Effective September 10, 2026 · Last updated September 10, 2026
This Privacy Policy explains how Nathan Cole LLC, trading as Pegasy ("Pegasy", "we", "us"), collects, uses, shares and protects personal information when you visit pegasy.io, create or use a Pegasy account, receive or interact with a proposal created in Pegasy, or contact our support team.
Pegasy is a proposal and closing platform for service businesses. It is intended for professional and business use.
The entity responsible for the personal information described in this policy is:
Nathan Cole LLC
Trading as Pegasy
Website: pegasy.io
Registered address:
Email: support@pegasy.io
This policy applies to the Pegasy marketing website, the Pegasy web application and its APIs, proposals delivered through Pegasy, billing and support, and related services.
It does not apply to third-party websites or services that operate independently and maintain their own privacy policies.
We act as a controller when we process information to create and manage accounts, authenticate users, operate and secure the platform, manage subscriptions, communicate with customers, provide support, prevent fraud and comply with legal obligations.
We act as a processor or service provider when a customer uses Pegasy to manage information about their own companies, contacts, deals, proposals and proposal recipients. In that case the customer is the controller and determines how that information is used.
Customers remain responsible for having a lawful basis for the client and recipient information they enter into Pegasy, and for providing any notices required in their own client relationships.
When you create or manage an account we may collect your name, professional email address, a password hash, an authentication-provider identifier, profile picture, language preference, role and permissions, workspace memberships, onboarding responses, account creation date, sign-in timestamps and account activity.
Passwords are never stored in plain text.
When you create, join or manage a workspace we may collect the workspace and business name, logo, owner, members and their email addresses, roles and permissions, invitations, connected services, usage and quota information, billing plan and workspace configuration.
Workspaces are logically separated so that users can only access workspaces they have been granted access to.
Customers enter information about the businesses and people they work with, including company names and details, contact names, professional email addresses and telephone numbers, roles, notes, deal names, deal stages, values and history.
This information is supplied by the customer and processed on the customer's behalf.
We process the content of proposals and the material used to create them, including proposal titles and structure, sections, services, descriptions, pricing, packages, quantities, options and add-ons, terms, images and brand assets.
We also process the context a customer supplies to build a proposal, including uploaded files, briefs, meeting or call transcripts, notes and content imported from connected sources where that integration is enabled.
This material may contain personal information where the customer includes it.
To deliver a proposal we process information about the recipient designated by the customer, such as name, email address, company, role and the access link or credentials used to open the proposal.
Recipients do not need a Pegasy account to view a proposal that has been shared with them.
Where the feature is implemented we record events relating to a proposal, such as when it was opened, number of visits, time spent, reading progress, sections viewed, options selected, and interactions with the offer.
These are records of observed events. They are indicators and are not guaranteed to be complete or to establish who was physically present at a device.
Where a recipient asks a question, leaves a comment or requests a change, we process the content of that message, its author details and its timestamp so it can be delivered to the seller and kept with the deal.
When a proposal is accepted or signed we record the fact and time of acceptance, the identity information supplied by the signer, the signature itself, the version of the proposal accepted, and supporting technical metadata such as IP address, device and browser information used to evidence the event.
Where online payment is enabled, payment is processed by third-party payment infrastructure, including Stripe. That provider collects payment details directly from the payer under its own privacy policy.
Pegasy generally receives and stores only limited metadata, such as a customer or transaction identifier, amount, currency, status, timestamps and limited payment-method information made available by the provider.
Pegasy does not store raw payment-card numbers or card security codes.
Where a customer enables manual bank transfer, we may record that a transfer has been reported, together with any reference supplied. Such a record does not itself confirm that funds have been received or settled.
Where you connect a third-party service, we process the information necessary to operate that connection, such as the connected account identifier, granted permissions, connection status, stored credentials in encrypted form, and the specific content you choose to import.
We request only the permissions needed for the feature you have enabled, and we use the data obtained only to provide that feature.
We automatically collect limited technical information needed to operate and secure the Service, including IP address, browser and device type, operating system, pages and features accessed, sign-in and session events, request timestamps, API usage, error and diagnostic logs, security and abuse-prevention events, usage limits, and identifiers stored through cookies or similar technologies.
When you contact us we collect your name, email address, company or workspace, the subject and content of your message, any attachments, and technical information relevant to the issue.
We use personal information to:
Pegasy does not sell personal information and does not use personal information for third-party behavioural advertising.
Certain features use artificial-intelligence service providers to help draft or structure proposal content from the context a user supplies.
Depending on the feature, the information sent to a provider may include proposal instructions, business and service descriptions, pricing structure, uploaded briefs or transcripts, and existing proposal text. We limit inputs to what is reasonably necessary for the requested feature.
We do not use Customer Content to train generalised or non-personalised artificial-intelligence models.
AI-generated output may be inaccurate or unsuitable. It is a draft, and the user remains responsible for reviewing and approving it before a proposal is sent.
Where the GDPR, UK GDPR or similar laws apply, we rely on:
You may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.
We do not sell personal information. We disclose it only as follows.
We use providers to operate the Service, including hosting and infrastructure, database and storage, content delivery, transactional email delivery, payment processing and artificial-intelligence processing. Providers act on our instructions and are subject to confidentiality and security obligations.
Payment processing is handled by Stripe where online payment is enabled.
Information may be visible to other authorised members of the same workspace according to their role and permissions. Owners and administrators may access account, deal, proposal, billing and connected-service information for their workspace.
Content a customer publishes in a proposal is disclosed to the recipients that customer designates.
We may disclose information where reasonably necessary to comply with law or legal process, respond to a lawful request, protect the security and integrity of the Service, investigate fraud or abuse, protect the rights and safety of Pegasy, our users or others, or establish, exercise or defend legal claims.
If Nathan Cole LLC is involved in a merger, acquisition, financing, reorganisation or sale of assets, information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
Pegasy and its service providers may process information in countries other than your own, including outside the European Economic Area and the United Kingdom.
Those countries may have data protection laws that differ from those where you live. Where required, we use appropriate safeguards for international transfers, which may include data processing agreements, standard contractual clauses and other recognised transfer mechanisms.
We retain personal information only as long as reasonably necessary to provide the Service, maintain accounts and workspaces, keep the record of a proposal, its acceptance and its payment status, maintain security, comply with tax and accounting obligations, resolve disputes, prevent fraud and enforce our agreements.
When you submit a valid account-deletion request, we aim to delete or anonymise eligible personal information from active systems within a reasonable period, unless continued retention is required for legal compliance, tax or accounting, fraud prevention, security, billing, dispute resolution or legal claims.
Records evidencing acceptance, signature and payment may be retained longer where necessary to establish or defend the transaction they relate to.
Residual copies may remain in secure backups until overwritten in the normal backup cycle. Aggregated or anonymised information that no longer identifies an individual may be retained for longer.
We use administrative, technical and organisational measures designed to protect personal information. Depending on the processing involved these may include encryption in transit, encryption of stored integration credentials, hashed passwords, session protection, role-based permissions, workspace-level access isolation, restricted internal access, secret redaction from logs, rate limiting, abuse-prevention controls, backup and recovery processes, and security monitoring.
No method of storage or transmission is completely secure and we cannot guarantee absolute security. If a security incident affects personal information, we will investigate and provide notifications where required by law.
Depending on your location and applicable law, you may have the right to request access to your personal information, request correction of inaccurate information, request deletion, request restriction of processing, object to certain processing, withdraw consent, receive a portable copy, opt out of any sale or sharing, appeal a decision on a privacy request, and lodge a complaint with a competent data protection authority.
To make a request, contact support@pegasy.io. Please provide enough information for us to identify the account, workspace, proposal or record concerned.
We may request additional information to verify your identity and protect against fraudulent requests. We will not discriminate against you for exercising your rights.
If your information was entered into Pegasy by one of our customers, that customer controls it. We will refer your request to them and support them in responding.
If you are located in the European Economic Area, the United Kingdom or Switzerland, you may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent.
Where we rely on legitimate interests, you may object based on your particular circumstances. You may lodge a complaint with your local data protection authority, though we encourage you to contact us first at support@pegasy.io.
Residents of certain United States states may have rights to know what personal information is collected and how it is used, to access, correct, delete and obtain a portable copy, to opt out of sale, sharing or targeted advertising, to limit use of sensitive personal information, and to appeal a denied request.
Pegasy does not sell personal information and does not share personal information for cross-context behavioural advertising. Where legally required, we honour recognised browser-based opt-out preference signals.
Information about cookies and similar technologies used on pegasy.io is set out in the Pegasy Cookie Policy.
Pegasy is intended only for professional users aged 18 or over. We do not knowingly collect personal information from children. If you believe a person under 18 has provided personal information, contact support@pegasy.io so we can investigate and delete it where appropriate.
Pegasy may link to or integrate with third-party services. Those services operate under their own terms and privacy policies, and we are not responsible for their practices. We encourage you to review them before use.
We may update this Privacy Policy to reflect changes to our features, data practices, service providers, security practices or legal requirements. The "Last updated" date at the top of this page will be revised.
Where a change materially affects how we use personal information, we will provide additional notice and seek renewed consent where required.
For questions, privacy requests, deletion requests or complaints, contact:
Nathan Cole LLC
Trading as Pegasy
Website: pegasy.io
Registered address:
Email: support@pegasy.io
Create a premium proposal your client can review, compare, approve, sign and pay without leaving the experience you built for them.