Privacy Policy


1. Summary

This policy explains what personal data we collect when you visit pulse.dhihospitality.com, why we collect it, who we share it with, and what rights you have.

In short: we collect the details you submit when you register interest in pulse. or book a demonstration, together with basic technical information generated when your browser loads a page. We use it to respond to you, to assess early access enquiries, and to understand how the website is used. We do not sell personal data and we do not use it for advertising profiling.

2. Who is responsible for your data

The controller of personal data collected through this website, and the Data Fiduciary for the purposes of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), is:

EntityREGALE DELIZIA PRIVATE LIMITED, trading as dhi Hospitality
IncorporatedIndia, 28 October 2021, under the Companies Act, 2013
Office addressWorkbazzar, 3rd Floor, Park Circle, No. 20, Moores Road, Egmore, Chennai, Tamil Nadu 600006, India
CINU74999TN2021PTC147493
GSTIN33AALCR4050P1Z0
Privacy contactpulse.support@dhihospitality.com
Grievance OfficerDiksha Chawla, diksha.chawla@dhihospitality.com

Throughout this policy, "dhi", "we", "us", and "our" mean the entity above. "pulse." (styled in lower case with a full stop as part of the mark) means the commercial decision software developed by dhi Hospitality.

3. What this policy covers, and what it does not

This policy covers personal data we collect through pulse.dhihospitality.com, and through direct correspondence that begins there, such as an early access enquiry or a demonstration booking.

This policy does not cover:

4. What we collect

4.1 Information you give us

The early access form on this website collects the following. All fields are required.

FieldTypeWhy it is needed
First nameFree textTo address you correctly
Last nameFree textTo identify your enquiry
Business email addressEmailTo respond to you and to send early access communications
Company or hotel nameFree textTo identify the organisation the enquiry relates to
CountrySelection from a listTo determine which data protection and commercial terms apply
Phone dialling codeSelection from a listTo format your telephone number correctly
Phone numberTelephoneTo contact you about your enquiry where email is not practical
Business typeSelection from a listTo understand the commercial context and assess fit

Where you book a demonstration through our scheduling provider, that provider collects your name, email address, chosen meeting time, and time zone. See clause 6.

Where you email us directly, we hold the content of your message and any information you choose to include in it.

We ask for business contact details. Please do not submit guest data, employee data, financial account details, government identifiers, or any special category or sensitive personal data through this website.

4.2 Information collected automatically

When you load a page, the following is generated or received:

We use Google Analytics 4, loaded through a Google Tag Manager container, to measure how the website is used. The container loads no other tags. There is no advertising pixel, no social media tracker, no chat widget, and no session recording tool on this website.

The website itself sets no cookies directly. All cookies described in clause 4.3 are set by the two third-party services named there.

4.3 Cookies and similar technologies

CookieSet byPurposeDurationCategory
_gaGoogle Analytics 4, via Google Tag ManagerDistinguishes one visitor from another2 yearsAnalytics
_ga_<container id>Google Analytics 4, via Google Tag ManagerRetains session state2 yearsAnalytics
_gidGoogle Analytics 4, via Google Tag ManagerDistinguishes visitors, legacy identifier, may not be set24 hoursAnalytics
Scheduling widget session cookiesCalendly, only after you open the booking widgetOperates the booking widget during your sessionSessionNecessary to that widget
__cf_bmCloudflare, via the Calendly widgetDistinguishes human visitors from automated trafficUp to 30 minutesStrictly necessary

The scheduling widget and its cookies load only when you choose to book a demonstration. They are not set on page load.

Analytics cookies are not strictly necessary. Where local law requires prior consent for non-essential cookies, we ask for that consent before they are set. You can withdraw consent, or block or delete cookies, through your browser settings. Blocking strictly necessary cookies may stop parts of the website working.

4.4 Children

This website is directed at business users. We do not knowingly collect data from anyone under 18. If you believe a child has submitted data to us, contact us and we will delete it.

5. Why we use your data, and our legal basis

PurposeLegal basis under GDPR and UK GDPRBasis under the DPDP Act
Responding to your enquirySteps taken towards a contract at your request, or legitimate interestsConsent, given at the point of submission
Assessing and managing early access registrationsSteps towards a contract, or legitimate interestsConsent
Arranging and holding a demonstration you requestedSteps towards a contract at your requestConsent
Sending you information about pulse. early access that you asked forLegitimate interests in business-to-business contact, or consentConsent
Operating, securing, and maintaining the websiteLegitimate interestsLegitimate use, including security and prevention of fraud
Measuring website performanceConsent for analytics cookies where required, otherwise legitimate interestsConsent
Keeping records and meeting legal or regulatory obligationsLegal obligation, and legitimate interestsCompliance with applicable law
Establishing, exercising, or defending legal claimsLegitimate interestsEnforcement of legal rights

Where we rely on legitimate interests, our interest is in operating and growing a business-to-business software business, and we have assessed that this does not override your rights. You may object, as set out in clause 9.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing already carried out.

We contact you only about pulse. early access. We do not use your details for unrelated marketing and we do not pass them to anyone else for marketing.

6. Who we share data with

We do not sell personal data and we do not share it with third parties for their own marketing. We use no prospecting, enrichment, or third-party customer relationship tooling in connection with this website.

We share data with the following service providers, who process it on our instructions:

ProviderWhat they doWhat they receiveProcessing location
Supabase Inc.Stores early access registrationsAll form fields listed at clause 4.1Japan (Tokyo)
Microsoft Corporation (Microsoft 365)Business email, sending and receiving correspondenceEmail content and address book entriesIndia
Vercel Inc.Serves website pages and static assets, records edge and build logsRequest metadata, including IP addressUnited States
Google LLC (Google Analytics 4 and Google Tag Manager)Website usage measurementCookie identifier, session data, pages viewed, approximate locationUnited States and other Google locations
Calendly LLCDemonstration scheduling, only where you book a meetingName, email address, chosen meeting time, time zoneUnited States
Professional advisersLegal, accounting, auditOnly as necessary for the engagementIndia, and as instructed

Each provider is bound by contract to process data only on our instructions, to keep it confidential, and to apply appropriate security measures.

We may also disclose data:

7. International transfers

We are established in India. Some of our providers process data outside India, as set out below.

DestinationData transferredSafeguard
IndiaEmail correspondenceProcessed within the provider's India region. Written data protection terms.
JapanEarly access registrationsWritten data protection terms. Encrypted in transit and at rest. Access restricted by database-level row security.
United StatesRequest metadata and hosting logs, analytics identifiers and session data, demonstration booking detailsWritten data protection terms with each provider, including the provider's standard transfer clauses.

Where personal data is transferred out of the EEA or the United Kingdom, we rely on one of the following:

Where personal data of individuals in other jurisdictions is transferred, we apply the transfer conditions required by that jurisdiction's applicable data protection law.

You may request a copy of the relevant safeguards by contacting us.

8. How long we keep data

DataRetention
Early access registrations that do not proceed180 days from the date of registration, or from last contact, whichever is later
Enquiry and demonstration correspondence180 days from last contact, unless it forms part of an ongoing commercial discussion
Records relating to a signed agreementFor the term of the agreement and the applicable limitation period afterwards
Hosting runtime logs1 hour, rolling
Hosting build logs and deployment history30 to 90 days, per the provider's retention settings
Analytics dataPer the retention period configured in Google Analytics, and no longer than 14 months

We delete or anonymise data when it is no longer needed for the purpose it was collected for, unless a longer period is required by law.

9. Your rights

Depending on where you are, you may have some or all of the following rights.

Under the DPDP Act, if you are in India, you may:

Under GDPR and UK GDPR, if you are in the EEA or the United Kingdom, you may:

Similar rights apply under other applicable data protection laws in your jurisdiction.

To exercise a right, email pulse.support@dhihospitality.com. We respond within 30 days, or sooner where the law requires it. We may ask for information to verify your identity. Exercising these rights is free, unless a request is manifestly unfounded or excessive.

To stop receiving email from us, use the unsubscribe link in any message, or email us directly.

10. Security

We apply technical and organisational measures appropriate to the data we hold, including:

No system is completely secure. We cannot guarantee absolute security of data transmitted over the internet.

We do not hold SOC 2 or ISO 27001 certification. This section will be updated if that position changes. Security documentation for procurement review is available on request under an appropriate confidentiality agreement. Measures applying to the pulse. application itself are set out in the data protection annex to each customer agreement, which is more detailed than this section and governs that processing.

Where a personal data breach occurs, we notify affected individuals and the relevant authority within the timeframes required by applicable law.

11. Automated decision-making

We do not make decisions about you by automated means alone that have a legal or similarly significant effect on you.

Analytical outputs generated inside the pulse. application relate to commercial performance at the level of demand and market, not to individuals, and are surfaced as recommendations for review by customer personnel before any action is taken.

12. Google, Meta, and third-party integrations for connected pulse. accounts

Where a customer connects a Google Ads, Google Analytics 4, Meta Ads, or other advertising or analytics account to pulse., pulse. accesses data from that account under the customer's authorisation to compute cross-channel performance, produce recommendations, and (where instructed) apply changes. This section describes that processing, in addition to what is set out in §3 and in the customer agreement.

12.1 Scopes we request

When a customer connects an account, we request the minimum set of permissions needed:

ProviderScope or permissionWhat we do with it
Google Ads https://www.googleapis.com/auth/adwords Read campaign, ad group, keyword, spend, and conversion data for the customer's connected Google Ads accounts. Apply approved changes (bid, budget, or status adjustments) only where the customer has explicitly authorised each change through the pulse. interface.
Google Analytics 4 https://www.googleapis.com/auth/analytics.readonly Read session, event, and revenue data from the customer's connected GA4 properties to compute attribution and channel contribution. Read only.
Meta (Facebook / Instagram) ads_read, ads_management, business_management, and related Marketing API and Pages permissions Read campaign, ad set, ad, spend, and conversion data for the customer's connected Meta ad accounts and Business Manager. Apply approved changes only where the customer has explicitly authorised each change.

12.2 How we use this data

Data accessed under these scopes is used solely to provide the pulse. service to the customer that authorised the connection. Specifically:

We do not use this data for advertising to you, to train generalised or general-purpose machine learning models, to build profiles unrelated to the customer's own account, or for any purpose outside providing the pulse. service to that customer.

12.3 Who this data is shared with

Data accessed under these scopes is not sold. It is not shared with third parties for their own use, and it is not shared with other pulse. customers. It is accessible only to the customer that authorised the connection, to authorised users under that customer's account, and to a strictly limited set of dhi personnel for operational support under the security controls set out in §10.

Sub-processors used to provide the pulse. service (hosting, database, background job infrastructure) are listed in the customer agreement's data protection annex. No sub-processor uses the data for its own purposes.

12.4 Where the data is stored

OAuth tokens, refresh tokens, and service account credentials for connected accounts are held in a dedicated encrypted secrets store (AWS Secrets Manager), separate from the application database, and never held in source control. Metric data pulled from the connected accounts is stored in the pulse. application database under row-level security so that each customer can access only its own data.

12.5 How long we keep it

Access tokens are held for as long as the connection remains active. Metric data pulled from the connected accounts is retained for the duration of the customer's pulse. subscription plus a short reasonable period after termination for wind-down and reconciliation, as set out in the customer agreement.

12.6 How to disconnect or delete

A customer can disconnect any connected Google or Meta account at any time from within pulse. under Settings → Integrations. On disconnection, the OAuth token is deleted from the secrets store and the customer's authorisation to pulse. is revoked with the platform. Historical metric data already pulled is retained under the customer's account until the account itself is deleted.

A customer can also revoke access directly at the platform:

Full account deletion, and the effect on connected accounts, is described at pulse.dhihospitality.com/data-deletion.

12.7 Compliance with the Google API Services User Data Policy

pulse.'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

13. Changes to this policy

We may update this policy. The version on this page is the version in force, and the "Last updated" date shows when it changed. Where a change materially affects how we use data you have already given us, we will tell you directly by email before it takes effect.

14. Contact and complaints

For any question, request, or complaint about privacy:

Privacy contact: pulse.support@dhihospitality.com
Grievance Officer: Diksha Chawla, diksha.chawla@dhihospitality.com
Legal notices: diksha.chawla@dhihospitality.com

Postal address:
REGALE DELIZIA PRIVATE LIMITED (t/a dhi Hospitality)
Workbazzar, 3rd Floor, Park Circle
No. 20, Moores Road, Egmore
Chennai, Tamil Nadu 600006, India

If you are not satisfied with our response, you may complain to the Data Protection Board of India, or to the supervisory authority in your country of residence.