Terms of Service
Privacy Notice
Below is the Privacy Notice for DataPal Privacy Pulse
Draft dated: 7 September 2026
Effective date: 14 September 2026
Last updated: 14 September 2026
This Privacy Notice explains how Personal Data Labs UK Ltd, trading as DataPal, collects and uses personal information in connection with:
the DataPal Privacy Pulse website at privacypulse.datapal.me;
Privacy Pulse accounts, subscriptions, scans, monitoring and reports;
Privacy Pulse Index, our public domain-level record and benchmarking product;
enquiries, support, challenges and correction requests; and
related business communications.
It should be read together with the Privacy Pulse Terms of Service and Cookie Notice.
1. Who we are
Personal Data Labs UK Ltd, trading as DataPal, is the controller of the personal information described in this Notice.
Registered company: Personal Data Labs UK Ltd
Company number: SC777053
Registered office: 4/5 Turnberry House, 175 West George Street, Glasgow, Scotland, G2 2LB
Privacy contact: privacypulse@datapal.me
ICO registration number: ZB697162
When this Notice says DataPal, we, us or our, it means Personal Data Labs UK Ltd.
2. Who this Notice applies to
This Notice applies to:
representatives and employees of business customers and prospective customers;
agency, consultancy and partner users;
people who administer or use a Privacy Pulse account;
people who contact us for support, sales or other business purposes;
domain owners, website operators and their representatives who contact us about a Privacy Pulse or Privacy Pulse Index result;
suppliers and professional contacts; and
visitors to the Privacy Pulse website.
Privacy Pulse is a business-to-business service and is not offered to consumers or children.
3. Our approach to website scanning and personal information
Privacy Pulse scans only domains and web pages that are accessible on the public internet using ordinary HTTP or HTTPS requests and without authentication.
The scanner loads a site in three separate clean browser sessions:
without interacting with the consent interface;
after selecting an available acceptance option; and
after selecting an available refusal or rejection option.
The scanner is designed to observe and retain non-personal technical information, such as:
public domain names and URLs;
cookie names, categories and attributes;
contacted domains and technical service providers;
network destinations and request classifications;
response headers;
consent-interface behaviour;
page structure relevant to consent choices;
detected technologies;
scores, grades and finding categories; and
scan dates, technical context, methodology versions and evidence fingerprints.
The scanner is not designed to collect, record or retain personally identifiable information about visitors to a scanned website or people whose information may appear on that website. It does not intentionally:
enter names, contact details or other personal information;
complete ordinary forms;
enter credentials or access authenticated areas;
create accounts;
make purchases;
upload files; or
capture text entered into website forms.
It is nevertheless possible for a public website to unexpectedly expose personal information in a URL, technical response, cookie identifier or data payload. If we identify this, we may stop or exclude the scan and suppress, redact, isolate or delete the affected information. We do not use incidentally encountered personal information to profile website visitors or enrich Privacy Pulse Index.
You must not submit a URL deliberately constructed to contain personal information, credentials, authentication tokens, special-category information or confidential information.
3A. Data minimisation by design
The scanner is engineered to observe how a website behaves without retaining the identifiers that behaviour produces. In particular, from engine version 0.3.1:
Cookie values are never recorded: We record the cookie name, domain, path, expiry, and classification. The value of a cookie (which is commonly the identifier assigned to a visitor) is never written to our systems.
Query strings are reduced to parameter names: The values of URL parameters are actively stripped and removed before the record is created and are not retained.
Request bodies are captured as a limited excerpt: We retain an excerpt of no more than 500 characters, in which fields that appear to contain credentials, tokens, or email addresses are replaced with a redaction marker. We do not retain full request bodies.
These measures operate automatically on every scan and cannot be disabled by a customer.
4. Personal information we may collect
We may collect, or you may supply, the following limited categories of personal information.
4.1 Account and business contact information
name;
business email address;
business telephone number, if provided;
job title, role and department;
employer or organisation;
account ID and account permissions; and
sign-in, authentication and account-status information.
4.2 Subscription and transaction information
Plan, allowances and account entitlements;
billing contact and business address;
invoices, transaction dates, amounts and payment status;
subscription renewal and cancellation information; and
payment-provider customer or transaction references.
We do not intend to store complete payment-card details. These should be collected and processed by our payment provider, Stripe - https://stripe.com/gb
4.3 Service-use and security information
scans requested and domains submitted;
scan and monitoring activity associated with an account;
report access, downloads and authorised sharing activity;
IP address, approximate location derived from IP address, device and browser information;
login timestamps, session and security logs;
feature use, errors, diagnostics and performance information; and
suspected abuse, restrictions, blacklist decisions and security incidents.
4.4 Communications
enquiries, support requests and feedback;
sales and account-management communications;
challenge, correction, rescan and blocked-domain review requests;
evidence of authority to represent or control a domain; and
communication preferences.
4.5 Marketing information
whether you have asked to receive updates;
the communications sent to you;
whether you opened or interacted with a communication, where permitted; and
unsubscribe or objection records.
4.6 Privacy Pulse Index information that may relate to an individual
Most Privacy Pulse Index records concern companies, organisations and public domains rather than individuals. A domain name, business name or public website may sometimes relate to an identifiable sole trader, professional or other individual. In that limited situation, the public domain-level record may constitute personal information.
Privacy Pulse Index does not publicly identify the customer, account or user who requested a scan. Privacy Pulse Index only reports on what is already in the public domain.
5. How we obtain personal information
We obtain personal information:
directly from you when you register, buy or use the Service, contact us or submit a request;
from your employer, organisation or account administrator;
automatically when you use the Privacy Pulse website or account;
from payment, identity, authentication, hosting and security providers;
from public business websites and professional sources;
from a person who asks us to scan or monitor a public domain; and
from a domain owner or authorised representative who challenges or comments on a result.
6. Why we use personal information and our lawful bases
We use personal information only where we have a lawful basis under applicable data-protection law.
6.1 Purpose: Create and administer business accounts
Types of information: Account, business contact and authentication information
Lawful basis: Performance of a contract; legitimate interests in providing and administering a B2B service
6.2 Purpose: Provide scans, reports, monitoring, subscriptions and support
Types of information: Account, service-use, transaction and communication information
Lawful basis: Performance of a contract; legitimate interests in delivering and improving the Service
6.3 Purpose: Process payments, invoices and renewals
Types of information: Business contact, subscription and transaction information
Lawful basis: Performance of a contract; legal obligations relating to tax and accounting
6.4 Purpose: Secure Privacy Pulse and prevent misuse
Types of information: Service-use, device, IP, authentication and security information
Lawful basis: Legitimate interests in protecting DataPal, customers, suppliers, target sites and the Service; compliance with legal obligations where applicable
6.5 Purpose: Enforce our Terms and manage disputes
Types of information: Account, service-use, transaction, security and communication information
Lawful basis: Legitimate interests in protecting our legal rights and operating the Service responsibly; legal claims
6.6 Purpose: Operate and improve Privacy Pulse
Types of information: Service-use, diagnostic, support and feedback information
Lawful basis: Legitimate interests in developing, testing and improving our products and methodology
6.7 Purpose: Create and maintain Privacy Pulse Index
Types of information: Public domain-level results and, where applicable, limited information connected with a sole trader or identifiable professional
Lawful basis: Legitimate interests in providing transparent domain-level technical observations, longitudinal benchmarking, research and market insight
6.8 Purpose: Publish named domain-level records
Types of information: Public domain, dated score and grade, summary findings, historical results and methodology information
Lawful basis: Legitimate interests in maintaining a useful, accountable and publicly accessible record of technical website behaviour
6.9 Purpose: Produce sector, industry and market statistics
Types of information: Aggregated scan data using appropriate cohort thresholds
Lawful basis: Legitimate interests in research, benchmarking, product development and informing the market; published outputs should not identify individuals
6.10 Purpose: Review challenges and corrections
Types of information: Contact details, domain-authority evidence, correspondence and relevant result data
Lawful basis: Legitimate interests in maintaining accuracy, fairness and accountability and resolving concerns
6.11 Purpose: Send service communications
Types of information: Account and business contact information
Lawful basis: Performance of a contract; legitimate interests in administering the Service
6.12 Purpose: Send business marketing
Types of information: Business contact information and communication preferences
Lawful basis: Legitimate interests where permitted; consent where required by applicable electronic-marketing law
6.13 Purpose: Comply with law and regulatory requests
Types of information: Relevant account, transaction, security and communication information
Lawful basis: Compliance with legal obligations; legitimate interests in cooperating with lawful requests
Where we rely on legitimate interests, we consider whether the use is necessary and proportionate and balance our interests against the rights and interests of affected people. You may request information about an applicable legitimate-interests assessment by contacting us.
7. Privacy Pulse Index
Every scan submitted through Privacy Pulse will be added to Privacy Pulse Index, including scans under free and paid Plans, repeated scans and scans that are incomplete or Unrated.
Privacy Pulse Index may publicly display:
the public domain name;
scan date and technical context;
score and grade;
detected technologies;
summary finding categories and severities;
observed consent behaviour;
historical results and changes over time; and
methodology or rubric information.
Privacy Pulse Index does not publish the identity of the customer or user who requested the scan. Full customer reports and detailed evidence remain accessible only through the authenticated customer account and to users authorised by that customer.
We principally publish sector, industry, territory, technology and market statistics using sufficiently robust cohorts. We may take steps to prevent repeated scans of one domain from disproportionately influencing aggregate statistics.
Privacy Pulse Index is longitudinal. Domain-level scan records may be retained indefinitely to show historical change. Every result should be read as an observation made at the stated time using the stated methodology—not as a guarantee about the website’s present configuration.
8. Challenges, corrections and objections
A domain owner or authorised representative may:
challenge a result;
report a factual or technical error;
provide relevant context;
request a correction or rescan;
ask us to review a blocked-domain decision; or
object to processing that relates to them personally.
Requests may be submitted through privacypulse@datapal.me. We may ask for reasonable evidence that you control or are authorised to represent the domain.
We will consider credible challenges within a reasonable period. Depending on the circumstances, we may correct, annotate, temporarily mark as under review, suppress, replace or retain a result. A new scan does not necessarily erase an accurate historical record.
You have the right to object to processing based on our legitimate interests where it concerns your personal information. We will consider your circumstances and stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is needed for legal claims. The right to object to direct marketing is absolute; if you object, we will stop using your information for that purpose.
9. Automated analysis
Privacy Pulse automatically analyses public website behaviour and generates scores, grades and findings about domains. These outputs concern the technical behaviour of a website and are not intended to make decisions about an individual that produce legal or similarly significant effects.
We do not use Privacy Pulse to evaluate an individual’s creditworthiness, employment, health, eligibility, behaviour or personal characteristics.
10. Who we share personal information with
Where necessary, we may share limited personal information with:
cloud hosting and infrastructure providers;
account-authentication and identity providers;
payment and billing providers;
email, customer-support and business-communications providers;
security, monitoring, logging and fraud-prevention providers;
professional advisers, auditors and insurers;
contractors supporting the operation of Privacy Pulse under appropriate obligations;
a buyer, investor or successor in connection with a proposed or completed corporate transaction; and
courts, regulators, law-enforcement bodies or other authorities where disclosure is required or lawfully appropriate.
We require service providers handling personal information for us to protect it and use it only for the agreed purposes.
We do not sell personal information about Privacy Pulse users or website visitors. This does not prevent us from commercialising Privacy Pulse Index, domain-level results, aggregated statistics or effectively anonymised insights that do not identify the customer who requested a scan or any website visitor.
10A. Sub-processors
The following providers process personal information, or scan traffic, on our behalf:
Google Cloud: Hosting, infrastructure, database. Location: Belgium (EEA).
AWS Cognito: Account authentication. Location: London, UK.
Stripe: Payments and subscription billing. Location: EU and US.
Resend, Inc.: Sending of account and monitoring emails. Location: US (established), EU (dispatched).
MaxMind, Inc.: Approximate geolocation. Location: Database held locally in our GCP environment.
[Residential Proxy Provider - e.g., Bright Data]: Routing of residential-route scans. Location: Exit country as stated on the report. (To be finalized upon KYC approval).
11. International transfers
Some suppliers may process personal information outside the United Kingdom. Where a restricted international transfer occurs, we will use an appropriate legal mechanism, which may include:
UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to the EU Standard Contractual Clauses; or
another lawful safeguard or exception.
Where required, we assess whether the destination and safeguards provide an appropriate level of protection. Contact us for further information about the safeguards relevant to your personal information.
12. How long we keep information
We keep personal information only for as long as reasonably necessary for the purposes described above, including providing the Service and meeting legal, accounting, security and dispute-resolution requirements.
Our intended retention framework is:
12.1 Information: Active account and authentication information
Intended retention: For the life of the account
12.2 Information: Closed-account profile and service history
Intended retention: up to 6 years after closure.
12.3 Information: Billing, invoice and transaction records
Intended retention: up to 6 years.
12.4 Information: Customer reports
Intended retention: For as long as the account is open.
12.5 Information: Security and access logs
Intended retention: up to 24 months.
12.6 Information: Support and routine correspondence
Intended retention: up to 2 years after closure of any matter.
12.7 Information: Contractual and dispute records
Intended retention: For the relevant limitation period and while a dispute or investigation remains active
12.8 Information: Marketing records
Intended retention: Until you unsubscribe or object, plus a minimal suppression record so we honour your preference
12.9 Information: Challenge and correction records
Intended retention: For the life of the Index record plus 6 years.
12.10 Information: Domain-level Privacy Pulse Index records
Intended retention: Indefinitely as a longitudinal historical record
12.11 Information: Incidentally encountered personal information from a scanned site
Intended retention: Suppressed, redacted, isolated or deleted as soon as reasonably practicable after identification, unless retention is legally required for security or evidence purposes
12.12 Information: Technical scan evidence supporting a customer report.
Intended retention: For as long as the associated report is retained, because reports are generated from it. Evidence is held in a database whose backups are overwritten on a rolling basis: within 30 days in our production environment and within 7 days in non-production environments. Evidence for an Anonymous Scan is deleted after 7 days.
Domain-level information relating only to a company or organisation is not personal information. If a Privacy Pulse Index record relates to an identifiable individual, we will periodically consider whether its continued retention remains necessary, proportionate and lawful.
Information may remain for a limited period in protected backups before being overwritten. We may retain information for longer where required by law, necessary for legal claims or reasonably required to investigate fraud, abuse or security incidents.
13. How we protect personal information
We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, alteration, disclosure or destruction. These include, as appropriate:
access controls and account authentication;
encryption in transit and, where appropriate, at rest;
separation of customer reports from public Index records;
authenticated report access;
logging, monitoring and incident management;
supplier due diligence and contractual controls;
isolated scanning environments and restricted network access;
data minimisation, suppression and redaction; and
staff access limited according to role and need.
No internet service can guarantee absolute security. You must keep your account credentials confidential and notify us promptly if you suspect unauthorised use.
14. Your data-protection rights
Depending on the circumstances and lawful basis, you may have the right to:
ask for access to your personal information;
ask us to correct inaccurate or incomplete personal information;
ask us to erase personal information;
ask us to restrict processing;
object to processing based on legitimate interests;
object to direct marketing;
receive certain information in a portable format;
withdraw consent where we rely on consent; and
complain to a data-protection regulator.
These rights are not absolute and may not apply to information about a company or to every circumstance. A request concerning a public domain score is not necessarily a request concerning personal information, but it may still be considered through our Index challenge process.
To exercise a right, contact privacypulse@datapal.me. We may ask for information necessary to confirm your identity and locate the relevant records. We will normally respond within one month, subject to any lawful extension.
15. Marketing preferences
You may opt out of marketing at any time by using the unsubscribe link in an email or contacting privacypulse@datapal.me.
Even if you opt out of marketing, we may still send essential account, billing, security, Terms, Privacy Notice and service communications.
16. Cookies and similar technologies on Privacy Pulse
Privacy Pulse may use strictly necessary cookies and similar technologies to provide authentication, account security and core functionality. Any optional analytics or other non-essential technologies will be described and managed as set out in our Cookie Notice at https://www.datapal.me/cookies.
This section concerns technologies used on the Privacy Pulse service itself. It is separate from the cookies and technologies observed when Privacy Pulse scans a public website.
17. Children
Privacy Pulse is a B2B service for adults acting in a professional capacity. It is not directed at children, and we do not knowingly permit children to create accounts.
18. Complaints
Please contact us first if you have a concern about our use of personal information:
Email: privacypulse@datapal.me
Address: Personal Data Labs UK Ltd, 4/5 Turnberry House, 175 West George Street, Glasgow, Scotland, G2 2LB
You also have the right to complain to the UK Information Commissioner’s Office:
Website: ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113
If you are located outside the United Kingdom, you may also have the right to complain to the data-protection authority where you live or work.
19. Changes to this Notice
We may update this Privacy Notice when our products, suppliers, legal obligations or data practices change. We will publish the updated version with a revised date. If a change materially affects how we use personal information, we will provide reasonable additional notice where appropriate.
20. Contact us
Personal Data Labs UK Ltd, trading as DataPal
4/5 Turnberry House
175 West George Street
Glasgow, Scotland
G2 2LB
Privacy email: privacypulse@datapal.me

