Data processing addendum

Terms · Privacy · DPA · Legal noticesLast updated 8 September 2026. This addendum is part of the Pulse terms when you use Pulse to process analytics from your websites.Pulse, operated by Pierre Ousset (the processor, contact hello@getpul.dev), acts as processor for analytics events collected from websites of the customer (the controller). Processing is limited to providing the Pulse service: ingest, aggregation, dashboards, exports, billing of the controller’s Pulse subscription, and optional features the controller enables (including revenue attribution, heatmaps, Web Vitals, identity hashing, short links and team sharing).

Instructions and roles

The controller’s installation of the tracker, configuration in the Pulse dashboard, and optional integrations are the documented instructions. Pulse processes personal data only for those instructions, unless Union or Member State law requires otherwise. The controller is responsible for the lawfulness of collection on its websites, including notices and consent where required. Pulse will inform the controller if an instruction appears to infringe GDPR, unless the law forbids that notice.

Data

Analytics may include page paths, referrer origins, coarse device and browser information, approximate location, UTM fields, event names and properties, and daily visitor hashes. Optional features add click coordinates, Web Vitals, hashed attribution/order IDs, payment amounts, or a stable site-scoped hash from pulse.identify. Raw IP addresses are not stored in analytics tables; transient rate limiting and external geolocation processing are described in the privacy notice.Data subjects are visitors of the controller’s websites and, where optional identity or revenue features are enabled, people whose hashed identifiers or payment amounts the controller sends. Pulse account data (login email, billing) is handled by Pulse as controller under the privacy notice, not under this addendum.

Duration

Processing lasts for the life of the workspace or site, until the controller deletes the site or account, or until Pulse stops providing the service.

Subprocessors

The controller authorises Pulse to use the following subprocessors for the hosted getpul.dev service: Vercel (hosting and edge geolocation headers); Neon or another PostgreSQL provider (database); Resend (transactional email); Whop (Pulse plan billing); Stripe (legacy Pulse billing, and the controller’s revenue events when the controller connects Stripe); ipwho.is (geolocation fallback when platform country data is missing); Slack (digest delivery only if the controller configures it). Connecting another payment webhook is an instruction to receive that provider’s events.Pulse will impose data-protection terms on subprocessors. If a subprocessor is added or replaced in a way that materially changes processing, Pulse will update this addendum or the privacy notice. The controller may object by deleting the workspace if it does not accept a material change.

International transfers

Subprocessors may process data outside the EEA, including in the United States. Pulse relies on each provider’s published transfer mechanism, including Standard Contractual Clauses where offered.

Security

Daily hashing secrets rotate at 00:00 UTC. Site tokens are stored hashed. Attribution identifiers are hashed before insert. TLS in transit. Access to production systems is limited to people operating Pulse. Pulse will notify the controller without undue delay, and at the latest within 72 hours of becoming aware of a personal-data breach affecting the controller’s analytics, with information reasonably available to help the controller meet GDPR Articles 33 and 34.

Assistance

Pulse will assist the controller, taking into account the nature of processing, with data-subject requests that concern analytics Pulse stores, and with DPIA or prior-consultation work that reasonably relates to this service. Pulse does not respond to visitor requests as if it were the controller; it routes them to the controller when the requester can be identified as relating to a customer site.

Retention and deletion

Events are retained for the life of the workspace unless the controller deletes the site or account. Deletion of a site removes events, payments, funnels, and secrets for that site. After deletion, residual backups may persist for a short period until they are overwritten. Pulse will not retain the controller’s analytics for its own purposes after deletion.

Information and audits

Pulse will make available information reasonably necessary to demonstrate compliance with this addendum. Audits are limited to documents and written answers in the first instance, scheduled to avoid disruption, and subject to confidentiality. On-site or intrusive testing is not offered on the shared hosted platform.

Confidentiality

People authorised to process the controller’s analytics are bound to confidentiality.

Law

This addendum is governed by French law, like the terms of use. The privacy notice explains Pulse’s role as controller for account data.