Pulse Privacy Policy
V
1.1
—
Zuletzt bearbeitet am
PFM Pulse ("the App") is a building occupancy analytics application built with Flutter, provided by PFM Global Holding B.V. and its subsidiary companies ("PFM", "we", "us", "our"). This Privacy Policy explains how we collect, use, and protect your personal information when you use the App.
1. Who We Are (Data Controller)
The App is provided by:
PFM Global Holding B.V. and subsidiary companies
De Schans 23, 2405 XX Alphen aan den Rijn, Netherlands
+31 172 435901 · info.nl@pfm-intelligence.com
Chamber of Commerce (KvK) no. 57340196
PFM has appointed a Data Protection Officer registered with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). For any privacy question or to exercise your rights, contact: privacy@pfm-intelligence.com.
Controller and processor roles. PFM Pulse is a business tool used by our clients (for example retailers, property owners and municipalities) who install a people-counting system on their site and instruct us to process the resulting data on their behalf. For that building occupancy data, our client is the data controller and PFM acts as the data processor under a processor agreement. For the personal data relating to your App user account (see section 2.1), PFM is the data controller. This Privacy Policy describes the processing for which PFM is responsible; processing carried out on behalf of a client is additionally governed by our agreement with that client.
2. Information We Collect
2.1 Account Information
When you create an account or sign in, we collect:
Email address
Password (processed through AWS Cognito authentication)
Name (optional, from user profile)
Phone number (optional, from user profile)
Email verification status
Phone number verification status
2.2 Site and Usage Data
The App fetches and stores building occupancy data from an external service API, including:
Building identification, name, and attributes (type, description, timezone)
Site cluster information and relationships
Daily and hourly occupancy statistics (count-in, count-out)
Zone-level occupancy metrics for monitored areas
Weather data including temperature (Celsius/Fahrenheit), precipitation, and weather descriptions for building locations
Geolocation data (latitude/longitude) of the building location being monitored — this is the site's location, not your device's location, and the App does not track your device's GPS position
Historical data (from the site's earliest recorded date up to the threshold configured in user preferences)
Opening hours and operational time settings
Device and measurement feed information
This occupancy data is aggregated counting data. It does not contain video images and is not used to identify any individual passer-by or visitor.
2.3 User Preferences and Settings
We store your app preferences locally on your device using SharedPreferences:
Pulse dashboard configuration (module order, active states)
Temperature unit preferences (Celsius/Fahrenheit)
Week start day preferences
Opening and closing time preferences
Data display mode preferences (percentage/absolute values)
Cache refresh frequency settings (15 minutes, 1 hour, or always)
Historical data retention threshold (number of days)
Threshold difference settings for anomaly detection
Sites cache for offline access
2.4 Device and Usage Data
The App collects the following information to operate the service, and to improve performance and security:
Connection type (WiFi vs cellular) for prefetch operations (WiFi-only by default)
Sign-in security information recorded through AWS Cognito / Amplify each time you log in, including the authentication result, the device name or model used, your IP address, and the approximate location (city) derived from that IP address. This information is used to secure your account and detect suspicious sign-in activity. The platform has the capability to collect further in-app usage analytics; this additional analytics collection is not currently enabled.
Authentication session tokens and user pool tokens
Error logs and crash reports (for debugging and improvement)
Prefetch completion status and last prefetch time
Cache storage sizes and database statistics
3. Legal Basis for Processing
Under the UK GDPR and the EU General Data Protection Regulation, we process your personal data on the following legal bases:
Performance of a contract: to create and authenticate your account and to provide the occupancy analytics service you and/or your organisation have signed up for.
Legitimate interests: to secure the App, diagnose and fix technical issues, and improve performance and reliability. We balance these interests against your rights and freedoms.
Legal obligation: where we are required to process or disclose data to comply with the law.
Consent: where you have explicitly agreed to a specific processing activity; you may withdraw consent at any time.
4. How We Use Your Information
We use the collected information to:
Authenticate users and manage secure sessions via AWS Cognito
Fetch and display building occupancy data from external services
Provide personalized dashboard experiences with customizable modules
Cache data locally for offline access and improved performance
Process data prefetch requests (WiFi-only by default to conserve bandwidth)
Aggregate hourly data to daily statistics for optimized storage
Refresh today's data in background based on configured frequency settings
Maintain data synchronization across sessions
Diagnose and fix technical issues using error logging
Store a normalized database for efficient querying and reporting
5. Data Storage and Security
We implement multiple layers of security:
AWS Cognito Authentication: User credentials are securely managed through AWS Cognito with industry-standard encryption.
Secure Storage: Sensitive tokens and session data are stored using flutter_secure_storage (iOS Keychain/Android Keystore).
Local Cache: Site data, preferences, and statistics are stored using shared_preferences for app functionality.
Normalized Database: Hourly and daily statistics are stored in a local SQLite database for efficient querying.
API Security: All API communications use HTTPS with bearer token authentication.
Data Encryption: Data in transit is encrypted using TLS 1.2+.
The App stores data in the following locations:
Cloud: AWS Cognito (authentication), Backend API (site and statistics data)
Local Device: SharedPreferences (settings, cache), Secure Storage (tokens), SQLite database (normalized statistics)
6. International Data Transfers
Our authentication and backend services are hosted in the Amazon Web Services (AWS) Europe (Ireland) region (eu-west-1), within the European Economic Area. Where personal data is processed by AWS as our sub-processor, this is governed by the AWS Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum to provide appropriate safeguards for any transfer of personal data outside the EEA or the UK. You may request a copy of the relevant safeguards by contacting privacy@pfm-intelligence.com.
7. Data Sharing and Disclosure
We do not sell your personal information. We may share data in the following circumstances:
With Your Consent: When you explicitly agree to share information.
Service Providers (Sub-processors): We use AWS services (Cognito, API Gateway) to process and store data. These providers act on our documented instructions and have access to data only to perform services on our behalf, under a data processing agreement.
Our Clients: Where PFM processes building occupancy data on behalf of a client (the controller), that data is handled in accordance with our processor agreement with that client.
Legal Requirements: We may disclose information when required by law or in response to valid requests by public authorities.
Business Transfers: In connection with a merger, acquisition, or asset sale, user data may be transferred as part of the transaction.
8. Data Retention
We do not keep your personal data longer than is necessary for the purposes for which it is processed. Account and cloud-stored data are retained for the duration of your (or your organisation's) contract with PFM, in accordance with PFM's data retention policy, after which the data is deleted or anonymised unless we are required to keep it to meet a legal obligation.
Local cached data on your device is retained until:
You manually clear app data/cache through app settings
You uninstall the application
It is automatically refreshed based on your configured cache settings
Historical data exceeds your configured retention threshold
9. Your Rights and Choices
Under the UK GDPR and the EU GDPR, you have the right to:
Access the personal data we hold about you
Rectification — correct inaccurate or incomplete data
Erasure — request deletion of your personal data ("right to be forgotten")
Restriction of processing in certain circumstances
Objection to processing based on our legitimate interests
Data portability — receive your data in a structured, commonly used, machine-readable format
Withdraw consent at any time, where processing is based on consent
Opt out of data prefetch (can be disabled in app settings)
To exercise any of these rights, email privacy@pfm-intelligence.com or raise a support ticket via the web form on our website. We will respond within the statutory time limit (within one month). You also have the right to lodge a complaint with your data protection supervisory authority — for PFM that is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), and you may also contact your local supervisory authority in the EEA or the UK.
10. Account and Data Deletion
You can request deletion of your PFM Pulse account and its associated personal data at any time:
From within the App / online: use the account deletion link provided in the App to open our support request form, or go directly to the deletion request form on our website.
By support ticket: submit a request via the web form on our website, or email privacy@pfm-intelligence.com.
Because PFM Pulse accounts are provisioned for business users, a deletion request removes your authentication account (AWS Cognito) and the personal data associated with it, subject to any data we are legally required to retain. You can also remove locally stored data at any time by clearing the app cache in settings or by uninstalling the App.
11. Third-Party Services
This App uses the following third-party services:
AWS Cognito: Authentication and user management (https://aws.amazon.com/privacy/)
AWS Amplify: Authentication events and backend services (https://aws.amazon.com/privacy/)
Flutter Framework: Application framework (https://flutter.dev/privacy)
Third-party services have access to data only to perform services on our behalf and are obligated not to disclose or use it for other purposes. Privacy manifests are provided for third-party SDKs as required by the Apple App Store.
12. Children's Privacy
PFM Pulse is a business tool and is not directed at or intended for use by children. We do not knowingly collect personal information from children under the age of 16. If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will delete that information. If you believe a child has provided us with personal data, please contact privacy@pfm-intelligence.com.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
PFM Global Holding B.V.
De Schans 23, 2405 XX Alphen aan den Rijn, Netherlands
Email: privacy@pfm-intelligence.com
App Version: 1.0.0