Privacy Policy

nudgepath.io

How KeepFlow L.L.C-FZ handles personal data around nudgepath.io: what we gather, what we do with it, who sees it, and how it is kept safe.

Operator: KeepFlow L.L.C-FZ · Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Licence / Formation No. 2646796.01 / 2646796 · Effective date: 19 March 2026
Website: https://nudgepath.io
Primary contact: support@nudgepath.io

This policy is maintained in English; the English text is the working version published on nudgepath.io.

NudgePath is run by KeepFlow L.L.C-FZ (“KeepFlow”, “we”, “our”, or “us”). This page answers, in plain language, the questions people ask most often about personal data and the nudgepath.io website, the platform, its integrations, our support desk, and our marketing — and it sets out the rights that data protection law gives you.

1. Who and what does this policy cover?

It covers personal data that reaches us through the Website, demo bookings, sign-up and account flows, billing and contracting, support conversations, and the day-to-day running of the Services. It equally covers the moments you write to us, subscribe to our updates, join a webinar or event we host, or deal with us in any other business setting.

Our role changes with the situation. For some data we decide ourselves why and how it is used — there we act as an independent controller. But when one of our business customers runs support conversations, tickets, knowledge-base material, end-user messages, or similar operational content through the platform, it is normally that customer who sets the purposes. In that scenario the customer acts as primary controller, and we handle the data only on its instructions, within the limits of our contract with that customer.

Are you an End User chatting with a company that happens to use NudgePath? Then the contents of that conversation belong to that company’s privacy relationship with you, so please raise privacy questions with them first. Where it makes sense, we help our customer answer such requests.

2. What do we collect?

  • Who you are and how to reach you — name, employer, role, email, phone, postal address, and comparable business contact details.
  • Account and profile details — username, login identifiers, authentication metadata, role and permission settings, organisation details, and your preferences.
  • Billing records — billing address, invoices, subscription details, payment status, tax details, plus the limited payment information our payment processors pass back to us.
  • Device and technical signals — IP address, browser type, operating system, device identifiers, session identifiers, timestamps, rough IP-based location, and diagnostic logs.
  • How you use the product — pages viewed, features clicked, navigation paths, connection settings, event logs, usage volumes, and aggregated service statistics.
  • Conversations with us — messages you send, call notes, email threads, feedback, survey answers, demo requests, and support tickets.
  • Customer Content — tickets, conversations, prompts, knowledge sources, instructions, helpdesk metadata, attachments, and whatever else is submitted to or flows through the Services.
  • Marketing preferences — your subscription choices, consent records, and how you engage with what we send.
  • Cookie data — covered in detail in our Cookie Policy.

3. Where does this data come from?

Mostly from you: when you open an account, book a demo, subscribe, get in touch, attend an event, fill in a form, hook up an integration, or upload material.

Some of it arrives automatically while you use the Website and Services — through cookies, server logs, device data, APIs, and similar telemetry and diagnostics.

Some comes from our customers and their authorised users — say, when a workspace admin invites colleagues, wires up data sources, configures integrations, or files a support request that mentions you.

And some comes from third parties: payment processors, analytics vendors, cloud and infrastructure providers, communication tools, integration partners, resellers, identity providers, and publicly available business sources.

4. Why do we use your data — and what makes that lawful?

We only touch personal data when the law gives us a valid basis to do so. Depending on the situation, that basis is the contract we perform for you, a legal duty we must meet, our legitimate interest in running and improving the business, your consent, or another ground recognised by the law that applies. Concretely, we use personal data:

  1. to set up and manage accounts, authenticate users, enforce access controls, and deliver the Services;
  2. to take in, host, retrieve, and analyse Customer Content and produce Outputs from it — the core of running the platform for our customers;
  3. to take payments, run subscriptions, issue invoices, keep proper books, and stop payment fraud;
  4. to watch performance, fix problems, keep the platform secure, spot abuse, audit usage, and make the Services better and more reliable;
  5. to run support, onboarding, training, and account management;
  6. to tell you about your account, your subscription, legal notices, service updates, and policy changes;
  7. to send marketing where the law allows and your preferences permit, and to see whether that marketing works;
  8. to meet legal obligations, enforce agreements, establish or defend claims, protect our rights, and answer lawful demands from courts, regulators, and public authorities;
  9. to support corporate transactions, internal reporting, due diligence, financing, and similar legitimate business steps, always lawfully and with proper safeguards.

5. Do we sell or share your data?

Selling personal data, in the everyday sense of the word, is not something we do. We do pass it to a limited set of recipients — only as far as the purposes above require, and always under suitable contractual and organisational protections:

  • companies in our own group, where that matters for delivering the service, corporate administration, compliance, finance, or support;
  • vendors and subprocessors behind hosting, infrastructure, analytics, security, communications, support tooling, payments, identity management, model inference, and other operational work;
  • the integration providers and third-party tools you decide to connect;
  • professional advisers — lawyers, accountants, insurers, auditors, financing counterparties — all bound to confidentiality;
  • government, regulatory, law-enforcement, tax, and other public bodies, where the law requires or permits disclosure;
  • potential or actual buyers, investors, or merger counterparties during a corporate transaction, under appropriate confidentiality arrangements.

6. Does your data cross borders?

It can. Personal data may be kept or handled inside the United Arab Emirates, and also in whatever other countries we or our vendors work from — which means it may end up in jurisdictions whose privacy laws differ from those at home.

Where the applicable law asks for it, we put transfer safeguards in place — adequacy mechanisms, contractual protections, or other transfer tools the law recognises. By giving us personal data and using the Services, you accept that this kind of cross-border handling can happen as described here.

7. How do we protect your data?

We keep reasonable administrative, technical, and organisational safeguards in place to shield personal data from unlawful or unauthorised access, loss, misuse, alteration, or disclosure — things like role-based permissions, access controls, logging, encryption in transit and, where appropriate, at rest, vetting of suppliers, incident-response procedures, and internal confidentiality rules.

Honesty requires a caveat: nothing sent over the internet and nothing stored electronically is ever perfectly safe, so we cannot promise absolute security. Your side of the bargain is to use strong credentials, grant access sparingly, set permissions with care, and keep your own security controls in shape while using the Services.

If we learn of a data breach touching personal data we are responsible for, we act in line with applicable law and our contracts — including sending notifications whenever the law requires them.

8. How long is data kept?

Only as long as reasonably needed for the purposes it was gathered for: running the Services, keeping business records, meeting legal duties, settling disputes, enforcing agreements, preventing fraud, and protecting our rights and other people’s.

The exact period depends on the kind of data, your plan, technical and operational realities, and legal or contractual requirements. Once data has served its purpose, we delete it, anonymise it, or move it into secure archives, consistent with the law and our retention practices.

9. What rights do you have?

Depending on the law that applies and the context of the processing, you may ask to see your personal data, have mistakes fixed, have data erased, have processing restricted, receive a portable copy, object to certain uses, and take back consent where consent is what the processing rests on. You may also complain to a competent supervisory authority.

To use any of these rights, write to support@nudgepath.io or use the other contact routes on the Website. We may need to confirm who you are and pin down what exactly you are asking for. And where we merely process data for one of our customers, we may point your request to that customer or help them handle it, as our contract requires.

Exercising your rights never counts against you with us. Bear in mind, though, that not every right is unconditional: legal exceptions, technical limits, or record-keeping duties can oblige us to hold on to certain information.

10. Will you get marketing from us?

Possibly — where the law allows, we send service announcements, product news, event invitations, offers, and the like. Opting out of anything non-essential takes one click on the unsubscribe link, or a short note to us, at any time.

Opting out of marketing does not silence the operational messages we have to send anyway: account administration, service delivery, replies to your support requests, and anything the law obliges us to tell you.

11. What about cookies?

We and our partners rely on cookies, local storage, pixels, SDKs, and similar techniques to run the Website and Services, remember your choices, measure usage, improve features, and — where applicable — support marketing. The full story, including the cookie types involved and your options for managing them, lives in our Cookie Policy.

12. What about other companies’ sites and tools?

You will find links on the Website and in the Services to outside websites, documentation, helpdesks, communication channels, file-storage tools, and more. Their privacy, security, and content practices are theirs, not ours — so have a look at a third party’s privacy notice before you interact with it or switch on an integration.

13. Is NudgePath for children?

No — this is a business tool, not something aimed at children, and we do not knowingly gather children’s data in breach of the law. If you think a child has handed us personal data they should not have, tell us and we will put it right.

14. What if this policy changes?

We revise this Privacy Policy now and then as the law, our technology, or our business evolves. Material changes go up on the Website, and where it makes sense we add notice inside the Services or by email. The “effective date” at the top tells you when the current version took effect.

15. How do you reach us?

Questions about this Privacy Policy or how we treat data? KeepFlow L.L.C-FZ is at support@nudgepath.io — or on paper at Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.