Pulsar Analytics
Legal notice Terms Privacy DPA
Log in

Data processing agreement

Compliant with Article 28 of the GDPR · Version of 29 juillet 2026 (2)

This data processing agreement (hereinafter the "DPA") governs the processing of personal data carried out by Expeteo SARL, société à responsabilité limitée de droit luxembourgeois, whose registered office is Op der Haart 28, L-9999 Wemperhardt, Luxembourg (RCS Luxembourg B212614), operating the trade mark Pulsar (hereinafter the "Processor"), on behalf of its client (hereinafter the "Controller"), in the context of the Pulsar Analytics service. It supplements the General Terms and prevails in the event of contradiction on data protection matters only. It is concluded in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR").

1. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject", "data breach" and "supervisory authority" have the meaning given to them by Article 4 of the GDPR. The "Service" means Pulsar Analytics; the "Audience Data" means the data processed through the pixel on the Controller's sites.

2. Roles of the parties

The Controller determines the purposes and means of the processing of the Audience Data of its own sites. The Processor processes this data solely on behalf of and on documented instructions from the Controller, for the purpose of providing the Service. The Processor is not responsible for the lawfulness of the collection decided by the Controller (legal basis, information of visitors), which is the Controller's responsibility.

3. Subject matter, duration, nature and purpose of the processing

Subject matter and nature: cookieless web audience measurement (collection, aggregation and presentation of statistics). Purpose: to provide the Controller with aggregated audience statistics, excluding any advertising, personalisation or retargeting use. Duration: for the entire term of the Service contract. The categories of data and of data subjects are detailed in Annex 1.

4. Obligations of the Processor (Article 28(3))

The Processor undertakes to:

  • (a) process the data only on documented instructions from the Controller, including for transfers outside the EU, unless required by law (in which case it informs the Controller, unless legally prohibited);
  • (b) ensure that persons authorised to process the data are bound by a duty of confidentiality;
  • (c) implement the security measures required by Article 32 (see Annex 2);
  • (d) respect the conditions for engaging a sub-processor (Article 5 below);
  • (e) assist the Controller, by appropriate technical and organisational measures, in responding to requests to exercise data subject rights;
  • (f) assist the Controller in ensuring compliance with the obligations of security (Art. 32), breach notification (Art. 33-34) and impact assessment (Art. 35-36);
  • (g) at the Controller's choice, delete or return the data at the end of the service and destroy existing copies, unless legally required to retain them;
  • (h) make available to the Controller all information necessary to demonstrate compliance with Article 28 and allow for audits (Article 8 below).

The Processor immediately informs the Controller if, in its opinion, an instruction constitutes a breach of the GDPR.

5. Sub-processors

The Controller authorises the engagement of the sub-processors listed in Annex 3 (general authorisation). The Processor informs the Controller of any addition or replacement, leaving the Controller the possibility to object on legitimate grounds. The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those of this DPA, and remains liable for their performance.

6. Security (Article 32)

The Processor implements the technical and organisational measures described in Annex 2, appropriate to the risk, in particular: design without cookies or persistent identifiers, truncation/anonymisation of the IP address, encryption in transit and at rest, partitioning per site, access control and logging.

7. Data breaches (Articles 33-34)

In the event of a breach affecting the Audience Data, the Processor notifies the Controller without undue delay after becoming aware of it, with the relevant information, in order to allow the Controller to meet its own obligations to notify the supervisory authority and, where applicable, to communicate with the data subjects.

8. Audits

The Processor makes available the information necessary to demonstrate its compliance and allows for audits, including inspections, conducted by the Controller or a mandated auditor, subject to reasonable notice, respecting confidentiality and security, and without disrupting the Service.

9. Transfers outside the European Union

The Audience Data is processed in Switzerland, which benefits from an adequacy decision of the European Commission. The only data processed in the European Union is billing data, at Stripe (Ireland). No transfer outside this area is carried out without an appropriate legal basis within the meaning of Articles 44 to 49 of the GDPR (in particular standard contractual clauses).

10. End of the contract

At the end of the service, the Processor deletes or returns the Audience Data at the Controller's choice, and deletes existing copies, unless legally required to retain them. Raw data is in any event deleted at the latest 25 months after its collection (retention period applied automatically).

11. Liability and applicable law

The liability of the parties is governed by the General Terms and by Article 82 of the GDPR. This DPA is subject to Luxembourg law; the courts of the Grand Duchy of Luxembourg have jurisdiction, subject to the applicable mandatory rules.


Annex 1: description of the processing

  • Categories of data subjects: visitors to the Controller's websites.
  • Categories of data: aggregated and pseudonymised technical browsing data (pages viewed, source/referrer, channel, UTM, device type, browser, system, country derived from a truncated IP, timestamp, events and scroll depth). When the heatmaps option is enabled by the Controller for a site: aggregated click positions and a sample of cursor movements, counted per cell and per page, without any identifier and without reconstruction of an individual journey; form fields and masked areas (data-pulsar-mask) are excluded. No persistent identifier: the visitor identifier is a non-persistent daily hash (less than 24 hours). No directly identifying data, no special category within the meaning of Article 9.
  • Nature and purpose: aggregated statistical audience measurement (including, optionally, aggregated heatmaps).
  • Duration: term of the contract; raw data retained for 25 months maximum; aggregated heatmap data retained for 12 months maximum.

Annex 2: technical and organisational measures

  • No cookie and no storage on the device; no fingerprinting.
  • IP address used solely to derive a country, then truncated/anonymised immediately, never stored in clear text.
  • Visitor identifier: non-persistent daily rotating hash, computed with a secret salt; partitioning per site (no cross-site matching).
  • Encryption of data in transit (HTTPS) and at rest.
  • Access control, logging, rate limiting of the collection endpoint.
  • Data minimisation and automatic purge beyond the retention period.
  • Hosting of the Audience Data in Switzerland (Infomaniak, Geneva).

Annex 3: authorised sub-processors

  • Infomaniak Network SA (Switzerland): hosting of the application and of the collection server.
  • Stripe Payments Europe, Limited (Ireland, EU): payment processing (account/billing data, excluding Audience Data).

To receive a signed version of this DPA or to ask a question, write to privacy@pulsar.lu. This document constitutes a standard contractual basis; having it validated by your legal counsel is recommended.

© 2026 Pulsar Analytics
Legal notice Terms Privacy