Privacy policy

Last updated: 2026-06-15

1. Who we are

Nudje is a B2B SaaS product operated by:

  • UPSID SAS, a French simplified joint-stock company
  • Registered address: 76 Boulevard Diderot, 75012 Paris, France
  • SIRET: 89183223000017
  • SIREN: 891832230
  • Contact: [email protected]
  • Data Protection: [email protected] (interim; DPO duties handled by the founder Benoit Lecureur until a dedicated DPO is appointed)

2. What data we collect

From you (account holder, our customer)

  • Email address (required for login)
  • Full name (optional, displayed in workspace)
  • Password (hashed, never stored in plaintext)
  • Workspace name + settings
  • Billing data: Stripe customer ID, payment method last 4 digits, billing address
  • Support conversations (when you chat with us via Crisp)

From your end-users (your customers, on your behalf)

When you send events to Nudje API on behalf of your end-users, we receive:

  • End-user identifiers (e.g., email, custom IDs)
  • Custom traits you choose to send
  • Events you choose to track

We process this data as a Data Processor on your behalf. You are the Data Controller for your end-users' data and remain responsible for collecting valid consent from them.

3. How we use your data

  • Operate the service: authentication, billing, sending nudges
  • AI-powered insights: Mistral processes anonymized customer data to generate nudge messages and Customer 360 insights
  • Customer support: respond to your chat messages via Crisp
  • Service quality: detect bugs and outages via Sentry error monitoring
  • Product improvement: anonymous usage analytics (only with your consent via the cookie banner)
  • Legal compliance: keep billing records as required by French law

We do NOT sell your data or your end-users' data. Ever.

4. Sub-processors

We rely on the following sub-processors to operate Nudje:

Provider Purpose Location Data shared
Supabase Database hosting + authentication EU (Frankfurt) All workspace data, accounts
Cloudflare Workers compute + CDN + DNS Global All HTTP traffic
Stripe Payment processing US (with EU SCCs) Billing data, payment methods
Resend Transactional email delivery US (with EU SCCs) Recipient email + email content
Mistral AI text generation EU (France) Customer data sent for AI insights (anonymized where possible)
Crisp Chat support widget EU (France) Email + name + workspace + plan during chat
Sentry Error monitoring EU (Frankfurt) Stack traces + user email + workspace ID on errors
Inngest Background job orchestration US (with EU SCCs) Event payloads sent for async processing

We're happy to share Data Processing Agreements (DPAs) on request. Email [email protected].

5. Data retention

  • Account data: kept while your account is active + 30 days after deletion (recovery window)
  • Customer events: kept for the duration of your subscription + 90 days after cancellation
  • Billing records: 10 years (French legal requirement)
  • Support conversations (Crisp): 2 years
  • Error logs (Sentry): 90 days
  • Backups: 30-day rolling window

6. Your rights under GDPR

You have the right to:

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate data (most editable via Settings; otherwise email [email protected])
  • Erasure: delete your workspace via Settings · Workspace, or email [email protected]
  • Data portability: API endpoint /v1/me/export (coming V1.5) or email request
  • Object to processing: stop marketing emails via Profile · Email preferences
  • Lodge a complaint: with CNIL (France) or your local data protection authority

To exercise these rights, email [email protected]. We respond within 30 days.

7. International data transfers

Some sub-processors (Stripe, Resend, Inngest) are based in the US. We rely on:

  • EU Standard Contractual Clauses (SCCs) signed with each sub-processor
  • Adequacy decisions where applicable (e.g., EU-US Data Privacy Framework)

8. Cookies

We use cookies for three purposes:

  • Strictly necessary: authentication, session, billing flows. Always on.
  • Analytics (optional): anonymous usage stats to improve the product.
  • Functional (optional): chat widget (Crisp), email open tracking.

You can manage your preferences via the cookie banner shown on first visit, or reopen preferences at any time by clicking Cookie preferences in the footer.

9. Security

  • Passwords are hashed with bcrypt
  • All traffic encrypted via TLS 1.3
  • Database hosted on Supabase with at-rest encryption
  • Service role keys stored in Cloudflare Workers secrets (encrypted)
  • 2FA available on your Nudje account (Settings · Profile)
  • Regular security reviews

In case of a data breach, we'll notify you within 72 hours per RGPD article 33.

10. Changes to this policy

Material changes will be notified by email 30 days before they take effect. Continued use of Nudje after a change = acceptance.

11. Contact

For any privacy or data protection question: