Privacy Policy

This Privacy Policy explains how Pharmed Pulse, Inc. (“Pharmed Pulse,” “we,” “us,” or “our”), a company incorporated in the United States and operator of the RocketMSL platform, collects, uses, discloses, and protects personal data when you use our mobile applications, web platform, and related services (collectively, the “Services”). It applies to the RocketMSL applications distributed through the Apple App Store and Google Play, and to https://www.rocketmsl.com.

RocketMSL is an AI-native Medical Affairs platform used by Medical Science Liaisons (MSLs) and Healthcare Professionals (HCPs) to prepare for, capture, and analyze scientific interactions. Please read this Policy alongside any notices presented inside the app.

  • Our role and your relationship with us

RocketMSL is licensed to pharmaceutical and life-sciences organizations (each, a “Customer”). How you relate to us depends on how you use the Services:

  • MSL users access the Services as authorized users of a Customer (typically their employer).
  • HCP users interact with the Services in connection with a Customer’s scientific engagement activities.

For most personal data processed within the platform on a Customer’s behalf — for example meeting content, HCP profiles, insights, and knowledge assessments — the Customer is the data controller and Pharmed Pulse acts as a processor / service provider under the Customer’s instructions and our agreement (including a Data Processing Agreement). Where we act as a processor, certain rights requests are best directed to the relevant Customer, and we will assist them in responding.

For a narrower set of data — such as account provisioning, app diagnostics, security, and lawful product improvement — Pharmed Pulse determines the purposes and means and acts as a controller. This Policy covers both roles.

  • Information we collect

We collect the following categories of personal data, depending on your role and how the Services are configured by your Customer:

Category Examples
Account & identity Name, work email, employer/Customer, role, credentials, authentication data.
MSL professional data Role, team, assigned products and territories, in-app activity.
HCP professional profile Name, professional title, specialty, institution/affiliation; where lawfully sourced, publications, clinical-trial involvement and other professional/scientific footprint data.
Meeting & interaction data Meeting metadata (date, time, participants, product, topic), talking-point coverage, engagement and sentiment indicators, questionnaire responses, follow-up actions.
Audio recordings Where recording consent is given, audio of the scientific interaction.
Category
Account & identity
Examples
Name, work email, employer/Customer, role, credentials, authentication data.
Category
MSL professional data
Examples
Role, team, assigned products and territories, in-app activity.
Category
HCP professional profile
Examples
Name, professional title, specialty, institution/affiliation; where lawfully sourced, publications, clinical-trial involvement and other professional/scientific footprint data.
Category
Meeting & interaction data
Examples
Meeting metadata (date, time, participants, product, topic), talking-point coverage, engagement and sentiment indicators, questionnaire responses, follow-up actions.
Category
Audio recordings
Examples
Where recording consent is given, audio of the scientific interaction.
Category Examples
Transcripts & AI-derived content Transcriptions and AI-generated summaries, insights, sentiment, and knowledge/engagement scores derived from recordings or manual entry.
Biometric data (voiceprints) For certain speaker-attribution features, and only with your separate explicit consent, a voiceprint (a mathematical representation of voice characteristics). See Section 6.
Health-adjacent / clinical content Interactions may reference clinical topics, treatments, and — incidentally — safety information or suspected adverse events.
Device & technical data Device model, OS, app version, device identifiers, IP address, crash and diagnostic logs.
Usage data Feature usage, in-app actions, and timestamps.
Communications Support requests and related correspondence.
Category
Transcripts & AI-derived content
Examples
Transcriptions and AI-generated summaries, insights, sentiment, and knowledge/engagement scores derived from recordings or manual entry.
Category
Biometric data (voiceprints)
Examples
For certain speaker-attribution features, and only with your separate explicit consent, a voiceprint (a mathematical representation of voice characteristics). See Section 6.
Category
Health-adjacent / clinical content
Examples
Interactions may reference clinical topics, treatments, and — incidentally — safety information or suspected adverse events.
Category
Device & technical data
Examples
Device model, OS, app version, device identifiers, IP address, crash and diagnostic logs.
Category
Usage data
Examples
Feature usage, in-app actions, and timestamps.
Category
Communications
Examples
Support requests and related correspondence.

Device permissions used by the apps

  • Microphone — to capture audio only during a consented recording.
  • Camera — (HCP app) to scan an MSL code/QR to start a session, where offered.
  • Files/Storage — to upload or view scientific documents.
  • Notifications — to deliver meeting and follow-up alerts.
  • How we use personal data

We use personal data for the following purposes:

  • Providing, operating, and securing the Services;
  • Supporting pre-meeting preparation and generating planned scientific talking points;Supporting pre-meeting preparation and generating planned scientific talking points;
  • Capturing and analyzing consented interactions (transcription, summaries, insights);
  • Generating HCP knowledge and engagement assessments by product and communication topic;
  • Detecting and routing safety, pharmacovigilance, and product-quality signals in line with the Customer’s approved processes;
  • Powering the scientific Digital Twin and follow-up recommendations;
  • Providing analytics and dashboards to authorized Customer users;
  • Security, fraud prevention, audit logging, and troubleshooting;
  • Responding to support requests and communicating with you;
  • Complying with legal, regulatory, and safety-reporting obligations;
  • Improving the Services within the limits of applicable law and Customer instructions.

Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity. Transcure does not knowingly collect any Personal Identifiable Information from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.

  • AI and automated processing

The Services use artificial intelligence and machine learning, including third-party AI providers, to transcribe audio and to generate summaries, insights, and knowledge and engagement assessments.

Some processing involves profiling or scoring of HCP scientific knowledge and engagement. These outputs are decision-support aids intended for human review by MSLs and authorized Customer staff; they are not intended to be decisions based solely on automated processing that produce legal or similarly significant effects.

  • Legal bases for processing (EEA / UK)

Where GDPR (or the UK GDPR) applies, we and/or the relevant Customer rely on the following legal bases:

Purpose Legal basis
Recording audio; creating voiceprints; marketing Consent (Art. 6(1)(a); Art. 9(2)(a) for special-category data).
Providing the Services to you as a user Performance of a contract / Customer's contract (Art. 6(1)(b)).
Security, product functionality, service improvement Legitimate interests (Art. 6(1)(f)).
Safety / pharmacovigilance reporting Legal obligation (Art. 6(1)(c)); public-interest / vital-interest conditions where relevant.
Special-category (health / biometric) data Explicit consent or another Art. 9 condition, as applicable.
Purpose
Recording audio; creating voiceprints; marketing
Legal basis
Consent (Art. 6(1)(a); Art. 9(2)(a) for special-category data).
Purpose
Providing the Services to you as a user
Legal basis
Performance of a contract / Customer's contract (Art. 6(1)(b)).
Purpose
Security, product functionality, service improvement
Legal basis
Legitimate interests (Art. 6(1)(f)).
Purpose
Safety / pharmacovigilance reporting
Legal basis
Legal obligation (Art. 6(1)(c)); public-interest / vital-interest conditions where relevant.
Purpose
Special-category (health / biometric) data
Legal basis
Explicit consent or another Art. 9 condition, as applicable.
  • Recording consent and biometric data

Recording consent
Audio recording of a scientific interaction only occurs when consent is obtained. An HCP may decline recording, in which case the interaction is documented manually without audio capture. The recording-consent prompt is not itself a general consent to this Policy.

Voiceprints and biometric data
Certain features (for example, attributing statements to individual speakers in a group interaction) may use a voiceprint. We process voiceprints only where the individual has provided separate, explicit opt-in consent. For these purposes:

  • We tell you why we collect the voiceprint and how it will be used before enrollment;
  • Enrollment is voluntary; you may decline, and speaker attribution can instead be confirmed manually by the MSL;
  • We retain voiceprints only as long as needed for the stated purpose, and delete them within 30 days of withdrawal of consent and in any event within three (3) years of your last interaction;
  • We do not sell or lease biometric data, and we protect it using the safeguards in Section 10.

These practices are designed to align with biometric-privacy laws, including the Illinois Biometric Information Privacy Act (BIPA) and comparable state laws. Our standalone biometric data policy and retention schedule are available on request.

  • How we share personal data

We share personal data as follows and do not otherwise disclose it:

  • With the relevant Customer (the controller) and its authorized users.
  • With service providers / sub-processors who process data on our behalf under contract. These currently include Amazon Web Services (cloud hosting and storage) and OpenAI (AI/LLM processing of audio and text). Database, vector-search, and cache components operate within our AWS environment, and we use analytics and crash-diagnostics providers to keep the apps reliable. Our current list is maintained at https://www.rocketmsl.com/subprocessors.
  • For legal and regulatory reasons, including safety and pharmacovigilance reporting where required by law.
  • In a corporate transaction, such as a merger, acquisition, or asset sale, subject to this Policy.
  • With your consent or at your direction.

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

  • International data transfers

Your personal data is processed in the United States, where Pharmed Pulse and its primary infrastructure are located. If you access the Services from the European Economic Area, the United Kingdom, or another region with data-transfer restrictions, we and our Customers use appropriate safeguards for cross-border transfers — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or reliance on an adequacy decision, as applicable.

  • Data retention

We retain personal data for as long as necessary to fulfill the purposes described in this Policy, to comply with the Customer’s documented instructions, and to meet legal, audit, and regulatory obligations. Specifically:

  • Audio recordings are retained per the Customer’s configuration and deleted after analysis, unless linked to a safety or pharmacovigilance signal that must be retained longer to meet legal obligations;
  • Transcripts and derived insights are retained for the duration of the Customer relationship and for up to 90 days thereafter, unless a longer period is required by law or Customer instruction;
  • Voiceprints are deleted within 30 days of withdrawal of consent and in any event within three (3) years of the last interaction;
  • Account data is deleted within 90 days of account closure, subject to legal retention requirements.
  • How we protect personal data

We maintain administrative, technical, and organizational safeguards designed to protect personal data, including:

  • Encryption in transit (TLS) and at rest (AES-256);
  • Role-based access controls and per-Customer tenant isolation;
  • Audit logging and monitoring;
  • Access restricted to personnel and sub-processors who need it to provide the Services.
  • Your privacy rights
EEA / UK (GDPR)
Subject to conditions, you may request access to, rectification of, or erasure of your personal data; restrict or object to processing; request data portability; and withdraw consent at any time without affecting prior processing. You may also lodge a complaint with your local supervisory authority.

United States (California and other states)
Depending on your state, you may have the right to know, access, delete, and correct personal information; to opt out of “sale” or “sharing” (we do not sell or share as defined); to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights.

Depending on your state, you may have the right to know, access, delete, and correct personal information; to opt out of “sale” or “sharing” (we do not sell or share as defined); to limit the use of sensitive personal information; and to be free from discrimination for exercising these rights.

  • Health information (HIPAA)

Pharmed Pulse is generally not a HIPAA “covered entity.” To the extent it processes protected health information on behalf of a covered entity or business associate, it does so only under a Business Associate Agreement and consistent with that agreement.

  • Children’s privacy

The Services are intended for professional use by adults and are not directed to children. We do not knowingly collect personal data from anyone under the age required by applicable law. If you believe a child has provided us personal data, please contact us so we can delete it.

  • Third-party services and links

The Services may integrate with or link to third-party services (for example, a Customer’s systems of record). Their handling of your data is governed by their own privacy notices, not this Policy.

  • Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice. Material changes affecting consented recording or biometric processing will be communicated before they take effect.

  • How to contact us
Operator Pharmed Pulse, Inc. (RocketMSL platform)
Address 680 Amboy Ave, Woodbridge, NJ 07095-3120, United States
Phone +1 (416) 578-5588
Privacy contact privacy@rocketmsl.com
Operator
Pharmed Pulse, Inc. (RocketMSL platform)
Address
680 Amboy Ave, Woodbridge, NJ 07095-3120, United States
Phone
+1 (416) 578-5588
Privacy contact