Legal
Privacy Policy
Last updated:
Pulse Pty Ltd (ABN to be inserted) ('Pulse', 'we', 'us', 'our') is committed to protecting the privacy of individuals whose personal information we collect and handle. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Who this policy applies to
This policy applies to all personal information collected by Pulse in connection with the Pulse platform and mobile application ('the Service'). This includes information about:
• Employees, contractors, and administrators of organisations that subscribe to Pulse ('Organisational Users');
• NDIS participants whose information is entered into the platform by Organisational Users ('Participants');
• Visitors to our website (pulse.app).
Pulse operates as a data processor on behalf of subscribing organisations (the data controllers) for Participant data entered into the platform. Organisational Users are responsible for ensuring they have appropriate authority to enter Participant data into the Service.
2. What personal information we collect
We may collect the following categories of personal information:
Organisational Users: name, work email address, job title, organisation name, login credentials, usage logs, and device/browser information.
Participants (entered by Organisational Users): name, contact details, NDIS number, date of birth, NDIS plan details (including funding categories, budgets, and plan dates), support goals, case notes, service delivery records, and related correspondence.
Website visitors: IP address, browser type, pages visited, and referral source (collected via server logs and analytics tools where consent has been obtained).
We do not knowingly collect sensitive information beyond what is necessary to deliver the Service (for example, disability-related information contained in NDIS plan data entered by Organisational Users).
3. How we collect personal information
We collect personal information:
• Directly from Organisational Users when they register for the Service, configure their account, or contact us;
• When Organisational Users enter Participant data into the platform in the course of providing NDIS support coordination services;
• Automatically through the platform (usage logs, session data) and our website (server logs);
• From third parties where permitted by law (for example, identity verification services).
4. Why we collect and use personal information
We collect and use personal information for the following purposes:
• To provide, operate, and improve the Pulse platform and mobile application;
• To create and manage user accounts and authenticate access;
• To enable Organisational Users to manage NDIS participant caseloads, plan budgets, case notes, and billing;
• To send service-related communications (account notices, security alerts, product updates);
• To respond to support requests and enquiries;
• To comply with our legal obligations;
• To detect and prevent fraud, security incidents, and misuse of the Service;
• For internal analytics and product improvement (using aggregated or de-identified data where possible).
We will not use personal information for direct marketing without consent, and we will not sell personal information to third parties.
5. Disclosure of personal information
We may disclose personal information to:
• Our employees and contractors who need access to deliver the Service;
• Cloud infrastructure and hosting providers (data is stored in Australia or in jurisdictions with equivalent privacy protections);
• Software sub-processors used to operate the platform (for example, email delivery, error monitoring, and analytics services) — we maintain a current list of sub-processors and require them to handle data in accordance with applicable privacy laws;
• Professional advisers (lawyers, accountants, auditors) under obligations of confidentiality;
• Regulatory bodies or law enforcement agencies where required by law.
We do not disclose Participant data to third parties for their own purposes. We do not transfer personal information outside Australia except where the recipient country has comparable privacy protections or the individual has consented.
6. Data security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:
• Encryption of data in transit (TLS) and at rest;
• Role-based access controls and authentication requirements;
• Regular security assessments and vulnerability management;
• Staff training on privacy and data handling obligations.
While we take these precautions, no method of electronic transmission or storage is completely secure. We encourage Organisational Users to maintain strong passwords and to notify us immediately of any suspected unauthorised access.
7. Data retention
We retain personal information for as long as necessary to provide the Service and to comply with our legal obligations. When a subscription is terminated:
• Organisational User account data is retained for 90 days to allow data export, then deleted;
• Participant data entered by the organisation is retained for 90 days after subscription termination, then deleted, unless a longer retention period is required by law;
• Backup copies may persist for up to 30 additional days before permanent deletion.
Organisational Users are responsible for exporting any data they require before termination.
8. Access, correction, and deletion
Under the Privacy Act 1988 (Cth), individuals have the right to:
• Request access to personal information we hold about them;
• Request correction of personal information that is inaccurate, out of date, incomplete, or misleading;
• Request deletion of personal information in certain circumstances.
To make a request, please contact our Privacy Officer at [email protected]. We will respond within 30 days. We may need to verify your identity before processing a request. In some cases we may be unable to provide access or delete information (for example, where retention is required by law), and we will explain the reason.
Participants whose data has been entered by an Organisational User should direct requests to that organisation in the first instance, as the organisation is the data controller for that data.
9. Cookies and tracking
Our website uses cookies and similar technologies to operate the site and, where consent has been obtained, to analyse usage. You can control cookie preferences through your browser settings or through the cookie consent banner on our website. Disabling certain cookies may affect the functionality of the site.
The Pulse platform itself does not use third-party advertising or tracking cookies.
10. Children's privacy
The Pulse platform is intended for use by organisations and their staff. We do not knowingly collect personal information directly from individuals under the age of 18. Participant data relating to minors may be entered by Organisational Users in the course of providing NDIS support coordination; such data is handled in accordance with this policy and the Organisational User's own obligations under applicable law.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify Organisational Users of material changes by email or by a notice within the platform. The updated policy will be effective from the date it is posted on our website. Continued use of the Service after that date constitutes acceptance of the updated policy.
12. Contact us
If you have questions, concerns, or complaints about how we handle personal information, or to make a privacy request, please contact our Privacy Officer:
Email: [email protected]
Postal: Privacy Officer, Pulse Pty Ltd, [Address]
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Questions about this policy? [email protected] or visit our Support page.