Privacy statement

1. Who is responsible for your data

Pulsify is the controller within the meaning of the General Data Protection Regulation (GDPR, in Dutch the AVG). That means we decide why and how your personal data is processed.

2. When this statement applies

It applies whenever you:

3. What we process

Only what the contact or the assignment actually requires:

4. Why we process it, and on what legal basis

We do not build advertising profiles, we do not use your data for marketing to third parties, and we do not sell or trade it. There is no automated decision-making and no profiling.

5. Cookies, analytics and third-party requests

This website sets no cookies. There is no analytics, no tag manager, no advertising pixel, no embedded video and no social media plug-in. Nothing is stored on your device and no consent banner is needed.

Two files are loaded from outside our own server: the typeface Plus Jakarta Sans, from Google Fonts, and the interface icons, from the unpkg content delivery network. To deliver those files your browser has to contact those services, which means your IP address and basic browser information reach them. No cookies are set by those requests and we receive no data from them. If you would rather avoid this entirely, a browser extension that blocks third-party requests will stop it; the site remains readable.

6. Who we share it with

Your data stays with us unless a supplier is needed to do the work. We use the following categories of recipient:

Where a supplier processes personal data on our behalf, we conclude a processor agreement with them, as the GDPR requires. We do not pass your data to anyone else without your instruction or a legal obligation.

7. Transfer outside the European Economic Area

Our email runs through Google, an American provider, so email correspondence may be stored on or accessible from servers outside the European Economic Area. The same applies to the content delivery services named in section 5. Such transfers take place on the basis of the European Commission's adequacy decision for the EU–US Data Privacy Framework and, where that decision does not apply, the European Commission's standard contractual clauses.

8. How long we keep it

9. How we protect it

No system is completely safe. If a data breach occurs that is likely to affect you, we report it to the Dutch Data Protection Authority within 72 hours where the law requires, and we tell you directly where the law requires that too.

10. Your rights

Under the GDPR you can ask us to:

Send your request to pulsify.zakelijk@gmail.com. We answer within one month. If a request is complex we may extend that by two months, and we will tell you within the first month if we do. We may ask a question to confirm that you are who you say you are — but we will never ask for a copy of your identity document. Exercising these rights is free of charge.

11. Complaints about how we handle your data

Tell us first, by email: it is usually the fastest way to fix something. If that does not resolve it, you have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. If you live or work in another EU member state, you may also complain to the supervisory authority there.

12. Automated decision-making

We take no decisions about you by automated means that produce legal effects or similarly significantly affect you. Automated tools are used in producing content, which is described in our terms and conditions; those tools do not make decisions about you as a person.

13. Changes to this statement

We may amend this statement, for example when we change a supplier or a service. The current version and its date are shown at the top of this page. For a significant change affecting an ongoing assignment, we tell you by email.