Nudgy

Privacy Policy

Last updated: June 18, 2026

This Privacy Policy (this “Policy”) explains how Nudgy(“Nudgy,” “we,” “us,” or “our”) collects, uses, discloses, transfers, retains, and protects information in connection with the Nudgy compliance-auditing service (the “Service”), and describes the rights and choices available to you. This Policy forms part of, and is incorporated by reference into, our Terms of Service.

Nudgy is a business-to-business tool used by architecture, engineering, and construction firms. The Service is not directed to consumers, to the general public, or to children, and we do not knowingly collect personal information from anyone under the age of majority in their jurisdiction.

We design the Service to comply with Canada's Personal Information Protection and Electronic Documents Act (“PIPEDA”) and substantially similar provincial legislation and, where it applies to a given customer, the European Union / United Kingdom General Data Protection Regulation (“GDPR”). Capitalized terms not defined here have the meaning given in the Terms of Service.

1. Our role: when we are a processor and when we are a controller

The Service handles two categories of information, and our legal role differs between them:

  1. Customer Content. With respect to the specifications, drawings, and other materials you connect or upload, and any personal information they may contain (for example, names, stamps, or contact details appearing in a title block), you (or the organization you represent) are the controller and Nudgy acts as a processor that processes such information only on your documented instructions. Our processing of Customer Content is governed by our Data Processing Agreement (the “DPA”), which prevails over this Policy in the event of a conflict as to Customer Content.
  2. Account, billing, and usage data. With respect to the information we collect to operate, secure, support, and improve the Service (for example, your account identity, billing records, and technical logs), Nudgy is the controller, and this Policy describes how we process it.

2. Information we collect

We collect only the information the Service needs to operate:

  • Account & organization data — your name, work email, authentication credentials, and the organization, projects, and team membership you create or are invited to.
  • Documents you connect or upload (Customer Content) — project specifications and drawing sets, either uploaded directly or retrieved from OneDrive or SharePoint files you select, together with any personal information those documents happen to contain.
  • Microsoft 365 data — when you connect OneDrive or SharePoint, we use read-only Microsoft Graph permissions, and we retrieve only the files you explicitly select. We never write, move, rename, re-permission, or delete your files, and we do not retrieve files you have not selected.
  • Audit records we generate — the spec index, embeddings, findings, citations, and audit history produced when we check a drawing against a specification, including metadata identifying which document version was checked and when.
  • Billing data — records of the fees, plan, and engagement applicable to your account. Where payment processing is involved, payment-card details are handled by a payment processor and are not stored by Nudgy.
  • Technical & usage data — standard server and application logs, such as request metadata, device and browser information, IP address, timestamps, and error traces, that are needed to operate, secure, debug, and monitor the Service.

We do not intentionally collect special categories of personal data (such as health, biometric, or government-identifier information), and you should not place such information into Customer Content except as ordinarily appears in construction documents.

3. Cookies & similar technologies

We use only strictly necessary cookies and equivalent local-storage technologies — principally to authenticate you, maintain your logged-in session, secure the Service, and remember basic interface preferences. These are essential to deliver a service you have requested.

We do not use advertising cookies, cross-site tracking, or third-party marketing analytics, and we do not sell or share information for behavioural advertising. Because we use only strictly necessary technologies, the Service does not present a consent banner; you can block or delete cookies through your browser, but doing so will prevent you from logging in.

4. How we use information, and our legal bases

We use the information described above to:

  • Provide the Service — index your specification, run audits, and return cited findings;
  • Maintain the audit trail your industry requires — an immutable record of which document version was checked, and when;
  • Authenticate you, secure your account, prevent abuse, and isolate your data from that of other customers;
  • Provide support, communicate about your account, and send transactional notifications;
  • Process billing and administer the contractual relationship; and
  • Diagnose problems, monitor performance, and maintain the reliability and security of the Service.

Where the GDPR applies, we rely on the following legal bases for processing personal information for which we are the controller:

  1. Performance of a contract — to provide the Service to you and administer your account;
  2. Legitimate interests — to secure the Service, prevent abuse, diagnose problems, and improve reliability, balanced against your rights and interests;
  3. Legal obligation — to comply with recordkeeping, tax, and other legal requirements; and
  4. Consent — for the Microsoft 365 connection you authorize, which you may withdraw at any time (see Sections 6 and 12).

Where the GDPR designates you as controller of Customer Content, our processing on your behalf is governed by the DPA. Under PIPEDA, our collection, use, and disclosure of personal information rest on consent (express or implied through your use of the Service) and the limited exceptions permitted by law.

We do not sell your information, and we do not use your documents for advertising or to build profiles about you.

5. How your documents are handled

Specification and drawing PDFs you add to a project are stored in private, access-controlled storage, isolated per organization. Audits are processed by an isolated worker that reads the stored document, extracts the schedule tables, and runs the audit.

Stored documents are retained as part of your project's audit trail — so the exact version of the document behind each audit remains available for review — alongside the spec index, the embeddings, the findings, and the audit records. Retention and deletion are described in Section 9.

6. Microsoft 365 access & tokens

Authentication happens on Microsoft's side — Nudgy never sees or stores your Microsoft password. The read-only access token is held in your own browser session, not stored on Nudgy's servers, and expires automatically. Access can be revoked at any time from your Microsoft admin center or account settings. Revoking access prevents adding further files from Microsoft 365 but does not delete documents already added to a project or audit records already generated (see Section 9).

7. AI processing & service providers (subprocessors)

To deliver the Service we engage third-party providers (“subprocessors”) that process information on our behalf and under contract. Audit analysis and document embeddings run under commercial application-programming-interface agreements — the enterprise terms, not consumer AI products. Your documents are transmitted for processing only; they are not used to train any provider's models.

The current, authoritative list of subprocessors — including each provider's function and processing location — is maintained on our Subprocessors page, which also describes how we provide advance notice of changes. Each subprocessor is bound by data-protection obligations no less protective than those in this Policy and the DPA.

8. International data transfers

Nudgy is operated from Canada, and certain of our subprocessors process data on servers located in the United States or other countries. Where we transfer personal information across borders, we rely on appropriate safeguards, which may include:

  • Contractual protections requiring each subprocessor to provide a comparable level of protection, consistent with PIPEDA;
  • The European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) for transfers subject to the GDPR; and
  • The data-processing terms and certifications maintained by the relevant subprocessor.

By using the Service you acknowledge that your information may be processed in, and transferred to, countries other than your country of residence, where data-protection laws may differ, subject to the safeguards described above. A copy of the relevant transfer mechanism is available on request at contact@nudgy.ca.

9. Data retention & deletion

We retain information only for as long as necessary for the purposes described in this Policy:

  • Specification and drawing PDFs, the spec index, embeddings, findings, and audit records are retained for the life of your project to preserve the audit trail your industry requires, and thereafter only as necessary for legal, security, recordkeeping, or dispute-resolution purposes.
  • Account & billing data is retained while your account is active and for a reasonable period afterward to meet legal and recordkeeping obligations.

On termination of your account or engagement, we will, on your written request and subject to the DPA, delete or return Customer Content and delete personal information for which we are the controller, except for (i) information we are required to retain by law, and (ii) routine backups, which are deleted on our ordinary backup-rotation cycle. Unless a longer period is required by law or a separate written agreement, we aim to complete deletion within ninety (90) days of a verified request.

10. Security

We maintain administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration, including:

  • Encryption of all traffic in transit using TLS;
  • Encryption at rest of the stored documents, spec index, findings, and audit records by the managed services that hold them;
  • Logical separation of data per organization and per project, enforced server-side on every query;
  • Least-privilege internal access controls and use of the service-role key only on trusted server-side infrastructure; and
  • Use of reputable managed infrastructure and subprocessors bound by their own security commitments.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for the security of your own Microsoft 365 tenant.

11. Data breach notification

We maintain procedures to detect, investigate, and respond to security incidents. If we become aware of a breach of security safeguards involving personal information that creates a real risk of significant harm (under PIPEDA) or a personal-data breach (under the GDPR), we will:

  1. notify the affected customer without undue delay after becoming aware of the breach;
  2. where we act as processor, support the controller in meeting its own notification obligations to regulators and data subjects; and
  3. make any reports to supervisory authorities and affected individuals that applicable law requires of us.

12. Your rights

Subject to applicable law, you may exercise the following rights with respect to personal information about you:

  • Access — obtain confirmation of, and a copy of, the personal information we hold about you;
  • Correction — have inaccurate or incomplete information rectified;
  • Deletion — request erasure of personal information, subject to our legal retention obligations;
  • Portability — receive certain information in a structured, commonly used, machine-readable format;
  • Restriction & objection — restrict or object to certain processing, including processing based on legitimate interests;
  • Withdraw consent — withdraw any consent you have given, including for the Microsoft 365 connection, without affecting the lawfulness of prior processing; and
  • Complain — lodge a complaint with a supervisory authority.

To exercise any of these rights, email contact@nudgy.ca. We may need to verify your identity before responding, and we will respond within the time required by applicable law. Where Nudgy acts as a processor of Customer Content, we will refer requests we receive directly from data subjects to the relevant controller and assist that controller in responding.

You also have the right to complain to the Office of the Privacy Commissioner of Canada (or your applicable provincial commissioner) and, where the GDPR applies, to your local data-protection supervisory authority. We would appreciate the chance to address your concern before you do so.

13. Automated decision-making

The Service uses software and AI models to analyze documents and generate audit findings. These findings concern the technical compliance of construction documents — they are not used to make automated decisions that produce legal or similarly significant effects about individuals within the meaning of Article 22 of the GDPR. Findings are advisory and remain subject to the independent professional judgment of a licensed architect or engineer, as described in our Terms of Service.

14. Aggregated & de-identified information

We may create aggregated, statistical, or de-identified information (for example, counts of audits run or aggregate error rates) that does not identify you, your organization, or any individual, and that cannot reasonably be re-associated with Customer Content. We may use such information for any lawful business purpose, including operating, analyzing, and improving the Service. We do not attempt to re-identify de-identified information.

15. Children's privacy

The Service is intended solely for use by businesses and their authorized personnel. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

16. Changes to this Policy

We may update this Policy as the Service evolves. Material changes will be reflected by an updated date at the top of this page and, where appropriate or required, we will notify you directly. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

17. Contact

Questions about this Policy, or requests concerning your information, may be directed to our privacy contact at contact@nudgy.ca. This Policy is governed by the laws of Manitoba, Canada.

Questions about this page? Email contact@nudgy.ca.