Privacy
Privacy Policy
NumuPulse is used by schools to make everyday learning signals easier to understand. Because that involves information about children, this page explains what we collect, why, and who controls it.
1. Who controls the information
When a school uses NumuPulse, the school decides what information is entered, who may see it, and how long it is kept. The school is the controller of that information. NumuPulse acts as a processor: we handle information on the school's instructions and under our agreement with them.
This matters for parents and students in practice: if you want a record corrected or removed, your school is the right first contact, because they hold the relationship with the learner and the authority over the record. We support schools in acting on those requests.
For information you give us directly — for example, contacting us through this website — NumuPulse is the controller.
NumuPulse operates from Malaysia. This policy is governed by the laws of Malaysia, including the Personal Data Protection Act 2010 (as amended), where it applies.
2. What we collect
Account and sign-in information
- Your email address, used to sign you in with a one-time code.
- Activation codes, where a school invites you to join that way.
- Your role — student, teacher, parent or guardian, school staff — which determines what you are able to see.
- A device identifier stored on your device. It identifies the device, not you personally, and is used to keep your session secure.
Learning information, provided by the school
Schools and teachers record information as part of normal teaching. Depending on what a school chooses to use, this can include:
- Class, subject, and topic structure, and which learners belong to which class.
- Lesson check-ins and class pulse responses.
- Questions a learner has asked, and assignments and their progress.
- Attendance records.
- Wellbeing check-ins and notes recorded by staff.
- Insights generated from the above — for example, that a topic appears secure or that a learner may need support.
- Messages and notifications sent between the people connected to a learner.
Technical information
- Basic information needed to operate and secure the service, such as the app version and the fact that a request was made, so we can diagnose faults and prevent abuse.
The current mobile apps do not include third-party analytics, crash-reporting, or push notification services. Our servers produce operational logs, metrics, and traces to keep the service reliable and secure. The logging controls are designed to exclude message bodies, passwords, one-time codes, tokens, email addresses, and other sensitive request content.
3. Children's information
NumuPulse is designed for use in schools, and much of the information in it concerns children. We treat that information as sensitive by default.
- Accounts for learners are created by the school, not by children signing up.
- We do not use children's information to show advertising, and we do not build profiles for marketing.
- Insight wording is written to describe learning and suggest next steps, rather than to label a child.
NumuPulse is operated from Malaysia and handles personal information in accordance with applicable Malaysian law, including the Personal Data Protection Act 2010 (as amended). The school is responsible for having the authority, notices, and consents required to provide learner information to NumuPulse. If a school is subject to additional local education or children's privacy rules, we work with that school under the applicable service agreement and processing instructions.
4. How we use information
We use information to:
- Sign you in and keep your account secure.
- Show you the views appropriate to your role.
- Turn recorded learning signals into insights for the people entitled to see them.
- Send notifications you or your school have asked for.
- Keep the service working, diagnose faults, and prevent misuse.
- Meet our legal obligations.
We do not sell personal information, and we do not share it for advertising.
NumuPulse does not use personal information to train machine-learning or generative-AI models. The current insight engine applies deterministic, explainable rules to the learning information recorded by the school. We may use aggregated operational information that does not identify a learner to understand reliability and improve the service.
5. Who we share it with
Information is shared only in these situations:
- With people at your school, according to their role — a teacher sees their classes, a parent sees their own child, school staff see their school.
- With Google Cloud, which hosts the service on our behalf. Google stores and processes information under our instructions and does not use it for its own purposes.
- Where the law requires it, or to protect the safety of a person.
We also use an email delivery service to send one-time sign-in codes, invitations, and requested communications. That service receives the recipient's email address and the email content for delivery. The current release does not use an SMS provider, a mobile analytics or crash-reporting provider, or a push-notification provider. We require service providers to process information only to provide their contracted service.
6. Where information is processed
The NumuPulse service runs on Google Cloud, and its application services are hosted in Google's asia-southeast1 region in Singapore. Information may be accessed by our team elsewhere in order to operate and support the service.
Our team is based in Malaysia. Because the application is hosted in Singapore, using NumuPulse can involve a transfer of personal information from Malaysia, or from the school's country, to Singapore. We and the school use the contractual and other safeguards required by applicable law for those transfers.
7. How we protect it
- Connections between the apps and our service are encrypted in transit.
- Sign-in credentials and session tokens are held in the device's secure storage — the Keychain on iOS, and the equivalent protected storage on Android.
- Access is shaped by role, so people see the learning context their responsibility covers rather than everything in the school.
- Signing out clears the session on the device, and signing out everywhere ends every active session for the account.
No service can promise perfect security, but we aim to keep the amount of information visible to any one person no larger than their role requires.
Data stored by the service uses the encryption at rest provided by its managed Google Cloud storage and database services. Secrets are supplied through managed secret storage, internal services are private behind the gateway, and security-sensitive events are recorded for investigation. If a personal-data breach occurs, we will notify affected schools and the relevant authorities as required by applicable law and our agreements with those schools.
8. How long we keep it
We keep information for as long as the school needs it to run NumuPulse, and then for any period the law requires. When a school ends its use of NumuPulse, we delete or return the information it controls in line with our agreement with that school.
The school sets the retention period for learner and school records through its agreement with us. Authentication data has shorter technical lifetimes: one-time sign-in codes expire after 10 minutes, emailed activation codes after 7 days, printed activation codes after 60 days, and a normal refresh session after 30 days unless it is revoked sooner. Deleted information may remain temporarily in restricted backups until those backups are overwritten under the hosting provider's backup cycle.
9. Your rights and choices
Depending on where you live, you may have the right to ask for a copy of your information, to have it corrected or deleted, to object to certain uses, or to complain to a regulator.
For information held on behalf of a school — which is most information in NumuPulse — please contact the school first. They control the record and can act on it directly. If you contact us instead, we will pass the request to the school and support them in responding.
For information you gave us directly, such as an enquiry through this website, contact us using the details below.
We respond within the period required by applicable law. Before acting, we may verify a request through the signed-in account, the account's email address, and the relevant school. In Malaysia, you may raise a concern with the Personal Data Protection Commissioner if you believe your personal information has not been handled lawfully.
10. Changes to this policy
We update this page when the service changes. The date at the top shows when it last changed. If a change materially affects how information about learners is handled, we will tell schools before it takes effect.
11. Contact us
For any privacy question, or to exercise a right described above, contact us at privacy@numupulse.com.
If you are a parent or student, contacting your school first is usually the fastest route, because the school controls the record.