Privacy Policy
This policy explains how ScalePulse handles information when you use our website, workspace, consent widget, and related services. ScalePulse is a product name; the contracting entity is identified in your order form or other written agreement.
1. What we process
We process account information you give us, including an administrator email address and Cognito account identifier. When a customer installs the ScalePulse widget, we process a tenant-scoped pseudonymous subject reference, consent choices, notice version and locale, timestamps, purpose identifiers, and integrity hashes. We do not ask customers to send raw names, email addresses, phone numbers, or other direct identifiers in widget events.
2. Why we process it
We use administrator information to provide and secure the workspace, authenticate users, respond to support requests, and protect the service. We use consent-event metadata to operate the customer’s consent ledger, provide their evidence view, enforce their plan allowance, and investigate reliability or security issues. We do not sell personal data or use consent-event metadata for advertising.
3. Customer roles and instructions
For a customer’s end-user consent data, the customer is normally the Data Fiduciary and ScalePulse acts on its documented instructions as a service provider. Customers remain responsible for their notice content, lawful basis, rights handling, retention decisions, and the systems in which their users’ data is stored. ScalePulse is not a Board-registered Consent Manager.
4. Storage, security, and location
Production data is designed to remain in AWS India regions. Consent evidence is written to append-only ledger records and retained in an Object Lock evidence store. We use access controls, encryption in transit, encryption at rest where supported by the service, and tenant-scoped authorization. No security measure is absolute; report a suspected security issue promptly to contact@scalepulse.in.
5. Retention
We retain account information while an account is active and for a reasonable period afterwards for security, legal, and dispute-resolution purposes. Consent evidence is retained according to the customer’s configured evidence policy and may be subject to immutable retention controls. We will not alter immutable evidence merely because an account is closed where retention is required by a valid agreement or law.
6. Sharing
We share information only with service providers needed to operate ScalePulse, such as AWS for hosting and transactional email providers for account verification, or where required by law. We require service providers to handle data only for the service they provide. We do not disclose a customer’s consent evidence to another customer.
7. Your choices and rights
You may request access, correction, or deletion of your ScalePulse administrator account information by contacting us. Requests concerning a customer’s own users should be directed to that customer, which controls the underlying product data and privacy notice. Our hosted rights portal is not yet available; customers must currently operate their own request channel.
8. Changes
We may update this policy when our service or legal obligations change. We will post the revised version here and update the effective date. Material changes to customer processing commitments will be handled under the applicable customer agreement.
9. Contact
For privacy questions, contact contact@scalepulse.in.