Privacy Policy
Last updated: 8 September 2026
This Privacy Policy explains how Decimo (“the Service”), operated by PulsePages (“we”, “us”), collects, uses, and protects personal information. We handle personal information in line with South Africa’s Protection of Personal Information Act (POPIA). If you connect services governed by other frameworks (such as the GDPR), those protections may also apply.
1. Who is responsible for your data
For the account information you give us to run the Service, we act as the responsible party (data controller). For the client and business data you enter into your workspace (“Your Data”), you are the responsible party and we act as an operator (processor) handling it on your instructions.
2. Information we collect
Information you provide
- Account details — your name, email address, and password (stored only as a secure hash).
- Your Data — the clients, conversations, meetings, tasks, income, expenses, invoices, and business/profile details you enter to use the Service.
- Billing details — handled by our payment provider; see “How we share information” below.
Information collected automatically
- basic technical and usage data needed to operate the Service securely, such as log data and timestamps;
- essential cookies or local storage used to keep you signed in. We do not use third-party advertising trackers.
Information from services you connect
If you choose to connect a third-party account, we access only what is needed for the feature you enable, using tokens you can revoke at any time:
- Google / Gmail — to send invoices and communications from your own email address and to sync relevant messages, at your direction. We request the narrowest permissions required and do not use Google user data for any purpose other than providing the features you enable.
- Meeting transcription providers — to import meeting summaries and transcripts you ask to bring in.
3. How we use information
- to provide, maintain, and secure the Service;
- to authenticate you and send essential account emails (verification, password reset, billing);
- to process subscriptions and prevent fraud and abuse;
- to respond to support requests;
- to comply with legal obligations.
We do not sell your personal information, and we do not use Your Data to build advertising profiles.
4. How we share information
We share information only with service providers who help us run the Service, under contracts that require them to protect it:
- Paddle — our payment provider and Merchant of Record, which processes payments and handles billing details. We do not store your full card number.
- Email delivery provider — used to send essential account emails such as verification and password-reset messages.
- Hosting and infrastructure provider — where the Service and its databases are hosted.
- Services you connect — data flows to and from Google or a transcription provider only as you direct.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the Service.
5. Where your data is stored
Your Data is stored in an isolated per-account database on our hosting infrastructure. Some of our service providers may process data outside South Africa; where that happens, we take reasonable steps so that your information continues to receive an adequate level of protection as required by POPIA.
6. Data retention
We keep Your Data for as long as your account is active. If you close your account, we retain it for a limited period so you can reactivate or export it, after which it is deleted or anonymised, except where we must keep certain records (for example billing records) to meet legal obligations. You can export or request deletion of Your Data at any time.
7. Security
We use reasonable technical and organisational measures to protect personal information, including encryption in transit, hashed passwords, per-account database isolation, and access controls. No system is perfectly secure, but we work to protect your information and to notify affected users and the Information Regulator of any breach as required by law.
8. Your rights
Under POPIA (and comparable laws), you may:
- access the personal information we hold about you;
- correct or update inaccurate information;
- request deletion of your information, subject to legal retention requirements;
- object to certain processing;
- export Your Data in a usable format;
- lodge a complaint with the Information Regulator of South Africa.
Much of this you can do yourself in the app. For anything else, contact us using the details below.
9. Children
The Service is intended for use by adults in a business context and is not directed at children. We do not knowingly collect personal information from anyone under 18.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you. The “Last updated” date at the top shows when it was last revised.
11. Contact
For privacy questions or to exercise your rights, contact us at support@maarsch.net.