PulsitPulsit

Legal

Privacy Policy

Last updated: 29 June 2026

1. Data controller

Pulsit is operated by Pulsit AB (reg. no 556832-2449), Stockholm, Sweden. Pulsit AB is the data controller for personal data processed about visitors, account users and business customers when Pulsit determines the purpose and means of the processing.

Where a business uses Pulsit to manage its own customers, bookings, offers or client relationships, that business is normally the data controller for that customer data and Pulsit acts as data processor. This is handled through business terms and data processing terms.

During a transition period, selected billing or payment administration may be handled by Hillstream AB when explicitly shown on invoice, checkout or customer communication. This does not change the purpose of this policy: to explain how personal data is handled in and around Pulsit.

Contact: info@pulsit.se

2. Pulsit is not a medical records system

Pulsit is built for business presence, offers, bookings, relationships and operational workflows. It must not be used to store medical records, diagnoses, patient journals, national identity numbers, insurance details or other sensitive data that requires a dedicated regulated system.

3. What data we process

  • Account data such as name, email address and login information.
  • Profile and business information published through Pulsit.
  • Services, availability, bookings, favourites and contact actions.
  • Billing, subscription and payment-related information where relevant.
  • Support messages, privacy requests and operational correspondence.
  • Technical information such as IP address, browser, device and logs.

4. Purposes and legal basis

We process personal data to provide the service, maintain accounts, publish business profiles, handle bookings or requests, send transactional messages, provide support, protect the platform, comply with legal obligations and improve Pulsit. Marketing communication is sent only where we have permission or another valid legal basis.

5. Storage, retention and suppliers

Pulsit follows an EU/EES-first data strategy. We use selected suppliers for hosting, authentication, database, email, payments, analytics or operational support. Some suppliers may process limited data outside the EU/EES under appropriate safeguards.

We keep data only for as long as needed for the purpose, for legal obligations, security, accounting, dispute handling or the continued operation of the service. Some records may be anonymized, restricted or retained in minimal form instead of being immediately deleted.

Supplier and subprocessor transparency is part of Pulsit's security and GDPR roadmap. See also Security & Trust.

6. Your rights

Under the GDPR, you may have the right to access, correct, delete, restrict, export or object to the processing of your personal data. You can contact us at any time to exercise these rights.

Logged-in users can also use the account privacy page to review account information and request export, correction or deletion. Some actions are handled manually while Pulsit's automated GDPR self-service is completed.

7. AI-assisted features

Pulsit may include AI-assisted features such as public profile guidance, SEO suggestions, FAQ drafts, onboarding support, summarization or operational suggestions. AI is assistive and should not be treated as the only decision maker for payments, permissions, deletion, legal matters, regulated advice or critical account changes.

When a user chooses to run an AI-assisted review, Pulsit may send selected data needed for that review to an AI service provider. This may include business profile text, public URL, city or area, contact channel types, FAQ drafts and other profile fields needed to return useful suggestions. Pulsit aims to minimize the data sent to what is needed for the requested AI task.

AI suggestions are drafts. Pulsit does not automatically publish AI suggestions to a public profile. Users are responsible for reviewing, correcting and approving content before it is saved or published. See the AI Notice.

8. AI suppliers and subprocessors

Pulsit may use OpenAI or another selected AI provider to generate AI-assisted suggestions. Where personal data is processed by such a provider on behalf of Pulsit or a Pulsit business customer, that provider is handled as a subprocessor under applicable data protection terms.

Pulsit does not ask users to place sensitive personal data, medical records, national identity numbers, payment card data or confidential client notes in public profile fields. Users should remove such information before using AI-assisted review.

A current internal subprocessor register is maintained in Pulsit documentation and should be reviewed before wider commercial launch.

9. Complaints and contact

Questions about privacy or data protection can be sent to info@pulsit.se. You may also contact the Swedish Authority for Privacy Protection (IMY) if you believe your rights have not been respected.