Impulsion

Effective August 24, 2026 · Last updated August 24, 2026 · Version 2026-08-24

Government & Law Enforcement Data Request Policy

This policy describes how Impulsion Systems, Inc., operating as Impulsion ("we", "us", "our"), responds to requests from law enforcement agencies, courts, regulators, and other government or public authorities — domestic or foreign — for information about the businesses ("Barns") and individuals who use the Impulsion platform. It applies to every such request, on every channel, in every jurisdiction in which we operate.

For authorities: serve legal process in writing to privacy@impulsion.io, addressed to Impulsion Systems, Inc., 15202 Carrs Mill Road, Woodbine, MD 21797, USA. We do not accept legal process by phone or social media, and we do not disclose user data in response to informal requests.

1. Scope

This policy covers all demands and requests for user data from public authorities, including subpoenas, court orders, search warrants, national-security process, and informal or emergency requests, whether directed at us as a controller of our own account and security data or as a processor/service provider handling a Barn's data on its instructions.

2. How requests must reach us

3. Legality review — before anything else

Every request receives a legality review before any data is disclosed. Designated personnel, with outside counsel where needed, verify that the request: (a) was issued by an authority with jurisdiction; (b) uses the type of legal process the requested data requires under applicable law — in the United States, including the Stored Communications Act, under which we require a search warrant for the content of communications; (c) is authentic and properly served; and (d) is specific about the data and accounts sought. A request that fails this review is not fulfilled.

4. Challenging overbroad or unlawful requests

We do not treat legal process as self-executing. If a request is legally deficient, overbroad, vague, seeks data protected from disclosure, or appears to be an abuse of process, we push back: we reject it, ask the authority to narrow it, or seek relief from a court, including moving to quash or modify the demand. Where we act as a processor for a Barn, we also refer the authority to the Barn (the controller of its own customer data) and notify the Barn, unless we are legally prohibited from doing so.

5. Data minimization

When a request survives review, we disclose only the specific data the legal process expressly and lawfully compels, interpreted narrowly — never whole-account exports, adjacent records, or data about users the process does not name. Where a narrower category of data satisfies the request on its face, we produce the narrower category.

6. Notice to affected users

Our policy is to notify the affected Barn or user before disclosing their data, so they may seek their own legal remedies, unless we are legally prohibited from doing so (for example by a non-disclosure order) or notice would create a risk of harm. Where a prohibition is time-limited, we provide notice after it expires.

7. Documentation

We maintain a written record of every government or law-enforcement request we receive, including the date received, the requesting authority, the type of legal process, the data sought, the legality-review outcome, any challenge or narrowing, what (if anything) was disclosed, and the date of the response. These records are retained for at least five years and reviewed as part of our periodic compliance reviews.

8. Emergency requests

Where an authority asserts an emergency involving imminent danger of death or serious physical injury, we may disclose the minimum information necessary to address the emergency, as permitted by applicable law. Emergency requests receive the same documentation as any other request, and an after-the-fact legality review.

9. National-security requests

Requests made under national-security authorities are handled in accordance with the laws that govern them, subject to the same principles of legality review, minimization, and documentation to the fullest extent those laws allow.

10. What we never do

11. Governance

This policy is owned by the management of Impulsion Systems, Inc., is reviewed at least annually, and binds our personnel and contractors. Questions about it may be sent to privacy@impulsion.io. Our Privacy Policy is at https://api.impulsion.io/privacy.