Privacy Policy
This policy explains what personal data PulseWatch collects, why, how long we keep it, and the rights you have over it. PulseWatch is operated by Paulo Jardim, based in Ireland ("we", "us"). For anything in this policy, contact us at [email protected].
1. Who this applies to
This policy covers:
- Visitors to pulsewatchai.com
- People who request a hosted trial or create an account ("Customers")
- Individual users within a Customer's workspace (added by a Customer's own administrator)
If you self-host PulseWatch on your own infrastructure, this policy does not apply to data processed by your own instance — you are the controller of that data, and your own privacy practices govern it, not ours.
2. What we collect, and why
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, company name (trial signup) | Create and activate your workspace, contact you about your trial | Steps to enter a contract / contract performance |
| Account email, display name, hashed password | Authenticate you and let you use the product | Contract performance |
| Audit logs (who did what, when, IP address) | Security, abuse prevention, and troubleshooting access issues | Legitimate interest (securing the service) |
| Notification recipient email addresses you configure | Send the alerts you've asked us to send, to whoever you designate | Contract performance (processed on your instructions — see Section 6) |
| Infrastructure monitoring data (server names, service status, logs your agents report) | Provide the monitoring/incident/self-healing functionality itself | Contract performance (processed on your instructions — see Section 6) |
We do not use cookies or scripts for advertising or cross-site tracking, and the marketing site has no analytics tracking installed as of the date above.
3. How long we keep it
Monitoring/operational data is purged automatically on a schedule:
- Raw heartbeats and their logs/snapshots: 30 days (unless still referenced by an open incident)
- Audit logs: 180 days
- Remote command history: 90 days
- Self-healing execution history: 90 days
- Resolved incidents: 2 years
Account and workspace data (your login, workspace settings) is kept for as long as your account is active, plus a reasonable period after cancellation in case you want to reactivate, then deleted. You can request deletion at any time — see Section 7.
4. Who we share it with
We use a small number of processors to run the service. We don't sell data, ever.
| Processor | What for | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting and database storage | Germany (EU) |
| Resend | Sending transactional emails (activation, password reset, alerts) | United States |
| Cloudflare, Inc. | DNS, content delivery, secure tunnel to our servers | United States (global network) |
Where a processor is located outside the European Economic Area, we rely on that provider's Standard Contractual Clauses and/or their certification under the EU-U.S. Data Privacy Framework as the transfer safeguard. We review this list periodically and will update it here if it changes.
5. Your rights
Under GDPR, you can ask us to:
- Access the personal data we hold about you
- Correct it if it's inaccurate
- Delete it ("right to be forgotten")
- Export it in a portable format
- Object to or restrict certain processing
To exercise any of these, email [email protected]. We currently handle these requests manually and aim to respond within 30 days, as required by GDPR. If you're an individual user inside a company's workspace (not the workspace owner), some requests may need to go through your workspace administrator, since they control that workspace's data.
You also have the right to lodge a complaint with a supervisory authority. In Ireland, that's the Data Protection Commission.
6. If you're a Customer, using PulseWatch to monitor your own systems
For the monitoring data your own agents send us (server names, service status, log excerpts, incident history), we act as a processor on your behalf — you remain the controller of that data, including any personal data your own logs might incidentally contain (e.g. if your application logs happen to include user identifiers). We only process it to provide the service to you, following your configuration and instructions. A Data Processing Agreement covering this relationship is available on request — email [email protected].
7. Security
We use industry-standard measures appropriate to the risk: encrypted connections (HTTPS) for the hosted service, hashed (never plaintext) passwords, tenant data isolation between customer workspaces, role-based access control, and a network-isolated internal admin tool with no public exposure. No system is perfectly secure, but we take this seriously and actively audit for vulnerabilities.
8. Changes to this policy
We'll update this page if what we collect or how we use it changes, and update the "Last updated" date above. For material changes, we'll email active account holders.
9. Contact
Questions about this policy or your data: [email protected].