Personal Data Processing Policy
Version: pulse-privacy-2026-07-17. Effective July 17, 2026.
Data controller: the owner of the Pulse service. The controller's full legal details are specified in the agreement, invoice, or other document under which the client connects to the service.
Personal data contact: Privacy team.
1. Data we process
- the client's email address and, for legacy accounts, phone number; client or workspace name, hashed password, and technical client session;
- project names, goals, tasks, feedback, and trusted email domain and address settings;
- work messages, files, links, notes, summaries, meeting transcripts, and derived AI reports when the client connects these sources;
- technical data such as consent date, policy version, IP address, user agent, and audit events.
2. Purposes of processing
- registration and access to the Pulse client workspace;
- management of projects, goals, tasks, meetings, and daily summaries;
- analysis of work context to identify risks, blockers, decisions, and next actions;
- client support, service security, activity tracking, and compliance with legal requirements.
3. Legal basis
Processing is based on the data subject's consent, the agreement with the client, the controller's legitimate interest in maintaining service security, and applicable legal requirements.
4. Consent to processing
By registering, the user confirms that they have read this policy and consent to the processing of personal data for the operation of Pulse. The system records the policy version, date, source, IP address, and user agent as evidence of consent.
5. Data sharing and processors
To operate the product, data may be shared with technical providers supporting Chats, Video, Task trackers, AI analysis, transcription, hosting, logging, and infrastructure. The controller limits transfers to the purposes required to operate the service and governs these relationships through an agreement or another lawful basis.
6. Cross-border transfers and localization
Use of international services may involve cross-border data transfers. Where applicable, the initial collection, systematization, accumulation, and storage of personal data belonging to Russian citizens must comply with Federal Law No. 152-FZ and its requirements concerning databases located in the Russian Federation.
7. Retention periods
Data is retained while the client account exists, the agreement remains in force, or the data is needed for the stated purposes. Work messages, transcripts, AI reports, and audit events are deleted or anonymized after those purposes are fulfilled, the agreement ends, or a valid data subject request is received, unless a longer retention period is required by law.
8. Data subject rights
Users may request access to, correction, export, or deletion of their data, restriction of processing, or withdrawal of consent. Requests can be submitted through Settings in the client workspace or by contacting the Privacy team.
9. Security measures
- access to the administration workspace is restricted by administrator credentials;
- client passwords are stored as cryptographic hashes;
- client data is separated by workspace;
- a basic record of consents, requests, and data-related actions is maintained;
- tokens, API keys, backups, and server files are stored in protected infrastructure with access controls.
10. Policy changes
When this policy changes, the controller updates the document version. Material changes are communicated through the interface, a contractual communication channel, or another available method.