← Pulse CRM

Privacy Policy

Last updated: 10 August 2026

Pulse CRM ("Pulse", "we", "us") is a customer relationship management platform operated by EngGenius ("the operator"). This policy explains what personal data we collect, why, and the choices you have. It is written to comply with the UK GDPR and the Data Protection Act 2018.

The short version. We collect what we need to run your account and nothing more. The business data you put into your CRM belongs to your organisation — we process it on your instructions and never sell it, share it with advertisers, or use it to train AI models.

1. Who is responsible for your data

For your account information (your name, email address, billing status), we are the data controller. For the content of your CRM (companies, contacts, notes, emails and messages you compose), your organisation is the controller and we act as a processor on its instructions.

Contact: jack.wheldon@enggenius.tech

2. What we collect and why

DataWhy we have itLegal basis
Name, email address, password (hashed by our authentication provider)Creating and securing your accountContract
Organisation name, team members' emailsRunning your organisation's shared workspaceContract
Billing details (held by Stripe — we never see full card numbers)Paid subscriptionsContract
CRM content: the companies, contacts, notes, emails and messages your team createsProviding the service — processed only on your organisation's instructionsContract (as processor)
Usage counters (e.g. how many AI credits your organisation has used this month)Operating plan allowances fairlyLegitimate interests
Details submitted through a public contact card ("leave your details" forms)Delivered to the organisation whose card you completed, so they can follow upLegitimate interests / consent at the form
Anonymous view and click counts on public contact cardsShowing card owners how their page performs. No profile is built of visitors.Legitimate interests

3. AI features

Pulse includes AI-assisted writing and research powered by Anthropic's Claude models. When you use these features, the relevant content (for example, a contact's name and your notes about their company) is sent to Anthropic's API to generate the result, then returned to your CRM. Anthropic does not use API data to train its models. We meter how often AI features are used; we do not read the content.

4. Who we share data with

Only the service providers needed to run Pulse, each bound by their own data protection terms:

ProviderPurpose
Google Firebase (Google Cloud)Hosting, database, authentication
AnthropicAI writing and research features
StripePayment processing
ClickSendSending text messages you compose
Google (Gmail API)Sending and syncing email, only for mailboxes you explicitly connect

If your organisation connects its own accounts (for example a Hunter.io or Calendly account), data flows to those services under your organisation's own agreement with them. We never sell personal data, and we do not share it with advertisers or data brokers.

5. Where data lives

Our infrastructure runs on Google Cloud. Some providers (including Google and Anthropic) process data in the United States; where they do, transfers are protected by the UK Extension to the EU–US Data Privacy Framework or standard contractual clauses.

6. How long we keep it

Account and CRM data is kept while your account is active. If you delete your account or ask us to, we delete your organisation's data within 30 days, except minimal records we must keep for legal or accounting reasons. Details submitted through a public contact card are held by the receiving organisation and can be deleted on request to them or to us.

7. Your rights

Under the UK GDPR you can ask us to access, correct, delete, restrict or export your personal data, and you can object to processing based on legitimate interests. Email jack.wheldon@enggenius.tech and we will respond within one month. If you're unhappy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk.

8. Cookies and local storage

Pulse uses only what's needed to keep you signed in and remember your preferences (via our authentication provider's tokens and your browser's local storage). We do not use advertising or cross-site tracking cookies.

9. Gmail & Google user data

If you connect a Gmail mailbox, Pulse uses Google's APIs solely to send the emails you compose or schedule and to read replies to conversations Pulse is tracking, so your CRM timeline stays accurate. Pulse's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train AI models. You can disconnect your mailbox at any time in Settings, which revokes Pulse's access.

10. Changes to this policy

If we make material changes we'll notify account owners by email and update the date at the top of this page.