Website Privacy Policy
Company: M.S.F Consulting Ltd
Company Number: 15884336
Address: 15 Waterside Way, Nottingham, NG2 4RS, United Kingdom
Effective Date: 1 February 2026
Last Updated: 14 April 2026
1. Introduction
M.S.F Consulting Ltd ("we", "us", "our") operates Pulse (the "Platform"), an execution intelligence platform designed to help organisations connect strategy to execution. We are committed to protecting personal data in accordance with the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
Our Commitment: We do not sell your personal data to third parties, and we do not share your data with third parties for advertising or marketing purposes.
Important Note: This policy applies to Personal Data only. It does not cover organisational or corporate data (e.g. strategic goals, initiatives, or OKRs). Corporate data is handled under our Terms of Service and our Data Processing Agreement (DPA).
Contact: info@pulseio.net
Supervisory Authority: Information Commissioner's Office (ICO) – www.ico.org.uk
2. Data Residency
All core platform data, including user profiles and organisational strategic content, is stored at rest on secure servers located within the European Union (EU).
3. Personal Data We Collect
We collect and process the following categories of personal data:
- Identity & Contact: Name, professional email address, job title, and username.
- Account Data: Encrypted login credentials, account settings, and role permissions.
- Transaction Data: Billing history and payment method details.
- Technical Data: IP address, browser type, device identifiers, and session information.
- Usage Data: Specific actions taken within the platform and interaction patterns.
- Communications Data: Content of support tickets, feedback, and correspondence.
4. Use of Artificial Intelligence (AI)
Pulse uses AI to generate viability scores, execution risk signals, and intelligence outputs.
- API Gateway & Models: We use OpenRouter as an API gateway to access models from a range of leading AI providers.
- Gateway Privacy: OpenRouter acts as a secure routing layer. Unless prompt logging is explicitly enabled by us (which we do not do), OpenRouter does not retain or use conversation content passing through its gateway for training or any purpose beyond routing the request.
- Data Usage: Data submitted via API to the underlying model providers is not used to train their models.
- Intelligence Augmentation: Pulse outputs are intended for "Intelligence Augmentation." The platform does not make solely automated decisions that produce legal or significant effects on individuals without human review.
- Chat Data for Service Improvement: Beyond the immediate API request to model providers, Pulse retains chat interactions with the AI Agent for quality assurance, system prompt optimization, and agentic harness improvement. This chat data is:
- stored securely on Pulse infrastructure, with access restricted to authorized personnel;
- used solely to improve the quality, safety, and reliability of our AI features — it is never sold or used for advertising;
- retained for up to 12 months, after which it is deleted or anonymized; and
- subject to your data protection rights — you may request access to, or deletion of, this data at any time via Contact Us.
5. Legal Basis for Processing
We process personal data under the following lawful bases:
- Contractual Necessity: To provide the Platform and manage your account.
- Legitimate Interests: To secure the platform, debug errors, and improve UI/UX.
- Legal Obligation: To comply with UK tax and financial reporting laws.
- Consent: For optional marketing communications.
6. Data Subprocessors
We use the following third-party subprocessors to deliver the Platform:
- Hosting & Database: Supabase (European Union)
- Deployment: Railway (European Union)
- Product Analytics: PostHog (European Union)
- Error Monitoring: Sentry (European Union)
- AI Gateway: OpenRouter (United States)
- AI Processing: Model providers via OpenRouter (United States)
- Payments: Stripe (European Union)
- Email Delivery: Resend (United States)
7. International Data Transfers
While our primary database is in the EU, specific processing (AI and transactional emails) involves transfers outside the UK and EEA. Transfers to US-based providers are protected as follows.
- OpenRouter: no personal data is retained under its Zero Data Retention policy. We rely on a UK International Data Transfer Agreement as a supplementary safeguard.
- Anthropic: transfers are protected by a UK International Data Transfer Agreement incorporated into Anthropic’s standard API data processing terms. Anthropic holds ISO 27001:2022 and SOC 2 Type II certifications.
- OpenAI: transfers are protected by a UK International Data Transfer Agreement incorporated into OpenAI’s standard API data processing terms. OpenAI holds ISO 27001:2022 and SOC 2 certifications.
- Resend: transfers are protected by a UK International Data Transfer Agreement.
- Stripe: transfers are protected by the UK-US Data Bridge. Stripe is certified under the EU-US Data Privacy Framework including the UK Extension.
8. Data Retention
- Account Data: Retained for the duration of your active subscription and deleted within 90 days of account closure.
- Technical/Usage Logs: Retained for 12 months for security and performance analysis.
- Financial Records: Retained for 7 years to comply with UK HMRC requirements.
- AI Inputs: Personal data sent to third-party AI providers via our gateway is transient and not retained by those providers beyond the processing request. For our own platform-level retention of chat interactions, see "Chat Data for Service Improvement" in Section 4.
9. Your Rights
Under UK law, you have the following rights:
- Access & Rectification: Request a copy of your data or correct inaccuracies.
- Erasure: Request deletion of data where no legal basis for retention exists.
- Restriction & Portability: Limit processing or request a data transfer.
Complaints:
- You have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
- Under the Data (Use and Access) Act 2025, you also have a formal right to lodge a complaint directly with us. We will acknowledge your complaint within 30 days.
To exercise these rights, contact info@pulseio.net.
10. Security
To protect your personal data, we implement the following measures:
- Encryption: End-to-end encryption in transit (TLS 1.3) and at rest (AES-256).
- Access Control: Strict "Least Privilege" protocols for all staff access.
- Monitoring & Integrity: Continuous error monitoring via Sentry and product usage analysis via PostHog to maintain platform stability.
Full technical and organisational security practices are detailed at pulseio.net/security.
11. Marketing and Cookies
- Marketing: We only send marketing emails if you have explicitly opted in. You can unsubscribe at any time.
- Cookies: We use essential cookies for authentication. Non-essential analytics cookies are only deployed with your consent via our cookie banner.
12. Contact
M.S.F Consulting Ltd Email: info@pulseio.net
Address: 15 Waterside Way, Nottingham, NG2 4RS, United Kingdom