GDPR Compliance
Your rights and our obligations under the EU General Data Protection Regulation.
Last updated: June 2026
Data Controller
Data controller under GDPR: Nudge Technologies Ltd., Istanbul, Turkey.
Data protection contact: privacy@thenudge.io
Personal Data Processed and Purposes
Nudge processes only personal data necessary for service delivery:
- Account data: Name, email, company — for account management
- Billing data: Name, billing address — for payment processing
- Usage data: Platform interactions — to improve the service
Competitor price tracking uses only publicly available data. No personal data is obtained in this process.
Legal Basis (GDPR Article 6)
- Contract performance (6(1)(b)): Account management and service delivery
- Legitimate interests (6(1)(f)): Platform security and improvements
- Legal obligation (6(1)(c)): Tax and accounting records
Your Rights (GDPR Chapter 3)
- Right of access (Art. 15): Request information about your processed data
- Right to rectification (Art. 16): Correct inaccurate data
- Right to erasure (Art. 17): Request deletion of your data
- Right to portability (Art. 20): Receive data in machine-readable format
- Right to object (Art. 21): Object to interest-based processing
- Right to restriction (Art. 18): Restrict processing under certain conditions
To exercise your rights: privacy@thenudge.io — responses within 30 days.
Data Transfers
Your data is not transferred to countries outside the EEA. All infrastructure operates within the European Union.
Data Breach Notification
In the event of a personal data breach, the supervisory authority is notified within 72 hours and affected users are notified without undue delay.
Data Processing Agreement
A DPA under GDPR Article 28 is available for Enterprise customers: privacy@thenudge.io
Right to Lodge a Complaint
You have the right to lodge a complaint with your national data protection authority. In the UK: Information Commissioner's Office — ico.org.uk