Terms of Service
Terms of Service
Below are the Terms of Service for DataPal Privacy Pulse
Draft dated: 7 September 2026
Effective date: 9 September 2026
These Terms of Service (the Terms) govern access to and use of DataPal Privacy Pulse at privacypulse.datapal.me, including its website-scanning, monitoring and reporting services, and Privacy Pulse Index, the related public record and benchmarking product (together, the Service).
The Service is provided by Personal Data Labs UK Ltd, trading as DataPal, a company registered in Scotland under company number SC777053, whose registered office is at 4/5 Turnberry House, 175 West George Street, Glasgow, Scotland, G2 2LB (DataPal, we, us or our).
By creating an account, submitting a domain or URL for scanning, buying a Plan, or otherwise using the Service, you agree to these Terms. If you use the Service for an organisation, you confirm that you have authority to accept these Terms for that organisation; references to you include that organisation.
If you do not agree to these Terms, do not use the Service.
1. Who may use the Service
1.1 You must be at least 18 years old and legally able to enter into a contract.
1.2 The Service is offered solely on a business-to-business basis. You may use it only in the course of a business, trade, profession, public function or organisational activity, including on behalf of a company, public body, charity, agency, consultancy or other organisation. You must not create an account or buy a Plan as a consumer.
1.3 You must provide accurate account and billing information, keep it up to date, keep your sign-in credentials secure, and promptly notify us at privacypulse@datapal.me if you suspect unauthorised account use. You are responsible for activity carried out through your account unless it results from our breach of duty.
2. What Privacy Pulse does
2.1 Privacy Pulse is an automated technical observation and auditing service. It scans only domain names and web pages that are accessible on the public internet using ordinary HTTP or HTTPS requests and without authentication. For a standard scan, the Service attempts to load a publicly accessible website in three separate clean browser sessions:
without interacting with the site or its consent interface;
after selecting an available acceptance option; and
after selecting an available refusal or rejection option, including navigating a preferences interface where reasonably necessary.
2.2 During those sessions, the Service may observe and record non-personal technical information made available to the browser, including cookie names and attributes, categories of storage technology, network destinations, contacted domains and services, response headers, consent-interface behaviour, page structure and other technical evidence. It compares the sessions and applies the then-current Privacy Pulse rules, scoring methodology and regulatory reference framework.
2.3 The scanner is designed not to collect, record or retain personally identifiable information about website visitors or people whose information may appear on a target website. It does not populate ordinary website forms, enter credentials, create accounts, make purchases or intentionally capture form contents. If personal information is unexpectedly exposed within a public URL, response or technical payload, we may suppress, redact, isolate or delete it and may stop or exclude the affected scan.
2.4 Depending on your Plan and the scan outcome, the Service may provide an online result, grade, score, findings, supporting technical evidence, suggested remediation, downloadable report, monitoring, change notification, bulk-scanning capability or other features described on the pricing page or in an order form.
2.5 A scan is a snapshot of what the Service could observe from a particular technical environment, location and time, using the rubric version stated in the report. Website behaviour may vary by location, device, browser, user status, language, traffic source, experimentation, configuration, bot protection, prior interactions or later changes.
2.6 We may mark a scan Unrated, incomplete or unsuccessful where the Service cannot complete the relevant tests, including because of bot protection, access controls, timeouts, technical errors, an unsupported consent interface or website behaviour. An incomplete scan is not evidence that a website is compliant or free from risk.
3. Important limitations: not legal advice or certification
3.1 The Service and its reports provide automated technical observations and general information. They do not constitute legal advice, a legal opinion, regulatory approval, a formal audit, certification, warranty of compliance or guarantee that a website complies or does not comply with any law.
3.2 References to legislation, regulators, standards, possible violations, risk levels or remediation are indicative and may not account for the website operator’s lawful bases, contracts, policies, server-side processing, records of processing, exemptions, jurisdiction, factual context or legal interpretation.
3.3 Automated scanning can produce false positives, false negatives, incomplete findings or misclassification. The Service cannot detect every technology, transmission, consent mechanism, legal basis, data flow, security weakness or compliance issue.
3.4 Grades, scores and labels such as “critical”, “fail”, “defensible”, “compliant”, “violation” or similar terms are outputs of the Privacy Pulse methodology. They should be read in the context of the complete report and its stated limitations, not as definitive legal conclusions.
3.5 You are responsible for independently reviewing findings before making legal, regulatory, technical, commercial, employment or public statements in reliance on them. Where appropriate, obtain advice from suitably qualified legal, privacy, security or technical professionals.
4. Your right to submit a site and permitted scanning
4.1 You may submit only URLs and domains that are publicly accessible without authentication and that you are legally permitted to test in the manner described in section 2.
4.2 You may scan:
a site you own or operate;
a site for which the owner or operator has authorised you to conduct the scan; or
another public-facing site for a legitimate and lawful professional purpose, such as due diligence, research, benchmarking or preparing to offer relevant professional services, provided that your use is not abusive, misleading, harassing or otherwise prohibited by these Terms.
4.3 Submitting a domain does not give you any ownership of, or other rights in, that site, its content or its data. You are responsible for determining whether you need the website operator’s permission and for obtaining it where required.
4.4 You must not use the Service to access authenticated, private, restricted or non-public areas; bypass technical restrictions; exploit vulnerabilities; submit forms other than consent controls used by the scan; make purchases; create accounts on a target site; or obtain content or data that an ordinary public visitor would not be entitled to receive.
4.5 You must not represent that DataPal instructed, sponsored, endorsed or authorised your scan or any approach you make to a website operator unless we have expressly agreed this in writing.
5. Prohibited use and restricted websites
5.1 You must not use or attempt to use the Service:
unlawfully, fraudulently, deceptively or to facilitate unlawful activity;
to damage, disrupt, degrade, overload or interfere with the Service, a target website or any other system;
to conduct denial-of-service activity, penetration testing, vulnerability exploitation, credential attacks, malware analysis or security testing beyond the ordinary website observations expressly provided by the Service;
to evade scan limits, access controls, rate limits, blocks or safety measures, including by creating multiple accounts or rotating domains or identities;
to scrape, reverse engineer, copy or systematically extract the Service, its scoring logic, reports, datasets or user interface, except to the extent the law does not permit that restriction;
to generate reports or statements that are false, altered, misleading, defamatory, threatening, harassing or used to coerce a website operator;
to scan a site for surveillance, stalking, discrimination or another purpose that may harm an individual; or
to upload or introduce malware, malicious code or content.
5.2 For safety, legal, ethical, operational and reputational reasons, we may refuse, stop, quarantine, restrict or remove a scan, and may block or blacklist a domain, URL, category of site, account, user, IP address or territory. This may include sites that contain, distribute, promote or facilitate suspected:
child sexual abuse material or exploitation;
non-consensual intimate imagery, trafficking or serious abuse;
malware, phishing, fraud, credential theft or cybercrime;
terrorism or violent extremist content;
unlawful hate content or incitement to violence;
illegal goods, services or content;
material that creates a material risk to our people, suppliers, systems or infrastructure; or
other content or activity that we reasonably consider unlawful, harmful, unsafe, technically hazardous or inconsistent with the legitimate purpose of the Service.
5.3 We may also restrict scans of authenticated services, private networks, local or loopback addresses, infrastructure endpoints, critical national infrastructure, government or military systems, financial transaction endpoints, healthcare systems, adult-content sites, gambling sites, sanctions-related targets or any other high-risk category where we reasonably consider additional controls or evidence of authority necessary.
5.4 A decision to permit or block a scan is an operational risk-control decision. It is not a judgment about the legality, morality, safety or compliance of a website. We are not required to publish our blocklist or detailed detection criteria where doing so could create security, legal or abuse risks.
5.5 You must not try to evade a restriction or blacklist. If you believe a site has been blocked in error, contact privacypulse@datapal.me.
5.6 To protect DataPal, our suppliers, target websites and other users, we may apply technical and operational safety controls to any submitted target. These may include:
accepting only public http:// and https:// destinations on permitted ports;
validating the submitted hostname and its resolved destination before a scan begins;
blocking loopback, private, link-local, reserved, internal-network, cloud-metadata and other non-public destinations;
revalidating every redirect and stopping a scan if a redirect leads to a prohibited or non-public destination;
limiting request rates, scan frequency, concurrency, retries, redirects, duration, page depth and resources consumed;
preventing logins, credential entry, purchases, account creation, file uploads and form submission other than interaction with a consent control required for the three-session scan;
isolating scan sessions and stopping or quarantining a scan where malicious code, malware, dangerous downloads or other harmful behaviour is detected; and
applying restricted-site classifications, allowlists, blocklists and manual review.
5.7 We may change these controls without notice and are not required to disclose configurations, thresholds or detection criteria where disclosure could weaken security or enable evasion. A scan that is blocked, limited or stopped for safety reasons may be recorded as unsuccessful or Unrated.
5.8 A business responsible for a blocked domain may ask us to review the restriction by contacting privacypulse@datapal.me and supplying reasonable evidence of its authority and the intended use. We may uphold, vary or remove the restriction at our reasonable discretion. We are not obliged to permit a scan that we reasonably consider unsafe, unlawful or inconsistent with these Terms.
6. Privacy Pulse Index and use of scan data
6.1 Every scan submitted to Privacy Pulse will be added to Privacy Pulse Index, whether the scan is initiated under a free or paid Plan and whether it is complete, incomplete or repeated. Privacy Pulse Index is a separate DataPal product that creates a public, evolving record of privacy-related technical observations concerning domains available on the public internet.
6.2 Privacy Pulse Index may retain and display the submitted public domain name, scan date and technical context, score and grade, detected technologies, summary categories and severities of findings, observed consent behaviour, report metadata, evidence-derived non-personal technical indicators, historical results and changes between scans. The full customer report and its detailed evidence remain subject to the access controls in section 12.4.
6.3 We may use scan data and Privacy Pulse Index to:
operate, secure, maintain, test and improve the Service and its scoring methodology;
identify errors, abuse, false positives and false negatives;
compare results over time and between sectors, industries, technologies, territories or other cohorts;
produce high-level statistics, insights, research and trend reports;
develop new products and services; and
support legitimate internal analysis and commercial planning.
6.4 Named domain-level scores, grades, dates and summary findings may be published and made visible online as part of the publicly accessible record maintained by DataPal through Privacy Pulse Index. Publication of a domain result does not mean that the domain owner commissioned, approved or endorsed the scan. We will not publicly identify the customer, account or individual user who requested a scan unless that information is already public or the relevant party has agreed.
6.5 We will principally use aggregate data and sufficiently robust cohorts when publishing industry, sector, territory, technology or market-level statistics, so that conclusions are not based on an unreasonably small or misleading sample. We may set and change minimum cohort thresholds according to the nature of the analysis and available dataset.
6.6 Privacy Pulse Index is longitudinal. We may retain domain-level scan records indefinitely so that changes and trends can be measured over time. Each record is time-stamped and should be understood as a historical observation, not a statement about the domain’s current configuration. Older results naturally become less current as websites and the Privacy Pulse methodology change, but they may remain visible as part of the historical record.
6.7 A domain may be scanned repeatedly at any frequency permitted by the applicable Plan and our fair use and safety controls. A new scan does not erase an earlier result. Privacy Pulse Index may show the latest result, historical results, the direction of change or a representative result, and may apply reasonable controls to avoid repeated scans distorting aggregate statistics.
6.8 A domain owner or authorised representative may challenge a published result, report a factual or technical error, provide relevant context or request a correction or rescan through privacypulse@datapal.me. We may ask for evidence of authority over the domain. We will review credible challenges within a reasonable period and may correct, annotate, temporarily suppress, replace or retain a result as appropriate. A challenge does not automatically require removal of an accurate historical observation.
6.9 Privacy Pulse Index records automated technical observations rather than allegations about any person. We may remove or suppress any personal information that is inadvertently included and will not use Privacy Pulse Index to identify the customer or user who initiated a scan.
6.10 You must not submit URLs deliberately constructed to include personal information, credentials, authentication tokens, special-category information or confidential information. Where practicable, submit only a domain name or the shortest public URL necessary for the scan.
7. Accounts, Plans and fair use
7.1 Features, scan allowances, monitored-domain allowances, prices and billing periods for each subscription or usage package (Plan) are those shown when you purchase, in an applicable order form, or in a written agreement with us.
7.2 All Plans, including paid, Enterprise, bulk-scan and add-on Plans, are subject to this fair use policy. Stated allowances are maximum entitlements, not a commitment that any pattern of use is reasonable or technically safe.
7.3 Fair use means using the Service for its intended privacy-auditing purpose at a volume, frequency and pattern reasonably consistent with your Plan and without adversely affecting the Service, our suppliers, target websites or other users. We may consider concurrency, repeated scans of the same site, automated or API-generated requests, failed scans, retries, bandwidth, processing time, report generation, target-site impact and attempts to divide usage across accounts.
7.4 We may apply technical limits, queue or slow scans, require you to reschedule bulk activity, count repeated or failed requests where resources were consumed, or ask you to move to a more suitable Plan. If use is excessive or abusive, we may suspend or restrict it immediately. Where the issue is not urgent or abusive, we will normally give reasonable notice and an opportunity to adjust use or Plan.
7.5 Unless the pricing page or your order form says otherwise, unused monthly allowances do not roll over. Purchased scan add-ons expire on the date stated at purchase. You may not resell or transfer allowances except under an Agency, Consultancy or Enterprise Plan that expressly permits client work.
7.6 We may change Plan features, allowances and prices. Changes will not take effect during a prepaid fixed term unless agreed with you or reasonably necessary for security, legal or technical reasons. We will give reasonable advance notice of a material adverse change and explain any right to cancel.
8. Fees, billing, renewal and cancellation
8.1 Prices exclude VAT and other applicable taxes unless stated otherwise. You must pay the fees and taxes shown at checkout or in your order form using an accepted payment method.
8.2 A paid subscription renews automatically for the same billing period until cancelled, unless the purchase page or order form states otherwise. We will charge the payment method on file at the start of each renewal period.
8.3 You may cancel a subscription through the application by going to your Account > Plans & credits. Cancellation stops future renewal and takes effect at the end of the current paid period. Except where required by law, fees already paid are non-refundable and no credit is due for part-used periods, unused scans or unused monitored-domain capacity.
8.4 We may suspend paid features if payment is overdue or fails. You remain responsible for accrued fees. We will not reduce any mandatory statutory cancellation or refund rights.
8.5 Enterprise terms, service levels, invoicing, overages or commitments agreed in a signed order form prevail over these Terms to the extent of any direct conflict.
9. Reports and acceptable sharing
9.1 Subject to payment and these Terms, we grant you a limited, non-exclusive, non-transferable licence to use reports generated for your account for your internal business purposes and, where your Plan permits, to share an unaltered report with the relevant website owner, your client, professional advisers or internal stakeholders.
9.2 You must preserve the report’s date, rubric version, context, disclaimers and evidence fingerprint when sharing or quoting findings. You must not alter a report in a way that misrepresents DataPal’s output or presents an out-of-date result as current.
9.3 Public disclosure of named-site findings can create legal and reputational risk. Before publishing, advertising or using findings in comparative marketing or sales outreach, you are responsible for verifying the result, presenting it fairly and accurately, and complying with applicable law and professional obligations.
9.4 Reports and evidence may contain third-party names, marks, URLs and technical information. Those materials remain subject to third-party rights. A reference to a third party does not imply endorsement by or affiliation with DataPal.
10. Intellectual property and feedback
10.1 DataPal and its licensors own all rights in the Service, its software, interface, branding, methodology, scoring framework, report design, documentation and Privacy Pulse Index, excluding your account information and third-party website content.
10.2 These Terms do not transfer intellectual property rights to you. You may not use DataPal’s name, marks or report format except as expressly permitted by these Terms or with our written permission.
10.3 If you provide feedback or suggestions, you grant us a worldwide, perpetual, irrevocable, royalty-free right to use them without restriction or payment, provided we do not identify you publicly as the source without permission.
11. Availability, changes and third parties
11.1 We aim to provide a reliable Service but do not guarantee uninterrupted, error-free or always-available access. Scans may depend on hosting, browser automation, geolocation, payment, authentication and other third-party services.
11.2 We may maintain, update, replace, withdraw or change the Service or methodology. Because privacy regulation and web technologies evolve, scores for the same site may change following a rubric, evidence or interpretation update even if the site itself has not changed.
11.3 We may suspend access where reasonably necessary for maintenance, security, suspected abuse, legal compliance, supplier failure or protection of a target website or other users.
12. Confidentiality and data protection
12.1 Each party must protect the other party’s non-public confidential information and use it only for performing or receiving the Service. This does not apply to information that is public through no breach, already lawfully known, independently developed, lawfully received from another source, or required to be disclosed by law.
12.2 Our handling of account and other personal data is governed by the Privacy Pulse Privacy Notice. Our use of cookies and similar technologies on the Service is described in our Cookie Notice here.
12.3 The scanning Service is not intended to collect or receive personal information about individuals or to appoint DataPal to process personal information on your behalf. You must not use the Service for that purpose. Account administration, business contact, billing, authentication and security information is handled as described in the Privacy Pulse Privacy Notice.
12.4 Customer reports are accessible only through the authenticated account that requested them and to users that customer has expressly authorised. They are not published through a public or guessable report link. This access restriction does not prevent DataPal from publishing the separate domain-level record described in section 6 through Privacy Pulse Index.
13. Suspension and termination
13.1 You may stop using the Free service at any time. Stopping using an account does not remove domain-level scan records from Privacy Pulse Index or require us to remove records lawfully retained in backups, security logs or for legal, accounting or dispute purposes.
13.2 We may suspend or terminate your access immediately if you materially breach these Terms, create a security or legal risk, fail to pay, evade controls, use the Service abusively, or expose us, our suppliers, other users or target websites to harm. Where appropriate and lawful, we will tell you why and may allow a reasonable opportunity to remedy the breach.
13.3 We may discontinue the Service or a Plan on reasonable notice. If we discontinue a prepaid paid Service for reasons not caused by your breach, we will provide a pro-rata refund for the unused portion unless we provide a materially equivalent replacement.
13.4 Sections intended by their nature to continue including sections 3, 6, 9, 10, 12, 14, 15 and 17 survive termination.
14. Responsibility and indemnity
14.1 You are responsible for your submitted targets, instructions, use of reports, communications with website operators and compliance with applicable law.
14.2 If you use the Service in the course of a business, you will reimburse DataPal for reasonable losses, liabilities, damages, costs and expenses (including reasonable legal fees) arising from a third-party claim caused by your unlawful target selection, prohibited use, material misrepresentation of a report, or material breach of sections 4, 5 or 9. This does not apply to the extent the claim was caused by DataPal’s breach, negligence or wilful misconduct. We will notify you promptly and allow you reasonable participation in the defence and settlement of the claim.
15. Liability
15.1 Nothing in these Terms excludes or limits liability where it would be unlawful to do so, including liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot legally be excluded or limited.
15.2 If you use the Service for business purposes, DataPal is not liable for indirect or consequential loss, loss of profit, revenue, business, contracts, anticipated savings, goodwill, reputation or data, or for regulatory fines or third-party claims arising from your reliance on, publication of or failure to act on a scan or report.
15.3 If you use the Service for business purposes, DataPal’s total aggregate liability arising out of or in connection with the Service and these Terms in any 12-month period is limited to the greater of:
the fees you paid or owe for the Service in that 12-month period; and
£100.
15.4 The exclusions and cap in sections 15.2 and 15.3 do not apply to liability described in section 15.1 or to the extent caused by DataPal’s wilful misconduct.
16. Changes to these Terms
16.1 We may change these Terms to reflect changes to the Service, law, regulation, security, pricing or business operations.
16.2 We will post the revised Terms with an updated date. For a material change affecting a paid subscription, we will give reasonable advance notice by email or through the Service. If you do not agree, you may cancel before the change takes effect. Continued use after the effective date constitutes acceptance.
17. General
17.1 Order of precedence. A signed order form or separately negotiated agreement prevails over these Terms where it expressly says it does. The Privacy Notice governs personal-data processing.
17.2 Assignment. You may not transfer your rights or obligations without our written consent. We may transfer ours as part of a merger, reorganisation, sale of business or assets, or to an affiliate, provided this does not reduce mandatory rights.
17.3 No waiver. A delay in enforcing a right is not a waiver of that right.
17.4 Severability. If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary or removed, and the remaining provisions will continue.
17.5 No partnership. These Terms do not create a partnership, joint venture, agency, employment or fiduciary relationship between you and DataPal.
17.6 Third-party rights. No person other than you and DataPal may enforce these Terms under the Contract (Third Party Rights) (Scotland) Act 2017.
17.7 Events beyond reasonable control. Neither party is responsible for delay or failure caused by events beyond its reasonable control, except that this does not excuse payment obligations already due.
17.8 Governing law and courts. These Terms and non-contractual disputes are governed by Scots law. The Scottish courts have exclusive jurisdiction.
18. Contact
Questions, complaints, blocked-domain appeals and legal notices relating to the Service may be sent to:
Personal Data Labs UK Ltd (trading as DataPal)
4/5 Turnberry House
175 West George Street
Glasgow, Scotland
G2 2LB
Email: privacypulse@datapal.me

