Last updated: 23 June 2025
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and Pulstracker ("Processor", "we", "us", or "our"). This DPA governs our processing of personal data on your behalf if and when you use Pulstracker's web analytics service.
Pulstracker is purposely designed from scratch to minimise data collection, avoid the use of cookies, and comply with the strictest global privacy standards, including GDPR, ePrivacy, and UK Data Protection Act 2018.
1. Definitions
- Data Controller: You, the customer, who determines the purpose and means of personal data processing.
- Data Processor: Pulstracker, which processes data on your behalf under your instructions.
- Personal Data: Any information that relates to an identified or identifiable individual, as defined by the GDPR.
- Processing: Any operation performed on personal data, such as collection, storage, or analysis.
2. Scope and Nature of Processing
- Subject Matter: Use of Pulstracker's analytics platform to monitor website traffic.
- Nature of Processing: Pulstracker collects anonymized or pseudonymised statistical data to help you understand your site's performance.
- Purpose: To provide you with aggregated insights into site usage without tracking individual users.
- Duration: For as long as you maintain an active account or until data deletion is requested.
3. Types of Data Collected
Pulstracker processes only the minimal technical data necessary to provide analytics. This includes:
🔍
User-agent string (anonymized)
🌍
Country (derived from IP, not stored)
📱
Device type (desktop/mobile/tablet)
We do not collect or store:
- IP addresses
- Cookies
- User identifiers
- Personal user profiles
4. Data Storage and Retention
- All data is stored within the EU.
- Data is retained for up to 12 months by default, with configurable retention policies.
- You may delete your data at any time via the dashboard or API.
5. Subprocessors
Pulstracker uses the following subprocessors to operate the service:
Subprocessor | Purpose | Location
Hetzner | Hosting infrastructure | Finland
Mailgun | Transactional emails | EU
We ensure all subprocessors are contractually bound to meet the obligations of this DPA.
6. Security Measures
Pulstracker applies robust technical and organisational security controls, including:
🔐
Encryption in transit (HTTPS)
🛡️
Firewall isolation and rate-limiting
🔑
Multi-factor authentication for internal systems
🔍
Regular security patching and audits
7. Data Subject Rights
As Controller, you are responsible for responding to data subject requests. Pulstracker will assist you, to the extent possible, by:
- Allowing access to and deletion of your analytics data
- Providing evidence of anonymization and non-identifiability of stored information
8. Transfers Outside the EU
Pulstracker stores and processes data only in the EU. If data is ever transferred outside these regions, we rely on:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where applicable
We do not use US-based cloud analytics providers that fall under FISA 702 or similar surveillance laws.
9. Audit Rights
Pulstracker will make available documentation and system details to demonstrate compliance. Upon written request, and subject to confidentiality, you may audit our practices once per year.
10. Breach Notification
In the event of a personal data breach, Pulstracker will:
- Notify you without undue delay (within 72 hours of discovery)
- Provide sufficient information for you to meet your legal obligations
11. Termination and Deletion
Upon termination of your account:
- All stored data is automatically deleted within 7 days.
- You may request an immediate purge via written notice.
12. Contact
If you have questions about this DPA or how Pulstracker processes your data, contact:
This DPA is effective as of the date you begin using Pulstracker and forms an integral part of your agreement with us.