RoomPulse · Data protection information · v1.0
RoomPulse is the live participation app built and operated by AIM Learning Solutions. It runs polls, timers, team challenges and shared walls during an event, on the phone already in your pocket. This page holds every privacy, retention and security document that applies to it.
We built RoomPulse because the tools we were using put our clients' data on platforms outside the EU, under terms we could not change and a supply chain we could not see. This one we run ourselves. That is why the list below is short, and why we can put it in writing.
Version 1.0, issued 10 August 2026 and effective for events from 15 September 2026. This statement describes RoomPulse as delivered from that date.
Every document governing how RoomPulse handles personal data. Each is versioned and dated, and the reference is stable so it can be cited in a contract or a processing record.
| Ref. | Document | Section | Version | Updated |
|---|---|---|---|---|
| RP-PS-01 | Privacy StatementWhat is collected, why, for how long, and your rights. Shown to participants before they join. | 2 | 1.0 | 10 Aug 2026 |
| RP-TOM-01 | Technical and Organisational MeasuresThe security controls protecting personal data, as required by Article 32 GDPR. | 3 | 1.0 | 10 Aug 2026 |
| RP-RET-01 | Retention and Deletion PolicyRetention options, the automated purge, and the deletion certificate issued afterwards. | 2.4 | 1.0 | 10 Aug 2026 |
| RP-RES-01 | Data Residency and Sub-processorsWhere data is stored and processed, and every third party involved. | 4 | 1.0 | 10 Aug 2026 |
| RP-CK-01 | Cookie NoticeThe one cookie RoomPulse sets, and what it is for. | 5 | 1.0 | 10 Aug 2026 |
| RP-IC-01 | Questions We Are Often AskedAnswers to the data protection questions organisations put to us before approving the app for an event. | 6 | 1.0 | 10 Aug 2026 |
| RP-ROPA-01 | Record of Processing ActivitiesOur Article 30(2) processor record, published here in full, not held back for a request. | 7 | 1.0 | 10 Aug 2026 |
| RP-DPA-01 | Data Processing AgreementSend us your template and we will sign it. If you would rather we supplied one, we can. Either way the annexes are already written: the description of processing is section 7, the security measures section 3, the sub-processor list section 4.2. | 7, 3, 4.2 | On request | n/a |
A facilitator builds a running order before the event. During it, they push one activity at a time to everyone's phone. Participants join by scanning a QR code or typing a short code. There is no account, no app store download and no password.
Most live-participation tools cover the first group below. RoomPulse covers all six, because an away day is not a webinar: people move, form teams, go outdoors, make things, and meet colleagues they have never worked with. The app has to follow them.
Every one of those is configured per session by the facilitator rather than hard-coded, so the same app runs a twenty-person workshop in one meeting room and an event of several hundred spread across a whole venue, indoors or out.
For each event, the organisation that commissioned it decides what is collected and why. They are the controller. AIM Learning Solutions runs the app on their instructions, which makes us the processor. Both are named in the privacy notice shown on your phone before you join.
DOCRP-PS-01
Written for participants. If you are joining an event on your phone, this is what happens to what you type, tap and photograph.
The organisation running your event (your employer, your agency, or the body that invited you) decides what the app collects and why. Under data protection law they are the controller. AIM Learning Solutions provides and operates RoomPulse on their written instructions, which makes us the processor. We do not use anything collected during your event for our own purposes, and we never sell or share it.
Where your event is run by an institution, body, office or agency of the European Union, the controller's obligations arise under Regulation (EU) 2018/1725 and their supervisory authority is the European Data Protection Supervisor. Our own obligations as a Belgian processor arise under the GDPR (Regulation (EU) 2016/679). The two are aligned, and the practical protections described below are the same either way.
How you are identified is chosen by the organiser before the event, and stated on the notice you see before you join. Anonymous is the default for new sessions.
| Identity mode | What identifies you | Typical use |
|---|---|---|
| Anonymous (default) | Nothing. A random token in your browser tells one device from another so you are not asked the same question twice. It is not linked to you and is discarded with everything else. | Feedback, sensitive topics, large plenaries |
| First name | A first name you type yourself. You may type anything. | Smaller workshops where a facilitator addresses people by name |
| Nickname | A display name you choose. | Games and scoreboards |
| Roster | Your name and organisational unit, imported in advance by the organiser. | Events where who-met-whom is part of the exercise |
In addition, depending on which activities the facilitator runs:
| Category | Detail |
|---|---|
| Your answers | Choices in a poll, ratings, rankings, words for a word cloud, free text you write, questions you post and votes you give them. |
| Photographs (only if enabled) | Off unless the organiser switches photo challenges on for the event. Where they are on, only where a challenge asks for one, and only if you have agreed. See section 2.3. |
| Team and progress | Which team you were put in, which challenges it completed, the score, and the time of each submission. |
| Technical | One functional cookie holding a signed session token. Your IP address and browser type also appear in the runtime logs our hosting provider keeps in order to deliver the page and limit abuse. Those logs are held by that provider for one hour, are not readable by the app, and are never written to our database. |
| Not collected | No email address. No account or password. No location. No device fingerprinting. No analytics or advertising identifiers. No contacts, no microphone, no background access to your phone. |
This section applies only if the organiser has enabled photo challenges for your event. Photography is off unless it is deliberately switched on, and many events never use it. If it is off, the app cannot access your camera at all and nothing below applies to you.
Where it is on, some team challenges ask a team to photograph something: an object, a scene, or the team itself. A photograph of a person is personal data, and a group photo is personal data about everyone in it. We treat it accordingly.
DOCRP-RET-01
Retention is set per event by the organiser and shown on the notice before you join. The options are deliberately short, and the shortest is the default.
| Setting | What happens |
|---|---|
| Immediate (default) | All participant data, including any photographs, is permanently deleted as soon as the facilitator closes the session, typically within minutes of the event ending. |
| 24 hours / 7 days / 30 days | Chosen only where the organiser needs the raw responses to write up the event. Deletion then happens automatically at the end of that period. |
Deletion is carried out by an automated task running every five minutes inside the database itself, so it does not depend on anyone remembering. A separate daily watchdog, running on independent infrastructure, checks that no deletion is overdue and raises an alarm if the task ever falls behind. Afterwards the system re-counts every table to confirm nothing is left, and issues a deletion certificate recording what was deleted and when. An administrator can also trigger the full deletion immediately at any point after an event ends, and can export or erase a single participant's data on request during one.
What is kept afterwards is anonymous summary only. For example, "62 of 88 people chose option B", or a team's total score. Where a future activity type summarises words people typed, rare answers will be suppressed before the summary is kept, so an unusual response cannot be traced back to one person. Free text is never kept. The event's written report is generated at the end and handed to the organiser. From that moment they hold it, and it is governed by their retention rules, not ours.
To run the session you are taking part in: to show the facilitator how the room is responding, to give you your timer and your team's challenges, and to produce a summary for the organiser. The legal basis is set by the controller and named in the notice you see before joining. For EU bodies it is normally the performance of a task carried out in the public interest. Where the controller relies on consent for photographs, this is how we implement it: you are asked separately from joining, and refusing costs you nothing, so the choice is a real one. Participation in any activity is voluntary. You can skip a question or close the page at any time.
You may ask for access to your data, correction, erasure, restriction of processing, or object to it. Because retention is usually immediate, the fastest route during an event is to tell the facilitator. They can delete your responses on the spot, and the change takes effect at once. Otherwise contact the organiser as controller, or us at dpo@aim-associes.com and we will pass it on.
You also have the right to complain to a supervisory authority. That is the European Data Protection Supervisor where the controller is an EU body, and your national authority otherwise. In Belgium that is the Autorité de protection des données / Gegevensbeschermingsautoriteit.
If a personal data breach occurs, we notify the controller without undue delay so they can meet their own notification deadlines, and we support their assessment.
DOCRP-TOM-01
The controls protecting personal data processed through RoomPulse, appropriate to the risk of a short-lived event application handling responses and photographs. Required by Article 32 GDPR.
DOCRP-RES-01
All personal data processed through RoomPulse is stored and processed in the European Union. There is no transfer to a third country in normal operation.
Every component is pinned to an EU region. Participants receive no email. The application makes no requests to third-party services from a participant's browser, so no data leaves the EEA by that route either.
Storage is contractual. Our database provider's terms commit that where a customer directs processing in a specific geographical region, the data is stored and primarily processed in that region. We have directed Frankfurt. Every participant record, every uploaded photograph and every account lives there, so for the data itself, EU residency is a contractual obligation, not a preference.
Compute is configuration, and we would rather tell you than have you read it in their terms. Our hosting provider's agreement states that its primary processing facilities are in the United States and permits processing elsewhere in the world, relying on the Standard Contractual Clauses. We pin every function to that provider's Frankfurt region, so requests execute in Germany. That is our configuration, not their guarantee.
What limits the exposure is that this provider stores nothing. It holds no database and no files. Personal data passes through it only in transit, for the moment it takes to serve a request, and is written only to the database in Frankfurt.
The exception worth naming is logs. Serving a request produces a runtime log entry containing the IP address and browser type, held by that provider and not by us. Retention is one hour, we do not enable the extended observability tier, and we send logs to no third party. If the distinction matters to your assessment, raise it early: the application is portable and we can host it elsewhere.
One limitation we would rather state than have you discover. Our hosting provider's published data processing addendum applies to its paid plans; we are on its free tier, so that addendum does not currently cover us. We therefore have no separate processor agreement with the host — unlike the database and email providers below, whose terms do apply. This is a contractual gap, not a technical one: the residency configuration, the Frankfurt pin and the one-hour log retention described above are all in force regardless. If your assessment requires a processor agreement covering compute, tell us and we will move to a plan or a provider that gives you one.
We engage three sub-processors directly. Their published terms are linked below so you can read them without asking us for a copy; the database and email providers' terms incorporate the European Commission's Standard Contractual Clauses and apply to us, while the hosting provider's addendum does not cover its free tier — see the note in section 4.1. Links open on the provider's own site and pass no referrer.
| Sub-processor | Purpose | Location of processing | Their terms |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Frankfurt, Germany (eu-central-1) | Data Processing Addendum |
| Vercel | Application hosting and delivery | Frankfurt, Germany (fra1) | Data Processing Agreement |
| Brevo | Invitation and notification email to AIM staff only, never to participants | European Union | Terms of Use, Appendix 3 |
Three is the number we engage. Each of them engages others in turn, which is normal and lawful under Article 28(4), and the chain is worth showing you in full.
Supabase publishes a list of around two dozen, most of which support their own helpdesk, billing and monitoring, not customer databases. The ones that host infrastructure are Amazon Web Services, Google, Cloudflare, Fly.io and Upstash. Their list also names OpenAI, for natural language features in their own product. RoomPulse uses no Supabase AI feature, and no participant data is sent to any model. Vercel's list covers Amazon Web Services, Google, Microsoft, Datadog and Honeycomb, plus several providers used only for AI features we do not enable.
Both publish their current list and let you subscribe to changes: Supabase sub-processors and Vercel Trust Center. We review both when they change, and a client can be notified of anything material before their event.
Supabase Inc. and Vercel Inc. are incorporated in the United States, and the infrastructure we use from them is in Germany. Both build the European Commission's Standard Contractual Clauses into their terms automatically, with no separate signature: Supabase applies Modules Two and Three, Vercel applies Modules One, Two and Three together with the UK addendum.
The two are not equivalent on residency, and the difference is worth stating. Supabase commits contractually to the region a customer directs. Vercel's agreement records that its primary processing facilities are in the United States and reserves the right to process elsewhere. Our compute runs in Frankfurt because we configured it to, and because Vercel stores no participant data at any point, but we are not going to describe that as a contractual guarantee when it is not.
Our email provider, Brevo, reaches AIM staff only and never participants. Their terms note that they may rely on the EU-US Data Privacy Framework for transfers to the United States. No participant data is ever sent to them.
We consider the residual risk low and appropriately mitigated. We do not claim it is nil.
Where a client requires infrastructure with no non-EU corporate parent, RoomPulse is built to be portable. It uses standard PostgreSQL and no proprietary lock-in beyond authentication and live messaging. A migration path to EU-sovereign hosting is documented and can be executed on request.
DOCRP-CK-01
RoomPulse sets one cookie. It is strictly necessary to deliver the service you asked for, so no consent banner is required. There is nothing to consent to in any case, because there is nothing else.
| Cookie | Purpose | Expires |
|---|---|---|
| Session token | Signed and HTTP-only. Identifies your device to the event you joined so your answers are yours and you are not asked a question twice. Contains no name and is not readable by scripts. | When the event's data is deleted, and in any case within 24 hours |
| Everything else | No advertising, analytics, tracking or profiling cookies are set, by us or by anyone else. There are no third-party scripts on the page that could set one. | n/a |
Facilitators, who do have accounts, also have an authentication cookie for as long as they stay signed in.
DOCRP-IC-01
These are the questions public and private organisations put to us most often before approving RoomPulse for an event. If yours is not here, write to us at dpo@aim-associes.com and we will answer it properly. Send us your own data processing agreement and we will sign it. If you would rather we supplied one, we can do that too, and it can sit as an annexe to an existing framework contract.
RoomPulse, developed and operated by AIM & Associés SRL, also referred to as AIM Learning Solutions, in Brussels. It is our own application, not a resold third-party product, so we can configure it around your requirements instead of asking you to accept it as given.
The privacy statement is section 2 of this document, reference RP-PS-01. Our Article 30 record of processing is section 7, published in full. A notice specific to your event is also shown to every participant before they submit anything. It names you as controller and states that event's identity mode and retention period.
That is up to you, and it is minimised by default. New events are set to fully anonymous: no name, no email, no account, no location. Participants are distinguished only by a random device token that is discarded on deletion.
Where an event uses them, the additional categories are a first name or nickname the participant types, or name and organisational unit if you supply a roster. Beyond identity, the app records the participant's own answers (choices, ratings, rankings, free text, posted questions), team membership and progress, and submission timestamps.
Photographs are collected only if you ask for them. They are off by default, and an event can run its full programme without ever enabling them. Where you do want a challenge that needs one, they are the most sensitive category we handle and they are treated separately: consent is asked for on its own, refusal carries no disadvantage, camera metadata including GPS coordinates is stripped before storage, images are held privately with expiring access links, and no facial recognition or image analysis is performed at any point.
As short as you want, and by default no time at all. For an event like yours we would set retention to Immediate: all participant data is permanently deleted when the facilitator closes the session, normally within minutes of the event ending. That covers responses, free text, team records, and any photographs if your event used them. Longer options exist (24 hours, 7 or 30 days) for clients who need the raw material to write up the day. They are never required, and never longer than 30 days.
Deletion is automated, running inside the database every five minutes, so it does not depend on a person remembering or on an external scheduler being available. It is verified by re-counting every table containing personal data and confirming the result is zero — inside the same transaction, so a deletion that leaves anything behind cannot be reported as complete. We then issue you a deletion certificate recording what was deleted, when, by which process, and the verification result, protected by a SHA-256 fingerprint of its contents and published at a private link you can open without an account, at any later date.
What remains afterwards is anonymous aggregate only: counts, distributions and team totals. Where a summary would be built from typed words, rare responses are suppressed before it is kept, so no answer can be traced to an individual. Free text is never retained. Your event report is generated at the end of the day and handed to you. From that point it is under your control and your retention rules.
No participant data is stored outside the EEA, and none is transferred there in normal operation. Every record, response and photograph is held in Frankfurt, Germany. Application compute is pinned to Frankfurt as well. Participants receive no email at all, and the app makes no requests to third-party services from a participant's browser, so no analytics, tag manager or externally hosted font carries anything to a third country by the back door.
Two points of completeness, since you would find both if you looked. First, our providers Supabase and Vercel are US-incorporated companies operating EU regions, with the Standard Contractual Clauses built into their terms. Second, and more precisely: only our database provider commits contractually to the region we direct. Our hosting provider's agreement records US primary facilities and permits processing elsewhere, so we pin compute to Frankfurt by configuration, and that provider stores no participant data at any point. Section 4.3 sets this out in full.
If your organisation requires infrastructure with no non-EU corporate parent, or a contractual rather than configured residency commitment for compute, tell us during preparation. The application is portable and we can move it.
Section 3 sets them out in full, reference RP-TOM-01. The short version: TLS 1.2+ in transit and AES-256 at rest; deny-by-default row-level security on every table, with the public application key holding no database privileges at all; participants never connect to the database and never appear as an identifier in a web address; invitation-only staff accounts with 12-character minimum passwords and role-based access scoped to individual events; privileged actions checked independently at three layers; private image storage with expiring access links and metadata stripped before upload and verified on arrival; automated, verified deletion with a fingerprinted certificate; and no analytics, trackers or third-party scripts anywhere in the participant experience.
We also run load and resilience testing before large events.
DOCRP-ROPA-01
The record we are required to keep as a processor under Article 30(2) GDPR. Most providers hand this over only when asked. It is a statement of fact, not a negotiation, so we publish it.
| Article 30(2) requirement | Our entry |
|---|---|
| Processor | AIM & Associés SRL (also referred to as AIM Learning Solutions). Enterprise number 0864.046.009. Avenue de Tervueren 36A, 1040 Brussels, Belgium. dpo@aim-associes.com |
| Controllers | The organisation commissioning each event. Named individually in that event's processing agreement and on the participant notice. |
| Data protection contact | dpo@aim-associes.com, a monitored function mailbox held by the AIM management team and routed to whoever can answer: the Digital Manager, the Security Officer, or the IT team. |
| Categories of processing | Collection, display, aggregation, temporary storage and erasure of participant contributions during a live event, carried out solely on the controller's documented instructions. |
| Categories of data subjects | Participants at an event run by the controller, and the controller's own staff who operate the app as facilitators. |
| Categories of personal data | Participants: a random device token, and where the controller enables it a first name, nickname, or name and organisational unit from a roster. Contributions: poll choices, ratings, rankings, free text, posted questions and votes, team membership, progress and scores, submission timestamps, and, only where the organiser has enabled photo challenges, photographs taken by participants who have consented. Facilitators: name, work email, role. No special categories are collected by design. |
| Recipients | The controller. The sub-processors listed in section 4.2. No one else. Nothing is sold, shared or used for our own purposes. |
| Third-country transfers | None. All processing takes place in the European Union. See section 4.3 for our position on the corporate nationality of our providers. |
| Retention | Set per event by the controller: immediate on session close (the default), or 24 hours, 7 days or 30 days. Enforced by an automated task and evidenced by a deletion certificate. See section 2.4. |
| Security measures | As set out in full in section 3. |
This record is maintained alongside the application. It is reviewed whenever a new activity type, sub-processor or retention option is introduced, and it carries the same version number as this page.
Data protection questions go to one monitored address, and from there to the person who can answer: the Digital Manager for how the app is built, the Security Officer for controls, the IT team for infrastructure. Nothing waits for whoever happens to pick up the message.
The reason we can answer quickly is that the data protection decisions in this app are architectural, not procedural. Anonymous by default, deletion running inside the database, no participant identifier in a web address, camera metadata stripped on upload. None of those could have been added afterwards by someone reviewing a finished product. They exist because the people accountable for data protection were in the design, alongside the facilitation and engineering choices.
If your assessment needs our position on Data Protection Officer designation, ask and we will confirm it in writing.
If you took part in an event and want to know what was held about you, or want it deleted, the fastest route is to ask the facilitator during the event. It is done immediately. Otherwise write to us and we will act on the controller's instruction.
dpo@aim-associes.com
AIM & Associés SRL, enterprise number 0864.046.009
Avenue de Tervueren 36A, 1040 Brussels, Belgium
A monitored mailbox held by the AIM management team, routed to whoever can answer: the Digital Manager, the Security Officer, or the IT team. If you are a controller's data protection officer and would prefer to speak, say so and we will arrange a call.
Our record of processing activities is section 7 of this document, so there is nothing to request. For a data processing agreement, send us your template and we will sign it, or ask and we will supply one. We can also complete a security questionnaire in your own format or contribute to a data protection impact assessment.