We take the privacy of our customers, their employees, and their guests seriously. This policy is written in plain language wherever possible and is structured to map cleanly to the General Data Protection Regulation (GDPR), the UK GDPR, and the Danish Data Protection Act. For business-to-business customers, this policy is supplemented by our Data Processing Agreement.
Data controller
For personal data we collect about you as a visitor to our website, a prospective customer, an employee of a customer, or a job applicant, the data controller is:
PulseMenu ApS
CVR (Danish company registry) on request
Copenhagen, Denmark
privacy@pulse-menu.com
For personal data we process on behalf of our customers (for example, your venue's guest data inside the PulseMenu platform), our customer is the controller and PulseMenu acts as a processor. Our obligations in that role are governed by the Data Processing Agreement (DPA).
What personal data we collect
Information you give us
- Account data — name, work email address, role, employer, and any phone number you provide.
- Billing data — billing name, address, tax ID, and the last four digits of payment instruments held by our payment processor.
- Support and sales communications — content of emails, chat messages, and call notes.
- Recruitment data — CVs, cover letters, references, and notes from interviews when you apply for a role.
Information collected automatically
- Usage telemetry — pages viewed, actions taken, device and browser metadata, IP address, and approximate location derived from IP.
- Logs — request, application, and security logs that may incidentally contain personal data such as user IDs.
- Cookies and similar technologies — see our Cookie Policy.
Information from third parties
- Identity & authentication providers — name and email from Google or Microsoft when you sign in via single sign-on.
- Integration partners — operational data we receive from connected POS, booking, and inventory systems on the instruction of our customers.
- Public sources — publicly available business contact information used for sales outreach.
Purposes and legal bases
We only process personal data when we have a valid legal basis. The matrix below summarises the most common processing activities.
| Purpose | Categories | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the PulseMenu platform | Account, usage, content | Contract (6(1)(b)) |
| Billing and payments | Billing, transaction | Contract, legal obligation |
| Customer support | Account, support content | Contract, legitimate interest |
| Security, fraud prevention, abuse detection | Logs, usage | Legitimate interest (6(1)(f)) |
| Product improvement and analytics | Usage, telemetry | Legitimate interest, consent for non-essential cookies |
| Marketing communications | Account, prospect contact | Consent or legitimate interest (B2B) |
| Recruitment | Application data | Pre-contract steps; legitimate interest |
| Legal and regulatory compliance | Records as required | Legal obligation (6(1)(c)) |
International transfers
Personal data is hosted in the European Economic Area (EEA) by default. Where data is transferred outside the EEA — for example, to a subprocessor's support team — we rely on:
- European Commission adequacy decisions, where they apply;
- The 2021 Standard Contractual Clauses with supplementary technical and organisational measures; and/or
- For UK-originated data, the UK International Data Transfer Addendum.
Transfer impact assessments are performed before any new transfer mechanism is relied upon.
Retention
We retain personal data for as long as we need it for the purposes set out above. Specifically:
- Active accounts — for the duration of your subscription.
- Closed accounts — up to 90 days after closure to allow reactivation, then deleted or anonymised.
- Customer venue data — retained according to the customer's instructions and the DPA.
- Billing records — minimum 5 years under Danish bookkeeping law.
- Recruitment data — up to 6 months after a decision, or with consent for future opportunities.
- Backups — purged according to a documented backup retention schedule, typically within 35 days.
Your rights
If you are in the EU, EEA, UK, or Switzerland you have the right to:
- Access the personal data we hold about you;
- Request rectification of inaccurate data;
- Request erasure where one of the grounds in GDPR Art. 17 applies;
- Request restriction of processing;
- Object to processing based on legitimate interests, including direct marketing;
- Data portability for data you provided to us and we process by automated means under contract or consent;
- Withdraw consent at any time, without affecting the lawfulness of previous processing; and
- Lodge a complaint with a supervisory authority — for example, the Danish Data Protection Agency (Datatilsynet).
To exercise any of these rights, email privacy@pulse-menu.com. We respond within 30 days, extendable by 60 days for complex requests.
How we protect personal data
PulseMenu maintains administrative, technical, and physical safeguards designed to protect personal data, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent);
- Role-based access control with least-privilege principles;
- Multi-factor authentication on all administrative accounts;
- Comprehensive audit logging and anomaly detection;
- Regular vulnerability scanning, third-party penetration testing, and secure SDLC practices;
- An incident response programme with notification within 72 hours of a confirmed breach affecting personal data.
Children
PulseMenu is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.
Automated decision-making
The platform offers AI-assisted recommendations (for example, suggested prices or forecasts). These are recommendations only — every meaningful operational decision in PulseMenu requires a human user to approve it. We do not perform solely automated decision-making with legal or similarly significant effects on individuals.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify account administrators by email and update the "Last updated" date above. Continued use of the platform after a change becomes effective constitutes acceptance.
Contact us
Privacy questions, data subject requests, and compliance enquiries should be directed to privacy@pulse-menu.com. For urgent security issues, write to security@pulse-menu.com.
We're happy to walk your legal or compliance team through any clause. Reach out at privacy@pulse-menu.com.
