Trust the feedback. Protect the data.
Pulse is built to give organisations confidence in both the feedback they collect and the information behind it.
From secure feedback capture to controlled access, responsible AI and independently tested security controls, protection is built into the way Pulse operates.
- Cyber Essentials certified
- UK data residency
- UK GDPR & Data Protection Act 2018
- ICO registered
Your data is protected
Pulse operates on AWS infrastructure configured for UK data residency.
We use technical and organisational controls designed to protect information throughout its lifecycle – from collection and storage through to access, analysis and deletion.
Encryption
Data is encrypted in transit and at rest.
Role-based access
Users only see information appropriate to their role and organisational permissions.
Multi-factor authentication
MFA provides an additional layer of account protection.
Single sign-on
SSO can support centralised identity and access management for organisations that require it.
Audit logging
Important administrative, configuration and system activity is recorded to support security and accountability.
Feedback you can trust
Making feedback easy to give is valuable only if organisations can trust what they receive.
Pulse uses automated review-integrity checks to identify unusual or potentially suspicious submission patterns.
This can include combinations of permitted technical and behavioural signals.
Where a submission is considered high risk, it can be separated from trusted reporting and referred for human review before being included in organisational results.
Automated integrity checks
Detect unusual submission patterns.
Pattern monitoring
Identify risks that may only become visible across multiple responses.
Human review
Flagged activity can be assessed by authorised members of the technical team.
Protected methodology
Detailed fraud-detection rules and thresholds are kept confidential to protect the effectiveness of the system.
AI supports people. It doesn't replace them.
Pulse uses AI-assisted analysis to help authorised users understand large volumes of feedback.
It can help:
- Identify themes and recurring patterns
- Summarise feedback
- Analyse sentiment
- Highlight emerging areas for attention
- Support service-improvement insight
AI-generated insight is provided as decision support.
Pulse does not make employment, disciplinary, safeguarding, promotion, remuneration or similarly significant decisions about individuals on behalf of customers.
Human users remain responsible for reviewing information, applying professional judgement and deciding what action to take.
Clear responsibilities. Controlled processing.
When an organisation uses Pulse to collect and analyse feedback, that organisation will generally act as the Data Controller and Thankyu Limited acts as the Data Processor.
Pulse is designed to support customers’ responsibilities under UK data-protection law through measures including:
- Data minimisation
- Controlled access
- Secure processing
- Retention and deletion controls
- Support for data-subject requests
- Incident-management procedures
- Appropriate controls over Sub-processors
Our Data Processing Terms form part of the contractual arrangements provided to Pulse customers.
Anonymised benchmarking
Pulse may create aggregated and anonymised information to support benchmarking, research, product development and sector insights.
We do not use identifiable personal information for cross-customer benchmarking.
Security is an ongoing process
Pulse operates within Thankyu Limited’s information-security environment.
Our security programme includes:
Cyber Essentials
Independent technical verification of controls designed to protect against common cyber threats.
Vulnerability management
Routine identification and management of potential technical weaknesses.
Independent penetration testing
Additional independent testing of platform security.
Backup & recovery
Regular backups and documented recovery arrangements support service resilience.
Incident response
Defined processes support the identification, escalation, containment and management of security incidents.
Access follows responsibility
Pulse uses role-based permissions so that people can access the information required for their role without unnecessary access to other data.
Staff
Can access appropriate personal feedback and recognition information made available to them.
Managers
Can access information for relevant people, teams, services or locations according to their permissions.
Senior leaders
Can access appropriate aggregated organisational insight and reporting.
Technical personnel
Access to sensitive technical and review-integrity information is restricted to authorised personnel where required for legitimate operational purposes.
Need to complete a security review or DPIA?
Whether a Data Protection Impact Assessment is required depends on how an organisation intends to use Pulse.
Customers remain responsible for determining whether their particular implementation requires a DPIA.
We make that process easier. Thankyu Limited can provide:
- Data Protection & DPIA Support Information
- Details of Pulse processing activities
- Information about security controls
- Relevant Sub-processor information
- Data-location and transfer information
- Assistance with customer DPIA questionnaires
- Additional security information where reasonably required for procurement
Built for scrutiny
Pulse combines secure infrastructure, controlled access, feedback-integrity protection and responsible analysis so organisations can turn real-world feedback into insight with confidence.
Frequently asked questions
Where is Pulse data hosted?
Pulse operates on AWS infrastructure configured for UK data residency.
Is Pulse independently certified?
Thankyu Limited holds Cyber Essentials Plus and ISO/IEC 27001 certification.
Is data encrypted?
Yes. Pulse data is encrypted in transit and at rest.
Does Pulse use AI to make decisions about staff?
No. AI-assisted features help authorised users identify themes, sentiment, patterns and insights. Human users remain responsible for interpretation and decision-making.
Can feedback be anonymous?
Pulse can support anonymous feedback where this is enabled within the customer's configuration.
Who is responsible for GDPR?
Where Pulse processes feedback on behalf of a customer, the customer will generally act as Data Controller and Thankyu Limited acts as Data Processor.
Can you help with our DPIA or security questionnaire?
Yes. We provide Data Protection & DPIA Support Information and can provide appropriate information to help customers complete their own assessment or procurement process.