Privacy Policy
This Privacy Policy explains how PulsePoint Foundation, a public 501(c)(3) nonprofit organization (“PulsePoint,” “we,” “us,” or “our”), handles personal data in connection with the PulsePoint Respond mobile application for Public CPR Responders (the “App” or “Service”). PulsePoint Respond notifies trained bystanders of nearby cardiac emergencies where their assistance, including CPR and the retrieval of an AED, could help save a life.
We built PulsePoint Respond for Public CPR Responders to work with as little personal data as possible. This policy describes the limited data we do process, why we process it, and the rights available to you — including the specific rights granted to individuals in the European Union and European Economic Area (“EU/EEA”) under the General Data Protection Regulation (GDPR). This policy is effective as of April 1, 2025, and was last updated on July 20, 2026.
1. Data Controller Contact Information
For purposes of the GDPR, PulsePoint Foundation is the data controller responsible for the personal data processed in connection with PulsePoint Respond.
Mailing Address
PulsePoint Foundation
PO Box 12594
Pleasanton, CA 94588-2594
General inquiries: info@pulsepoint.org
Data Protection Officer: dpo@pulsepoint.org
Support: support@pulsepoint.org
If you are located in the EU/EEA and have concerns we have not resolved, you also have the right to lodge a complaint with your local data protection supervisory authority (see Section 7).
2. Types of Data We Collect
PulsePoint Respond is designed to be used anonymously. We do not require you to create an account, and we do not collect your name, date of birth, government ID, or other directly identifying information through the App. The categories of data we do process are:
- Device and notification data: a randomly generated device identifier and push-notification token, used solely to deliver emergency alerts to your device.
- Location data (opt-in only): your device's current location, collected only if you opt in to receive proximity-based alerts. We store only your current location for the purpose of matching you to nearby alerts. We do not build or retain a history of your movements.
- Active-response location: if you indicate that you are responding to a specific alert, your device's location may be collected on a continuous basis for the duration of that response only. This sharing stops automatically when the response ends.
- Optional survey responses: if you choose to complete a post-response survey, your responses are collected to help us and partner agencies improve response outcomes.
- Support communications: if you contact PulsePoint support, we collect the information you provide (such as an email address and the content of your message) in order to respond to you.
- Technical and diagnostic data: standard mobile app diagnostics (app version, device type, crash logs) used to maintain and improve the Service.
- Emergency and dispatch information: we receive incident information, including location and potentially details of the person experiencing the emergency (the "cardiac arrest victim"), from emergency dispatch (911) systems and connected medical devices (such as wearable devices capable of detecting a cardiac arrest, which can automatically trigger an alert to us the same way a 911 dispatch center does) in order to generate alerts.
3. How and Why We Use Your Data (Legal Basis)
Under the GDPR, we only process personal data where we have a valid legal basis to do so. We rely on the following bases:
- Consent (Art. 6(1)(a)): for opt-in location sharing and proximity alerts, and for optional survey participation. You may withdraw this consent at any time by changing your device or in-app settings, which stops future collection (see Section 7).
- Performance of a service you requested (Art. 6(1)(b)): to operate the core alerting functionality of the App you have chosen to install and enable.
- Legitimate interests (Art. 6(1)(f)): to secure the Service against abuse, to maintain and troubleshoot the App, and to conduct anonymized, aggregated research and reporting on emergency response effectiveness — an interest we believe is not overridden by your privacy interests given the limited, non-identifying data involved.
- Legal obligation (Art. 6(1)(c)): where we are required to retain or disclose information to comply with applicable law.
- Vital interests (Art. 9(2)(c)): where an alert is initiated by emergency dispatch or a connected medical device, any health-related signal, and any identifying information about the person experiencing the emergency (such as their name or date of birth) that we receive in order to generate that alert, is processed solely to protect that person’s vital interests, given that they are typically unable to give consent.
4. Sharing of Alert and Location Data
Because PulsePoint Respond exists to coordinate emergency response, limited data is necessarily shared with:
- Emergency dispatch and public safety agencies in your area, to initiate the response you are participating in.
- Partner organizations and researchers, only in aggregated or anonymized form (e.g., response-time statistics), never in a way that identifies you.
We do not sell your personal data, and we do not disclose it for advertising or marketing purposes. Any sharing beyond what is described in this Policy will only occur with your consent or as required by law.
5. Use of Third-Party Processors
We engage a limited number of trusted third-party service providers to help us operate PulsePoint Respond, such as cloud hosting providers, mobile push-notification platforms (e.g., Apple and Google), and help-desk/support applications. These providers process data only on our documented instructions and under written Data Processing Agreements that require them to protect your data and use it only for the purposes we specify.
Where a service provider processes data outside the EU/EEA (including in the United States, where PulsePoint is based), we rely on the European Commission's Standard Contractual Clauses (SCCs) or another legally recognized transfer mechanism to ensure your data receives an equivalent level of protection, as required by GDPR Chapter V.
6. How Emergency Alerts Work
When a cardiac arrest is reported where PulsePoint Respond is active, nearby app users who have opted in to alerts may receive a push notification asking them to assist, for example, to begin CPR or retrieve a nearby AED, until professional responders arrive. If you have indicated your willingness to respond, your approximate location is used for the sole purpose of initiating that response. We do not collect your location for any purpose unrelated to alerting and coordinating emergency response.
7. Your Rights Under GDPR
If you are located in the EU/EEA, you have the following rights regarding your personal data:
- Right of access: to obtain confirmation of, and a copy of, the personal data we hold about you.
- Right to rectification: to have inaccurate or incomplete data corrected.
- Right to erasure (“right to be forgotten”): to request deletion of your data, subject to limited legal exceptions.
- Right to restriction of processing: to request that we limit how we use your data in certain circumstances.
- Right to object: to object to processing based on our legitimate interests.
- Right to data portability: to receive data you provided to us in a structured, commonly used, machine-readable format.
- Right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (e.g., by disabling location permissions in your device settings).
- Right to lodge a complaint with a supervisory authority in your EU/EEA member state of residence, work location, or the place of the alleged infringement.
To exercise any of these rights, contact our Data Protection Officer at dpo@pulsepoint.org. Because PulsePoint Respond does not require an account, please provide enough detail for us to reasonably locate any data associated with your device. We will respond within one month (30 days) of receiving a verifiable request, as required by GDPR Article 12.
8. International Data Transfers
PulsePoint Foundation is based in the United States, and the servers and service providers that support PulsePoint Respond may be located in the United States or other countries outside the EU/EEA. When we transfer personal data internationally, we use Standard Contractual Clauses or another GDPR-recognized safeguard to ensure your data continues to be protected to the standard required by the GDPR, regardless of where it is processed.
9. Data Retention
We retain data only for as long as necessary for the purposes described in this Policy:
- Location data used for alert matching: current location only; not retained as a history.
- Cardiac arrest victim data: retained in our transaction systems for no more than 60 days.
- Device/notification identifiers: retained only while the App remains installed and alerts are enabled; deleted upon uninstall or opt-out, and in any event no account or profile persists.
- Post-response survey data: retained for up to 12 months, after which it is anonymized.
- Support tickets: retained for up to 24 months, then securely deleted.
- Aggregated / anonymized statistics: may be retained indefinitely, as they no longer constitute personal data.
10. Security Measures
We implement technical and organizational measures designed to protect personal data, including encryption of data in transit and at rest, role-based access controls limiting who within our organization and service providers can access data, and regular security review of our systems. In the event of a personal data breach affecting EU/EEA individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33, and will notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
11. Children's Privacy
PulsePoint Respond is not directed to, and is not knowingly used by, individuals under the age of 13 (or under 16 in the EU/EEA, where applicable under local implementing law). If we become aware that we have inadvertently collected data from a child below the applicable age without appropriate consent, we will take prompt steps to delete that data.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the App's functionality, or applicable law. We will update the “Last Updated” date above, and where changes are material, we will provide additional notice (such as an in-app notice) before the change takes effect. We encourage you to review this Policy periodically.
13. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or have a concern about how PulsePoint Respond handles data, please contact:
PulsePoint Foundation
PO Box 12594
Pleasanton, CA 94588-2594
Email: dpo@pulsepoint.org
14. Summary of Key Points
This summary is provided for convenience and does not replace the full Policy above.
- PulsePoint Respond does not require an account and is designed to be used anonymously.
- We only collect your location if you opt in, and only your current location.
- Continuous location sharing occurs only while you are actively responding to a specific alert.
- We never sell your data or use it for advertising.
- EU/EEA users have full GDPR rights, including access, deletion, and the right to complain to a supervisory authority.
- Questions or requests can be sent to dpo@pulsepoint.org at any time.