Nature of the data collected:#

As part of the use of its services, PulseHeberg may collect the following data about its customers:

  • Identification data: Last name, first name, postal address, email address and phone number.
  • Connection data: IP address, connection date and time, and history of actions performed in the customer area.
  • Service usage data: Order history and service usage history.
  • Exchanges and communications between the customer and the PulseHeberg teams: Support tickets, communication by email, via social media or any other communication channel.
  • Payment information: Last 4 digits of the bank card, last 4 digits of the bank account and the email address of the PayPal account, as well as the name of their holder.

Disclosure of personal data to third parties#

On the basis of legal obligations, your personal data may be disclosed in application of a law, a regulation or pursuant to a decision of a competent regulatory or judicial authority. In general, we undertake to comply with all legal rules that could prevent, limit or regulate the dissemination of information or data, and in particular to comply with Law No. 78-17 of 6 January 1978 relating to information technology, data files and civil liberties.

The personal data you provide to us when placing your order is transmitted to our suppliers and subsidiaries for its processing. This information is considered strictly confidential by our suppliers and subsidiaries.

Collection of identity data#

The use of our services requires prior registration and identification. Your personal data is used to fulfil our legal obligations arising from the delivery of services, under our general terms and conditions as well as the specific conditions of the service subscribed to. You must not provide false personal information and must not create an account for another person without their authorisation. Your contact details must always be accurate and up to date. Collection of device data Some of the technical data of your device is collected automatically by PulseHeberg. This information includes in particular your IP address, Internet service provider, hardware configuration, software configuration, browser type and language... The collection of this data is necessary for the provision of the services.

Use of cookies#

In accordance with the recommendations of the CNIL, the maximum retention period for cookies is 13 months at most after their first deposit in the User's terminal, as is the duration of the validity of the User's consent to the use of these cookies. The lifetime of cookies is not extended on each visit. The User's consent must therefore be renewed at the end of this period.

PulseHeberg only uses cookies that are essential to the operation of its services. These cookies are used for logging in to your customer account and for guaranteeing security when managing your services and your orders. In accordance with the regulations, these cookies are used without requiring your consent.

The PulseHeberg customer area and the PulseHeberg website may use the following cookies:

  • WHMCSxxxxxxxxx: This is a session cookie used by our customer area to make sure you are actually logged in to your customer account.
  • _GRECAPTCHA: This is a cookie used by our Google Recaptcha anti-bot system.
  • __stripe_mid: This is a cookie used by our credit card payment processor Stripe. This cookie enables anti-fraud analysis during a credit card payment.
  • adOtr: This is a session cookie used by our application protection system (WAF) Stackpath to make sure the visitor is a human.
  • PRLST: This is a session cookie used by our application protection system (WAF) Stackpath to make sure the visitor is a human.
  • sbtsck: This is a cookie used by our application protection system (WAF) Stackpath to make sure the visitor is a human.
  • sp_lit: This is a cookie used by our application protection system (WAF) Stackpath to make sure the visitor is a human.
  • spcsrf: This is a cookie used by our application protection system (WAF) Stackpath to prevent cross-site request forgery.
  • UTGv2: This is a cookie used by our application protection system (WAF) Stackpath to record that your browser is safe and to avoid further anti-bot checks.
  • sbbi: This is a session cookie used to control the connection to our CDN system.
  • SPSI: This is a session cookie that allows us to obtain data on the user behaviour of visits in order to improve the operation of our application protection (WAF).
  • crisp-client/*: This is a cookie used by our Chat support system that makes it possible to retrieve the conversation history when the user changes pages.

Retention period for personal data and anonymisation We keep personal data for as long as you hold a PulseHeberg customer account. Beyond that period, it will be anonymised and kept for exclusively statistical purposes and will not be used in any way whatsoever.

Data purge mechanisms are in place to provide for its effective deletion as soon as the retention or archiving period necessary for the accomplishment of the determined or imposed purposes has been reached. In accordance with Law No. 78-17 of 6 January 1978 relating to information technology, data files and civil liberties, you also have a right to deletion of your data, which you can exercise at any time by contacting PulseHeberg customer service.

Account deletion#

The User has the option of deleting their customer account at any time, simply by requesting it from support via their PulseHeberg customer area.

PulseHeberg undertakes to carry out the deletion of the account as soon as possible and under the following conditions:

  • Your personal data (last name, first name, billing address, email address, and password) is deleted immediately from our production database
  • Personal information may be kept in the backups of our database for a maximum of 1 year
  • Invoices and payment references are kept for a period of 10 years
  • Exchanges with our technical support are anonymised and kept for a period of 10 years

Instructions in the event of a security breach detected by PulseHeberg#

We undertake to implement all appropriate technical and organisational measures in order to guarantee a level of security appropriate to the risks of accidental, unauthorised or illegal access, disclosure, alteration, loss or destruction of personal data concerning you. Should we become aware of illegal access to personal data concerning you stored on our servers or those of our providers, or of unauthorised access resulting in the occurrence of the risks identified above, we undertake to:

  • Notify you of the incident as soon as possible
  • Examine the causes of the incident and inform you of them
  • Take the necessary measures within reasonable limits in order to reduce the negative effects and damage that may result from the incident.

In no case may the commitments defined in the point above relating to notification in the event of a security breach be construed as any admission of fault or liability regarding the occurrence of the incident in question.

Modification of the privacy policy#

We undertake to inform you in the event of a substantial modification of this Privacy Policy, and not to substantially lower the level of confidentiality of your data without informing you and obtaining your consent.

Applicable law and remedies#

This Privacy Policy and your use of the Site are governed and interpreted in accordance with the laws of France, and in particular Law No. 78-17 of 6 January 1978 relating to information technology, data files and civil liberties. The choice of applicable law does not affect your rights as a consumer in accordance with the applicable law of your place of residence.

If you are a consumer, you and we agree to submit to the non-exclusive jurisdiction of the French courts, which means that you may bring an action relating to this Privacy Policy in France or in the EU country in which you live.

If you are a professional, all actions against us must be brought before a court in France.

In the event of a dispute, the parties will seek an amicable solution before any legal action. Should these attempts fail, all disputes regarding the validity, interpretation and/or performance of the Privacy Policy must be brought, even in the event of multiple defendants or a third-party claim, before the French courts.

Exercising your rights#

For any information or to exercise your Data Protection and Civil Liberties rights regarding the processing of personal data processed and collected by PulseHeberg, you can contact our data protection officer (DPO):

  • by email: [email protected]
  • by post: PulseHeberg SAS - For the attention of the DPO - 9 boulevard de Strasbourg - 83000 Toulon - France