Government & Law Enforcement Data Request Policy
This policy describes how Impulsion Systems, Inc., operating as Impulsion ("we", "us", "our"), responds to requests from law enforcement agencies, courts, regulators, and other government or public authorities — domestic or foreign — for information about the businesses ("Barns") and individuals who use the Impulsion platform. It applies to every such request, on every channel, in every jurisdiction in which we operate.
1. Scope
This policy covers all demands and requests for user data from public authorities, including subpoenas, court orders, search warrants, national-security process, and informal or emergency requests, whether directed at us as a controller of our own account and security data or as a processor/service provider handling a Barn's data on its instructions.
2. How requests must reach us
- Requests must be made in writing, identify the requesting authority and the legal basis for the request, describe the specific data sought and the specific account(s) concerned, and be validly issued and properly served under the law that governs the authority making them.
- Requests from authorities outside the United States must proceed through a mutual legal assistance treaty (MLAT), letters rogatory, or another mechanism that results in legal process valid in the United States, unless United States law expressly permits a direct response.
3. Legality review — before anything else
Every request receives a legality review before any data is disclosed. Designated personnel, with outside counsel where needed, verify that the request: (a) was issued by an authority with jurisdiction; (b) uses the type of legal process the requested data requires under applicable law — in the United States, including the Stored Communications Act, under which we require a search warrant for the content of communications; (c) is authentic and properly served; and (d) is specific about the data and accounts sought. A request that fails this review is not fulfilled.
4. Challenging overbroad or unlawful requests
We do not treat legal process as self-executing. If a request is legally deficient, overbroad, vague, seeks data protected from disclosure, or appears to be an abuse of process, we push back: we reject it, ask the authority to narrow it, or seek relief from a court, including moving to quash or modify the demand. Where we act as a processor for a Barn, we also refer the authority to the Barn (the controller of its own customer data) and notify the Barn, unless we are legally prohibited from doing so.
5. Data minimization
When a request survives review, we disclose only the specific data the legal process expressly and lawfully compels, interpreted narrowly — never whole-account exports, adjacent records, or data about users the process does not name. Where a narrower category of data satisfies the request on its face, we produce the narrower category.
6. Notice to affected users
Our policy is to notify the affected Barn or user before disclosing their data, so they may seek their own legal remedies, unless we are legally prohibited from doing so (for example by a non-disclosure order) or notice would create a risk of harm. Where a prohibition is time-limited, we provide notice after it expires.
7. Documentation
We maintain a written record of every government or law-enforcement request we receive, including the date received, the requesting authority, the type of legal process, the data sought, the legality-review outcome, any challenge or narrowing, what (if anything) was disclosed, and the date of the response. These records are retained for at least five years and reviewed as part of our periodic compliance reviews.
8. Emergency requests
Where an authority asserts an emergency involving imminent danger of death or serious physical injury, we may disclose the minimum information necessary to address the emergency, as permitted by applicable law. Emergency requests receive the same documentation as any other request, and an after-the-fact legality review.
9. National-security requests
Requests made under national-security authorities are handled in accordance with the laws that govern them, subject to the same principles of legality review, minimization, and documentation to the fullest extent those laws allow.
10. What we never do
- We never sell user data to any government, and we never provide any authority with direct, standing, or bulk access to user data or to our systems.
- We never disclose data in response to a request that has not passed the legality review in Section 3.
11. Governance
This policy is owned by the management of Impulsion Systems, Inc., is reviewed at least annually, and binds our personnel and contractors. Questions about it may be sent to privacy@impulsion.io. Our Privacy Policy is at https://api.impulsion.io/privacy.