Our commitment
PulsePigeon is built to help regulated senders meet their obligations. We act as a controller for account data and as a processor for the recipient data in the mail you send, and we offer the contractual and technical tools you need to demonstrate compliance.
Data Processing Addendum
Our Data Processing Addendum is incorporated into the Terms of Service and covers Article 28 processor obligations, sub-processor terms, security measures, breach notification, and international transfer safeguards including the Standard Contractual Clauses. No separate signature is required, though we can provide a countersigned copy on request.
International transfers
Where personal data leaves the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the applicable Standard Contractual Clauses and, where relevant, supplementary measures. Our subprocessors and their regions are listed on the Subprocessors page so you can assess transfers.
Supporting data-subject rights
The console provides tools to help you honor recipient rights and your own obligations, including:
- suppression list export and management;
- recipient data deletion and configurable retention windows;
- delivery-event records for accountability; and
- a hosted preference center for opt-out and consent management.
For requests about recipient data, we refer the data subject to you as the controller and assist you in responding.
Security and breach notification
We maintain appropriate technical and organizational measures (see the Security page) and will notify you without undue delay of a personal data breach affecting your data, with the information you need to meet your own notification duties.
Contact
For GDPR questions, DPA requests, or to raise a data-protection concern, contact [email protected].