Legal

Privacy Policy

Read this part first — there are two very different relationships at work here.

For your enquiry and account details, we decide how the information is used, so this policy is our promise to you.

For the patient records inside your workspace, your laboratory decides everything. We simply hold and process that data on your instruction. If you are a patient asking about your own test report, please contact the laboratory that tested you — not us. We are not permitted to release, correct, or delete a patient record without that laboratory's instruction.

1. Who we are

A Pulse Solution ("APulse", "we", "us") provides lab management software to medical, pathology and diagnostic laboratories. The entity responsible for the information described in this policy is A Pulse Solution, based in Pakistan.

This policy covers apulsesolution.com and the APulse laboratory platform. It does not cover websites we link to, such as WhatsApp, which have their own policies.

2. Information we collect through this website

We ask for very little, and only where it has an obvious purpose.

What we collectWhenWhat we use it for
Laboratory name, your email, phone number, laboratory type, approximate patients per day, number of branches, city, the plan you are interested in, and your messageWhen you submit the quote formPreparing a price for your lab, recommending a plan, and following up on your enquiry
Your name, laboratory name, email, phone, chosen plan, payment reference and our correspondence with youWhen you open a demo or paid accountCreating your workspace, issuing invoices, providing support, and keeping accounting records
Message content and your phone number or email addressWhen you contact us on WhatsApp or by emailAnswering you and keeping a record of what was agreed
IP address, browser and device type, pages requested, referring page and timestampsAutomatically, in our web server logsKeeping the site available, investigating faults, and detecting abuse or attacks

Depending on how our quote form is configured at the time, your enquiry may reach us through our own server, through WhatsApp, or through your own email program. In the last two cases the message travels through that provider before it reaches us.

We do not buy contact lists, we do not sell or rent your details to anyone, and we do not run advertising or behavioural-tracking networks on this site.

3. Patient and clinical data inside the platform

When your laboratory uses APulse, your staff enter information about real people. That typically includes patient names and medical record numbers, age and sex, contact details, referring doctor, requested tests, results measured against reference ranges, generated report PDFs, and invoices.

This is health information, and it deserves the strictest treatment. Two points matter most:

  • Your laboratory is in charge of it, not us. You decide what is collected, who on your team can see it, how long it stays, and what patients are told. You are responsible for having a lawful basis to hold it.
  • We only touch it for a narrow set of reasons: to keep the service running and backed up; to diagnose a fault you have reported to us; to import or export your data when you ask us to; and where the law compels us.

Access on our side is restricted to the small number of authorised personnel who need it for those purposes. We do not use patient records to train machine-learning models, we do not market anything to your patients, we do not combine your records with another laboratory's, and we do not pass them to third parties for their own purposes.

4. Why we process information

  • To perform our contract with you — creating your workspace, providing support, taking payment.
  • Because we have a legitimate interest — securing our systems, preventing fraud and abuse, understanding which pages of this site are useful, and following up on a quote you asked us for.
  • Because you consented — where we send you optional product news. You can withdraw at any time and it will not affect your service.
  • Because the law requires it — tax, accounting and lawful requests from authorities.
  • On your laboratory's instruction — for everything inside your workspace, as described in section 3.

5. Cookies, fonts and analytics

The platform itself uses only the cookies needed to keep you signed in securely and to remember your workspace — these cannot be switched off without breaking sign-in.

This marketing website uses Google Analytics 4 to count visits and see which pages and buttons people use. It records page views and a handful of actions — opening WhatsApp, clicking through to the free demo, submitting the quote form — with your IP address truncated before storage.

It also carries the Meta (Facebook) pixel, and we would rather say plainly what that is: an advertising tracker. It records the same handful of actions, sets cookies associated with facebook.com, and lets us measure which of our Facebook and Instagram adverts brought someone here and show adverts again to people who visited. That does mean your visit contributes to a profile Meta holds across other websites, which is how all such advertising pixels work. It never receives anything you type into the quote form — not your name, email, phone number or lab name — only that a submission happened.

Blocking third-party scripts, using a tracker-blocking browser or extension, or Meta's own ad preferences settings will stop the pixel. Nothing on this site depends on it, and no page breaks without it.

Typefaces are served from our own servers, not from Google Fonts or any other font network, so loading a page here does not disclose your IP address to a font provider.

We do use Tawk.to to run the live chat widget in the corner of these pages. Tawk.to loads only when a page opens the widget script, and as the chat provider it receives your IP address, basic device information and whatever you type into the chat. Please do not put patient names or clinical details into live chat — for anything involving real records, contact us on WhatsApp or by email instead. Blocking third-party scripts in your browser prevents the widget from loading at all; nothing else on the page depends on it.

6. Who we share information with

We keep this list short on purpose. We share only what a provider needs to do its job:

  • Hosting and infrastructure providers — who run the servers, networking and backups the service depends on.
  • Email and messaging providers — to deliver account notices and to reply when you contact us. Messaging us on WhatsApp means Meta processes that conversation under its own terms.
  • Payment providers — where card or online payment is offered. We never see or store your full card number.
  • Professional advisers — accountants and lawyers, bound by confidentiality, where genuinely necessary.
  • Authorities — where we are legally obliged to disclose. We will tell you unless we are prohibited from doing so.

If our business is ever sold or reorganised, information may transfer to the acquirer. We would notify account holders in advance and the protections in this policy would continue to apply.

7. Where your data is stored

Our servers and those of our providers may be located outside your country, which means your information can be transferred across borders. Where that happens we use providers who commit to recognised safeguards and contractual protections, and we keep the transfer limited to what the service requires. If your regulator requires data to remain inside a particular country, tell us before you subscribe so we can confirm whether we can meet that.

8. How long we keep things

Type of recordKept for
Quote enquiries that do not become accountsUp to 24 months, then deleted
Patient records inside your workspaceFor as long as your subscription runs. After it ends you have 30 days to export; we then delete on your written request
Invoices and accounting recordsAs long as tax and company law requires, typically six years
Support conversationsUp to 24 months after the issue is closed
Web server and security logsUp to 12 months
Encrypted backupsOn a rolling window of roughly 30 days, after which they are overwritten

Because backups roll over, a deletion request is honoured in the live system immediately and works its way out of backups as that window passes.

9. How we protect data

  • Separation between labs. Each laboratory's records live in their own isolated database schema, so one customer's data is never mixed with another's.
  • Role-based access. You give each staff member their own account and decide what they can see and do. Receptionists need not see financial reports.
  • Encryption in transit. Traffic between your browser and our servers is encrypted with TLS.
  • Password protection. Passwords are stored as one-way hashes — we cannot read them, and neither can an attacker who obtains the file.
  • Restricted administrative access, limited to named personnel who need it.
  • Regular encrypted backups, so a failure or mistake does not become a permanent loss.

We will not pretend any system is perfectly secure. Much of your protection also rests with you: give every staff member their own login rather than sharing one, remove accounts when people leave, and choose passwords that are not reused elsewhere. If we ever discover a breach that puts people at real risk, we will tell affected laboratories without undue delay and explain what happened and what to do.

10. Your rights and choices

Depending on where you live, you may have the right to:

  • Ask what we hold about you and get a copy;
  • Have inaccurate details corrected;
  • Ask us to delete information we no longer need;
  • Receive your data in a portable format, or have us send it to another provider;
  • Object to processing based on our legitimate interests, or ask us to restrict it;
  • Withdraw consent to marketing at any time;
  • Complain to your national data protection authority.

To exercise any of these, email [email protected]. We will respond within 30 days and will not charge you. We may need to verify your identity first — a sensible precaution, since we are not going to hand over records to whoever asks.

If you are a patient: your report and medical history belong to the laboratory that tested you. Contact that laboratory directly. If you approach us instead, all we can do is pass your request on to them.

11. Children and minors

APulse is business software; it is not intended for anyone under 18 to sign up for directly. Patient records held by a laboratory will sometimes relate to children, which is entirely normal in clinical practice. In those cases the laboratory is responsible for having the right consent from a parent or guardian under its own local rules.

12. Changes to this policy

As the product grows, this policy will need updating. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle your information, we will email account holders at least 30 days before it takes effect, so nothing important changes quietly behind your back.

13. Contact us

Questions about this policy, or about anything we hold, go to [email protected]. You can also reach us on WhatsApp through the button on our contact section, though for anything involving personal data we prefer email so there is a clear written record.

A Pulse Solution operates from Pakistan. We handle data requests by email rather than by post, so that nothing is lost in transit and you have a written record. If you need our full registered address in writing — for a regulator, or to serve formal notice — email us and we will provide it.

See also our Terms & Conditions.

Request a free quote