SLApulse Privacy Policy

This Privacy Policy covers Norsker Labs ApS, CVR no. 46545427, Lyngevej 217, 3450 Allerød, Denmark (“Norsker Labs”, “we”) as controller for personal data we process for our website, business enquiries, account administration, billing and direct relationship with our customers. Contact us at contact@slapulse.com.

1. Data we process as controller

We may process business contact and account details, support correspondence, billing and subscription information, website and security logs, and information necessary to prevent abuse or comply with law. Payment-card information is handled by the payment provider and is not stored by SLApulse.

1a. Optional marketing-site analytics

When enabled for the public SLApulse marketing site, we use Umami Cloud to understand aggregate estimated visits, page views, landing pages and referrer sources. This uses only the public page path, referrer and the limited technical request information needed to prepare those aggregate statistics.

We do not send form contents, email addresses, names, issue keys, app user IDs, free text or other custom analytics fields to Umami. We do not use Umami on the authenticated SLApulse app, and this integration does not use session replay, heatmaps, advertising or cross-site tracking.

2. Purposes and legal bases

We use this data to respond to enquiries, provide and administer the contract, bill for the Service, secure our systems, provide support, and meet legal obligations. Our legal bases are performance of a contract, compliance with legal obligations, and our legitimate interests in operating and securing the business. Where we rely on consent, it may be withdrawn at any time.

3. Recipients and transfers

We use service providers where necessary to host and operate SLApulse, deliver email and process payments. When optional marketing-site analytics are enabled, Umami Cloud processes the limited analytics data described above. We require appropriate contractual safeguards. Where a transfer of personal data outside the EEA is necessary, we use a lawful transfer mechanism under Chapter V GDPR, such as an adequacy decision or Standard Contractual Clauses, as applicable.

4. Retention

We retain controller data only for as long as needed for the purposes above, including legal, accounting, security and dispute-resolution requirements. The selected Umami Cloud account retains the aggregate marketing-site analytics described above for 12 months.

5. Rights and complaints

Subject to applicable law, you may request access, rectification, erasure, restriction, portability or object to processing. Contact contact@slapulse.com. You may also lodge a complaint with the Danish Data Protection Agency or your local supervisory authority.

6. Security and changes

We use technical and organisational measures appropriate to the risk. No service can be completely secure. We may update this policy by publishing a new version on this page.