Skip to content
P Puls

HR | EN

Sign in

Back to Puls

Data processing agreement

Version of 3 September 2026. An integral part of the Puls Terms of use.

This agreement governs the processing of personal data that Dodana vrijednost d.o.o. carries out for a client of the Puls service. It is concluded under Article 28 of Regulation (EU) 2016/679, the General Data Protection Regulation, referred to below as the GDPR. If your company uses Puls, your company is the controller and we are the processor who processes the data on your instructions.

1. The parties

The controller is the client of the Puls service, the legal person that opened a workspace in the application and that decides on the purposes and means of processing the data it enters into Puls.

The processor is Dodana vrijednost d.o.o., Ribnjak 56, 10000 Zagreb, Croatia, company identification number (OIB) 28795267248, registered in the court register of the Commercial Court in Zagreb. The address for data protection questions is info@puls-value.com.

The processor processes personal data solely on behalf of the controller and has no right to decide on the purposes of the processing.

2. Subject matter and duration

The subject matter of this agreement is the processing of personal data necessary to deliver the Puls service as that service is described in the Terms of use.

The processing lasts for as long as the Puls subscription lasts. That includes the trial period and any period in which access to the workspace is locked while the user account still exists. When the service ends, Article 13 of this agreement applies.

3. Nature and purpose of the processing

The purpose of the processing is the delivery of the Puls service. That covers the hosting and processing of the controller's financial figures, users and documents in order to present the plan and the result, the indicators, the cost structure, the monthly commentary and the business plan document, and in order to run user accounts, charge the subscription and provide technical support.

The processing operations are collection, recording, storage, access, calculation, presentation, export at the user's request, backup and deletion.

The processor does not use the controller's data for its own purposes, does not sell it and does not use it for profiling.

4. Types of personal data

  • Names and business e-mail addresses of the workspace users.
  • Sign-in data, including the password stored in a form that cannot be read back, sign-in times and access records.
  • Company and billing data, including the company name, address, identification number and details of the invoices issued.
  • Personal data that may appear in ledger line descriptions, in the names of business partners and in the employee count.
  • The content of documents and files that the controller uploads to Puls or composes inside Puls.
  • The questions a user types into the AI consultant.

5. Categories of data subjects

  • Users of the controller's workspace.
  • Employees of the controller.
  • Customers, suppliers and other business partners named in the ledger.
  • People named in documents that the controller uploads to Puls.

6. Documented instructions

The processor processes personal data only on the documented instructions of the controller. Instructions means this agreement, the Terms of use and every action a user starts inside the application, for example a data import, building a plan, requesting a commentary or an export. The instructions also cover any transfer of personal data to a third country or to an international organisation, which is permitted only where this agreement provides for it or where European Union law or Croatian law requires it.

If European Union law or Croatian law requires the processor to process data beyond those instructions, the processor informs the controller before the processing takes place, unless that law expressly prohibits such notice.

The processor informs the controller immediately if it considers that an instruction infringes the GDPR or another data protection law.

7. Confidentiality

Only persons who need access in order to do their work have access to the controller's data. Every such person is bound to confidentiality by contract or by a statutory duty, and that duty continues after their engagement ends.

8. Security of processing under Article 32 of the GDPR

The processor applies the following technical and organisational measures.

  • All traffic between the browser and the application runs over an encrypted connection (TLS).
  • The data of each company is separated at row level in the database. Isolation rules check the ownership of every row before it is read and before it is written, so one workspace cannot see the data of another.
  • Passwords are stored in a form that cannot be read back. Access tokens for connected services, for example e-Računi, are stored encrypted.
  • Data is stored and processed on servers inside the European Union. The database is in Frankfurt and the server on which the application runs is in Nuremberg.
  • The database has daily automatic backups with seven days of history, made by the database provider listed in Annex 1. The restore procedure is documented and covers the choice of the day, the restore of the database and the restart of the application.
  • Sign-ins and data access are written to logs. Those logs are kept by the database provider and by the server on which the application runs, that is, in systems separate from the data the logs describe.
  • The least privilege rule applies. Every person and every component of the system receives only the rights that the work at hand requires.
  • Access to the server is possible only with a cryptographic key, sign-in with a password is switched off, and the firewall passes only the traffic that the operation and the maintenance of the service require.
  • The development and production environments are separated. Development runs on a local computer with demonstration data and does not touch production data.
  • The operating system of the server receives security updates from its distribution regularly.

9. Sub-processors

The controller gives a general prior authorisation for the engagement of sub-processors. The list of sub-processors engaged on the date of this version of the agreement is set out in Annex 1.

With every sub-processor the processor agrees data protection obligations that are no weaker than the obligations in this agreement, and the processor remains liable to the controller for the work of a sub-processor as for its own.

The processor gives the controller at least 30 days notice of an intention to add or replace a sub-processor, by e-mail to the workspace owner and by publishing the amended Annex 1 on this page. Within that period the controller may raise a reasoned objection. If the objection remains unresolved, the controller may cancel the subscription before the change takes effect, and access remains active until the end of the paid period.

10. Transfers outside the European Economic Area

The data is processed in the European Union. A transfer to a third country takes place only to the sub-processors listed in Annex 1 and only under the European Commission standard contractual clauses, with a transfer impact assessment carried out beforehand.

If those measures cease to be sufficient for a transfer, the processor suspends the transfer and informs the controller.

11. Assistance to the controller

Taking into account the nature of the processing, the processor assists the controller by appropriate technical and organisational measures in responding to requests from data subjects under Chapter III of the GDPR, that is requests for access, rectification, erasure, restriction of processing, portability and objection.

If a data subject request reaches the processor directly, the processor forwards it to the controller without delay and does not act on it independently.

The processor also assists the controller in meeting the obligations of Articles 32 to 36 of the GDPR, that is security of processing, breach notification, data protection impact assessment and prior consultation with the supervisory authority, to the extent that the information is available to the processor.

12. Personal data breach

The processor notifies the controller of any personal data breach without undue delay after becoming aware of it, and early enough for the controller to meet its own duty to notify the supervisory authority.

The notice describes the nature of the breach, the approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed and the contact person at the processor from whom further information can be obtained.

The processor keeps a record of breaches and of the measures taken and makes it available to the controller on request.

13. Deletion or return of the data

When the service ends the processor, at the choice of the controller, returns the data in a machine readable form or deletes it, together with any existing copies.

The controller communicates that choice within 30 days of the end of the service. After that period, and at the latest 90 days after the end of the service, the processor deletes the data.

For as long as the user account exists the data remains stored, including while access is locked because the trial period expired or the subscription is unpaid.

The exception to deletion is data the processor is required by law to retain, above all issued invoices and fiscal records. The processor keeps those until the statutory retention period expires and processes them for no other purpose.

Data held in backups is deleted in the regular rotation cycle of those backups.

14. Audit and inspection

The processor makes available to the controller all information necessary to demonstrate compliance with the obligations of Article 28 of the GDPR and allows for audits, including inspections, conducted by the controller or by an auditor the controller mandates.

An audit is announced at least 30 days in advance, takes place during working hours and in a way that does not disrupt the service. An audit may not reach the data of other clients. The controller bears the cost of the audit, unless the audit establishes a material breach of this agreement.

15. Liability

The liability of the parties is governed by the Puls Terms of use and by mandatory law. This agreement neither widens nor narrows the limitation of liability set out in the Terms of use, except where the GDPR provides otherwise.

16. Governing law

This agreement is governed by the law of the Republic of Croatia and by the GDPR. The competent court in Zagreb has jurisdiction over disputes.

17. Acceptance, changes and version

This agreement applies upon acceptance of the Puls Terms of use. No separate signature is required and there is no separate signing workflow.

We notify the controller of material changes to this agreement in advance, by e-mail and by publishing them on this page with the version date stated.

If a provision of this agreement conflicts with the Terms of use, this agreement prevails in matters of personal data processing.

Version: 3 September 2026.

Annex 1. List of sub-processors

Sub-processor Role Place of processing
Supabase Database, user authentication and file storage. European Union, Frankfurt
Hetzner Online GmbH The server the application runs on. Germany, Nuremberg
Anthropic The monthly AI commentary and the AI consultant. What is sent are the calculated aggregate indicators and the questions the user types, never the source files and never individual ledger lines. United States, with the European Commission standard contractual clauses as the transfer safeguard
Brevo Sending transactional e-mail, for example account confirmations and subscription notices. European Union, France
Stripe Subscription payment and subscription management. For payment data Stripe acts as an independent controller, and for subscription data as a sub-processor. We do not store payment card data, Stripe holds it. European Union, Ireland, with safeguards for transfers outside the European Economic Area
e-Računi Issuing and fiscalising subscription invoices. For clients who connect their own e-Računi organisation, also reading ledger data, solely through an access token the client issues. Croatia and Slovenia
Cloudflare DNS and cookieless visit measurement on the public pages. The application and the data inside it do not pass through this service. European Union and the global delivery network, with the European Commission standard contractual clauses for transfers outside the European Economic Area

This list is valid as at 3 September 2026. Changes are announced under Article 9 of this agreement.

Send questions about this agreement and about data protection to info@puls-value.com. The Puls privacy policy and terms of use are available in the application.

P Puls

A monthly view of the business and a business plan for small and medium companies. A product of Dodana vrijednost d.o.o.

Puls

What you get Business plan Pricing Sign in to the application

Company

About Dodana vrijednost Bookkeeping Advisory Training

Legal

Terms of use Privacy policy Data processing agreement

Contact

info@puls-value.com Enquiry form dodana-vrijednost.hr
© 2026 Dodana vrijednost d.o.o. All rights reserved. Ribnjak 56, 10000 Zagreb, Croatia · OIB 28795267248 · registered in the court register of the Commercial Court in Zagreb
The data is kept on servers in the European Union. Puls provides informative analysis, not tax or legal advice.