Privacy Policy
Data Duke Project Consulting e.U.
Last Updated: October 2, 2026 · Effective Date: October 2, 2026
Who We Are
Data Duke Project Consulting e.U.
Lehenstr. 12/2/3 OG, 1220 Vienna, Austria
UID: ATU77808106
Email: privacy@dataduke.net
Website: https://dataduke.net
We are the operator of PulseCheck, a software-as-a-service platform providing agile transformation tools, team performance monitoring, process compliance auditing, and AI-driven insights for development teams.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you:
- Visit our website at https://dataduke.net
- Use the PulseCheck platform and its features
- Contact us via email or other channels
- Participate in our Beta Program
We are committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Austrian Data Protection Act (Datenschutzgesetz — DSG).
1. Data Controller
The data controller responsible for your personal data is:
Data Duke Project Consulting e.U.
Lehenstr. 12/2/3 OG, 1220 Vienna, Austria
UID: ATU77808106
Email: privacy@dataduke.net
2. What Personal Data We Collect
We collect different categories of personal data depending on how you interact with us.
2.1 Account and Registration Data
When you register for PulseCheck or our Beta Program, we collect:
- Full name and job title
- Company name and company address
- Business email address
- Password (stored as a cryptographic hash — we never see your actual password)
- Country and time zone
- Profile picture (optional)
Legal basis: Article 6(1)(b) GDPR — necessary for the performance of a contract.
2.2 Billing and Payment Data
When you subscribe to a paid plan, we collect:
- Billing contact name and email
- Company VAT number (if applicable)
- Billing address
- Subscription and invoice history
Payment card data is processed directly by Stripe, Inc. and is never stored on our systems. We store only a Stripe customer ID and subscription reference.
Legal basis: Article 6(1)(b) GDPR — necessary for the performance of a contract; Article 6(1)(c) GDPR — compliance with legal obligations (invoicing, tax).
2.3 Employee and Team Member Data (Processed on Behalf of Customers)
When your organization uses PulseCheck, we process personal data of your team members on your behalf as a Data Processor under a Data Processing Agreement (DPA). This data includes:
- Names, usernames, and email addresses (from integrated tools)
- Job titles, roles, and team assignments
- Work activity data: code commits, pull requests, Jira tickets, code reviews
- Performance and compliance metrics derived from the above
2.4 Usage and Technical Data
When you use the platform, we automatically collect:
- IP address and approximate location (country/city level)
- Browser type, operating system, and device type
- Session start and end times
- Features accessed and actions performed
- Error logs and diagnostic information
Legal basis: Article 6(1)(f) GDPR — legitimate interest (maintaining service security, improving the platform, and preventing abuse).
2.5 Communications Data
When you contact us (email, support tickets, feedback), we collect:
- Your name and email address
- The content of your message
- Any attachments you send us
- Communication timestamps
Legal basis: Article 6(1)(b) GDPR — necessary to respond to your request; Article 6(1)(f) GDPR — legitimate interest (providing support, maintaining records).
2.6 Marketing Data (Opt-In Only)
If you explicitly consent to marketing communications, we collect:
- Name and email address
- Marketing preferences and opt-in/opt-out history
Legal basis: Article 6(1)(a) GDPR — consent. You may withdraw consent at any time by contacting marketing@dataduke.net or clicking "unsubscribe" in any marketing email.
3. How We Use Your Personal Data
3.1 Providing the Service
- Creating and managing your account
- Providing access to PulseCheck features
- Processing integrations with your development tools (GitHub, Jira, GitLab, etc.)
- Generating compliance analytics, dashboards, and AI-driven insights
- Sending transactional emails (account confirmation, password reset, notifications)
- Processing payments and generating invoices
3.2 AI Processing — Mandatory Masking of Personal Data
Before any personal data is sent to an AI provider — whether PulseCheck's default provider or an AI provider your organization has configured itself — PulseCheck automatically masks it. This cannot be turned off.
- Names of your organization's PulseCheck users and of people named in issue fields (such as assignee or reporter), email addresses, phone numbers, IBANs, payment-card numbers, IP addresses, access credentials and user mentions are replaced with placeholders (for example "[PERSON_1]").
- The AI provider receives only the placeholders. The real values are put back only in the answer delivered to your organization — in PulseCheck, or in the Slack or Microsoft Teams channels your organization has connected.
- Credentials are never put back; they appear as "[redacted credential]".
- Masking recognizes personal data by its format, by the field it appears in, and by matching the names of your organization's PulseCheck users. A name written only in free text (for example inside an issue description) may not be recognized — in particular the name of someone who is not a PulseCheck user in your organization, or a first or last name used on its own.
In addition, your organization can switch on pseudonymization of stored data. This replaces the names and email addresses in person fields of synced data (such as assignee, reporter and comment authors) with pseudonymous codes (e.g. "User #A3F2", derived with SHA-256 and an organization-specific salt); free text such as issue descriptions is not changed. The originals are kept encrypted in our EU database. Each mapping carries an expiry date — by default 7 days after a sync last refreshed it (configurable) — after which it is eligible for deletion.
3.3 Customer Support
- Responding to your inquiries and support requests
- Troubleshooting bugs and technical issues
- Providing onboarding assistance
3.4 Security and Fraud Prevention
- Detecting and preventing unauthorized access, abuse, and security threats
- Maintaining security audit logs
- Investigating suspected security incidents
3.5 Legal and Compliance Obligations
- Complying with applicable laws and regulations (tax, accounting, GDPR)
- Responding to lawful requests from public authorities
- Establishing, exercising, or defending legal claims
3.6 Service Improvement (Anonymized/Aggregated Only)
- Analyzing anonymized usage patterns to improve features
- Generating industry benchmarks (aggregated data only, no individual identification)
- Internal research and product development
We never use identifiable personal data for marketing analytics or product improvement without your consent.
4. Masking of Personal Data Before AI Processing
How It Works
Whenever a PulseCheck feature uses an AI model, the following happens automatically — it cannot be turned off:
| Step | What Happens |
|---|---|
| 1. Request prepared | PulseCheck assembles the data an AI feature needs |
| 2. Masking | Names of your PulseCheck users and of people named in issue fields, email addresses, phone numbers, IBANs, payment-card numbers, IP addresses, access credentials and user mentions are replaced with placeholders |
| 3. AI processing | Only the masked request is sent to the AI provider |
| 4. Restoring | Placeholders in the answer are replaced with the real values before it is shown in PulseCheck or delivered to your organization's connected Slack or Microsoft Teams channels; credentials are never restored |
What AI Providers See
- ✅ "[PERSON_1] has 2 compliance violations"
- ✅ Aggregated team metrics (percentages, counts)
- ✅ Issue keys (e.g., "PROJ-123")
- ✅ The content an AI feature works on — issue titles, descriptions and fields, chat, Slack and Teams messages, and documents you submit — with personal data masked
- ❌ Names of your PulseCheck users and of people named in issue fields
- ❌ Email addresses, phone numbers, IBANs, payment-card numbers and IP addresses
- ❌ Access credentials
A name that appears only in free text may not be recognized — in particular the name of someone who is not a PulseCheck user in your organization, or a first or last name used on its own.
Why This Matters for You
Personal data is masked before it reaches any AI provider. Where AI processing involves non-EU providers, only masked data is transferred, under appropriate safeguards (SCCs / EU-U.S. DPF). This significantly reduces your GDPR risk profile and simplifies your own compliance obligations.
5. Data Sharing and Third Parties
We do not sell, rent, or share your personal data for third-party marketing purposes. We share personal data only in the following circumstances.
5.1 Sub-processors
We engage a number of sub-processors to help us deliver the Service. Each sub-processor is contractually bound by data protection obligations equivalent to those in our DPA. The current list is available on request — email privacy@dataduke.net.
We will notify you of any intended changes to our sub-processor list at least 30 days in advance.
5.2 Legal Requirements
We may disclose personal data if required by law, court order, or request from a competent authority.
5.3 Business Transfers
If Data Duke is involved in a merger, acquisition, or asset sale, personal data may be transferred to the successor entity, subject to the same privacy protections.
5.4 With Your Consent
We may share personal data with third parties if you have provided explicit prior consent.
6. International Data Transfers
Where Your Data Is Stored
All personal data is primarily stored and processed in the European Union — specifically in Supabase's Frankfurt, Germany (eu-central-1) infrastructure. Some sub-processors store limited data in the US: email delivery metadata and logs (Resend), web hosting logs including IP addresses (Vercel), and marketing measurement data (LinkedIn).
Limited US Transfers
- AI processing: Only masked data (see Section 4) is transferred outside the EU, under Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework
- Payment processing: Covered by EU-U.S. Data Privacy Framework certification and SCCs
- Notification webhooks: Covered by SCCs; include compliance summaries and recipient email addresses
- Email delivery and web hosting: Covered by the EU-U.S. Data Privacy Framework and SCCs
Transfer Safeguards
For all transfers outside the EEA, we ensure appropriate safeguards: Standard Contractual Clauses (SCCs), EU-U.S. Data Privacy Framework (DPF) certification, and Transfer Impact Assessments (TIAs).
7. Data Retention
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 2 years | Legal obligations, dispute resolution |
| Signed legal documents (ToS/DPA/Subprocessor List acceptances) | Duration of account + 2 years | Contract evidence, dispute resolution |
| Billing/invoice data | 7 years from invoice date | Austrian tax law (BAO §132) |
| Employee performance data (active) | Duration of subscription | Service provision |
| Employee performance data (historical) | Up to 24 months | Trend analysis |
| Deactivated user data | 90 days | Reactivation possibility |
| PII pseudonym mappings | Expire 7 days after the last sync refresh (default, configurable) | Re-identification for your organization; eligible for deletion after expiry |
| AI conversation history | 90 days | Service improvement, debugging |
| Compliance audit log (rule evaluations, configuration changes, sign-offs) | At least 5 years from the event | Evidence for your own audits; the log is append-only and the database rejects edits and deletes |
| Security audit logs | Indefinitely | Security, legal compliance |
| Marketing data | Until consent withdrawn | Consent-based processing |
| Support communications | 3 years from resolution | Legal claims, quality assurance |
When the retention period expires, we securely delete or anonymize your personal data.
8. Business Customers — Employee Data
Our Role as Data Processor
When your organization uses PulseCheck to monitor team performance, we process personal data of your employees on your behalf. You (the Customer) are the Data Controller; we (Data Duke) are the Data Processor. This relationship is governed by our DPA.
Your Responsibilities as Employer/Controller
Under GDPR, you are responsible for:
- Lawful basis: Ensuring you have a valid legal basis for monitoring employee performance
- Transparency: Informing your employees about the monitoring via internal privacy notices
- Works council / Betriebsrat: In Austria and other EU countries, you may need works council approval
- Data minimization: Only connecting integrations and enabling data collection necessary for your purposes
What We Do to Protect Your Employees' Privacy
- Mandatory masking of personal data before any AI processing (always on, cannot be disabled)
- EU data residency (Frankfurt, Germany)
- No employee data used to train AI models
- No employee data shared with other organizations
- Employees' data automatically deleted when removed from the platform (within 90 days)
9. Your Rights as a Data Subject
Under GDPR, you have the following rights regarding your personal data:
9.1 Right of Access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and to receive a copy.
9.2 Right to Rectification (Article 16)
You have the right to have inaccurate personal data corrected and incomplete data completed.
9.3 Right to Erasure (Article 17)
You have the right to request deletion of your personal data where the data is no longer necessary, you withdraw consent, you object to processing, or the data has been unlawfully processed.
9.4 Right to Restriction of Processing (Article 18)
You have the right to request that we restrict processing in certain circumstances.
9.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (CSV or JSON).
9.6 Right to Object (Article 21)
You have the right to object to processing based on legitimate interests. You have an absolute right to object to processing for direct marketing purposes at any time.
9.7 Rights Related to Automated Decision-Making (Article 22)
We do not make solely automated decisions that produce legal effects. AI-generated compliance insights are always presented to human managers/administrators.
9.8 Right to Withdraw Consent (Article 7(3))
Where processing is based on consent, you have the right to withdraw consent at any time.
9.9 How to Exercise Your Rights
Contact us at: privacy@dataduke.net
We will respond within one (1) month. We may request verification of your identity before processing your request.
9.10 Right to Lodge a Complaint
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)
Barichgasse 40-42, 1030 Wien, Austria
Email: dsb@dsb.gv.at · Phone: +43 1 52 152-0 · Website: www.dsb.gv.at
10. Security
Technical Measures
- Encryption in transit: TLS 1.3 for all data transmission
- Encryption at rest: AES-256 for all stored data (via Supabase)
- Mandatory masking of personal data (names, email addresses, phone numbers, IBANs, card numbers, IP addresses, credentials) before any AI processing; optional SHA-256 pseudonymization of stored data
- EU data residency: All data stored in Frankfurt, Germany
- Multi-factor authentication (MFA): Available for all user accounts
- Role-based access control (RBAC): Minimum necessary access per user role
Organizational Measures
- Annual security awareness training for all personnel
- Confidentiality agreements with all staff and contractors
- Quarterly GDPR compliance reviews
- Privacy impact assessments (PIAs) for new features
- Documented incident response procedures
Infrastructure Certifications (via Supabase)
- ISO 27001 certified
- SOC 2 Type II audited
- Automated daily backups with 7-day retention (EU region)
11. Cookies and Tracking
11.1 What We Use
PulseCheck uses only strictly necessary cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| sb-auth-token | Supabase authentication session | Session / 24 hours |
| sb-refresh-token | Session refresh token | 7 days |
| theme-preference | UI dark/light mode setting | 1 year |
| cookie-consent | Records your cookie consent decision | 1 year |
11.2 What We Do Not Use
- ❌ No Google Analytics or other third-party analytics
- ❌ No advertising or tracking cookies
- ❌ No social media pixels
- ❌ No cross-site tracking
12. Children's Privacy
PulseCheck is designed for use by businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18.
13. Links to Third-Party Websites
Our website and Service may contain links to third-party websites and services. We are not responsible for the privacy practices of such third parties.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date, notify you via email at least 14 days before changes take effect, and display a prominent notice in the Service.
Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Contact Us
Data Duke Project Consulting e.U.
Lehenstr. 12/2/3 OG, 1220 Vienna, Austria
UID: ATU77808106
General: web@dataduke.net
Support: support@dataduke.net
Privacy / Data Protection: privacy@dataduke.net
Legal / Contracts: legal@dataduke.net
Website: https://dataduke.net
Sub-processor List: available on request — email privacy@dataduke.net
We aim to respond to all privacy-related inquiries within five (5) business days.