Privacy notice
Version 2026-10-02 · 2 October 2026
1. Who is responsible
Christopher Healey, a UK sole trader trading as PulseWatch, controls account, website and service-administration information. Business correspondence address: 35 Cardamon Road, Saffron Walden, CB11 3FE, England. Contact support@pulsewatch.ai. PulseWatch serves adults worldwide, including individuals and businesses.
Use monitor names and messages without other people's personal information, sensitive records or secrets. We do not offer this service for processing third-party personal datasets under a customer data-processing agreement. Contact Christopher Healey directly about data protection.
2. Information received and used
- Account: email, password hash, account identifier, creation time, plan and manual billing-override state. Your password is processed to create or check its hash; the account database stores the hash, not the original password.
- Monitoring: names, schedules, private ping tokens, monitor ownership, pause/resume state, check/alert/instability state, run identifiers, outcomes, times and durations. Optional failure messages are limited to 1,000 characters. Replaced runs remain internal history. We do not read your job files or outputs ourselves.
- Billing: Stripe customer, subscription, Checkout, invoice and event identifiers; confirmed paid period; subscription state; minimal processing-error codes; versioned purchase information and the timestamp of your express immediate-start request. Plan and monitor-selection audit records include the affected account, operator where applicable, time, changes and a short reference.
- Support: your email, correspondence and any attachments you send. The monitored support address forwards through Cloudflare Email Routing to Christopher Healey's personal iCloud inbox. Do not send a password, private ping URL, card details or unnecessary personal records.
- Connections: infrastructure providers receive IP addresses, request URLs and headers. There are no dedicated account-database IP or user-agent fields; this does not mean providers keep no request records. Ping credentials are in URL paths and optional failure messages in URL queries, so infrastructure logging needs particular care.
Stripe collects payment and billing details directly, including payment-security and device information, under its own Privacy Policy. PulseWatch does not receive or store full card numbers or card security codes. Stripe Managed Payments may act as merchant of record for eligible transactions. It has its own payment, compliance and tax responsibilities; that does not make it the sole controller for every PulseWatch activity.
Account information is needed for login; settings and pings are needed to monitor jobs. Diagnostic message text is optional. Billing details are needed only for a paid purchase. There is no newsletter or CRM and no newsletter signup.
3. Purposes and lawful bases
For an individual account holder, necessary account, monitoring, alert, support and subscription administration is used to perform the service contract, including a Free account (UK GDPR Article 6(1)(b)). An organisation's staff contact is not automatically a party to that contract; administration of business contacts and account/security investigations relies on legitimate interests in providing and protecting a reliable service (Article 6(1)(f)). Data-rights handling relies on applicable legal obligations (Article 6(1)(c)); billing/accounting records are retained under a legal obligation only where one actually applies.
These bases are purpose-specific; agreeing to Terms is not blanket privacy consent. PulseWatch does not use the information described here for marketing or sell it.
4. Recipients and international processing
Render hosts the application, independent watchdog and PostgreSQL database in Oregon, United States. Resend delivers alert email to your account address, receiving the recipient address, monitor name and generated health/instability text. Current alert payloads do not include the raw failure message or private ping token. Resend states that customer data is stored in the United States regardless of sending region. Your own mailbox provider also receives delivered alerts.
Render Services, Inc., Resend's Plus Five Five, Inc. and Cloudflare, Inc. are used under their standard service agreements and incorporated Render, Resend and Cloudflare data-processing agreements. Those agreements describe their international-transfer provisions, including the UK Addendum to the EU standard contractual clauses and, where applicable, the UK Extension to the EU–US Data Privacy Framework. This notice does not claim UK-only storage or that every provider setting or certification has been independently audited.
Stripe handles payment and subscription data, with its own controller and processor responsibilities depending on the activity. Stripe Managed Payments acts as merchant of record for eligible purchases. Stripe's Data Processing Agreement, Data Transfer Agreement and Privacy Policy describe its processing, international transfers and independently retained payment records.
Cloudflare handles website/network services and forwards support email to Christopher Healey's personal Apple iCloud mailbox. The operator has checked this forwarding and monitors the inbox. Apple receives the correspondence under its iCloud terms and Privacy Policy. The contractual coverage of this personal mailbox for PulseWatch support correspondence remains under review; no separate processor agreement for that use is claimed. Mailbox and synced-device copies are included in the operator's manual retention review.
Christopher Healey accesses account and service records for administration and support. The watchdog can send empty start/success/failure requests to a separately configured heartbeat endpoint, with no customer payload. Its production configuration and recipient, provider log/export settings, Resend tracking settings and some backup/copy expiry settings remain under review. Contact support@pulsewatch.ai for the available recipient and safeguard details. No unverified location, tracking setting or expiry period is promised.
5. Retention and deletion
The application currently has no automatic age-based deletion of accounts, monitors or runs, including superseded runs. Free's seven-day history filter hides older runs; it does not erase them. Paid history has no age filter; all plans display at most 100 recent runs per monitor.
Deleting a monitor removes its monitor and run rows from the live database. This does not cancel billing, recall delivered email, erase Stripe's independently required records or immediately erase backup copies. Account closure and rights requests use the manual process below.
Christopher Healey reviews retained records at least annually and when an account closes or a deletion request is received. The review considers whether each record remains necessary for the service, an unresolved support request, payment/refund dispute, security investigation or a specific accounting or legal obligation. Records without a continuing purpose are deleted. Closed-account monitoring data is removed after any requested export and necessary dispute or security investigation are completed. Minimal billing, contract and audit records remain only while necessary for the applicable obligation or dispute, with the reason and next review recorded. Superseded runs and optional diagnostic text are included in the review; there is no promise of permanent storage.
Support correspondence and forwarded mailbox copies are reviewed after a request is resolved and at the annual review; unneeded copies are removed. Provider logs and backups can retain separate copies. Actual account expiry settings and operator-held exports remain under review, so no unverified expiry period is promised. A necessary backup can contain a deleted record until it is removed or expires. The operator reapplies deletions to any restored database before normal use resumes. Stripe may retain separate records for its own payment and legal purposes.
7. Security
The production website uses HTTPS. The application hashes passwords, generates random ping tokens, scopes customer monitor access to the account, restricts owner controls, protects browser POSTs with CSRF and verifies Stripe signatures against raw requests. These are safeguards, not a guarantee against every breach or loss. Keep passwords and ping URLs confidential.
Provider access, infrastructure logging and backup protection remain operational review items. No end-to-end encryption or independent security certification is claimed.
8. Your rights and the manual request process
Depending on the applicable law and basis, you may request access, correction, erasure, restriction and portability, and object to legitimate-interests processing. Rights have conditions and exceptions; we must explain any refusal. If optional processing relies on consent, it can be withdrawn without affecting prior lawful use. You can complain directly to the UK Information Commissioner's Office, without first complaining to us, or to an applicable authority in your country.
Email support@pulsewatch.ai or write to Christopher Healey at the address above. No account or special form is required. Tell us the request and relevant account email; do not send passwords, private tokens or card details. The owner handles requests manually, may ask for proportionate identity information before disclosure, clarifies scope, checks application and relevant provider records, and arranges a secure copy, correction or deletion where required. An account-closure request also requests cancellation of renewal, which is handled separately in Stripe.
There is no self-service account-deletion/export or password-reset route. Requests are normally free. Under UK data-protection rules responses are required without undue delay, normally within one month, subject to applicable identity/clarification requirements, exceptions and explained extensions. Christopher Healey performs proportionate identity checks, arranges secure data delivery and handles deletion, separate billing cancellation/refunds and reapplication of deletions after a database restore.
9. Changes
This notice carries a version/date. Material processing changes will be explained through the service or email as appropriate before new processing where required. A notice change does not itself supply a new lawful basis.