NurtureHub
BlogFAQFeaturesHow it worksIntegrationsPricingSecurityUse cases
Join the waitlist
NurtureHubJoin the waitlist
NurtureHub
HomeBlogFAQFeaturesHow it worksIntegrationsPricingSecurityUse cases
Join the waitlist
NurtureHub
BlogFAQFeaturesHow it worksIntegrationsPricingSecurityUse cases
TermsPrivacyData Processing

© 2026 NurtureHub

[ SECURITY & COMPLIANCE / NURTUREHUB ]

Built for agents who handle real people's data

UK property contacts are third-party individuals — your tenants, vendors, landlords. NurtureHub is designed so that every email sent, every score computed, and every CRM sync performed respects their rights and your obligations.

Email our security team

UK GDPR-aligned by design

Consent tracking, suppression lists, one-click unsubscribe in every email, DSAR export, and right-to-erasure — built into the platform, not bolted on.

Encrypted credentials at rest

CRM connection credentials and OAuth tokens are stored encrypted. No integration secret is ever readable in plaintext from the application layer.

Human in the loop — always

No email leaves your agency without agent approval. AI generates; your team reviews and approves. The send queue only runs after you say so.

COMPLIANCE_GUARDIANPre-send consent check passed — contact opted in via web form0.1s
CRM_SYNCagentOS bidirectional sync completed — 12 contacts updated0.4s
SUPPRESSION_LISTUnsubscribe recorded — future sends suppressed and audit log written0.2s
OAUTH_ADAPTERGoogle Workspace token refreshed — encrypted and stored0.3s
COMPLIANCE_GUARDIANSend blocked — no marketing consent on file for SMS channel0.1s
DSAR_ENGINEData subject export generated — all contact records compiled0.6s
CRM_MONITORSync health check — all 3 connected CRMs reporting green0.2s
COMPLIANCE_GUARDIANPre-send consent check passed — contact opted in via web form0.1s
CRM_SYNCagentOS bidirectional sync completed — 12 contacts updated0.4s
SUPPRESSION_LISTUnsubscribe recorded — future sends suppressed and audit log written0.2s
OAUTH_ADAPTERGoogle Workspace token refreshed — encrypted and stored0.3s
COMPLIANCE_GUARDIANSend blocked — no marketing consent on file for SMS channel0.1s
DSAR_ENGINEData subject export generated — all contact records compiled0.6s
CRM_MONITORSync health check — all 3 connected CRMs reporting green0.2s
COMPLIANCE_GUARDIANPre-send consent check passed — contact opted in via web form0.1s
CRM_SYNCagentOS bidirectional sync completed — 12 contacts updated0.4s
SUPPRESSION_LISTUnsubscribe recorded — future sends suppressed and audit log written0.2s
OAUTH_ADAPTERGoogle Workspace token refreshed — encrypted and stored0.3s
COMPLIANCE_GUARDIANSend blocked — no marketing consent on file for SMS channel0.1s
DSAR_ENGINEData subject export generated — all contact records compiled0.6s
CRM_MONITORSync health check — all 3 connected CRMs reporting green0.2s
COMPLIANCE_GUARDIANPre-send consent check passed — contact opted in via web form0.1s
CRM_SYNCagentOS bidirectional sync completed — 12 contacts updated0.4s
SUPPRESSION_LISTUnsubscribe recorded — future sends suppressed and audit log written0.2s
OAUTH_ADAPTERGoogle Workspace token refreshed — encrypted and stored0.3s
COMPLIANCE_GUARDIANSend blocked — no marketing consent on file for SMS channel0.1s
DSAR_ENGINEData subject export generated — all contact records compiled0.6s
CRM_MONITORSync health check — all 3 connected CRMs reporting green0.2s
  1. STEP 01 — CONSENT CHECK

    Before any email, consent is verified

    The Compliance Guardian agent queries consent status, marketing opt-in, suppression list, and unsubscribe history in sequence. A single failure blocks the send.

  2. STEP 02 — DELIVERY & TRACKING

    Emails sent from your domain, events stored immediately

    Send events, opens, and clicks are written to the engagement store the instant they occur. No data is held in transit — events are attributed to the contact record in real time.

  3. STEP 03 — AUDIT TRAIL

    Every decision is logged with reason and timestamp

    Compliance decisions, CRM sync events, consent changes, and sequence approvals all write to immutable audit logs. Exportable on demand for regulatory review.

console
0.0scompliance_guardian: checking consent for contact #4821
0.1s→ gdpr_consent: verified | marketing_optin: true | suppression: clear
0.2ssend_authorised: true
0.0semail_dispatcher: routing via google_workspace adapter
0.3sdelivered: message_id=msg_9f3a | sent_folder: updated
1.2sopen_event: recorded | intent_scorer: +5pts applied
0.0saudit_log: writing compliance decision — send_authorised
0.1saudit_log: writing engagement event — email_opened
0.2scontact_timeline: 4 events appended | dsar_ready: true

[ DATA / UK GDPR ]

GDPR compliance isn't a checkbox — it's the default path

The Compliance Guardian agent runs before every single email send. It checks GDPR consent status, validates marketing opt-in for the specific channel, confirms the contact hasn't unsubscribed, and cross-references the suppression list. If any check fails, the send is blocked automatically and your agent is told exactly why.

  • Pre-send consent verification on every email, every time

  • PECR-compliant one-click unsubscribe in every email footer

  • ICO-compliant privacy notice links in all outbound emails

[ AUTH / ACCESS CONTROL ]

Access control that matches how agencies actually work

Multi-branch agencies, individual negotiators, and org-level admins each operate within scoped boundaries. Data from one branch never bleeds into another's view.

NurtureHub activity timeline showing CRM sync events and compliance audit trail

[ AUDIT / TRACEABILITY ]

Every action is logged. Nothing is ambiguous.

The contact timeline combines every touchpoint — sequences started, emails sent, opens, clicks, notes added, CRM sync events, consent changes, and compliance decisions — in one auditable chronology. If a regulator asks, you can show exactly what happened and when.

[ INTEGRATIONS / DATA HANDLING ]

Third-party data flows, documented and controlled

NurtureHub connects to external services to deliver its features. We document those connections, what data flows through them, and how.

Sub-processor register

A publicly accessible register at /legal/sub-processors lists every third-party service that receives personal data, their purpose, and their data location — as required under UK GDPR Article 28.

CRM credentials encrypted at rest

agentOS, Reapit, Alto, Street, and Loop connection credentials are stored as encrypted JSON. Connection health is monitored continuously; three consecutive failures alert the org owner.

[ KNOWN CONTROLS / PLATFORM STATUS ]

What we've built, and what we're transparent about

Security is a process, not a feature flag. The controls below are implemented and active. Where gaps exist, we name them and state the remediation path — no security page should pretend a product is perfect.

Webhook signature verification

Inbound webhooks from Resend, agentOS, and SMS providers validate signing secrets. Production deployments are required to configure secrets — requests without a valid signature are rejected.

Retry logic with backoff

All background jobs run through Inngest with configurable retry policies and exponential backoff. Transient provider failures do not result in silent data loss.

[ ANALYTICS / DATA ACCESS ]

Your engagement data stays yours

Open rates, click trends, intent scores, and attributed outcomes are stored against your organisation and never shared across tenants. Analytics data is exportable to CSV at any time. The ROI attribution dashboard shows only your agency's data, scoped to your org.

  • All analytics scoped to your organisation — no cross-tenant reads

  • CSV export of all metrics available from the analytics dashboard

  • Intent score history and engagement events exportable per contact

  • DSAR endpoint compiles full contact data export on demand

[ FAQ / SECURITY & PRIVACY ]

Common questions from compliance-minded agents

[ QUESTIONS / GET IN TOUCH ]

Security questions deserve direct answers

If you have a compliance requirement or security question that isn't addressed here, email sf-core-org-support-nurturehub@saas-factory.ai and we'll respond with specifics — not a generic privacy policy link.

Email the security team
Data Subject Access Request (DSAR) export endpoint
  • Right-to-erasure: contact data anonymised, future sends suppressed

  • Full compliance audit log for every send decision

  • NurtureHub alerts dashboard showing intent score alerts and compliance status

    Org-scoped data isolation

    Every contact, sequence, brand profile, and API call is scoped to your organisation. No cross-tenant data access is possible at the API layer.

    Role-based access

    Branch admin, network admin, and team member roles with distinct permission surfaces. Org owners control who can approve sequences, view analytics, or manage integrations.

    Multi-branch isolation

    Each branch operates with its own brand voice, contacts, and sequences. Parent admins see cross-branch reporting; branch users see only their own office.

    Consent audit trail per contact: when and how consent was recorded

  • CRM sync log: last 100 events with error details and manual retry

  • Suppression list: bounce, complaint, and unsubscribe entries all retained

  • Sequence edit history: every AI regeneration and manual edit preserved

  • Email delivery from your own domain

    Agents can connect their Google Workspace or Microsoft 365 account so nurture emails arrive from a verified address they own — not a shared platform domain. OAuth tokens are encrypted and auto-refreshed.

    UK data residency awareness

    Deployment configuration specifies UK/EU regions for document storage. Sub-processor documentation records the data location and legal basis for each processor, including international transfer mechanisms.

    CRM sync failure alerts

    Three consecutive CRM sync failures trigger an automatic notification to the org owner. Sync health indicators are visible at all times in the integrations dashboard.

    Admin platform oversight

    Platform admins have a dedicated oversight panel showing AI generation volume, email delivery metrics, CRM sync health across all orgs, and flagged GDPR requests pending processing.

    NurtureHub analytics dashboard showing email performance and engagement trends
    A human always approves before anything goes out. When you assign a contact to one of the 12 lead categories, NurtureHub's AI generates a personalised 3-email sequence and places it in a review queue. You read each email in a rendered preview, edit inline if you want, and approve — either email by email or the whole sequence at once. Only after you click approve does the send queue pick it up. No email leaves your agency without a person signing off on it.
    No prompt-writing required. During setup, you submit your agency website URL and NurtureHub crawls your homepage, about page, services, team, and area pages, then extracts your tone, service descriptions, local market context, and team profiles automatically. You can supplement that with uploaded PDFs or Word documents — brochures, service guides, team bios. The AI builds a structured brand profile from all of it, you review and edit it in a section-by-section UI, and once you approve it, every email generated from that point forward inherits your voice. You can re-run the crawl any time your website changes.
    NurtureHub has a native connector for agentOS with bidirectional real-time sync, plus connectors for Reapit, Alto, Street, and Loop via their respective APIs. Each integration polls for changes every 4 hours via a scheduled background job, and agentOS also supports real-time webhook push for instant updates. Contacts imported from any CRM retain their external ID so changes stay in step. You can also trigger an on-demand sync manually from the integrations page. The integrations dashboard shows sync health (green/amber/red), last sync timestamp, recent errors, and a retry option — and the agency owner gets an alert if a sync fails three times running.
    Every engagement event a contact has with your emails feeds a rolling 0–100 intent score: an open adds 5 points, a link click adds 15, clicking a booking link adds 30, and a reply adds 25. Scores are multiplied by a category weight — Active Sellers score 1.5x, Sellers 1.3x, Buy-to-Let Investors 1.2x — so the system prioritises the contact types most likely to convert for you. Scores decay over time for inactive contacts. When a contact crosses your configured hot threshold (default 85), your assigned agent gets an immediate in-app notification and an email alert with the contact's name, category, score breakdown, and a direct link to their profile. You set the thresholds yourself, and a score simulator lets you model how a hypothetical engagement sequence would score before you change any settings.
    Before every email send, a Compliance Guardian agent checks GDPR consent status, validates marketing opt-ins for the specific channel, cross-references suppression lists, and confirms the contact hasn't unsubscribed. If any check fails, the send is blocked and you're told exactly why. Every send decision is written to a compliance audit log. Every email includes a one-click unsubscribe link; unsubscribes are stored in a suppression list and sequences pause automatically. Contacts can also request erasure, which anonymises their data and suppresses future contact. Consent records show when and how consent was obtained, and the full audit trail is visible on each contact's profile. For questions about Data Processing Agreements with the underlying services NurtureHub uses, details are available on request.
    Each branch runs as its own sub-organisation with its own brand profile, agent personas, contact database, and journey configuration. Emails from your Kensington office carry Kensington's voice; emails from Chelsea carry Chelsea's. Billing sits under a single Agency Pro subscription, and a parent-level admin account gives you cross-branch analytics and shared template management in one view. Branch admins manage their own office; the network admin sees everything. Cross-branch contact deduplication runs automatically so the same individual doesn't get contacted by two offices simultaneously.
    View sub-processor register

    [ JOIN THE WAITLIST ]

    Be first to go live when NurtureHub opens