Data Processing Agreement
This agreement governs how Pulsero processes personal data on behalf of estate agency customers under UK GDPR.
This Data Processing Agreement ("DPA") forms part of the Pulsero Terms of Service and applies where Pulsero processes personal data on behalf of the Customer as a Processor under UK GDPR. By accepting the Terms of Service at sign-up, the Customer agrees to the terms of this DPA.
1. Roles
Data Controller: The estate agency or business entity that has registered for a Pulsero account ("Customer").
Data Processor: Pulsero Ltd, which processes personal data solely on documented instructions from the Customer as set out in this DPA and the Terms of Service.
Data Subjects: Individuals whose personal data is contained within inbound communications forwarded to Pulsero by the Customer.
2. Nature and purpose of processing
Pulsero processes personal data solely to provide the services described in the Terms of Service. Pulsero will not process personal data for any other purpose without prior written instruction from the Customer.
Categories of personal data processed: Names, email addresses, phone numbers, property addresses, and free-text content as submitted by data subjects to the Customer and forwarded to Pulsero.
Special category data: Pulsero does not intentionally process special category data. Customers must not forward communications containing special category data.
3. Sub-processors
Pulsero engages the following sub-processors to deliver the service:
| Sub-processor | Service | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, storage | European Union |
| Vercel Inc. | Hosting, CDN, serverless infrastructure | Global edge (EU primary) |
| Resend Inc. | Transactional email | United States |
| Anthropic PBC | Service delivery | United States |
| OpenAI LLC | Service delivery | United States |
Pulsero will provide at least 14 days' notice of any intended changes to its sub-processor list. Customers may object in writing within that period on reasonable data protection grounds.
4. International transfers
Personal data may be transferred outside the UK to sub-processors in the United States. Transfer mechanisms in each case are UK IDTA or equivalent Standard Contractual Clauses as incorporated in the relevant sub-processor's DPA. Links to sub-processor DPAs are available on request.
5. Security measures
Pulsero implements the following technical and organisational measures: encryption in transit (TLS 1.3) and at rest; HTTP Strict Transport Security; Content Security Policy; Row Level Security on all database tables; tenant data isolation with no cross-tenant data access; passwords hashed via Supabase Auth; production access limited to authorised personnel; and regular dependency and security updates.
6. Processor obligations
Pulsero will process personal data only on documented instructions from the Customer; ensure authorised personnel are bound by confidentiality obligations; assist the Customer in responding to data subject rights requests to the extent reasonably practicable; notify the Customer without undue delay upon becoming aware of a personal data breach; make available all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR; and not engage additional sub-processors without notifying the Customer.
7. Breach notification
In the event of a personal data breach affecting Customer data, Pulsero will notify the Customer without undue delay and within 72 hours where feasible, provide a description of the breach including categories and approximate volume of data affected, and cooperate with the Customer in any required notification to the ICO or affected data subjects.
8. Data subject rights
Where Pulsero receives a data subject request directly, it will promptly forward it to the Customer. The Customer remains responsible for responding to data subject rights requests. Pulsero will provide reasonable technical assistance upon request.
9. Audit rights
The Customer may request information to demonstrate Pulsero's compliance with this DPA. Pulsero will make available all necessary information and, upon reasonable notice, cooperate with audits conducted by the Customer or a mandated third party, subject to confidentiality obligations.
10. Data deletion and return
Upon termination of the Customer's account, Pulsero will delete all Customer personal data within 30 days unless retention is required by law. The Customer may request deletion at any time via written notice to legal@pulsero.io.
11. Duration and hierarchy
This DPA applies for the duration of any processing of personal data by Pulsero under the Terms of Service. In the event of conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters.
12. Contact
Data protection enquiries: legal@pulsero.io
Pulsero Ltd, Suite A, 82 James Carter Road, Mildenhall, IP28 7DE, registered in England and Wales (Company No. 17369221)
Supervisory authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF