Privacy Policy

Data Duke Project Consulting e.U.

Last Updated: October 2, 2026 · Effective Date: October 2, 2026

Who We Are

Data Duke Project Consulting e.U.
Lehenstr. 12/2/3 OG, 1220 Vienna, Austria
UID: ATU77808106
Email: privacy@dataduke.net
Website: https://dataduke.net

We are the operator of PulseCheck, a software-as-a-service platform providing agile transformation tools, team performance monitoring, process compliance auditing, and AI-driven insights for development teams.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you:

  • Visit our website at https://dataduke.net
  • Use the PulseCheck platform and its features
  • Contact us via email or other channels
  • Participate in our Beta Program

We are committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Austrian Data Protection Act (Datenschutzgesetz — DSG).

1. Data Controller

The data controller responsible for your personal data is:

Data Duke Project Consulting e.U.
Lehenstr. 12/2/3 OG, 1220 Vienna, Austria
UID: ATU77808106
Email: privacy@dataduke.net

2. What Personal Data We Collect

We collect different categories of personal data depending on how you interact with us.

2.1 Account and Registration Data

When you register for PulseCheck or our Beta Program, we collect:

  • Full name and job title
  • Company name and company address
  • Business email address
  • Password (stored as a cryptographic hash — we never see your actual password)
  • Country and time zone
  • Profile picture (optional)

Legal basis: Article 6(1)(b) GDPR — necessary for the performance of a contract.

2.2 Billing and Payment Data

When you subscribe to a paid plan, we collect:

  • Billing contact name and email
  • Company VAT number (if applicable)
  • Billing address
  • Subscription and invoice history

Payment card data is processed directly by Stripe, Inc. and is never stored on our systems. We store only a Stripe customer ID and subscription reference.

Legal basis: Article 6(1)(b) GDPR — necessary for the performance of a contract; Article 6(1)(c) GDPR — compliance with legal obligations (invoicing, tax).

2.3 Employee and Team Member Data (Processed on Behalf of Customers)

When your organization uses PulseCheck, we process personal data of your team members on your behalf as a Data Processor under a Data Processing Agreement (DPA). This data includes:

  • Names, usernames, and email addresses (from integrated tools)
  • Job titles, roles, and team assignments
  • Work activity data: code commits, pull requests, Jira tickets, code reviews
  • Performance and compliance metrics derived from the above

2.4 Usage and Technical Data

When you use the platform, we automatically collect:

  • IP address and approximate location (country/city level)
  • Browser type, operating system, and device type
  • Session start and end times
  • Features accessed and actions performed
  • Error logs and diagnostic information

Legal basis: Article 6(1)(f) GDPR — legitimate interest (maintaining service security, improving the platform, and preventing abuse).

2.5 Communications Data

When you contact us (email, support tickets, feedback), we collect:

  • Your name and email address
  • The content of your message
  • Any attachments you send us
  • Communication timestamps

Legal basis: Article 6(1)(b) GDPR — necessary to respond to your request; Article 6(1)(f) GDPR — legitimate interest (providing support, maintaining records).

2.6 Marketing Data (Opt-In Only)

If you explicitly consent to marketing communications, we collect:

  • Name and email address
  • Marketing preferences and opt-in/opt-out history

Legal basis: Article 6(1)(a) GDPR — consent. You may withdraw consent at any time by contacting marketing@dataduke.net or clicking "unsubscribe" in any marketing email.

3. How We Use Your Personal Data

3.1 Providing the Service

  • Creating and managing your account
  • Providing access to PulseCheck features
  • Processing integrations with your development tools (GitHub, Jira, GitLab, etc.)
  • Generating compliance analytics, dashboards, and AI-driven insights
  • Sending transactional emails (account confirmation, password reset, notifications)
  • Processing payments and generating invoices

3.2 AI Processing — Mandatory Masking of Personal Data

Before any personal data is sent to an AI provider — whether PulseCheck's default provider or an AI provider your organization has configured itself — PulseCheck automatically masks it. This cannot be turned off.

  1. Names of your organization's PulseCheck users and of people named in issue fields (such as assignee or reporter), email addresses, phone numbers, IBANs, payment-card numbers, IP addresses, access credentials and user mentions are replaced with placeholders (for example "[PERSON_1]").
  2. The AI provider receives only the placeholders. The real values are put back only in the answer delivered to your organization — in PulseCheck, or in the Slack or Microsoft Teams channels your organization has connected.
  3. Credentials are never put back; they appear as "[redacted credential]".
  4. Masking recognizes personal data by its format, by the field it appears in, and by matching the names of your organization's PulseCheck users. A name written only in free text (for example inside an issue description) may not be recognized — in particular the name of someone who is not a PulseCheck user in your organization, or a first or last name used on its own.

In addition, your organization can switch on pseudonymization of stored data. This replaces the names and email addresses in person fields of synced data (such as assignee, reporter and comment authors) with pseudonymous codes (e.g. "User #A3F2", derived with SHA-256 and an organization-specific salt); free text such as issue descriptions is not changed. The originals are kept encrypted in our EU database. Each mapping carries an expiry date — by default 7 days after a sync last refreshed it (configurable) — after which it is eligible for deletion.

3.3 Customer Support

  • Responding to your inquiries and support requests
  • Troubleshooting bugs and technical issues
  • Providing onboarding assistance

3.4 Security and Fraud Prevention

  • Detecting and preventing unauthorized access, abuse, and security threats
  • Maintaining security audit logs
  • Investigating suspected security incidents

3.5 Legal and Compliance Obligations

  • Complying with applicable laws and regulations (tax, accounting, GDPR)
  • Responding to lawful requests from public authorities
  • Establishing, exercising, or defending legal claims

3.6 Service Improvement (Anonymized/Aggregated Only)

  • Analyzing anonymized usage patterns to improve features
  • Generating industry benchmarks (aggregated data only, no individual identification)
  • Internal research and product development

We never use identifiable personal data for marketing analytics or product improvement without your consent.

4. Masking of Personal Data Before AI Processing

How It Works

Whenever a PulseCheck feature uses an AI model, the following happens automatically — it cannot be turned off:

StepWhat Happens
1. Request preparedPulseCheck assembles the data an AI feature needs
2. MaskingNames of your PulseCheck users and of people named in issue fields, email addresses, phone numbers, IBANs, payment-card numbers, IP addresses, access credentials and user mentions are replaced with placeholders
3. AI processingOnly the masked request is sent to the AI provider
4. RestoringPlaceholders in the answer are replaced with the real values before it is shown in PulseCheck or delivered to your organization's connected Slack or Microsoft Teams channels; credentials are never restored

What AI Providers See

  • ✅ "[PERSON_1] has 2 compliance violations"
  • ✅ Aggregated team metrics (percentages, counts)
  • ✅ Issue keys (e.g., "PROJ-123")
  • ✅ The content an AI feature works on — issue titles, descriptions and fields, chat, Slack and Teams messages, and documents you submit — with personal data masked
  • ❌ Names of your PulseCheck users and of people named in issue fields
  • ❌ Email addresses, phone numbers, IBANs, payment-card numbers and IP addresses
  • ❌ Access credentials

A name that appears only in free text may not be recognized — in particular the name of someone who is not a PulseCheck user in your organization, or a first or last name used on its own.

Why This Matters for You

Personal data is masked before it reaches any AI provider. Where AI processing involves non-EU providers, only masked data is transferred, under appropriate safeguards (SCCs / EU-U.S. DPF). This significantly reduces your GDPR risk profile and simplifies your own compliance obligations.

5. Data Sharing and Third Parties

We do not sell, rent, or share your personal data for third-party marketing purposes. We share personal data only in the following circumstances.

5.1 Sub-processors

We engage a number of sub-processors to help us deliver the Service. Each sub-processor is contractually bound by data protection obligations equivalent to those in our DPA. The current list is available on request — email privacy@dataduke.net.

We will notify you of any intended changes to our sub-processor list at least 30 days in advance.

5.2 Legal Requirements

We may disclose personal data if required by law, court order, or request from a competent authority.

5.3 Business Transfers

If Data Duke is involved in a merger, acquisition, or asset sale, personal data may be transferred to the successor entity, subject to the same privacy protections.

5.4 With Your Consent

We may share personal data with third parties if you have provided explicit prior consent.

6. International Data Transfers

Where Your Data Is Stored

All personal data is primarily stored and processed in the European Union — specifically in Supabase's Frankfurt, Germany (eu-central-1) infrastructure. Some sub-processors store limited data in the US: email delivery metadata and logs (Resend), web hosting logs including IP addresses (Vercel), and marketing measurement data (LinkedIn).

Limited US Transfers

  • AI processing: Only masked data (see Section 4) is transferred outside the EU, under Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework
  • Payment processing: Covered by EU-U.S. Data Privacy Framework certification and SCCs
  • Notification webhooks: Covered by SCCs; include compliance summaries and recipient email addresses
  • Email delivery and web hosting: Covered by the EU-U.S. Data Privacy Framework and SCCs

Transfer Safeguards

For all transfers outside the EEA, we ensure appropriate safeguards: Standard Contractual Clauses (SCCs), EU-U.S. Data Privacy Framework (DPF) certification, and Transfer Impact Assessments (TIAs).

7. Data Retention

Data CategoryRetention PeriodReason
Account dataDuration of account + 2 yearsLegal obligations, dispute resolution
Signed legal documents (ToS/DPA/Subprocessor List acceptances)Duration of account + 2 yearsContract evidence, dispute resolution
Billing/invoice data7 years from invoice dateAustrian tax law (BAO §132)
Employee performance data (active)Duration of subscriptionService provision
Employee performance data (historical)Up to 24 monthsTrend analysis
Deactivated user data90 daysReactivation possibility
PII pseudonym mappingsExpire 7 days after the last sync refresh (default, configurable)Re-identification for your organization; eligible for deletion after expiry
AI conversation history90 daysService improvement, debugging
Compliance audit log (rule evaluations, configuration changes, sign-offs)At least 5 years from the eventEvidence for your own audits; the log is append-only and the database rejects edits and deletes
Security audit logsIndefinitelySecurity, legal compliance
Marketing dataUntil consent withdrawnConsent-based processing
Support communications3 years from resolutionLegal claims, quality assurance

When the retention period expires, we securely delete or anonymize your personal data.

8. Business Customers — Employee Data

Our Role as Data Processor

When your organization uses PulseCheck to monitor team performance, we process personal data of your employees on your behalf. You (the Customer) are the Data Controller; we (Data Duke) are the Data Processor. This relationship is governed by our DPA.

Your Responsibilities as Employer/Controller

Under GDPR, you are responsible for:

  • Lawful basis: Ensuring you have a valid legal basis for monitoring employee performance
  • Transparency: Informing your employees about the monitoring via internal privacy notices
  • Works council / Betriebsrat: In Austria and other EU countries, you may need works council approval
  • Data minimization: Only connecting integrations and enabling data collection necessary for your purposes

What We Do to Protect Your Employees' Privacy

  • Mandatory masking of personal data before any AI processing (always on, cannot be disabled)
  • EU data residency (Frankfurt, Germany)
  • No employee data used to train AI models
  • No employee data shared with other organizations
  • Employees' data automatically deleted when removed from the platform (within 90 days)

9. Your Rights as a Data Subject

Under GDPR, you have the following rights regarding your personal data:

9.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and to receive a copy.

9.2 Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete data completed.

9.3 Right to Erasure (Article 17)

You have the right to request deletion of your personal data where the data is no longer necessary, you withdraw consent, you object to processing, or the data has been unlawfully processed.

9.4 Right to Restriction of Processing (Article 18)

You have the right to request that we restrict processing in certain circumstances.

9.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format (CSV or JSON).

9.6 Right to Object (Article 21)

You have the right to object to processing based on legitimate interests. You have an absolute right to object to processing for direct marketing purposes at any time.

9.7 Rights Related to Automated Decision-Making (Article 22)

We do not make solely automated decisions that produce legal effects. AI-generated compliance insights are always presented to human managers/administrators.

9.8 Right to Withdraw Consent (Article 7(3))

Where processing is based on consent, you have the right to withdraw consent at any time.

9.9 How to Exercise Your Rights

Contact us at: privacy@dataduke.net

We will respond within one (1) month. We may request verification of your identity before processing your request.

9.10 Right to Lodge a Complaint

Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42, 1030 Wien, Austria
Email: dsb@dsb.gv.at · Phone: +43 1 52 152-0 · Website: www.dsb.gv.at

10. Security

Technical Measures

  • Encryption in transit: TLS 1.3 for all data transmission
  • Encryption at rest: AES-256 for all stored data (via Supabase)
  • Mandatory masking of personal data (names, email addresses, phone numbers, IBANs, card numbers, IP addresses, credentials) before any AI processing; optional SHA-256 pseudonymization of stored data
  • EU data residency: All data stored in Frankfurt, Germany
  • Multi-factor authentication (MFA): Available for all user accounts
  • Role-based access control (RBAC): Minimum necessary access per user role

Organizational Measures

  • Annual security awareness training for all personnel
  • Confidentiality agreements with all staff and contractors
  • Quarterly GDPR compliance reviews
  • Privacy impact assessments (PIAs) for new features
  • Documented incident response procedures

Infrastructure Certifications (via Supabase)

  • ISO 27001 certified
  • SOC 2 Type II audited
  • Automated daily backups with 7-day retention (EU region)

11. Cookies and Tracking

11.1 What We Use

PulseCheck uses only strictly necessary cookies:

CookiePurposeDuration
sb-auth-tokenSupabase authentication sessionSession / 24 hours
sb-refresh-tokenSession refresh token7 days
theme-preferenceUI dark/light mode setting1 year
cookie-consentRecords your cookie consent decision1 year

11.2 What We Do Not Use

  • ❌ No Google Analytics or other third-party analytics
  • ❌ No advertising or tracking cookies
  • ❌ No social media pixels
  • ❌ No cross-site tracking

12. Children's Privacy

PulseCheck is designed for use by businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18.

13. Links to Third-Party Websites

Our website and Service may contain links to third-party websites and services. We are not responsible for the privacy practices of such third parties.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date, notify you via email at least 14 days before changes take effect, and display a prominent notice in the Service.

Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

15. Contact Us

Data Duke Project Consulting e.U.
Lehenstr. 12/2/3 OG, 1220 Vienna, Austria
UID: ATU77808106

General: web@dataduke.net
Support: support@dataduke.net
Privacy / Data Protection: privacy@dataduke.net
Legal / Contracts: legal@dataduke.net
Website: https://dataduke.net
Sub-processor List: available on request — email privacy@dataduke.net

We aim to respond to all privacy-related inquiries within five (5) business days.