1 Who we are
MarginNudge is a trading name of MarginNudge Ltd. For personal information used to operate our website, accounts, billing, sales, analytics and support, MarginNudge Ltd is the controller.
When a business customer enters personal information about its employees, contractors, clients, prospects or suppliers into MarginNudge, the customer normally acts as controller and MarginNudge normally acts as processor. That processing is governed by our Data Processing Agreement.
Questions or privacy requests may be sent to contact@marginnudge.com.
2 Scope
This notice applies to visitors, prospective customers, account holders, authorised users, people invited to a workspace, quote recipients, demo participants and business contacts. MarginNudge is intended only for UK businesses and users aged 18 or over.
3 Personal information we collect
| Category | Examples |
|---|---|
| Identity and account | Name, work email address, login method, authentication identifiers, account status and password reset or verification records. We do not receive Google passwords. |
| Business and workspace | Business name, sector, workspace membership, assigned roles, invitations, branding and business contact details. |
| Quote and customer content | Client or prospect names, business contact details, quote recipients, scope, commercial terms, role and cost information, notes, approvals and quote history entered by users. |
| Billing and subscription | Plan, billing frequency, trial and renewal dates, Stripe customer and subscription identifiers, payment status, refunds and failed-payment status. Stripe handles full card details; MarginNudge does not store them. |
| Communications | Demo requests, Calendly bookings, support messages, feedback and records of transactional quote emails, including sender and recipient addresses and delivery status. |
| Technical and usage | IP address, device and browser information, session and security records, timestamps, pages or product features used, event identifiers and cookie preferences. |
| Audit and administration | Actions taken by users and authorised MarginNudge operators, approval records, access changes, suspension or cancellation records and related reasons. |
| Marketing and CRM | Business contact details, lead source, sales activity, communication preferences and engagement records held in Attio or connected marketing tools. |
Please do not upload special category data, criminal offence data, children’s information, payment card numbers, passwords, national insurance numbers or other sensitive information that is not necessary for the quote assessment.
4 How we collect information
- Directly from you when you visit the website, request a demo, create an account, invite a user, contact us or use the service.
- From your employer or another customer when it creates or manages your workspace access.
- From customer users when they enter client, prospect, employee, contractor or supplier information into a quote.
- Automatically through authentication, security, analytics, cookies and similar technologies.
- From providers such as Stripe, Calendly, Google sign-in, Resend and our other service providers.
- From legitimate business sources such as a company website or professional business profile where permitted by law.
5 Why we use personal information
| Purpose | Use | Lawful basis |
|---|---|---|
| Provide accounts and the service | Create and secure accounts, manage workspaces, calculate quote economics, save versions, generate PDFs and send user-confirmed quote emails. | Contract; legitimate interests |
| Subscriptions and billing | Start trials, process subscriptions, manage failed payments, cancellations and refunds. | Contract; legal obligation |
| Support and communications | Answer enquiries, arrange demos, provide support and send service messages. | Contract; legitimate interests |
| Security and administration | Prevent misuse, enforce roles, investigate incidents, maintain audit trails and protect customers. | Legitimate interests; legal obligation |
| Product analytics | Understand adoption and improve the service without placing sensitive quote content in analytics events. | Consent where required; legitimate interests where permitted |
| Sales and marketing | Manage prospective customer relationships and send relevant B2B communications. | Consent where required; legitimate interests where permitted |
| Legal and financial records | Keep evidence of contracts, transactions, disputes and compliance. | Legal obligation; legitimate interests |
| Anonymised insight | Create aggregated or irreversibly anonymised statistics that no longer identify an individual. | Legitimate interests |
Where we rely on legitimate interests, those interests include operating and improving a secure B2B service, protecting our business, understanding product use and communicating with relevant business contacts. You may object where the law gives you that right.
6 Automated calculations
MarginNudge uses deterministic calculations and rules to produce statuses such as Approve, Review, Reprice or Blocked. These outputs support a business user’s decision and do not make decisions about individuals that produce legal or similarly significant effects. MarginNudge does not use artificial intelligence in the MVP.
7 Who receives personal information
We share information only where needed to provide, secure and administer the service, meet legal obligations or protect our rights. Recipients may include our hosting, database, authentication, email, analytics, CRM, payment, consent-management and scheduling providers; professional advisers; regulators; law-enforcement bodies; and a buyer or successor in a genuine corporate transaction.
Our current providers are identified in the MarginNudge Subprocessor List. Stripe and some other providers may also act as independent controllers for particular activities under their own privacy terms.
8 International transfers
Some providers process information outside the United Kingdom, including in the United States, Singapore or other countries. Where UK personal information is transferred to a country without UK adequacy regulations, we use an approved safeguard where required, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism. We also assess relevant provider protections and contractual commitments.
9 Retention
| Record | Typical retention |
|---|---|
| Active accounts and customer content | For the subscription term. Following cancellation, the customer has 14 days to access or export data. Active-system deletion is targeted within 30 days after that access period, subject to legal retention. |
| Backups | Removed through the normal backup cycle, targeted within 90 days after active-system deletion. |
| Billing and accounting records | Normally six years after the end of the relevant financial year, or longer where law requires. |
| Support and operational communications | Normally 24 months after the matter closes, unless needed for a dispute or legal obligation. |
| Demo, sales and CRM records | Normally 24 months after the last meaningful interaction, unless you object sooner or a longer period is justified. |
| Security and access logs | Normally up to 12 months, unless required for an incident, investigation or legal claim. |
| Analytics and cookie information | For the periods stated in Cookie Settings and the Cookie Policy. |
| Audit and legal records | For as long as reasonably necessary to establish, exercise or defend legal claims; records may be minimised or anonymised where appropriate. |
10 Security
We use proportionate technical and organisational measures designed to protect personal information. These include encrypted connections, provider-supported encryption at rest, verified authentication, role-based access, tenant separation, row-level security, private storage paths, restricted production access, server-side secrets, signed service events, audit records, backups and incident procedures. No online service can guarantee absolute security.
11 Your rights
Depending on the circumstances, you may have rights to be informed, access your personal information, correct it, erase it, restrict its use, object to processing and receive certain information in a portable format. Where we rely on consent, you may withdraw it without affecting earlier lawful processing.
To exercise a right, email contact@marginnudge.com. We may request information needed to verify your identity and authority. If MarginNudge processes the information solely for a customer, we may refer the request to that customer.
You may complain to the UK Information Commissioner’s Office at ico.org.uk. We would appreciate the opportunity to address your concern first.
12 Marketing
You can unsubscribe from marketing by using the link in the message or contacting us. We may retain a minimal suppression record so that we continue to respect your choice. Service, security, billing and account messages are not marketing and may still be sent where necessary.
13 Cookies
We use cookies and similar technologies as explained in the MarginNudge Cookie Policy. You can change non-essential choices through Cookie Settings. Essential technologies required for security, authentication and requested functionality cannot always be disabled through the preference centre.
14 Changes to this notice
We may update this notice to reflect changes to the service, suppliers or law. We will publish the updated date and provide reasonable notice of material changes where appropriate.
Company information
MarginNudge is a trading name of MarginNudge Ltd, a company registered in England and Wales under company number 17470390. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: contact@marginnudge.com.
