Privacy Policy

Effective 13 August 2026 · Last updated 13 August 2026

1. About this policy

ebs Pulse is a private, work-only platform operated by ebs Chartered Accountants (EBSCA Accountants LLC) (“ebs”, “we”, “us”, “our”) for accounting and professional-services teams. This policy explains what personal information we handle when you use ebs Pulse, why we handle it, and the choices you have.

ebs Pulse is used only by people whose organisation has an account and who have been invited by an administrator. There is no public sign-up. It is a business tool for staff — it is not a consumer product and is not intended for use by children.

If you have any questions about this policy, contact us at info@ebs.ae.

2. Two different kinds of information

It helps to separate two things ebs Pulse deals with:

  • Your information — the personal details tied to you as a user: your name, work email, your sign-in and security records, and so on. This policy is mainly about this.
  • Your organisation’s working data — the client and business records that your firm enters into ebs Pulse to do its work (for example, a client’s legal name, trade licence number, tax registration number, contacts, tasks and deadlines). Your organisation decides what goes into these records and is responsible for them. ebs Pulse holds and processes this data on your organisation’s behalf and under its instructions. If you are a client of a firm that uses ebs Pulse and want to know how your data is handled, please contact that firm directly.

3. Information we collect

Account and profile details. When an administrator creates your account, we hold your full name, work email address, and — if provided — your phone number and a profile photo. We also hold your role, which teams and organisation you belong to, and your reporting manager.

Sign-in credentials and security settings. If you sign in with a password, that password is stored in a securely hashed form by our authentication provider — we never see or store it in plain text. If you turn on two-factor authentication, we store the secret needed to verify your one-time codes. If you sign in with Microsoft or Google (see section 5), we store the identity link those providers give us, not your Microsoft or Google password.

Sign-in and session records.Each time you sign in, we record technical details of the session so you and your administrators can see and manage active logins: the IP address you connected from, your browser and device information (the “user-agent”), and the times the session started and was last active. You can view your own active sessions in Profile → Security and sign out of any of them.

Approximate location.To help you recognise your own sessions, we show an approximate location (for example, “near Dubai, United Arab Emirates”) worked out from the session’s IP address. To do this we send only the IP address to a location-lookup service (ipwho.is) and receive back an approximate city and country. The result is city-level and approximate, not a precise location, and we do not always get one.

Photos and logos you upload. Profile photos and organisation logos you upload are stored privately and are only shown to people within your organisation who are allowed to see them.

Activity and audit records. To keep the system secure and accountable, we keep an audit log of meaningful actions taken in the platform — for example who created or changed a record, completed a task stage, exported data, or signed in and out. Each entry records who did it, their role at the time, what was done, when, and the IP address it came from. Audit records are kept as a tamper-evident history and cannot be edited after the fact.

Error and diagnostic reports. If something goes wrong in the app, we send a technical error report to our monitoring service (Sentry) so we can find and fix the problem. These reports are automatically scrubbed to remove personal and sensitive data before they are sent — we strip out things like email addresses, tokens, cookies, request contents and passwords, and keep only an anonymous account identifier so we can correlate an error to a session without exposing who you are.

Emails we send you. We send service emails needed to run your account — for example your invitation to join, password-reset links, and email-address confirmations. These are delivered through our email provider (Resend).

4. How we use your information

We use the information above to:

  • create and manage your account and control what you can see and do based on your role;
  • authenticate you securely, including two-factor authentication where enabled;
  • let you and your administrators see and manage active sign-ins, and detect or investigate suspicious activity;
  • keep an accurate audit trail for security, accountability and compliance;
  • operate, maintain, monitor and improve the reliability of the platform, including diagnosing errors;
  • send you the service emails needed to run your account; and
  • meet our legal, regulatory and professional obligations.

We do not sell your personal information, and we do not use it for advertising.

5. Signing in with Microsoft or Google

You may be able to sign in using a Microsoft or Google account. When you do, that provider confirms your identity to us and tells us the account you signed in with so we can match it to your invited ebs Pulse account. We do not receive your Microsoft or Google password. Your use of Microsoft or Google is also governed by their own privacy policies. Because ebs Pulse is invitation-only, signing in with Microsoft or Google only works if your email has already been invited by an administrator.

6. Who we share information with

We do not sell your data. We share it only in these situations:

  • Within your organisation. Colleagues and administrators in your organisation can see information appropriate to their role — for example your name and profile, and the activity and records you create.
  • Service providers who help us run the platform. We use a small number of trusted providers to host and operate ebs Pulse. They process data only to provide their service to us and under agreements that require them to protect it:
    • Supabase — database, authentication and file storage (holds your account, security and working data);
    • Vercel — application hosting;
    • Sentry — error monitoring (receives the scrubbed diagnostic reports described above);
    • Resend — delivery of service emails;
    • ipwho.is — approximate location lookup from an IP address;
    • Microsoft and Google — sign-in, if you choose to use them.
  • Legal and safety reasons. We may disclose information where we are required to by law or regulation, or to protect the rights, safety or property of ebs, our users, or others.

7. Where your data is held and international transfers

ebs Pulse is operated from the United Arab Emirates, but some of our service providers host and process data outside the UAE. In particular, our database, authentication and uploaded files are stored with Supabase in a data centre in Mumbai, India. Our application hosting (Vercel), error monitoring (Sentry) and email delivery (Resend) run on globally distributed infrastructure and may process data in other countries. This means your information may be transferred to and stored outside the UAE. Where it is, we rely on the protections built into our agreements with those providers to keep it safe and to handle it consistently with this policy.

8. How long we keep information

  • We keep your account and profile data for as long as your account is active. When an account is deactivated, we retain the record where needed for audit, legal or professional-compliance reasons rather than deleting it immediately.
  • Audit records are kept as a history for security and compliance; recent records are readily available in the app and older records are retained in line with our retention practices.
  • Session records are kept while a session is valid and are removed by the authentication system once a session expires or is revoked.
  • Error reports are retained by our monitoring provider for a limited period to help us diagnose issues.

When we no longer need personal information, we delete it or keep it only in a form that no longer identifies you.

9. How we protect your information

We take security seriously and use measures appropriate to the sensitivity of the data, including: role-based access controls and row-level security so people only see what they are permitted to; encryption of data in transit; hashed passwords and optional two-factor authentication; private storage for uploaded photos and logos; scrubbing of sensitive data from error reports; and an audit trail of significant actions. No system can be guaranteed completely secure, but we work to protect your information and to respond appropriately if a problem occurs.

10. Your choices and rights

Depending on your situation and applicable law, you may have the right to ask us to access, correct, or delete personal information about you, or to object to or restrict certain uses. You can update much of your own profile directly in the app. For anything else, or to make a request, contact us at info@ebs.ae or speak to your organisation’s administrator. Because many records are held on behalf of your organisation, we may need to direct some requests to them.

If you sign in with a password, you can change it at any time; if you enable two-factor authentication, you can manage it in your security settings.

11. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, let you know within the app. Continuing to use ebs Pulse after a change means you accept the updated policy.

12. Contact us

If you have questions, concerns, or requests about this policy or your personal information, contact:

EBSCA Accountants LLC
Office 803, Metropolis Tower, Al Abraj Street, Business Bay, Dubai, UAE, PO Box 94091
info@ebs.ae