Privacy Policy
1. Summary
This policy explains what personal data we collect when you visit pulse.dhihospitality.com, why we collect it, who we share it with, and what rights you have.
In short: we collect the details you submit when you register interest in pulse. or book a demonstration, together with basic technical information generated when your browser loads a page. We use it to respond to you, to assess early access enquiries, and to understand how the website is used. We do not sell personal data and we do not use it for advertising profiling.
2. Who is responsible for your data
The controller of personal data collected through this website, and the Data Fiduciary for the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), is:
| Entity | REGALE DELIZIA PRIVATE LIMITED, trading as dhi Hospitality |
|---|---|
| Incorporated | India, 28 October 2021, under the Companies Act, 2013 |
| Office address | Workbazzar, 3rd Floor, Park Circle, No. 20, Moores Road, Egmore, Chennai, Tamil Nadu 600006, India |
| CIN | U74999TN2021PTC147493 |
| GSTIN | 33AALCR4050P1Z0 |
| Privacy contact | pulse.support@dhihospitality.com |
| Grievance Officer | Diksha Chawla, diksha.chawla@dhihospitality.com |
Throughout this policy, "dhi", "we", "us", and "our" mean the entity above. "pulse." (styled in lower case with a full stop as part of the mark) means the commercial decision software developed by dhi Hospitality.
3. What this policy covers, and what it does not
This policy covers personal data we collect through pulse.dhihospitality.com, and through direct correspondence that begins there, such as an early access enquiry or a demonstration booking.
This policy does not cover:
- Data inside the pulse. application. Where a hotel customer uses pulse., that customer determines what data is processed and why. The customer is the controller, or Data Fiduciary, and dhi acts as data processor on the customer's documented instructions. That processing is governed by the customer's signed agreement and its data protection annex, not by this policy. If you are a hotel guest or employee and want to know how a specific hotel uses your data, contact that hotel.
- dhihospitality.com, the dhi Hospitality corporate website, which is operated separately and has its own notice.
- Third-party websites we link to.
4. What we collect
4.1 Information you give us
The early access form on this website collects the following. All fields are required.
| Field | Type | Why it is needed |
|---|---|---|
| First name | Free text | To address you correctly |
| Last name | Free text | To identify your enquiry |
| Business email address | To respond to you and to send early access communications | |
| Company or hotel name | Free text | To identify the organisation the enquiry relates to |
| Country | Selection from a list | To determine which data protection and commercial terms apply |
| Phone dialling code | Selection from a list | To format your telephone number correctly |
| Phone number | Telephone | To contact you about your enquiry where email is not practical |
| Business type | Selection from a list | To understand the commercial context and assess fit |
Where you book a demonstration through our scheduling provider, that provider collects your name, email address, chosen meeting time, and time zone. See clause 6.
Where you email us directly, we hold the content of your message and any information you choose to include in it.
We ask for business contact details. Please do not submit guest data, employee data, financial account details, government identifiers, or any special category or sensitive personal data through this website.
4.2 Information collected automatically
When you load a page, the following is generated or received:
- IP address
- browser type and version, operating system, device type, screen size
- pages viewed, time of visit, time spent, and the order of pages viewed
- the referring website, and any campaign parameters in the page address
- approximate location derived from IP address, at country or city level only
- edge and build logs recorded by our hosting provider for security and diagnostics
We use Google Analytics 4, loaded through a Google Tag Manager container, to measure how the website is used. The container loads no other tags. There is no advertising pixel, no social media tracker, no chat widget, and no session recording tool on this website.
The website itself sets no cookies directly. All cookies described in clause 4.3 are set by the two third-party services named there.
4.3 Cookies and similar technologies
| Cookie | Set by | Purpose | Duration | Category |
|---|---|---|---|---|
_ga | Google Analytics 4, via Google Tag Manager | Distinguishes one visitor from another | 2 years | Analytics |
_ga_<container id> | Google Analytics 4, via Google Tag Manager | Retains session state | 2 years | Analytics |
_gid | Google Analytics 4, via Google Tag Manager | Distinguishes visitors, legacy identifier, may not be set | 24 hours | Analytics |
| Scheduling widget session cookies | Calendly, only after you open the booking widget | Operates the booking widget during your session | Session | Necessary to that widget |
__cf_bm | Cloudflare, via the Calendly widget | Distinguishes human visitors from automated traffic | Up to 30 minutes | Strictly necessary |
The scheduling widget and its cookies load only when you choose to book a demonstration. They are not set on page load.
Analytics cookies are not strictly necessary. Where local law requires prior consent for non-essential cookies, we ask for that consent before they are set. You can withdraw consent, or block or delete cookies, through your browser settings. Blocking strictly necessary cookies may stop parts of the website working.
4.4 Children
This website is directed at business users. We do not knowingly collect data from anyone under 18. If you believe a child has submitted data to us, contact us and we will delete it.
5. Why we use your data, and our legal basis
| Purpose | Legal basis under GDPR and UK GDPR | Basis under the DPDP Act |
|---|---|---|
| Responding to your enquiry | Steps taken towards a contract at your request, or legitimate interests | Consent, given at the point of submission |
| Assessing and managing early access registrations | Steps towards a contract, or legitimate interests | Consent |
| Arranging and holding a demonstration you requested | Steps towards a contract at your request | Consent |
| Sending you information about pulse. early access that you asked for | Legitimate interests in business-to-business contact, or consent | Consent |
| Operating, securing, and maintaining the website | Legitimate interests | Legitimate use, including security and prevention of fraud |
| Measuring website performance | Consent for analytics cookies where required, otherwise legitimate interests | Consent |
| Keeping records and meeting legal or regulatory obligations | Legal obligation, and legitimate interests | Compliance with applicable law |
| Establishing, exercising, or defending legal claims | Legitimate interests | Enforcement of legal rights |
Where we rely on legitimate interests, our interest is in operating and growing a business-to-business software business, and we have assessed that this does not override your rights. You may object, as set out in clause 9.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing already carried out.
We contact you only about pulse. early access. We do not use your details for unrelated marketing and we do not pass them to anyone else for marketing.
6. Who we share data with
We do not sell personal data and we do not share it with third parties for their own marketing. We use no prospecting, enrichment, or third-party customer relationship tooling in connection with this website.
We share data with the following service providers, who process it on our instructions:
| Provider | What they do | What they receive | Processing location |
|---|---|---|---|
| Supabase Inc. | Stores early access registrations | All form fields listed at clause 4.1 | Japan (Tokyo) |
| Microsoft Corporation (Microsoft 365) | Business email, sending and receiving correspondence | Email content and address book entries | India |
| Vercel Inc. | Serves website pages and static assets, records edge and build logs | Request metadata, including IP address | United States |
| Google LLC (Google Analytics 4 and Google Tag Manager) | Website usage measurement | Cookie identifier, session data, pages viewed, approximate location | United States and other Google locations |
| Calendly LLC | Demonstration scheduling, only where you book a meeting | Name, email address, chosen meeting time, time zone | United States |
| Professional advisers | Legal, accounting, audit | Only as necessary for the engagement | India, and as instructed |
Each provider is bound by contract to process data only on our instructions, to keep it confidential, and to apply appropriate security measures.
We may also disclose data:
- where required by law, court order, or a lawful request from a public authority
- to establish, exercise, or defend legal claims
- to a purchaser or successor entity in connection with a merger, acquisition, restructuring, or transfer of assets, subject to this policy continuing to apply
7. International transfers
We are established in India. Some of our providers process data outside India, as set out below.
| Destination | Data transferred | Safeguard |
|---|---|---|
| India | Email correspondence | Processed within the provider's India region. Written data protection terms. |
| Japan | Early access registrations | Written data protection terms. Encrypted in transit and at rest. Access restricted by database-level row security. |
| United States | Request metadata and hosting logs, analytics identifiers and session data, demonstration booking details | Written data protection terms with each provider, including the provider's standard transfer clauses. |
Where personal data is transferred out of the EEA or the United Kingdom, we rely on one of the following:
- an adequacy decision covering the destination country
- Standard Contractual Clauses approved by the European Commission, or the UK International Data Transfer Addendum
- another transfer mechanism permitted under applicable law
Where personal data of individuals in other jurisdictions is transferred, we apply the transfer conditions required by that jurisdiction's applicable data protection law.
You may request a copy of the relevant safeguards by contacting us.
8. How long we keep data
| Data | Retention |
|---|---|
| Early access registrations that do not proceed | 180 days from the date of registration, or from last contact, whichever is later |
| Enquiry and demonstration correspondence | 180 days from last contact, unless it forms part of an ongoing commercial discussion |
| Records relating to a signed agreement | For the term of the agreement and the applicable limitation period afterwards |
| Hosting runtime logs | 1 hour, rolling |
| Hosting build logs and deployment history | 30 to 90 days, per the provider's retention settings |
| Analytics data | Per the retention period configured in Google Analytics, and no longer than 14 months |
We delete or anonymise data when it is no longer needed for the purpose it was collected for, unless a longer period is required by law.
9. Your rights
Depending on where you are, you may have some or all of the following rights.
Under the DPDP Act, if you are in India, you may:
- ask for a summary of the personal data we hold about you and how it is processed
- ask us to correct, complete, or update inaccurate or incomplete data
- ask us to erase data where the purpose is served or consent is withdrawn
- withdraw consent at any time
- nominate another individual to exercise your rights in the event of death or incapacity
- raise a grievance with our Grievance Officer, and escalate to the Data Protection Board of India if unresolved
Under GDPR and UK GDPR, if you are in the EEA or the United Kingdom, you may:
- request access to your data and a copy of it
- request rectification of inaccurate data
- request erasure
- request restriction of processing
- request portability of data you provided to us, in a machine-readable format
- object to processing based on legitimate interests
- withdraw consent
- lodge a complaint with your local supervisory authority
Similar rights apply under other applicable data protection laws in your jurisdiction.
To exercise a right, email pulse.support@dhihospitality.com. We respond within 30 days, or sooner where the law requires it. We may ask for information to verify your identity. Exercising these rights is free, unless a request is manifestly unfounded or excessive.
To stop receiving email from us, use the unsubscribe link in any message, or email us directly.
10. Security
We apply technical and organisational measures appropriate to the data we hold, including:
- encryption of all data in transit using TLS 1.2 or above
- encryption of stored data at rest using AES-256
- multi-factor authentication enforced on administrative accounts across hosting, source control, and database services
- row-level security enforced at the database layer, so that stored registrations cannot be read using the website's public access key
- access granted on a least-privilege basis and limited to personnel with an operational need
- credentials and access tokens held in a dedicated encrypted secrets store, never in the application database or in source control
- prompt revocation of access on change of role or end of engagement
- contractual security obligations imposed on each provider
- a documented incident response procedure defining severity classification, escalation, and notification obligations
No system is completely secure. We cannot guarantee absolute security of data transmitted over the internet.
We do not hold SOC 2 or ISO 27001 certification. This section will be updated if that position changes. Security documentation for procurement review is available on request under an appropriate confidentiality agreement. Measures applying to the pulse. application itself are set out in the data protection annex to each customer agreement, which is more detailed than this section and governs that processing.
Where a personal data breach occurs, we notify affected individuals and the relevant authority within the timeframes required by applicable law.
11. Automated decision-making
We do not make decisions about you by automated means alone that have a legal or similarly significant effect on you.
Analytical outputs generated inside the pulse. application relate to commercial performance at the level of demand and market, not to individuals, and are surfaced as recommendations for review by customer personnel before any action is taken.
12. Google, Meta, and third-party integrations for connected pulse. accounts
Where a customer connects a Google Ads, Google Analytics 4, Meta Ads, or other advertising or analytics account to pulse., pulse. accesses data from that account under the customer's authorisation to compute cross-channel performance, produce recommendations, and (where instructed) apply changes. This section describes that processing, in addition to what is set out in §3 and in the customer agreement.
12.1 Scopes we request
When a customer connects an account, we request the minimum set of permissions needed:
| Provider | Scope or permission | What we do with it |
|---|---|---|
| Google Ads | https://www.googleapis.com/auth/adwords |
Read campaign, ad group, keyword, spend, and conversion data for the customer's connected Google Ads accounts. Apply approved changes (bid, budget, or status adjustments) only where the customer has explicitly authorised each change through the pulse. interface. |
| Google Analytics 4 | https://www.googleapis.com/auth/analytics.readonly |
Read session, event, and revenue data from the customer's connected GA4 properties to compute attribution and channel contribution. Read only. |
| Meta (Facebook / Instagram) | ads_read, ads_management, business_management, and related Marketing API and Pages permissions |
Read campaign, ad set, ad, spend, and conversion data for the customer's connected Meta ad accounts and Business Manager. Apply approved changes only where the customer has explicitly authorised each change. |
12.2 How we use this data
Data accessed under these scopes is used solely to provide the pulse. service to the customer that authorised the connection. Specifically:
- to compute cross-channel performance metrics, cost per acquisition, and return on ad spend
- to generate recommendations for budget, bid, and creative changes
- to apply changes back to the connected account, only where the customer has explicitly approved the change through the pulse. interface
- to display historical trends and reporting inside the customer's pulse. workspace
We do not use this data for advertising to you, to train generalised or general-purpose machine learning models, to build profiles unrelated to the customer's own account, or for any purpose outside providing the pulse. service to that customer.
12.3 Who this data is shared with
Data accessed under these scopes is not sold. It is not shared with third parties for their own use, and it is not shared with other pulse. customers. It is accessible only to the customer that authorised the connection, to authorised users under that customer's account, and to a strictly limited set of dhi personnel for operational support under the security controls set out in §10.
Sub-processors used to provide the pulse. service (hosting, database, background job infrastructure) are listed in the customer agreement's data protection annex. No sub-processor uses the data for its own purposes.
12.4 Where the data is stored
OAuth tokens, refresh tokens, and service account credentials for connected accounts are held in a dedicated encrypted secrets store (AWS Secrets Manager), separate from the application database, and never held in source control. Metric data pulled from the connected accounts is stored in the pulse. application database under row-level security so that each customer can access only its own data.
12.5 How long we keep it
Access tokens are held for as long as the connection remains active. Metric data pulled from the connected accounts is retained for the duration of the customer's pulse. subscription plus a short reasonable period after termination for wind-down and reconciliation, as set out in the customer agreement.
12.6 How to disconnect or delete
A customer can disconnect any connected Google or Meta account at any time from within pulse. under Settings → Integrations. On disconnection, the OAuth token is deleted from the secrets store and the customer's authorisation to pulse. is revoked with the platform. Historical metric data already pulled is retained under the customer's account until the account itself is deleted.
A customer can also revoke access directly at the platform:
- Google (Google Ads and GA4): myaccount.google.com → Data & privacy → Third-party apps & services, find pulse., and remove access.
- Meta: accounts.meta.com → Business tools, find pulse., and remove access.
Full account deletion, and the effect on connected accounts, is described at pulse.dhihospitality.com/data-deletion.
12.7 Compliance with the Google API Services User Data Policy
pulse.'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
13. Changes to this policy
We may update this policy. The version on this page is the version in force, and the "Last updated" date shows when it changed. Where a change materially affects how we use data you have already given us, we will tell you directly by email before it takes effect.
14. Contact and complaints
For any question, request, or complaint about privacy:
Privacy contact: pulse.support@dhihospitality.com
Grievance Officer: Diksha Chawla, diksha.chawla@dhihospitality.com
Legal notices: diksha.chawla@dhihospitality.com
Postal address:
REGALE DELIZIA PRIVATE LIMITED (t/a dhi Hospitality)
Workbazzar, 3rd Floor, Park Circle
No. 20, Moores Road, Egmore
Chennai, Tamil Nadu 600006, India
If you are not satisfied with our response, you may complain to the Data Protection Board of India, or to the supervisory authority in your country of residence.