This Data Retention Policy sets out how long Pulse Technology Solutions Inc (“Pulse,” “we,” or “us”) keeps the categories of information it holds, and when and how that information is deleted or de-identified. It is the internal reference for how long each data type is kept; the retention commitments in the Terms of Use, Subscription Agreement, Privacy Policy, and Business Associate Agreement are drawn from this Policy, and this Policy controls where a conflict arises over an internal record not described in those documents.
1. PURPOSE AND SCOPE
This Policy applies to all information Pulse holds in the course of operating the Platform, regardless of format or location, including information held by a Subcontractor on Pulse’s behalf. It applies to provider, driver, and passenger data; to Pulse’s own business and workforce records; and to website and marketing data. It does not override a longer retention period required by law, by a broker, health plan, or government program contract to which a provider is subject and of which Pulse has notice, or by a litigation hold, audit, or investigation.
2. RETENTION SCHEDULE
Retention runs from the event stated. Where a period is expressed as a range, the Company applies the longer period unless a shorter period is required by law.
| Data Category | Retention Period | Runs From |
|---|---|---|
| Trip records and associated documentation (including PHI) | 6 years | Date of the trip |
| Driver, vehicle, and credential records | 6 years | Record ceases to be active |
| Claims submitted through the Platform | 6 years | Date of submission |
| Provider account data (business and billing information) | 2 years | Account closure |
| Driver account data not otherwise covered above | 2 years | Account closure |
| Passenger application account data | 2 years | Account closure or last activity, whichever is later |
| Location data (driver on-shift GPS) | As part of the trip record; 6 years | Date of the trip |
| Masked call and messaging logs (metadata only; content is not recorded) | 1 year | Date of the call or message |
| Security and access logs, audit logs | 1 year, or longer if under investigation | Date logged |
| System backups | 35 days rolling, then overwritten | Backup date |
| Support tickets and correspondence | 3 years | Ticket closure |
| Marketing contact lists and website form submissions | Until consent is withdrawn, or 3 years of inactivity | Last engagement |
| Job applicant records (not hired) | 1 year | Decision date |
| Employee and contractor personnel and payroll records | 7 years | End of engagement |
| Signed corporate and commercial agreements (NDAs, BAAs, contracts) | 7 years after expiration or termination | Expiration or termination |
| Financial and tax records | 7 years | End of the fiscal year |
Note on trip and credential records. Six years reflects the retention period generally required for Medicaid non-emergency medical transportation records; providers subject to a longer requirement under a specific broker, health plan, or state contract should notify Pulse in writing so the longer period can be applied to their records.
3. DELETION AND DE-IDENTIFICATION
3.1 Method. When a retention period ends and no hold applies, Pulse deletes the information from production systems and from backups as backups roll off under Section 2, or de-identifies it in accordance with 45 C.F.R. § 164.514(a) through (c) where retaining de-identified data supports analytics, security, or platform improvement under the Privacy Policy.
3.2 Provider Notice Before Deletion. Pulse notifies the affected provider by email at least thirty (30) days before trip records, credential records, or claims data are scheduled for deletion, so the provider can export them under Section 9.5 of the Terms of Use. Providers are responsible for keeping their contact information current to receive that notice.
3.3 Legal Holds. Where Pulse is on notice of litigation, a regulatory audit, or a government investigation that requires preservation of specific records, those records are placed on hold and excluded from routine deletion until the hold is released. The Secretary maintains the list of active holds.
3.4 Backups. Deleting a record from production systems does not immediately remove it from backups. Backups are retained on the rolling schedule in Section 2 and are not individually purged; a deleted record is fully removed once the backup containing it rolls off.
4. ROLES AND REVIEW
4.1 Responsibility. The Secretary is responsible for maintaining this Policy and the schedule in Section 2, and the Tech Lead is responsible for implementing deletion and de-identification in Pulse’s systems in accordance with it.
4.2 Review. This Policy is reviewed at least annually and on any material change to the retention obligations imposed by a broker, health plan, government program, or law applicable to Pulse or its providers.
4.3 Relationship to Other Documents. This Policy is referenced by, and is consistent with, Section 10 of the Terms of Use, Section 6 of the Privacy Policy, and Section 5.4 of the Business Associate Agreement. Where a conflict arises between this Policy and one of those documents as to a provider’s trip or credential records, the longer retention period and the provider-facing document govern; this Policy governs for all other data categories.
Contact
Questions about this Policy may be sent to support@dispatch.software.