[NEW]

A new system is on its way.

[PRIVACY]·Legal

Privacy policy

[EFFECTIVE 3 AUGUST 2026]

We build and defend systems that hold other people's data, so we hold a strong opinion about how it should be treated. This policy explains exactly what this website collects, why, who else sees it, and what you can ask us to do about it.

It is written to be read rather than skimmed past. If anything here is unclear, ask us and we will answer plainly.

Who we are

Cybepulse LLC is a software engineering and cybersecurity company, registered in the Republic of Kosovo with the Kosovo Business Registration Agency (ARBK) and based at Rruga B, Prishtina, Kosovo. We trade as Cybepulse.

For the information described in this policy, we are the data controller — we decide why and how it is processed.

You can reach us about anything in this policy at privacy@cybepulse.com, or by post at the address above.

What this policy covers

This policy covers https://cybepulse.com and any enquiry you send us through it.

It does not cover data we process inside a client engagement — systems we build, host, test, or monitor on your behalf. There we act as a processor under the contract and data processing agreement signed with you, and those terms take precedence over this policy. See the section on client data below.

Information we collect

Information you give us. The contact form asks for your name, email address, the topic of your enquiry, and your message. Company name is optional. That is the whole of it — there are no hidden fields beyond a single honeypot input, which is invisible to people, always empty for real submissions, and only used to discard automated spam.

Information collected automatically. Our servers process the technical details every web request carries: your IP address, browser user agent, the page requested, and the time of the request. Your IP address is also counted against a short-lived rate limit on the contact endpoint, held in server memory only, so a single address cannot flood us with submissions.

Anything else you choose to send us. If you email us directly, we hold that correspondence and whatever you put in it. Please do not send credentials, secrets, or sensitive personal data over email — if an engagement needs them, we will agree a secure channel first.

Cookies and tracking

This website sets no cookies. It runs no analytics, no advertising pixels, no session recording, and no third-party tracking scripts. Fonts are served from our own domain rather than a font provider, so simply loading a page does not report you to anyone.

That means there is no consent banner, because there is nothing to consent to. If we ever add analytics, this policy changes first and you will be asked before anything non-essential is set.

How we use your information

We use what you send us for four things:

  • To reply to your enquiry and continue the conversation it starts.
  • To prepare a proposal, scope, or written plan you have asked for.
  • To keep the site available, secure, and free of abuse — including rate limiting and spam filtering.
  • To meet our legal, tax, and record-keeping obligations.

We do not sell your information. We do not share it with advertisers, and we do not add you to a marketing list because you asked us a question. There is no sales sequence.

Who we share it with

We share as little as possible, and only with providers who need it to deliver a service to us:

  • Our email provider (Resend), which transmits contact form submissions to our inbox and delivers our replies.
  • Our hosting and infrastructure provider, which serves this site and processes the request data described above.
  • Professional advisers — accountants, lawyers, insurers — where genuinely necessary.
  • Authorities, where we are legally required to disclose. We will tell you unless we are prohibited from doing so.

Each provider is bound by contract to process data only on our instructions. We do not grant them any right to use your information for their own purposes.

International transfers

We are based in the Republic of Kosovo, and several of our providers operate in the European Union and the United States. That means your data will usually cross a border on its way to us. Where it does, we rely on the transfer mechanisms our data protection law permits — an adequacy decision, standard contractual clauses, or your explicit consent — together with the technical measures described below. You can ask us which providers are involved and where they are located.

How long we keep it

  • Enquiries that do not lead to an engagement: up to 24 months, then deleted.
  • Correspondence connected to an engagement: for the life of the engagement and up to seven years after, to meet contractual, tax, and limitation-period requirements.
  • Rate-limiting counters: held in server memory for at most one hour, and lost on every deploy or restart. They are never written to a database.
  • Server logs: retained by our hosting provider for a short operational window, then rotated out.

If you ask us to delete your enquiry sooner, we will, unless we are required to keep it.

How we protect it

The site is served over TLS, submissions are validated and size-limited on the server rather than trusted from the browser, and the contact endpoint is rate limited. Access to our inbox and infrastructure is restricted to the people who need it and protected by multi-factor authentication.

No system is perfect, and we will not pretend otherwise. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant supervisory authority within the timeframes the law requires.

Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — a copy of what we hold about you.
  • Rectification — correction of anything inaccurate or incomplete.
  • Erasure — deletion, where we have no overriding reason to keep it.
  • Restriction — a pause on processing while a dispute is resolved.
  • Portability — a machine-readable copy of data you gave us.
  • Objection — to processing based on our legitimate interests.
  • Withdrawal of consent — at any time, where consent is the basis we relied on.

Email privacy@cybepulse.com to exercise any of these. We will respond within one month, free of charge. If you are not satisfied with our answer, you may complain to the competent data protection authority in the Republic of Kosovo, or to the authority where you live — but we would rather you told us first and gave us the chance to fix it.

Data we process for clients

During an engagement we may access systems, repositories, logs, or environments that contain personal data belonging to your users. In that context you are the controller and we are your processor.

That work is governed by the engagement contract and a data processing agreement: we act only on your documented instructions, restrict access to the named engineers on the engagement, keep any findings confidential, and return or destroy what we hold at the end of the work. We do not use client data to train models, build products, or improve our own services.

Children

This site is aimed at organisations, not children, and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.

Changes to this policy

We update this policy when what we do changes — a new provider, a new type of processing, a change in the law. The effective date at the top always reflects the current version. Material changes will be flagged on this page rather than slipped in quietly.

Contact us

Questions, requests, or complaints about privacy: privacy@cybepulse.com. Anything else: use the contact form and pick the closest topic.

[QUESTIONS]

Something here you need clarified?

Ask us directly — we would rather answer a question now than have you agree to something you are unsure about.

Talk to us