Effective date: 23 August 2026 · Notice version: 2026-08-23
Who is responsible
Avonlea Systems SpA operates pulsyr.dev and the hosted application at app.pulsyr.dev. Privacy requests may be sent to legal@pulsyr.dev.
Data we process
For hosted accounts we process the name, verified email address and stable account identifier supplied by GitHub or Google; account, subscription and onboarding records; project content and audit history; API-token hashes and integration configuration; and limited security and operational logs. Raw MCP tokens are shown once and are not stored. OAuth rate limiting uses a temporary keyed digest instead of retaining a raw IP address.
Why we process it
We use this data to create and authenticate the account, provide the requested project service, enforce plan limits, secure and troubleshoot the platform, prevent abuse, communicate material service or legal changes, and comply with applicable obligations. We do not sell personal data, run advertising profiles, or use private project content for advertising.
Providers and international processing
GitHub or Google handles the identity step under its own terms. Hosting, monitoring, email and infrastructure providers may process limited data on our behalf and may operate in other jurisdictions. We limit access to what each provider needs and apply contractual and technical safeguards appropriate to the service.
Payments
Paid plans are sold through Paddle.com Market Limited, which acts as our authorised reseller and Merchant of Record. Paddle collects your billing and payment data directly, as an independent controller of that data, not as a processor acting on our behalf. Card numbers and tax identifiers never pass through Pulsyr and we never store them. What we keep is the subscription state Paddle reports back to us: the plan, its status, and the Paddle customer and subscription identifiers needed to link them to your account. Paddle's own processing is governed by the Paddle Privacy Policy.
Retention and choices
Account and project data is retained while the hosted account remains active and as reasonably needed for security, backup recovery, dispute handling or legal obligations. You may request access, correction, deletion, opposition or portability where applicable by contacting the address above. We may need to verify that the requester controls the account before acting.
Public website
The public website may use a lightweight Plausible Analytics configuration for aggregate page views and a small set of navigation events. It does not use advertising cookies or send private application content to public-site analytics.
Self-hosted installations
A self-hosted Pulsyr installation is operated independently. Its operator chooses infrastructure, integrations, access rules, retention, backups and legal basis, and is responsible for its own privacy notice.
Changes
Material changes will be published here with a new version date. When a change requires renewed acceptance for hosted accounts, Pulsyr will request it before continued use.