Privacy Policy
Last updated: March 20, 2026
Translations are provided for convenience only. In the event of any discrepancy, the English version shall prevail.
1. Data Controller
The data controller for personal data processed through PULSE is:
Terra Sense SRLVia San Michele, 24
24047 Treviglio (BG), Italy
P.IVA: 04854480169
Email: admin@ecocanto.com
PEC: terrasense.srl@lamiapec.it
2. What Data We Collect
We collect and process the following categories of personal data:
- Account data: email address, full name, and password (hashed)
- Profile data: role, industry sector, team size, experience level, and selling style description
- Chat messages: all messages you send and receive during coaching sessions
- Usage analytics: session frequency, feature usage, message counts, and interaction patterns (first-party only, no third-party tracking)
- Payment data: billing information processed by Stripe (we do not store card numbers)
- Technical data: browser type, language preference, and authentication tokens
3. Legal Basis for Processing
We process your data under the following legal bases as defined by GDPR Article 6:
- Contract performance (Art. 6(1)(b)): processing necessary to provide the PULSE coaching service you signed up for
- Consent (Art. 6(1)(a)): for optional analytics cookies and marketing communications (where applicable)
- Legitimate interest (Art. 6(1)(f)): for service improvement, security monitoring, and fraud prevention
- Legal obligation (Art. 6(1)(c)): for tax, accounting, and regulatory compliance
4. How We Use Your Data
- To provide and personalize AI sales coaching
- To improve the quality and relevance of coaching responses
- To detect usage patterns and autonomously evolve new features
- To manage your account and process payments
- To send transactional emails (account confirmation, password resets)
- To ensure the security and integrity of the service
5. Data Retention
- Coaching conversations: preserved for the lifetime of your account to enable conversation history and continuous improvement
- Account data: retained until you request account deletion
- Analytics data: aggregated and anonymized after 24 months
- Payment records: retained for 10 years as required by Italian tax law
Upon account deletion request, personal data is removed within 30 days. Anonymized, aggregated data may be retained indefinitely.
6. Your Rights
Under GDPR, CCPA, and applicable data protection laws, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your personal data (“right to be forgotten”)
- Data portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interest
- Restriction: request restriction of processing in certain circumstances
- Withdraw consent: withdraw consent at any time without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at admin@ecocanto.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or your local supervisory authority.
7. Data Processors and Sub-processors
We use the following third-party services to deliver PULSE:
- Supabase (EU region) — database hosting and authentication
- Anthropic (United States) — AI language model processing (Claude)
- Stripe (EU/US) — payment processing
- Vercel (Global CDN) — application hosting
- Resend (US) — transactional email delivery
8. International Data Transfers
Some of our data processors operate outside the European Economic Area (EEA). For transfers to the United States (Anthropic, Resend), we rely on:
- EU-US Data Privacy Framework (where certified)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Supplementary technical and organizational measures to ensure adequate protection
Your chat messages are sent to Anthropic for AI processing. These are processed transiently and are not used by Anthropic to train their models.
9. Data Security
We implement appropriate technical and organizational measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews.
10. Children’s Privacy
PULSE is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. Continued use of the service after changes constitutes acceptance.
12. Data Protection Officer
For questions about data protection, contact our DPO at admin@ecocanto.com.