage | NAS (first-party) | Records your cookie-preference choice so we don’t ask again on each visit. | Until you clear local storage or change preferences |
JSESSIONID or equivalent |
session cookie | NAS (first-party, on Partner-facing Surfaces) | Maintains your authenticated session. | End of browser session |
XSRF-TOKEN or equivalent |
session cookie | NAS (first-party, on Partner-facing Surfaces and on nas.cards contact form) | Protects against cross-site request forgery on form submissions. | End of browser session |
| Cookies set by the third-party anti-bot service | third-party | Third-party service provider | Detect and deter automated abuse on interactive forms. | Per the service provider’s policy; typically up to 6 months |
A more detailed list of the cookies set on a given Partner-branded Surface is available from the Partner that operates the relevant Program.
7. International transfers
Where a third-party service used in connection with a cookie may transfer information internationally (for example, to a service provider located outside the EU/EEA, the UK, or Hong Kong), we rely on the transfer mechanisms described in our Privacy Policy and our Data Processing Addendum.
8. Changes to this Cookie Policy
We may update this Cookie Policy from time to time. The “Last revised” date at the top reflects the most recent revision. If we introduce new categories of cookies (for example, if we add analytics in future), we will update the Cookie Policy and the cookie banner before the new cookies are set.
9. How to contact us
For any cookie-related question, please contact privacy@nas.cards.