Privacy Policy
How Pulza collects, uses, and protects your information.
Information We Collect
We collect account details you provide directly (name, email, practice information) and usage data generated as you use Pulza. For clinical practices, patient data entered by therapists is controlled by the practice as the data owner — Pulza processes it on their behalf.
How We Use It
We use account and usage data to operate, secure, and improve Pulza — including product analytics, customer support, and communicating important service updates. We do not sell personal data.
Data Storage & Security
Data is encrypted in transit and at rest, stored with role-based access controls, and scoped per practice using row-level security so one practice can never see another's data.
Where Your Data Is Stored
Pulza uses Supabase (PostgreSQL) and Vercel for hosting. The Supabase project is currently deployed in the ap-northeast-1 (Tokyo, Japan) region, and Vercel deployments serve from the edge. If you are accessing Pulza from outside Japan, your data will be processed and stored in Japan. Cross-border transfers from the European Economic Area (EEA), UK, or other jurisdictions are handled using Standard Contractual Clauses and other relevant safeguards. Japan has an EU adequacy decision in place, which provides an additional layer of protection for EEA-to-Japan transfers. This statement reflects our current infrastructure configuration and should be reviewed against your actual Supabase project settings.
GDPR Rights (EEA & UK Users)
If you are located in the EEA or UK, you have the right to: (1) request access to or a copy of your personal data; (2) request correction of inaccurate data; (3) request erasure of your data (the right to be forgotten), subject to applicable clinical record retention requirements; (4) request restriction of processing or data portability; and (5) lodge a complaint with a supervisory authority in your jurisdiction. Practice administrators can request account deletion from Settings → Data & Account. For other requests, contact us via /contact.
Your Rights
You can request a copy of your data or account deletion at any time. Family portal users can do this from Settings → Data & Account; practice staff should contact their practice administrator.
Changes to This Policy
We'll post updates here and, for material changes, notify practice administrators by email.
Questions about this policy? Contact us.