Privacy Notice
LAST UPDATED · 26 AUGUST 2026
This notice explains what personal data Mizen Pulse collects, why, and what rights you have over it. The data controller is Mizen Digital, established in İzmir, Türkiye.
If you are in the European Economic Area or the United Kingdom, we process your data in accordance with the GDPR and UK GDPR respectively. Turkish customers are covered by Law No. 6698 (KVKK); the Turkish version of this notice sets out those rights.
What we process, and on what basis
| Data | Why | Lawful basis |
|---|---|---|
| Email address | Account identity, sign-in, notifications | Performance of a contract |
| Business name and sector | Sector context and competitor suggestions | Performance of a contract |
| The competitor brands you track | Building your scan list | Performance of a contract |
| Payment details | Collecting the subscription | Performance of a contract |
| Technical logs (IP, browser) | Security and debugging | Legitimate interests |
| Analytics and advertising cookies | Measuring which pages work | Consent |
Where we rely on legitimate interests, we have weighed them against your rights: the data is limited to what security and fault diagnosis require, and it is never used to profile you.
We never see your card details. Payment is taken by Paddle as Merchant of Record; card data never enters our systems.
About the advertising data
The ad content Pulse scans comes from the public transparency archives published by Meta and Google. This is published commercial communication, not personal data. We never access a private account and never connect to any platform on your behalf.
Who we share it with
We do not sell your data. We use these processors to run the service:
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | Frankfurt, EU |
| Vercel | Application hosting | Frankfurt, EU |
| Resend | Email delivery | Ireland, EU |
| Paddle | Payment and invoicing | United Kingdom / EU |
| AI provider | Generating the interpretations | United States |
What reaches the AI provider is the public ad content that was scanned, the brand names you track, and your business name. Your email address, phone number and payment details are not sent. Under our agreement the provider does not use this data to train models. We will name the provider on request.
International transfers
Our infrastructure sits in the EU. Two transfers leave it: the AI provider in the United States, and our own operations in Türkiye, which the European Commission has not issued an adequacy decision for. Both are covered by the European Commission's Standard Contractual Clauses. You may request a copy of the relevant clauses at the address below.
How long we keep it
- Account data: for the life of the subscription and 30 days after it ends, then permanently deleted.
- Advertising and analysis data: up to 24 months, so trends remain comparable.
- Invoice records: 10 years, as tax law requires (held by Paddle).
Security
Each customer's data is isolated at the database level by row-level security policies. One customer's query cannot technically reach another customer's rows. All connections are encrypted with TLS.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you,
- have inaccurate data corrected,
- have your data erased,
- restrict how we process it,
- receive your data in a portable, machine-readable format, and have it sent to another controller,
- object to processing carried out on the basis of legitimate interests,
- withdraw consent at any time, without affecting past processing,
- lodge a complaint with your national supervisory authority — in Türkiye, the Personal Data Protection Authority (KVKK).
Write to pulse@mizendigital.com. We answer within one month, as Article 12(3) requires.
Pulse does not make automated decisions producing legal effects about you. The interpretations it writes are about publicly advertised brands, not about you.
Cookies
Cookies fall into two groups. Strictly necessary ones are required for the site to function and are set without asking. Optional ones load only if you consent — refuse and those scripts are never sent to your browser at all, and the site works exactly the same.
Strictly necessary
| Cookie | Purpose | Lifetime |
|---|---|---|
sb-…-auth-token | Keeps you signed in. Created only when you sign in. | Session |
mp_consent | Remembers your cookie choice — without it we would ask again on every page | 6 months |
mp_src | Records which link brought you here (an ad, a search result). It is not linked to your identity, never shared with third parties, and used only to measure which promotion works. | 90 days |
NEXT_LOCALE | Your language preference | 1 year |
Your theme preference (light/dark) is kept in your browser's local storage, not a cookie, and is never sent to our servers.
Optional, consent-based
These load when you press “Accept” on the cookie bar. If you reject, none of them run. You can change your mind at any time:
| Tool | Provider | What for |
|---|---|---|
| Google Analytics 4 | Google Ireland Ltd. | How many people visit which pages. IP addresses are anonymised. |
| Google Tag Manager | Google Ireland Ltd. | Managing the other measurement scripts |
| Meta Pixel | Meta Platforms Ireland Ltd. | Measuring Facebook and Instagram advertising |
| Yandex Metrica | Yandex LLC | Visit statistics and on-page behaviour |
These providers may process data outside the EEA. Consenting means consenting to that transfer as well. Refusing has no effect on your use of the service.
Contact
Mizen Digital · İzmir, Türkiye
pulse@mizendigital.com