Data processing addendum

Data processing

You are the controller of your attendees' data. We are your processor. This is what that obliges us to do.

What this is and when it applies

This Addendum applies whenever we process personal data on your behalf — in practice, whenever your attendees use your concierge. It forms part of the Terms of Service. You do not need to sign it or ask for it; it applies automatically from the moment you start using the service.

You are the controller. We are the processor. Where this Addendum and the Terms of Service disagree about personal data, this Addendum wins.

If your procurement process needs a signed copy on paper, write to contact@pulsierlabs.com and we will sign this text. What we will not do is sign a different one quietly — the version here is the one the product actually implements, and a signed document that describes different behaviour would be worth less than this page.

Who you are dealing with

AskConcierge is operated under the trading name Pulsier Labs, established in Portugal. You can reach a person at contact@pulsierlabs.com.

Pulsier Labs is currently operated by an individual and is not a registered company. Two things a contract normally names are therefore not yet stated: the legal name for service (not yet stated) and the postal address (not yet stated). We would rather say this plainly than let a document imply a corporate form that does not exist. If you need a counterparty that is a registered entity before you can sign, write to us and say so — it is a reasonable thing to need, and it is the one thing standing between these documents and a signature.

We have not appointed a Data Protection Officer. On our reading we are not required to: we do not carry out large-scale systematic monitoring of people, and processing special categories of data is not a core activity of ours. That reading is ours, made without legal advice, and it is on the list of things we have asked a lawyer to check.

Language

This document exists in English only, and the English text is the one that governs. Our website, and the notice an attendee reads before asking a question, are available in English, Portuguese and Spanish. We would rather hand you one text we have read carefully than three that can drift apart, because a mistranslated clause in a document like this is not a wording problem — it is two different promises.

We act on your instructions

We process personal data only on your documented instructions, which are: these documents, the settings you choose in the product, and anything else you tell us in writing. That includes transfers to another country.

If we think an instruction of yours breaks data protection law, we will tell you and we may decline to carry it out.

If we are required by law to process personal data for some other reason, we will tell you first unless the law forbids us from telling you.

Annex I — what is actually processed

Subject matterRunning an AI concierge that answers your attendees’ questions from information you provide.
DurationFor as long as your account is open, plus the retention periods set out below.
Nature and purposeStoring, retrieving, analysing and generating answers; producing aggregate reports for you; alerting you to questions nobody has answered.
Categories of data subjectAttendees at your event; the people named in the content you provide, such as speakers; the people on your own team you invite.
Types of personal dataQuestions attendees type, which may contain anything they choose to write; a pseudonymous per-event browser identifier; language and timing; an email address only where an attendee typed one in to be replied to; survey answers; and whatever personal data is contained in the sources you give us.
Special categoriesNot sought, and not a purpose of the service. Attendees may nevertheless disclose health, disability or similar information in a question, because it is often the reason they are asking. We classify topics rather than people, and we hold reports to an aggregation floor.
FrequencyContinuous, for as long as your concierge is published.

Confidentiality and who may see it

Anyone who can reach your data is bound to confidentiality and only gets access where they need it. Support access to a customer workspace is capped below owner — support can administer a workspace, never transfer or delete it — and every change made through it is recorded against a person, a time and a reason. You can ask us for that record for your own workspace.

Annex II — the security measures

These are the measures in place today, not a list of intentions. Where a measure is absent, it is absent from this list.

MeasureWhat is in place
Encryption in transitTLS on every connection, to the product and between us and our providers.
Encryption at restProvided by our database and hosting providers.
Access controlNo browser ever reaches the database. All access goes through our own server; the privileged key exists only there. Organizer access is by workspace and project membership.
Tenant isolationEnforced at a single checkpoint in code rather than per screen, with automated tests that attempt to read across the boundary and fail the build if they succeed.
Rate limitingPer person, on a server-issued signed identifier, sized so a crowd on one venue network is never mistaken for one abusive caller.
Spend limitsA per-concierge daily ceiling and a monthly allowance, so a runaway cost cannot be created through your account.
Prompt-injection handlingAll ingested content is kept in delimited blocks and never merged into the instructions the model follows, so a crawled page cannot issue commands.
DeletionA scheduled job runs daily and enforces the retention periods below. It reports when it could not finish, so a silent failure is visible.
Logging and auditSupport access, administrative actions and changes to a concierge are recorded with the actor, the time and the action.
MonitoringAutomated checks on ingestion failures, delivery failures, spend and answer quality, alerting a human.
BackupsPoint-in-time recovery as provided by our database provider.
PersonnelA very small team. There is no separate security function, and we are not going to imply one.

We hold no security certification — no ISO 27001, no SOC 2. If your process requires one, we do not meet it today, and we would rather you knew that at the start of a procurement than at the end of one.

Sub-processors

You give general authorisation for us to use the sub-processors listed below. We remain responsible for what they do, and each is engaged under terms that impose obligations equivalent to these.

ProviderWhat they do for usWhereCan they see an attendee’s question?
SupabaseThe database and file storage the product runs on.EU — AWS eu-west-1 (Dublin).Yes — as typed
VercelHosting and the serverless functions that answer questions.EU — the deployment is pinned to dub1 (Dublin).Yes — as typed
OpenRouterRoutes model calls to the language and vision models that write answers.United States.Yes — as typed
FirecrawlReads the organizer’s own website so the concierge can answer from it.United States.No
TavilySearches the public web when an organizer turns that on, for questions their own content cannot answer. Only when the organizer has enabled web search for that concierge.United States.Yes — but reworded by the model, not copied
ResendSends email — sign-in links, invitations, and alerts to the organizer.EU — eu-west-1.No
PostHogProduct analytics on our own marketing site and the organizer app, and the traces we use to debug and improve answers.EU Cloud.Yes — as typed

That list is generated from the register the product itself uses, so it cannot lag behind the code. We will give organizers notice before adding or replacing a sub-processor that can see attendee content, and you may object on reasonable data-protection grounds; if we cannot resolve it, you may terminate the affected concierge and we will refund the unused part of what you have paid.

Which language model answers a question is configuration rather than documentation — it can be changed by us without a code release. The register resolves what is actually in use, which is why it is a register in the product and not a paragraph in a document.

International transfers

Hosting, the database and email are in the EU. The model router, the web search provider and the crawler are in the United States, and personal data reaching them does so under the European Commission’s Standard Contractual Clauses contained in those providers’ terms.

We have not carried out a documented transfer impact assessment for each provider. We are telling you that rather than leaving you to assume it exists.

Helping you meet your own obligations

  • Data subject requests — if an attendee comes to us, we will point them at you and help you answer. We will not respond on your behalf unless you ask us to.
  • Impact assessments and prior consultation — we will give you the information about the service that you reasonably need.
  • Breaches — we will tell you without undue delay after becoming aware of a personal data breach affecting your data, with what we know and what we are doing.
  • Audits — we will answer your questions and provide what we have. We are a very small team, and an on-site audit is something we will accommodate where it is reasonable and at your cost.

Retention and deletion

WhatHow long
Attendee conversations and messages90 days from the last message, then deleted
Unanswered questions, in the attendee’s own words90 days, then deleted
An attendee’s reply addressDeleted as the message is sent; deleted anyway if it never can be
A decided request to join a private concierge14 days, then deleted
An archived concierge and everything it knows7 days, then deleted
Aggregate counts and topic statisticsRetained, and containing no personal data

On termination we delete your personal data. You can trigger it yourself by archiving the concierge, and the same job does the work either way.

Liability

The liability limits in the Terms of Service apply to this Addendum. Nothing here limits a data subject’s rights against either of us under data protection law.

How to reach us

For anything in this policy — a question, a request about your own data, or a complaint — write to contact@pulsierlabs.com and put “Privacy” in the subject line. A person reads it. We aim to answer substantively within 30 days, and to tell you inside 5 working days that we have it.

If you are not satisfied with how we have handled something, you can complain to a data protection authority. Ours is the Comissão Nacional de Proteção de Dados (CNPD) (https://www.cnpd.pt). You can also complain to the authority where you live or work.

Something missing here? The FAQ covers the questions people ask most.

Version 1.0 · in effect from 23 August 2026 · English is the governing text

These documents were written by the people who built the product, against the code that implements them, and have not yet been reviewed by a lawyer. Every number in them is read from the part of the system that enforces it. Where we are unsure, we say so on the page rather than leaving it out. All documents