1. Controller and contact details

Code lunatics (business ID 2915609-2), Louhikkorinne 14 B, 80140 Joensuu, Suomi.
Data protection matters: contact@pulpetti.com.

This policy concerns the Pulpetti service (hereinafter the Service): the website at pulpetti.com and the browser application at pulpetti.com/app. Use of the Service is also governed by the terms of service.

No data protection officer has been designated for the Service, because there is no obligation to do so under the General Data Protection Regulation. All data protection matters are handled from the address above.

2. Two roles: controller and processor

There are two kinds of personal data in the Service, and the role differs between them:

In practice this means that for the people added to a group, the controller is you — or the educational institution or organization on whose behalf you act. You are responsible for the data having a lawful basis, and you answer their inquiries. The Provider's obligations as a processor are set out in the data processing addendum in section 13, which forms part of the agreement.

3. What data is processed

3.1 Account data

  • email address, user identifier and whether the address has been verified,
  • sign-in method (email and password, or a Google account),
  • a hash of the password — the password is not stored in plain text and the Provider cannot see it; authentication is handled by Google (Firebase Authentication),
  • the chosen setting, language selection and tag colors.

Your name and your profile picture are not stored in the Provider's own database, even if you sign in with a Google account.

3.2 Payment data

  • the payment intermediary's customer identifier and subscription identifier,
  • subscription status, billing interval, end date of the period and whether the subscription has been canceled,
  • the email address associated with the payment,
  • for one-off purchases, the transaction identifier, the amount and the currency.

Card details are not processed or stored at any point. They are given directly to the payment intermediary on its own page.

3.3 Content you enter into the Service

  • groups and their names, plus the acknowledgment of permission to use images and its timestamp, if images have been added to the group,
  • people: a name and optionally a status (attending / unknown / not attending), a tag (up to 40 characters) and a note (up to 200 characters),
  • photographs of people, if you add them,
  • rooms and their floor plans, seating charts and rules.

People are not asked for a date of birth, an address, a national identification number or contact details, and there are no fields for them. In the teacher setting there is no status field at all.

3.4 Technical data

  • IP address and basic request details in server logs and in abuse prevention (rate limiting),
  • error logs for troubleshooting.

The application itself has no visitor tracking. Behind the login there are no analytics tools, tracking pixels, advertising identifiers or separate error tracking service. Users' names and the content they enter are not written to the logs. The marketing pages use Google Analytics, which is loaded only with your consent — see section 11.

If you contact support through the support link in the Service, the message is pre-filled with your language selection, your setting, your subscription status and your browser's identifying details. You see them before sending and can remove them.

4. Purpose and legal basis of processing

For the content entered into the Service, the legal basis is determined by you as the controller — see section 2.

Personal data is not used for direct marketing, profiling, automated decision-making or for training artificial intelligence models. Data is not sold.

5. Special categories of data and minors

The Service has no fields for sensitive data, and none is requested. The free note field may nevertheless contain such data if a user records it there — for example a remark about diet or mobility may be health data within the meaning of the GDPR. A photograph is likewise identifying data.

For this reason:

  • Record in the notes only what is necessary for the seating chart.
  • You are responsible for there being a lawful basis for processing sensitive data and images.
  • Photographs of minors require the permission of a guardian or of the educational institution. The Service asks for an acknowledgment of this before the first image and records the time of the acknowledgment.

When the Service is used in an educational institution, the controller is typically the institution rather than an individual teacher. Check your own organization's instructions before taking student data into any external tool. The processing addendum in section 13 is intended for exactly this situation.

6. Where the data is located

This is the most significant section for the privacy of the Service, and it depends on your access level.

6.1 Free use and trying it without an account

All content you enter is stored solely in your own browser's local storage. It is not transferred to the Provider's servers at all. Groups, people, names, notes, images, rooms and seating charts stay on your device.

Two things follow from this. Your data is nowhere else — but it is also lost if you clear your browser data, change device or browser, or use a private browsing window. Use the export function to make backups.

If you create an account but buy nothing, your account data is stored in the cloud but the content you enter is not.

6.2 Paid use

When you subscribe to Pro or make a one-off purchase, the content is stored in a Google Cloud Firestore database, which makes it available on different devices. At the moment of payment you can bring the data in your browser into the cloud; this adds the data and does not replace anything.

The servers are located in the European Union, in Google Cloud's eur3 multi-region (data centers in Belgium and the Netherlands).

Photographs are stored in the database as part of the other data, not in a separate file service. Images are reduced in size in the browser before they are stored.

7. Recipients and processors

Data is not sold or disclosed to outside parties for marketing purposes. The following sub-processors process data on the Provider's behalf:

The typefaces of the site and the application are self-hosted, so opening a page does not make a request to a third-party font service and your IP address is not disclosed that way. Signing in with Google and paying take place on Google's and Stripe's own pages, where their own privacy practices apply.

Data may be disclosed to an authority where the law so requires.

8. Transfers outside the EU

Data is stored within the EU. The sub-processors used by the Provider are, however, part of United States corporate groups, so the data may be accessible from outside the EU, for example in connection with technical support.

Transfers are based on the standard contractual clauses approved by the European Commission and on the EU–US Data Privacy Framework, together with supplementary safeguards. Up-to-date details for each service can be found in its own privacy documentation.

9. Retention and deletion

  • Account and content: retained for as long as the account exists. An unused account is deleted automatically 24 months after it was last used, unless paid access is in force. A reminder is sent to the account's email address at least 30 days in advance, and signing in restarts the period from the beginning. If the provision of the Service is discontinued altogether, the data is deleted according to the closing date of the Service without waiting for that period.
  • Deleting the account: you can delete the account in the Service's settings. Deletion immediately and permanently removes the account data, all groups, people, images, rooms, seating charts, rules and purchase records, as well as the authentication data. Any subscription in force ends at the same time.
  • Accounting records: payment transactions are retained for the period required by accounting legislation (as a rule 6 years from the end of the financial year). This cannot be deleted on request, because retention is a legal obligation. The payment intermediary also has a retention obligation of its own.
  • Server logs: for a short time, for troubleshooting and information security.
  • Browser local storage: data stays on your device until you clear your browser data or delete it in the Service. Deleting the account does not clear your browser's local storage — if you want to remove that as well, clear the site's data in your browser settings.

10. Your rights as a data subject

You have the right to:

  • access your data and obtain a copy of it,
  • rectify incorrect data,
  • erase your data (the "right to be forgotten"),
  • transfer the data from one system to another,
  • restrict processing and object to processing based on a legitimate interest,
  • lodge a complaint with a supervisory authority (in Finland, the Office of the Data Protection Ombudsman, tietosuoja.fi).

Most of these rights can be exercised directly in the Service without a separate request: the data can be viewed and edited, the export function gives you a machine-readable copy of it, and deleting the account removes everything. The export function also works when a subscription has ended — getting your data out is not behind a payment.

For other requests, contact contact@pulpetti.com. We reply within one month. We may have to verify your identity before acting on a request.

If your data was added to the Service by somebody else — a teacher, a couple getting married or an event organizer, for example — turn to them first. They are the controller of that data and can edit or delete it themselves. As a processor, the Provider cannot delete an individual person's data from another user's account without that user's instruction, but will pass your request on to them if you get in touch.

11. Cookies and browser storage

The application does not use cookies. Behind the login there are no analytics, visitor tracking, advertising networks or social media tracking plugins.

The marketing pages use Google Analytics, and they ask for consent. Nothing is loaded until you choose “Accept”: before that, no request is sent to Google and no analytics cookie is stored in your browser. If you decline, no measurement is enabled at all and the pages work exactly the same. Your choice is stored in your browser and you can change it at any time from the Cookie settings link at the bottom of the page.

The legal basis for this processing is your consent (Article 6(1)(a) of the GDPR). You may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before it.

The analytics cookies are _ga and _ga_<id>. The data collected is per-visit and aggregated: the page opened, the referring source, approximate location, device type and browser. Ad personalisation and Google signals are switched off, and the data is not used for advertising. Google retains the data for 14 months.

The Service does store information in your browser's local storage. This is necessary for the Service to work, so it does not require consent. The data stored is:

  • The content you enter into the Service on the free plan — groups, people, images, rooms, seating charts and rules — as well as unsaved work, so that it is not lost if the browser closes mid-task.
  • Your settings: language selection, setting, tag colors and the state of the panels.
  • A record of what you have already been shown: progress through the onboarding guidance and confirmations asked once — and, in paid use, the fact that saving happens in the cloud.
  • Temporary data that survives a page load; it is removed when the tab closes.

The data is stored as entries whose names begin with the Service's own prefixes. You can see them in full in your browser's developer tools; here they are described by purpose, so that the description stays accurate as the Service develops.

The sign-in session is kept in the browser's own storage (Firebase Authentication), not as a cookie. You can remove all of the above by clearing the site's data in your browser settings; unsaved seating charts will then be lost as well.

Signing in with a Google account and paying take place on Google's and Stripe's own pages, which may set cookies of their own in accordance with their own practices.

12. Information security

  • All traffic is encrypted (HTTPS).
  • Every API request is authenticated with a sign-in token, and the data is isolated per user: a user can reach only their own data.
  • The browser is not connected directly to the database; everything goes through the server.
  • Passwords are not stored in plain text; authentication is handled by Google.
  • Card details are not processed at all.
  • The size and number of images is limited, and the number of requests is rate-limited to prevent abuse.

No online service is completely safe, and absolute security cannot be guaranteed. If a personal data breach occurs, it will be notified to the supervisory authority and, where necessary, to you, in the manner and within the time limits required by law.

If you notice a security weakness in the Service, report it to contact@pulpetti.com. A report made in good faith will not be used against the person making it.

13. Addendum: data processing addendum

This addendum is an agreement under Article 28 of the GDPR for the situation in which a user (the controller) enters other people's data into the Service and the Provider processes it on their behalf (the processor). The addendum takes effect when the user accepts the terms of service, and it does not require a separate signature.

As a processor, the Provider undertakes the following:

  • Processing on documented instructions. Data is processed only in order to provide the Service and in accordance with the controller's instructions, unless the law requires otherwise. Data is not used for the Provider's own purposes, for marketing or for training models.
  • Confidentiality. Only those who need access in order to maintain the Service have access to the data, and they are bound by a duty of confidentiality.
  • Security. The measures described in section 12 are implemented, together with other safeguards appropriate to the risk (Art. 32).
  • Sub-processors. The sub-processors listed in section 7 are used, to which the controller gives general prior authorisation. A new sub-processor will be notified by updating this policy at least 30 days before it is taken into use. The controller may object to the change by ceasing to use the Service before it takes effect. Equivalent obligations are imposed on sub-processors.
  • Assistance. The Provider assists the controller with reasonable measures in responding to data subjects' requests, in impact assessments and in dealings with authorities. For the most part no assistance is needed, because the controller can search, edit, export and delete the data in the Service themselves.
  • Personal data breaches. The Provider notifies the controller without undue delay of any breach concerning the controller's data that comes to its knowledge, and provides the information the controller needs in order to meet its own notification obligation.
  • Return and deletion. On termination of the agreement the controller obtains the data through the export function. Deleting the account removes the data permanently. The agreement ends at the latest when an unused account is deleted after the period described in section 9. The Provider does not retain copies unless the law requires it.
  • Demonstrating compliance. On request, the Provider supplies the information necessary to demonstrate compliance with this addendum.

If your organization requires a separately signed processing agreement, contact contact@pulpetti.com.

14. Changes to this policy

This policy is updated when the Service or the processing of data changes. The version in force is always on this page, and the version number and effective date are shown at the top of the page. Material changes will be notified in the Service and, where necessary, by email at least 30 days before they take effect.