Legal
Privacy Policy
Nelia is a sentiment-analytics platform for game studios, operated by Aegis Bridge Ltd, a company registered in England and Wales under company number 16436462, with registered office at 1 The Sheepcote Lumber Lane, Lugwardine, Hereford, England, HR1 4AG ("Nelia", "we", "us"). We are the data controller for the personal data described in this policy, except where the "Player and community data" section below says otherwise.
This policy explains what personal data we collect when you visit nelia.uk, enquire about or use our services, and how we use, share and protect it. It should be read together with our Cookie Policy and, if you are a client, the Nelia Terms of Service and Data Processing Agreement.
Contact: office@nelia.uk · Complaints: see "Your rights and complaints" below.
1. The personal data we collect
Information you give us. Name, business email address, company and role, and the content of your messages when you contact us, request a demo, subscribe to updates, or register for an account. If you become a client, we also process billing contact details and account administration data.
Information collected automatically. When you visit our site we collect technical data such as IP address, browser type and version, device and operating system, pages visited, referral source and interaction data. Our website currently sets no cookies and uses no similar tracking technologies, and any visitor statistics are collected without identifying you — see our Cookie Policy. If that ever changes, we will update these policies and ask for your consent before any non-essential technology is used.
Information from third parties. Business contact information from publicly available professional sources or event organisers, where we have a legitimate interest in contacting you about Nelia.
We do not intentionally collect special category data through our website, and this site is not directed at children.
2. Player and community data — an important distinction
Nelia's platform analyses player and community feedback (for example from Steam, Discord, Reddit or X) on behalf of our game-studio clients. For that data:
- The studio is the data controller and Nelia is a data processor, acting on the studio's instructions under a Data Processing Agreement that meets the requirements of Article 28 UK/EU GDPR.
- If you are a player or community member and want to exercise your data protection rights over feedback you have posted about a game, the studio that operates that game is the right first point of contact. If you contact us instead, we will refer your request to the relevant studio and notify them, as our DPA requires.
- We do not sell player data, we do not use identifiable player data to train our general models, and we apply pseudonymisation and data minimisation to identifiers where reasonably practicable.
The rest of this policy concerns the data for which we are the controller: website visitors, prospects, and our clients' own account users.
3. How we use your data and our lawful bases
| Purpose | Data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Responding to enquiries and demo requests | Contact details, message content | Legitimate interests (responding to you) |
| Providing and administering client accounts | Account and billing contact data | Contract (Art. 6(1)(b)) |
| Sending service notices (renewal, security, changes) | Account contact data | Contract / legal obligation |
| Marketing our services to business contacts | Business contact details | Legitimate interests, with an opt-out in every message; consent where required by PECR |
| Website analytics and improvement | Aggregated, cookieless technical data | Legitimate interests (no cookies or identifiers used); consent will be sought before any non-essential technology is introduced |
| Security, fraud prevention, enforcing our terms | Technical and account data | Legitimate interests / legal obligation |
| Complying with law (tax, accounting, legal claims) | Billing and correspondence records | Legal obligation / legitimate interests |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.
4. Who we share data with
- Service providers (processors): hosting and cloud infrastructure, email and CRM tooling, payment processing and analytics providers, in each case under contracts that restrict their use of your data to providing services to us.
- Professional advisers and authorities where required by law or to establish, exercise or defend legal claims.
- A buyer or successor in the event of a merger, acquisition or asset sale, subject to this policy.
We do not sell or rent personal data, and we do not permit advertisers to use it.
5. International transfers
We are based in the UK. Where our service providers process personal data outside the UK or EEA in a country without adequacy regulations, we put in place an appropriate transfer mechanism — the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses — together with any supplementary measures required. Details of the mechanism used for any specific transfer are available on request.
6. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls and least-privilege administration, logging and monitoring, and staff confidentiality obligations. No system is perfectly secure; if a breach affecting your personal data occurs, we will act in accordance with our legal obligations, including notifying you and the ICO where required.
7. Retention
We keep personal data only as long as needed for the purposes above: enquiry correspondence for 24 months after last contact; client account and billing records for the contract term plus 6 years (legal and tax requirements); marketing contact data until you opt out or 24 months of inactivity; aggregated website statistics, which do not identify you, per our Cookie Policy. We then delete or irreversibly anonymise it.
8. Your rights and complaints
Under the UK GDPR you have the right to access your personal data, to rectification, erasure, and restriction, to object (including to direct marketing, which we will always honour), to data portability where applicable, and to withdraw consent at any time where consent is our basis.
To exercise any right, email office@nelia.uk. We will respond within one month. We maintain a complaints procedure in line with the Data (Use and Access) Act 2025: if you are unhappy with how we have handled your data, tell us and we will acknowledge your complaint within 30 days and respond substantively without undue delay. You also have the right to complain to the Information Commissioner's Office (ico.org.uk / 0303 123 1113) at any time.
9. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page with a revised date and, for material changes, give reasonable notice by email to account holders or by prominent notice on our site before the change takes effect.
Aegis Bridge Ltd · Company no. 16436462 · Registered in England and Wales · 1 The Sheepcote Lumber Lane, Lugwardine, Hereford, England, HR1 4AG · office@nelia.uk