Privacy policy
Last updated: July 2026
1. Who we are
NudgeCompliant (“we”, “us”) provides tools that help businesses understand their EU AI Act readiness. We are the controller of the personal data described in this policy. Privacy questions can be sent to hello@nudgecompliant.com.
2. Data we collect
- Contact details, including your name and email address
- Your company name and other organisation details you provide
- The AI tools you list and information about how your business uses them
- Audit answers, classifications, results, and generated recommendations
- Basic technical and usage data needed to secure and improve the service
3. How and why we use it
- To run audits, classify tools, produce results, and provide requested features
- To maintain security, prevent misuse, and improve the service
- To respond to support and service enquiries
- To send product or deadline emails you have requested
For business users, we generally rely on our legitimate interests to provide, secure, and improve a B2B service. Where required, we rely on consent for marketing communications. You can withdraw marketing consent at any time by using the unsubscribe link or contacting us.
We do not sell personal data or use your audit information to train our own AI models.
4. Sub-processors and international transfers
- Supabase, database and authentication services, hosted in the EU West region in Ireland
- Resend, transactional and requested email delivery
- Anthropic, processes relevant audit inputs to produce classifications and documents
- Paddle, payment processing / Merchant of Record (EU, UK, US). See paddle.com/privacy
| Processor | Purpose | Regions | Privacy |
|---|---|---|---|
| Supabase | Database & auth | EU (Ireland) | supabase.com/privacy |
| Resend | Email delivery | EU / US | resend.com/legal/privacy-policy |
| Anthropic | AI classification | US | anthropic.com/privacy |
| Paddle | Payment processing / Merchant of Record | EU, UK, US | paddle.com/privacy |
We use appropriate data-processing agreements and safeguards where a provider processes data outside the UK or EEA.
4a. Payment Processing
Payments are processed by Paddle.com Market Limited, who act as Merchant of Record for all transactions. Paddle collect and process payment information including card details, billing address, and transaction history on our behalf. Paddle are responsible for PCI-DSS compliance for all payment data. We do not store card details. For Paddle's privacy practices see paddle.com/privacy. Data processed: subscription plan, payment status, billing country, transaction ID.
5. Retention
We keep account, audit, and result data for up to two years after your last interaction with the service, unless we need to retain it longer to meet a legal obligation or resolve a dispute. We may delete or anonymise data sooner when it is no longer needed.
6. Your UK GDPR and EU GDPR rights
Depending on the circumstances, you may ask us to access, correct, erase, restrict, or provide a copy of your personal data. You may also object to processing based on legitimate interests and withdraw consent where consent is the lawful basis.
To exercise a right, email hello@nudgecompliant.com. We normally respond within one month. You may also complain to the UK Information Commissioner's Office at ico.org.uk.
7. Security, cookies, and changes
We use reasonable technical and organisational measures to protect personal data. Our cookie policy explains the limited functional technologies used on this site. We do not use advertising or tracking cookies. We may update this policy as the service or law changes; the latest version and date will always appear here.
See also our terms of service and cookie policy.