Privacy policy
Last updated:
This page explains what data AskNudge processes, why, who it is shared with, how long it is kept and what you can do about it. It covers the site www.asknudge.ai, the application app.asknudge.ai, the booking forms published by our customers — including on their own domain names — and the conversation widget embedded in their websites.
1.The essentials
- Most of the data we hold is not ours. When you book through an AskNudge form, the company that publishes that form decides everything; we merely process the data on its behalf.
- We do not sell anything, we do not use this data for our own prospecting, and we do not use it to train artificial intelligence models.
- Product analytics are never started without your agreement. Advertising tags, on the other hand, depend on a setting that belongs to each company — and that setting is off by default: section 5 says exactly what fires, and when.
- The database is hosted in the European Union. Several providers are American; section 7 names them one by one.
- To have your data deleted, write to the company you booked with, or to us at contact@asknudge.ai if you no longer remember which one. Section 11 says what deletion reaches, and what it does not.
2.Who is responsible for your data
This is the most important distinction in this document, because it determines who you should be writing to.
You booked a meeting
The company that sent you the form is the controller. It decides which questions are asked, what it does with the answers and how long it keeps them.
AskNudge is its processor within the meaning of Article 28 GDPR: we store and process that data on its instructions, in order to provide it with the service, and for nothing else.
Send your requests to that company first. Its name appears on the form and in the emails you received. If you cannot find it, write to us: we will pass the request on.
You have an AskNudge account
Here, the publisher of AskNudge (BeBranded) is the controller for your account, your organisation and your subscription data.
This is the only data whose use we decide ourselves. Section 6 sets it out.
We never use a customer’s visitor data for our own purposes: no prospecting, no resale, no model training.
3.If you filled in a booking form
Here is what is collected, what it is used for and on what legal basis. Not every row applies to every form: each company chooses the questions it asks and the options it turns on.
| Data | What it is used for | Legal basis |
|---|---|---|
| First name, last name | Identify who is coming to the meeting and personalise the messages. | Performance of your booking request (Art. 6(1)(b)) |
| Email address | Confirmation, reminders, calendar invitation, cancellation or reschedule link, follow-up after a missed meeting, unsubscribe. | Performance of your request, then the company’s legitimate interest for follow-ups (Art. 6(1)(b) and 6(1)(f)) |
| Phone number | Let the person you are meeting reach you. SMS or reminder message if the company has enabled that option. | Performance of your request (Art. 6(1)(b)) |
| Answers to the form’s questions, free text included | Prepare the conversation and route you to the right person. | Performance of your request (Art. 6(1)(b)) |
| Qualification score | Computed from your answers and the rules the company has defined, in order to prioritise meetings. It produces no solely automated decision: a human calls you back, or does not. | The company’s legitimate interest (Art. 6(1)(f)) |
| Chosen slot and assigned host | Create the calendar event and, where applicable, the video call. | Performance of your request (Art. 6(1)(b)) |
| Conversation with the assistant | Answer your questions and book the slot. See section 4. | Performance of your request (Art. 6(1)(b)) |
| Answers typed before the form was submitted | If you start the form without finishing it, the company can follow up with what you had already entered. | The company’s legitimate interest (Art. 6(1)(f)) |
| UTM parameters, referring site, page address, device type | Know which campaign or which page produced the meeting. Device type is reduced to “mobile” or “desktop”, inferred from your window width rather than from any analysis of your browser. | The company’s legitimate interest in internal attribution (Art. 6(1)(f)); consent (Art. 6(1)(a)) as soon as analytics or advertising reporting is involved |
| IP address | Limit abuse and automated form filling, and keep the record of the consent given at the moment of booking. Your country, derived from your IP address by our content delivery network, is used to apply the geographic restrictions chosen by the company; it is not retained. | Legitimate interest: security of the service (Art. 6(1)(f)); the obligation to be able to prove consent |
What is done with this data
- Create and manage the meeting, cancel it or move it.
- Create the calendar event and the video call with the provider the company has connected (Google Calendar, Microsoft, Zoom). Zoom meetings created by AskNudge are configured without automatic recording.
- Send service emails: confirmation, reminders, follow-up after a missed meeting, recovery sequence if the form was left unfinished.
- Copy the contact and the meeting into the company’s CRM, if it has connected one. From then on, that data also lives with the company and follows its own policy.
- Report a conversion to its advertising accounts where it has configured them. Your email and phone number never leave in the clear towards those platforms: they are normalised and then turned into a cryptographic fingerprint (SHA-256) before being sent.
- Limit abuse, monitor technical errors and measure product usage.
4.The booking assistant
Some forms offer a conversational assistant. It answers your questions and books the meeting for you. What you write to it is sent to Anthropic, which provides the language model, for as long as it takes to produce the reply.
The assistant draws on a knowledge base built from the customer company’s public website, read by a Cloudflare service when the company triggers that analysis. That knowledge base contains no visitor personal data.
Transcripts are not used to train models. Those that did not lead to a meeting are deleted automatically — see section 9.
5.Consent, analytics and advertising
This section is detailed because the honest answer depends on a setting that belongs to each customer company.
Analytics
Our product analytics tool (PostHog) is never started until you have given your agreement. This is not a switch flipped after the fact: without your agreement the script is not initialised at all, so no analytics cookie is set and no event is sent. It is only present on the public booking pages; the application itself contains none.
Advertising tags
They exist to tell the company’s ad platforms (Meta, Google, LinkedIn, TikTok, OpenAI) that a meeting has been booked. Two cases, depending on what the company has configured:
- It has turned the consent request on. No vendor script is loaded and no event is sent until you have given your agreement.
- It has not turned it on. This setting is off by default, so this is the case unless the organisation has deliberately changed it: the tags it has configured then load on page view. Configuring them and collecting consent are its responsibility, as the controller — if a cookie banner appears, it is the company’s own.
What the checkbox actually commits you to
When a form shows a consent checkbox, it covers the processing of your data by the company, not merely analytics. As a result, refusing it prevents the booking from being completed: you can read the page and talk to the assistant, but confirmation stays blocked until the box is ticked. We would rather write this down than let you believe it is a simple statistics toggle.
This consent is recorded as evidence: the wording that was shown to you, the date and your IP address. Your choice, on the other hand, is not remembered from one visit to the next — there is no consent cookie. It is held in memory for the length of the page view and is gone on reload, so you are asked again each time the form loads. The durable record is a row in the database attached to your contact, not something stored in your browser.
6.If you have an AskNudge account
For users of the application, we process: identity and email address, password as a hash or external sign-in identifier, organisation and role, display preferences, access tokens for the services you connect (calendar, video conferencing, CRM, advertising platforms, telephony), billing and subscription data, audit logs of sensitive actions, technical logs and errors.
This data is used to run the service, to bill it, to secure it and to answer you when you write to us. Legal basis: performance of the contract between us, our accounting obligations, and our legitimate interest in securing and improving the product.
Access tokens for third-party services are used only for the actions you have asked for (read your availability, create an event, push a contact). You can revoke each connection from within the application and from the provider itself.
7.Processors and recipients
We sell no data. We entrust some of it to providers, strictly in order to run the service. Those marked “on activation” receive nothing until the customer company has configured them.
| Provider | Role | Hosting |
|---|---|---|
| Supabase | Database and server-side processing — the foundation of the service. | European Union (Ireland; uploaded files in Frankfurt) |
| Vercel | Hosting of the site and the application. | United States |
| Resend | Sending service emails: confirmations, reminders, follow-ups. | United States |
| Anthropic | Language model behind the booking assistant, and writing assistance inside the application. | United States |
| Cloudflare | Reading a customer’s public website to feed the assistant’s knowledge base — on activation. | Global network |
| Stripe | Customer subscriptions. Also booking deposits, on activation, collected through the company’s own Stripe account. | United States / EU |
| Sentry | Technical error reporting. Configured with no personal data and no session replay. | European Union (Germany) |
| PostHog | Usage analytics, on the public pages only and after consent. | European Union |
| Twilio, Aircall, Ringover, WhatsApp Business | SMS and reminder messages — on activation, using the company’s own account. | United States / EU |
| Google, Microsoft, Zoom | Calendars and video conferencing — on activation, once the company’s account is connected. | United States / EU |
| Meta, Google, LinkedIn, TikTok, OpenAI | Advertising conversion reporting — on activation. This means these companies’ advertising platforms, not their artificial intelligence services. | United States |
To which may be added, where relevant: the CRM the company has connected, and judicial or administrative authorities where a legal obligation requires it.
8.Transfers outside the European Union
The database and the application processing are located in the European Union, as are error collection and analytics. Several of the providers listed above are, however, established in the United States.
Those transfers rely on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework, together with technical measures: encryption in transit and at rest, separation by organisation, and minimisation of what is sent — the identifiers passed to advertising platforms, for example, are reduced to cryptographic fingerprints.
9.How long we keep what
These durations are not intentions: they are the ones applied by the automatic purge that runs every night.
| Data | Retention |
|---|---|
| Assistant conversations that did not lead to a meeting | 90 days by default, then deletion. Each customer company can shorten this, down to 7 days, or lengthen it. A conversation that led to a meeting follows the fate of that meeting. |
| Answers typed into an unfinished form | 30 days, then deletion — unless the meeting was eventually booked. |
| Webhook delivery logs | 60 days. |
| Test contacts created by our monitoring probes | 7 days. |
| Contacts and meetings | For as long as the customer company’s account exists: they are not erased after a fixed period. The company can trigger their deletion at any time, in particular at your request. |
| Consent evidence (wording shown, date, IP address) | Kept with the contact record, and deleted with it. |
| Address on the unsubscribe list | Kept indefinitely, including after an erasure: that is what guarantees we do not write to you again. |
| Account and organisation data (AskNudge customers) | For the duration of the contract, then [[TO FILL: deletion delay after an account is terminated]]. |
| Invoicing documents | 10 years, in accordance with French accounting obligations. |
| Encrypted database backups | [[TO FILL: backup retention period at the database host]] |
10.Your rights
You have a right of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time and to give directives about what happens to your data after your death.
How to exercise them
- You booked a meeting with a company: write to that company. It is the one that decides, and it has a command inside AskNudge that carries out the deletion. If you do not know who to write to, write to us and we will pass the request on.
- You have an AskNudge account: write to us directly.
- You simply want to stop receiving emails: the unsubscribe link at the bottom of every message is enough, and it takes effect immediately. Messages tied to a meeting already booked — confirmation, reminders — keep arriving.
By email: legal@asknudge.ai. By post: BeBranded, 34 avenue Chanzy, 93250 Villemomble, France.
No data protection officer has been appointed. Requests are handled by the publication director, Maxime Konzelmann, at legal@asknudge.ai.
We answer within one month. We may ask you for something that lets us verify your identity if the request leaves any doubt — only in that case, and that item is not retained.
11.What deletion reaches — and what it does not
A promise of total erasure would be false. Here is the truth, in both directions.
What is genuinely deleted
- Your contact record.
- Your meetings, their notes and their history.
- Your conversations with the assistant.
- Scheduled follow-ups addressed to you.
- Partial answers from an unfinished form.
- Webhook delivery logs concerning you.
- The consent evidence attached to your record.
What remains, but depersonalised
- Analysis reports covering free-text answers are redacted — what concerns you is replaced by a deletion marker — rather than destroyed.
- Audit log entries keep the action, its author and its date; the personal detail is replaced.
- CRM synchronisation logs keep the trace of a push and its outcome, without its content.
- The revenue associated with your meetings is kept as a total, with nothing that identifies you.
- Your address stays on the unsubscribe list if you had put it there: it is the only way to guarantee we do not write to you again.
What we cannot reach
- The company’s CRM. If it synchronised your contact, a copy of it exists there, outside AskNudge. Only that company can delete it.
- Our email provider’s delivery logs. It keeps its own delivery records, according to its own policy.
- Database backups. They are not edited row by row; they expire on their own, and deleted data is never reintroduced into the live service.
- What has already been reported to advertising platforms as a fingerprint, where the company had configured them. Erasing it is a matter for each platform.
13.Security
Traffic is encrypted in transit and data is encrypted at rest at our database host. Each organisation’s data is partitioned and access to it is filtered by rules enforced in the database itself, not only in the application. Sensitive actions are logged. Internal access is limited to the people who need it.
Our error-tracking tool is configured to receive no personal data: sensitive URL parameters, headers, cookies and request bodies are stripped before sending, and session video replay is deliberately absent — replaying those screens would amount to exporting their contents.
In the event of a data breach likely to create a risk to your rights, we inform our customer — the controller — without delay, so that it can make the notifications incumbent on it.
14.Minors
AskNudge is a professional tool. The service is not addressed to minors and we do not knowingly collect their data. If you believe a minor has sent us information, write to us: we will delete it.
15.Changes
This policy changes along with the product. The date of the last update appears at the top of the page. When a change materially alters the way data is processed, our customers are informed so that they can inform their own visitors.
16.Contacting us and complaining
Write to contact@asknudge.ai. The publisher’s full details appear in the legal notice.
If our answer does not satisfy you, you may refer the matter to the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr.