Data Processing Agreement
Version 1.0 · Last updated: 16 August 2026
PubPulse — a product of Enorme Limited
1. Parties and status
This Data Processing Agreement (“DPA”) forms part of, and is subject to, the PubPulse Terms of Service (the “Agreement”) between:
Enorme Limited, a company registered in England and Wales under company number 14608315, whose registered office is at Market House, Church Street, Harleston, Norfolk, IP20 9BB (“PubPulse”, “we”, “us”, the “Processor”); and
the customer identified in the Agreement (the “Customer”, “you”, the “Controller”).
Where the Customer uses PubPulse to process personal data about its own staff, contacts, customers or suppliers, the Customer is the controller and PubPulse is the processor of that personal data. This DPA records the terms required by Article 28 of the UK GDPR.
PubPulse acts as a controller in its own right in respect of the Customer's own account and billing information. That processing is governed by the PubPulse Privacy Policy, not this DPA.
2. Definitions
“Data Protection Law” means the UK GDPR, the Data Protection Act 2018 and all other laws relating to the processing of personal data applicable to the parties, as amended or replaced.
“Personal Data”, “controller”, “processor”, “data subject”, “processing” and “personal data breach” have the meanings given in the UK GDPR.
“Customer Personal Data” means personal data that PubPulse processes on the Customer's behalf under the Agreement, as described in Annex 1.
“Sub-processor” means any third party engaged by PubPulse to process Customer Personal Data.
3. Scope and roles
3.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
3.2 Each party shall comply with its own obligations under Data Protection Law.
3.3 The Customer is responsible for the accuracy and lawfulness of Customer Personal Data, and for ensuring it has a valid lawful basis for entering that data into PubPulse and for having it processed as described in this DPA. In particular, the Customer is responsible for providing appropriate privacy information to its own staff.
4. Processing on documented instructions
4.1 PubPulse shall process Customer Personal Data only on the Customer's documented instructions, including as regards transfers to a third country, unless required to do otherwise by law — in which case PubPulse shall inform the Customer of that requirement before processing, unless the law prohibits it.
4.2 The Agreement, this DPA, and the Customer's use of the features of the Services constitute the Customer's complete documented instructions.
4.3 PubPulse shall inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
5. Confidentiality
PubPulse shall ensure that all persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and are made aware of the confidential nature of the data.
Access to Customer Personal Data by PubPulse personnel is limited to those who need it to provide, secure or support the Services. Where support requires access to a Customer's data, that access is limited as described in Annex 2.
6. Security
6.1 Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, PubPulse shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
6.2 The measures in place as at the date of this DPA are described in Annex 2. PubPulse may update those measures provided the level of protection is not reduced.
7. Sub-processors
7.1 The Customer gives PubPulse general written authorisation to engage sub-processors for the purposes of providing the Services.
7.2 The sub-processors engaged as at the date of this DPA are listed in Annex 3.
7.3 PubPulse shall give the Customer at least 30 days' notice before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Services without penalty, with a pro-rata refund of any prepaid fees for the unused period.
7.4 PubPulse shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
8. Assistance to the Customer
8.1 Data subject rights. Taking into account the nature of the processing, PubPulse shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise data subject rights. The Services provide the Customer with direct access to Customer Personal Data so that most such requests can be handled by the Customer without PubPulse's involvement.
8.2 If PubPulse receives a request directly from a data subject relating to Customer Personal Data, it shall not respond substantively but shall refer the individual to the Customer and notify the Customer without undue delay.
8.3 Wider assistance. PubPulse shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to PubPulse.
9. Personal data breach
9.1 PubPulse shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
9.2 The notification shall describe, so far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not all available at once, it may be provided in phases without undue further delay.
9.3 PubPulse shall not notify the ICO or affected data subjects on the Customer's behalf unless required by law or specifically instructed in writing by the Customer.
10. Deletion and return
10.1 On termination or expiry of the Agreement, PubPulse shall, at the Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless required by law to retain it.
10.2 The Customer may export its data through the Services at any time during the term. The Customer should do so before terminating.
10.3 Unless the Customer requests earlier deletion, Customer Personal Data will be deleted from live systems within 30 days of termination. Encrypted backups are retained on the cycle described in Annex 2 and are overwritten in the ordinary course; PubPulse will not restore deleted Customer Personal Data from backup other than as part of a disaster-recovery event.
10.4 Certain records are retained for shorter periods by design during the term — for example TaskPulse completed checklists are retained for three months. Those retention periods form part of the Services as described in the documentation.
11. Audits and information
11.1 PubPulse shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR.
11.2 PubPulse shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice of at least 30 days, no more than once in any 12-month period (save where required by a supervisory authority or following a personal data breach), during business hours, subject to confidentiality undertakings, and in a manner that does not disrupt the Services or the data of other customers.
11.3 PubPulse may satisfy an audit request by providing a written response to a security questionnaire, together with any relevant third-party certifications or reports held by its sub-processors.
12. International transfers
12.1 Customer Personal Data is hosted in Frankfurt, Germany (European Union). Germany is covered by the UK adequacy regulations, so no additional transfer mechanism is required for this hosting.
12.2 Where a sub-processor listed in Annex 3 processes Customer Personal Data outside the United Kingdom, PubPulse shall ensure an appropriate transfer mechanism is in place — the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or an applicable adequacy decision.
12.3 The Customer authorises such transfers for the purposes of providing the Services.
13. Liability and general
13.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
13.2 This DPA takes effect on the date the Customer accepts the Agreement and continues for as long as PubPulse processes Customer Personal Data.
13.3 In the event of conflict between this DPA and the Agreement in relation to the processing of Customer Personal Data, this DPA prevails.
13.4 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Contact for data protection matters:
Enorme Limited
Market House, Church Street, Harleston, Norfolk, IP20 9BB
Company number 14608315 · VAT registration number GB 497 4987 05
Email: info@pubpulse.co.uk
Annex 1 — Description of processing
Subject matter. Provision of the PubPulse software applications to the Customer.
Duration. For the term of the Agreement, plus the deletion period in clause 10.
Nature and purpose. Hosting, storage, organisation, retrieval, display, transmission and deletion of data entered by the Customer, for the purpose of enabling the Customer to run its licensed premises — staff rostering, task and checklist management, event and booking management, and supplier price monitoring — together with related notifications, backup and support.
Categories of data subjects
- the Customer's employees, workers and other staff
- the Customer's account holders, managers and authorised users
- the Customer's own customers, event bookers and enquirers (DiaryPulse)
- contacts at the Customer's suppliers (PricePulse)
Types of personal data
| Application | Personal data processed |
|---|---|
| RotaPulse | Staff names, mobile telephone numbers, email addresses, hourly pay rates, shift and rota allocations, hours worked, availability, holiday and leave records, shift-swap requests |
| TaskPulse | Staff names, checklist completion records with date and time stamps, reasons given for incomplete tasks, free-text shift notes |
| DiaryPulse | Event and booking contact names, telephone numbers, email addresses, booking and event details, deposit and payment records, enquiry form submissions |
| PricePulse | Supplier invoice documents, which may incidentally contain contact names and contact details of supplier personnel |
| PubPulse Hub | Account holder names, email addresses, login credentials (stored as salted hashes), venue and role assignments |
Special category data. The Services are not designed or intended for special category personal data as defined in Article 9 of the UK GDPR, or for criminal offence data. The Customer must not enter such data — in particular, free-text fields must not be used to record health information about staff (for example reasons for sickness absence).
Annex 2 — Technical and organisational measures
Access control
- Access to each venue's data is restricted to authenticated users assigned to that venue; venue data is separated at the application layer on every request
- Role-based permissions distinguish owners, managers and staff
- Passwords are stored as salted hashes, never in plain text
- Sessions are held in signed, HTTP-only, secure cookies with a limited lifetime
Application security
- All traffic is served over HTTPS with HTTP Strict Transport Security
- Cross-site request forgery protection on all state-changing requests
- Security response headers, including protections against content-type sniffing and clickjacking
- Rate limiting on authentication endpoints to resist brute-force attempts
- Application hosts are excluded from search engine indexing
Support access
- PubPulse support personnel may access a Customer's data only where necessary to provide support, and such access is read-only
- Support access is logged
Payment data
- PubPulse does not store card details. Payments are processed by Stripe on Stripe's own hosted pages; PubPulse receives only a payment reference and subscription status
Backup and resilience
- Databases are continuously replicated to encrypted object storage
- Backups are encrypted in transit and at rest
- Restoration procedures are tested
Organisational
- Personnel with access to Customer Personal Data are bound by confidentiality obligations
- Access credentials are held in the hosting provider's secret management, not in source code
- Changes are version-controlled and reviewed before release
Annex 3 — Authorised sub-processors
| Sub-processor | Purpose | Personal data involved |
|---|---|---|
| Render | Application hosting and database hosting | All Customer Personal Data |
| Cloudflare | Website delivery, object storage for uploaded documents and encrypted database backups, bot protection | Uploaded invoice documents; encrypted backups of all data |
| Brevo | Transactional and notification email | Names and email addresses of users and staff |
| Twilio | SMS shift notifications (RotaPulse) | Staff names and mobile telephone numbers |
| Stripe | Subscription payment processing | Account holder billing details. Stripe acts as an independent controller for payment data |
| Anthropic | Automated extraction of line items from uploaded supplier invoices (PricePulse) | Content of uploaded invoice documents, which may incidentally contain supplier contact names |
| Microsoft | Business email for support correspondence | Data contained in support correspondence |