Who this applies to
This policy applies to visitors to our marketing sites, trial users, and paying customers who use the GagePulse application to manage calibration assets, certificates, and related records.
Information we process
We process categories of data that fall into a few buckets:
- Account and profile data: name, business email, organization name, role, and authentication identifiers maintained by our identity provider.
- Service and asset data: the records you enter or import into GagePulse — including asset metadata, calibration dates, tags, and operational fields required to run an asset management system.
- Documents you upload: calibration certificates and similar PDFs you attach to assets, stored in private tenant-scoped storage.
- Technical and security data: diagnostic logs, IP addresses, device and browser metadata, and similar signals used to operate and protect the service.
- Billing and subscription data: plan selection, payment status, and payment instrument metadata processed by our payment processor — not full card numbers stored inside GagePulse.
How we use information
We use the information above to:
- Provide, operate, and improve GagePulse features you subscribe to;
- Authenticate users, enforce roles, and secure tenant boundaries;
- Maintain audit history and exports consistent with the product design;
- Deliver billing, receipts, and subscription lifecycle messages;
- Detect abuse, investigate security incidents, and comply with law where required.
Legal bases (where GDPR-style laws apply)
Depending on context, we rely on performance of a contract (providing the service you purchased), legitimate interests (securing and improving the product, fraud prevention), or consent where we expressly ask for it — for example, certain marketing communications.
Subprocessors and infrastructure
We host GagePulse on reputable cloud infrastructure and use vendors for foundational services such as authentication, database, object storage, payment processing, and observability. Subprocessors are bound by agreements that require appropriate confidentiality and security controls. Customer data is not sold for advertising profiling.
Retention
We retain customer account and tenant data for as long as your subscription is active and for a reasonable period afterward to resolve disputes, enforce agreements, and satisfy legal obligations. Backup and log retention periods vary by system and are tuned for recovery — not indefinite archiving.
Security
We implement administrative, technical, and organizational measures appropriate to the sensitivity of calibration records — including access control, encryption in transit, private storage for PDFs, and auditing of privileged operations. No method of transmission or storage is perfectly secure; we continuously improve our posture as threats evolve.
Your rights
Depending on your region, you may have rights to access, correct, delete, or export certain personal data, or to object to particular processing. Many requests must be routed through your organization’s administrator because GagePulse is a business service. Contact us if you need help identifying the right route.
International transfers
If you access GagePulse from outside the primary region where we host data, your information may be processed across borders. We use contractual mechanisms recognized for international transfers where required.
Children
GagePulse is a business product and is not directed at children. We do not knowingly collect personal information from minors.
Changes
We may update this policy as the product and legal landscape change. Material updates will be reflected with a revised “Last updated” date and, where appropriate, additional notice in the product or by email.
Contact
Privacy questions: privacy@gagepulse.com
