Security & Compliance

Trust the feedback. Protect the data.

Pulse is built to give organisations confidence in both the feedback they collect and the information behind it.

From secure feedback capture to controlled access, responsible AI and independently tested security controls, protection is built into the way Pulse operates.

  • Cyber Essentials certified
  • UK data residency
  • UK GDPR & Data Protection Act 2018
  • ICO registered
Secure by design

Your data is protected

Pulse operates on AWS infrastructure configured for UK data residency.

We use technical and organisational controls designed to protect information throughout its lifecycle – from collection and storage through to access, analysis and deletion.

  • Encryption

    Data is encrypted in transit and at rest.

  • Role-based access

    Users only see information appropriate to their role and organisational permissions.

  • Multi-factor authentication

    MFA provides an additional layer of account protection.

  • Single sign-on

    SSO can support centralised identity and access management for organisations that require it.

  • Audit logging

    Important administrative, configuration and system activity is recorded to support security and accountability.

Protecting the integrity of every response

Feedback you can trust

Making feedback easy to give is valuable only if organisations can trust what they receive.

Pulse uses automated review-integrity checks to identify unusual or potentially suspicious submission patterns.

This can include combinations of permitted technical and behavioural signals.

Where a submission is considered high risk, it can be separated from trusted reporting and referred for human review before being included in organisational results.

  • Automated integrity checks

    Detect unusual submission patterns.

  • Pattern monitoring

    Identify risks that may only become visible across multiple responses.

  • Human review

    Flagged activity can be assessed by authorised members of the technical team.

  • Protected methodology

    Detailed fraud-detection rules and thresholds are kept confidential to protect the effectiveness of the system.

Responsible AI

AI supports people. It doesn't replace them.

Pulse uses AI-assisted analysis to help authorised users understand large volumes of feedback.

It can help:

  • Identify themes and recurring patterns
  • Summarise feedback
  • Analyse sentiment
  • Highlight emerging areas for attention
  • Support service-improvement insight

AI-generated insight is provided as decision support.

Pulse does not make employment, disciplinary, safeguarding, promotion, remuneration or similarly significant decisions about individuals on behalf of customers.

Human users remain responsible for reviewing information, applying professional judgement and deciding what action to take.

Data protection

Clear responsibilities. Controlled processing.

When an organisation uses Pulse to collect and analyse feedback, that organisation will generally act as the Data Controller and Thankyu Limited acts as the Data Processor.

Pulse is designed to support customers’ responsibilities under UK data-protection law through measures including:

  • Data minimisation
  • Controlled access
  • Secure processing
  • Retention and deletion controls
  • Support for data-subject requests
  • Incident-management procedures
  • Appropriate controls over Sub-processors

Our Data Processing Terms form part of the contractual arrangements provided to Pulse customers.

Anonymised benchmarking

Pulse may create aggregated and anonymised information to support benchmarking, research, product development and sector insights.

We do not use identifiable personal information for cross-customer benchmarking.

Independently supported assurance

Security is an ongoing process

Pulse operates within Thankyu Limited’s information-security environment.

Our security programme includes:

  • Cyber Essentials

    Independent technical verification of controls designed to protect against common cyber threats.

  • Vulnerability management

    Routine identification and management of potential technical weaknesses.

  • Independent penetration testing

    Additional independent testing of platform security.

  • Backup & recovery

    Regular backups and documented recovery arrangements support service resilience.

  • Incident response

    Defined processes support the identification, escalation, containment and management of security incidents.

Access follows responsibility

Pulse uses role-based permissions so that people can access the information required for their role without unnecessary access to other data.

  • Staff

    Can access appropriate personal feedback and recognition information made available to them.

  • Managers

    Can access information for relevant people, teams, services or locations according to their permissions.

  • Senior leaders

    Can access appropriate aggregated organisational insight and reporting.

  • Technical personnel

    Access to sensitive technical and review-integrity information is restricted to authorised personnel where required for legitimate operational purposes.

DPIA & procurement support

Need to complete a security review or DPIA?

Whether a Data Protection Impact Assessment is required depends on how an organisation intends to use Pulse.

Customers remain responsible for determining whether their particular implementation requires a DPIA.

We make that process easier. Thankyu Limited can provide:

  • Data Protection & DPIA Support Information
  • Details of Pulse processing activities
  • Information about security controls
  • Relevant Sub-processor information
  • Data-location and transfer information
  • Assistance with customer DPIA questionnaires
  • Additional security information where reasonably required for procurement

Built for scrutiny

Pulse combines secure infrastructure, controlled access, feedback-integrity protection and responsible analysis so organisations can turn real-world feedback into insight with confidence.

Frequently asked questions

Where is Pulse data hosted?

Pulse operates on AWS infrastructure configured for UK data residency.

Is Pulse independently certified?

Thankyu Limited holds Cyber Essentials Plus and ISO/IEC 27001 certification.

Is data encrypted?

Yes. Pulse data is encrypted in transit and at rest.

Does Pulse use AI to make decisions about staff?

No. AI-assisted features help authorised users identify themes, sentiment, patterns and insights. Human users remain responsible for interpretation and decision-making.

Can feedback be anonymous?

Pulse can support anonymous feedback where this is enabled within the customer's configuration.

Who is responsible for GDPR?

Where Pulse processes feedback on behalf of a customer, the customer will generally act as Data Controller and Thankyu Limited acts as Data Processor.

Can you help with our DPIA or security questionnaire?

Yes. We provide Data Protection & DPIA Support Information and can provide appropriate information to help customers complete their own assessment or procurement process.

Give your people recognition you can act on.