Privacy & Compliance
Your data doesn't belong to us.
It never will.
Individual responses are anonymized and never surfaced to leadership. Role-based access controls. Encrypted in transit and at rest. Your data is never sold. Ever. Formal compliance audits are in progress; current status is on our security page.
Why this matters here
Data privacy is now a buying criterion, not a checkbox. Your board already knows this.
You are asking people to tell you the truth about whether they understand the direction. They will only do that if the system protects them, and they can tell the difference. Anonymization is not a compliance checkbox here. It is the thing that makes the data worth collecting at all.
Your data lives in your Pulse instance. Not commingled with other organizations.
Encryption at rest and in transit. Every record. Every voice memo. Every file.
No data is sold to third parties. No data is used to train AI models without explicit consent.
A Data Processing Agreement is available for any organization that requires one before signing.
How privacy is built in
Four layers. Not one policy memo.
Encrypted storage
All data, including check-in responses, is encrypted at rest using AES-256. Encryption in transit via TLS 1.3.
Role-based access
Every user sees only the data their role permits. A frontline team member cannot access records outside their scope. A leader sees aggregate patterns, not individual surveillance.
No individual attribution
Leadership sees patterns across groups, never a single person's answers. We cannot show you what one employee said, and we will not build the ability to. DPA available on request.
No data selling
Your data is never sold to third parties. It is never used for advertising. It is never used to train AI models without your organization's explicit consent.
Who sees what
Role-based access means the right visibility for every level.
Access is configured by your organization's administrator. Every level sees what they need, and nothing they shouldn't.
For IT directors and data officers
A DPA is available before you sign anything.
We know how procurement works. The IT director needs to approve before the deal can move. We have a Data Processing Agreement ready for any organization that requires one. Request it in the demo, or ask us to send it before the call.
We also support SSO, so your team doesn't need another set of credentials to manage.
IT approval checklist
- Anonymized at the individual level
- DPA available on request
- SSO compatible
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- No customer data sold or used for ad targeting
- Role-based access controls
- Data retention policy configurable
- SOC 2 Type II (in progress)