Privacy policy
Last updated: 2026-06-15
1. Who we are
Nudje is a B2B SaaS product operated by:
- UPSID SAS, a French simplified joint-stock company
- Registered address: 76 Boulevard Diderot, 75012 Paris, France
- SIRET: 89183223000017
- SIREN: 891832230
- Contact: support@nudje.io
- Data Protection: support@nudje.io (interim; DPO duties handled by the founder Benoit Lecureur until a dedicated DPO is appointed)
2. What data we collect
From you (account holder, our customer)
- Email address (required for login)
- Full name (optional, displayed in workspace)
- Password (hashed, never stored in plaintext)
- Workspace name + settings
- Billing data: Stripe customer ID, payment method last 4 digits, billing address
- Support conversations (when you chat with us via Crisp)
From your end-users (your customers, on your behalf)
When you send events to Nudje API on behalf of your end-users, we receive:
- End-user identifiers (e.g., email, custom IDs)
- Custom traits you choose to send
- Events you choose to track
We process this data as a Data Processor on your behalf. You are the Data Controller for your end-users' data and remain responsible for collecting valid consent from them.
3. How we use your data
- Operate the service: authentication, billing, sending nudges
- AI-powered insights: Mistral processes anonymized customer data to generate nudge messages and Customer 360 insights
- Customer support: respond to your chat messages via Crisp
- Service quality: detect bugs and outages via Sentry error monitoring
- Product improvement: anonymous usage analytics (only with your consent via the cookie banner)
- Legal compliance: keep billing records as required by French law
We do NOT sell your data or your end-users' data. Ever.
4. Sub-processors
We rely on the following sub-processors to operate Nudje:
| Provider | Purpose | Location | Data shared |
|---|---|---|---|
| Supabase | Database hosting + authentication | EU (Frankfurt) | All workspace data, accounts |
| Cloudflare | Workers compute + CDN + DNS | Global | All HTTP traffic |
| Stripe | Payment processing | US (with EU SCCs) | Billing data, payment methods |
| Resend | Transactional email delivery | US (with EU SCCs) | Recipient email + email content |
| Mistral | AI text generation | EU (France) | Customer data sent for AI insights (anonymized where possible) |
| Crisp | Chat support widget | EU (France) | Email + name + workspace + plan during chat |
| Sentry | Error monitoring | EU (Frankfurt) | Stack traces + user email + workspace ID on errors |
| Inngest | Background job orchestration | US (with EU SCCs) | Event payloads sent for async processing |
We're happy to share Data Processing Agreements (DPAs) on request. Email support@nudje.io.
5. Data retention
- Account data: kept while your account is active + 30 days after deletion (recovery window)
- Customer events: kept for the duration of your subscription + 90 days after cancellation
- Billing records: 10 years (French legal requirement)
- Support conversations (Crisp): 2 years
- Error logs (Sentry): 90 days
- Backups: 30-day rolling window
6. Your rights under GDPR
You have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data (most editable via Settings; otherwise email support@nudje.io)
- Erasure: delete your workspace via Settings · Workspace, or email support@nudje.io
- Data portability: API endpoint
/v1/me/export(coming V1.5) or email request - Object to processing: stop marketing emails via Profile · Email preferences
- Lodge a complaint: with CNIL (France) or your local data protection authority
To exercise these rights, email support@nudje.io. We respond within 30 days.
7. International data transfers
Some sub-processors (Stripe, Resend, Inngest) are based in the US. We rely on:
- EU Standard Contractual Clauses (SCCs) signed with each sub-processor
- Adequacy decisions where applicable (e.g., EU-US Data Privacy Framework)
8. Cookies
We use cookies for three purposes:
- Strictly necessary: authentication, session, billing flows. Always on.
- Analytics (optional): anonymous usage stats to improve the product.
- Functional (optional): chat widget (Crisp), email open tracking.
You can manage your preferences via the cookie banner shown on first visit, or reopen preferences at any time by clicking Cookie preferences in the footer.
9. Security
- Passwords are hashed with bcrypt
- All traffic encrypted via TLS 1.3
- Database hosted on Supabase with at-rest encryption
- Service role keys stored in Cloudflare Workers secrets (encrypted)
- 2FA available on your Nudje account (Settings · Profile)
- Regular security reviews
In case of a data breach, we'll notify you within 72 hours per RGPD article 33.
10. Changes to this policy
Material changes will be notified by email 30 days before they take effect. Continued use of Nudje after a change = acceptance.
11. Contact
For any privacy or data protection question:
- Email: support@nudje.io
- Postal: UPSID SAS, 76 Boulevard Diderot, 75012 Paris, France