LEGAL

Privacy Policy

Effective date: July 20, 2026 · Last updated: August 28, 2026

This Privacy Policy explains how Pharmed Pulse, Inc. (“Pharmed Pulse,” “we,” “us,” or “our”), a company incorporated in the United States and operator of the RocketMSL platform, collects, uses, discloses, and protects personal data when you use our mobile applications, web platform, public website, and related services (collectively, the “Services”). It applies to the RocketMSL applications distributed through the Apple App Store and Google Play, and to https://www.rocketmsl.com.

RocketMSL is an AI-native Medical Affairs platform used by Medical Science Liaisons (MSLs) and Healthcare Professionals (HCPs) to prepare for, capture, and analyze scientific interactions. Please read this Policy alongside any notices presented inside the app.

1. Our role and your relationship with us

RocketMSL is licensed to pharmaceutical and life-sciences organizations (each, a “Customer”). How you relate to us depends on how you use the Services:

  • MSL users access the Services as authorized users of a Customer (typically their employer).
  • HCP users interact with the Services in connection with a Customer’s scientific engagement activities.
  • Website visitors and enquirers browse our public website at rocketmsl.com or contact us through it.
  • Job applicants apply for roles advertised on our website.

For most personal data processed within the platform on a Customer’s behalf — for example meeting content, HCP profiles, insights, and knowledge assessments — the Customer is the data controller and Pharmed Pulse acts as a processor / service provider under the Customer’s instructions and our agreement (including a Data Processing Agreement). Where we act as a processor, certain rights requests are best directed to the relevant Customer, and we will assist them in responding.

For a narrower set of data — such as account provisioning, app diagnostics, security, and lawful product improvement — Pharmed Pulse determines the purposes and means and acts as a controller. This Policy covers both roles.

For website visitors, enquirers, and job applicants, Pharmed Pulse is the controller. No Customer is involved in that processing, and requests relating to it should be made directly to us using the contact details in Section 18.

2. Information we collect

We collect the following categories of personal data, depending on your role and how the Services are configured by your Customer:

Categories of personal data
CategoryExamples
Account & identityName, work email, employer/Customer, role, credentials, authentication data.
MSL professional dataRole, team, assigned products and territories, in-app activity.
HCP professional profileName, professional title, specialty, institution/affiliation; where lawfully sourced, publications, clinical-trial involvement and other professional/scientific footprint data.
Meeting & interaction dataMeeting metadata (date, time, participants, product, topic), talking-point coverage, engagement and sentiment indicators, questionnaire responses, follow-up actions.
Audio recordingsWhere recording consent is given, audio of the scientific interaction.
Transcripts & AI-derived contentTranscriptions and AI-generated summaries, insights, sentiment, and knowledge/engagement scores derived from recordings or manual entry.
Biometric data (voiceprints)For certain speaker-attribution features, and only with your separate explicit consent, a voiceprint (a mathematical representation of voice characteristics). See Section 7.
Health-adjacent / clinical contentInteractions may reference clinical topics, treatments, and — incidentally — safety information or suspected adverse events.
Device & technical dataDevice model, OS, app version, device identifiers, IP address, crash and diagnostic logs.
Usage dataFeature usage, in-app actions, and timestamps.
Website visitor dataPages viewed, referring URL, approximate location derived from IP address, browser and device type, and session duration, recorded in standard server logs.
Enquiry and contact dataName, work email, company, job title, and the content of your message where you submit a contact form or request a walkthrough.
Recruitment dataName, contact details, CV or résumé, work history, right-to-work information, and correspondence relating to your application.
CommunicationsSupport requests and related correspondence.

Device permissions used by the apps

  • Microphone — to capture audio only during a consented recording.
  • Camera — (HCP app) to scan an MSL code/QR to start a session, where offered.
  • Files/Storage — to upload or view scientific documents.
  • Notifications — to deliver meeting and follow-up alerts.

We do not knowingly collect personal data from children. The Services are intended for professional use only. See Section 15.

3. Cookies and similar technologies

Our public website uses strictly necessary cookies only. These keep the site working — for example, maintaining your session and recording your preferences — and cannot be switched off.

We do not currently use analytics, advertising, or cross-context behavioural tracking cookies on our website. Because no non-essential cookies are set, no cookie consent banner is presented.

If we introduce analytics or any other non-essential cookies in future, we will update this Policy first and ask for your consent before setting them. You will be able to change that choice at any time.

Standard server logs are generated when you visit the website, as described in Section 2. These are used for security, diagnostics, and to keep the site available.

The RocketMSL mobile and web applications do not use advertising cookies or third-party advertising trackers. Crash-diagnostics and reliability tooling used within the applications is described in Section 9.

4. How we use personal data

We use personal data for the following purposes:

  • Providing, operating, and securing the Services;
  • Supporting pre-meeting preparation and generating planned scientific talking points;
  • Capturing and analyzing consented interactions (transcription, summaries, insights);
  • Generating HCP knowledge and engagement assessments by product and communication topic;
  • Detecting and routing safety, pharmacovigilance, and product-quality signals in line with the Customer’s approved processes;
  • Powering the scientific Digital Twin and follow-up recommendations;
  • Providing analytics and dashboards to authorized Customer users;
  • Security, fraud prevention, audit logging, and troubleshooting;
  • Operating and securing our public website;
  • Responding to enquiries submitted through our website, and sending you the information you asked for;
  • Assessing applications for employment;
  • Responding to support requests and communicating with you;
  • Complying with legal, regulatory, and safety-reporting obligations;
  • Improving the Services within the limits of applicable law and Customer instructions.

We use the information you submit through our contact form solely to respond to your enquiry. We do not add you to marketing lists without your consent.

5. AI and automated processing

The Services use artificial intelligence and machine learning, including third-party AI providers, to transcribe audio and to generate summaries, insights, and knowledge and engagement assessments.

Some processing involves profiling or scoring of HCP scientific knowledge and engagement. These outputs are decision-support aids intended for human review by MSLs and authorized Customer staff; they are not intended to be decisions based solely on automated processing that produce legal or similarly significant effects.

Where content is processed by third-party AI providers, it is subject to contractual protections. See Section 9 for our sub-processors.

6. Legal bases for processing (EEA / UK)

Where GDPR (or the UK GDPR) applies, we and/or the relevant Customer rely on the following legal bases:

Purposes and legal bases
PurposeLegal basis
Recording audio; creating voiceprints; marketingConsent (Art. 6(1)(a); Art. 9(2)(a) for special-category data).
Providing the Services to you as a userPerformance of a contract / Customer’s contract (Art. 6(1)(b)).
Security, product functionality, service improvementLegitimate interests (Art. 6(1)(f)).
Responding to website enquiriesLegitimate interests, or steps taken at your request prior to entering a contract (Art. 6(1)(f), Art. 6(1)(b)).
Assessing job applicationsSteps taken at your request prior to entering a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)).
Non-essential cookies, if introduced in futureConsent (Art. 6(1)(a)).
Safety / pharmacovigilance reportingLegal obligation (Art. 6(1)(c)); public-interest / vital-interest conditions where relevant.
Special-category (health / biometric) dataExplicit consent or another Art. 9 condition, as applicable.

7. Recording consent and biometric data

Recording consent

Audio recording of a scientific interaction only occurs when consent is obtained. An HCP may decline recording, in which case the interaction is documented manually without audio capture. The recording-consent prompt is not itself a general consent to this Policy.

Voiceprints and biometric data

Certain features (for example, attributing statements to individual speakers in a group interaction) may use a voiceprint. We process voiceprints only where the individual has provided separate, explicit opt-in consent. For these purposes:

  • We tell you why we collect the voiceprint and how it will be used before enrollment;
  • Enrollment is voluntary; you may decline, and speaker attribution can instead be confirmed manually by the MSL;
  • We retain voiceprints only as long as needed for the stated purpose, and delete them within 30 days of withdrawal of consent and in any event within three (3) years of your last interaction;
  • We do not sell or lease biometric data, and we protect it using the safeguards in Section 12.

These practices are designed to align with biometric-privacy laws, including the Illinois Biometric Information Privacy Act (BIPA) and comparable state laws. Our standalone biometric data policy and retention schedule are available on request.

8. International data transfers

Your personal data is processed in the United States, where Pharmed Pulse and its primary infrastructure are located. This includes data submitted through our website. If you access the Services from the European Economic Area, the United Kingdom, or another region with data-transfer restrictions, we and our Customers use appropriate safeguards for cross-border transfers — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or reliance on an adequacy decision, as applicable.

9. How we share personal data

We share personal data as follows and do not otherwise disclose it:

  • With the relevant Customer (the controller) and its authorized users.
  • With service providers / sub-processors who process data on our behalf under contract. These currently include Amazon Web Services (cloud hosting and storage) and OpenAI (AI/LLM processing of audio and text). Database, vector-search, and cache components operate within our AWS environment, and we use analytics and crash-diagnostics providers to keep the apps reliable. Our current list is maintained at https://www.rocketmsl.com/subprocessors.
  • For legal and regulatory reasons, including safety and pharmacovigilance reporting where required by law.
  • In a corporate transaction, such as a merger, acquisition, or asset sale, subject to this Policy.
  • With your consent or at your direction.

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

10. Data retention

We retain personal data for as long as necessary to fulfill the purposes described in this Policy, to comply with the Customer’s documented instructions, and to meet legal, audit, and regulatory obligations. Specifically:

  • Audio recordings are retained per the Customer’s configuration and deleted after analysis, unless linked to a safety or pharmacovigilance signal that must be retained longer to meet legal obligations;
  • Transcripts and derived insights are retained for the duration of the Customer relationship and for up to 90 days thereafter, unless a longer period is required by law or Customer instruction;
  • Voiceprints are deleted within 30 days of withdrawal of consent and in any event within three (3) years of the last interaction;
  • Account data is deleted within 90 days of account closure, subject to legal retention requirements;
  • Website enquiries are retained for 24 months from last contact, unless you become a Customer, in which case the information is retained under the Customer relationship;
  • Unsuccessful job applications are retained for 12 months, and we will delete them sooner on request;
  • Server logs are retained for a limited period for security and diagnostic purposes.

11. How we protect personal data

We maintain administrative, technical, and organizational safeguards designed to protect personal data, including:

  • Encryption in transit (TLS) and at rest (AES-256);
  • Role-based access controls and per-Customer tenant isolation;
  • Audit logging and monitoring;
  • Access restricted to personnel and sub-processors who need it to provide the Services.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Your privacy rights

EEA / UK (GDPR)

Subject to conditions, you may request access to, rectification of, or erasure of your personal data; restrict or object to processing; request data portability; and withdraw consent at any time without affecting prior processing. You may also lodge a complaint with your local supervisory authority.

United States (California and other states)

Depending on your state, you may have the right to know, access, delete, and correct personal information; to opt out of “sale” or “sharing” (we do not sell or share as defined); to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights.

To exercise any right, contact us at privacy@rocketmsl.com. Where Pharmed Pulse acts as a processor for a Customer, we will forward your request to the relevant Customer or assist them in responding. Where your request relates to website enquiry data or a job application, we handle it directly.

13. Job applicants

Where you apply for a role at Pharmed Pulse, we use the information you provide solely to assess your application and to communicate with you about it.

  • We do not use automated decision-making to screen applicants;
  • We share application information only with those involved in the hiring process;
  • Unsuccessful applications are retained for 12 months, and deleted sooner on request;
  • If we would like to keep your details on file for future roles, we will ask you first.

14. Health information (HIPAA)

Pharmed Pulse is generally not a HIPAA “covered entity.” To the extent it processes protected health information on behalf of a covered entity or business associate, it does so only under a Business Associate Agreement and consistent with that agreement.

15. Children’s privacy

The Services are intended for professional use by adults and are not directed to children. We do not knowingly collect personal data from anyone under the age required by applicable law. If you believe a child has provided us personal data, please contact us so we can delete it.

16. Third-party services and links

The Services may integrate with or link to third-party services (for example, a Customer’s systems of record). Their handling of your data is governed by their own privacy notices, not this Policy.

17. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice. Material changes affecting consented recording or biometric processing will be communicated before they take effect.

18. How to contact us

Contact details
FieldDetail
OperatorPharmed Pulse, Inc. (RocketMSL platform)
Address680 Amboy Ave, Woodbridge, NJ 07095-3120, United States
Phone+1 (416) 578-5588
Privacy contactprivacy@rocketmsl.com

© 2026 Pharmed Pulse, Inc. All rights reserved.