Last updated: July 23, 2026
This policy explains what data PulseLABS collects, why, where it goes, and how to protect it — including in on-premise mode, where it never leaves your infrastructure.
The controller of the personal data collected via PulseLABS is Pulse Software, a sole trader represented by Dorian Lexteriaque (SIRET 933 544 108 00014, 105 chemin du Mas de Vignolles, 30000 Nîmes, France). For any question relating to your data, contact: contact@pulse-labs.fr.
Depending on your use of the platform, we collect:
This data is processed to: provide and operate the platform (performance of the contract); ensure security and prevent abuse (legitimate interest); respond to your contact requests (performance of the contract or legitimate interest); comply with our legal and accounting obligations (legal obligation).
In on-premise mode, PulseLABS runs on your own infrastructure with local AI models (Ollama): your data does not pass through any third-party server.
In cloud mode, requests that require an external AI model (OpenAI in particular) go through our routing system (Synapse Engine), which can apply automatic redaction of personal and health data before any transmission to an external provider ("PII/PHI Shield", several levels configurable according to data sensitivity). This protection strongly reduces, without entirely eliminating, the risk associated with transfers to a third-party provider.
The AI model providers we may use in cloud mode (including OpenAI, a US company) act as processors within the meaning of the GDPR. A transfer of data outside the European Union may result in this mode; we rely on the contractual safeguards offered by these providers (standard contractual clauses) and on the PII redaction described above to limit exposure.
Your data may be transmitted to the following processors, strictly for the performance of the service: Supabase (database and authentication hosting), Vercel (site and application hosting), OpenAI and the other AI model providers used in cloud mode, Google (sign-in via Google SSO, if you use it) and Stripe (payment). Any audience measurement is carried out in-house, without any third-party analytics tool. No data is sold or used for advertising purposes by Pulse Software.
Account and usage data is retained for as long as your account is active. It is deleted following your deletion request or the closure of your account, except where a longer legal retention obligation applies (in particular accounting and billing documents, retained for the applicable legal period). You may request the deletion of your data at any time at contact@pulse-labs.fr.
In accordance with the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data. You may exercise these rights by writing to contact@pulse-labs.fr. You also have the right to lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).
We implement reasonable technical and organizational measures to protect your data (password encryption, token-based authentication, data isolation per workspace). As no system is infallible, we invite you to report any suspected vulnerability to contact@pulse-labs.fr.
The Site uses only cookies strictly necessary for its operation (session, authentication). No advertising or third-party audience-measurement cookie is placed without prior consent.
This policy may be updated to reflect changes to the service or to regulations. The date of the last update appears at the top of this page.
Questions about this document? Email us at contact@pulse-labs.fr.