Privacy policy
What Pulse Recruit collects, why, where it is kept, and how you get it back or get it deleted.
Last updated 9 August 2026
In plain language
Two different kinds of personal data pass through Pulse and they are governed differently. Your account data, meaning your name, work email and how you use the product, is ours to answer for. The candidate and client records you load are yours to answer for, and we only handle them on your instructions.
Everything is stored and processed in London, in a dedicated database. Connections run over TLS 1.2 or better, data at rest including backups is encrypted with AES-256, and access is enforced by row-level policies in the database that check your workspace membership on every read and every write.
We do not sell personal data, we do not run advertising trackers, and we do not use your candidate records to train anyone's models. A short, named list of sub-processors is in section 6, and it is the whole list.
You can export your candidates, clients and history at any time, including after you cancel. If you want your workspace deleted, write to operations@recruitergtm.com and we will delete it within 30 days.
This summary is here to be read, not to replace the document below. Where the two differ, the document is what applies.
Who this policy is from
Pulse Recruit is a recruitment applicant tracking system operated by RecruiterGTM. In this document, Pulse, we and us mean RecruiterGTM operating the Pulse Recruit service at pulse.recruitergtm.io.
We are a small team and we do not have a Data Protection Officer, because the law does not require one at our scale and we would rather tell you that than name a role nobody holds. Every privacy question, data request or complaint goes to operations@recruitergtm.com and a person answers it.
The distinction that matters most: controller and processor
An applicant tracking system holds personal data about two different groups of people, and the same company is not responsible for both in the same way. Getting this right decides who a person goes to when they want their data.
For your account data, we are the data controller. We decided to collect your name and work email in order to run the service, so the decisions and the answers are ours.
For the candidate and client records inside your workspace, you are the data controller and we are your data processor. You chose to source those people, you decided what to record about them, and you decide how long to keep them. We hold and process those records on your instructions and for no purpose of our own.
In practice that means a candidate asking to be deleted asks you, not us, because it is your relationship and your lawful basis. If a candidate contacts us directly we will not act on their record ourselves. We will tell them who the controller is and pass the request to you without delay, then help you carry it out.
It also means you are responsible for having a lawful basis to hold the candidates you load, for telling them you hold their data, and for not loading categories of data the product is not built for. We do not accept health records, and Pulse is not built for them.
What we collect about you, the customer
This is the data we are the controller for. It is deliberately small.
- Account details: your name, work email address, and the password hash held by our authentication provider. We never see your password.
- Workspace details: your agency name, the workspace you belong to, and your role in it, which is what the database uses to decide what you can read and write.
- Billing details: your plan, your billing status, and the invoice history. Card details are handled by the payment provider and are never stored by us.
- Product usage: which features you use, credit consumption on the AI features, and the audit trail of significant actions in your workspace.
- Support correspondence: emails you send us and our replies.
- Technical logs: request logs and error reports generated by our hosting and database providers, which include IP address and browser user agent, and which we use to keep the service running and to investigate faults.
What passes through Pulse about candidates and clients
This is the data you are the controller for. What is in it is your choice, because you type it or import it.
In normal use it includes candidate names, contact details, work history, CVs and documents you upload, notes your team writes, pipeline stage and activity history, and the same kind of record for your client contacts.
Where you use the enrichment feature, contact details may be returned by an enrichment provider rather than typed by you. Where you use the AI features, the content of the records the question touches is sent to the model provider in order to answer it. Both are named in section 6.
We do not use your candidate or client records to train models, to build a shared database, or to market to the people in them. They exist to serve your workspace and nothing else.
Why we process it, and the legal bases
For the account data we control, these are the grounds we rely on under the UK GDPR and the EU GDPR.
- Performance of a contract: creating your account, running your workspace, providing support, and taking payment. Without this data there is no service to provide.
- Legitimate interests: keeping the service secure, preventing abuse, investigating faults, and understanding which features are used so we can improve them. We use the least data that answers the question.
- Legal obligation: keeping billing and tax records for the period the law requires.
- Consent: only where we ask for it explicitly, for example before sending product email you can opt out of. You can withdraw consent at any time and it does not affect anything done before you withdrew it.
- For candidate and client records, the legal basis is yours to establish as the controller, and it is usually legitimate interests in a recruitment context or the consent you collected. We process those records on your documented instructions.
Sub-processors: the whole list
These are the third parties that process data for us. This is the complete list as at the date at the top of this page, not a sample of it. We will update this page before adding a new one.
- Supabase: the database, authentication and file storage behind the product. It holds your workspace data, in the London region.
- Vercel: application hosting and the edge network the site runs on. It processes request data and technical logs.
- OpenAI: the model behind the AI features. It receives the content of the records a question touches, at the moment you ask a question, and only then.
- Exa: web research behind the BD research feature. It receives the search query, not your candidate records.
- Prospeo: contact enrichment. It receives the identifying details needed to look a person up, when you run an enrichment.
- Unipile: LinkedIn account connection and posting. It receives the LinkedIn account authorisation and the content you choose to publish.
Where your data is kept, and international transfers
Your workspace data is stored and processed in eu-west-2, the London region, in a database project dedicated to Pulse and shared with no other product. We do not offer a choice of region today, so if your policy requires a particular one, say so before you start a pilot rather than after.
Some sub-processors in section 6 operate outside the United Kingdom, and the AI, research and enrichment features send data to them when you use those features. Where that happens, the transfer is covered by the standard contractual clauses and equivalent safeguards in those providers' data processing terms.
If you would rather no data left the United Kingdom at all, the AI, research, enrichment and LinkedIn features are the ones to leave switched off. The core ATS does not depend on them.
Security
Every connection to Pulse runs over TLS 1.2 or better. There is no unencrypted route into the product.
Data at rest is encrypted with AES-256 by our database and storage provider, including automated backups.
Integration credentials and API keys you paste in are encrypted before they are stored, and they are never sent to the browser.
Access is enforced in the database rather than only in the interface. Every table carries a row-level security policy scoped to workspace membership, checked on every read and every write, so a bug in a screen cannot return another agency's records.
Inside RecruiterGTM, production data access is limited to the engineer who maintains the platform, is used only to investigate a fault you have reported, and is not used for support browsing.
We hold no security certifications today and we have not commissioned an independent penetration test. We would rather say that than imply an audit we have not had. The security page tracks what is held, in progress and planned.
How long we keep things
Your workspace data lives for as long as your workspace does. We do not expire your records for you, because a candidate you sourced two years ago is often the placement you make this quarter, and quietly deleting your pipeline would be a worse failure than keeping it.
When you cancel, your data stays available for export for at least 30 days. After that we delete the workspace and its records. Deletion is carried out by a person today rather than by an automated job, so if you want it done on a specific date, tell us and we will confirm when it is done. If you ask us to delete it sooner, we will.
Billing and tax records are kept for the period UK law requires, which is currently six years, and they are kept separately from your workspace data.
Technical logs are held on a rolling short window by our hosting and database providers and are not retained long term.
Deciding how long to keep an individual candidate record is a controller decision, which makes it yours. You can delete any record at any time and it is removed from the database, not hidden.
Your rights, and how to use them
If you are a Pulse customer, you have the following rights over the account data we control. If you are a candidate whose record sits in an agency's workspace, you have the same rights, and you exercise them against that agency because they are the controller. Ask us and we will tell you which agency holds you and pass your request on.
- Access: ask what we hold about you and get a copy of it.
- Rectification: have anything inaccurate corrected. Most account fields you can edit yourself in settings.
- Erasure: ask for your account and workspace to be deleted. We will do it within 30 days unless the law requires us to keep a specific record, such as an invoice, and we will tell you if that applies.
- Portability: get your candidates, clients and history in a machine-readable export, at any time, including after you cancel. This is a product feature, not a request queue.
- Objection: object to processing we base on legitimate interests, and we will stop unless we have grounds that override yours.
- Restriction: ask us to pause processing while a dispute about accuracy or grounds is resolved.
- Withdraw consent: where we relied on consent, take it back at any time.
How to make a request, and how to complain
Write to operations@recruitergtm.com. Say what you want and enough for us to identify you. We answer within 30 days, and we will tell you if a request is genuinely complicated enough to need longer.
There is no charge for a request unless it is repetitive or excessive, in which case we will tell you the reason before doing anything.
If you are not satisfied with how we handled it, you can complain to the Information Commissioner's Office in the United Kingdom, at ico.org.uk, or to your local supervisory authority in the European Union. We would rather you came to us first so we get the chance to fix it.
Cookies
Pulse uses authentication cookies to keep you signed in and nothing else. There is no analytics tracking and no advertising tracking. The detail is on the cookie policy page, which is a separate document because cookies are separately regulated.
Automated decision-making
Pulse does not make automated decisions with legal or similarly significant effects about candidates. The AI features summarise, draft and surface records for a human to act on, and the cold-spot signal is an activity indicator, not a score of a person's suitability. A recruiter decides.
Children
Pulse is a business tool sold to recruitment agencies and it is not directed at children. We do not knowingly collect data from anyone under 16 through the product itself.
Changes to this policy
When this policy changes, the date at the top changes and the version history at the bottom records what changed. For a change that materially affects you, we will email account holders rather than relying on you noticing.
Legal and privacy enquiries
Questions about this document, a data request, or anything else legal: write to us and a person will answer.
Email operations@recruitergtm.com. This document has been written to be clear and accurate, and it has not been reviewed by a lawyer.
Version history
- v1.0, 9 August 2026Initial version.