Pulse CRM ("Pulse", "we", "us") is a customer relationship management platform operated by EngGenius ("the operator"). This policy explains what personal data we collect, why, and the choices you have. It is written to comply with the UK GDPR and the Data Protection Act 2018.
1. Who is responsible for your data
For your account information (your name, email address, billing status), we are the data controller. For the content of your CRM (companies, contacts, notes, emails and messages you compose), your organisation is the controller and we act as a processor on its instructions.
Contact: jack.wheldon@enggenius.tech
2. What we collect and why
| Data | Why we have it | Legal basis |
|---|---|---|
| Name, email address, password (hashed by our authentication provider) | Creating and securing your account | Contract |
| Organisation name, team members' emails | Running your organisation's shared workspace | Contract |
| Billing details (held by Stripe — we never see full card numbers) | Paid subscriptions | Contract |
| CRM content: the companies, contacts, notes, emails and messages your team creates | Providing the service — processed only on your organisation's instructions | Contract (as processor) |
| Usage counters (e.g. how many AI credits your organisation has used this month) | Operating plan allowances fairly | Legitimate interests |
| Details submitted through a public contact card ("leave your details" forms) | Delivered to the organisation whose card you completed, so they can follow up | Legitimate interests / consent at the form |
| Anonymous view and click counts on public contact cards | Showing card owners how their page performs. No profile is built of visitors. | Legitimate interests |
3. AI features
Pulse includes AI-assisted writing and research powered by Anthropic's Claude models. When you use these features, the relevant content (for example, a contact's name and your notes about their company) is sent to Anthropic's API to generate the result, then returned to your CRM. Anthropic does not use API data to train its models. We meter how often AI features are used; we do not read the content.
4. Who we share data with
Only the service providers needed to run Pulse, each bound by their own data protection terms:
| Provider | Purpose |
|---|---|
| Google Firebase (Google Cloud) | Hosting, database, authentication |
| Anthropic | AI writing and research features |
| Stripe | Payment processing |
| ClickSend | Sending text messages you compose |
| Google (Gmail API) | Sending and syncing email, only for mailboxes you explicitly connect |
If your organisation connects its own accounts (for example a Hunter.io or Calendly account), data flows to those services under your organisation's own agreement with them. We never sell personal data, and we do not share it with advertisers or data brokers.
5. Where data lives
Our infrastructure runs on Google Cloud. Some providers (including Google and Anthropic) process data in the United States; where they do, transfers are protected by the UK Extension to the EU–US Data Privacy Framework or standard contractual clauses.
6. How long we keep it
Account and CRM data is kept while your account is active. If you delete your account or ask us to, we delete your organisation's data within 30 days, except minimal records we must keep for legal or accounting reasons. Details submitted through a public contact card are held by the receiving organisation and can be deleted on request to them or to us.
7. Your rights
Under the UK GDPR you can ask us to access, correct, delete, restrict or export your personal data, and you can object to processing based on legitimate interests. Email jack.wheldon@enggenius.tech and we will respond within one month. If you're unhappy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk.
8. Cookies and local storage
Pulse uses only what's needed to keep you signed in and remember your preferences (via our authentication provider's tokens and your browser's local storage). We do not use advertising or cross-site tracking cookies.
9. Gmail & Google user data
If you connect a Gmail mailbox, Pulse uses Google's APIs solely to send the emails you compose or schedule and to read replies to conversations Pulse is tracking, so your CRM timeline stays accurate. Pulse's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train AI models. You can disconnect your mailbox at any time in Settings, which revokes Pulse's access.
10. Changes to this policy
If we make material changes we'll notify account owners by email and update the date at the top of this page.