Legal
Privacy Policy
How PULSE-GRID handles personal data, for app users, hospitals, partners, and website visitors, in line with India's Digital Personal Data Protection Act, 2023.
Last updated: 4 August 2026
This section explains how the PulseGrid mobile apphandles personal information. The app is used by hospitals and clinics (“Healthcare Providers”) and their authorized staff.
1. Our role
For your staff account — the email and profile from your sign-in, the role your hospital assigns you, and how you use the app — PulseGrid is the data controller (Data Fiduciary).
For the clinical, billing, pharmacy, and operational records you view or enter through the app, the Healthcare Provider that employs you is the controller, and PulseGrid acts as its processor, handling that data only on the Provider’s instructions. Requests about patient records should go to that Provider — see the For hospitals & partners tab.
2. Information we collect
- Account & identity: the email address and basic profile from your Google or Apple sign-in, and the role(s) your hospital assigns you.
- Usage & device: app version, device model and operating system, and diagnostic or crash data used to keep the app working.
- Content you access:patient, billing, pharmacy, and operational records belonging to your hospital, which you view or enter to do your job. PulseGrid stores this on the hospital’s behalf.
We do not collect payment-card details in the app, and we do not use your data for advertising.
3. How we use information
- to sign you in and show you only what your role permits;
- to provide, maintain, and improve the app;
- to secure the service, prevent misuse, and keep the audit records your hospital requires;
- to respond to your requests and provide support.
4. Legal bases
We process personal data under India’s Digital Personal Data Protection Act, 2023 and, where applicable, other data-protection laws — on the bases of your consent, performance of the service, our legitimate interest in operating and securing the app, and our legal obligations.
5. How information is shared
- Your hospital: staff and administrators at your hospital see data according to their roles.
- Service providers (sub-processors):we use Supabase for database and authentication hosting, Google and Apple for sign-in, and OpenAI to generate Pulse AI’s answers. They process data under contract, only to run the service.
- Legal: we may disclose information where required by law or to protect rights and safety.
We never sell your personal data.
6. Pulse AI
Pulse AI is an optional assistant your hospital can switch on for administrators. It answers questions about your hospital’s own records.
- What leaves the platform: your question, and the hospital records retrieved to answer it, are sent to OpenAI, our AI sub-processor, which processes them on servers outside India. Only the data needed to answer that question is sent.
- Not used for training:neither your questions nor your hospital’s records are used to train AI models.
- Scope:the assistant can read only your own hospital’s data, enforced by the same database access rules as the rest of the app. It cannot see another hospital’s records.
- Stored conversations: chats are saved against your login. No other user at your hospital can open them; they may be accessed by us for support and audit.
- Accuracy: answers can be incomplete or wrong. See the Terms of Service.
Administrators are shown these points and asked to accept them before first use.
7. Data security
Access is scoped by tenant and role at the database, data is encrypted in transit, and your session is held in your device’s secure storage. No system is perfectly secure, but we work to protect your information.
8. Data retention
We keep account data while your access is active. Clinical and operational records are retained by your hospital for as long as its own legal and medical-record obligations require. See “Deleting your data” below.
9. Your rights
Subject to law, you may access, correct, or request deletion of your personal data, withdraw consent, and complain to a data-protection authority. Exercise these by emailing vishal@pulse-grid.app or from Settings → Delete account & data in the app. Requests about patient records are handled by your hospital as the controller.
10. Deleting your data
You can delete your PulseGrid account from Settings → Delete account & datain the app, or by email. This removes your whitelist entry and the sign-in linked to it — the login itself — ends your access, and completes final cleanup within 30 days. We confirm by email when it is done.
It does not delete clinical or hospital records, which belong to your hospital and are retained under its obligations. Full steps — and how a hospital deletes its own data — are on our Account & Data Deletion page.
11. Children
The app is for authorized adult staff. Patient records may relate to minors; those are controlled by the hospital, not by PulseGrid.
12. International transfers
Data may be processed on servers outside your country. Where it is, we rely on appropriate safeguards.
13. Changes to this policy
We may update this policy. Material changes will be notified in the app or by email, and the effective date above will change.
14. Contact
PulseGrid — vishal@pulse-grid.app.