← Back to Pulse

Privacy policy

Pulse by Code Khalaq · Effective 27 August 2026

Pulse is an AI receptionist and front desk automation service for healthcare practices, built and operated by Code Khalaq ("we", "us"). This policy explains what we collect on the Pulse pages of codekhalaq.com, what the Pulse service processes on behalf of the practices that use it, and the choices you have. It applies to Pulse specifically; the rest of codekhalaq.com may be covered by its own notices.

What we collect on this website

  • Booking details. When you book a call through the calendar on this page, Calendly collects the details you enter (name, email, and anything you add to the booking) and shares them with us so we can hold the meeting. Calendly's own privacy notice applies to that form.
  • Contact details. If you email us or use the contact form on codekhalaq.com, we keep your message and contact details to reply and follow up.
  • Technical logs. Our web server records standard request logs (IP address, pages requested, timestamps) for security and reliability. The Pulse pages set no advertising cookies and run no third-party analytics or tracking scripts.

What the Pulse service processes for practices

When a practice runs Pulse, the AI receptionist handles calls and messages on that practice's behalf. In that relationship the practice is the data controller (or covered entity) and we act as its service provider (or business associate), processing data only to deliver the service:

  • Call data. Audio, transcripts, and structured details a caller provides (for example a requested appointment time or a callback number), used to answer the call, book or change appointments, and hand anything clinical to the practice's staff.
  • Scheduling and intake data. Appointment details and intake answers, written into the practice's own calendar, practice management system, or EHR.
  • Minimization by design. We keep protected health information out of places it does not belong, limit what the AI hears and stores to what the workflow needs, and never use a practice's patient data to advertise, sell, or profile.
  • Business associate agreements. For US practices subject to HIPAA, we contract accordingly, including a BAA where required, before live patient traffic flows.

How long we keep data

Website enquiries and booking details are kept for as long as we are in an active conversation with you and for a reasonable period afterwards. For practices using Pulse, call logs and transcripts are retained per the terms agreed with that practice, and deleted or returned when the engagement ends.

Security

Data is encrypted in transit and at rest. Access is limited to the people who need it to run the service, and conversations handled by Pulse are logged and auditable so a practice can always see what its receptionist said and did.

Sharing

We do not sell personal information. We share data only with the subprocessors needed to run the service (for example telephony and scheduling infrastructure), under contracts that bind them to protect it, and with a practice's own systems as configured by that practice.

Your rights

Depending on where you live (including the UK and EU under GDPR, and various US states), you may have rights to access, correct, or delete personal information we hold about you, and to object to or restrict certain processing. If you are a patient of a practice that uses Pulse, please contact your practice first — it controls your records, and we will support its response.

Contact

Questions about this policy or your data: hello@codekhalaq.com.

Changes

If this policy changes, we will update this page and its effective date. Material changes affecting practices under contract are communicated directly.