Engineurs Pulse
Privacy Policy
This public policy covers cookies, similar device storage, and personal information handled by the Pulse web application, PWA, and separate Android and iOS applications.
Cookies & Privacy
Last updated: 20 July 2026. This notice applies to the Pulse web application, installed Progressive Web App (PWA), and separate Engineurs Pulse CMS Android and iOS applications.
Scope and Responsible Organisation
This Cookies and Privacy Notice explains how Engineurs Limited, trading through the Engineurs Pulse service, collects and handles personal information. Engineurs Limited is registered in England and Wales under company number 09694217. Its registered office is 77 The Harley Building, New Cavendish Street, London, England, W1W 6XB.
Engineurs Limited is the controller for its own account administration, service security, support, and business operations. A customer organisation is normally the controller for project, workforce, activity, punch, and other business data that it places in Pulse. For that data, Engineurs Limited acts as the customer's processor or service provider and follows the customer's documented instructions. Contact your organisation first if your request concerns project or employment records.
Pulse is a business service for authorised personnel. It is not directed to children, and Engineurs Limited does not knowingly collect personal information from children through Pulse.
Public policy URL
Personal Information We Handle
- Identity and account data: name, work email address, user ID, organisation, role, permissions, Microsoft tenant and authentication identifiers, and optional Microsoft profile photo.
- Project and workforce data: project membership, discipline, assignments, activities, checklists, actual results, approvals, signatures, punches, comments, hours, dates, equipment, tags, and audit history.
- Files and media: photos, documents, file names, captions, attachment links, timestamps, and metadata uploaded by authorised users.
- Location: device location captured when an authorised user invokes a location-enabled field action. Pulse does not use location for advertising and does not intentionally collect background location.
- Technical and security data: IP address, browser or device type, operating system, app version, network state, request records, authentication events, sync status, diagnostics, crash information, and security logs.
- Support and communications: support requests, email messages, feedback, and records needed to investigate an issue.
We receive this information from you, your organisation, Microsoft Entra ID, the device you use, and authorised Pulse users. Project data may identify other people. Only upload information that your organisation is authorised to collect and use.
Purposes and Legal Bases
Engineurs Limited handles personal information to:
- authenticate users and enforce project and role permissions;
- provide project, commissioning, field, offline, reporting, approval, and audit functions;
- store, synchronise, reconcile, display, export, and protect authorised business records;
- send service, approval, security, and support communications;
- detect errors, prevent abuse, investigate incidents, and maintain service reliability;
- meet contractual, tax, accounting, legal, regulatory, and dispute obligations; and
- establish, exercise, or defend legal claims.
Where UK or EEA law applies, the legal basis is normally performance of a contract, legitimate interests in operating and securing a business service, compliance with legal obligations, or consent where the law requires it. A customer organisation determines the legal basis for the project and workforce information for which it is controller. You may withdraw consent at any time, without affecting earlier lawful processing.
Pulse does not use personal information for solely automated decisions that produce legal or similarly significant effects. Reports and status calculations support human project decisions.
Separate Android and iOS Mobile Applications
Engineurs Pulse CMS for Android and iOS is a native application separate from the PWA. It uses the same authorised Pulse service and project records, but stores data through native device facilities. The app should request a sensitive permission only when a user starts the related feature. A user may refuse a permission, but the related feature may then be unavailable.
| Mobile access | When and why it is used | Control |
|---|---|---|
| Camera | When a user chooses to take a project, activity, checklist, or punch photo. | Android or iOS permission settings; gallery or file selection may remain available. |
| Photos and files | When a user selects an attachment or saves authorised media for a field record. Older Android versions may expose a broader storage permission. | System photo picker, selected-photo access where supported, and operating-system permissions. |
| Precise or approximate location | When a user invokes a location-enabled field action so the business record can include its capture location. | Foreground permission and operating-system location settings. Pulse does not use location for advertising or intentional background tracking. |
| Microphone | The current Pulse feature set does not collect or use microphone data. | No microphone access is needed for current workflows. |
| Network and device state | To connect, authenticate, determine online or offline status, synchronise records, and troubleshoot failures. | Required for connected features; offline work remains subject to the records already stored on the device. |
| Diagnostics through Sentry | To capture crashes, errors, app version, device and operating-system details, network context, IP-derived context, and related user or account identifiers when present. | Used for security and service reliability, not advertising. Diagnostic data is restricted to authorised support personnel and configured retention controls. |
The native apps do not use advertising identifiers, serve behavioural advertising, track users across third-party apps or websites, or access contacts, call logs, SMS, health data, calendars, or financial information. Store privacy labels and Google Play Data safety answers must disclose all data handled by the released binary, including third-party SDK behaviour, and must match this notice.
Pulse accounts are provisioned by an organisation and Microsoft Entra ID. The current apps do not let the public create a Pulse account. An organisation admin can revoke app access. A user may request deletion using the contact route below. If a future app version supports account creation, it must also provide an in-app deletion route and the public web deletion route required by Google Play and Apple.
Store release check
Service Providers, Disclosures, and International Transfers
Personal information may be disclosed only as needed to:
- the customer organisation, project owners, contractors, and authorised project users according to their Pulse permissions;
- Microsoft, including Microsoft Entra ID, Microsoft Graph, Azure hosting, database, blob storage, and communication services;
- Sentry, for native app error and crash diagnostics;
- professional advisers, auditors, insurers, and support providers under duties of confidentiality;
- regulators, courts, law enforcement, or other parties where law requires or permits it; and
- a successor in a merger, reorganisation, financing, or sale, subject to appropriate safeguards.
Service providers may process information in the United Kingdom, European Economic Area, United States, or other countries where they operate. Where required, we use recognised transfer safeguards, such as an adequacy decision, the UK International Data Transfer Agreement or Addendum, or approved contractual clauses, with relevant technical and organisational measures.
Security, Retention, and Deletion
Pulse uses role-based access, Microsoft authentication, encrypted network connections, protected cloud services, audit records, backups, and access controls. No system can guarantee absolute security. Users must protect their devices and accounts, synchronise field work promptly, and report suspected access or loss.
We retain personal information only for the service, contractual, project, safety, audit, legal, and dispute periods that apply. Active project records normally remain for the customer's project retention period. Account and security records may remain while access is active and for a reasonable period afterwards. Support and diagnostic records are retained only as long as needed to resolve issues and protect the service. Backups age out under the applicable backup schedule.
On a valid deletion request, Engineurs Limited deletes or de-identifies data it controls unless retention is required for law, security, fraud prevention, contract, project integrity, audit, safety, or legal claims. Where a customer controls the record, Engineurs Limited forwards the request or acts on the customer's instructions. Removing a user account does not require deletion of business records that the customer must retain, but identifying fields will be restricted or removed where lawful and practical.
Your Privacy Rights
Depending on your location and the organisation that controls the data, you may have rights to receive information, access, correct, delete, restrict, object, withdraw consent, obtain a portable copy, opt out of sale, sharing, targeted advertising or qualifying profiling, and appeal a refused request. You also have the right not to receive unlawful discrimination for exercising a privacy right.
Submit a request to your organisation for project or employment data. You can also email sales@engineurs.com with the subject "Pulse Privacy Request", or write to the registered office above. State the right you want to exercise, the organisation and project involved, and the email address used for Pulse. We may verify identity and authority before acting. An authorised agent must provide proof of authority where local law permits agents.
We will respond within the period required by applicable law. UK users may complain to the Information Commissioner's Office. EEA users may complain to their local supervisory authority. Users elsewhere may contact their regional privacy regulator. Please contact us first so we can investigate.
Changes and Contact
We may update this notice when Pulse features, providers, legal requirements, or mobile releases change. The date above identifies the current version. We will give additional notice where a material change requires it.
Privacy contact: sales@engineurs.com. Postal address: Engineurs Limited, 77 The Harley Building, New Cavendish Street, London, England, W1W 6XB.
