Privacy Policy
- 1. Who we are & how to contact us
- 2. The data we collect
- 3. How and why we use your data (legal bases)
- 4. What we do not collect or store
- 5. AI processing & third-party model provider
- 6. Service providers (sub-processors)
- 7. International data transfers
- 8. Data retention
- 9. Security
- 10. Your rights
- 11. Children's data
- 12. Cookies & similar technologies
- 13. Business customers & data processing agreements
- 14. Complaints
- 15. Changes to this policy
1. Who We Are & How to Contact Us
Pulsenox ("Pulsenox", "we", "us") provides software products for industrial and technical organizations, accessible at pulsenox.com. For all privacy matters, including any request to exercise your rights, contact us at contact@pulsenox.com.
For account data (names, emails, billing), Pulsenox acts as a data controller. For the measurement descriptions and diagnostic content you submit through AIDEN on behalf of your organization, Pulsenox generally acts as a data processor on your organization's instructions.
2. The Data We Collect
- Account data: your name, work email, company, role, and an encrypted (hashed) password when you create an account.
- Subscription & billing data: plan, trial dates, invoice details, and VAT information where applicable. Card payments, if any, are handled by our payment provider — we do not store full card numbers.
- Usage data: analysis type, timestamps, feature usage, and usage counts — used for trial enforcement, security, and service improvement.
- Analysis content: the descriptions, values, and context you submit for AI analysis. A short summary of each analysis (approximately the first 200 characters) is stored to power your session history.
- Technical data: IP address, browser type, and similar data collected automatically by our hosting and security infrastructure to keep the service reliable and secure.
3. How and Why We Use Your Data (Legal Bases)
We use your data to provide, secure, and improve the service, to manage your subscription, to enforce trial limits, to respond to support requests, and to communicate service and — where you have opted in — marketing information. Under the PDPL and GDPR, we rely on the following legal bases:
- Performance of a contract — to create and operate your account and deliver the service you subscribe to.
- Legitimate interests — to secure our systems, prevent abuse, and improve our products, balanced against your rights.
- Legal obligation — to meet tax, accounting, and regulatory requirements.
- Consent — for optional marketing communications, which you may withdraw at any time.
4. What We Do Not Collect or Store
- Raw measurement data files and thermal images are processed within your browser session. We do not permanently store your uploaded raw files on our servers.
- We do not sell or rent your personal data, and we do not share it with third parties for their own marketing.
- We ask that you do not submit personal, sensitive, or third-party confidential data in analysis prompts unless it is necessary and you are authorized to do so.
5. AI Processing & Third-Party Model Provider
AIDEN uses artificial intelligence to generate diagnostic analysis. To produce results, the analysis query you submit is transmitted to our AI provider, Anthropic, and processed through its API. This is an international transfer of data (see section 7).
- Under Anthropic's commercial API terms, inputs and outputs are not used to train AI models.
- AIDEN is a decision-support tool. AI outputs may contain errors and must be reviewed and approved by a qualified engineer before any action is taken. AIDEN does not make automated decisions that produce legal or similarly significant effects about individuals.
- To protect your data, submit only the technical information needed for the diagnosis and avoid including personal or confidential details in prompts.
6. Service Providers (Sub-processors)
We rely on a small number of trusted providers to run the service. Each is bound by contractual confidentiality and security obligations:
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase | Authentication & database hosting | AWS, Singapore (ap-southeast-1) |
| Anthropic | AI analysis processing | United States |
| Netlify | Website & application hosting | Global content delivery |
We may update this list as our service evolves. Where required, we will notify account holders of material changes to our sub-processors. A current list is available on request at contact@pulsenox.com.
7. International Data Transfers
Because our providers operate outside the UAE, your data may be transferred to and processed in other countries, including Singapore and the United States. Where we transfer personal data internationally, we do so under a lawful transfer mechanism permitted by the PDPL — such as processing in a jurisdiction recognized as providing adequate protection, appropriate contractual safeguards (including standard contractual clauses), the necessity of the transfer to perform our contract with you, or your explicit consent. For transfers of EU personal data outside the EEA, we rely on Standard Contractual Clauses and related safeguards.
8. Data Retention
We keep personal data only for as long as needed for the purposes described in this policy:
- Account data — for the life of your account, and for a reasonable period afterwards to meet legal, tax, and audit obligations.
- Usage and analysis summaries — retained while your account is active to provide session history, then deleted or anonymized.
- Billing records — retained as required by applicable UAE tax and accounting law.
You may request deletion of your account and associated personal data at any time by emailing contact@pulsenox.com. We will complete verified deletion requests within 30 days, subject to any records we must retain by law.
9. Security
We implement appropriate technical and organizational measures to protect personal data. Passwords are hashed and never stored in plaintext. Access to data is restricted by row-level security so each user can only access their own records. All traffic is encrypted in transit using TLS. We maintain access controls, monitoring, and recovery procedures. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident. Where a personal data breach is likely to create a risk to your rights, we will notify the UAE Data Office and affected individuals without undue delay, in line with applicable law.
10. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you and be informed how it is processed;
- Request correction of inaccurate or incomplete data;
- Request erasure of your data;
- Restrict or object to certain processing;
- Receive your data in a structured, machine-readable format (data portability);
- Withdraw consent where processing is based on consent; and
- Object to automated decision-making that produces legal or similarly significant effects.
To exercise any of these rights, contact contact@pulsenox.com. We will respond within the timeframe required by applicable law and may need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.
11. Children's Data
AIDEN and our other products are business tools intended for professional use by adults. They are not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
12. Cookies & Similar Technologies
We use only the cookies and local browser storage necessary to operate the service — for example, to keep you signed in and to remember your preferences. We do not use advertising cookies. Where any non-essential analytics are introduced, we will update this policy and, where required, request your consent.
13. Business Customers & Data Processing Agreements
Where Pulsenox processes personal data on behalf of a business customer, we act on that customer's documented instructions and can provide a Data Processing Agreement (DPA) that sets out the required data-protection terms, including the sub-processors listed above. To request a DPA, contact contact@pulsenox.com.
14. Complaints
If you have a concern about how we handle your data, please contact us first at contact@pulsenox.com so we can resolve it. You also have the right to lodge a complaint with the UAE Data Office. If you are in the EU/EEA, you may also complain to your local data-protection supervisory authority.
15. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify registered users by email or in-app notice. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.