OpenPulse
SecurityLegal documentsMain page

GDPR information

Privacy notice

How AUVY GmbH processes personal data on openpulse.org, during handle and identity flows, and for invite-only managed OpenPulse services.

Last updated 2026-08-03

1. Controller

AUVY GmbH
Am Haag 8, 82166 Gräfelfing, Germany
Privacy: privacy@auvy.ai

A data protection officer is not currently required or appointed. Privacy requests are handled through the address above.

2. Website delivery and security

When you open the site, our hosting and delivery systems process the IP address, request time, requested URL, response status, referrer, user-agent and technical security data. This is necessary to deliver the page, prevent abuse, diagnose faults and protect the service.

The legal basis is Article 6(1)(f) GDPR (secure and reliable operation). Where a request is necessary to provide a service you asked for, Article 6(1)(b) GDPR also applies. Operational logs are normally removed or anonymised within 30 days, unless a security event, legal claim or statutory duty requires longer retention.

3. Request access and contact

The request-access form collects your name, work email, organisation, optional note, language selection, submission time and limited request metadata. We use it to assess and answer your request, prevent abuse and document our business communication.

The legal bases are Article 6(1)(b) GDPR (steps at your request before a possible agreement) and Article 6(1)(f) GDPR (qualified access management and business communication). We generally retain declined or inactive requests for up to 12 months. Contract records and legally relevant correspondence may be retained for statutory limitation, tax and commercial-law periods.

4. Handles, identity and managed services

If you claim an @handle, create an identity or use managed OpenPulse, we may process your email address, handle, decentralised identifier (DID), public encryption material, verification status, account and realm membership, session and device metadata, routing metadata, security events and support communication. Managed relays process sealed payloads and the metadata required to route them.

Processing is based on Article 6(1)(b) GDPR to provide the requested account or service and Article 6(1)(f) GDPR to secure identities, prevent impersonation and abuse, and operate the network. Account records remain while the identity or service is active. After deletion, we remove or irreversibly anonymise personal data according to the service deletion flow, except for short-lived backups, fraud-prevention records and data we must retain by law.

5. Cookies and storage on your device

We do not currently use advertising or audience-measurement cookies on the OpenPulse site. A consent banner is therefore not shown. The following storage is technically necessary when you use the corresponding feature:

  • Identity session: a secure, HTTP-only session cookie valid for up to 12 hours.
  • Handle claim: local and session storage for a claim draft (normally two hours), verification state and the recently claimed handle.
  • Device identity: a device-generated private key and DID stored in your browser until you clear it. The private key is not sent to OpenPulse; signatures and public key material are sent when required.
  • Bot protection: Cloudflare Turnstile may set technically necessary storage when the bot check is enabled.

You can clear browser storage through your browser. Doing so may sign you out or remove a locally held identity key; export a recovery kit before clearing a handle identity you intend to keep.

6. Service providers and recipients

We use providers only for defined operational purposes:

  • Hetzner Online GmbH: EU origin hosting for identity, directory, managed relay and durable service records.
  • Vercel Inc.: public website hosting, content delivery and website request handling.
  • Resend Inc.: verification, security, request-access and other transactional email.
  • Cloudflare Inc.: Turnstile bot protection, only when enabled on a form.

We may also disclose data to professional advisers, authorities or courts where required by law or necessary to establish, exercise or defend legal claims. OpenPulse does not sell personal data.

7. International transfers

Core managed service records are hosted in the EU. Website delivery and the US-based providers named above may involve access or processing outside the EEA. Where no adequacy decision applies, we use the European Commission's Standard Contractual Clauses and supplementary safeguards; an applicable EU-US Data Privacy Framework certification may also be used.

8. Your rights

Subject to the GDPR conditions, you may request access, rectification, erasure, restriction, data portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it for the future. You may also lodge a complaint with a supervisory authority.

Our competent lead authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany — lda.bayern.de. Contact us first at privacy@auvy.ai if you want us to resolve a concern.

9. Automated decisions and changes

We do not use personal data from these flows for decisions with legal or similarly significant effects under Article 22 GDPR. Automated abuse controls may temporarily reject a request; you can ask for manual review.

We update this notice when services, providers or legal requirements change. Material changes are identified by the date at the top of this page.

LegalImprintPrivacyTermsAcceptable use

OpenPulse is operated by AUVY GmbH, Germany.