Pulsar Analytics
Legal notice Terms Privacy DPA
Log in

Privacy policy

Last updated: 29 juillet 2026 (2)

Expeteo SARL, operating the trade mark Pulsar (hereinafter "Pulsar", "we"), attaches particular importance to the protection of personal data. This policy describes how data is processed in the context of the Pulsar Analytics service (analytics.pulsar.lu), in accordance with Regulation (EU) 2016/679 ("GDPR"), Directive 2002/58/EC ("ePrivacy") and, for data subjects in Switzerland, the Swiss Federal Act on Data Protection ("nFADP").

This policy distinguishes two parts corresponding to two different legal roles:

  • Part A: the data of Pulsar clients and users (accounts, billing). The Publisher is the controller.
  • Part B: the audience data collected through the Pulsar pixel on our clients' sites. The Publisher acts as a processor (Article 28 of the GDPR), on behalf of the client, who is the controller.

Contact details

  • Controller (Part A): Expeteo SARL, Op der Haart 28, L-9999 Wemperhardt, Luxembourg. RCS Luxembourg: B212614.
  • Data protection contact point: privacy@pulsar.lu.
  • In the absence of an appointed data protection officer (DPO), the contact point above serves as the contact for any question relating to data.

Part A: data of Pulsar clients and users

For this processing, Expeteo SARL is the controller within the meaning of Article 4(7) of the GDPR.

A.1. Account management and provision of the Service

  • Purpose: creation and management of the account, authentication, provision and administration of the Service, support.
  • Legal basis: performance of the contract (Article 6(1)(b) of the GDPR).
  • Categories of data: identity, email address, login credentials, configuration data, technical connection logs.
  • Recipients: authorised staff of the Publisher; hosting provider (Infomaniak Network SA).
  • Retention period: duration of the contractual relationship, then limited intermediate archiving for evidential purposes and legal obligations.

A.2. Billing and payment

  • Purpose: management of subscriptions, billing, collection, fraud prevention.
  • Legal basis: performance of the contract (Art. 6(1)(b)) and legal accounting and tax obligations (Art. 6(1)(c)).
  • Categories of data: billing data (legal name, address, VAT number), subscription history, transaction data. Card data is processed directly by Stripe; the Publisher does not have access to the full card number.
  • Recipients: Stripe (Stripe Payments Europe, Limited); the accountant and the tax authorities where applicable.
  • Retention period: accounting records are kept for the legal period applicable in Luxembourg (ten years).

A.3. Communications and improvement of the Service

  • Purpose: information relating to the Service, response to requests, improvement and security.
  • Legal basis: legitimate interest (Art. 6(1)(f)); performance of the contract for Service-related communications. Any commercial prospecting by electronic means is based on consent or legitimate interest under the conditions of the ePrivacy Directive.
  • Retention period: the time necessary for the purpose, then deletion or anonymisation.

A.4. Free compliance check (scanner)

  • Purpose: providing the result to the person who requests it, then monitoring use of the tool and improving the checks it performs.
  • Legal basis: legitimate interest (Article 6(1)(f) of the GDPR) in knowing how a freely available public tool is used.
  • Categories of data: the domain name analysed, the date, the score and the nature of the points observed. The full address of the page, URL parameters and the requester's IP address are not recorded. A company domain name is not, in principle, personal data; it may become so where it corresponds to the name of a natural person.
  • Recipients: authorised staff of the Publisher. No disclosure to third parties, no resale.
  • Retention period: twelve months from the analysis, then automatic deletion.
  • Objection: deletion of an analysis may be requested at any time from privacy@pulsar.lu, stating the domain concerned.

A.5. Legal obligations and dispute management

Compliance with legal obligations and defence of rights in court. Legal basis: legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)). Retention for the duration of the applicable limitation periods.

A.6. Recipients and processors

  • Infomaniak Network SA (Switzerland): hosting.
  • Stripe Payments Europe, Limited (Ireland, EU): payment processing.
  • Where applicable, support and emailing providers established in the European Union.

A.7. Transfers outside the European Union

The application server and the collection server are located in Switzerland, which benefits from an adequacy decision of the European Commission. Billing data is processed in the European Union, at Stripe (Ireland). Should a provider be engaged that may transfer data outside the European Economic Area without an adequacy decision, such operations are framed by appropriate safeguards within the meaning of Articles 44 to 49 of the GDPR, in particular standard contractual clauses.

A.8. Rights of data subjects

In accordance with Articles 15 to 22 of the GDPR, every data subject has the following rights:

  • right of access (Article 15);
  • right to rectification (Article 16);
  • right to erasure (Article 17);
  • right to restriction of processing (Article 18);
  • right to data portability (Article 20);
  • right to object (Article 21), in particular to processing based on legitimate interest.

These rights are exercised by writing to privacy@pulsar.lu. A response is provided within the periods set by the GDPR (in principle one month, extendable). Proof of identity may be requested in the event of reasonable doubt.

A.9. Complaint to a supervisory authority

  • in Luxembourg: Commission nationale pour la protection des données (CNPD), 15, boulevard du Jazz, L-4370 Belvaux, Luxembourg, cnpd.public.lu;
  • or to the supervisory authority of the Member State of their residence, place of work or of the place of the alleged infringement;
  • for data subjects in Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern.

Part B: audience data collected through the Pulsar pixel

For this processing, the Publisher acts as a processor (Article 28 of the GDPR), on behalf of its client, who is the controller. The client determines the purposes and means of the audience measurement of their own sites; the Publisher processes the data solely according to their documented instructions.

B.1. Nature of the collection: cookieless audience measurement

The Pulsar pixel is designed according to the principle of data protection by design (Article 25 of the GDPR):

  • No cookie, no storage on the Visitor's device (neither cookie nor localStorage).
  • IP address: used solely, at server level, to derive a country code and a city name, then truncated and anonymised immediately. Never stored in clear text.
  • Order data (merchant sites, on activation): order number, amount, currency and product names. No customer data is transmitted: no name, address or email. The order number serves accounting reconciliation and prevents a reloaded confirmation page from counting twice.
  • Form interaction: names of the fields reached and the order in which they were, to identify those causing drop-off. No entered value is read or transmitted, and password fields are ignored down to their name.
  • Visitor identifier: a daily rotating and non-persistent hash (lifetime of less than 24 hours), computed with a secret salt. It does not allow a person to be followed from one day to the next nor from one session to another.
  • Isolation per site: each site is partitioned, cross-site matching is impossible. No advertising profile, no retargeting.
  • No fingerprinting: no canvas/WebGL and no combination of individualising attributes.
  • Aggregated data: the statistics presented contain no directly identifying data.

Heatmaps (option that can be enabled per site). The client may enable, site by site, a measurement of aggregated heatmaps: the position of clicks and a sample of cursor movements are counted per cell and per page, without any identifier and without any possibility of reconstructing an individual's browsing (unlike a session recording, which Pulsar does not perform). Form fields and areas marked data-pulsar-mask are excluded from the measurement; no input, no field content is collected. This measurement remains cookieless and without storage on the Visitor's device. A preview of the public page may be captured on the server side to serve as a background for the heatmaps.

B.2. Purpose, legal basis and roles of the parties

  • Purpose: aggregated audience measurement of the client's sites, for statistical purposes only, excluding any advertising, personalisation or retargeting use.
  • Legal basis: determined by the client, as controller, under Article 6 of the GDPR (in practice, legitimate interest for strictly statistical measurement, or consent where the client considers it required).
  • Role of the Publisher: processor acting on the client's documented instructions.

B.3. Consent exemption under Article 5(3) of the ePrivacy Directive

The Pulsar pixel neither stores nor reads information on the Visitor's device beyond what is strictly necessary, and uses neither cookies nor a stable identifier. In this configuration, the access to the device that triggers the consent requirement of Article 5(3) of Directive 2002/58/EC is not established, and audience measurement may benefit from the consent exemption. This exemption assumes that the following conditions remain met:

  • the measurement serves the sole statistical purpose of the site and is strictly necessary to its provision;
  • the data is not cross-matched with other processing nor transmitted to third parties;
  • there is no tracking of browsing across different sites or applications;
  • the data produced is anonymous or strictly limited to the production of anonymous statistics.

It is for the client, as controller, to verify that their use meets these conditions and, in the event of a configuration departing from them, to obtain the required consent and to inform their Visitors (Articles 13 and 14 of the GDPR).

B.4. Import of Google Analytics 4 history (optional)

When the client enables the import of their Google Analytics 4 history, they authorise an address from a pool managed by the Publisher to access their own GA4 property in read-only mode. The imported data comes from the client's Google Analytics account, of which they remain the controller. The Publisher uses it only to present the history to the client within the Service.

B.5. Processing compliant with Article 28 of the GDPR

As a processor, the Publisher makes available to the client a data processing agreement (DPA) compliant with Article 28(3) of the GDPR (also available on request at privacy@pulsar.lu). That agreement provides in particular for:

  • processing the data solely on the client's documented instructions;
  • guaranteeing the confidentiality of the persons authorised to process the data;
  • implementing appropriate security measures (Article 32);
  • framing the engagement of sub-processors, with equivalent obligations;
  • assisting the client with requests to exercise rights, with breaches and with impact assessments (Articles 32 to 36);
  • deleting or returning the data at the end of the service, at the client's choice;
  • making available the necessary information and allowing audits to be carried out.

The Publisher maintains the record of categories of processing activities carried out on behalf of its clients (Article 30(2) of the GDPR).

B.6. Sub-processors and hosting

The Audience Data is hosted and processed in Switzerland:

  • Infomaniak Network SA (Switzerland): hosting of the application server and of the collection server.

The list of sub-processors is communicated within the DPA and kept up to date; the client is informed of any change.

B.7. Security (Article 32 of the GDPR)

The Publisher implements appropriate technical and organisational measures: encryption in transit (HTTPS) and at rest, partitioning per site, data minimisation, truncation of the IP address, non-persistent daily hash, access control, logging and rate limiting of the collection endpoint.

B.8. Data breaches (Articles 33 and 34 of the GDPR)

In the event of a data breach affecting the Audience Data, the Publisher, in its capacity as processor, notifies the client without undue delay so as to allow the client to meet its obligations to notify the supervisory authority (Article 33) and to communicate with the data subjects (Article 34).

B.9. Transfers outside the European Union

No transfer of the Audience Data is carried out outside Switzerland, which benefits from an adequacy decision. Should a provider outside the EEA be engaged on an occasional basis without an adequacy decision, appropriate safeguards within the meaning of Articles 44 to 49 of the GDPR would be put in place.

B.10. Retention period

Raw audience measurement data is kept for 25 months at most, then deleted or kept only in the form of statistical aggregates without individualising data. The aggregated data of the heatmaps (counters per cell and per page) is kept for 12 months at most.

B.11. Rights of data subjects

Given the absence of a persistent identifier and of directly identifying data, the Audience Data does not, in principle, allow a person to be re-identified (Article 11 of the GDPR). Requests relating to a given site must be addressed to the client, controller of that site. The Publisher assists the client in handling such requests.


Amendment of this policy

This policy may be updated to take account of legal, regulatory or technical developments. The version in force is the one published on analytics.pulsar.lu. Substantial amendments are brought to the attention of clients by an appropriate means.

© 2026 Pulsar Analytics
Legal notice Terms Privacy