Legal

Privacy Policy

Last updated: 3 September 2026

This policy explains what personal data DealPulse processes, why, and what rights you have. It is written to be read, not skimmed past.

1. Who is responsible

The controller for your account and website data is Digiteum Sp. z o.o., with its registered office at Szafarnia 11/F8, 80-755 Gdańsk, Poland, entered in the National Court Register (KRS) under number 0000866372, NIP 5833409796 (EU VAT: PL5833409796), REGON 387354235 ("Digiteum", "we"). For personal data contained inside the transcripts you upload (for example the names of people on your sales calls), you are the controller and we act as your processor, handling that data only to provide the Service.

2. What we process, and why

DataWhere it comes fromWhy we process itLegal basis
Account data: name, email, sign-in identifierGoogle or email sign-inCreating and securing your accountContract
Your Content: the analysis derived from the transcripts you upload (signals, evidence quotes, call summaries, recommendations). The uploaded file itself is processed and then deleted; we do not keep the transcript textYouProviding the analysis the Service exists forContract (as your processor for in-transcript personal data)
Usage and technical data: log records, IP address, approximate request metadataYour use of the ServiceSecurity, abuse prevention, keeping the Service workingLegitimate interest
Contact form dataYouAnswering youLegitimate interest / pre-contract steps
Billing data: what you bought, when, the amount, your country and any VAT number you give us. Card details go to Stripe and never reach usYou, via StripeTaking payment, issuing invoices and meeting tax and accounting lawContract and legal obligation
Website analytics: pages viewed, how you arrived, approximate location by country and city, browser and device. Only if you switch analytics onYour use of this websiteUnderstanding which pages are useful and how people find usConsent

We do not sell personal data, and we do not use advertising trackers.

3. AI processing

Transcript analysis runs through the OpenAI API. Under OpenAI's API terms, data submitted through the API is not used to train their models. We send only what is needed to perform the analysis you requested.

4. Who helps us run the Service

ProviderRoleLocation
Amazon Web Services (AWS)Hosting: application and databaseEU (Ireland, eu-west-1)
SupabaseAuthentication (Google sign-in)EU (Ireland)
OpenAITranscript analysis via APIUnited States
ResendTransactional email delivery (sign-in links, invitations, account notifications)United States (email delivered via EU infrastructure)
Stripe (Stripe Payments Europe, Ltd.)Payments, subscription billing and VAT calculationIreland, with group companies in the United States
Google (Google Analytics 4)Website analytics, and only for visitors who switch it onUnited States

Stripe contracts with us through its Irish entity and holds billing data in the EU; where it transfers data to its group companies outside the EU, that transfer runs under the European Commission's Standard Contractual Clauses. Where other data leaves the EU (OpenAI for transcript analysis, Resend for email delivery, and Google for website analytics if you have switched it on), the transfer is covered by the same Clauses and the provider's data processing addendum.

5. How long we keep data

6. Your rights

Under the GDPR you can ask us for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Use the contact form and we will respond within the statutory time. You also have the right to lodge a complaint with a supervisory authority; in Poland that is the President of the Personal Data Protection Office (PUODO), or the authority in your own EU country.

7. People on your calls

If you upload transcripts of calls with other people, you are responsible for having a lawful basis to record and process those conversations. As your processor for that data, we handle it only on your instructions: we analyse the transcript, delete it once the analysis is done, show you the results, and delete those when you delete them.

8. Security

Data is encrypted in transit, hosted in the EU, and access to production systems is restricted. Sign-in is delegated to Google or a one-time email link via Supabase; we never see or store a password.

9. Changes

If this policy changes materially we will say so in the Service before the change takes effect. The date at the top always tells you when it was last touched.