privacy policy.
this policy explains how pulse collects, uses and protects personal data. we keep it plain - no fog. lowercase, like everything else we do.
01who we are
pulse is a customer-engagement platform operated by pulse technologies. brands use pulse to run prize-draw campaigns and build first-party customer profiles. this policy explains what we do with personal data - both the data of the brands who use pulse, and the data their customers share when entering a campaign.
02the data we handle
we handle two kinds of personal data:
- account data - names, work emails, and login details of the people at a brand who use pulse.
- campaign data - the information a brand's customers choose to share when they enter a campaign: contact details, answers to questions, referral activity and status.
for campaign data, the brand running the campaign is the data controller and pulse is the processor acting on its instructions.
03how we use it
we use account data to provide, secure and support the platform. we process campaign data only to deliver the service to the brand - storing entries, scoring answers, building profiles and producing reports. we do not sell personal data, and we do not use campaign data to build our own marketing lists.
04legal bases
where GDPR applies, we rely on legitimate interests to run and improve the platform, contract to provide the service, and consent where a customer opts in to a campaign. customers can withdraw consent at any time.
05sharing & sub-processors
we share data only with vetted sub-processors that help us run the platform (for example, cloud hosting and email delivery), each under contract. we may disclose data where required by law. a current list of sub-processors is available on request.
06retention
we keep account data for as long as an account is active. campaign data is retained on behalf of the brand and deleted on the brand's instruction or when their agreement ends, subject to any legal retention requirements.
if you contact us through this website, we keep your enquiry and the details you provide for 24 months from our last correspondence, so we can follow up and keep a record of what was discussed. after that we delete it, unless you have become a customer - in which case the account retention above applies.
07security
each brand's data is isolated at the database level, access is role-based and permissioned, and privileged actions are written to an immutable audit log. customer sign-in is passwordless.
08your rights
depending on where you live, you may have the right to access, correct, export or erase your personal data, and to object to or restrict its processing. brand customers should contact the brand they entered a campaign with; we will support that brand in honouring the request. you can also contact us directly.
09international transfers
where data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses.
10changes
we may update this policy from time to time. material changes will be posted here with an updated date.
questions about privacy, or want to make a data request? get in touch and we will respond within a reasonable time. for campaign data, please also contact the brand whose campaign you entered.