Security and Processing Annex
Last Updated: September 22, 2026
This page describes how we process personal data on behalf of our customers. It expands Annex 1 and Annex 2 of our Data Processing Addendum into the detail a data protection officer normally asks for before approving an integration, and it is written to be handed over as it stands. The Data Processing Addendum remains the contractual document, and where the two differ, it prevails.
Contents
- 1. Scope and roles
- 2. Who processes the data
- 3. Purposes of the processing
- 4. Data subjects and data categories
- 5. Agent Analytics in detail
- 6. Where the data is hosted
- 7. International transfers
- 8. Sub-processors
- 9. How long we keep data
- 10. Technical measures
- 11. Organizational measures
- 12. Personal data breaches
- 13. Data subject rights
- 14. Documentation and signed agreements
1. Scope and roles
For the personal data you submit to the Service or connect to it, you are the controller and we are your processor. Where you use LLM Pulse to serve your own clients, you act as their processor and we act as your sub-processor. We process that data only on your documented instructions, which consist of our Terms, the Data Processing Addendum and your configuration of the Service.
We are separately the controller of the data we need to run our own business, such as your account and billing details. That processing is described in our Privacy Policy.
2. Who processes the data
LLM PULSE SL
Registered office: Passeig de Gràcia 53, Ático 1ª, 08007 Barcelona, Spain
Tax identification number (NIF): B27561133
Registered with the Mercantile Registry of Barcelona
Data protection contact: info@llmpulse.ai
We are established in the European Union, so we do not appoint a representative under Article 27 GDPR. Data protection requests reach the company through the address above and are handled by management.
3. Purposes of the processing
We process personal data to host and store what you submit, to analyze how brands appear in the answers of AI assistants, to import and aggregate the traffic sources you connect, to produce reports and exports, to serve embedded and white label portals, to run the AI assisted features you ask for, and to provide support, security and abuse prevention.
We do not sell personal data, and we do not train models on what you submit.
4. Data subjects and data categories
Categories of data subjects: your users and staff; your clients and the end viewers of shared or embedded reports; your website visitors; and individuals named in content you submit or in public sources the Service analyzes.
Personal data we store: names, email addresses and other contact and professional details, plus any personal data in the content you submit or the sources you connect.
Personal data in your logs: log records you connect can contain the IP addresses and other identifiers of your visitors. We discard them while reading each record and never store them. A log file you upload yourself is deleted at most 30 days after processing.
Data that is not personal data: aggregated daily figures per project (requests per bot, page and status code; traffic, session and conversion totals), the paths of your own pages and the user agent strings of AI crawlers.
Special categories: none is intended, and the Data Processing Addendum asks you not to submit them.
5. Agent Analytics in detail
Agent Analytics counts how AI crawlers and assistants request your pages. From each server, CDN or log drain record it reads five fields only: the timestamp, the user agent string, the requested path, the response status code and the response size. Client IP addresses present in the source are discarded while the record is being read and are never written to our database.
What we store is a daily aggregate per project: requests per bot, per path and per status code. There is no per visitor record and no identifier that would single out a person. If you upload a log file yourself, that file is kept for at most 30 days after it is processed and is then deleted.
Those five fields are all Agent Analytics needs. As the controller, you decide what your log sources send us: configure them to send only those fields where your provider allows it, and remove IP addresses and other identifiers from any file before you upload it. Anything else that arrives is discarded as described above, but minimizing personal data starts with what you send.
6. Where the data is hosted
The application, its databases and its job queues run on dedicated servers rented from Hetzner in Germany. Backups are written to a Hetzner Storage Box in Germany and mirrored to Cloudflare R2 object storage. Files you upload, such as logos, and the exports the Service generates are stored on Cloudflare R2.
Our preproduction environment runs on a separate server, also at Hetzner in Germany, under the same access controls. It is refreshed from a reduced copy of the production backup, which is how we exercise the restore procedure every week.
7. International transfers
Customer personal data is hosted in the European Union. Some sub-processors are established outside the European Economic Area. For those transfers we rely on an adequacy decision of the European Commission where one applies, including the EU-US Data Privacy Framework where the recipient is certified, or on the Standard Contractual Clauses adopted by the European Commission, with supplementary measures where they are needed.
8. Sub-processors
The current list, with the purpose of each provider and the regions where it processes data, is published at llmpulse.ai/subprocessors and kept up to date. We notify customers at least 30 days before we add or replace a sub-processor, and you may object in writing within that period on reasonable data protection grounds. Every sub-processor is bound by data protection obligations materially equivalent to the ones we owe you.
9. How long we keep data
Scheduled jobs delete traffic and Agent Analytics aggregates after 395 days, and connected Search Console data after 400 days. Raw log files uploaded to Agent Analytics are deleted at most 30 days after they are processed. Generated exports are deleted when they expire. Our internal trail of administrative actions is trimmed after 24 months. Backups are kept as seven daily, four weekly and three monthly copies, and older ones are removed automatically.
The rest is kept for the life of the account. When the processing ends you can ask us to return the data or delete it, and we complete deletion within 90 days of termination, apart from backup copies that are overwritten in the normal cycle and data we have to keep by law.
10. Technical measures
Our technical measures include:
- Encryption in transit. The Service is served over HTTPS only, with strict transport security.
- Encrypted backups. Daily backups are encrypted, held off the application server and mirrored to a second location. Their integrity is verified daily, and a file is restored from the newest archive as a canary.
- Access control. Access inside the product follows least privilege through a role based permission system. Administrative access to servers is limited to the two company founders.
- Authentication. Optional two factor authentication, hashed passwords and encrypted second factor secrets.
- Host hardening. Automatic banning of abusive addresses, unattended security updates and alerts on privileged access to the server.
- Application hardening. Rate limiting, protection against cross site request forgery, a content security policy, and validation that refuses requests aimed at internal network addresses.
- Separated environments. Production and preproduction run on separate machines with separate credentials.
- Monitoring. Production systems are monitored and failures raise an alert to the engineering team.
11. Organizational measures
Our organizational measures include:
- Confidentiality. Everyone authorized to process customer data is bound by confidentiality.
- Accountability. Changes a person makes to customer records are recorded with the acting user, and administrative console sessions in production are recorded and available for review.
- Change control. Every change is reviewed and runs through an automated test suite, and a release reaches production only from a build that passed it.
- Provider due diligence. We review a provider's data protection terms and its location before we use it.
- Documented procedures. Written procedures for incident response, for data subject requests, and for deletion and restore.
12. Personal data breaches
We notify you without undue delay after we become aware of a breach affecting personal data we process for you. The first notice carries the information available at that point, and we send further detail as it emerges rather than waiting for a complete picture. We assist you with your own notifications to supervisory authorities and to data subjects.
13. Data subject rights
You remain the point of contact for the people whose data you send us. If one of them contacts us directly, we forward the request to you and do not answer it on the merits, unless the law requires us to. We assist you with requests for access, rectification, erasure, restriction and portability, and the Service lets you export and delete the data in your account yourself.
14. Documentation and signed agreements
Our Data Processing Addendum applies to every customer automatically and needs no signature. If your client needs a signed agreement, the Standard Contractual Clauses, or a completed security questionnaire, write to info@llmpulse.ai and we will provide it. We answer reasonable written security questionnaires and support the audit rights set out in the Data Processing Addendum.