Privacy Policy
This Privacy Policy explains how Nervespan Ltd ("nervespan", "we", "us") collects, uses, and protects personal data when you use our technology strategy platform and website.
1. Who we are
Nervespan Ltd is a company registered in England & Wales (company number 17059178), registered address: Grosvenor House, 11 St. Pauls Square, Birmingham, England, B3 1RB.
For account, billing, and marketing data we act as a data controller. For the technology-strategy content you and your colleagues create inside a workspace, we act as a data processor on your organisation's behalf. We have not appointed a statutory Data Protection Officer; data-protection queries are handled by our team at [email protected].
2. What data we collect
- Account data: name, email address, organisation, authentication identifiers.
- Workspace content: the technology strategy data you create (components, technologies, risks, initiatives, decisions, metrics, documents you upload).
- Billing data: subscription tier and billing identifiers. Payments are processed by our payment provider, Polar; card details are handled by Polar and are never stored on nervespan's systems.
- Usage & technical data: log data, IP address, browser/device information, and product-usage events.
3. How we use it & legal basis
- To provide and operate the service — legal basis: performance of a contract.
- To process AI features you invoke — see our Security & Sub-processors page for where inference runs.
- To handle billing and subscriptions — legal basis: performance of a contract.
- To send you service and administrative messages about your account — legal basis: performance of a contract. Where we send marketing or product-update emails, we do so only with your consent, which you can withdraw at any time.
- To secure the service and prevent abuse — legal basis: legitimate interest.
4. Where your data is stored
Workspace data is stored in the European Union (Supabase, AWS eu-west-1, Ireland), and AI inference runs on Scaleway in the EU. Full details, our sub-processor list, and how we handle US-incorporated vendors are on the Security & Sub-processors page.
5. International transfers
Where personal data is processed by a sub-processor whose parent company is incorporated outside the EU/UK, that processing is governed by the provider's Data Processing Agreement, which incorporates appropriate transfer safeguards — the EU–US Data Privacy Framework where the provider is certified, and Standard Contractual Clauses (with the UK International Data Transfer Addendum for UK-protected data) as the fallback mechanism. The per-provider position is set out on our Security & Sub-processors page.
6. How long we keep it
- Workspace and account data: retained for the life of your account and deleted within 30 days of account closure.
- Backups: rolling backups are purged within 35 days, so deleted data is removed from backups within that window.
- Logs (access, edge, and error logs): retained for up to 90 days for security and diagnostic purposes, then deleted.
7. Your rights
Under UK GDPR / EU GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. To exercise any of these, contact us at [email protected]. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.
If you have a complaint about how we handle your personal data, please contact us first at [email protected]. We will acknowledge your complaint within 30 days and aim to resolve it as quickly as possible. You can escalate to the ICO at any time if you are not satisfied with our response.
8. Cookies
We keep cookies and local storage to a minimum:
- Authentication (essential): Supabase sets a first-party session cookie/token (e.g.
sb-<project>-auth-token) so you stay signed in. Strictly necessary for the service to function. - Preferences (essential): a first-party
theme-modevalue in local storage remembers your light/dark choice. - Bot protection (essential): Cloudflare Turnstile may set a short-lived token when verifying that a request is human.
- Analytics (non-essential): we use Microsoft Clarity to understand how visitors use the site. This is the only non-essential/tracking technology we deploy; no personal data is sold or shared.
The essential cookies above do not require consent under PECR/GDPR because they are strictly necessary to provide a service you have requested.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via the service or by email.
10. Contact
Questions about this policy: [email protected].