1. Introduction
Employee Pulse Hub ("we," "us," or "our") operates a SaaS platform that enables organizations to manage HR support requests, live chat, appointments, knowledge content, and employee feedback — including anonymous reports. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with the Service.
In most cases, the organization that subscribes to the Service (the "Customer") is the controller of the personal data it uploads (such as employee records), and we act as a processor on the Customer's behalf. Where you are an individual user (an employee or HR staff member), this policy also describes your rights.
2. Information We Collect
Account & administrative data: name, email, organization details, role, and authentication information for Customer administrators and users.
Employee directory data: names, emails, job titles, departments, managers, hire dates, and phone numbers that a Customer uploads or syncs into the Service.
Content & communications: support tickets, comments, HR notes, live chat messages, attachments, and appointment requests submitted through the Service.
Anonymous report data: when an individual chooses to submit an anonymous report (e.g., harassment, discrimination, safety, or ethics concerns), we store the report details without attaching the reporter's identity. We take measures to preserve anonymity and do not knowingly link anonymous reports to identified accounts.
Usage & technical data: IP address, device and browser information, log data, and interaction data used for security, operations, and analytics.
Billing data: limited billing information collected by our payment processors (we do not store full card numbers).
3. How We Use Information
We use personal information to:
- Provide, operate, secure, and improve the Service;
- Process support requests, live chats, appointments, and reports as directed by the Customer;
- Authenticate users and administer accounts and roles;
- Communicate about the Service, including security and policy notices;
- Detect, prevent, and respond to fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our Terms.
We do not sell personal information. We do not use sensitive personal data for our own commercial advertising.
4. Legal Bases (GDPR)
For users in the European Economic Area, UK, or Switzerland, we process personal data on the following legal bases:
- Performance of a contract — to provide the Service you or your organization requested;
- Legitimate interests — for security, fraud prevention, and service improvement, balanced against your rights;
- Legal obligation — where required by law;
- Consent — where you provide consent for specific activities (you may withdraw consent at any time).
When we process data on behalf of a Customer, the Customer determines the legal basis for that processing and is responsible for providing any required notices to its employees.
6. Data Retention
We retain Customer Data for as long as your account is active or as needed to provide the Service, plus a limited period after termination to allow data export. After that, we delete or anonymize Customer Data in accordance with our retention schedule, unless retention is required by law.
Customers may configure retention and deletion of their data within the Service where applicable, and may request deletion upon account termination.
7. Security
We implement industry-standard safeguards, including encryption in transit and at rest, access controls, regular monitoring, and vendor due diligence. Access to Customer Data is restricted to authorized personnel with a need to access it.
Despite these measures, no method of transmission or storage is perfectly secure. In the event of a security incident affecting your personal data, we will notify affected Customers and, where required by law, relevant authorities and affected individuals.
8. Your Privacy Rights
Depending on your jurisdiction, you may have rights to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete personal data;
- Request deletion of your personal data (subject to legal retention obligations);
- Restrict or object to certain processing;
- Receive a copy of your data in a portable format;
- Withdraw consent where processing relies on consent;
- Opt out of the "sale" or "sharing" of personal data (as defined by laws like CCPA).
Because we often process data on behalf of a Customer organization, many requests are best directed to your employer or the Customer administrator, who controls the data. You may also contact us directly using the information below, and we will forward or respond as appropriate.
We do not sell personal information and do not process personal data for targeted advertising that would require an opt-out under applicable law.
9. Sensitive & Special-Category Data
The Service may be used to submit information revealing health, racial or ethnic origin, trade union membership, or other special-category data, particularly through anonymous reports. Where the Customer is the controller, the Customer is responsible for establishing a lawful basis and appropriate safeguards for such processing.
We minimize our handling of special-category data and process anonymous reports in a manner designed to protect reporter identity.
10. Children's Privacy
The Service is intended for business use and is not directed to individuals under 16 (or the applicable age of digital consent). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take steps to delete it.
11. International Data Transfers
We and our subprocessors may process and store personal data in countries other than your own. Where we transfer personal data internationally, we rely on recognized transfer mechanisms (such as Standard Contractual Clauses) or another lawful basis where required.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide notice (e.g., via email or in-app). The "Last updated" date above reflects the most recent revision.
14. Contact & Questions
If you have questions about this Privacy Policy or wish to exercise your rights, contact us through your account, the contact information provided on the Service, or your organization's data protection officer. We will respond in accordance with applicable law.