Data Processing Agreement

Template — pending final legal review. Organisers may supply their own DPA through the admin settings; this default applies until they do.

1. Parties

Controller is the event organiser (the entity running the event on Pulsea). Processor is Pulsea SA, Lausanne, Switzerland.

2. Scope of processing

Pulsea processes delegate personal data strictly to operate the registration, accreditation, hotel booking, payment, and post-event communication flows on the controller's behalf. No processing for Pulsea's own marketing without explicit delegate opt-in.

3. Data categories

  • Identity: name, email, phone, country of residence.
  • Travel documents: passport number, issuing country, expiry date (encrypted at rest with AES-256-GCM; decryption logged to activity_logs).
  • Payment: Stripe PaymentIntent references, invoice metadata. Card numbers never touch Pulsea servers — tokenised by Stripe.
  • Dietary + accessibility requirements, session preferences.

4. Sub-processors

  • Supabase (EU/Frankfurt) — primary database, file storage.
  • Railway — API hosting.
  • Vercel — web frontend hosting.
  • Stripe Connect — payments + Connected Account KYC.
  • Resend — transactional email delivery.
  • Loops — marketing email (opt-in only).

New sub-processors are disclosed 30 days before activation. The controller may object in writing within that window.

5. Security measures

  • TLS 1.3 in transit, AES-256 at rest.
  • Passport details encrypted with AES-256-GCM using a rotating application key; decryption is role-gated (Visa Manager) and audit-logged.
  • Row-level security on every tenant table. Unauthorised cross- tenant access returns 404 (not 403) per spec.
  • HSTS with 2-year max-age, preload enabled. CORS allowlist; no wildcards.
  • Staff access via SSO + 2FA, least-privilege roles, reviewed quarterly.

6. Data subject rights

Pulsea supports the data-subject rights under GDPR Articles 15 (access), 16 (rectification), 17 (erasure), 18 (restriction of processing) and 20 (portability), and their Swiss nFADP equivalents. Profile details are self-service — a data subject can update them at any time under /my/profile. Every other request — access (including a copy of the personal data), erasure, restriction, portability, and any rectification beyond profile details — is made to the event organiser (the data controller); Pulsea, as processor, assists and can be reached at support@usepulsea.com if the organiser is unavailable. Requests are actioned without undue delay and within one month, subject to any extension permitted by GDPR Article 12(3). Personal data is erased or anonymised in response to a valid request, except where continued processing or retention is permitted or required by law. Erasure anonymises PII while preserving financial records for the 10-year Swiss retention period (nFADP + tax law).

7. Breach notification

Pulsea notifies the controller within 24 hours of becoming aware of a personal data breach, with the information required under GDPR Article 33.

8. Term + termination

This DPA remains in force while the controller runs events on Pulsea. On termination, the controller may request export of all event data (see /reports/export/zip). Pulsea deletes personal data within 30 days of termination unless legal retention requires otherwise.

Last updated 2026-04-25. Questions? support@usepulsea.com.

Data Processing Agreement