Data Processing Addendum

Last Updated: September 24, 2026

This Data Processing Addendum ("DPA") is part of the Terms of Service between Sales Pulse AI, LLC, a Florida limited liability company doing business as AI Sales Pulse ("we," "us," or the "Processor"), and the company that uses Pulse ("you" or the "Customer"). It applies whenever we process Personal Data on your behalf. You accept it when you accept the Terms. If you need a countersigned copy, email support@aisalespulse.com.

Plain-Language Summary: Your business data is yours. We only use it to run Pulse for you, we keep it secure, we tell you who else touches it, we tell you fast if something goes wrong, and we delete it when you leave.

1. Definitions

2. Roles and Scope

For Personal Data in your business data (customers, contacts, connected messages, ERP records and anything else you bring into Pulse), you are the controller and we are your processor, or your "service provider" under the CCPA. For account, billing and security data we need to run our own business (for example, your users' login details), we act as an independent controller under our Privacy Policy. The details of the processing are in Annex 1.

3. Processing Only on Your Instructions

We process Personal Data only to provide, secure and support the Service, and otherwise on your documented instructions. The Terms, this DPA, and the way you configure the Service (for example, which accounts you connect and which chats you exclude in Privacy Settings) are your instructions. If we believe an instruction breaks Data Protection Laws, we will tell you. If a law requires us to process Personal Data in another way, we will tell you first unless that law forbids it.

We do not sell Personal Data, and we do not use your business data to train AI models.

4. Confidentiality of Our People

Only personnel who need access to provide or support the Service can access Personal Data, and they are bound by confidentiality obligations.

5. Security

We keep appropriate technical and organizational measures in place to protect Personal Data, taking into account the nature of the data and the risks involved. The current measures are described in Annex 2. We may update them over time, but we will not reduce the overall level of protection.

6. Subprocessors

7. Help With Requests From Individuals

If a person asks us directly to access, correct, delete or otherwise exercise their rights over Personal Data we hold for you, we will pass the request to you and will not respond ourselves except to direct them to you. Pulse lets you find, export, correct and delete data yourself. Where you cannot do something yourself, we will help you respond, as far as is reasonable.

8. Security Incidents

If we become aware of a Security Incident affecting your Personal Data, we will notify you without undue delay, and in any event within 72 hours after confirming it. We will tell you what we know about what happened, the data affected, and what we are doing about it, and we will update you as we learn more. We will take reasonable steps to contain the incident and reduce its effects. Notifying you is not an admission of fault.

9. Other Assistance

Taking into account the information available to us, we will give you reasonable help with data protection impact assessments and consultations with regulators where the law requires them and they relate to our processing.

10. Return and Deletion

You can export your data at any time in Settings > Privacy > Export My Data. When your account ends, we delete Personal Data within 30 days, unless you ask for an export first or the law requires us to keep it. Copies in backups are removed as those backups expire in the normal backup cycle, and until then they stay protected under this DPA and are not used for anything else.

11. Information and Audits

We will give you the information reasonably needed to show that we comply with this DPA, including written answers to security questionnaires, once a year or after a Security Incident. If that is not enough to meet a requirement of Data Protection Laws or a regulator, you may carry out an audit, with at least 30 days' written notice, during business hours, at your own cost, no more than once a year, and under confidentiality terms. The audit must not give access to other customers' data.

12. International Transfers

Pulse is hosted in the United States. If Personal Data from the European Economic Area, the United Kingdom or Switzerland is transferred to us, the Standard Contractual Clauses approved by the European Commission (Decision 2021/914) apply and are incorporated into this DPA by reference: Module Two (controller to processor), with Clause 7 (docking) included, Option 2 (general authorization) in Clause 9 with the notice period in Section 6 above, the optional wording in Clause 11 left out, Clause 17 governed by the law of Ireland, and Clause 18 disputes before the courts of Ireland. Annexes I and II of those clauses are completed by Annex 1 and Annex 2 of this DPA. For the UK, the UK International Data Transfer Addendum applies alongside them, and for Switzerland they are read with the changes the Swiss law requires. If these clauses conflict with this DPA, the clauses control.

13. U.S. State Privacy Laws (CCPA)

Where the CCPA or a similar U.S. state law applies, we act as your service provider or processor. We will not:

We will comply with the CCPA's obligations for service providers, give the same level of privacy protection it requires, and tell you if we can no longer meet them. You may take reasonable steps to stop and fix any unauthorized use.

14. Your Responsibilities

You are responsible for having a lawful basis for the processing, for giving any notices and getting any consents the law requires (including telling your employees and users that their business email and WhatsApp messages are processed by Pulse), and for the accuracy of the data you bring in. You will use the Privacy Settings to exclude personal chats and contacts that should not be processed.

15. Liability and Precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms. If this DPA conflicts with the Terms on data protection, this DPA controls. This DPA lasts as long as we process Personal Data for you. We may update it to reflect changes in law or in our Subprocessors, with notice as described in the Terms, and we will not reduce the protection it gives your Personal Data without your agreement.

Annex 1: Details of Processing

PartiesData exporter / controller: the Customer (contact details on its account). Data importer / processor: Sales Pulse AI, LLC, 300 Oakwood Lane, Hollywood, FL 33020, USA, support@aisalespulse.com.
Subject matter and purposeProviding the Pulse sales assistant: organizing customers and conversations, reminders and follow-ups, AI summaries, insights and draft replies, search, reporting, and support.
Nature of processingCollecting (through the integrations you connect), storing, organizing, analyzing (including with AI), searching, displaying, exporting and deleting.
Data subjectsYour employees and users; your customers, prospects and suppliers, and their staff and contacts.
Categories of Personal DataNames, business contact details (email, phone, WhatsApp number, address), job details, the content and metadata of business email and WhatsApp messages (including attachments and voice notes), order, invoice and payment-terms history, notes, and usage and log data.
Sensitive dataNot intended. You should not use Pulse to process special categories of data. Personal chats can be excluded in Privacy Settings.
FrequencyContinuous, for as long as the integrations are connected.
Duration and retentionFor the term of your subscription, then deleted as described in Section 10.
SubprocessorsAs listed in the Privacy Policy, for the purposes stated there.

Annex 2: Security Measures

Questions about this DPA: support@aisalespulse.com · Sales Pulse AI, LLC, 300 Oakwood Lane, Hollywood, FL 33020, United States.