Privacy Notice
This Privacy Notice describes the privacy practices for PulseIQ EMS Management, a Veltiq LLC product, effective August 28, 2026.
1. Scope and roles
This notice covers public website visitors, agency evaluation applicants, customer administrators, and authorized PulseIQ users. For customer-controlled workforce and operational data, the customer generally determines why and how the information is used, while Veltiq LLC processes it to provide the contracted service. Applicable customer agreements define the parties’ roles for each data category.
2. Information collected
- Evaluation application: agency name and type, address, website, phone number, approximate personnel, station and ambulance counts, and the authorized contact’s name, work email and phone.
- Account and identity: name, work email, role, agency membership, authentication status, security-factor and recovery events, and administrator-approved access.
- Customer content: EMS workforce credentials, training, scheduling, HR, fleet, supply, finance, CQI, configuration, documents, and other data the customer chooses to enter within its authorized scope.
- Service and security records: timestamps, request and audit events, session and authorization outcomes, application errors, delivery results, configuration changes, and limited technical metadata used to secure and operate the service.
- Commercial records: plan, subscription, entitlement, contract, invoice, payment or complimentary-pilot status, billing contact, onboarding, provisioning, support, and pilot-readiness records.
3. Intended uses
Information may be used to evaluate agency requests; verify authority; create and secure approved accounts; provide subscribed modules; enforce tenant, role, entitlement, and activation boundaries; deliver transactional email; bill or administer an approved complimentary pilot; provide support; monitor reliability; investigate misuse or incidents; meet legal obligations; and improve the service using appropriately limited information.
4. Disclosures and subprocessors
Veltiq LLC discloses information only to personnel with a business need, customer-authorized users, approved service providers, professional advisers under appropriate duties, or authorities when legally required. Current infrastructure providers and processing purposes are listed in the Subprocessor Disclosure. A payment provider has not been selected or activated.
5. Advertising, sale, and tracking
PulseIQ is not designed to sell personal information or share it for cross-context behavioral advertising. A current source review found no third-party advertising pixel or behavioral analytics script on the public pages. Infrastructure providers may still process ordinary request metadata necessary to deliver and secure the site.
6. Retention and deletion
Retention is limited to operational, contractual, security, tax, dispute, and legal needs. Applicable customer agreements and approved operating policies govern application disposition, customer-configured records, audit/security evidence, support cases, billing records, backups, post-termination export, legal holds, and verified deletion.
7. Security and shared responsibility
PulseIQ uses authentication, tenant-scoped authorization, role and entitlement gates, forced row-level security, service-only administrative paths, encryption provided by infrastructure vendors, audit evidence, guarded deployment, and environment separation. No security program eliminates all risk. Customers remain responsible for authorized-user selection, endpoint security, least-privilege roles, lawful data entry, and timely reporting of suspected compromise.
8. PHI and sensitive information
Until the PHI/BAA gate is formally closed, customers must not enter PHI into PulseIQ or include PHI in email, support requests, filenames, or free-text fields. Supabase requires a signed BAA, its HIPAA add-on, and specific customer-managed controls for PHI projects. Resend’s standard DPA describes email addresses and message content as processed data and lists sensitive data as not applicable; accordingly, PulseIQ transactional email must not contain PHI unless separate written approval is obtained.
9. Data location and transfers
Current service providers operate infrastructure in the United States and may process data in other disclosed locations under their agreements. Applicable data-processing terms govern international transfer requirements.
10. Privacy choices and requests
Depending on applicable law and the customer’s role, individuals may have rights to access, correct, delete, restrict, or obtain information about certain processing. Requests should be sent to support@pulseiqmanagement.com and should identify the relevant agency. Veltiq LLC may need to route customer-controlled data requests to the agency and verify identity and authority.
11. Children
PulseIQ is a business service for EMS organizations and is not directed to children. Customers are responsible for ensuring any workforce or training records involving minors are entered and managed lawfully.
12. Changes and contact
Material changes will be communicated by publishing an updated version and effective date. Privacy and security inquiries: support@pulseiqmanagement.com. Commercial inquiries: sales@pulseiqmanagement.com.