[PRIVACY]·Legal
Privacy policy
We build and defend systems that hold other people's data, so we hold a strong opinion about how it should be treated. This policy explains exactly what this website collects, why, who else sees it, and what you can ask us to do about it.
It is written to be read rather than skimmed past. If anything here is unclear, ask us and we will answer plainly.
Who we are
Cybepulse LLC is a software engineering and cybersecurity company, registered in the Republic of Kosovo with the Kosovo Business Registration Agency (ARBK) and based at Rruga B, Prishtina, Kosovo. We trade as Cybepulse.
For the information described in this policy, we are the data controller — we decide why and how it is processed.
You can reach us about anything in this policy at privacy@cybepulse.com, or by post at the address above.
What this policy covers
This policy covers https://cybepulse.com and any enquiry you send us through it.
It does not cover data we process inside a client engagement — systems we build, host, test, or monitor on your behalf. There we act as a processor under the contract and data processing agreement signed with you, and those terms take precedence over this policy. See the section on client data below.
Information we collect
Information you give us. The contact form asks for your name, email address, the topic of your enquiry, and your message. Company name is optional. That is the whole of it — there are no hidden fields beyond a single honeypot input, which is invisible to people, always empty for real submissions, and only used to discard automated spam.
Information collected automatically. Our servers process the technical details every web request carries: your IP address, browser user agent, the page requested, and the time of the request. Your IP address is also counted against a short-lived rate limit on the contact endpoint, held in server memory only, so a single address cannot flood us with submissions.
Anything else you choose to send us. If you email us directly, we hold that correspondence and whatever you put in it. Please do not send credentials, secrets, or sensitive personal data over email — if an engagement needs them, we will agree a secure channel first.
How we use your information
We use what you send us for four things:
- To reply to your enquiry and continue the conversation it starts.
- To prepare a proposal, scope, or written plan you have asked for.
- To keep the site available, secure, and free of abuse — including rate limiting and spam filtering.
- To meet our legal, tax, and record-keeping obligations.
We do not sell your information. We do not share it with advertisers, and we do not add you to a marketing list because you asked us a question. There is no sales sequence.
Our legal bases
We process personal data under the data protection law applicable in the Republic of Kosovo, which follows the GDPR model. Where the EU or UK GDPR reaches you directly, we hold ourselves to the same standard. In either case we rely on the following bases:
- Legitimate interests — responding to enquiries, protecting the site from abuse, and running our business. We have weighed these against your rights and consider the impact minimal.
- Performance of a contract — where you are a client, or taking steps at your request before entering an engagement.
- Legal obligation — where retention or disclosure is required by law.
- Consent — where we ever ask for it explicitly, and which you may withdraw at any time.
International transfers
We are based in the Republic of Kosovo, and several of our providers operate in the European Union and the United States. That means your data will usually cross a border on its way to us. Where it does, we rely on the transfer mechanisms our data protection law permits — an adequacy decision, standard contractual clauses, or your explicit consent — together with the technical measures described below. You can ask us which providers are involved and where they are located.
How long we keep it
- Enquiries that do not lead to an engagement: up to 24 months, then deleted.
- Correspondence connected to an engagement: for the life of the engagement and up to seven years after, to meet contractual, tax, and limitation-period requirements.
- Rate-limiting counters: held in server memory for at most one hour, and lost on every deploy or restart. They are never written to a database.
- Server logs: retained by our hosting provider for a short operational window, then rotated out.
If you ask us to delete your enquiry sooner, we will, unless we are required to keep it.
How we protect it
The site is served over TLS, submissions are validated and size-limited on the server rather than trusted from the browser, and the contact endpoint is rate limited. Access to our inbox and infrastructure is restricted to the people who need it and protected by multi-factor authentication.
No system is perfect, and we will not pretend otherwise. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant supervisory authority within the timeframes the law requires.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — a copy of what we hold about you.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion, where we have no overriding reason to keep it.
- Restriction — a pause on processing while a dispute is resolved.
- Portability — a machine-readable copy of data you gave us.
- Objection — to processing based on our legitimate interests.
- Withdrawal of consent — at any time, where consent is the basis we relied on.
Email privacy@cybepulse.com to exercise any of these. We will respond within one month, free of charge. If you are not satisfied with our answer, you may complain to the competent data protection authority in the Republic of Kosovo, or to the authority where you live — but we would rather you told us first and gave us the chance to fix it.
Data we process for clients
During an engagement we may access systems, repositories, logs, or environments that contain personal data belonging to your users. In that context you are the controller and we are your processor.
That work is governed by the engagement contract and a data processing agreement: we act only on your documented instructions, restrict access to the named engineers on the engagement, keep any findings confidential, and return or destroy what we hold at the end of the work. We do not use client data to train models, build products, or improve our own services.
Children
This site is aimed at organisations, not children, and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.
Changes to this policy
We update this policy when what we do changes — a new provider, a new type of processing, a change in the law. The effective date at the top always reflects the current version. Material changes will be flagged on this page rather than slipped in quietly.
Contact us
Questions, requests, or complaints about privacy: privacy@cybepulse.com. Anything else: use the contact form and pick the closest topic.
Something here you need clarified?
Ask us directly — we would rather answer a question now than have you agree to something you are unsure about.