PRA-Pulse Privacy Policy
Published 2026-09-09
PRA-Pulse Privacy Policy
Last updated: September 9, 2026
This Privacy Policy explains how PRA-Pulse Inc. ("PRA-Pulse", "we", "us") handles personal information in connection with the PRA-Pulse application and related services (the "Service"). It applies to employees, managers, administrators, and other individuals who use the Service.
Read this alongside the PRA-Pulse End User License Agreement.
Our role, and your employer's role
PRA-Pulse is provided to organizations (your employer or another entity, the "Customer") that subscribe to it. In most cases your Customer decides what data is collected, why, and how long it is kept. Under privacy law your Customer is the controller of that data, and we act as the processor, handling data on the Customer's instructions.
This means questions about why your organization uses PRA-Pulse, who at your organization can see results, and how your organization acts on them should go to your employer. Questions about how the Service itself handles data can come to us using the contact details below.
For our own account, billing, and website records, we act as controller. This policy covers both roles and notes which applies where it matters.
What we collect
Account information. Name, work email, role designation (employee, manager, administrator), and the workspace you belong to.
Check-in responses. Your answers to the PRA-Pulse ABC check-in, submitted on a recurring basis. These are used to produce the scores, bands, and trends the Service presents.
Derived results. Scores and bands calculated from your responses, and the aggregate views built from them.
Usage and technical data. Log data such as access times, IP address, device and browser type, and actions taken in the Service, used to operate and secure it.
Billing information. For the individuals who manage a subscription, billing contact details. Payment card data is handled by our payment processor and is not stored by us.
We do not ask for or intend to collect information beyond what the check-in and account setup require. Please do not enter clinical diagnoses, health record details, or other sensitive information into free-text fields.
How your responses are surfaced
How your individual responses appear to others depends on your role and your Customer's configuration:
- Administrators see aggregate results and a pseudonymous individual worklist by default. Individuals are not named in that view.
- Where re-identification is enabled, it requires step-up authentication, a recorded reason, and is logged to an immutable audit record.
- Manager and leadership responses may feed a separate leadership cohort aggregate, shown only in aggregate.
- Minimum-respondent thresholds may apply to certain views so that small groups are not identifiable.
Why we process data
We process personal information to:
- provide the Service and produce check-in results for your Customer;
- authenticate users and secure accounts and workspaces;
- operate, maintain, troubleshoot, and improve the Service;
- process subscriptions and payments;
- meet legal, regulatory, and security obligations.
Where we act as processor, we process data on your Customer's instructions for the purposes above. Where we act as controller (account, billing, website), our legal bases include performing our contract with you or your Customer, our legitimate interest in operating and securing the Service, and compliance with law.
What the Service is not
PRA-Pulse detects early signals of workplace psychological strain from self-reported responses. It is not a medical device or diagnostic tool and does not produce clinical assessments. Results reflect relative change over time, not clinical thresholds.
Sharing and service providers
We share personal information only as needed to run the Service:
- Your Customer, which receives aggregate results and, subject to the safeguards above, the pseudonymous worklist for its own workspace.
- Service providers (sub-processors) that host and operate the Service on our behalf, under contracts that limit their use of data to providing their services to us. These currently include:
- Supabase — application database and backend
- Vercel — application hosting
- Cloudflare — DNS and network security
- Stripe — payment processing
- Authorized partners. Where your Customer has arranged the Service through a reseller or case-management partner, that partner may receive data as described in the arrangement between your Customer and the partner.
- Legal and safety. We may disclose information where required by law, to enforce our agreements, or to protect the rights, safety, and security of users, the public, or PRA-Pulse.
We do not sell personal information, and we do not use check-in responses for advertising.
Where data is stored and processed
The Service is operated using providers that may store and process data in Canada, the United States, or other countries where our providers operate. Where data crosses borders, we rely on appropriate safeguards required by applicable law. Your Customer's configuration and location may affect where your data is held.
How long we keep data
We retain personal information for as long as your Customer's subscription is active and as needed to provide the Service, then delete or de-identify it within a reasonable period, unless a longer period is required by law or by our agreement with your Customer. Your Customer may set its own retention preferences. Aggregate and de-identified results that cannot reasonably identify an individual may be retained.
How we protect data
We use technical and organizational measures to protect personal information, including access controls tied to role, authentication requirements, audit logging of sensitive actions such as identity reveals, and encryption in transit. No system is perfectly secure, but we work to protect data appropriate to its sensitivity.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, or to object to certain processing.
Because your Customer usually controls your check-in data, the fastest route for most requests is your employer, who can action them directly in the Service. You can also contact us and we will help route your request to the right party. We respond to requests as required by applicable law and may need to verify your identity first.
Children
The Service is intended for use by adults in a workplace setting and is not directed to children.
Changes to this policy
We may update this policy. We will post the updated version and revise the "Last updated" date, and provide notice where required.
Contact us
PRA-Pulse Inc. [MAILING ADDRESS] privacy@pra.company