1. Data controller
Kévin Aubrée, sole trader, based in Villeneuve-d'Ascq (59491), France, is the controller of the personal data collected through the PulseVault service, published under the pulseview.app brand, within the meaning of article 4 of regulation (EU) 2016/679 (GDPR).
For any question about how your personal data is handled, write to [email protected]. The publisher's full details are in the legal notice.
2. Data processed
Account data. When you create an account: email address, organisation name and password. Passwords are always hashed with Argon2id and never stored in clear text. A one-time code (OTP) is emailed to verify your address.
Secrets and configuration. The values you store in the vault (environment variables, API keys, connection strings) are encrypted at rest with AES-256-GCM using envelope encryption: each secret has its own data key, itself encrypted with the instance master key. On the hosted version the publisher holds that master key, so the service is not zero-knowledge; access to decrypted data is strictly limited to authorised staff and reserved for indispensable operations or support. If that model does not meet your confidentiality requirements, the self-hosted version lets you hold the master key yourself.
You remain responsible for the content of the secrets you store. The service is not intended to hold personal data inside secret values; we recommend storing only technical credentials.
Audit log. Every sensitive action (sign-in, project creation, reading, updating or deleting a secret, issuing a token) creates a hash-chained entry containing the timestamp, the actor's identifier and label (email address or token prefix), the action, the project, the environment and the secret name concerned. Secret values are never logged.
Support data. Tickets you open and messages exchanged with support are kept in your account so requests can be followed up.
Waitlist. If you join the waitlist before the service opens, we record your email address, interface language and the page the sign-up came from, for the sole purpose of telling you when we launch.
Payment data. When billing is enabled, payments are processed by Stripe. The publisher neither collects nor stores card numbers; only the information needed to manage the subscription (customer identifier, subscription status, billing history) is retained.
Cookies. The service sets only strictly necessary cookies: pv_session (opaque session token, httpOnly, inaccessible to JavaScript, seven days by default) and pv_locale (language preference, one year, containing no identifying data). These cookies are exempt from consent under article 82 of French law n° 78-17 of 6 January 1978 and CNIL guidance, since their sole purpose is to deliver the service you requested. No advertising cookie and no third-party analytics tool is set.
3. Legal bases
Pursuant to article 6 GDPR, processing relies on the following legal bases:
- Performance of a contract (art. 6.1.b): account creation and management, storing and returning secrets, managing organisation members, support.
- Legal obligation (art. 6.1.c): retention of invoices and accounting records required by French law.
- Legitimate interest (art. 6.1.f): service security, access traceability through the audit log, fraud prevention and abuse mitigation.
- Consent (art. 6.1.a): joining the waitlist, withdrawable at any time.
4. Retention periods
- Account data: for the lifetime of the account, then deleted or anonymised subject to statutory retention obligations.
- Secrets and previous versions: until you delete them or until the organisation is closed, which deletes them.
- Audit log: for the lifetime of the organisation, then deleted with it.
- One-time codes (OTP): ten minutes, then automatic expiry.
- Support tickets: for the lifetime of the account.
- Waitlist: until the service opens, then deleted — and at any time on request.
- Invoices and accounting records: 10 years, pursuant to article L.123-22 of the French Commercial Code.
5. Recipients and processors
Data is accessible only to authorised staff of the publisher and to the following processors within the meaning of article 28 GDPR:
- Hostinger International Ltd. (61 Lordou Vironos Street, 6023 Larnaca, Chypre): hosting of the service on servers located in France.
- Stripe (Stripe Payments Europe, Ltd.): payment processing and subscription management, when billing is enabled.
- Transactional email (SMTP) provider: delivery of verification codes, invitations and account notifications.
Where a processor transfers data outside the European Union — which may be the case for Stripe towards the United States for certain payment operations — the transfer is governed by the European Commission's standard contractual clauses (implementing decision (EU) 2021/914) or any other appropriate safeguard under chapter V GDPR.
No data is sold, rented or passed on to third parties for commercial purposes.
6. Your rights
Under the GDPR and French law n° 78-17 of 6 January 1978, you have the following rights:
- Right of access (art. 15 GDPR): confirm whether your data is processed and obtain a copy.
- Right to rectification (art. 16 GDPR): have inaccurate or incomplete data corrected.
- Right to erasure (art. 17 GDPR): request deletion of your data in the cases provided for by the regulation.
- Right to restriction (art. 18 GDPR): temporarily freeze the use of your data in certain situations.
- Right to portability (art. 20 GDPR): receive the data you provided in a structured, commonly used, machine-readable format.
- Right to object (art. 21 GDPR): object to processing based on our legitimate interest, on grounds relating to your particular situation.
- Post-mortem directives (art. 85 of law n° 78-17): set directives on what happens to your data after your death.
To exercise these rights, write to [email protected]. Pursuant to article 12.3 GDPR we reply within one month of receiving your request, extendable by two months for complex requests. Proof of identity may be requested where there is reasonable doubt as to the requester's identity.
7. Complaint to the supervisory authority
If, after contacting us, you consider that your rights are not respected, you may lodge a complaint with the French data protection authority, pursuant to article 77 GDPR:
CNIL — Commission Nationale de l'Informatique et des Libertés — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — https://www.cnil.fr
8. Security
Pursuant to article 32 GDPR, we implement appropriate technical and organisational measures to ensure a level of security matching the risk, in particular:
- encryption of data in transit (TLS);
- encryption of secrets at rest with AES-256-GCM, using envelope encryption (one data key per secret);
- password hashing with Argon2id;
- an opaque, httpOnly session cookie, inaccessible to browser JavaScript;
- email verification by one-time code and rate limiting on sign-in attempts;
- read-only service tokens scoped to a single project and environment;
- a hash-chained audit log whose integrity is verifiable and which never contains secret values.
9. Changes to this policy
This policy may be updated to reflect changes to the service or to regulations. In the event of a substantial change we will inform you by any appropriate means (in-app notification or email). The last update date appears at the top of this page. Service conditions are set out in the terms of service.