PlantPulsePro
TermsPrivacySecurityData processing
Data governance

Data Processing

The standard processing roles, purposes, data categories and safeguards used to provide the service.

Effective 18 July 2026

Data-processing overview

This page describes the standard processing needed to provide Plant Pulse Pro. It is not a signed data processing agreement. If a customer has a signed order form or data processing agreement, that document controls. Customers that require a signed DPA or current deployment and subprocessor details can request them at hello@plantpulsepro.com.

Roles, duration and instructions

For personal information contained in a customer's account and operating records, the customer generally acts as controller or business and Plant Pulse Pro acts as processor or service provider. Processing continues for the subscription and the agreed return, export or deletion period. Customer configuration, authorized user actions, support requests and the applicable agreement form the documented instructions.

Nature and purpose

  • Authenticate users and enforce organization, plant and role scope.
  • Store and present reactor state, batches, steps, delays, comments, approvals, output, master versions and audit evidence.
  • Calculate server-side dashboards, reports, comparisons and customer-requested exports.
  • Secure, monitor, support, troubleshoot, back up and recover the contracted service according to the deployment tier.
  • Process bounded read-only AI context only when the customer has enabled that feature and provider path.

Data subjects and categories

Data subjects may include customer employees, contractors, administrators, support contacts and other authorized users.

  • Identity and work-contact data, employee or user code, role, designation, shift and authorized organizational scope.
  • Authentication, device, request, security, audit and support metadata.
  • Operational comments, assignments, approvals and action history that may identify an authorized user.
  • No special-category data is required for the service; customers should not submit it unless separately agreed and lawful.

Confidentiality and safeguards

Personnel and providers with access to customer data are expected to be bound by appropriate confidentiality duties. Technical measures include server-side authorization, tenant and plant scoping, validated commands, audit evidence, bounded responses, server-held secrets and HTTPS transport. Deployment-specific encryption at rest, backup, recovery, region and retention settings are confirmed through the applicable service arrangement.

Service providers and transfers

Plant Pulse Pro may use contracted cloud hosting, database, monitoring, email, support and optional AI providers as subprocessors. They may process only the data needed for their service and are subject to contractual data-protection obligations. Current provider names, locations and transfer safeguards depend on the deployed environment and are available to the contracting customer on request.

Requests, incidents and assistance

Taking into account the nature of processing, Plant Pulse Pro will provide reasonable assistance for verified data-subject requests, security incidents, risk assessments and regulator inquiries as required by the applicable agreement and law. Customers remain responsible for determining whether a request is valid and for communicating with their users or regulator unless law requires otherwise.

Return, deletion and audit

At the end of service, customer data will be returned or deleted as agreed, except where retention is required by law or necessary for security, backup or legal claims. Backup copies may remain until overwritten under the deployment schedule. Production and audit history is not casually deleted because it may be part of the customer's regulated operating record; deletion scope and authority must be confirmed before execution.

Questions about these documents can be sent to hello@plantpulsepro.com.

Return to Plant Pulse Pro