Data Processing Agreement

Template — pending final legal review. Organisers may supply their own DPA through the admin settings; this default applies until they do.

1. Parties

Controller is the event organiser (the entity running the event on Pulsea). Processor is Pulsea SA, Lausanne, Switzerland.

2. Scope of processing

Pulsea processes delegate personal data strictly to operate the registration, accreditation, hotel booking, payment, and post-event communication flows on the controller's behalf. No processing for Pulsea's own marketing without explicit delegate opt-in.

3. Data categories

  • Identity: name, email, phone, country of residence.
  • Travel documents: passport number, issuing country, expiry date (encrypted at rest with AES-256-GCM; decryption logged to activity_logs).
  • Payment: Stripe PaymentIntent references, invoice metadata. Card numbers never touch Pulsea servers — tokenised by Stripe.
  • Dietary + accessibility requirements, session preferences.

4. Sub-processors

  • Supabase (EU/Frankfurt) — primary database, file storage.
  • Railway — API hosting.
  • Vercel — web frontend hosting.
  • Stripe Connect — payments + Connected Account KYC.
  • Resend — transactional email delivery.
  • Loops — marketing email (opt-in only).

New sub-processors are disclosed 30 days before activation. The controller may object in writing within that window.

5. Security measures

  • TLS 1.3 in transit, AES-256 at rest.
  • Passport details encrypted with AES-256-GCM using a rotating application key; decryption is role-gated (Visa Manager) and audit-logged.
  • Row-level security on every tenant table. Unauthorised cross- tenant access returns 404 (not 403) per spec.
  • HSTS with 2-year max-age, preload enabled. CORS allowlist; no wildcards.
  • Staff access via SSO + 2FA, least-privilege roles, reviewed quarterly.

6. Data subject rights

Pulsea supports GDPR Article 15 (access), 16 (rectification), 17 (erasure), 18 (restriction), and 20 (portability) through self-service endpoints at /my/profile and POST /api/v1/users/me/gdpr. The deletion cascade anonymises PII while preserving financial records for the 10-year Swiss retention period (nFADP + tax law).

7. Breach notification

Pulsea notifies the controller within 24 hours of becoming aware of a personal data breach, with the information required under GDPR Article 33.

8. Term + termination

This DPA remains in force while the controller runs events on Pulsea. On termination, the controller may request export of all event data (see /reports/export/zip). Pulsea deletes personal data within 30 days of termination unless legal retention requires otherwise.

Last updated 2026-04-25. Questions? support@usepulsea.com.

Data Processing Agreement