Privacy Policy
Last updated: 2026-05-21
1. Who We Are
Nurtiq is operated by Nurtiq SL, with registered address in Barcelona, Spain. We provide Customer Success Operations services to B2B SaaS businesses. For any privacy-related questions or requests, please contact us at privacy@nurtiq.io.
2. Our Two Roles
Nurtiq acts in two distinct capacities depending on the data in question. First, we are the data controller for information about visitors to nurtiq.io, our own leads, and our internal billing and administrative data — we determine the purposes and means of processing this data. Second, we are a data processor acting on behalf of our business clients when we handle the data they entrust to us (such as their CRM records, product analytics, and communication metadata). Processing in that second capacity is governed by a separate Data Processing Agreement (DPA) signed with each client, and the remainder of this policy should be read in light of that distinction.
3. What We Collect
From website visitors (controller role): When you visit nurtiq.io or our other public pages, we collect standard server and analytics data including IP address, browser and device type, referring URL, and page views. This is collected via Vercel Analytics in a privacy-respecting manner.
From clients and on behalf of clients (processor role): In order to deliver our Customer Success Operations service, we access data from the systems our clients connect to Nurtiq. This includes:
- CRM data from HubSpot: account names, contact details, deal stages, and deal values.
- Product analytics from PostHog or similar tools: event types and timestamps (not the content of events).
- Email metadata from Gmail or Microsoft/Graph: sender address, recipient address(es), subject line, and timestamp. We never access, store, or process the body of any email message.
- Billing data from Stripe: subscription status, MRR, and payment history as reported by the client's Stripe account.
We do not intentionally collect special-category data (as defined in GDPR Art. 9) and ask clients not to send it to us.
4. Why We Collect It
The data we access and process is used exclusively to deliver the services described in our client agreements. Specifically, we use it for: detecting churn risk and expansion signals among our clients' customer accounts; drafting human-reviewed recommendations and playbooks for the client's Customer Success team; and generating structured weekly reports summarising account health. Visitor data is used to understand how our public website performs and to follow up with inbound leads. We do not sell any data to third parties, nor do we use client data to train AI models beyond what is required to fulfil the current service.
5. Legal Bases
We process personal data only where we have a lawful basis to do so under GDPR Art. 6:
- Performance of contract (Art. 6(1)(b)): Processing is necessary to provide the Customer Success Operations services agreed with our clients, including all CRM, billing, and product analytics data.
- Legitimate interest (Art. 6(1)(f)): Email metadata (sender, recipient, subject, timestamp) is processed on the basis of our and our clients' legitimate interest in understanding communication patterns and response times as Customer Success signals. We have carried out a balancing test and consider this interest proportionate, given that we access only metadata and never message content.
- Legitimate interest (Art. 6(1)(f)): Website analytics and lead follow-up are processed on the basis of our legitimate interest in running and improving our business.
Where required by applicable law (including LOPDGDD), we will obtain explicit consent before processing.
6. Gmail Data Handling
When you connect a Gmail account, Nurtiq accesses email metadata only (the gmail.metadata OAuth scope): sender, recipient(s), subject, and timestamp. We do not access, store, or use the body of any email message. This metadata is used solely to compute Customer Success signals about response timing and communication patterns with your accounts. Nurtiq's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Sub-Processors
To deliver our service, we engage the following sub-processors. Each is bound by a data processing agreement or equivalent safeguard.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database & authentication | EU (Frankfurt) |
| Vercel | Application hosting | Global edge, EU regions |
| Anthropic | AI processing (Claude API) | US (Standard Contractual Clauses) |
| Resend | Transactional email | EU |
Clients receive 30 days' notice before a new sub-processor is added and may object during that period.
8. Connected Data Sources
In addition to the sub-processors above, Nurtiq connects to data sources that belong to and are controlled by the client themselves. These connected sources — HubSpot, Stripe, PostHog, Google/Gmail, and Microsoft/Graph — are accessed solely with the client's explicit authorisation and for the purpose of delivering the agreed service. They are not sub-processors of Nurtiq; rather, the client is the controller of that data and Nurtiq accesses it as processor under the client's instructions.
Note that Stripe plays a dual role: it is a connected data source when Nurtiq reads a client's billing data from the client's Stripe account, and separately it is Nurtiq's own payment processor when Stripe is used to bill the client for Nurtiq's services.
9. Data Retention
During the contract: We retain client data for as long as necessary to deliver the service and as specified in the DPA.
After contract end: Client data is retained for a maximum of 30 days following termination, to allow for backup recovery and orderly offboarding. After that period, data is permanently deleted from all systems, including backups, unless a longer retention period is required by applicable law.
Earlier deletion: Clients may request deletion of their data before the end of the 30-day window by contacting privacy@nurtiq.io. We will confirm deletion within 30 calendar days of the request.
Visitor and lead data collected in our controller capacity is retained for no longer than 12 months from collection, or until a deletion request is received.
10. Your Rights (GDPR Arts. 15–22)
Under the GDPR and LOPDGDD, you have the following rights regarding your personal data:
- Access (Art. 15): Request a copy of the personal data we hold about you.
- Rectification (Art. 16): Ask us to correct inaccurate or incomplete data.
- Erasure (Art. 17): Request deletion of your data, subject to applicable legal obligations.
- Restriction of processing (Art. 18): Ask us to limit how we use your data in certain circumstances.
- Data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
To exercise any of these rights, contact privacy@nurtiq.io. We will respond within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the AEPD (Agencia Española de Protección de Datos), the Spanish data protection supervisory authority, at www.aepd.es.
11. International Transfers
Most of our sub-processors are based in the European Union and no transfer outside the EEA is involved. The one exception is Anthropic, which processes data in the United States. This transfer is governed by Standard Contractual Clauses (SCCs) as approved by the European Commission, providing an adequate level of protection for your data. We keep the list of sub-processors and their transfer mechanisms up to date and will notify clients of any material changes.
12. Cookies
We use a small number of cookies on our websites. Essential cookies are required for the site to function correctly (e.g., session management). We also use privacy-respecting analytics provided by Vercel Analytics, which does not require consent under our current configuration. We do not use third-party advertising cookies. A fuller cookie notice, including an opt-out mechanism where required by law, will be published separately and linked from the footer of our public pages.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, legal requirements, or services. When we do, we will post the revised version at this URL and update the date at the bottom of the page. For material changes that affect how we process client data, we will provide advance notice by email. Continued use of our services after the effective date of any update constitutes acceptance of the revised policy.