Legal
How we process data you submit, and metadata pulse-agent sends when you run Pulse. Source code is not transmitted to our servers.
Controller: Codebase Pulse s.r.o., IČO 23583436, Vlněna 5, 602 00 Brno, Czech Republic. Privacy mail: ondrej@codebasepulse.com. Product and support: support@codebasepulse.com. Sales: sales@codebasepulse.com. No data protection officer is appointed.
This notice covers the marketing site, the request form, mail you send us, invoices, and Pulse as a B2B service. It is not a substitute for a DPA. If you need one, send a request. Where the agent runs is also on Security.
Effective 20 September 2026.
For this website, for a request, and for our own billing records, we are the controller.
For Pulse job metadata that your organisation sends through pulse-agent, you are the controller of any personal data in that payload. We process it as a processor so we can show the report, land headlines on the PR or in the CI output, meter Pulse Runs, and apply Guard if you turn it on. A written DPA is available on request — there is no public self-serve click-through.
From the plan request: work email, billing region (EU/EEA, United States, or Global), tax / VAT / EIN, company name, company address, the plan you picked, and — if you are Global — the Pulse data seat you chose (EU or US). Currency on the form is USD. Without a work email and company details we cannot reply or invoice.
If you verify an EU VAT ID on the form, we send the VAT number to the official EU VIES service and may fill company name and address from the reply.
From the question form on Contact: name, work email, company if given, and your message. Filling it is voluntary. Without a name, email and a message we cannot reply. The same applies if you write to the addresses on that page, or use the waitlist path (work email, company, optional notes).
When Pulse runs on your CI, pulse-agent sends metadata: timings, test outcomes, performance signals, repo health, SARIF summaries you choose to drop in, and identifiers needed to attach the run to your workspace (repo, branch, job, token). That payload can include names or emails if your pipeline or SARIF already contains them. We do not request the source tree. Source remains on the runner. We do not store it.
We keep what we need to authenticate the agent, meter Pulse Runs (one run is one pulse command), apply a soft cap, and invoice. We also process hosting and security logs for this site: IP address, time, requested URL, user agent.
We do not use automated decision-making or profiling that produces legal or similarly significant effects. A request is reviewed by a person. It is not a purchase.
Request and mail: to answer you and, if we continue, to take steps toward a contract (GDPR Art. 6(1)(b)). We also have a legitimate interest in handling B2B inquiries, keeping a record of what was asked, and defending legal claims (Art. 6(1)(f)). You may object to processing based on legitimate interest.
VAT check: necessary to take steps toward a contract and to issue a correct invoice (Art. 6(1)(b) and (c) where VAT rules require it).
Pulse metadata and metering: performance of the contract with the customer organisation (Art. 6(1)(b)), and our legitimate interest in operating, securing, and billing the service (Art. 6(1)(f)). Where we act as processor, the customer’s instructions and the DPA govern the purpose.
Invoices and tax records: legal obligation (Art. 6(1)(c)).
Hosting and security logs: necessary to run and protect the site (Art. 6(1)(f)).
If you allow Analytics in the cookie settings, we use Google Analytics 4 to see page views. That processing rests on your consent (Art. 6(1)(a)). The gtag script is not loaded until you allow it. You can withdraw consent from Cookies in the footer.
A person at Codebase Pulse reads every request. The forms are emailed through Resend (Resend, Inc., United States) from marketing.codebasepulse.com. A plan request goes to sales@codebasepulse.com. A question goes to support@codebasepulse.com. We do not put you on a marketing list. See resend.com/legal/privacy-policy.
EU VAT checks go to the European Commission VIES REST API. The hosting provider that serves this website processes technical logs. Typefaces are bundled on this site; they are not loaded from Google.
Pulse metadata is stored on the product backend we operate so we can build the report and meter runs. Seat is by customer region — see below. We do not sell personal data. We do not share it for advertising. Analytics, if you allow it, is processed by Google (Google Ireland Limited / Google LLC). See Google’s privacy policy.
We may share data with an accountant or invoicing provider under a contract, or if a law requires it. We do not have a public self-serve payment page. Stripe is not used on this site today.
Resend is in the United States. That is a transfer outside the EEA for the request form, not for Pulse job metadata. It is carried out under the vendor’s standard contractual clauses or another GDPR-recognised mechanism they offer. If you do not want that transfer, write to ondrej@codebasepulse.com or sales@codebasepulse.com instead of using the form.
This is the product backend — the metadata pulse-agent sends, the report, metering. It is not the marketing site, not Resend, and not Google Analytics.
EU and EEA customers: Pulse data stays in the EU. We do not put it in the United States.
US customers: Pulse data stays in the United States. We do not put it in the EU.
Global customers (Canada, the UK, and the rest of the world outside the EU/EEA and the US): you choose the seat — EU or US — on the request. That choice is the seat we confirm in writing. You may not split one plan across both regions.
The product cloud in the EU is live. A US region on Google Cloud is planned. Until it is live, we do not store EU/EEA Pulse data in the United States. When the US region is up, a US seat stays in the United States. A DPA can lock the seat. Request.
Google Analytics, if you consent, also involves a transfer to Google in the United States under Google’s GDPR transfer mechanism.
Inquiries: 24 months after the last reply, then we delete them unless a longer period is required for an ongoing contract, accounting, or a legal claim.
Pulse job metadata: for the retention on the plan we confirm with you in writing. List retention on the site today is 30 days (Starter), 180 days (Team), 1 year (Scale), or as agreed (Custom). After that window the run data is deleted. Metering and invoice totals may be kept longer so we can bill and account.
Invoices and tax records: for the period Czech accounting and tax law require.
Server logs: as long as the host retains them for operation and security, typically up to 90 days.
Your cookie / analytics choice: until you change it or clear site data in the browser.
Your Necessary / Analytics choice is stored in local storage on this device so the banner does not return every visit. If you allow Analytics, Google’s gtag may then set cookies for Google Analytics 4. Change this from Cookies in the footer.
You can ask for access, correction, deletion, restriction, or portability, and you can object to processing based on legitimate interest. Where we act as processor, we will point you to the customer organisation that controls the Pulse workspace, or assist them, as the DPA requires.
Where processing rests on consent, you can withdraw it; that does not affect what was done before the withdrawal.
Write to ondrej@codebasepulse.com. You can also complain to the Czech Office for Personal Data Protection (ÚOOÚ), uoou.cz.