01DATA SCOPE

What we measure, and what we never touch.

A tool that measures how people work with AI can be built two ways: by watching them, or by looking at work they and their colleagues already assess. HRPulsar is the second kind, and this page is the written boundary — the one a works council or a security reviewer can hold us to.

Last updated: July 28, 2026

Draft · pending US legal review

This page describes the product boundary we design and build against. It is not a contract on its own — the binding version is the Data Processing Agreement, which we share on request while the Privacy Policy is still with counsel. For that, or for a works-council review pack, email privacy@hrpulsar.com.

02SIGNALS

Three lists and a publication rule.

What the product uses today, what is still being built, what it will not collect at any point — and what leaves your workspace.

Evidence we use
  • Assessment results

    Self, 180° and 360° assessments, plus calibration outcomes. Someone answers questions; the answers are the data.

  • Competency and grading records

    The competency framework of the company, the level a person holds, and the history of changes to it.

  • Exam outcomes

    Scores from the knowledge tests a workspace runs — the result, not a recording of the person taking it.

  • Recruiting artifacts candidates submit

    CVs, skill checks and interview records inside the hiring process the candidate applied to — not scraped profiles.

Planned · not shipped
  • AI Fluency level, in the product

    The Hoffman scale is a public self-assessment on this site today — it runs in your browser and stores no answers. Inside the platform, the fluency score and the verified, portable level are being built on the evidence the assessment modules already collect; the evidence behind a level will be visible to the person it describes.

  • Aggregated usage signals

    Seat and activity counts from AI tools a workspace admin explicitly connects. When they ship they follow the same rule as everything above: counts and outcomes, never content — and this page gets updated before the feature does.

What we never collect
  • Prompt and conversation content

    We do not read what a person types into an AI tool, and we do not store it. Fluency is measured from outcomes and assessments, never from transcripts.

  • Keystrokes, screenshots, screen recording

    No agent on the endpoint, no activity capture, no idle-time tracking. There is nothing to install on a laptop.

  • Private messages, email, browsing history

    HRPulsar does not connect to a mailbox or a chat account to infer anything about a person.

  • Off-hours behaviour or location

    Working hours, presence and physical location are not signals in any score we produce.

Publication rule

Your workspace data stays yours. Nothing identifying a person or a company leaves it, and an industry benchmark is published only once at least 20 tenants are in that industry — the k-anonymity threshold. Below it, no number is published at all.

03VISIBILITY

The employee is not the last to know.

A measurement a person cannot see is a measurement they cannot argue with. Both sides of the table read the same record.

What a manager sees

  • Team-level skill and fluency distribution, and the gaps behind it
  • Assessment results for their own reports, with the evidence attached
  • Progress against development plans they agreed with the person

What the employee sees

  • Everything their manager sees about them — same numbers, same evidence
  • Their own fluency level, how it was derived, and what moves it
  • A copy of their record on request, and a route to dispute any result in it
04RIGHTS AND GDPR

Built for the jurisdiction with the strict rules.

Access

A person sees their own assessment results and their own profile inside the product. For a full structured copy of an employee record, a subject-access request under GDPR Article 15 is answered by us on the statutory timeline; on the recruiting side the export is already automated end to end.

Dispute

A result a person disagrees with has to be reviewable by a human, with the outcome recorded. The software does not carry a dedicated dispute object yet, so today this is a contractual obligation in the DPA that we handle case by case — stated that way rather than dressed up as a feature.

Human decisions, not automated verdicts

The AI in the product scores resumes, marks exams and recommends grades — all of it as input to a decision a person makes and signs off. No firing, promotion or compensation outcome is issued by the platform. Whether a specific use of it engages GDPR Article 22 is a call for your counsel; we build for meaningful human review and will document the flow for that assessment.

Data minimisation and retention

We store what the modules in use require. Retention windows are configurable for recruiting data today; there is no workspace-wide retention setting for assessment and competency records yet, so deletion for those runs through us as a contractual commitment until it does.

05WORKS COUNCILS

In the Netherlands and Germany, this conversation happens first.

Where a works council exists, a system that sets how employees are assessed normally needs its agreement before procurement signs anything — Article 27 of the Dutch WOR, and §94(2) of the German BetrVG for assessment principles. The monitoring paragraph (§87(1) no. 6) is the one we are built to stay out of: there is no endpoint agent and no activity capture to co-determine. We treat the council conversation as the normal path, not an obstacle — the scope on this page exists so the answer to “what does it watch?” is a document rather than a meeting.

On request we send a review pack: this data scope, the DPA, the sub-processor list, the retention windows that exist today, and the self-host option — under which none of the data leaves your own infrastructure and no cross-company signal is shared at all.