PulseFlow Systems Logo
Zero Data Retention Compliance

Privacy Policy

How PulseFlow Systems processes, protects, and governs telephony audio streams, conversational transcripts, and CRM pipeline intelligence across our enterprise voice infrastructure.

Effective Date: March 30, 2026 • Version: 3.4.1 • GDPR, CCPA/CPRA, HIPAA BAA Ready

1. Business Model & Scope of Service

PulseFlow Systems (“PulseFlow,” “we,” “our,” or “us”) operates an autonomous enterprise AI voice automation infrastructure platform accessible via pulseflowsystems.com. Our core business model provides turnkey sub-second speech synthesis, intelligent inbound and outbound call answering, automated calendar scheduling, n8n webhook workflow automation, and customer relationship management (CRM) synchronization for enterprise clients in healthcare, fintech, aviation, logistics, and professional services.

This Privacy Policy establishes our protocols regarding the collection, transmission, processing, isolation, and purge of information when businesses utilize our voice agents, APIs, edge telephony nodes, and web dashboard.

2. Telephony Data & Audio Streams Collected

When customer calls are routed through PulseFlow SIP trunks or WebRTC gateways, our systems process:

  • check_circle Signaling Metadata: Caller ID, Automatic Number Identification (ANI), dialed DID number, call duration, timestamp, carrier packet jitter, and edge point of presence (POP) routing tags.
  • check_circle Raw Audio Payload: Full-duplex RTP/SRTP audio streams sampled at up to 48kHz for real-time speech-to-text tokenization and turn-taking cadence computation.
  • check_circle Extracted Conversational Intents: Derived conversational intents (e.g. appointment scheduling requests, prescription refill authorizations, invoice confirmations, tier-1 technical support requests).

3. Volatile RAM Storage & Zero Audio Persistence

In line with our high-security infrastructure architecture:

AUDIO STREAM POLICY: RAW VOICE DATA IS PARSED IN-FLIGHT IN EPHEMERAL VOLATILE RAM (NON-PERSISTENT BUFFER). UPON SIP "BYE" TERMINATION PACKET, RAW WAVEFORM BUFFERS ARE INSTANTANEOUSLY PURGED AND OVERWRITTEN.

We do not store, archive, or listen to raw acoustic audio recordings unless an enterprise client explicitly mandates and cryptographically configures a dedicated storage bucket under an executed Business Associate Agreement (BAA) or SOC2 contractual addendum.

4. Vocal Biometrics & Cryptographic Tokenization

For financial verification and patient identification, PulseFlow employs one-way mathematical voiceprint hashes. We never store raw voice models. Instead, acoustic frequency vectors are tokenized into 512-bit non-reversible mathematical representations used solely to confirm authentication during an active call session.

5. Third-Party Webhooks & CRM Sync (n8n, GoHighLevel)

When you deploy PulseFlow voice agents with integrated workflow pipelines:

  • • CRM Ecosystems: Data synchronized to GoHighLevel (GHL), Salesforce, HubSpot, or custom webhook endpoints moves via TLS 1.3 encrypted REST APIs.
  • • Calendar Engines: Appointment times, customer names, and contact details transmitted to Google Workspace or Microsoft Outlook 365 operate strictly under customer-managed OAuth2 tokens.
  • • Carrier Backbones: Telephony handoffs via Twilio, Bandwidth, Lumen, or Level 3 are governed by telecommunications common-carrier privacy boundaries.

6. Global Compliance: GDPR, CCPA, and HIPAA

EU/EEA & UK Data Subjects (GDPR): PulseFlow operates primarily as a Data Processor on behalf of our enterprise clients (the Data Controllers). We process data under Art. 6(1)(b) (contractual necessity) and Art. 6(1)(f) (legitimate interest). European client traffic can be pinned strictly to our Frankfurt (POP-03) sovereign enclaves.

California Residents (CCPA/CPRA): We do not “sell” or “share” personal consumer voice data or phone numbers. You possess the right to request disclosure, deletion, and restriction of any retained metadata.

Healthcare (HIPAA): For healthcare providers, hospitals, and outpatient clinics, PulseFlow enters into standard Business Associate Agreements (BAAs), enforcing end-to-end PHI encryption, automatic PII redaction from text transcripts, and strict audit trails.

7. Contact Our Data Protection Officer (DPO)

For privacy inquiries, audit packet requests, or to exercise statutory data rights:

location_on PulseFlow Systems Data Privacy Office, 8080 Railroad St. Souther 32, CA