Back to sign in

Privacy Policy

How Pulse Health collects, uses, and protects information in the facility workspace.

Last updated Sep 1, 2026

1.Who this policy covers

Pulse Health provides queue management, scheduling, and clinical record-keeping software to healthcare facilities. This policy covers two groups of people: the facility staff who sign in to a Pulse workspace, and the patients whose records a facility keeps in Pulse.

For patient and clinical information, the facility is the data controller and Pulse acts as its processor: the facility decides what is recorded and why, and we handle that information only on its instructions. For staff account information, Pulse is the controller.

2.Information we collect

  • Staff account information — name, work email, phone number, role, title, department, and profile photo, provided by the facility or by the staff member during account activation.
  • Facility information — facility name, logo, region, physical address, and the licensing or verification documents submitted when access is requested.
  • Patient and clinical information — patient demographics and contact details, appointments, queue activity, and clinician-authored records such as visit notes, prescriptions, and laboratory results entered or uploaded by the facility.
  • Authentication information — password hashes, verification codes, trusted-device markers, and active session records.
  • Technical information — log data, IP address, browser and device type, and timestamps generated when the workspace is used.

3.How we use information

  • To operate the workspace: authenticating staff, running queues and appointments, and storing the records a facility creates.
  • To send operational messages such as verification codes, appointment notifications, and account or security notices.
  • To secure the service: detecting unauthorized access, investigating abuse, and maintaining audit trails.
  • To support facilities that contact us, and to diagnose faults they report.
  • To improve reliability and performance using aggregated, non-identifying usage measurements.

4.Clinical content

Pulse faithfully records and displays what clinicians write. It does not generate diagnoses, treatment recommendations, triage decisions, or any other clinical advice, and it does not alter clinician-authored content.

Clinical judgement remains entirely with the treating clinician and the facility. Records shown in Pulse reflect what facility staff entered; they are not an independent clinical assessment.

5.How information is shared

We do not sell personal information, and we do not use patient or clinical information for advertising.

  • Within your facility — staff see information according to the role and permissions the facility administrator assigns.
  • Never between facilities — each facility's data is isolated, and one facility can never see another facility's patients, staff, or records.
  • Service providers — vetted infrastructure, hosting, email, and messaging providers who process information on our behalf under contract, and only as needed to run the service.
  • Legal requirements — where disclosure is required by law, regulation, or valid legal process, or to protect the safety of a person.

6.Isolation and internal access

Every record in Pulse belongs to exactly one facility, and that boundary is enforced by our servers on every request rather than by the interface alone.

Pulse platform staff administer facility accounts using facility-level metadata such as name, licensing status, plan, and user counts. They cannot browse patient or clinical records, and they cannot sign in as one of your users. Access by our personnel for support or maintenance is limited to what the task requires, logged, and available to the facility on request.

7.Data retention

We keep information for as long as the facility's workspace is active and it is needed for the purposes described above.

When an account is closed or a deletion request is made, data is held for 90 days under the facility data-retention policy before permanent removal. Nothing is deleted immediately, which gives a facility time to reverse an accidental request. We may retain records for longer where a law, a regulator, or the facility's own medical-records obligations require it.

8.Security

Information is encrypted in transit. Access is protected by per-account passwords, verification codes on new or unrecognized devices, role-based permissions, and session controls that let staff review and revoke active sessions.

No system is perfectly secure. If a breach affects your information, we will notify the affected facility and the relevant authorities as required by law.

9.Your rights and choices

Staff can review and update their own profile details from the workspace, and can revoke active sessions at any time.

Patients should direct requests to access, correct, or delete their records to the facility that treats them: the facility holds those records and decides how they are handled. When a facility asks us to act on such a request, we support it.

10.Children

Pulse is not offered directly to children. Where a facility keeps records for a minor patient, those records are created and managed by the facility under its own consent and guardianship arrangements.

11.Changes to this policy

We may update this policy as the service changes. The date at the top of this page shows when it was last revised, and material changes will be communicated to facility administrators before they take effect.

12.Contact us

Questions about this policy, or about how a facility handles information in Pulse, can be sent to privacy@pulsehealth.example. Patients should contact their facility first.

Questions about this document? Contact support