What we collect, and what we refuse to
This policy is written to be read. If anything here is unclear, that is a defect and we would like to know about it.
- Last updated
- 12 June 2026
- Last updated
Our role
For the employee data your organisation puts into TeamPulse, your organisation is the controller and we are the processor. We act on their documented instructions and nothing else.
For account data we need to operate the service, such as your login and billing contact, we are the controller.
What we process
Employee records, objectives, delivery records, performance agreements and the survey responses people submit. Where you enable them, calendar and workload metadata used to compute the wellness signal.
We do not process message bodies, document contents, screen captures or keystrokes. There is no setting that enables this.
Why we process it
To provide the service your organisation has asked for: connecting strategy, delivery and people records, and producing the reporting built on them.
We do not sell personal data. We do not use customer data to train models that serve other customers.
Kenya Data Protection Act, 2019
For customers and employees in Kenya, this policy is written to conform with the Data Protection Act, 2019. TeamPulse is registered with the Office of the Data Protection Commissioner as a data controller and a data processor.
The rights described below are those granted under Part V of the Act: to be informed, to access, to correct, to request deletion, to object to processing, and to data portability. Complaints can be made to us at privacy@teampulse.app, and separately to the Office of the Data Protection Commissioner at any time.
Your rights
Every employee can view the complete record TeamPulse holds about them, export it in an open format, and request deletion, directly in the product rather than by raising a ticket.
Where your organisation is the controller, some requests are routed to them, and the product makes that routing visible rather than silent.
Retention
Retention periods are set by your organisation per record type, within the limits the law requires. When a period expires, records are deleted rather than archived indefinitely.
On termination of a contract we retain data for 30 days so it can be recovered if you change your mind, then delete it and issue a certificate of deletion.
International transfers
You can elect EU-only or Kenya-resident data storage on any plan, and cross-border transfers follow section 48 of the Kenya Data Protection Act, 2019. Where data does move between regions, transfers rely on Standard Contractual Clauses and are documented in the DPA.
Our subprocessor list is published, and we notify customers before adding to it.
Contact
Write to privacy@teampulse.app. Our Data Protection Officer can be reached at the same address, and we respond within five working days.
Questions your legal team needs answered?
We will send the DPA, subprocessor list and certifications without making you sign anything first.
