Infinity Pulse
Loading...
Infinity Pulse
App failed to load
We couldn't start the application. This might be a temporary issue. Please try a hard refresh (Ctrl/Cmd + Shift + R) or clear your browser cache.

    Next intake review: Friday 19 June

    Apply
    UK GDPR & Data Protection Act 2018 Compliant
    Last Updated: January 11, 2026

    Privacy Policy & GDPR Compliance Statement

    Effective Date: January 11, 2026

    Website: www.infinity-pulse.co.uk

    Secure Storage

    Enterprise-grade encryption for all data

    Transparency

    Clear explanation of all data we collect and why

    Your Control

    Request access, correction, or deletion at any time

    1. Introduction

    At Infinity Pulse ("we", "us", "our"), we value your business and respect your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use our comprehensive business platform, including networking services, e-learning academy, website builder tools, HR management suite, compliance documentation, time tracking features, and our AI-powered Pulse CRM system.

    For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Infinity Pulse is the Data Controller.

    2. The Data We Collect

    We collect data purely for business purposes to provide the services included in your membership. This includes:

    Account & Profile Information

    Name, job title, company name, email address, phone number, profile photo, and professional biography.

    Payment Information

    Billing address and payment records. Note: actual credit card details are processed securely by our payment provider (Stripe) and are not stored directly on our servers.

    Educational Data

    Course progress, quiz scores, training completions, certification records, and "Certificate of Completion" documents generated via our Infinity Pulse Academy.

    Pulse CRM Data (Sales & Customer Intelligence)

    Contact names, email addresses, phone numbers, company information, deal values, pipeline stages, email interaction data (opens, clicks, timestamps), AI-generated deal health scores, win probability calculations, activity logs, and communication history. All CRM data is encrypted at rest using AES-256 encryption and protected by Row-Level Security ensuring only authorised users can access their own data.

    Employee & HR Data

    For businesses using our People Hub: employee names, job titles, departments, employment dates, annual leave allowances, absence records, sickness logs, and role/permission levels (Employee, Manager, Super User).

    Time & Attendance Data

    Clock-in/clock-out times, working hours, overtime records, and attendance patterns for workforce management purposes.

    Location Data

    When employees use GPS-enabled time clocking features, we collect location coordinates at clock-in and clock-out for geofence verification. This data is only collected with explicit consent and can be disabled.

    Health & Safety Data

    H&S concern reports including descriptions, locations, severity levels, and photographic evidence. This special category data is processed for legitimate health and safety obligations.

    Compliance & Right to Work Data

    For compliance vault users: candidate names, passport details, visa information, share codes, right-to-work documentation, and verification records as required by UK immigration law.

    Website Builder Content

    Text, images, and business details you upload to create your landing pages or business sites.

    Usage Data

    Login timestamps, interaction logs, feature usage analytics, and device information to ensure the security and performance of the platform.

    3. Why We Process Your Data (Lawful Basis)

    Under the UK GDPR, we process your data under the following lawful bases:

    • Contractual Necessity: We need your data to deliver the services you paid for (e.g., to grant access to training courses, manage employee records, process leave requests, or to host the website you built).
    • Legitimate Interests: To maintain a directory of business members for networking purposes, to improve our platform's functionality, and to provide HR management tools that help businesses operate efficiently.
    • Legal Obligation: To keep financial records for tax and accounting purposes (e.g., HMRC requirements), maintain right-to-work documentation, and comply with health and safety regulations.
    • Consent: For optional features such as GPS location tracking, marketing communications, and photo uploads for H&S reports.
    • Vital Interests: For emergency alert features (panic buttons) designed to protect employee safety.

    4. Role-Based Access Control

    Our platform implements strict role-based access control to ensure data is only accessible to authorised personnel:

    • Employee Role: Can view and manage their own data, submit leave requests, report sickness, and raise H&S concerns.
    • Manager Role: Can view and approve their team's leave requests, review H&S concerns, access team attendance data, and manage their direct reports.
    • Super User (Business Owner): Full access to all employee data, system settings, compliance documentation, and business-wide reporting.

    Roles are assigned by business owners when adding staff members and can be changed at any time through the People Hub.

    5. How We Store and Protect Your Data

    Your data is stored securely using enterprise-grade cloud infrastructure. We implement robust security measures, including:

    • Encryption of data in transit (SSL/TLS) and at rest (AES-256).
    • Row-Level Security (RLS) to ensure that only authorised users can access their data.
    • Role-based access controls enforced at the database level using security-definer functions.
    • Regular security audits and penetration testing.
    • Multi-factor authentication options for enhanced account security.
    • Automatic session management and secure password hashing.

    Pulse CRM Data Protection

    All data stored in our Pulse CRM system (contacts, deals, activities, email tracking) is encrypted at rest using AES-256 encryption. Row-Level Security policies ensure that each user can only access their own CRM data. AI processing for Deal Health scores and predictions occurs on secure servers, and your data is never used to train external AI models.

    We do not sell your personal data to third parties. Data is only shared with trusted sub-processors required to run the business (e.g., payment gateways like Stripe, hosting providers), and only under strict confidentiality agreements.

    6. Data Retention

    We retain data only as long as necessary for the purposes for which it was collected:

    • Account data: Retained while your account is active, plus 30 days after closure.
    • Financial records: 7 years as required by HMRC.
    • Right-to-work documents: 2 years after employment ends, as per Home Office guidance.
    • Employee records: Duration of employment plus 6 years.
    • H&S records: As required by the Health and Safety Executive (typically 3-40 years depending on type).
    • Training certificates: Indefinitely or as required by relevant regulatory bodies.
    • CRM data (Pulse): Retained while your account is active. You may delete individual contacts at any time. Upon account closure, CRM data is permanently deleted after 30 days.

    Our Compliance Vault includes automated GDPR retention alerts to help you manage document deletion schedules.

    7. Your Rights Under UK GDPR

    Under the UK GDPR, you have specific rights regarding your data:

    • The Right to Access (Subject Access Request): You can request a copy of the personal data we hold about you free of charge within 30 days.
    • The Right to Rectification: You can request correction of inaccurate or incomplete data (most corrections can be made directly via your Dashboard).
    • The Right to Erasure ("Right to be Forgotten"): You can request that we delete your account and associated data, provided we do not need to keep it for legal/tax reasons.
    • The Right to Restrict Processing: You can ask us to limit how we use your data while a complaint is being investigated.
    • The Right to Data Portability: You can request your data in a structured, commonly used, machine-readable format (JSON or CSV).
    • The Right to Object: You can object to processing based on legitimate interests, direct marketing, or profiling.
    • Rights Related to Automated Decision Making: You have the right not to be subject to decisions based solely on automated processing that significantly affect you.

    You can exercise these rights through your account settings (Settings → Account → GDPR Rights) or by contacting us directly.

    8. International Transfers

    If any of our service providers (e.g., cloud servers) are located outside the UK, we ensure appropriate safeguards are in place, such as UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs), to protect your privacy. Our primary data storage is within UK/EU jurisdictions.

    9. Data Breach Procedures

    In the event of a personal data breach, we will:

    • Notify the ICO within 72 hours if the breach is likely to result in a risk to individuals' rights and freedoms.
    • Notify affected individuals without undue delay if there is a high risk to their rights and freedoms.
    • Document all breaches, their effects, and the remedial actions taken.

    10. Contact Us

    If you have any questions about this policy or wish to exercise your rights, please contact our Data Protection Officer (DPO) / Administration Team at:

    Email: dpo@infinity-pulse.co.uk

    General Enquiries: support@infinity-pulse.co.uk

    Address: Infinity Pulse, United Kingdom.

    Response Time: We aim to respond to all data protection queries within 5 working days.

    If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK at ico.org.uk/make-a-complaint.

    We use cookies

    We use cookies to ensure you get the best experience on our website and to manage your login session.