Privacy policy

Last updated:

This page explains what data AskNudge processes, why, who it is shared with, how long it is kept and what you can do about it. It covers the site www.asknudge.ai, the application app.asknudge.ai, the booking forms published by our customers — including on their own domain names — and the conversation widget embedded in their websites.

1.The essentials

  • Most of the data we hold is not ours. When you book through an AskNudge form, the company that publishes that form decides everything; we merely process the data on its behalf.
  • We do not sell anything, we do not use this data for our own prospecting, and we do not use it to train artificial intelligence models.
  • Product analytics are never started without your agreement. Advertising tags, on the other hand, depend on a setting that belongs to each company — and that setting is off by default: section 5 says exactly what fires, and when.
  • The database is hosted in the European Union. Several providers are American; section 7 names them one by one.
  • To have your data deleted, write to the company you booked with, or to us at contact@asknudge.ai if you no longer remember which one. Section 11 says what deletion reaches, and what it does not.

2.Who is responsible for your data

This is the most important distinction in this document, because it determines who you should be writing to.

You booked a meeting

The company that sent you the form is the controller. It decides which questions are asked, what it does with the answers and how long it keeps them.

AskNudge is its processor within the meaning of Article 28 GDPR: we store and process that data on its instructions, in order to provide it with the service, and for nothing else.

Send your requests to that company first. Its name appears on the form and in the emails you received. If you cannot find it, write to us: we will pass the request on.

You have an AskNudge account

Here, the publisher of AskNudge (BeBranded) is the controller for your account, your organisation and your subscription data.

This is the only data whose use we decide ourselves. Section 6 sets it out.

We never use a customer’s visitor data for our own purposes: no prospecting, no resale, no model training.

3.If you filled in a booking form

Here is what is collected, what it is used for and on what legal basis. Not every row applies to every form: each company chooses the questions it asks and the options it turns on.

DataWhat it is used forLegal basis
First name, last nameIdentify who is coming to the meeting and personalise the messages.Performance of your booking request (Art. 6(1)(b))
Email addressConfirmation, reminders, calendar invitation, cancellation or reschedule link, follow-up after a missed meeting, unsubscribe.Performance of your request, then the company’s legitimate interest for follow-ups (Art. 6(1)(b) and 6(1)(f))
Phone numberLet the person you are meeting reach you. SMS or reminder message if the company has enabled that option.Performance of your request (Art. 6(1)(b))
Answers to the form’s questions, free text includedPrepare the conversation and route you to the right person.Performance of your request (Art. 6(1)(b))
Qualification scoreComputed from your answers and the rules the company has defined, in order to prioritise meetings. It produces no solely automated decision: a human calls you back, or does not.The company’s legitimate interest (Art. 6(1)(f))
Chosen slot and assigned hostCreate the calendar event and, where applicable, the video call.Performance of your request (Art. 6(1)(b))
Conversation with the assistantAnswer your questions and book the slot. See section 4.Performance of your request (Art. 6(1)(b))
Answers typed before the form was submittedIf you start the form without finishing it, the company can follow up with what you had already entered.The company’s legitimate interest (Art. 6(1)(f))
UTM parameters, referring site, page address, device typeKnow which campaign or which page produced the meeting. Device type is reduced to “mobile” or “desktop”, inferred from your window width rather than from any analysis of your browser.The company’s legitimate interest in internal attribution (Art. 6(1)(f)); consent (Art. 6(1)(a)) as soon as analytics or advertising reporting is involved
IP addressLimit abuse and automated form filling, and keep the record of the consent given at the moment of booking. Your country, derived from your IP address by our content delivery network, is used to apply the geographic restrictions chosen by the company; it is not retained.Legitimate interest: security of the service (Art. 6(1)(f)); the obligation to be able to prove consent

What is done with this data

  • Create and manage the meeting, cancel it or move it.
  • Create the calendar event and the video call with the provider the company has connected (Google Calendar, Microsoft, Zoom). Zoom meetings created by AskNudge are configured without automatic recording.
  • Send service emails: confirmation, reminders, follow-up after a missed meeting, recovery sequence if the form was left unfinished.
  • Copy the contact and the meeting into the company’s CRM, if it has connected one. From then on, that data also lives with the company and follows its own policy.
  • Report a conversion to its advertising accounts where it has configured them. Your email and phone number never leave in the clear towards those platforms: they are normalised and then turned into a cryptographic fingerprint (SHA-256) before being sent.
  • Limit abuse, monitor technical errors and measure product usage.

4.The booking assistant

Some forms offer a conversational assistant. It answers your questions and books the meeting for you. What you write to it is sent to Anthropic, which provides the language model, for as long as it takes to produce the reply.

The assistant draws on a knowledge base built from the customer company’s public website, read by a Cloudflare service when the company triggers that analysis. That knowledge base contains no visitor personal data.

Transcripts are not used to train models. Those that did not lead to a meeting are deleted automatically — see section 9.

6.If you have an AskNudge account

For users of the application, we process: identity and email address, password as a hash or external sign-in identifier, organisation and role, display preferences, access tokens for the services you connect (calendar, video conferencing, CRM, advertising platforms, telephony), billing and subscription data, audit logs of sensitive actions, technical logs and errors.

This data is used to run the service, to bill it, to secure it and to answer you when you write to us. Legal basis: performance of the contract between us, our accounting obligations, and our legitimate interest in securing and improving the product.

Access tokens for third-party services are used only for the actions you have asked for (read your availability, create an event, push a contact). You can revoke each connection from within the application and from the provider itself.

7.Processors and recipients

We sell no data. We entrust some of it to providers, strictly in order to run the service. Those marked “on activation” receive nothing until the customer company has configured them.

ProviderRoleHosting
SupabaseDatabase and server-side processing — the foundation of the service.European Union (Ireland; uploaded files in Frankfurt)
VercelHosting of the site and the application.United States
ResendSending service emails: confirmations, reminders, follow-ups.United States
AnthropicLanguage model behind the booking assistant, and writing assistance inside the application.United States
CloudflareReading a customer’s public website to feed the assistant’s knowledge base — on activation.Global network
StripeCustomer subscriptions. Also booking deposits, on activation, collected through the company’s own Stripe account.United States / EU
SentryTechnical error reporting. Configured with no personal data and no session replay.European Union (Germany)
PostHogUsage analytics, on the public pages only and after consent.European Union
Twilio, Aircall, Ringover, WhatsApp BusinessSMS and reminder messages — on activation, using the company’s own account.United States / EU
Google, Microsoft, ZoomCalendars and video conferencing — on activation, once the company’s account is connected.United States / EU
Meta, Google, LinkedIn, TikTok, OpenAIAdvertising conversion reporting — on activation. This means these companies’ advertising platforms, not their artificial intelligence services.United States

To which may be added, where relevant: the CRM the company has connected, and judicial or administrative authorities where a legal obligation requires it.

8.Transfers outside the European Union

The database and the application processing are located in the European Union, as are error collection and analytics. Several of the providers listed above are, however, established in the United States.

Those transfers rely on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework, together with technical measures: encryption in transit and at rest, separation by organisation, and minimisation of what is sent — the identifiers passed to advertising platforms, for example, are reduced to cryptographic fingerprints.

9.How long we keep what

These durations are not intentions: they are the ones applied by the automatic purge that runs every night.

DataRetention
Assistant conversations that did not lead to a meeting90 days by default, then deletion. Each customer company can shorten this, down to 7 days, or lengthen it. A conversation that led to a meeting follows the fate of that meeting.
Answers typed into an unfinished form30 days, then deletion — unless the meeting was eventually booked.
Webhook delivery logs60 days.
Test contacts created by our monitoring probes7 days.
Contacts and meetingsFor as long as the customer company’s account exists: they are not erased after a fixed period. The company can trigger their deletion at any time, in particular at your request.
Consent evidence (wording shown, date, IP address)Kept with the contact record, and deleted with it.
Address on the unsubscribe listKept indefinitely, including after an erasure: that is what guarantees we do not write to you again.
Account and organisation data (AskNudge customers)For the duration of the contract, then [[TO FILL: deletion delay after an account is terminated]].
Invoicing documents10 years, in accordance with French accounting obligations.
Encrypted database backups[[TO FILL: backup retention period at the database host]]

10.Your rights

You have a right of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time and to give directives about what happens to your data after your death.

How to exercise them

  • You booked a meeting with a company: write to that company. It is the one that decides, and it has a command inside AskNudge that carries out the deletion. If you do not know who to write to, write to us and we will pass the request on.
  • You have an AskNudge account: write to us directly.
  • You simply want to stop receiving emails: the unsubscribe link at the bottom of every message is enough, and it takes effect immediately. Messages tied to a meeting already booked — confirmation, reminders — keep arriving.

By email: legal@asknudge.ai. By post: BeBranded, 34 avenue Chanzy, 93250 Villemomble, France.

No data protection officer has been appointed. Requests are handled by the publication director, Maxime Konzelmann, at legal@asknudge.ai.

We answer within one month. We may ask you for something that lets us verify your identity if the request leaves any doubt — only in that case, and that item is not retained.

11.What deletion reaches — and what it does not

A promise of total erasure would be false. Here is the truth, in both directions.

What is genuinely deleted

  • Your contact record.
  • Your meetings, their notes and their history.
  • Your conversations with the assistant.
  • Scheduled follow-ups addressed to you.
  • Partial answers from an unfinished form.
  • Webhook delivery logs concerning you.
  • The consent evidence attached to your record.

What remains, but depersonalised

  • Analysis reports covering free-text answers are redacted — what concerns you is replaced by a deletion marker — rather than destroyed.
  • Audit log entries keep the action, its author and its date; the personal detail is replaced.
  • CRM synchronisation logs keep the trace of a push and its outcome, without its content.
  • The revenue associated with your meetings is kept as a total, with nothing that identifies you.
  • Your address stays on the unsubscribe list if you had put it there: it is the only way to guarantee we do not write to you again.

What we cannot reach

  • The company’s CRM. If it synchronised your contact, a copy of it exists there, outside AskNudge. Only that company can delete it.
  • Our email provider’s delivery logs. It keeps its own delivery records, according to its own policy.
  • Database backups. They are not edited row by row; they expire on their own, and deleted data is never reintroduced into the live service.
  • What has already been reported to advertising platforms as a fingerprint, where the company had configured them. Erasing it is a matter for each platform.

12.Cookies and local storage

By default, only strictly necessary records are used. They do not ask for your agreement because, without them, the service does not work. Some are written under two names at once — nudge_ and pipecall_, the product’s former name. That is deliberate: a booking widget already embedded on a website keeps running the copy of our script it cached, and that older copy can only read the former name. Writing both is what stops a visitor who already dismissed or already booked from seeing the widget again. Both are dropped once those cached copies have expired.

NameWhat it doesDurationConsent
Session cookieKeep you signed in to the application. Set by our authentication layer.Length of the sessionNo
nudge_theme (formerly pipecall_theme)Remember the light or dark theme. Browser local storage, not a cookie: nothing is sent to the server.Until clearedNo
nudge_booking_access (formerly pc_booking_access)Open the cancellation or reschedule page from the link received by email.2 hoursNo
nudge_closed_… and pipecall_closed_…Remember that you closed the conversation window, so it is not reopened endlessly.7 daysNo
nudge_converted_… and pipecall_converted_…Remember that a meeting has already been booked from this page, so you are not asked again.365 daysNo
Analytics cookiesUnderstand how the public booking pages are used.Set by PostHogYes
Advertising platform cookiesAttribute a meeting to the campaign that produced it.Set by each platformSee section 5

There is no consent cookie and no language cookie: your consent choice lives in memory for the length of the page view, and the language you are reading is determined by the address of the page.

To remove these records, clear site data in your browser settings. You can also block them, at the cost of the convenience they provide: booking itself keeps working.

13.Security

Traffic is encrypted in transit and data is encrypted at rest at our database host. Each organisation’s data is partitioned and access to it is filtered by rules enforced in the database itself, not only in the application. Sensitive actions are logged. Internal access is limited to the people who need it.

Our error-tracking tool is configured to receive no personal data: sensitive URL parameters, headers, cookies and request bodies are stripped before sending, and session video replay is deliberately absent — replaying those screens would amount to exporting their contents.

In the event of a data breach likely to create a risk to your rights, we inform our customer — the controller — without delay, so that it can make the notifications incumbent on it.

14.Minors

AskNudge is a professional tool. The service is not addressed to minors and we do not knowingly collect their data. If you believe a minor has sent us information, write to us: we will delete it.

15.Changes

This policy changes along with the product. The date of the last update appears at the top of the page. When a change materially alters the way data is processed, our customers are informed so that they can inform their own visitors.

16.Contacting us and complaining

Write to contact@asknudge.ai. The publisher’s full details appear in the legal notice.

If our answer does not satisfy you, you may refer the matter to the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr.