This policy explains how [Company legal name] (“PulseIQ”, “we”, “us”) handles personal data when you visit our website, contact us, or use the PulseIQ platform — and how you can exercise your rights under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made under it.
1. Who we are
PulseIQ is operated by [Company legal name], a company incorporated in India (CIN [CIN]), with its registered office at [Registered address].
For anything in this policy, write to [Privacy email] or to our Grievance Officer (section 12).
2. Our role, depending on whose data it is
We handle three kinds of personal data, and our responsibilities differ for each:
- Website visitors and people who contact us. We decide why and how this data is used, so we are the Data Fiduciary and this policy applies in full.
- Users of the platform (staff of our customers who sign in to a workspace). We are the Data Fiduciary for account and usage data needed to run and secure the service.
- Our customers’ own customers — the shoppers, guests or retailers whose phone numbers and purchase records a brand loads into PulseIQ to segment and message them. Here the brand is the Data Fiduciary and we are its Data Processor: we process that data only on the brand’s instructions, under a written agreement. If you received a message from a brand that uses PulseIQ, please contact that brand to exercise your rights; we will help them respond.
3. What we collect
When you visit the website
- Technical data our servers log automatically: IP address, browser and device type, pages requested and time of request. We use these logs to keep the site secure and working.
- Your cookie choice, stored in a strictly necessary cookie. We do not use analytics or advertising cookies — see our Cookie Policy.
When you contact us or request a demo
- Your name, work email, company, the kind of business you run and anything you choose to tell us.
When you use the platform
- Your name, work email, role and workspace, and records of sign-in and actions taken, for security and audit.
On behalf of our customers
- Whatever the brand loads: typically phone numbers, names, purchase and invoice history, store and product records, messaging preferences (such as DND or opt-out flags) and delivery reports for messages sent.
We do not knowingly collect sensitive categories of data such as health, financial account or biometric information through the website.
4. Why we use it
| Purpose | Data | Basis under the DPDP Act |
|---|---|---|
| Reply to your enquiry or demo request | Contact form details | Your consent, given on the form |
| Send occasional product updates | Name, email | Your separate, optional consent — withdraw any time |
| Provide, secure and support the platform | Platform user account and usage data | Consent, and the uses the Act permits for a service you have asked for (Section 7) |
| Keep the website secure and available | Server logs | Legitimate uses permitted under Section 7 |
| Segment, message and measure on a brand’s behalf | The brand’s customer data | The brand’s instructions (we act as Data Processor) |
| Meet legal obligations | As required | Compliance with law, court orders and government requests |
5. Who we share it with
We do not sell personal data. We share it only with:
- Service providers who host and operate our infrastructure, bound by contracts that limit their use of the data to providing services to us.
- Messaging providers (WhatsApp Business solution providers and SMS aggregators) chosen by each brand, to deliver the brand’s messages and return delivery reports.
- Authorities, where Indian law requires it.
- A successor, if our business is merged or acquired, under the same protections.
6. Where it is stored
Personal data is stored on servers located in [Hosting country / region]. If we transfer data outside India, we will do so only to countries not restricted by the Central Government under Section 16 of the DPDP Act, and with safeguards equivalent to this policy.
7. How long we keep it
- Enquiries and demo requests: up to 24 months after our last conversation, unless you become a customer.
- Platform user accounts: for the life of the workspace, then deleted or anonymised within 90 days of closure.
- Server logs: up to 12 months, unless needed longer to investigate a security incident.
- Customer data processed for a brand: as the brand instructs, and returned or deleted when the contract ends.
- Where the law requires longer retention (for example, tax or audit records), we keep the minimum required.
8. How we protect it
We apply reasonable security safeguards appropriate to the data, including encrypted connections, role-based access, masking of phone numbers in the product and in exports, and regular backups. Access to production systems is limited to people who need it.
If a personal data breach occurs, we will inform the Data Protection Board of India and affected individuals as required by the DPDP Rules, and — where we act as a processor — the brand concerned without delay.
9. Your rights
Under the DPDP Act you have the right to:
- obtain a summary of the personal data we hold about you and how we process it;
- have inaccurate or incomplete data corrected, completed or updated;
- have your data erased when it is no longer needed for the purpose you consented to;
- withdraw consent at any time, as easily as you gave it — this does not affect processing already done;
- nominate another person to exercise your rights in case of death or incapacity; and
- have your grievances addressed.
To exercise a right, email [Privacy email] from the address we hold, or write to the Grievance Officer. We may need to verify your identity. We respond within 30 days and in any event within the period set by the DPDP Rules. For data we process on behalf of a brand, contact that brand; we will pass on any request we receive.
10. Children
Our website and platform are meant for businesses and are not directed at anyone under 18. We do not knowingly collect children’s personal data. If you believe a child has given us personal data, contact us and we will delete it.
11. Cookies
We use only strictly necessary cookies and browser storage. Read the Cookie Policy for the full list, and change your choice at any time from “Cookie settings” in the footer.
12. Grievance Officer
If you have a concern or complaint about how we handle personal data, contact our Grievance Officer:
[Company legal name]
Email: [Grievance email]
Address: [Postal address]
We will acknowledge your complaint within 48 hours and resolve it within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
13. Changes to this policy
We will post any change on this page and update the date at the top. If a change materially affects how we use data you have given us, we will tell you directly and, where required, ask for your consent again.