Skip to content
Legal centre

Data processing addendum

This addendum forms part of the terms of service and governs our processing of personal data contained in customer data. Where you require a signed copy on your own paper, ask and we will work from it.

Last updated: 28 July 2026

1. Roles

For personal data inside your workspace, you are the controller and we are the processor. You decide what data enters the platform and for what purpose; we process it only on your documented instructions, of which this addendum and the terms are part.

For our own account administration and commercial correspondence, we act as a controller under the privacy policy.

2. Subject matter, duration, nature and purpose

  • Subject matter: provision of the PulseUp platform.
  • Duration: for as long as your subscription or licence is in effect, plus the deletion period in clause 9.
  • Nature and purpose: storing, organising, transcribing, analysing and making available the customer data your users submit, including sending relevant content to the configured model endpoint for inference.
  • Types of personal data: names, contact details and roles of your people and your clients' people; any personal data contained in the documents and notes you upload.
  • Categories of data subject: your personnel, your clients and their personnel, and any individual referenced in customer data.

3. Our obligations

  • Process personal data only on your documented instructions, unless required otherwise by law — in which case we tell you first, where we lawfully can.
  • Ensure that personnel with access are bound by confidentiality.
  • Implement appropriate technical and organisational measures (clause 4).
  • Assist you, taking into account the nature of processing, with data subject requests, impact assessments and security obligations.
  • Make available the information needed to demonstrate compliance with this addendum.

4. Security measures

  • Passwords stored as argon2 hashes; sessions and API tokens opaque, hashed at rest and individually revocable.
  • Tenancy enforced in the data model — records from another workspace are not returned by any code path.
  • Authorisation applied through shared gates rather than per-route checks, with roles separating workspace authority from vendor staff.
  • Append-only histories for stage transitions and the AI usage ledger; hash-checked saves for validated document pages.
  • Transport encryption in transit for the hosted service; secrets held in the deployment environment only.
  • Request identifiers on every response and log line; optional structured logging and error tracking.
  • Nightly backups with retention on the hosted service; on-premises, backups are the customer's responsibility.

5. Sub-processors

You give general authorisation for us to engage the sub-processors listed on the sub-processors page. We impose data protection obligations on each of them no less protective than those in this addendum, and we remain liable for their performance.

We will give notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, we will work with you on an alternative — including, where feasible, configuring your deployment to avoid that sub-processor entirely.

6. Data subject requests

Where a data subject contacts us directly about data inside your workspace, we will refer them to you rather than acting ourselves. We will assist you in responding, using the platform's own capabilities where possible.

7. Personal data breaches

We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with the information available to us at the time and updates as our investigation proceeds.

8. Audit

We will respond to reasonable written security questionnaires, and will discuss our architecture and controls with your security team. Where your regulator or your own policy requires an audit, we will agree a scope and a schedule that does not compromise other customers' data.

9. Return and deletion

On termination, we will make your workspace data available for export on request. Once delivered — or if no export is requested within a reasonable period — we delete the production copies.

Copies held in routine backups are deleted on the ordinary backup rotation. Until then they remain protected by the measures in clause 4.

On-premises deployments hold no vendor copy of your data at any point.

10. International transfers

Where the configured model endpoint or another sub-processor processes data outside your jurisdiction, that transfer forms part of the service you have configured. Customers who cannot permit such transfers should deploy on-premises with a model endpoint inside their own network, which removes the transfer entirely.