Pulsus provides the Pulsus Technology Risk Intelligence Platform (the "Platform") to enterprise Customers under an Enterprise Platform Agreement. This Policy should be read together with the Terms of Use. Capitalized terms have the meanings given there.
For personal data contained in Customer Data (including Technology Inventory Data and monthly availability files), the Customer is the data controller and Pulsus acts as a data processor, processing such data only on the Customer's documented instructions (Terms of Use, Section 12.2). For the limited account and usage information described in Section 3, Pulsus acts as a controller.
The Platform does not use advertising trackers, analytics beacons, or third-party marketing cookies. It does not profile Authorized Users, and it does not sell or rent any data to third parties.
Pulsus shall not use Customer Data for any other purpose — including training machine learning models — without the Customer's express written consent (Terms of Use, Section 11.4).
The Platform serves multiple institutions from one codebase. Each tenant's data is stored under its own isolated storage location, sessions are scoped to a single tenant and are not valid across tenants, and no tenant can access another tenant's data through the Platform.
The Platform may verify technology lifecycle dates against public Third-Party Data Sources (for example, published end-of-life databases). These checks send only product and version identifiers — never Customer Data about availability, applications, or organisational performance.
Pulsus uses reputable cloud infrastructure providers to host the Platform and store Customer Data. Such providers act as subprocessors bound by confidentiality and data-protection obligations. Beyond hosting, information is disclosed only where required by applicable law or court order, and the Customer will be notified of any such demand unless legally prohibited.
Customer Data is retained for the duration of the Enterprise Subscription. Upon termination, at the Customer's election, Pulsus will return Customer Data in a standard machine-readable format or securely delete it within thirty (30) days (Terms of Use, Section 12.3).
Information is protected by the measures described in the Security Statement, including encryption in transit, hashed credentials, tenant-scoped signed session cookies, and least-privilege access. No method of transmission or storage is completely secure; suspected incidents should be reported to security@pulsus.tech.
Authorized Users may request access to, correction of, or deletion of personal data held about them. Where Pulsus acts as processor, such requests will be referred to the relevant Customer, and Pulsus will assist the Customer in fulfilling them. Requests may be directed to privacy@pulsus.tech.
Customer Data is stored in the cloud region applicable to the Customer's deployment. Where data is transferred across borders, Pulsus relies on appropriate safeguards consistent with applicable data-protection law.
The Platform is an enterprise service and is not directed at, or intended for use by, children.
Material changes to this Policy will be communicated with not less than thirty (30) days' notice, consistent with the Terms of Use. The "Effective" date above reflects the current version.