Privacy Policy
Last updated: 2026-07-27
1. Who We Are
This Privacy Policy applies to ContractsPulse (available at contractspulse.com), a SaaS renewal tracking service operated by:
SIA Tech Dev Baltic Registered in the Republic of Latvia Registration number: 40203459117 VAT number: LV40203459117 Registered address: Gailenu street 6-1, Riga, LV-1023, Latvia
Contact: support@contractspulse.com
As a company registered in Latvia (an EU member state), SIA Tech Dev Baltic is subject to the General Data Protection Regulation (GDPR) and acts as the data controller for personal data processed through ContractsPulse.
2. What ContractsPulse Does
ContractsPulse is a B2B SaaS tool that helps IT managers and their teams track software subscription contracts and receive timely renewal alerts by email. Users register on behalf of their organisation and enter contract data to manage their company's SaaS portfolio.
This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have over it.
3. What Data We Collect
3.1 Account Data
When you create an account, we collect:
- Full name — to identify your account
- Work email address — for login, notifications, and service communications
- Company name — to associate your account with your organisation
3.2 Contract Data
When you add contracts to ContractsPulse, the entries may include:
- Software tool names and vendor details
- Contract costs and renewal dates
- Owner names and email addresses — the internal contacts responsible for each contract at your organisation
This data is entered by you and is processed on your behalf. Where owner names and emails belong to your colleagues, you are responsible for ensuring you have an appropriate basis for sharing that information with us (e.g. your organisation's own privacy policies and internal procedures).
3.3 Billing Data
Payments are processed by Stripe, a third-party payment processor. We do not store your payment card details. We retain only a Stripe customer ID, which is a reference token used to manage your subscription.
3.4 Technical and Log Data
We collect limited technical data necessary to operate and secure the service:
- Authentication session data (via a single essential cookie — see Section 8)
- Error and diagnostic logs for debugging and stability monitoring
We do not use analytics trackers, advertising pixels, or behavioural profiling tools.
4. Why We Process Your Data (Legal Bases)
We only process personal data where we have a valid legal basis under GDPR Article 6.
| Purpose | Data involved | Legal basis |
|---|---|---|
| Creating and managing your account | Name, email, company name | Contract performance — Art. 6(1)(b) |
| Delivering the ContractsPulse service (renewal alerts, contract tracking) | Account data, contract data | Contract performance — Art. 6(1)(b) |
| Processing subscription payments | Stripe customer ID | Contract performance — Art. 6(1)(b) |
| Maintaining service security and preventing fraud or abuse | Technical logs, account data | Legitimate interests — Art. 6(1)(f) |
| Retaining billing and transaction records | Billing records, invoices | Legal obligation — Art. 6(1)(c) |
Our legitimate interests: We have a legitimate interest in keeping our service secure, detecting unauthorised access, and preventing misuse. We have assessed that these interests are not overridden by your rights, given the limited nature of the data involved and the reasonable expectations of users of a B2B business tool.
5. Who We Share Data With
We do not sell your data. We do not share your data with third parties for marketing purposes.
We work with the following data processors — companies that process data on our behalf under contractual obligations consistent with GDPR:
| Processor | Role | Location |
|---|---|---|
| Supabase | Database hosting and storage | EU region |
| Stripe | Payment processing | USA (with EU Standard Contractual Clauses) |
| Resend | Transactional email delivery (renewal alerts, account emails) | USA (with EU Standard Contractual Clauses) |
| Sentry | Error monitoring and diagnostics | USA (with EU Standard Contractual Clauses) |
Where processors are located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place — specifically Standard Contractual Clauses (SCCs) approved by the European Commission under Article 46(2)(c) GDPR.
We may also disclose personal data if required to do so by law, court order, or a competent regulatory authority.
6. Data Retention
We keep your data only as long as necessary for the purposes it was collected, or as required by law.
| Data type | Retention period |
|---|---|
| Account data (name, email, company) | While your account is active, plus 30 days after account deletion (to allow recovery and handle disputes) |
| Contract data | While your account is active, deleted with your account |
| Billing records and invoices | 7 years from the date of the transaction (required by Latvian and EU accounting law) |
| Error and diagnostic logs | 90 days |
After the applicable retention period, data is securely deleted or anonymised.
7. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights. You can exercise any of them by contacting us at support@contractspulse.com.
- Right of access (Art. 15): You can request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You can ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17): You can ask us to delete your personal data, subject to legal retention obligations (e.g. billing records we must keep for 7 years).
- Right to restriction of processing (Art. 18): You can ask us to restrict how we use your data in certain circumstances.
- Right to data portability (Art. 20): You can request your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): You can object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds that override your interests.
How to exercise your rights: Email us at support@contractspulse.com with your request. We will respond within 30 days. We may need to verify your identity before processing the request.
Right to lodge a complaint: If you believe we are not handling your data lawfully, you have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for SIA Tech Dev Baltic is:
Data State Inspectorate of Latvia (Datu valsts inspekcija) Website: www.dvi.gov.lv Email: info@dvi.gov.lv
You may also lodge a complaint with the supervisory authority in the EU member state where you live or work.
8. Cookies
ContractsPulse uses one essential cookie to maintain your authenticated session. This cookie is strictly necessary for the service to function — without it, you would be logged out on every page.
We do not use:
- Analytics cookies
- Advertising or tracking cookies
- Third-party marketing pixels
Because our only cookie is strictly necessary, we do not require cookie consent under ePrivacy rules. However, you may clear this cookie at any time via your browser settings, which will log you out.
9. Data Security
We take reasonable technical and organisational measures to protect your data, including:
- All data in transit is encrypted using TLS
- Our database (Supabase) is hosted in the EU and access is restricted
- Authentication tokens are managed securely
- We monitor errors and anomalies via Sentry to detect potential security issues promptly
No method of transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately at support@contractspulse.com.
10. B2B Context — A Note on Your Colleagues' Data
ContractsPulse is designed for business users. When you add contract owner names and email addresses belonging to your colleagues, those individuals are data subjects too.
In this context, your organisation acts as the data controller for your employees' data, and you use ContractsPulse as a tool to process it. We process that data on your behalf as a data processor under your instruction. You should ensure your organisation has an appropriate basis for using those individuals' data in this way (for example, in your internal HR policies or IT acceptable-use policy).
11. Children's Data
ContractsPulse is a professional B2B tool intended solely for use by adults acting in a business capacity. We do not knowingly collect data from anyone under the age of 18. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email.
We encourage you to review this policy periodically.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please reach out:
SIA Tech Dev Baltic Email: support@contractspulse.com Website: contractspulse.com
We aim to respond to all privacy-related enquiries within 5 business days.
This Privacy Policy is governed by the laws of the Republic of Latvia and the applicable provisions of the EU General Data Protection Regulation (GDPR — Regulation (EU) 2016/679).