1. Who this policy is for
Pulse is a workplace platform (mobile app and related admin/web services) for organisations such as retailers and field teams. It supports communication, learning, tasks, forms, scheduling, and related workplace features.
This Privacy Policy explains how Kreate Retail Ltd processes personal data when you use Pulse.
Pulse is not a consumer social network. Access is normally provided by your employer or organisation (“Customer Organisation”). There is no public self-sign-up in the mobile app.
2. Roles: Kreate and your organisation
Depending on the relationship:
- Customer Organisation (your employer / brand / hub) typically decides why workplace data is processed (for example: staffing, training compliance, store operations). In many cases they act as an independent controller (or joint controller) of employee/user data.
- Kreate Retail Ltd provides Pulse as a platform and processes personal data to host and operate the service. For customer workplace data we typically act as a processor on the Customer Organisation’s instructions, except where we process data for our own purposes (for example: platform security, billing the organisation, product diagnostics), in which case we act as a controller.
If you are an end user, many privacy requests (access, correction, deletion) should start with your organisation’s admin or HR/IT contact. We will support Customer Organisations in handling those requests.
3. Personal data we process
The exact data depends on which modules your organisation enables and how you use Pulse.
3.1 Account and profile data
- Email address and authentication credentials (passwords are hashed/managed by our auth provider; we do not store plaintext passwords)
- Name, username, job title, department, role, avatar/profile photo
- Organisation / hub membership and role within that organisation
- Preferred language and basic profile preferences (for example presence or notification settings)
- Account status (active / deactivated)
Accounts are created or invited by organisation admins (or related admin tools), not by public registration in the app.
3.2 Workplace content you create or receive
- Chat messages and channel membership
- Hub/space posts, comments, reactions, and media attachments
- Tasks, assignments, completion status, and related notes
- Forms and survey responses
- Training progress, lesson activity, quiz/knowledge-check answers, and related scores
- Files or policy documents your organisation makes available
- Notifications and in-app alerts
3.3 Location data
With your permission, Pulse may collect precise location while the app is in use to:
- Record where a form response was completed (when a form includes a location question)
- Verify clock-in / clock-out and related workplace geofence checks where your organisation enables that feature
We do not use background “always-on” location tracking for advertising. Location is used for the workplace features above.
3.4 Camera and photo library
With your permission, Pulse may access your camera and/or photo library so you can:
- Set a profile photo
- Attach images to chats, posts, forms, or similar workplace content
- Capture images for features your organisation enables (for example stories or media attachments)
3.5 Device, push, and diagnostics data
- Device type, OS version, app version, and similar technical identifiers needed to run the app
- Push notification tokens (to deliver workplace notifications)
- IP address and security/audit logs related to sign-in and important account events
- Crash and performance diagnostics (for example via error-monitoring tools) to keep the service reliable
3.6 Admin and organisation configuration
Organisation admins may configure hubs, users, roles, modules, training, forms, schedules, and similar settings. That configuration can include personal data about staff.
3.7 Data we do not intentionally collect
- We do not sell personal data.
- We do not use the mobile app for end-user payments or in-app purchases. Organisations pay for Pulse outside the app.
- We do not use App Tracking Transparency / advertising ID tracking for cross-app advertising.
4. How we use personal data
We use personal data to:
- Provide, operate, and secure the Pulse platform
- Authenticate users and enforce organisation access controls (including MFA where configured)
- Deliver the workplace features your organisation enables (chat, hub, tasks, training, forms, schedule, etc.)
- Send push and in-app notifications related to work activity
- Provide admin tools, reporting, and audit logs to Customer Organisations
- Diagnose crashes, prevent abuse, and improve reliability and performance
- Comply with law and enforce our terms with Customer Organisations
- Communicate with Customer Organisations about the service (support, security, service changes)
We do not use workplace content to send you third-party marketing offers inside the mobile app.
5. Legal bases (UK GDPR / GDPR)
Where UK GDPR / GDPR applies, we rely on one or more of:
- Contract / steps prior to contract — providing the platform to Customer Organisations and authenticated users
- Legitimate interests — securing the service, preventing abuse, improving reliability, supporting B2B operations (balanced against your rights)
- Legal obligation — where we must retain or disclose data
- Consent — where required for device permissions (for example location, camera, photos, push notifications). You can withdraw device permission in your OS settings; some features will then be unavailable
- Customer Organisation instructions — where we act as processor
Your employer may rely on additional bases (for example employment contract or legitimate interests) for workplace monitoring features such as shift geofencing. Ask your organisation for its employee privacy notice if you need that detail.
7. International transfers
Pulse may process data in the United Kingdom, European Economic Area, United States, or other locations where we or our providers operate.
Where required, we use appropriate transfer safeguards (for example standard contractual clauses or equivalent mechanisms) and supplementary measures as needed.
8. Retention
We retain personal data only as long as needed for the purposes above, including:
- Active accounts: for the life of the account / organisation subscription
- After organisation offboarding or account deactivation: for a limited period needed for security, disputes, backups, and legal obligations (typically up to 24 months unless a shorter or longer period is required)
- Audit / security logs: retained for security and compliance needs
- Backups: may persist for a limited backup cycle after deletion from live systems
Customer Organisations may set additional retention or export requirements by contract.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability / complaint to a supervisory authority (in the UK: the Information Commissioner’s Office).
How to exercise rights
- Start with your organisation (admin, manager, HR, or IT). They control workplace access and often the primary record of your employment data.
- You may also email josh.king@kreate-retail.com. We may need to verify your identity and coordinate with your Customer Organisation.
Account deletion
To ask us to delete your Pulse account and associated personal data, use the delete account page.
Because Pulse accounts are organisation-managed:
- End users generally cannot self-delete the whole account inside the mobile app.
- Your organisation’s admin can deactivate or remove access.
- Deletion or anonymisation of underlying personal data is handled with the Customer Organisation (and by Kreate on request/instruction), subject to legal retention needs.
You can still remove optional device permissions (location, camera, photos, notifications) in your device settings at any time.
10. Security
We use technical and organisational measures appropriate to a B2B workplace platform, including encryption in transit, access controls, authentication options (including MFA where configured), and monitoring. No method of transmission or storage is perfectly secure.
11. Children
Pulse is a workplace tool for organisation members. It is not directed at children under 16, and we do not knowingly create accounts for children under 16. If you believe a child has been given access incorrectly, contact us and your organisation’s admin.
12. Third-party links and customer content
Pulse may contain links or documents provided by your organisation. Their privacy practices are their responsibility. Please review any policies your employer provides alongside this one.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, notify Customer Organisations of material changes.
14. Contact
Kreate Retail Ltd
4th Floor, 95 Gresham Street
London, EC2V 7AB
United Kingdom
Email: josh.king@kreate-retail.com
For organisation/legal/DPA enquiries, use the same contact and mark the subject “Privacy / DPA”.
15. App Store / Play Store summary
For store questionnaires, Pulse may process:
- Contact info (email, name)
- User content (messages, posts, forms, training responses, photos you upload)
- Identifiers (account IDs, push tokens)
- Location (precise, only with permission, for forms / clock-in features)
- Diagnostics (crash logs)
- Usage data (feature activity needed to operate the service)
Data is used to provide the workplace app, not to track you across third-party apps for advertising.