TRIAS Pulse
Privacy Terms
EN TR
Privacy at TRIAS Pulse

Privacy Policy

A transparent explanation of how we handle personal data when you visit, register for or use TRIAS Pulse.

Effective date 8 September 2026 Version 1.0
On this page
01Scope and who we are 02Personal data we collect 03Where data comes from 04Purposes and legal bases 05Tenant registration, domains and approvals 06Microsoft, Google, LinkedIn and other integrations 07How we disclose data 08Service providers and subprocessors 09International data transfers 10Retention and deletion 11Security and account responsibility 12Personal data incidents 13Cookies and similar technologies 14Your data-protection rights 15Automated decisions and AI-enabled features 16Children and special-category data 17Policy changes and contact
Data controller and service providerTRIAS Technology B.V.
Brabantsestraat 16
3074 RS Rotterdam
The Netherlands
KVK99616165RSIN869062529
pulse@trias-technology.comtrias-technology.com
01

Scope and who we are

This Privacy Policy applies to the TRIAS Pulse website, registration flow, SaaS application, support interactions and related communications provided by TRIAS Technology B.V. It explains processing for visitors, prospective customers, customer administrators, authorised users and business contacts.

TRIAS Technology B.V. is the controller for account administration, business applications, billing, service security, product communications and its own website operations. When a customer organisation uploads or manages CRM, employee, contact, activity, communication or other workspace data, that customer normally determines the purposes and means of processing and acts as controller; TRIAS Technology B.V. processes that Customer Data as processor under the applicable agreement and Data Processing Agreement.

This policy does not replace a customer organisation’s own privacy notice to its employees, contacts, prospects or other individuals whose data it enters into TRIAS Pulse.
02

Personal data we collect

The categories collected depend on how you interact with the service and which features your organisation enables.

  • Identity and account data: name, business email, username, profile image, job title, department, preferred language, time zone, tenant membership, roles and permissions.
  • Business registration data: legal and trading name, company type, address, country, website, domain names, tax office, tax number, trade registry or MERSIS number, industry, employee range and expected number of users.
  • Authentication data: password hashes, identity-provider identifiers, verified-email status, login timestamps, authentication method, session identifiers and security events. We do not store your identity-provider password.
  • Customer Data: CRM companies, contacts, leads, opportunities, quotes, tasks, notes, activities, files, calendars, communications and other information submitted by or for a customer.
  • Integration data: provider account identifiers, authorisation scopes, tokens where required, synchronisation status and data retrieved from connected services such as Microsoft, Google or LinkedIn.
  • Technical data: IP address, device and browser characteristics, operating system, application version, request timestamps, diagnostic logs, cookie identifiers and approximate region derived from IP.
  • Support and communications data: support requests, correspondence, attachments, feedback, meeting notes and records of service notices.
  • Commercial data: subscription, plan, invoicing contact, transaction references, payment status and statutory accounting records. Complete card details are handled by the selected payment provider and are not intended to be stored in TRIAS Pulse.
03

Where data comes from

We collect data directly from you, from your organisation’s administrators and authorised users, automatically from your use of the service, and from integrations you or your administrator choose to connect.

  • Identity providers may supply your verified email, name, profile and provider-specific account identifier after you approve sign-in.
  • Your employer or contracting organisation may create your account, assign roles and add business information about you.
  • Connected services provide only the information covered by the scopes presented during authorisation.
  • Public business registers and lawful public sources may be used to validate a tenant application, company identity, domain ownership or authorised representative.
04

Purposes and legal bases

We process personal data only when a legal basis applies. The applicable basis depends on the context and our role.

  • Contract and pre-contractual steps: creating and administering accounts, reviewing tenant applications, authenticating users, delivering subscribed functionality, providing support and managing billing.
  • Legitimate interests: securing the platform, preventing fraud and misuse, maintaining audit trails, improving reliability and usability, managing customer relationships and communicating essential product information. We balance these interests against individual rights.
  • Legal obligation: tax and accounting records, responding to binding legal requests, sanctions and compliance checks, and security or breach obligations.
  • Consent: optional marketing, non-essential cookies, and provider integrations where consent or user authorisation is the appropriate basis. Consent can be withdrawn without affecting earlier lawful processing.
  • Customer instructions: for Customer Data, we process on behalf of the customer under Article 28 GDPR and the customer’s documented instructions, unless EU or Member State law requires otherwise.
05

Tenant registration, domains and approvals

When you register with a business email, we derive the domain and may match it to a verified customer domain. If a match exists, selected account details and the fact that you requested access may be shown to authorised tenant administrators so they can approve or reject membership.

If no verified tenant is found, you may submit a business application. We use the supplied company and representative information to validate the organisation, prevent duplicate or fraudulent tenants, contact the applicant and establish the initial administrator. Domain ownership may be verified using a controlled email, DNS record or equivalent method.

A matching email domain is a routing signal, not by itself proof of authority. Access remains subject to verification and approval.
06

Microsoft, Google, LinkedIn and other integrations

Social sign-in verifies identity and is logically separate from optional product integrations. Signing in with Microsoft, Google or LinkedIn does not automatically permit TRIAS Pulse to read mail, calendars, files, contacts or other provider data.

Where you connect an integration, the authorisation screen identifies the requested permissions. We use provider tokens to perform requested synchronisation and may store access and refresh tokens in protected form for as long as the connection remains active. You can disconnect an integration; provider-side revocation may also be required. Provider services operate under their own terms and privacy notices.

07

How we disclose data

We do not sell personal data. We disclose data only where necessary for the service, instructed by a customer, legally required or otherwise described here.

  • Within your tenant, according to roles, permissions, sharing choices and administrative settings.
  • To hosting, infrastructure, email, monitoring, support, identity, payment and professional service providers acting under contract and confidentiality obligations.
  • To connected third-party services when an authorised user initiates an integration or action.
  • To advisers, auditors, insurers, authorities or courts where necessary to establish, exercise or defend legal claims or comply with law.
  • In a merger, financing, reorganisation or sale, subject to appropriate confidentiality and continued protection.
  • In aggregated or de-identified form that is not reasonably capable of identifying an individual.
08

Service providers and subprocessors

We select processors that provide sufficient guarantees for privacy, confidentiality, availability and security. Contracts limit them to documented purposes and require appropriate safeguards. Categories may include cloud hosting, content delivery, transactional email, observability, customer support, identity, payment and backup providers.

For enterprise customers, a current subprocessor list and change-notification mechanism may be provided through the account, contract or on request. Where required, customers may object to a new subprocessor on reasonable data-protection grounds under the Data Processing Agreement.

09

International data transfers

We seek to host and process EEA customer data within the European Economic Area where commercially and technically appropriate. Some providers or support operations may involve access from another country.

For transfers outside the EEA, United Kingdom or Switzerland, we rely on a valid mechanism such as an adequacy decision, the European Commission’s Standard Contractual Clauses, supplementary technical and organisational safeguards, or another lawful derogation where strictly applicable. Copies of relevant safeguards can be requested, subject to protection of confidential information.

10

Retention and deletion

We keep personal data only for as long as needed for the purpose collected, contractual commitments, dispute handling, security and legal obligations. Customer configuration and contract terms may set more specific periods.

Account and workspace data is generally retained during the subscription and for a limited export or recovery period after termination. Security and audit logs are generally kept for up to 12 months unless risk, investigation or law requires longer. Unsuccessful or rejected registration applications are normally deleted or anonymised within 12 months. Support records are normally retained for up to 24 months after closure. Statutory financial records may be retained for the legally required period. Backups expire through controlled rotation and may not be immediately editable.

Deletion may be delayed where preservation is required for a legal claim, binding request, fraud investigation or statutory recordkeeping obligation. Access is restricted during any extended preservation.
11

Security and account responsibility

We use risk-based technical and organisational measures intended to protect confidentiality, integrity, availability and resilience. No internet service can guarantee absolute security.

  • Tenant-aware access controls, role and capability checks, authentication controls and session protection.
  • Encryption in transit, protected credential storage, password hashing and appropriate protection for integration secrets.
  • Logging, monitoring, vulnerability management, backups, recovery procedures and change controls.
  • Least-privilege administrative access, confidentiality commitments and incident-response procedures.
  • Customers must manage authorised users, permissions, endpoint security, integration choices and the lawfulness and accuracy of Customer Data.
12

Personal data incidents

We maintain procedures to assess and respond to suspected personal data breaches. Where we act as processor, we notify the affected customer without undue delay after becoming aware of a breach involving that customer’s data and provide available information to support the customer’s obligations.

Where we act as controller, we notify the competent supervisory authority and affected individuals when required by applicable law. Notifications may be delivered through account contacts, email, in-product notices or another appropriate channel.

13

Cookies and similar technologies

TRIAS Pulse uses strictly necessary cookies or equivalent storage for sessions, CSRF protection, language preference, load balancing and security. These are required for requested functionality and cannot always be disabled without making the service unusable.

Analytics, personalisation or marketing technologies will be activated only where configured and where an appropriate legal basis exists. When consent is required, a preference mechanism will be provided before non-essential technologies are set. Browser controls may delete cookies but can sign you out or reset preferences.

14

Your data-protection rights

Depending on the circumstances, you may request access, rectification, erasure, restriction, portability or objection, and may withdraw consent. You may also have rights relating to decisions based solely on automated processing.

  • For data controlled by TRIAS Technology B.V., contact pulse@trias-technology.com. We may request proportionate information to verify identity and protect other users.
  • For Customer Data, first contact the organisation that provided your account or entered the data. We assist customers with verified requests as required by our agreement and law.
  • Rights are not absolute. We may retain or withhold information where an exemption, competing right, legal obligation or security consideration applies, and will explain the applicable reason.
  • You may lodge a complaint with the Autoriteit Persoonsgegevens in the Netherlands or another competent supervisory authority, and seek a judicial remedy.
15

Automated decisions and AI-enabled features

TRIAS Pulse may provide automation, recommendations, summaries or AI-assisted features. Unless expressly stated for a specific feature, we do not use our own account processing to make decisions producing legal or similarly significant effects about individuals.

Customers are responsible for reviewing outputs, configuring workflows and ensuring that their use of automated or AI-enabled functionality is lawful, fair, accurate and subject to meaningful human oversight. Product-specific notices may explain additional data flows before a feature is enabled.

16

Children and special-category data

The service is designed for organisations and authorised business users, not children acting in a personal capacity. Individuals who cannot legally agree to the service must not register independently.

Customers should not submit health, biometric, political, religious, trade-union, sexual-life, criminal-conviction or other specially protected data unless the relevant feature and contract expressly support it and the customer has established a lawful basis and appropriate safeguards.

17

Policy changes and contact

We may update this policy to reflect product, legal or operational changes. The effective date and version will be updated. Material changes may be communicated through email, the service or another prominent notice before they take effect where appropriate.

Privacy requests and questions may be sent to pulse@trias-technology.com or by post to TRIAS Technology B.V., Brabantsestraat 16, 3074 RS Rotterdam, The Netherlands. Please identify the relevant organisation or tenant and avoid sending unnecessary sensitive information.

Privacy questions

Your privacy matters

Contact us to exercise your rights or ask how your information is handled.

pulse@trias-technology.com →
© 2026 TRIAS Technology B.V.KVK 99616165 · RSIN 869062529Back to sign in