Catalyse Pulse Privacy Policy
# Catalyse Pulse Privacy Policy
Effective date: 18 August 2026
## 1. Who we are
Catalyse provides Catalyse Pulse, a business-to-business market intelligence service. For personal data described in this Policy, Catalyse is the data controller.
Contact: simen@catalyse.no
Website: https://catalyse.no
Service: https://pulse.catalyse.no
## 2. What this Policy covers
This Policy explains how we collect, use, disclose, retain and protect personal data when you visit Pulse, create or use an account, purchase a subscription, contact us, or receive operational communications.
## 3. Personal data we collect
We may process:
- Account data, including name, business email address, organisation, role, account status and authorised markets.
- Authentication and security data, including password hashes, invitation and reset-token records, login status, IP-derived security records, user agent and security logs.
- Subscription and billing data, including plan, billing interval, subscription status, selected markets, Stripe customer and subscription identifiers, payment status and invoice references. Catalyse does not store complete payment-card details.
- Usage and technical data, including pages and features used, timestamps, device/browser information, diagnostics and service events.
- Communications, including support requests, feedback and other correspondence.
- Legal acceptance records, including the Terms and Privacy versions presented, acceptance time and related audit evidence.
- Cookie and analytics data where permitted and, where required, after your choice has been recorded.
Please do not submit special-category or other sensitive personal data to Pulse unless Catalyse has expressly requested it and provided an appropriate lawful basis and safeguards.
## 4. Why we use personal data and our legal bases
We process personal data to:
- Create, authenticate and administer accounts; provide subscribed features; manage billing; and deliver support. Legal basis: performance of a contract or steps requested before entering a contract.
- Keep Pulse secure, prevent misuse, troubleshoot, monitor availability and maintain audit records. Legal basis: Catalyse's legitimate interests in protecting and operating the service and, where applicable, compliance with legal obligations.
- Send essential account, security, billing and service messages. Legal basis: contract, legal obligation, or legitimate interests. These are not marketing messages.
- Improve Pulse through limited product analytics and diagnostics. Legal basis: legitimate interests where the processing is necessary and proportionate; consent where applicable law requires it for cookies or similar technology.
- Send marketing communications. Legal basis: consent or another lawful basis permitted by applicable marketing law. You may opt out at any time.
- Comply with accounting, tax, legal and regulatory requirements and establish or defend legal claims. Legal basis: legal obligation or legitimate interests.
Where we rely on legitimate interests, you may request information about the balancing assessment and may object to the processing.
## 5. Sources of personal data
We receive personal data directly from you, from an authorised administrator in your organisation, from Stripe during subscription events, and automatically from your browser or device when you use Pulse.
Pulse also uses weather, calendar, population, sports and other contextual datasets. These datasets are intended to describe markets and events, not individual users.
## 6. Who receives personal data
We disclose personal data only as necessary to operate Pulse, meet legal duties or protect legitimate rights. Recipients may include:
- Stripe for checkout, subscriptions, payments, invoices and the customer portal.
- Render and related infrastructure providers for application and database hosting.
- Resend or another configured email provider for invitations, password resets and service notifications.
- Analytics and measurement providers only as configured and permitted.
- Professional advisers, auditors, insurers, authorities or courts where necessary or legally required.
- A purchaser or successor in connection with a corporate transaction, subject to appropriate confidentiality and legal safeguards.
These providers act under contracts and may process data only for authorised purposes.
## 7. International transfers
Some providers may process personal data outside Norway or the European Economic Area. Where required, Catalyse uses an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. You may contact us for more information.
## 8. How long we keep personal data
We retain personal data only for as long as necessary for the purposes above:
- Active account and subscription data: while the account is active and for a reasonable period afterward for administration, disputes and reactivation.
- Billing and accounting records: for the period required by Norwegian accounting and tax law.
- Security, access and diagnostic logs: for a limited period based on security and operational need.
- Legal acceptance and audit records: for the period needed to document the agreement and compliance.
- Support communications: while needed to resolve the request and for a reasonable follow-up period.
- Marketing preferences: until withdrawal, plus a suppression record where needed to respect the opt-out.
We may retain data longer where required by law, necessary for legal claims, or subject to a valid preservation requirement. Data may be anonymised instead of deleted where it can no longer identify a person.
## 9. Security
We use appropriate technical and organisational measures designed to protect personal data, including access controls, password hashing, restricted administrative access, transport encryption, audit records and service monitoring. No online service can guarantee absolute security. Please use a strong unique password and notify us promptly of suspected misuse.
## 10. Your rights
Subject to applicable law, you may request:
- Access to your personal data.
- Correction of inaccurate or incomplete data.
- Erasure of data.
- Restriction of processing.
- Data portability.
- Objection to processing based on legitimate interests or direct marketing.
- Withdrawal of consent at any time where processing relies on consent.
Withdrawal does not affect processing that occurred before withdrawal. Some rights may be limited where Catalyse must retain data or has another lawful basis.
To exercise your rights, contact privacy@catalyse.no. We may need to verify your identity. You may also complain to the Norwegian Data Protection Authority (Datatilsynet): https://www.datatilsynet.no.
## 11. Cookies and analytics
Pulse may use strictly necessary cookies for authentication, security, session management and user preferences. Optional analytics or advertising technologies should be activated only in accordance with applicable consent requirements. Where a consent control is provided, you can change your choice through that control.
## 12. Business accounts and administrators
Your organisation may control your Pulse workspace and may invite, suspend or remove users and view account-related information. Questions about your organisation's internal use of your data should also be directed to your organisation.
## 13. Automated processing and Pulse outputs
Pulse uses automated processing to generate market-level signals, rankings, forecasts and recommendations. These outputs concern market conditions and business opportunities; they are not intended to make legal or similarly significant decisions about individuals.
## 14. Changes to this Policy
We may update this Policy when our services, providers or legal obligations change. Published versions are dated and retained. We will provide appropriate notice of material changes and, where necessary, present the updated Policy within Pulse.
## 15. Contact
Privacy questions and rights requests:
privacy@catalyse.no
Catalyse
Norway