This Data Processing Addendum ("DPA") forms part of the agreement between Pulse Payments LLC (dba Pulse Technologies) ("Pulse", "Processor") and the customer organization ("Customer", "Controller") for use of the Pulse Social Command Center (the "Service"). Where Customer Personal Data is processed, this DPA applies.
The Customer is the Controller and Pulse is the Processor of Customer Personal Data. Pulse processes Customer Personal Data only to provide the Service and in accordance with the Customer's documented instructions (including these Terms, the Privacy Policy, and this DPA), unless required by law.
The Customer authorizes Pulse to engage the Sub-processors listed in Annex III to process Customer Personal Data. Pulse imposes data protection terms on each Sub-processor no less protective than this DPA and remains responsible for their performance. Pulse will inform the Customer of intended changes to Sub-processors and give the Customer the opportunity to object on reasonable data-protection grounds.
Customer Personal Data may be processed in the United States. Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, that transfer is governed by the applicable Standard Contractual Clauses (and, for United Kingdom transfers, the UK International Data Transfer Addendum), which are incorporated into this DPA by reference and completed with the parties' details set out in Annex I.
Pulse retains Customer Personal Data for the duration of the agreement. On termination, Pulse will, at the Customer's choice, delete or return Customer Personal Data within 60 days, except where retention is required by law. Organization administrators can delete content and remove users in the Service at any time, and individual users can export their data and delete their account in-app (Security), supporting Data Subject access and erasure requests.
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service.
Provision of the Service for the duration of the agreement.
Hosting, generating (including AI text, image, and voice generation, generating posts from images or files the Customer uploads, and live trend research), operating an in-app AI assistant (PiP) that, on a user's instruction, plans, drafts, triages, and personalizes within the Customer's workspace and that stores a per-user preferences profile to do so (the assistant proposes content for the user's approval and does not publish autonomously), scheduling, and publishing social media content to the networks the Customer connects on the Customer's behalf; sending and receiving business text messages (Pulse SMS); sending opted-in marketing email — campaigns, automations, and signup-form confirmations — from the Customer's verified sending domain (Pulse Email); where the Customer connects a Shopify store, ingesting its orders and checkouts to run the Customer's ecommerce automations, attribute order revenue, and segment the Customer's customers; orchestrating multi-channel journeys the Customer builds (ordered email, SMS, AI voice, and CRM-task steps with delays, engagement-based branching, and goal-based exit) and placing the outbound AI voice calls the Customer configures, including processing the resulting call audio and transcript to run the AI agent and record the call summary and outcome (Pulse Voice); authoring long-form blog posts (including AI generation and web research) and, on the Customer's instruction, publishing them to the content management system the Customer connects and controls (e.g. WordPress, Webflow, Ghost, Hygraph, Medium); providing programmatic access via a public API and outbound webhooks; where enabled, forwarding copies of the Customer's communications (text, email, and social) to the archiving, supervision, or eDiscovery system the Customer configures and controls (compliance capture); delivering mobile push notifications; operating a support help desk; producing first-party in-product usage analytics for the Customer's administrators; and managing user access and billing.
The Customer's authorized users (administrators, editors, viewers); the Customer's SMS contacts and message recipients; the Customer's call recipients (individuals the Customer calls via Pulse Voice); the Customer's email contacts and recipients, including individuals who subscribe through the Customer's hosted signup forms; the Customer's store customers reflected in orders/checkouts synced from a connected Shopify store; the Customer's social-media audience to the extent reflected in engagement/inbox data; and any individuals referenced within Customer Content.
Names and email addresses of users; authentication and two-factor data; content and media submitted by the Customer; connected-account identifiers and tokens; a per-user AI-assistant preferences profile (work-style preferences such as tone, goals, and recurring topics, designed to exclude sensitive data and user-clearable in-product); engagement/inbox messages from the Customer's audience; mobile phone numbers, text-message content and media, and message delivery and opt-out status (for Pulse SMS); call audio, transcripts, AI-agent summaries, and call metadata (calling/called numbers, duration, disposition) (for outbound AI voice calls via Pulse Voice); email addresses, names, and tags of the Customer's email contacts, their subscription status, and email delivery/engagement data (for Pulse Email); mobile device push tokens (for the app); developer credentials (API key hashes, webhook URLs); the content of support tickets and live chats; first-party in-product usage-analytics, audit, and log data. Mobile phone numbers and SMS consent are not shared with third parties for their own marketing, nor sold. The Customer should avoid submitting special-category data, which the Service is not designed to process.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Hosting, serverless functions, media storage | United States |
| Neon | Managed PostgreSQL database | United States |
| Anthropic | AI content generation, trend research, and the in-app AI assistant (PiP) | United States |
| fal.ai (if enabled) | AI image generation | United States |
| ElevenLabs (if enabled) | AI voiceover / text-to-speech | United States |
| Connected social networks | Publishing to the networks the Customer connects (Meta/Facebook/Instagram, LinkedIn, X, TikTok, YouTube, Pinterest, Threads, Google Business Profile, Bluesky, Mastodon, Reddit, Telegram, Tumblr) | Varies |
| Twilio | Pulse SMS — phone number provisioning and SMS/MMS/WhatsApp/RCS delivery | United States |
| PulseVoice (if enabled) | Pulse Voice — placing outbound AI voice calls the Customer configures and running the AI agent (via its telephony carrier and its speech-to-text, language-model, and text-to-speech providers), solely to complete the call on the Customer's behalf | United States |
| Meta / WhatsApp (if enabled) | WhatsApp Business message delivery (via Twilio) | United States |
| Google (if enabled) | RCS Business Messaging delivery (via Twilio) | United States |
| OneSignal (mobile app) | Mobile push-notification delivery | United States |
| Microsoft (if enabled) | Microsoft Teams app sign-in and native Teams notifications | United States |
| Sentry (if enabled) | Application error monitoring | United States |
| Atlassian (Jira Service Management) | Support-desk ticketing — content of a Customer's support requests | United States |
| PulseTech payment gateway | Subscription payment processing | United States |
| Resend (if enabled) | Transactional email, and delivery of opted-in marketing email the Customer sends through Pulse Email | United States |
Sub-processors marked "if enabled" are engaged only where the Customer uses the related feature. Publishing destinations are determined by the social accounts the Customer chooses to connect.
Pulse Payments LLC (dba Pulse Technologies)
9160 Forum Corporate Pkwy, Suite 350, Fort Myers, FL 33905
Email: pulselegal@pulsetechnologies.ai