Legal

Privacy Policy

Version 1.0 · Last updated 4 August 2026

This policy explains what personal data Woods Architects Ltd holds about you when you use the Pulse portal, how it is used, and the rights you have over it.

Who is responsible for your data

Woods Architects Ltd (company no. 17165045) ("the practice", "we"), registered in England and Wales, is the data controller for the personal data held about you in connection with your project — it decides what information is collected and why. If you have questions or want to exercise your rights, contact the practice at hello@woodsarchitects.co.uk.

The portal itself is provided and operated by Pulse Centric UK Ltd (company no. 16760390) ("Pulse"), registered in England and Wales, which processes this data on the practice's behalf as a data processor — it does not use your data for its own purposes.

What we collect

Account details you provide — your name, email address and a password (which is only ever stored in an irreversible hashed form, never in plain text).

Project information — the documents, drawings, messages, tasks, approvals, fees and other content you and your project team add to the portal.

Files you upload — stored securely and made available only to the members of the project they belong to.

Where a studio user connects their Outlook mailbox, email content relevant to a project may be processed to match it to the right project and draft replies. This applies only to connected studio accounts, not to clients.

Basic technical data needed to run the service securely — such as your IP address for rate-limiting and sign-in security.

How your data is used and the legal basis

To provide the portal and the project you have been invited to — necessary to perform the contract with you or the party who invited you.

To keep the service secure (authentication, rate-limiting, preventing abuse) — the legitimate interest in protecting the platform and its users.

To send service messages such as invitations, password resets and project notifications — necessary to provide the service.

Some features use AI (provided by Anthropic) to summarise documents, draft replies or suggest tasks. AI is applied to project content only to provide these features; it is not used to train third-party models.

Who your data is shared with

Your personal data is not sold. The portal is operated by Pulse on the practice's behalf, and Pulse uses the following service providers (sub-processors), under contract and only as needed to run the service:

Microsoft (Microsoft Graph / Azure) — sending transactional email and, where enabled, connected-mailbox features.

Fly.io — hosting and the managed database where your data is stored (in the UK/EU region).

Tigris — secure object storage for uploaded files.

Anthropic — the AI provider powering the assistant features, processing only the content needed for a requested feature.

Data may also be disclosed where required by law.

Where your data is stored

Your data is hosted in the UK/EU region. Where any provider processes data outside the UK/EU, that transfer is covered by appropriate safeguards such as Standard Contractual Clauses.

How long it is kept

Project data is kept for as long as the project is active and for a reasonable period afterwards, in line with professional and legal record-keeping obligations. You can ask the practice to delete your personal data at any time (see your rights below), subject to any records that must legally be retained.

Your rights

Under UK GDPR you have the right to access your personal data, to correct it, to have it deleted, to restrict or object to processing, and to receive a copy in a portable format.

To exercise any of these, contact the practice at hello@woodsarchitects.co.uk. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

Cookies

Only strictly necessary cookies are used: a secure sign-in session cookie, a cookie remembering your light/dark theme, and a short-lived security cookie used when connecting an external mailbox.

No advertising or third-party analytics/tracking cookies are used, so no cookie-consent banner is required. Because the sign-in cookie is essential, disabling it will stop you being able to sign in.

Security

Access to every project is controlled by role and membership — you only ever see the projects you belong to. Passwords are hashed with bcrypt, secrets are encrypted at rest, and all traffic is served over HTTPS.

Changes to this policy

This policy may be updated from time to time. When a material change is made, the version and date at the top are updated and, where appropriate, you will be asked to accept the updated version.