[ SECURITY & COMPLIANCE / NURTUREHUB ]
UK property contacts are third-party individuals — your tenants, vendors, landlords. NurtureHub is designed so that every email sent, every score computed, and every CRM sync performed respects their rights and your obligations.
Email our security teamConsent tracking, suppression lists, one-click unsubscribe in every email, DSAR export, and right-to-erasure — built into the platform, not bolted on.
CRM connection credentials and OAuth tokens are stored encrypted. No integration secret is ever readable in plaintext from the application layer.
No email leaves your agency without agent approval. AI generates; your team reviews and approves. The send queue only runs after you say so.
The Compliance Guardian agent queries consent status, marketing opt-in, suppression list, and unsubscribe history in sequence. A single failure blocks the send.
Send events, opens, and clicks are written to the engagement store the instant they occur. No data is held in transit — events are attributed to the contact record in real time.
Compliance decisions, CRM sync events, consent changes, and sequence approvals all write to immutable audit logs. Exportable on demand for regulatory review.
[ DATA / UK GDPR ]
The Compliance Guardian agent runs before every single email send. It checks GDPR consent status, validates marketing opt-in for the specific channel, confirms the contact hasn't unsubscribed, and cross-references the suppression list. If any check fails, the send is blocked automatically and your agent is told exactly why.
Pre-send consent verification on every email, every time
PECR-compliant one-click unsubscribe in every email footer
ICO-compliant privacy notice links in all outbound emails
[ AUTH / ACCESS CONTROL ]
Multi-branch agencies, individual negotiators, and org-level admins each operate within scoped boundaries. Data from one branch never bleeds into another's view.

[ AUDIT / TRACEABILITY ]
The contact timeline combines every touchpoint — sequences started, emails sent, opens, clicks, notes added, CRM sync events, consent changes, and compliance decisions — in one auditable chronology. If a regulator asks, you can show exactly what happened and when.
[ INTEGRATIONS / DATA HANDLING ]
NurtureHub connects to external services to deliver its features. We document those connections, what data flows through them, and how.
A publicly accessible register at /legal/sub-processors lists every third-party service that receives personal data, their purpose, and their data location — as required under UK GDPR Article 28.
agentOS, Reapit, Alto, Street, and Loop connection credentials are stored as encrypted JSON. Connection health is monitored continuously; three consecutive failures alert the org owner.
[ KNOWN CONTROLS / PLATFORM STATUS ]
Security is a process, not a feature flag. The controls below are implemented and active. Where gaps exist, we name them and state the remediation path — no security page should pretend a product is perfect.
Inbound webhooks from Resend, agentOS, and SMS providers validate signing secrets. Production deployments are required to configure secrets — requests without a valid signature are rejected.
All background jobs run through Inngest with configurable retry policies and exponential backoff. Transient provider failures do not result in silent data loss.
[ ANALYTICS / DATA ACCESS ]
Open rates, click trends, intent scores, and attributed outcomes are stored against your organisation and never shared across tenants. Analytics data is exportable to CSV at any time. The ROI attribution dashboard shows only your agency's data, scoped to your org.
All analytics scoped to your organisation — no cross-tenant reads
CSV export of all metrics available from the analytics dashboard
Intent score history and engagement events exportable per contact
DSAR endpoint compiles full contact data export on demand
[ FAQ / SECURITY & PRIVACY ]
[ QUESTIONS / GET IN TOUCH ]
If you have a compliance requirement or security question that isn't addressed here, email sf-core-org-support-nurturehub@saas-factory.ai and we'll respond with specifics — not a generic privacy policy link.
Right-to-erasure: contact data anonymised, future sends suppressed
Full compliance audit log for every send decision

Every contact, sequence, brand profile, and API call is scoped to your organisation. No cross-tenant data access is possible at the API layer.
Branch admin, network admin, and team member roles with distinct permission surfaces. Org owners control who can approve sequences, view analytics, or manage integrations.
Each branch operates with its own brand voice, contacts, and sequences. Parent admins see cross-branch reporting; branch users see only their own office.
Consent audit trail per contact: when and how consent was recorded
CRM sync log: last 100 events with error details and manual retry
Suppression list: bounce, complaint, and unsubscribe entries all retained
Sequence edit history: every AI regeneration and manual edit preserved
Agents can connect their Google Workspace or Microsoft 365 account so nurture emails arrive from a verified address they own — not a shared platform domain. OAuth tokens are encrypted and auto-refreshed.
Deployment configuration specifies UK/EU regions for document storage. Sub-processor documentation records the data location and legal basis for each processor, including international transfer mechanisms.
Three consecutive CRM sync failures trigger an automatic notification to the org owner. Sync health indicators are visible at all times in the integrations dashboard.
Platform admins have a dedicated oversight panel showing AI generation volume, email delivery metrics, CRM sync health across all orgs, and flagged GDPR requests pending processing.

[ JOIN THE WAITLIST ]