This Acceptable Use Policy (“AUP”) sets out the rules for using the Pulse dispatch platform, driver application, passenger application, and any API or integration Pulse makes available (together, the “Platform”). It applies to every person and organization that accesses the Platform in any capacity: transportation providers and their staff, drivers, passengers, brokers and trip sources with integration access, auditors and regulators granted view access, and Pulse’s own employees and contractors. This Policy is incorporated by reference into the Terms of Use, the Driver Terms of Use, the Business Associate Agreement, and the Independent Contractor and Employee Confidentiality and IP Agreements. Where one of those documents states a more specific rule for its audience, the more specific rule governs; this Policy fills any gap and applies in full to anyone not otherwise covered.
1. WHO THIS POLICY COVERS
• Providers and their authorized staff, who access the dispatcher portal under the Terms of Use.
• Drivers, who access the driver application under the Driver Terms of Use.
• Passengers, who access the passenger application.
• Brokers and trip sources, and their staff, who connect to the Platform through an API or integration under a separate integration agreement.
• Auditors, regulators, and government program staff granted limited or view-only access for compliance or audit purposes.
• Pulse employees and contractors, who access the Platform and underlying systems to build, operate, and support it.
2. GENERAL RULES
Everyone who accesses the Platform shall:
• use the Platform only for its intended purpose: arranging, performing, documenting, and billing non-emergency medical transportation and for-hire vehicle trips, and the administration that supports it;
• access only the accounts, data, and features their role authorizes, and not attempt to access another person’s or organization’s account or data;
• keep login credentials confidential, use multi-factor authentication where offered, and not share an account between multiple people;
• report a suspected security incident, unauthorized access, or vulnerability to security@dispatch.software promptly on becoming aware of it;
• comply with all applicable law, including transportation licensing, Medicaid program rules, and data protection and privacy law; and
• comply with the Company’s Data Retention Policy and Privacy Policy in handling any data exported from the Platform.
3. PROHIBITED CONDUCT
No one may use the Platform to:
• submit trip records, credentials, claims, or other documentation that are false, altered, or inflated, or that misrepresent a trip actually performed;
• falsify or interfere with location data, including spoofing GPS location or using any tool to misrepresent a vehicle’s position;
• perform or dispatch a trip without the license, credential, or insurance the trip requires;
• access, request, or attempt to access data beyond the minimum necessary for the person’s assigned role, including protected health information;
• copy, download, screenshot, print, or transmit protected health information to any device, account, or system outside those the Company or the accessing organization has approved;
• share, sell, or transfer login credentials or API keys to anyone not authorized to hold them;
• probe, scan, or test the vulnerability of the Platform, or attempt to bypass any authentication or security control, except under a written agreement with Pulse authorizing that testing;
• introduce any virus, malware, or other harmful code, or transmit unsolicited bulk communications through the Platform;
• reverse engineer, decompile, or disassemble any software provided as part of the Platform;
• access the Platform by means other than the interfaces and APIs Pulse provides, or through automated means likely to degrade the Platform for other users;
• resell, sublicense, or provide access to the Platform to anyone who is not an authorized user under the applicable agreement; or
• use the Platform to discriminate against a passenger on any basis prohibited by law, or to harass or threaten any user.
4. PROTECTED HEALTH INFORMATION
Anyone whose role provides access to protected health information (“PHI”) shall handle it only in accordance with the Company’s Privacy Policy, the Business Associate Agreement applicable to the relevant provider, and, for Pulse workforce, the HIPAA workforce obligations in their Independent Contractor or Employee Confidentiality and IP Agreement. Those obligations include using only approved systems and devices, accessing PHI only as a role requires, and reporting any suspected unauthorized use or disclosure within twenty-four (24) hours. This Policy does not restate those obligations in full and does not reduce them.
5. BROKERS, TRIP SOURCES, AND API ACCESS
5.1 Scope of Access. A broker or trip source with API or integration access may use that access only to exchange trip data for trips it is authorized to send to or receive from the Platform, and only in accordance with its integration agreement with Pulse and the provider it is exchanging trips with.
5.2 Rate Limits and Stability. API access is subject to the rate limits and technical requirements Pulse publishes for its integrations. Pulse may throttle or suspend access that degrades Platform performance for other users.
5.3 No Independent Data Use. A broker or trip source shall not use data obtained through the Platform for any purpose other than the trip exchange it supports, and shall not aggregate, sell, or repurpose passenger or provider data obtained through its access.
6. MONITORING AND ENFORCEMENT
6.1 Monitoring. Pulse may monitor use of the Platform to detect violations of this Policy, to protect the security and integrity of the Platform, and to comply with law. Pulse is not obligated to monitor and does not review all content or activity on the Platform.
6.2 Consequences. A violation of this Policy may result in removal of content, suspension or termination of access, and referral to the appropriate authorities, in accordance with the termination provisions of the agreement that governs the violator’s access to the Platform. A violation involving PHI or a suspected pattern of fraudulent trip records is treated as a material breach under those agreements.
6.3 Reporting Violations. Anyone who becomes aware of a violation of this Policy should report it to support@dispatch.software, or to security@dispatch.software for a security-related violation.
Changes to This Policy
Pulse may update this Policy. Material changes are notified as provided in the Terms of Use, the Driver Terms of Use, or the relevant workforce agreement, as applicable to the reader.