Privacy Policy
Effective: August 2026
On Pulse Enterprises Pty Ltd (ABN 87 686 271 938) operates Pulsity at pulsity.io. This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. What This Policy Covers
Pulsity is a B2B platform. We process employee data on behalf of enterprise customers (employers). This policy covers:
- Customer contacts — people who sign up, manage accounts, or contact us
- Platform users — employees whose data is uploaded by their employer (our customer)
2. Information We Collect
Customer Account Information
- Contact name and email
- Company name, ABN, address
- Billing details
Platform Data (on behalf of customers)
Your employer uploads:
- Employee names and work emails
- Timesheet and allocation data
- Project information (names, timelines, budgets)
- Engagement economics (fees, margins)
We do not collect: Home addresses, bank details, health information, or other sensitive personal data.
3. How We Collect Information
- From customers when they sign up or contact us
- From customer uploads when employers import employee data
- Website analytics (IP addresses, pages visited)
We do not collect personal information directly from employees — that comes from their employer.
4. Why We Collect It
- To provide and maintain the Pulsity platform
- To process payments and manage subscriptions
- To provide customer support
- To comply with legal obligations
For platform data, the purpose is determined by your employer — typically resource planning, capacity management, and project economics.
5. Who We Share It With
We do not sell personal information. We share limited information with the service providers below, each engaged to operate the Pulsity platform or the pulsity.io website:
| Processor | Purpose | Data Categories | Hosting Region |
|---|---|---|---|
| Microsoft Azure | Platform and website hosting | Platform data, customer account data | Australia (Australia East) |
| Google Analytics 4 | Website usage analytics | IP address, pages visited, device and browser information | United States (offshore) |
| Sentry | Error and performance monitoring | Device/browser information, page URLs, session replay recordings, and request data that may identify you | United States (offshore) |
| Resend | Delivering emails submitted via our contact and enquiry forms | Name, email address, message content | United States (offshore) |
| Cal.com | Scheduling demo bookings | Name, email address, booking details | United States (offshore) |
Customer administrators within your organisation also have access to platform data, as configured by your employer.
Your platform data stays in Australia. Platform data (the information your employer uploads to Pulsity) and customer account information are hosted exclusively in Microsoft Azure's Australia East region. Website operational data — analytics, error monitoring, and form submissions — is processed by the named offshore providers above, as described in this section and in the Cookies section below.
6. Website Monitoring Before You Accept Cookies
Some website monitoring runs from the moment a page loads, before you make a cookie choice. This is limited to the following:
- Error and performance monitoring (Sentry) runs on every page load to help us detect and fix bugs. This includes Session Replay, which records a sample of browsing sessions and stores a session identifier in your browser's sessionStorage, and request data that may attach information capable of identifying you (such as your IP address).
- Analytics measurement requests are still sent to Google even when you deny analytics storage. Denying consent switches Google Analytics into a cookieless mode — it stops setting the
_gacookies described below — but a request is still made; it is not silent. - When a demo booking completes, our server sends a
booking_createdevent directly to Google Analytics. This server-side event is separate from, and not controlled by, your browser's cookie consent choice.
7. Cookies
We use the following cookies and browser storage on pulsity.io:
pulsity_consent— a first-party entry in your browser's localStorage (not a cookie) that records whether you accepted or declined analytics cookies._gaand_ga_*— Google Analytics cookies used to distinguish visitors and measure website usage. These are only set once you accept analytics cookies.
Purpose: these cookies help us understand how visitors use pulsity.io so we can improve the site. Retention: analytics data is retained for 26 months.
Consent Mode: Google Consent Mode v2 defaults analytics storage to denied until you make a choice. Choosing "Accept" sets it to granted; choosing "Decline" keeps it denied.
Changing your decision: clear the pulsity_consent entry from your browser's local storage (via your browser's site data settings) to be shown the cookie banner again, or contact us at privacy@pulsity.io.
8. Data Security
We protect information through:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls
- SSO and MFA options
- Daily encrypted backups
- Azure-managed infrastructure security
9. Data Retention
- Customer accounts: Duration of subscription plus 7 years (tax/legal)
- Platform data: Duration of subscription; deleted within 90 days of termination on request
- Analytics: 26 months
10. Your Rights
Access and Correction
You can request access to or correction of personal information we hold about you.
For platform data (employee information): Contact your employer — they control that data.
For customer account data: Contact us at privacy@pulsity.io.
Complaints
- Contact us first: privacy@pulsity.io
- We'll respond within 30 days
- If unsatisfied, contact the OAIC at www.oaic.gov.au
11. Data Breaches
We comply with the Notifiable Data Breaches scheme. If a breach is likely to cause serious harm, we will:
- Notify affected customers within 72 hours
- Notify affected individuals and the OAIC as required
- Provide recommendations for protective steps
12. Important Clarifications
Employee records exemption: Although we process employee data, the Privacy Act's employee records exemption does not apply to us — we are a service provider, not the employer.
Customer responsibilities: Employers (our customers) are responsible for notifying their employees about data collection under APP 5.
GDPR: This policy addresses Australian privacy law. GDPR does not apply as we operate in Australia for Australian customers only.
13. Changes to This Policy
We may update this policy. Material changes will be notified to customers via email.
14. Contact
On Pulse Enterprises Pty Ltd
9 Moncrieff St, Dickson ACT 2602
Privacy: privacy@pulsity.io
General: support@pulsity.io
This policy complies with the Privacy Act 1988 (Cth) and Australian Privacy Principles.