Privacy Policy

How Kreate Retail Ltd processes personal data when you use Pulse, our workplace platform for organisation teams.

1. Who this policy is for

Pulse is a workplace platform (mobile app and related admin/web services) for organisations such as retailers and field teams. It supports communication, learning, tasks, forms, scheduling, and related workplace features.

This Privacy Policy explains how Kreate Retail Ltd processes personal data when you use Pulse.

Pulse is not a consumer social network. Access is normally provided by your employer or organisation (“Customer Organisation”). There is no public self-sign-up in the mobile app.

2. Roles: Kreate and your organisation

Depending on the relationship:

  • Customer Organisation (your employer / brand / hub) typically decides why workplace data is processed (for example: staffing, training compliance, store operations). In many cases they act as an independent controller (or joint controller) of employee/user data.
  • Kreate Retail Ltd provides Pulse as a platform and processes personal data to host and operate the service. For customer workplace data we typically act as a processor on the Customer Organisation’s instructions, except where we process data for our own purposes (for example: platform security, billing the organisation, product diagnostics), in which case we act as a controller.

If you are an end user, many privacy requests (access, correction, deletion) should start with your organisation’s admin or HR/IT contact. We will support Customer Organisations in handling those requests.

3. Personal data we process

The exact data depends on which modules your organisation enables and how you use Pulse.

3.1 Account and profile data

  • Email address and authentication credentials (passwords are hashed/managed by our auth provider; we do not store plaintext passwords)
  • Name, username, job title, department, role, avatar/profile photo
  • Organisation / hub membership and role within that organisation
  • Preferred language and basic profile preferences (for example presence or notification settings)
  • Account status (active / deactivated)

Accounts are created or invited by organisation admins (or related admin tools), not by public registration in the app.

3.2 Workplace content you create or receive

  • Chat messages and channel membership
  • Hub/space posts, comments, reactions, and media attachments
  • Tasks, assignments, completion status, and related notes
  • Forms and survey responses
  • Training progress, lesson activity, quiz/knowledge-check answers, and related scores
  • Files or policy documents your organisation makes available
  • Notifications and in-app alerts

3.3 Location data

With your permission, Pulse may collect precise location while the app is in use to:

  • Record where a form response was completed (when a form includes a location question)
  • Verify clock-in / clock-out and related workplace geofence checks where your organisation enables that feature

We do not use background “always-on” location tracking for advertising. Location is used for the workplace features above.

3.4 Camera and photo library

With your permission, Pulse may access your camera and/or photo library so you can:

  • Set a profile photo
  • Attach images to chats, posts, forms, or similar workplace content
  • Capture images for features your organisation enables (for example stories or media attachments)

3.5 Device, push, and diagnostics data

  • Device type, OS version, app version, and similar technical identifiers needed to run the app
  • Push notification tokens (to deliver workplace notifications)
  • IP address and security/audit logs related to sign-in and important account events
  • Crash and performance diagnostics (for example via error-monitoring tools) to keep the service reliable

3.6 Admin and organisation configuration

Organisation admins may configure hubs, users, roles, modules, training, forms, schedules, and similar settings. That configuration can include personal data about staff.

3.7 Data we do not intentionally collect

  • We do not sell personal data.
  • We do not use the mobile app for end-user payments or in-app purchases. Organisations pay for Pulse outside the app.
  • We do not use App Tracking Transparency / advertising ID tracking for cross-app advertising.

4. How we use personal data

We use personal data to:

  • Provide, operate, and secure the Pulse platform
  • Authenticate users and enforce organisation access controls (including MFA where configured)
  • Deliver the workplace features your organisation enables (chat, hub, tasks, training, forms, schedule, etc.)
  • Send push and in-app notifications related to work activity
  • Provide admin tools, reporting, and audit logs to Customer Organisations
  • Diagnose crashes, prevent abuse, and improve reliability and performance
  • Comply with law and enforce our terms with Customer Organisations
  • Communicate with Customer Organisations about the service (support, security, service changes)

We do not use workplace content to send you third-party marketing offers inside the mobile app.

6. Sharing of personal data

We may share personal data with:

6.1 Your organisation and other users in your hubs

Content and profile information may be visible to other authorised users in your organisation according to roles and the features in use (for example chat participants, hub members, managers).

6.2 Service providers (subprocessors)

We use vetted providers to host and operate Pulse, including for example:

Provider Purpose
Supabase Database, authentication, storage, realtime, edge functions
Expo / EAS Mobile builds, updates, push delivery infrastructure
Apple / Google Delivery of push notifications on iOS / Android
Sentry Crash and error monitoring
Google Gemini (optional) AI-assisted grading of training knowledge-check answers, only when configured for an organisation

A fuller subprocessors list may be provided to Customer Organisations under a DPA.

6.3 Legal and safety

We may disclose data if required by law, or to protect users, Customer Organisations, or Kreate from fraud, security threats, or harm.

6.4 Business transfers

If Kreate is involved in a merger, acquisition, or asset sale, personal data may transfer as part of that transaction under appropriate protections.

We do not sell personal data to data brokers.

7. International transfers

Pulse may process data in the United Kingdom, European Economic Area, United States, or other locations where we or our providers operate.

Where required, we use appropriate transfer safeguards (for example standard contractual clauses or equivalent mechanisms) and supplementary measures as needed.

8. Retention

We retain personal data only as long as needed for the purposes above, including:

  • Active accounts: for the life of the account / organisation subscription
  • After organisation offboarding or account deactivation: for a limited period needed for security, disputes, backups, and legal obligations (typically up to 24 months unless a shorter or longer period is required)
  • Audit / security logs: retained for security and compliance needs
  • Backups: may persist for a limited backup cycle after deletion from live systems

Customer Organisations may set additional retention or export requirements by contract.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability / complaint to a supervisory authority (in the UK: the Information Commissioner’s Office).

How to exercise rights

  1. Start with your organisation (admin, manager, HR, or IT). They control workplace access and often the primary record of your employment data.
  2. You may also email josh.king@kreate-retail.com. We may need to verify your identity and coordinate with your Customer Organisation.

Account deletion

To ask us to delete your Pulse account and associated personal data, use the delete account page.

Because Pulse accounts are organisation-managed:

  • End users generally cannot self-delete the whole account inside the mobile app.
  • Your organisation’s admin can deactivate or remove access.
  • Deletion or anonymisation of underlying personal data is handled with the Customer Organisation (and by Kreate on request/instruction), subject to legal retention needs.

You can still remove optional device permissions (location, camera, photos, notifications) in your device settings at any time.

10. Security

We use technical and organisational measures appropriate to a B2B workplace platform, including encryption in transit, access controls, authentication options (including MFA where configured), and monitoring. No method of transmission or storage is perfectly secure.

11. Children

Pulse is a workplace tool for organisation members. It is not directed at children under 16, and we do not knowingly create accounts for children under 16. If you believe a child has been given access incorrectly, contact us and your organisation’s admin.

12. Third-party links and customer content

Pulse may contain links or documents provided by your organisation. Their privacy practices are their responsibility. Please review any policies your employer provides alongside this one.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, notify Customer Organisations of material changes.

14. Contact

Kreate Retail Ltd
4th Floor, 95 Gresham Street
London, EC2V 7AB
United Kingdom

Email: josh.king@kreate-retail.com

For organisation/legal/DPA enquiries, use the same contact and mark the subject “Privacy / DPA”.

15. App Store / Play Store summary

For store questionnaires, Pulse may process:

  • Contact info (email, name)
  • User content (messages, posts, forms, training responses, photos you upload)
  • Identifiers (account IDs, push tokens)
  • Location (precise, only with permission, for forms / clock-in features)
  • Diagnostics (crash logs)
  • Usage data (feature activity needed to operate the service)

Data is used to provide the workplace app, not to track you across third-party apps for advertising.