Legal

Privacy Policy

Version 1.1 · Last updated 6 August 2026

This policy explains how Woods Architects and the Pulse platform handle your personal data when you use the portal — what is collected, how it is used, and the rights you have over it.

Who is responsible for your data

Woods Architects — the architecture practice you are working with — is the data controller for the personal data held about you in connection with your project. It decides what information is collected and why.

The portal itself is provided and operated by Pulse Centric UK Ltd (company no. 16760390) ("Pulse"), registered in England and Wales. Pulse processes your project content on the practice's behalf as a data processor, and is the data controller only for the limited account and platform-operation data needed to run and secure the service (such as your login credentials and security logs). Pulse does not use your project data for its own purposes and does not sell it.

What we collect

Account details you provide — your name, email address and a password (which is only ever stored in an irreversible hashed form, never in plain text).

Project information — the documents, drawings, messages, tasks, approvals, fees and other content you and your project team add to the portal.

Files you upload — stored securely and made available only to the members of the project they belong to.

Where a studio user connects their Outlook mailbox, email content relevant to a project may be processed to match it to the right project and draft replies. This applies only to connected studio accounts, not to clients.

Basic technical data needed to run the service securely — such as your IP address for rate-limiting and sign-in security.

How your data is used and the legal basis

To provide the portal and the project you have been invited to — necessary to perform the contract with you or the party who invited you.

To keep the service secure (authentication, rate-limiting, preventing abuse) — the legitimate interest in protecting the platform and its users.

To send service messages such as invitations, password resets and project notifications — necessary to provide the service.

Some features use AI (provided by Anthropic) to summarise documents, draft replies or suggest tasks. AI is applied to project content only to provide these features; it is not used to train third-party models.

Who your data is shared with

Your personal data is not sold. The portal is operated by Pulse on the practice's behalf, and Pulse uses the following service providers (sub-processors), under contract and only as needed to run the service:

Microsoft (Microsoft Graph / Azure) — sending transactional email and, where enabled, connected-mailbox features.

Fly.io — hosting and the managed database where your data is stored (in the UK/EU region).

Tigris — secure object storage for uploaded files.

Anthropic — the AI provider powering the assistant features, processing only the content needed for a requested feature.

Data may also be disclosed where required by law.

Where your data is stored

Your data is hosted in the UK/EU region. Where any provider processes data outside the UK/EU, that transfer is covered by appropriate safeguards such as Standard Contractual Clauses.

How long it is kept

Project data is kept for as long as the project is active and for a reasonable period afterwards, in line with professional and legal record-keeping obligations. You can ask the practice to delete your personal data at any time (see your rights below), subject to any records that must legally be retained.

Your rights

Under UK GDPR you have the right to access your personal data, to correct it, to have it deleted, to restrict or object to processing, and to receive a copy in a portable format.

To access, correct or delete your data — or exercise any other right below — contact Woods Architects directly, using the contact details they have provided to you. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

Cookies

Only strictly necessary cookies are used: a secure sign-in session cookie, a cookie remembering your light/dark theme, and a short-lived security cookie used when connecting an external mailbox.

No advertising or third-party analytics/tracking cookies are used, so no cookie-consent banner is required. Because the sign-in cookie is essential, disabling it will stop you being able to sign in.

Security

Access to every project is controlled by role and membership — you only ever see the projects you belong to. Passwords are hashed with bcrypt, secrets are encrypted at rest, and all traffic is served over HTTPS.

Changes to this policy

This policy may be updated from time to time. When a material change is made, the version and date at the top are updated and, where appropriate, you will be asked to accept the updated version.