1. Scope and Status of This Policy

This policy describes how Pulse Insights, LLC ("Pulse Insights", "we", "us") uses artificial intelligence in its products and operations.

This policy is provided for information. It is not incorporated into our Terms of Service and does not create contractual obligations. The contractual treatment of AI features and their outputs is set out in Section 6A of the Terms of Service. How data is handled, including data sent to model providers, is set out in our Data Usage Policy, which is incorporated into the Terms of Service. Where a signed master services agreement, statement of work, or data processing addendum applies, it controls.

2. Where We Use AI, and Where We Do Not

We use machine learning models, including large language models, in three places:

  • Classification and tagging of free-text responses. Open-ended survey responses are categorized against a taxonomy the client configures or approves.

  • Summarization and reporting. Generation of summaries, themes, and suggested findings from response data already collected.

  • Research and authoring support. Assistance in researching a client's site and drafting candidate survey and intervention content, before anything is deployed.

We do not use AI in the live end user session. Surveys and interventions are delivered by deterministic rules, using content written and approved in advance. No model runs in the request path, and no model generates or selects what an end user sees. An end user interacting with a Pulse survey or intervention is not interacting with an AI system.

This is a deliberate design choice. It keeps the behavior an end user encounters reviewable, reproducible, and attributable to a human decision.

3. Models and Providers

We build on models operated by third parties rather than training our own. The providers we use in the Services are OpenAI and Anthropic, both listed in our Subprocessors list.

We do not permit those providers to retain or train on data transmitted through the Services.

We do not use client data or personal data to train, fine-tune, or otherwise develop any model made available outside a client's own account.

Models and providers may change over time. Where a change would materially affect how a feature behaves, we will notify affected clients.

4. How We Handle Data Sent to Models

  • We send the minimum data required for a feature to function.

  • We apply filtering intended to remove personal data and sensitive personal data before transmission.

  • Data is encrypted in transit.

  • Model providers process the data on our instruction and are bound by their agreements with us.

  • Because these features run after collection rather than during a session, no end user data is transmitted to a model provider in real time.

Full detail is in the Data Usage Policy.

5. Accuracy and Limitations

Outputs from these features are generated probabilistically. They may be inaccurate, incomplete, or out of date, and may present incorrect information in a way that reads as confident and authoritative. This is a characteristic of the technology rather than a defect in the Services.

Identical inputs may produce different outputs at different times. Outputs are not necessarily unique, and similar outputs may be generated for other clients.

We state this plainly because the alternative is a client relying on an output in a way the technology does not support.

6. Human Oversight

Our oversight model is specific rather than general.

Nothing reaches an end user without human approval. Every survey and every intervention is reviewed and approved by a person before it is enabled on a client property. Targeting rules, triggers, and content are configured and approved rather than generated at runtime.

Where AI output is used without individual review: classification of individual free-text responses against an approved taxonomy, and generation of draft summaries and themes in reporting. These are reviewed in aggregate for accuracy against the taxonomy rather than response by response.

What we ask of clients: review outputs before relying on them for a consequential decision, and do not use outputs as the sole basis for a decision producing legal or similarly significant effects for an individual.

7. Division of Responsibility

Pulse Insights supplies the AI features. The client decides where the Services run, what they say, and which end users see them.

Pulse Insights Client Model selection and integration ● Data minimization and filtering before transmission ● Feature configuration, triggers, and targeting ● (with client) ● Survey and intervention content approval ● (with client) ● Notice and consent for data collection on client properties ● Use of outputs in client decision-making ●

Because AI Features do not interact directly with end users, the EU AI Act transparency obligations that attach to systems interacting with natural persons are not engaged by the current product. Pulse Insights tracks its obligations under the EU AI Act framework regardless, and would allocate provider and deployer responsibilities accordingly if that changed.

8. Restricted Uses

The Services may not be used, and we do not design them, to:

  • Make or materially inform decisions producing legal or similarly significant effects for an individual, including decisions relating to credit, insurance, employment, housing, healthcare, or eligibility for goods or services.

  • Provide legal, medical, financial, tax, or other professional advice, or to present outputs to end users as such advice.

  • Infer or act on sensitive characteristics, including health status, race or ethnicity, religion, sexual orientation, or political affiliation.

  • Generate unlawful, deceptive, harassing, or discriminatory content.

These restrictions are also contractual. See Sections 6A(c), 6A(d), and 6A(h) of the Terms of Service.

9. Governance

Pulse Insights is a small company. Rather than describe a committee structure we do not have, here is how this actually works.

  • Responsibility for AI governance, privacy, and security is held jointly by our Chief Executive Officer and our Head of Product. Both are named points of contact for these matters.

  • Our governance program is maintained in Vanta. We track the EU AI Act framework alongside SOC 2, GDPR, US Data Privacy, and HIPAA, with defined controls, assigned owners, and supporting evidence.

  • Evidence collection and control review run on the cadence each framework requires, at least quarterly.

  • Changes to models, providers, or the features listed in Section 2 are reviewed before release.

  • This policy is reviewed at least annually and on any material change to our AI features or providers.

Clients and prospective clients can request current framework and control status under NDA.

10. Reporting a Concern

To report an inaccurate, inappropriate, or harmful output, or to ask how a feature works, contact privacy@pulseinsights.com.