Skip to content
Legal centre

Privacy policy

What we collect, why, and what you can do about it. Short version: account details to run the service, customer content processed only on your instructions, and no tracking or advertising anywhere.

Last updated: 28 July 2026

1. Who we are

Dotex provides the PulseUp platform. For personal data inside a customer's workspace we act as a processor on that customer's instructions; for our own website, sales enquiries and account administration we act as a controller.

Privacy questions: hossein.khaksar@samafinancials.com.

2. What we collect

  • Account data: name, email address, workspace membership and role, and the authentication material needed to sign you in (passwords are stored only as an argon2 hash).
  • Customer content: the documents, figures, notes, voice recordings and records your team puts into a workspace. This may contain personal data about your clients and their people; we process it on your instructions.
  • Usage and technical data: request logs with a request identifier, timestamps, error reports, and the AI usage ledger recording that a model call occurred and which workspace caused it.
  • Enquiry data: what you send through the demo or contact form, and our correspondence with you afterwards.

3. Why we process it

  • To provide the platform and its features to you (performance of our contract).
  • To keep the service secure, to detect abuse and to diagnose faults (our legitimate interest in a secure, working service).
  • To answer enquiries and manage the commercial relationship (your request, and our legitimate interest).
  • To comply with legal, accounting and tax obligations.

4. Processing by AI models

Reading a document, transcribing a voice note, extracting a proposal or answering an assistant question sends the relevant content to the model endpoint configured for your deployment. That may be a third-party provider or, on-premises, a model inside your own network.

We do not use customer content to train models, and we contract with providers on the basis that they do not either. Every call is recorded in an append-only usage ledger attributed to the workspace that caused it — the ledger records that a call happened and its size, not a second copy of your content.

5. Who else sees it

We use a small number of sub-processors — a model provider, infrastructure, email delivery and error tracking — listed with their purpose and location on the sub-processors page.

Our staff access customer content only where support requires it, and on-premises deployments give us no access at all unless you grant it. We do not sell personal data, and we do not share it for advertising.

6. Where it is stored

On PulseUp Cloud, customer data is stored on our managed infrastructure. On-premises, it is stored wherever you deploy — we hold no copy.

Where a model provider processes content outside the country in which you operate, that transfer is part of the service you have configured; you can avoid it entirely by pointing the deployment at a model within your own jurisdiction or network.

7. How long we keep it

  • Customer content: for as long as your workspace exists, then deleted after termination once any export you have requested is delivered, subject to the backup cycle described in the addendum.
  • Account data: for the life of the account. Accounts are disabled rather than deleted so that authorship of past work remains resolvable; a disabled account occupies no seat.
  • Logs and the usage ledger: retained for a limited operational period for security, billing accuracy and diagnostics.
  • Enquiry data: kept for as long as needed to answer you and for a reasonable period afterwards for our records.

8. Security

Passwords are argon2-hashed. Sessions and API tokens are opaque and stored hashed, revocable individually, and re-validated on every request. Credential endpoints are rate-limited with deliberately uniform failures.

Tenancy is enforced in the data model: a record belonging to another workspace is not returned at all. Certain histories — stage transitions, the AI usage ledger — have no update or delete path by design.

Detail on all of this, including the controls we do not yet have, is on the security page.

9. Your rights

You may ask us for a copy of the personal data we hold about you as a controller, ask us to correct it, ask us to delete it where we have no overriding obligation to keep it, or object to a particular processing activity.

Where the data sits inside a customer's workspace, we act on that customer's instructions — send your request to them, and we will support them in answering it.

Write to hossein.khaksar@samafinancials.com and we will respond within a reasonable period.

10. Cookies

The product sets an essential session cookie and stores a theme preference in your browser. This marketing website sets no analytics, advertising or third-party tracking cookies at all. Detail is in the cookie policy.

11. Children

The platform is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.

12. Changes

We will update this policy when our practices change and revise the date at the top. Material changes are notified to workspace owners before they take effect.