Privacy policy
Last updated: [DATE] · Draft pending legal review
Before launch: this page is a working draft written against how the product actually behaves. It still needs review by a qualified adviser in each market you sell into, and the bracketed placeholders below must be filled in.
Who we are
[LEGAL ENTITY NAME] operates KeepPulsing, practice management software provided at app.keeppulsing.com and marketed at keeppulsing.com. Our registered address is [REGISTERED ADDRESS]. You can reach us at [CONTACT EMAIL] or through the contact details on our contact page.
The two kinds of data here
KeepPulsing handles two separate things, and it matters which one is being discussed.
- Account data — information about you as a user of KeepPulsing: your name, phone number, optional email address, the clinics you belong to and your role in each.
- Clinic data — the records a clinic creates using KeepPulsing: patients, cases, consultations, prescriptions, dispensing records, stock and invoices. This data belongs to the clinic. We hold and process it on the clinic's behalf.
Where local law distinguishes a controller from a processor, the clinic is the controller of clinic data and we are the processor. We are the controller of account data.
What we collect, and why
- Phone number and password — required, because signing in uses a phone number. Without it there is no account.
- Email address — optional. If you confirm one, it becomes a second way to sign in and the way a forgotten password is reset. Nothing in the product requires an email address.
- Clinic configuration — the clinic's name, country, currency, timings and date and phone formats, so the product works the way that clinic works.
- Clinic records — whatever the clinic enters. We do not decide what goes into a patient record; the clinic does.
- Operational logs — technical records of requests to the service, kept to keep it running, diagnose faults and investigate abuse.
- Billing information — handled by our payment provider. We keep a record of what was paid and when, not your full card details.
What we do not do
- We do not sell clinic data or account data, to anyone, for any purpose.
- We do not use patient records to train machine learning models.
- We do not read clinical case notes. Support staff can see account and clinic configuration; clinical notes are scoped by role in the same way they are for your own staff.
- We do not send messages to your patients. When you contact a patient, the product opens WhatsApp with a message already written and you send it yourself, from your own number. We are not in that conversation.
Where data is stored
Clinic data is stored on servers located in [HOSTING REGION / PROVIDER]. Each clinic's data is separated in the database itself, using row-level security, rather than by application code that could be bypassed by a bug.
If you are in a jurisdiction that restricts transferring personal data abroad, the location above is the relevant fact, and you should check it against your own obligations before entering patient records.
How long we keep it
Clinic data is kept for as long as the clinic exists in the service. If a subscription lapses, the clinic is suspended rather than deleted, and export remains available so you can take your records with you. Data is deleted on request from the clinic owner, or [RETENTION PERIOD] after a clinic is closed, whichever comes first. Operational logs are kept for [LOG RETENTION PERIOD].
Getting your data out
You can export patient and billing data in standard formats at any time from inside the product. This works on an active clinic, a suspended clinic and a clinic whose subscription has expired. We consider this non-negotiable: software that holds your records hostage is not software you should trust with them.
Your rights
Depending on where you are, you may have the right to access the personal data we hold about you, correct it, have it deleted, object to certain processing, or receive it in a portable format. For account data, contact us. For clinic data, contact the clinic — they control those records, and we will assist them in responding.
One thing we cannot do is rewrite clinical history on request. A finalized consultation is immutable by design; corrections are appended as amendments. That is a clinical safety property, and it is how the record stays trustworthy.
Sub-processors
We use a small number of third parties to run the service: [HOSTING PROVIDER], [CDN PROVIDER], [PAYMENT PROVIDER], [EMAIL/SMS PROVIDER]. Each is bound by contract to handle data only as instructed. We will update this list before adding a new one.
Cookies and this website
This marketing site sets no tracking cookies and runs no third-party analytics. Your currency preference and your light or dark theme choice are stored in your own browser using local storage, and never leave your device. Our CDN may set a country cookie so the correct price is shown; it is not used to identify you.
Security
See our data and security page for how access is scoped, how changes are traced and what we do to keep records safe.
Changes to this policy
If we change this policy in a way that affects you materially, we will say so in the product rather than quietly updating the date at the top.