SuperPulse Privacy Policy

SuperPulse Collective Database Security & Data Protection Policy

Introduction


SuperPulse is committed to protecting client data, including sensitive patient information, with the highest security standards. This policy describes the framework for collective database hosting, where multiple clients agree to store their data in a shared environment. The collective model is designed to balance efficiency, cost-effectiveness, and compliance, while ensuring that each client’s data remains secure and segregated from others.

Controlled Collective Access Model

Under the collective database model, all client data is stored within a shared infrastructure. SuperPulse enforces strict tenant isolation, meaning that while data resides in the same database system, each client’s records are logically separated and protected by role-based access controls. No client can view, edit, or retrieve another client’s identifiable patient data. SuperPulse staff also operate under a zero-access policy, ensuring that only authorized client administrators can manage their own data.

Shared Infrastructure & Client Rights

Clients agree to host their data within this collective infrastructure, which is maintained and secured by SuperPulse. While SuperPulse manages uptime, patching, and compliance, ownership of the data remains fully with the client. Clients retain the right to request a full export of their data or migration to a private server environment at any time, ensuring flexibility and independence.

Business Continuity

In the event of any disruption to SuperPulse operations, collective database backups and encryption keys will be handed over to clients. Recovery protocols are standardized to guarantee uninterrupted access to patient data and clinical workflows, even in unforeseen circumstances.

Compliance with PDPA & GDPR

SuperPulse strictly adheres to the Personal Data Protection Act 2010 (Malaysia) and the General Data Protection Regulation (EU). Compliance measures include data minimisation, privacy-by-design principles, immutable audit trails and strong encryption standards. These frameworks ensure that collective hosting remains legally and ethically sound.

Security Controls

Security is enforced through multiple layers. Access to the system is protected by multi-factor authentication and firewalls. Network security is maintained through end-to-end encryption, brute-force protection, malware scanning, and segmented networks. Data pooling for analytics is strictly anonymised, ensuring no personally identifiable information is exposed. Finally, all data is encrypted at rest using AES-256, with decryption keys managed securely by SuperPulse.

Staff Legal Obligations

SuperPulse internal staff are legally bonded under company agreements to uphold strict data leak prevention measures. This binding obligation ensures that employees are contractually and legally accountable for safeguarding client information. Any breach of confidentiality or unauthorized disclosure is subject to disciplinary action, termination, and potential legal prosecution under applicable data protection laws. This measure reinforces SuperPulse’s zero-access policy and guarantees that staff conduct aligns with the highest standards of professional integrity and compliance.

Guarantees

SuperPulse guarantees that cross-client isolation prevents unauthorized access, export permissions require explicit client-admin approval, and encrypted data remains unintelligible even if leaked. The collective model ensures that breaches, if they occur, remain contained and do not compromise other clients.

Final Assurance

SuperPulse provides clinical-grade security in collective hosting. Clients retain ownership of their data while benefiting from shared infrastructure, collective analytics, and reduced hosting costs. This model offers a balance between efficiency and security, ensuring that patient information remains protected at all times.