Platform Privacy Policy

Pulse Health Ltd — Version 1.3

Last updated: July 2026 · Document version 1.3

Clinics issue their own patient-facing privacy notices. See Clinic patient privacy notice.

1. Who We Are

Pulse Health Ltd ("Pulse Health", "we", "us") provides the Pulse PMS / Pulse Health practice management platform. Company number 17122797, registered office 3 Beacon House, Kempson Way, Bury St. Edmunds, Suffolk, IP32 7AR. Contact: contact@pulsehealth.uk.

For subscriber account and billing data, we act as Data Controller. For Patient Data entered by clinics, we act as Data Processor under our DPA; the clinic is Controller.

2. Data We Process as Controller

  • Account identity and contact details of clinic owners and staff users
  • Billing, subscription, and payment metadata (card PANs are handled by payment providers)
  • Support communications and product analytics needed to operate the Service
  • Security logs (IP address, authentication events) for abuse prevention

3. Data We Process as Processor

On documented instructions from the Subscriber, we process Patient Data and related practice data as described in the DPA (identity, contact, health, appointments, invoices, communications). Clinics remain responsible for patient notices and lawful basis.

4. Lawful Bases (Controller activities)

  • Contract: providing and billing the Service
  • Legitimate interests: securing the platform, preventing fraud, improving reliability
  • Legal obligation: tax, accounting, and regulatory duties where applicable
  • Consent: optional marketing to subscribers where required

5. Sharing & Sub-Processors

We use sub-processors listed in the DPA (hosting, database, payments, messaging, AI providers) under appropriate contracts and UK transfer safeguards where required.

6. Retention

Account and billing records are retained for the subscription term and thereafter as required for legal, accounting, and dispute purposes. Patient Data retention follows the DPA and Subscriber instructions (including post-termination export window).

7. Your Rights

Where we are Controller, staff and account contacts may exercise UK GDPR rights by contacting contact@pulsehealth.uk. Where we are Processor, patient requests should be directed to the clinic Controller; we assist under the DPA.

8. Security

We apply appropriate technical and organisational measures as described in the Terms and DPA. No method of transmission or storage is perfectly secure.

9. Complaints

You may contact the ICO at ico.org.uk.

10. Changes

Material changes to this Platform Privacy Policy will be versioned with our legal document set and notified as described in the Terms of Service.