Privacy notice
This notice explains what ServerPulse does with personal data: what we collect, why, on what legal basis, who else sees it, how long we keep it, and how you can see, correct, erase or complain about it. It is written to meet India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and — for people in the European Union and the United Kingdom — the GDPR.
This notice is available in English. You can ask for it in any language listed in the Eighth Schedule to the Constitution of India by writing to privacy@dxcslabs.com; translations are being prepared.
- We collect what is needed to run the monitoring you asked for and to keep the service secure. No advertising, no data sales, no trackers on this website.
- Data about your website's visitors is collected on your instruction; for that data you decide and we act as your processor.
- Every kind of record has a retention period and is deleted automatically by a nightly job.
- Optional uses — product news and AI analysis — are off unless you turn them on, and off again in one click.
- Download, correct or delete your data yourself from Settings → Privacy & data, or send us a request.
1. Who we are
ServerPulse is operated by Cruzetec Solutions, a partnership firm based in Mohali (SAS Nagar), Punjab, India, trading as DxCS Labs. For the data described in section 2 we are the Data Fiduciary (DPDP) / controller (GDPR). For the visitor data described in section 3 we are a Data Processor acting for our customer.
- Privacy questions: privacy@dxcslabs.com
- Grievance Officer: Grievance Officerto be confirmed — grievance@dxcslabs.com
- EU/UK representative (GDPR Art. 27): not appointed — we do not target the EU/UK market; write to the privacy address above
2. What we collect, why, and on what basis
| Data | Why | Legal basis |
|---|---|---|
| Account and team — name, email, role, timezone, notification choices; a hash of your password (never the password); two-factor secrets (encrypted) and passkey public keys | To give you an account and run the service you signed up for | DPDP s.7(a) — provided by you for this purpose; GDPR 6(1)(b) contract |
| Sign-in and security records — time, IP address, browser, sign-in method, failed attempts, refused requests; an audit log of changes made in the console | To protect accounts, detect misuse and investigate incidents | DPDP s.8(5) security safeguards and Rules r.6 (logs kept one year); GDPR 6(1)(c) and (f) legitimate interest in security |
| Billing — billing contact, company address, GSTIN, invoices and payments (paid through Razorpay; we never see card or UPI details) | To invoice and to meet tax law | DPDP s.7(a)/(b) and legal obligation; GDPR 6(1)(b) and (c) |
| Demo requests — name, email, phone (optional), company, website, number of sites, hosting, needs, preferred time; the IP address and browser the form was sent from; the consent you ticked, its wording and when | To arrange and run the demo you asked for, and to stop form abuse | DPDP s.6 consent, given by ticking the box on the form; GDPR 6(1)(b) steps before a contract, 6(1)(f) for abuse prevention |
| Code audit (customers who connect a repository) — a read-only access token; a temporary copy of the repository, deleted when each scan ends; findings with a few lines of code around each, with secrets and personal data masked | To run the code scans you switched on and show you what they found | DPDP s.7(a) — provided by you for this purpose; GDPR 6(1)(b) contract. Where the code contains personal data, we process it as your processor under the DPA |
| Rights requests and grievances — what you send us and our reply | To answer you and to show that we did | Legal obligation (DPDP s.8(10), s.13; GDPR 6(1)(c)) |
| Public-site statistics — which page or step was reached, the name of the form field where someone stopped (never what was typed), referring site name, campaign tags, device type, the first three parts of the IP address, and a visitor code that changes every day | To see where the website loses people, and to stop scrapers | GDPR 6(1)(f) legitimate interest — no cookies, no profile, not linkable across days |
| Monitoring data about your sites — availability checks, certificates, DNS, headers, server metrics, software inventory, file hashes | The service itself | Contract; mostly not personal data |
| Optional: product news | Occasional product news by email | Consent — off by default, withdraw in Settings → Privacy & data |
| Optional: AI analysis — excerpts of flagged files, finding details and console summaries for your company; questions you type into the assistant | Automated triage and explanations | Consent of the company owner — off by default; switching it off stops all further sending |
We do not make decisions with legal or similarly significant effects about anyone by automated means, and we do not build advertising profiles.
3. Your website's visitors (we are your processor)
When you install the ServerPulse agent on a site, it reports each request to that site: time, IP address, country, method, path and query string, status, response size and time, referrer and user agent. Security events add the rule that fired and a short excerpt of the suspicious input. This is personal data about your visitors, collected because you asked us to, and you are its Data Fiduciary / controller. Our Data Processing Agreement governs it.
- A visitor session key is a salted hash of IP + browser + date computed on your server; the salt never leaves it, so the key cannot be reversed and does not link a visitor across days or sites.
- You can turn on Mask visitor IPs for your company so the last part of each address is hidden in the console.
- Raw traffic is kept 14 days and security events 90 days, or less if your company sets a shorter window.
- The agent never sends file contents, database contents or credentials.
If you visited a site monitored by ServerPulse and want to exercise your rights, contact that site's owner. If you write to us, we pass your request to them without delay and tell you we have.
4. Who else sees it
We do not sell personal data. These providers process it for us, under contract, only to provide their service:
| Provider | What for | Where |
|---|---|---|
| Hostinger Hostinger International Ltd. |
Hosting of the platform (virtual private server, database, backups) and, for now, outgoing email. Always. | VPS data-centre region as provisioned |
| Anthropic Anthropic, PBC |
AI analysis of suspicious files and findings, the console assistant, and code-fix explanations. Only for companies whose owner switched AI analysis on (off by default), and for questions typed into the assistant. | United States |
| Razorpay Razorpay Software Private Limited |
Payment collection for invoices. When an invoice is paid online. | India |
| Team Cymru / RDAP registries Team Cymru Inc.; regional Internet registries via rdap.org |
Looking up which network an IP address belongs to (attack attribution, CDN/origin detection). For addresses that appear in security events or traffic on agent-monitored sites. | United States / registries worldwide |
Details, including what data each receives, are on the subprocessors page. Alerts go to the Slack, Teams, Telegram or webhook destinations you configure. We disclose data to authorities only where the law requires it.
5. Transfers outside India
The platform is hosted on our provider's servers. Data leaves India only where a provider in section 4 is abroad: AI analysis (United States, and only when your company's owner switched it on) and IP-address network lookups. Under DPDP s.16 such transfers are permitted except to countries the Government of India restricts by notification; we will stop any transfer to a restricted country. For people in the EU/UK, transfers rely on the providers' Standard Contractual Clauses (GDPR Art. 46).
6. How long we keep it
| Record | Kept for |
|---|---|
| Account and team data | While the account exists; erased when you delete it (immediately) or your company (after a 14-day grace period) |
| Sign-in history | 365 days |
| Server application and security logs | 400 days, so an incident can be investigated for at least a year (DPDP Rules r.6) |
| Console audit log | 365 days |
| In-app notifications | 90 days |
| Mail delivery log | 90 days |
| Demo requests that did not become customers | 365 days |
| Public-site statistics / rate counters | 90 / 14 days |
| Visitor traffic / security events (section 3) | 14 / 90 days, or shorter per company |
| Rights requests and grievances | 3 years after they are closed |
| Data-export download files | 48 hours |
| Tax invoices | 8 years (Indian tax law), even after the company is deleted |
| Deleted sites | 30 days, then all their data is erased |
Backups roll over on their own cycle; erased data disappears from them when they expire.
7. How we protect it
TLS everywhere with HSTS; passwords hashed with bcrypt and API tokens stored only as hashes; two-factor secrets, agent secrets, repository tokens and webhook addresses encrypted at rest; two-factor authentication and passkeys; role-based access with per-company isolation; rate limits and lockouts on sign-in; security events logged and alerted; strict browser security headers. Our security page has more, including how to report a vulnerability.
If a personal-data breach happens, we inform the Data Protection Board of India and the people affected without delay, and send the Board a detailed report within 72 hours (DPDP Rules r.7). Customers are told without undue delay about anything affecting their visitors' data.
8. Your rights, and how to use them
- Access — a summary and a full copy of your data: Settings → Privacy & data → Email me a download link (machine-readable JSON, which also serves portability).
- Correction and completion — your profile is editable in Settings; ask us for anything else.
- Erasure — delete your account, or (owners) your whole company, from Settings → Privacy & data.
- Withdraw consent — the same toggles that gave it. Withdrawal does not affect what was done before.
- Objection and restriction (GDPR) — send a request.
- Nomination — name someone to act for you if you die or become unable to (DPDP s.14): Settings → Privacy & data → Nominee.
- Grievance redressal — write to our Grievance Officer.
We answer requests within 30 days and grievances within 30 days. We may need to confirm it is you first. If you are not satisfied with our answer, you may complain to the Data Protection Board of India, or, in the EU/UK, to your data protection authority.
9. Children
ServerPulse is a business service for adults. Accounts are for people aged 18 or over, and we do not knowingly process personal data of children. If we learn an account belongs to a child, we close it and erase its data. Customers whose own sites are used by children are responsible for the consents their sites need.
10. Cookies
This website and the console use two strictly necessary cookies (your session and a security token) and remember your light/dark choice in your browser. No analytics or advertising cookies, no third-party scripts or fonts. See the cookie notice.
11. Changes to this notice
When this notice changes, the date at the top changes. If a change is material, company owners are emailed before it takes effect, and where a change needs your consent we ask for it.
12. Contact
Cruzetec Solutions, Mohali (SAS Nagar), Punjab, India · privacy@dxcslabs.com · Grievance Officer: grievance@dxcslabs.com