Privacy Policy
Pulseoniq is a German company, and the legally binding version of this privacy policy is the German one. You can read it here: Datenschutzerklärung. The English text below is a reference translation, provided so that you can read it in the language of the rest of this site. Where the two differ, the German version governs.
This policy describes which personal data we process when you visit this website and when you contact us, on what legal basis, and what rights you have.
Last updated: 8 September 2026
1. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Pulseoniq GmbH i. G.
Franz-Wallraff-Str. 54
52078 Aachen
Germany
Represented by the managing directors Dr. Elmar Karlowitsch and Dr. Martin Karlowitsch.
Email for data protection enquiries: privacy@pulseoniq.com
We have not appointed a data protection officer; we are not required to.
2. Providing this website
When you open this website, our hosting provider processes the technical connection data your browser transmits automatically: your IP address, the date and time of access, the page requested, the page you came from, the browser you use and your operating system.
This data is required to deliver the website, keep it stable and fend off attacks. Operating the site is technically impossible without it.
Legal basis: Art. 6 (1)(f) GDPR. Our legitimate interest lies in providing our website securely and reliably.
Retention: No server logs of your visit are kept for us. Logging of HTTP requests is off by default at our hosting provider and we have not enabled it; application-level logging is switched off as well. There is therefore no log store we could inspect, evaluate or disclose. Cloudflare processes the connection data for as long as delivering the page and fending off attacks requires; for those purposes of its own, Cloudflare’s privacy policy applies.
Processor: Cloudflare, Inc. We use Cloudflare Workers.
On the place of processing. Cloudflare operates a worldwide network and usually serves a page from the location closest to the visitor — for a visit from Europe, therefore, from a European location. Processing outside the European Union is nevertheless not excluded. It is covered by the EU-US Data Privacy Framework; see section 9 for details.
3. Audience measurement
We want to know which content is read, without recognising you in the process. For that we use Plausible Analytics.
Plausible sets no cookies, does not access the storage of your device and does not build cross-device identifiers. What is collected are aggregated values: page views, referring page, device type and country.
So that visits within a single day are not counted twice, Plausible processes your IP address and your browser identifier (user agent) and derives a check value from them. The underlying values are not stored. Recognising an individual person is neither possible nor intended.
Legal basis: Art. 6 (1)(f) GDPR. Our legitimate interest lies in improving what we offer on the basis of aggregated usage data. Because no information is stored on your device or read from it, no consent under section 25 TDDDG (the German implementation of the ePrivacy rules) is required.
Processor: Plausible Insights OÜ. Processing and storage take place on servers in Germany; no transfer to a third country occurs.
4. Cookies
This website sets no cookies. Neither for advertising nor for analytics, and none that record your behaviour across visits. There is therefore no cookie banner either — there would be nothing for you to consent to.
Should we embed content in future that is loaded from third parties — a video, for instance — we will obtain your consent beforehand. Until you agree, such content is not loaded and no connection to its provider takes place. We will update this policy as soon as that is the case.
5. Contacting us, and forms
When you contact us through a form or by email, we process the details you provide. For an enquiry these are your name, your business contact details, your company and your role, and the content of your enquiry. For a plain sign-up — for our beta programme, for instance — it is your email address alone. For forms we additionally store the time of submission and the version of the consent wording that was shown to you.
Forms on this website are submitted directly to our service provider Brevo, not through a server of ours. As a technical consequence, Brevo receives your IP address and your browser identifier.
We use these details to answer your enquiry, to provide content you requested, and to maintain business contact with you.
Legal basis: Art. 6 (1)(b) GDPR for answering your enquiry and providing requested content. Art. 6 (1)(f) GDPR for maintaining business contact thereafter; our legitimate interest lies in initiating and continuing business relationships.
Retention: We keep your contact details for as long as the purpose of maintaining contact persists — but no longer than 120 months from the last relevant contact. After that we delete them.
There is a substantive reason for this long retention: we work in an indirect partner business in which contacts persist over many years and are picked up again after long pauses. Once a year we review the oldest group of our contacts and check whether the purpose still exists.
Processors: Brevo for receiving and managing form submissions, and Microsoft Ireland Operations Limited for email and file storage. Storage at Brevo takes place within the European Union; on the sub-processors Brevo uses, see section 9.
6. Consent to receive information about our products
How you give consent depends on which form you filled in.
On a plain sign-up — for our beta programme or a newsletter, say — receiving information is the form’s only purpose. There is therefore no tick box. After you submit, you receive a confirmation email, and only your click on the link it contains constitutes the consent (double opt-in). The text you consent to is in that email. Without your confirmation we do not add you to the mailing.
On a form carrying an enquiry — the contact form above all — you may additionally and voluntarily consent to receiving information about our products and services. This consent is not a precondition for us answering your enquiry: the form works without it, and we reply to you in any case. This consent, too, is confirmed by double opt-in afterwards.
What you consent to. Messages about our beta programme, product information, our newsletter, and invitations to webinars and events — and to the measurement of how you use those messages (section 7).
Legal basis: Art. 6 (1)(a) GDPR.
Withdrawal: You may withdraw your consent at any time without any disadvantage to you — via the unsubscribe link in every message, or by writing to the address given above. The lawfulness of processing carried out before the withdrawal remains unaffected.
Retention and proof: After your withdrawal we remove you from the mailing without delay. To prove that consent existed, we keep the wording of the consent and the times of sign-up, confirmation and withdrawal for three years from the end of the year in which you withdrew. In addition we maintain a suppression list so that you are not contacted again after a withdrawal; it contains as little data as possible.
End of mailing without withdrawal: If you do not react to our messages for 24 months, we stop sending of our own accord. Your contact record remains; should you get in touch again later, we obtain fresh consent.
7. How we measure the use of our emails
In the emails you receive on the basis of your consent, we measure whether you open them and which links you click. What is recorded is the time, your IP address and the address clicked. Technically this happens through a small image in the message and through links that are routed first through our address send.pulseoniq.com.
Why we do this. Firstly, to steer our mailings. Secondly, to recognise which topics interest you — and to do so over long periods. We work in an indirect partner business in which contacts are picked up again after years. If we come back into conversation after a long pause, this information helps us send you what fits and leave out what does not. It is the same reason for which we keep contact details for so long (section 5).
Legal basis: Art. 6 (1)(a) GDPR. The measurement is part of what you consent to with the confirmation click; it is named expressly in the text of the confirmation email.
How to end it. Through the unsubscribe link in every message — after that you receive no further messages and nothing further is measured. Independently of that, most email programs can be set not to load images automatically; open measurement then does not take place.
Retention. This data sits in the sending logs of our service provider Brevo. No fixed period is set for it; it is kept for as long as the purpose described above persists. We delete it at your request — please write to the address given in section 1.
8. Recipients and processors
We do not pass your data to third parties for advertising purposes, and we do not sell it.
We use service providers who process data exclusively on our instructions (processing under Art. 28 GDPR). A data processing agreement is in place with each of them:
- Cloudflare, Inc. — delivery of the website
- Plausible Insights OÜ — audience measurement, servers in Germany
- Brevo GmbH, Köpenicker Str. 126, 10179 Berlin — forms, contact management, sending
- Microsoft Ireland Operations Limited — email, file storage, collaboration
- Anthropic — AI-assisted analysis and text work, see below
On the use of AI tools. We use an AI assistant to work with our own business data — to handle enquiries, condense notes, or produce analyses of our contacts. In doing so, your contact details and the content of your correspondence with us may be processed. The purpose is the same one for which we collected the data; it is not used to train third-party models.
We say this expressly because, unlike most processing, it cannot be inferred from the purpose. We do not transmit special categories of personal data under Art. 9 GDPR in the process.
9. Transfers to third countries, in particular the United States
We prefer providers that process within the European Union, and we have set our website up accordingly: hosting and audience measurement take place in the EU.
It cannot be avoided entirely. Individual services we use are offered by companies based outside the EU, in particular in the United States. We name that here rather than paraphrasing it.
What that means. In the United States, security authorities hold powers of access that go beyond what European law provides for, and data subjects from the EU do not have legal protection there to the same degree. A risk that authorities access transmitted data can therefore not be excluded entirely.
What we base the transfer on. Per provider, on one of the following grounds:
- an adequacy decision of the European Commission, where one exists for the recipient country or for the provider (Art. 45 GDPR), or
- the standard contractual clauses adopted by the Commission (Art. 46 (2)(c) GDPR), supplemented by technical and organisational safeguards.
Where we rely on standard contractual clauses, we assess before the transfer whether the law and practice in the recipient country conflict with compliance, and we document that assessment.
What we do in addition. The most effective measure is to transmit as little as possible. We do not give services processed in third countries any special categories of personal data under Art. 9 GDPR and no personnel data of third parties, and we transmit only what is necessary for the respective purpose.
Which providers are affected:
- Cloudflare, Inc. — United States, on the basis of the EU-US Data Privacy Framework. Cloudflare is certified under this framework; for certified transfers the European Commission has found an adequate level of protection. In addition, the standard contractual clauses are agreed, which take effect should the certification lapse.
- Anthropic — United States, on the basis of the EU standard contractual clauses (module 2). There is no certification under the Data Privacy Framework here, which is why we rely on the standard contractual clauses and have carried out the assessment under their clause 14.
- Brevo — the data is stored in the European Union (France, Germany, Belgium). For customer service and maintenance, Brevo group companies also access it from the United States and from India; for delivery and support, Brevo additionally uses providers in the United States. These transfers take place on the basis of the EU-US Data Privacy Framework or the standard contractual clauses respectively. The complete list of sub-processors used by Brevo forms part of the Brevo terms of use.
- Microsoft — United States, on the basis of the EU-US Data Privacy Framework. The data stored for our tenant in the services we use is located in Germany; individual processing steps, in support for instance, may touch other locations.
Audience measurement takes place exclusively on servers in Germany; no third-country transfer is involved there.
We will provide you with a copy of the standard contractual clauses and the associated assessment on request.
10. Retention in all other cases
Where this policy does not state a separate retention period for a processing operation, the following applies: we store your data for as long as it is required for the respective purpose. If the purpose ceases to apply, if you assert a justified request for erasure, or if you withdraw a consent, we delete the data — unless we are obliged or entitled to keep it.
Where we cannot delete data for legal reasons, we block it: we keep it until the period expires but no longer use it for any other purpose (restriction of processing under Art. 18 GDPR).
Statutory retention obligations that take precedence are in particular:
- ten years for books, records, accounting vouchers and documents relevant to taxation (section 147 (1) AO, section 257 (1) nos. 1 and 4, (4) HGB)
- six years for commercial letters and other documents (section 257 (1) nos. 2 and 3, (4) HGB)
- three years for documents required to defend against claims, counted from the end of the year in which the claim arose (sections 195, 199 BGB)
We review our retention periods at least once a year.
11. Your rights
You have the following rights in relation to us:
- Access (Art. 15 GDPR) — which data we process about you, for what purposes, for how long and to whom we pass it on
- Rectification (Art. 16 GDPR) — correction of inaccurate and completion of incomplete data
- Erasure (Art. 17 GDPR) — insofar as no statutory retention obligation or other ground stands in the way
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) — release of the data you provided in a common, machine-readable format
- Objection (Art. 21 GDPR) — against processing based on legitimate interests. You may object to the use of your data for direct marketing at any time and without giving reasons; we will then stop that use.
- Withdrawal of a consent (Art. 7 (3) GDPR) — at any time and without disadvantage
Please write to the address given in section 1. We respond within one month. If your request is extensive, we may extend this period by up to two months; in that case we will inform you of the extension and its reasons within the first month.
Handling your request is free of charge for you.
12. Right to complain
You have the right to complain to a data protection supervisory authority about the processing of your personal data. The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
You may also turn to the supervisory authority of your place of residence or work.
13. Automated decisions and profiling
We do not use your data for automated decision-making within the meaning of Art. 22 GDPR — no decision with legal effect concerning you is taken by a machine alone.
From the open and click data described in section 7, however, we do infer which topics interest you. We name that expressly rather than hiding it behind “no profiling”. You can put an end to it at any time, as described in section 7.