Privacy Policy
How Pulse handles personal data – what we know about you, why we need it, and what you can do about it.
1. Who is responsible for what
Pulse involves two distinct roles, and the responsibility differs between them:
- Your account and billing. Here the controller is DxO Systems s.r.o., Gallandova 1232/1, 163 00 Prague 6, Czech Republic, company no. 22438505. We decide what we need to run your account and issue an invoice.
- Data inside a band. Here the controller is the band, through its admins. They decide who is invited, what is recorded about members and for how long. In this role we are a processor – we handle the data on their instructions. The terms of that processing are set out in a data processing agreement (DPA), which forms an annex to the Terms of Service and is entered into automatically when a band is created.
In practice: if you want something a band holds about you corrected or deleted, speak to the band’s admins first. We will help them, but we cannot decide it on their behalf.
2. What data we process
| What | Examples |
|---|---|
| Account | name, e-mail, language, time zone, sign-in credentials (passkey, one-time codes) |
| Profile | stage name, instruments, photo, contact details you choose to fill in |
| More sensitive profile data | date of birth, emergency contact, allergies and medical notes – filled in voluntarily, visible only to you and members with the relevant permission |
| Band activity | availability for events, line-ups, attendance, notes, messages, files |
| Finances | agreed pay, payouts, expenses and receipts, bank details for QR payment |
| Billing | the band’s billing details, payment history (card details are handled solely by Stripe; we never see them) |
| Technical data | IP address, browser type, time of access, sign-in records and administration audit logs |
3. Why we need it and on what basis
- To provide the service – performance of a contract. Pulse cannot work without an account and basic data.
- To issue invoices and keep accounts – legal obligation. Accounting records must be kept for 10 years.
- To keep the service safe – legitimate interest. This covers sign-in records, abuse protection and basic error diagnostics.
- More sensitive profile data (medical notes, allergies) is processed only with your consent, which you give by filling it in. You can delete it at any time.
We do not use your data for advertising, we do not sell it, and we do not pass it to anyone else for their own purposes.
4. How long we keep it
- Account and band data for as long as the account or band is active.
- After a band is deleted, data is kept for a further 30 days so it can be restored, then permanently deleted.
- After an account is deleted, data is removed within 30 days, except what we must keep by law.
- Accounting and tax documents for 10 years, as required by Czech accounting and VAT law.
- Sign-in records and administration audit logs for 12 months.
5. Who else sees the data
We do not run everything ourselves. We work with these processors:
| Who | For what | Where |
|---|---|---|
| Microsoft (Azure) | running servers and the database | data centres in the European Union |
| Microsoft 365 / Exchange Online | sending e-mail from the service | European Union |
| Stripe | payment processing, tax calculation, invoices | EU / USA under standard contractual clauses |
Beyond that, data is seen only by members of your band, to the extent the band’s admins allow, and by public authorities where the law requires it.
6. Cookies and measurement
Pulse uses no advertising or tracking cookies, and contains no Google Analytics or anything similar. We store only what the service cannot work without:
- being signed in, so you do not have to prove who you are on every click;
- your chosen language and appearance.
Bot protection during registration works without cookies and without third-party services – it is computed in your own browser.
7. Your rights
You have the right to:
- know what data we hold about you and receive a copy;
- have it corrected if it is wrong;
- have it deleted where there is no longer a reason to keep it;
- restrict processing or object to it;
- receive it in a machine-readable form and take it elsewhere – the export is in the app;
- withdraw consent where processing is based on it.
Write to support@bandpulse.cloud and we will reply within one month at the latest. If you believe we are handling your data badly, you may contact the Czech supervisory authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.
8. Security
All traffic is encrypted (HTTPS). We use no passwords at all – signing in uses a link, a one-time code or a passkey. Access to data inside a band is governed by permissions its admins set, and enforced in the database itself rather than only in the application. Backups are encrypted and stored in the EU.
9. Changes to this policy
We may update this policy; we will give notice of any material change by e-mail or in the app. Every version has a version number and an effective date.
10. Contact
DxO Systems s.r.o., Gallandova 1232/1, 163 00 Prague 6, Czech Republic · support@bandpulse.cloud