PulseArcHealth

Security & privacy

Written for a due-diligence review, not for reassurance.

This page states only what PulseArc can evidence. Where something has not been established, it says so instead of using general security language.

Administrator reviewing user access permissions on a laptop in a quiet office
Access administration is performed by the organisation's own nominated administrators.

Last updated: 31 July 2026

PulseArc does not hold, and does not claim, certification or attestation against any healthcare, privacy, payment-card, cybersecurity or medical-device standard. Any statement about a specific regulation is made only where an organisation and PulseArc have confirmed it in writing.

01

Data roles

In an approved implementation, the customer organisation is intended to determine the purposes of processing for the operational data it enters, and PulseArc is intended to act on that organisation's documented instructions. The exact roles vary by implementation and are fixed in the data-processing terms agreed with each organisation before any environment goes into use.

Roles vary by implementation. The final data-processing arrangement is agreed in writing with each organisation before an environment is used operationally.

02

Data categories

  • Enquiry data submitted through this website: name, organisation, work email, role, market and the enquiry text.
  • Account and user administration data for named organisational users: name, work contact details, role and access records.
  • Operational records created by an organisation's own users inside the configured environment.
  • Technical logs generated by use of the platform, such as sign-in and administrative events.

Categories beyond these — including clinical records or other health data — are only processed where an implementation has been assessed and expressly agreed for that purpose. PulseArc does not collect health data through this website.

03

Access controls

  • Named user accounts, with access granted and removed by the organisation's nominated administrators
  • Encryption of data in transit between users and the platform (HTTPS/TLS)
  • Separation of each organisation's configured environment
  • Recording of administrative access changes within the environment

Controls beyond those listed are not claimed. Where an organisation requires additional controls, they are assessed during implementation and, if agreed, documented in the applicable agreement.

Audit logging: Administrative access changes are recorded. A broader audit-logging capability is not published as available.

04

Hosting and transfers

Hosting arrangements, including region and any cross-border processing, are documented for each organisation during implementation. PulseArc does not publish a hosting-location claim on this website.

Where any cross-border processing applies to an implementation, it is identified and agreed in the data-processing terms for that organisation.

Retention: Website enquiry data is retained only as long as needed to respond to the enquiry and to keep a record of business correspondence. Retention inside a configured environment is agreed with the organisation.

05

Incident and support route

Security concerns, suspected vulnerabilities and incident reports should be sent to management@pulsearc.online. Please include what you observed, when, and how it can be reproduced.

No response-time commitment is published. Where an organisation requires one, it is agreed in the applicable agreement.

06

Customer responsibilities

The customer organisation configures and maintains its own authorised users, and retains responsibility for its clinical, privacy and regulatory obligations, including the lawfulness and accuracy of the information it places in the platform.

Data-subject requests relating to an organisation's own operational records are handled by that organisation. Requests about information PulseArc Health Technologies holds directly — such as a website enquiry — can be sent to management@pulsearc.online.

07

Claims we will not make

PulseArc does not describe itself as bank-grade, military-grade, fully compliant, HIPAA compliant or PCI compliant, and does not state that data is always safe. The only security statements permitted on this site are:

  • Data is transmitted between users and the platform over HTTPS/TLS.
  • Access is granted to named user accounts administered by the organisation.
  • Each organisation's configured environment is kept separate.

Documents confirmed before deployment

These are the implementation documents that may be confirmed with an organisation before an environment is configured. They are conditional on the agreed implementation — they are not documents that already exist for every visitor to this website.

  • Applicable agreement and service scope
  • Data-processing and confidentiality terms, where required
  • Agreed data-role allocation
  • Security and access-management schedule
  • Approved sub-processor and supplier information, where applicable
  • Support, incident and escalation contacts
  • Retention, deletion and exit arrangements
  • Implementation acceptance record

The required documents depend on the agreed implementation and applicable law. PulseArc does not represent that a standard document set alone makes an organisation compliant with healthcare, privacy, security or professional obligations.

Security incident route

If a contracted organisation identifies a suspected issue involving its configured environment, it must use the documented support and escalation route in its applicable agreement. This public website is not an incident-reporting portal and must not be used to send patient information, credentials or sensitive security details.

Running a due-diligence review?

Send the questions your information-security or privacy team needs answered and we will answer them in writing, including where the answer is that something is not in place.