How we handle your data.
Pulse by MHK is a managed service that classifies and organizes email inside your Microsoft 365 environment. This page explains, in plain language, what data the service touches, where it lives, and what rights you have over it.
Who we are
Pulse by MHK is built and operated by MHK Managed Technology Partner, a managed IT services firm based in Fair Lawn, New Jersey. We have provided managed services across New Jersey, New York, and Virginia for more than thirty years. Pulse is one of the services we deliver to clients within their own Microsoft 365 environments.
What data Pulse accesses
With the consent of your tenant administrator, Pulse uses the Microsoft Graph API to access:
- Mailbox contents, including emails, folders, and metadata for each authorized mailbox
- Read and write access to mail, so the service can classify messages and move them between folders
- Read access to user profile information, used for personalization within digest emails
Pulse does not access calendars, contacts, files, Teams messages, or any other Microsoft 365 resource outside of mail. Digests are delivered on Eastern-time schedules, configured per client or mailbox as Eastern-time slots; Pulse does not read each mailbox's individual time zone.
What data Pulse stores
The service retains the minimum data needed to classify mail and improve over time:
- Email metadata, including subject lines, sender and recipient addresses, timestamps, and folder paths
- Classification decisions made by the system, and any user corrections to those decisions
- Your folder structure and routing taxonomy
- A limited audit trail of administrative actions, such as when a mailbox was connected or removed, and by whom
- Aggregate statistics on email volume and classification accuracy
Pulse does not store the body or full content of email messages. Message bodies are read only transiently, for the moment needed to classify or summarize a message, and are not written to Pulse's storage. Pulse does not store attachments.
Thread summaries are not stored. When a user asks Pulse to summarize a thread from the Outlook add-in, the summary is generated on demand, shown to the user, and not stored. Reopening a thread generates a fresh summary. No summaries, message bodies, or attachments are written to Pulse's storage. Apart from these summaries, no message content is written to durable storage.
Where data lives
- Metadata is stored in Azure Table Storage in Microsoft's East US 2 region
- Classification is performed by Azure OpenAI, hosted within Microsoft's US infrastructure
- All Pulse infrastructure runs inside MHK's own Microsoft Azure tenant
- No data is shared with third-party analytics, advertising, or AI providers outside Microsoft
Who can access your data
- Authorized MHK technicians, for setup, monitoring, tuning, and support
- Your own users, through their normal Outlook inbox
- Microsoft, as the underlying platform provider for Microsoft 365 and Azure
No other parties have access. Pulse data is never sold, licensed, or shared for marketing purposes.
Data retention
While the service is active, mailbox metadata and classification history are retained so the system can continue to learn and produce digests. If you cancel the service, all client-specific data is purged within 30 days of cancellation.
Aggregate, anonymized statistics, such as overall classification accuracy across all clients, may be retained beyond that window for product improvement. These contain no identifying information.
Your rights
You may, at any time:
- Request a copy of the data Pulse holds about you or your organization
- Request deletion of that data
- Cancel the service entirely, which initiates the 30-day purge described above
To exercise any of these rights, contact MHK using the details at the bottom of this page.
Security
- All data is encrypted at rest using Azure Storage's default service-managed encryption
- All data is encrypted in transit using TLS 1.2 or higher
- Access to Pulse infrastructure is controlled through Microsoft Entra ID and managed identities, with no shared credentials
- MHK reviews the service's security posture on a regular cadence
Changes to this policy
This policy may change as the service evolves. Material changes will be communicated to clients in advance. The effective date at the top of this page reflects the most recent revision.
Contact
Questions about this policy, or requests to exercise your rights, can be directed to:
Fair Lawn, NJ 07410