Controller and processor roles
PulsePigeon plays two distinct roles, and it is important to keep them separate:
- As a controller for the personal data of our own account holders (your name, contact details, billing information, and how you use the platform). This policy describes that processing.
- As a processor for the personal data contained in the mail you send (recipient addresses and message content). We process that data on your instructions under the Data Processing Addendum; you are the controller of it.
Data we collect
Account and billing data
Name, email, organization, authentication identifiers, and billing details. Payment card data is handled by our payment processor; we do not store full card numbers.
Usage and log data
API requests, console activity, sending metadata (timestamps, message identifiers, delivery events, bounce and complaint signals), IP addresses, and device and browser information used to secure and operate the service.
Recipient data (as processor)
Recipient email addresses and the content of messages you send, processed only to deliver your mail and provide delivery reporting, suppression, and abuse controls.
How we use data
We use personal data to:
- provide, operate, secure, and improve the service;
- deliver your mail and report on delivery, bounces, and complaints;
- detect, prevent, and investigate abuse, fraud, and security incidents, and enforce our Acceptable Use Policy;
- process billing and manage your account;
- communicate service, security, and account notices; and
- meet legal and regulatory obligations.
We do not sell personal data, and we do not use the recipient data you send for our own marketing.
Legal bases (GDPR)
Where the GDPR applies, we process account data on the bases of contract (to provide the service), legitimate interests (to secure and improve it, and to prevent abuse), and legal obligation. Recipient data is processed on your instructions as controller. See our GDPR page for more.
Data retention
We retain account data for the life of your account and as needed afterward for legal, tax, and dispute-resolution purposes.
Message content and recipient metadata are retained for a limited operational window and then removed, subject to your plan’s log-retention setting. Suppression data (addresses that bounced, complained, or unsubscribed) may be retained indefinitely to prevent unlawful or unwanted re-sending.
Security
We protect data with encryption in transit and at rest, tenant isolation, least-privilege access, secret management that keeps credentials server-side, and monitoring. See our Security page for details. No system is perfectly secure, and we cannot guarantee absolute security.
International transfers
We and our subprocessors may process data in countries other than yours. Where we transfer personal data internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, as described in the Data Processing Addendum.
Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. To exercise rights over your account data, contact [email protected].
For requests about recipient data we process on a customer’s behalf, we will refer the request to that customer as the controller and support them in responding.
Changes and contact
We may update this policy; material changes will be posted here with a new effective date. Questions can be sent to [email protected].