Data processing
Where personal data does and does not enter the picture.
The short version: the analysis reads configuration, and the records that hold personal data are not part of it. The detail matters for a procurement review, so it is set out below.
The factual position
- Processing boundary
- SuitePulse processes ERP configuration and code. Customer, vendor and employee records, where personal data lives, are outside what the analysis reads.
- Personal data we do process
- The contact details of people who use SuitePulse: the work email used to request an analysis, and account holder details.
- Incidental personal data
- Configuration can contain names, such as a report owner or a script author. Where that appears in findings it is processed as configuration metadata, and is exportable and deletable with the rest of the analysis.
- Subprocessors
- A current list is available on request and will be annexed to the executed DPA.
- Data location
- The processing region depends on your contract. Confirm it before connecting rather than assuming a default.
- Deletion
- Deleting an analysis removes its findings. Closing an account removes all associated history.
The formal document is in preparation
What is above describes how the product behaves and is accurate. It is not the executable agreement, and it has not been through legal review. If you need the current draft for a procurement or security review, request it at hello@suitepulse.com and we will send what exists rather than point you at this page.