Last update
July 15, 2026

Terms of Use

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")
Chevron Right
The agreements and policies that govern the Buro 1 website and the Pulse platform. If you have a signed agreement with Buro 1 (Order Form, DPA, SOW, SLA), it controls over these pages. For registered platform users, the Pulse Clickwrap Agreement controls over the informational sections below. Each section below carries its own effective date and version. The End User License Agreement and the Privacy Policy are published as separate documents.

A Data Processing Addendum (DPA) is available for signature on request. A Service Level Agreement (SLA) is available to Enterprise customers by signed agreement. Contact info@buro-1.com.

These Terms of Use govern your access to and use of the Buro 1 website ("Website"). Use of the Pulse platform is governed by a separate agreement — the Pulse Clickwrap Agreement (End-User Licence Agreement) — which applies when you register as a platform user. By accessing the Website, you agree to these Terms of Use. If you do not agree, do not use the Website.

1. Who We Are

BURO ONE MANAGEMENT CONSULTANCIES L.L.C is a limited liability company registered in the United Arab Emirates (). We develop and operate the Pulse business intelligence and operations platform.

2. Using the Website

2.1 Permitted Use

You may use the Website for lawful purposes consistent with these Terms. You must not:

  • Use the Website in violation of any applicable law or regulation

  • Transmit unsolicited commercial messages (spam)

  • Attempt to gain unauthorised access to any system, account, or data

  • Introduce malware, viruses, or any other malicious or harmful code

  • Scrape, crawl, or harvest content from the Website without our written consent

  • Impersonate any person or entity or misrepresent your affiliation with any person or entity

2.2 Platform Access

Certain sections of the Website may link to or require a Pulse platform account. Platform access is governed exclusively by the Pulse Clickwrap Agreement accepted at registration.

3. Intellectual Property

All content on the Website — including text, graphics, photographs, logos, design, icons, software code, and data compilations — is owned by or licensed to Buro 1 and is protected under UAE and international intellectual property law.

Nothing on this Website grants you any licence or right to use any Buro 1 intellectual property, trademark, or trade name without our prior written consent. Unauthorised use may give rise to a claim for damages and may constitute a criminal offence.

4. No Warranties

The Website and its content are provided "as is" and "as available" without any representation or warranty, express or implied, including without limitation warranties of merchantability, fitness for a particular purpose, title, or non-infringement.

We do not warrant that:

  • The Website will be uninterrupted, timely, secure, or error-free

  • Any content is accurate, complete, reliable, or current

  • The Website is free from viruses or other harmful components

Nothing on the Website constitutes legal, financial, tax, or professional advice. You should obtain appropriate professional advice before taking any action based on content on this Website.

5. Third-Party Links

The Website may contain links to third-party websites. These links are provided for convenience only. We do not endorse, control, or accept responsibility for the content, privacy practices, security, or availability of any third-party site. Access to any linked third-party site is entirely at your own risk.

6. Exclusion of Liability

The Website is provided free of charge for general information. To the fullest extent permitted by applicable law, Buro 1, its owners, officers, employees, and contractors accept no liability whatsoever to you or any third party arising out of or in connection with the Website or its content — including any direct, indirect, incidental, special, consequential, or punitive damages; loss of profits, revenue, data, goodwill, or business opportunity; or damage to equipment or loss of data — and you agree that you have no claim of any kind against them in connection with the Website.

This exclusion applies regardless of the form of action (contract, tort, strict liability, or otherwise) and even if Buro 1 has been advised of the possibility of such damages. If and only to the extent applicable law does not permit a liability to be excluded, that liability is limited to the minimum amount permitted by law

7. Privacy

Your use of the Website is also governed by our Privacy Policy, which describes how we collect, use, and protect your personal data. The Privacy Policy is incorporated into these Terms by reference.

8. Acceptable Use

You must not use the Website to:

  • Post, transmit, or distribute unlawful, defamatory, threatening, abusive, harassing, or obscene content

  • Facilitate, encourage, or assist any unlawful activity

  • Interfere with or disrupt the security, integrity, or availability of the Website or any connected network or system

  • Collect or harvest information about other users without their consent

We reserve the right to suspend or permanently block access for any user who violates these Terms, without notice or liability

9. Changes to the Website

We may modify, restrict, suspend, or discontinue any part of the Website at any time without notice or liability to you.

10. Changes to These Terms

We may update these Terms of Use at any time. Updated Terms take effect when posted on the Website. Your continued use of the Website after posting constitutes acceptance of the updated Terms. We recommend checking this page periodically.

11. Governing Law and Jurisdiction

These Terms of Use are governed by the federal laws of the United Arab Emirates as applicable in the Emirate of Dubai and the local laws of the Emirate of Dubai. Any dispute arising from or related to your use of the Website, or these Terms, shall be subject to the exclusive jurisdiction of the courts of Dubai, United Arab Emirates.

12. Contact

For enquiries about these Terms: BURO ONE MANAGEMENT CONSULTANCIES L.L.C Dubai, United Arab Emirates Email: info@buro-1.com

Acceptable Use Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This Acceptable Use Policy ("AUP") applies to anyone who accesses or uses the Buro 1 website, the Pulse platform, APIs, or any related service (together, the "Services"). If you are a registered Pulse customer, this AUP supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and any signed agreement between you and Buro 1; in the event of conflict, that agreement controls.

Buro 1 may update this AUP from time to time. Continued use of the Services after an update constitutes acceptance.

1. Prohibited Conduct

You must not, and must not permit or assist anyone else to:

1.1 Unlawful and Harmful Use

  • Use the Services in violation of any applicable law, regulation, or third-party right

  • Upload, transmit, store, or process unlawful, defamatory, threatening, abusive, harassing, deceptive, fraudulent, or obscene material

  • Use the Services to facilitate, encourage, or assist any unlawful activity

1.2 Security Abuse

  • Upload or transmit malware, ransomware, spyware, viruses, worms, Trojan horses, or any other harmful code

  • Attempt to gain unauthorised access to the Services, Buro 1 systems, another customer's account or data, or any third-party system or network

  • Conduct denial-of-service attacks, load attacks, stress tests, vulnerability scans, or penetration tests without Buro 1's prior written approval

  • Bypass, disable, or interfere with authentication controls, access controls, rate limits, usage limits, seat limits, billing controls, or any other security or technical mechanism

  • Distribute phishing or credential-harvesting content

1.3 Misuse of the Platform

  • Send spam, unlawful marketing, or communications that violate anti-spam or telecommunications rules

  • Scrape, crawl, harvest, or extract content or data by automated means without Buro 1's written consent

  • Reverse engineer, decompile, disassemble, copy, train on, or attempt to derive source code, non-public APIs, models, prompts, architecture, workflows, or trade secrets, except to the extent applicable law prohibits this restriction

  • Resell, sublicense, timeshare, or provide third-party access to the Services except as expressly permitted in a signed agreement

  • Impersonate any person or entity or misrepresent your affiliation

1.4 Data Restrictions

  • Submit regulated health information, payment card data, government identifiers, children's data, biometric data, financial account credentials, or other highly sensitive data, unless expressly permitted in a signed Order Form or Data Processing Addendum

  • Submit personal data without a lawful basis, required notices, and required consents

1.5 High-Risk Use

  • Use the Services in any environment where failure could cause death, personal injury, catastrophic property damage, environmental harm, or critical-infrastructure disruption, unless Buro 1 expressly agrees in writing

2. Enforcement

Buro 1 may investigate suspected violations of this AUP. Buro 1 may throttle, suspend, or terminate access — in whole or in part, with or without notice — where Buro 1 reasonably believes a violation has occurred or may occur, or where necessary to protect the security, integrity, or availability of the Services, other customers, or third parties.

Buro 1 is not liable for any action taken in good faith under this AUP, including suspension or termination of access.

3. Reporting Violations

To report suspected violations of this AUP, contact info@buro-1.com. To report suspected security vulnerabilities, see our Vulnerability Disclosure Policy.

4. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Security at Buro 1

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Security is foundational to how we build and operate the Pulse platform. This Security Statement describes the technical and organisational measures we apply to protect customer data.

This page is informational. It does not create warranties, representations, or contractual commitments. The Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum govern Buro 1's contractual security obligations; in the event of conflict, those agreements control.

1. Infrastructure and Hosting

  • The Pulse platform runs on enterprise-grade cloud infrastructure: Microsoft Azure (application hosting, database, backend, authentication, storage and monitoring — hosted in the UAE region).

  • Our infrastructure providers maintain independent security and compliance programmes, including certifications such as SOC 2 and ISO 27001 at the infrastructure layer.

  • Buro 1 does not operate its own physical data centers; physical security is managed by our infrastructure providers.

2. Data Encryption

  • In transit: all traffic between your browser and the platform is encrypted using TLS 1.2 or higher.

  • At rest: customer data is encrypted at rest at the infrastructure layer.

3. Tenant Isolation

  • Pulse is a multi-tenant platform with row-level security (RLS) enforced at the database layer.

  • Each customer entity's data is logically separated. Access policies are enforced on every query — not only at the application layer.

4. Access Control

  • Role-based access controls govern what each user can see and do within the platform.

  • Internal access to production systems and customer data is restricted to personnel who need it to perform their role, protected by strong authentication.

  • Access is revoked promptly when no longer required.

5. Application Security

  • Secure development practices, including code review before production deployment

  • Dependency and vulnerability monitoring

  • Rate limiting and abuse protection on authentication and API endpoints

  • Logging and monitoring of security-relevant events

6. Backups and Continuity

  • Automated backups are maintained at the infrastructure layer for disaster-recovery purposes.

  • See our Backup, Business Continuity and Disaster Recovery Statement for details.

7. Incident Response

  • Buro 1 maintains an incident response process covering detection, containment, investigation, remediation, and — where required by law or contract — notification.

  • See our Incident Response and Breach Notification Statement for details.

8. Personnel

  • Buro 1 personnel and contractors with access to customer data are bound by written confidentiality and IP obligations before receiving access.

9. Sub-Processors

  • We use a small, disclosed set of infrastructure providers, each bound by contractual data protection obligations. See our Sub-Processor List.

10. Shared Responsibility

Security is shared between Buro 1 and each customer. Customers are responsible for:

  • Safeguarding their accounts, passwords, API keys, and administrator credentials

  • Provisioning and de-provisioning their own users promptly, and reviewing user access

  • Securing their own devices, networks, browsers, and integrations

  • Exporting and independently backing up their data where they require independent retention

  • Ensuring the data they submit is lawful and appropriate for the platform

  • Promptly reporting suspected unauthorised access to Buro 1

11. No Absolute Security

No software, network, or security programme can be guaranteed to be error-free or immune from attack. Security controls reduce risk; they cannot eliminate it. Buro 1 does not warrant that the Services will be free from vulnerabilities, unauthorised access, or security incidents. Buro 1's contractual responsibilities in relation to security are as set out in the applicable agreement.

12. Reporting a Vulnerability

If you believe you have found a security vulnerability in a Buro 1 service, please report it confidentially — see our Vulnerability Disclosure Policy, or email info@buro-1.com. Do not publicly disclose or exploit suspected vulnerabilities.

13. Security Documentation

Enterprise customers may request additional security information (questionnaires, summaries) under confidentiality via info@buro-1.com. Buro 1 does not disclose sensitive internal security architecture, vulnerability details, or information that could increase security risk.

Security at Buro 1

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Security is foundational to how we build and operate the Pulse platform. This Security Statement describes the technical and organisational measures we apply to protect customer data.

This page is informational. It does not create warranties, representations, or contractual commitments. The Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum govern Buro 1's contractual security obligations; in the event of conflict, those agreements control.

1. Infrastructure and Hosting

  • The Pulse platform runs on enterprise-grade cloud infrastructure: Microsoft Azure (application hosting, database, backend, authentication, storage and monitoring — hosted in the UAE region).

  • Our infrastructure providers maintain independent security and compliance programmes, including certifications such as SOC 2 and ISO 27001 at the infrastructure layer.

  • Buro 1 does not operate its own physical data centers; physical security is managed by our infrastructure providers.

2. Data Encryption

  • In transit: all traffic between your browser and the platform is encrypted using TLS 1.2 or higher.

  • At rest: customer data is encrypted at rest at the infrastructure layer.

3. Tenant Isolation

  • Pulse is a multi-tenant platform with row-level security (RLS) enforced at the database layer.

  • Each customer entity's data is logically separated. Access policies are enforced on every query — not only at the application layer.

4. Access Control

  • Role-based access controls govern what each user can see and do within the platform.

  • Internal access to production systems and customer data is restricted to personnel who need it to perform their role, protected by strong authentication.

  • Access is revoked promptly when no longer required.

5. Application Security

  • Secure development practices, including code review before production deployment

  • Dependency and vulnerability monitoring

  • Rate limiting and abuse protection on authentication and API endpoints

  • Logging and monitoring of security-relevant events

6. Backups and Continuity

  • Automated backups are maintained at the infrastructure layer for disaster-recovery purposes.

  • See our Backup, Business Continuity and Disaster Recovery Statement for details.

7. Incident Response

  • Buro 1 maintains an incident response process covering detection, containment, investigation, remediation, and — where required by law or contract — notification.

  • See our Incident Response and Breach Notification Statement for details.

8. Personnel

  • Buro 1 personnel and contractors with access to customer data are bound by written confidentiality and IP obligations before receiving access.

9. Sub-Processors

  • We use a small, disclosed set of infrastructure providers, each bound by contractual data protection obligations. See our Sub-Processor List.

10. Shared Responsibility

Security is shared between Buro 1 and each customer. Customers are responsible for:

  • Safeguarding their accounts, passwords, API keys, and administrator credentials

  • Provisioning and de-provisioning their own users promptly, and reviewing user access

  • Securing their own devices, networks, browsers, and integrations

  • Exporting and independently backing up their data where they require independent retention

  • Ensuring the data they submit is lawful and appropriate for the platform

  • Promptly reporting suspected unauthorised access to Buro 1

11. No Absolute Security

No software, network, or security programme can be guaranteed to be error-free or immune from attack. Security controls reduce risk; they cannot eliminate it. Buro 1 does not warrant that the Services will be free from vulnerabilities, unauthorised access, or security incidents. Buro 1's contractual responsibilities in relation to security are as set out in the applicable agreement.

12. Reporting a Vulnerability

If you believe you have found a security vulnerability in a Buro 1 service, please report it confidentially — see our Vulnerability Disclosure Policy, or email info@buro-1.com. Do not publicly disclose or exploit suspected vulnerabilities.

13. Security Documentation

Enterprise customers may request additional security information (questionnaires, summaries) under confidentiality via info@buro-1.com. Buro 1 does not disclose sensitive internal security architecture, vulnerability details, or information that could increase security risk.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Sub-Processor List

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Buro 1 uses the third-party service providers ("sub-processors") listed below to deliver the Pulse platform and related services. Each sub-processor is bound by contractual data protection obligations consistent with our Privacy Policy, the applicable Data Processing Addendum ("DPA"), and applicable law.

This page is the authoritative, current list of Buro 1 sub-processors referenced in our Privacy Policy, the Pulse Clickwrap Agreement, and each signed DPA. In the event of conflict with a signed agreement, the signed agreement controls.

Current Sub-Processors

  • Microsoft Azure
    Service: Application hosting, database, backend infrastructure, authentication, storage, transactional email delivery, monitoring
    Data processed: Customer Data, account data, authentication data, notification content, technical data
    Location: United Arab Emirates

Infrastructure Location

Customer Data submitted to the Pulse platform is stored and processed on Microsoft Azure infrastructure hosted in the United Arab Emirates.

Changes to This List

Buro 1 may add, replace, or remove sub-processors from time to time.

  • Notification: we update this page when sub-processors change. Customers with a signed DPA that requires notice of new sub-processors will be notified in accordance with the DPA (by email to the account or nominated contact address). This page itself creates no notification obligations beyond those in a signed DPA.

  • Objection: if a signed DPA grants you an objection right, you may object on reasonable data protection grounds within the period stated in the DPA. If no resolution is reasonably available, your remedy is as stated in the DPA.

To subscribe to sub-processor change notifications, email info@buro-1.com with the subject "Sub-processor notifications".

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Support Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This Support Policy describes standard support for the Pulse platform. It supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and any signed Order Form; in the event of conflict, the signed agreement or Order Form controls. Enhanced support tiers, if purchased, are described in the applicable Order Form.

1. Support Channels

  • Email: info@buro-1.com

  • In-product: the support channel within the Pulse platform, where available

  • Any additional channel stated in your Order Form

2. Support Hours

Unless your Order Form states otherwise, support is provided during Buro 1's normal business hours, Monday to Friday, 9:00–18:00 Gulf Standard Time (UTC+4), excluding UAE public holidays and Buro 1 company holidays.

3. Severity Levels and Target Response Times

Buro 1 prioritises issues by severity. Target first-response times below are goals, not guarantees, unless a signed Service Level Agreement ("SLA") states otherwise. Failure to meet a target does not constitute a breach and creates no liability, credit, or refund.

  • S1 — Critical
    Definition: Platform unavailable for all users of an entity, or confirmed data-integrity issue, with no workaround
    Target first response: 4 business hours

  • S2 — High
    Definition: Major feature unavailable or materially degraded; workaround difficult
    Target first response: 8 business hours

  • S3 — Normal
    Definition: Feature impaired but usable; reasonable workaround exists
    Target first response: 2 business days

  • S4 — Low
    Definition: Questions, cosmetic issues, feature requests
    Target first response: 5 business days

Buro 1 assigns severity based on customer impact, security risk, number of affected users, reproducibility, and whether a workaround exists, and may reclassify issues as information develops.

4. What Support Includes

  • Troubleshooting platform errors and unexpected behaviour

  • Guidance on standard platform features and configuration

  • Investigation of suspected bugs and defects

  • Account and access assistance

5. What Support Does Not Include

Unless expressly included in an Order Form or a signed Statement of Work:

  • Custom development, customisation, or integration work

  • Training beyond standard onboarding materials

  • Data migration, data cleansing, or bulk data entry

  • Support for customer networks, devices, browsers, or third-party systems

  • Support for customer-built integrations or unsupported configurations

  • Issues caused by customer misuse, user error, or use outside the applicable agreement

Bespoke work is available as professional services under a signed Statement of Work at Buro 1's then-current rates.

6. Customer Cooperation

Effective support depends on you. Please provide accurate descriptions, screenshots, logs, reproduction steps, and timely responses. Buro 1 may close tickets where the requester is unresponsive for ten (10) business days.

7. No Guaranteed Resolution

Unless a signed SLA states otherwise, Buro 1 does not guarantee response times, resolution times, root-cause analysis delivery, or continuous support availability.

8. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Refund and Cancellation Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This policy explains how subscription cancellations and refunds work for the Pulse platform. It supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and your Order Form; in the event of conflict, the signed Order Form and the Clickwrap Agreement control.

1. Subscription Term and Auto-Renewal

  • Unless your Order Form states otherwise, subscriptions run on a 12-month rolling term and renew automatically for successive periods at the then-current price.

  • Buro 1 will send a renewal reminder to your account email at least fourteen (14) days before renewal where required by applicable law.

2. How to Cancel

  • To cancel, give written notice to info@buro-1.com, or follow the cancellation procedure in your Order Form. Order Forms typically require notice at least thirty (30) days before the renewal date; if your Order Form does not specify a notice period, cancellation is effective if notice is given before the renewal date.

  • Cancellation takes effect at the end of the current subscription period. Access continues until then.

  • Cancellation does not relieve you of amounts already owed.

3. Refunds

  • Fees are non-refundable except as expressly stated in your Order Form, this policy, or as required by applicable law.

  • No refunds or credits are provided for partial periods, unused users or capacity, downgrade differences, or periods where the platform was available but unused.

  • Downtime is remedied by extra service days (capped at 30 days per 12-month period; or SLA credits where a signed SLA applies), and qualifying security incidents by free months (capped at 2 per 12-month period), per the Clickwrap Agreement — these in-kind remedies are exclusive, are not cash, and are not refundable.

  • If Buro 1 terminates your subscription without cause, or an extended force majeure event triggers termination under the Clickwrap Agreement, Buro 1 will refund prepaid fees for the unused remainder of the affected period. No refund is due where Buro 1 terminates or suspends for cause (including non-payment, unlawful use, or breach).

4. Free Trials and Pilots

  • Trial, evaluation, and pilot access is free of charge and carries no refund obligation.

  • If you do not convert to a paid subscription, trial data may be deleted after the trial ends.

5. Professional Services

  • Fees for professional services (implementation, configuration, integration, training, consulting) are governed by the applicable signed Statement of Work or Change Order and are non-refundable once the work is performed.

6. Your Data After Cancellation

  • After termination or expiry, you have a 30-day window to export your data in a machine-readable format. After that window, your data may be permanently deleted. See the Backup, Business Continuity and Disaster Recovery Statement and your agreement for details.

7. Consumer Rights

If applicable law grants you non-waivable rights (including consumer refund rights), nothing in this policy limits those rights.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Vulnerability Disclosure Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Buro 1 welcomes reports from security researchers and customers who believe they have identified a vulnerability in a Buro 1 service. This policy explains how to report responsibly and what you can expect from us.

This policy is not an invitation to test our systems and does not create a bug-bounty programme, a contract, or any entitlement to reward. Active security testing (scanning, penetration testing, load testing) of Buro 1 services requires Buro 1's prior written approval — see the Acceptable Use Policy and the Pulse Clickwrap Agreement.

1. How to Report

Email info@buro-1.com with the subject line "Security vulnerability report", including:

  • A description of the suspected vulnerability and its potential impact

  • Steps to reproduce (URLs, request/response samples, screenshots)

  • The date and time you observed the issue

  • Your contact details for follow-up

Please report in confidence and give us a reasonable opportunity to investigate and remediate before any disclosure to third parties.

2. Rules of Engagement

When investigating or reporting a suspected vulnerability, you must not:

  • Access, copy, modify, or delete data belonging to Buro 1 or any other customer — if you inadvertently access another party's data, stop immediately and report it

  • Degrade, disrupt, or deny service to any Buro 1 system or user

  • Use social engineering, phishing, or physical intrusion

  • Run automated scanners, brute-force tools, or denial-of-service tests

  • Publicly disclose, sell, or share the vulnerability or any related data with third parties

  • Demand payment or other consideration as a condition of disclosure

3. What You Can Expect

  • We aim to acknowledge reports promptly.

  • We investigate reports, prioritise based on severity, and work to remediate confirmed vulnerabilities.

  • We aim to keep reporters informed of progress where reasonably practicable.

This section describes our practice; it does not create contractual obligations, deadlines, or liability.

4. Good-Faith Safe Harbour

If you comply with this policy in full and act in good faith, Buro 1 does not intend to initiate legal action against you for your good-faith, proportionate research activities that led to the report. This safe harbour does not apply to any activity listed in Section 2, does not bind third parties or authorities, and does not authorise violations of applicable law.

5. Scope

In scope: the Buro 1 website, the Pulse platform, and Buro 1-operated APIs. Out of scope: third-party services and infrastructure operated by our providers (Microsoft Azure) — please report issues in those platforms to the relevant provider under their own disclosure programmes.

6. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Backup, Business Continuity and Disaster Recovery Statement

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This statement describes how Buro 1 approaches backups, business continuity, and disaster recovery for the Pulse platform.

This page is informational. It does not create warranties, service level commitments, or contractual obligations. Buro 1's contractual commitments regarding backups, data retention, and availability are set out exclusively in the Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, Order Form, Data Processing Addendum, or Service Level Agreement; in the event of conflict, those documents control.

1. Operational Backups

  • Automated backups of platform databases are maintained at the infrastructure layer (Microsoft Azure, UAE region) on a regular schedule for disaster-recovery purposes.

  • Backups are encrypted and access-restricted.

  • Operational backups exist to restore the platform, not to serve as an archival service for individual customer records. Restoration of specific customer records is not guaranteed unless expressly provided in a signed Order Form or SLA.

2. Customer Backup Responsibility

  • Customers are responsible for exporting and independently backing up their data where they require independent retention, using the export tools provided in the platform.

  • Buro 1 is not responsible for loss of data caused by a customer's failure to maintain independent backups, customer deletion or modification of data, credential compromise, or configuration choices.

3. Business Continuity

  • The Pulse platform is built on managed cloud infrastructure (Microsoft Azure) with provider-level redundancy, failover, and monitoring.

  • Buro 1 has no single physical point of failure under its own control: the platform is fully cloud-hosted and can be operated and administered remotely.

  • Key operational knowledge, configuration, and code are maintained in version-controlled repositories with restricted access.

4. Disaster Recovery

  • In the event of infrastructure loss, the platform is designed to be restored from infrastructure-layer backups.

  • Recovery targets (informational, not contractual): recovery point objective (RPO) of up to 24 hours; recovery time objective (RTO) of up to 72 hours for full platform restoration, depending on the nature of the event and our infrastructure providers.

  • Events affecting our infrastructure providers themselves (regional cloud outages, provider failures) may extend recovery times and are outside Buro 1's reasonable control.

5. Data Retention and Deletion

Summary of standard retention (the applicable agreement controls):

  • Active subscription
    Standard treatment: Data retained for the duration of the subscription

  • Termination or expiry
    Standard treatment: 30-day export window, after which data may be permanently deleted

  • Backup purge
    Standard treatment: Deleted data may persist in encrypted backups for up to 90 days, or longer where legally required

  • Legal records
    Standard treatment: Contracts and invoices retained 5 years or as required by UAE law

6. Continuous Improvement

Buro 1 reviews its backup and recovery arrangements periodically and as the platform and its infrastructure evolve. This statement will be updated to reflect material changes.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Incident Response and Breach Notification Statement

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This statement describes how Buro 1 responds to security incidents affecting the Pulse platform and how customers are notified.

This page is informational. Buro 1's contractual obligations regarding security incidents and breach notification are set out exclusively in the Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum ("DPA"); in the event of conflict, those documents control.

1. Definitions

  • A Security Incident is a confirmed breach of Buro 1's security controls that results in unauthorised access to or disclosure of Customer Data processed by Buro 1.

  • Unsuccessful attempts (blocked attacks, port scans, failed logins, denial-of-service attempts that do not compromise data) are not Security Incidents and do not trigger notification.

2. Our Incident Response Process

  • Detect
    What we do: Monitoring, logging, alerts, and reports from users, researchers, and providers

  • Contain
    What we do: Isolate affected systems, revoke compromised credentials, block attack vectors

  • Assess
    What we do: Determine scope, affected data, affected customers, and root cause

  • Remediate
    What we do: Fix the vulnerability, restore normal operation, harden controls

  • Notify
    What we do: Notify affected customers and authorities where required (Section 3)

  • Review
    What we do: Post-incident review and corrective actions

3. Customer Notification

  • Where a Security Incident affects your Customer Data and notification is required by applicable law or your DPA, Buro 1 will notify you without undue delay after confirming the incident.

  • Notification will be sent to your account email address or the contact nominated in your agreement, and will include — to the extent known at the time — the nature of the incident, categories of data affected, measures taken, and recommended customer actions. Information may be provided in phases as the investigation develops.

  • Notification may be delayed where required by law enforcement, legal obligations, or where immediate disclosure would compromise containment or investigation.

  • Notification of, or response to, a Security Incident is not an acknowledgement of fault or liability. Buro 1's notification obligations are only those imposed by applicable law or a signed DPA; this page creates no additional obligations.

4. Regulatory Notification

Where required, Buro 1 notifies competent authorities in accordance with applicable law, including UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL).

5. Customer Responsibilities

  • Promptly report suspected unauthorised access, credential compromise, or unusual activity to info@buro-1.com.

  • Cooperate with reasonable investigation, containment, and remediation efforts — including preserving logs, rotating credentials, and disabling affected integrations.

  • Where the incident originates from your own users, credentials, devices, networks, configurations, or integrations, you are responsible for your own incident handling and any notifications you are required to make.

6. Reporting a Suspected Incident or Vulnerability

  • Suspected incidents affecting your account: info@buro-1.com (subject: "Security incident")

  • Suspected vulnerabilities: see our Vulnerability Disclosure Policy

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

BURO ONE MANAGEMENT CONSULTANCIES L.L.C · Dubai, United Arab Emirates · info@buro-1.com · All legal documents

Circle icon

We transform organizations.

Your success is next.

Start your project now by booking a one-on-one consultation with our expert.

Team working in an office watching at a presentation
Last update
July 15, 2026

Terms of Use

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")
Chevron Right
The agreements and policies that govern the Buro 1 website and the Pulse platform. If you have a signed agreement with Buro 1 (Order Form, DPA, SOW, SLA), it controls over these pages. For registered platform users, the Pulse Clickwrap Agreement controls over the informational sections below. Each section below carries its own effective date and version. The End User License Agreement and the Privacy Policy are published as separate documents.

A Data Processing Addendum (DPA) is available for signature on request. A Service Level Agreement (SLA) is available to Enterprise customers by signed agreement. Contact info@buro-1.com.

These Terms of Use govern your access to and use of the Buro 1 website ("Website"). Use of the Pulse platform is governed by a separate agreement — the Pulse Clickwrap Agreement (End-User Licence Agreement) — which applies when you register as a platform user. By accessing the Website, you agree to these Terms of Use. If you do not agree, do not use the Website.

1. Who We Are

BURO ONE MANAGEMENT CONSULTANCIES L.L.C is a limited liability company registered in the United Arab Emirates (). We develop and operate the Pulse business intelligence and operations platform.

2. Using the Website

2.1 Permitted Use

You may use the Website for lawful purposes consistent with these Terms. You must not:

  • Use the Website in violation of any applicable law or regulation

  • Transmit unsolicited commercial messages (spam)

  • Attempt to gain unauthorised access to any system, account, or data

  • Introduce malware, viruses, or any other malicious or harmful code

  • Scrape, crawl, or harvest content from the Website without our written consent

  • Impersonate any person or entity or misrepresent your affiliation with any person or entity

2.2 Platform Access

Certain sections of the Website may link to or require a Pulse platform account. Platform access is governed exclusively by the Pulse Clickwrap Agreement accepted at registration.

3. Intellectual Property

All content on the Website — including text, graphics, photographs, logos, design, icons, software code, and data compilations — is owned by or licensed to Buro 1 and is protected under UAE and international intellectual property law.

Nothing on this Website grants you any licence or right to use any Buro 1 intellectual property, trademark, or trade name without our prior written consent. Unauthorised use may give rise to a claim for damages and may constitute a criminal offence.

4. No Warranties

The Website and its content are provided "as is" and "as available" without any representation or warranty, express or implied, including without limitation warranties of merchantability, fitness for a particular purpose, title, or non-infringement.

We do not warrant that:

  • The Website will be uninterrupted, timely, secure, or error-free

  • Any content is accurate, complete, reliable, or current

  • The Website is free from viruses or other harmful components

Nothing on the Website constitutes legal, financial, tax, or professional advice. You should obtain appropriate professional advice before taking any action based on content on this Website.

5. Third-Party Links

The Website may contain links to third-party websites. These links are provided for convenience only. We do not endorse, control, or accept responsibility for the content, privacy practices, security, or availability of any third-party site. Access to any linked third-party site is entirely at your own risk.

6. Exclusion of Liability

The Website is provided free of charge for general information. To the fullest extent permitted by applicable law, Buro 1, its owners, officers, employees, and contractors accept no liability whatsoever to you or any third party arising out of or in connection with the Website or its content — including any direct, indirect, incidental, special, consequential, or punitive damages; loss of profits, revenue, data, goodwill, or business opportunity; or damage to equipment or loss of data — and you agree that you have no claim of any kind against them in connection with the Website.

This exclusion applies regardless of the form of action (contract, tort, strict liability, or otherwise) and even if Buro 1 has been advised of the possibility of such damages. If and only to the extent applicable law does not permit a liability to be excluded, that liability is limited to the minimum amount permitted by law

7. Privacy

Your use of the Website is also governed by our Privacy Policy, which describes how we collect, use, and protect your personal data. The Privacy Policy is incorporated into these Terms by reference.

8. Acceptable Use

You must not use the Website to:

  • Post, transmit, or distribute unlawful, defamatory, threatening, abusive, harassing, or obscene content

  • Facilitate, encourage, or assist any unlawful activity

  • Interfere with or disrupt the security, integrity, or availability of the Website or any connected network or system

  • Collect or harvest information about other users without their consent

We reserve the right to suspend or permanently block access for any user who violates these Terms, without notice or liability

9. Changes to the Website

We may modify, restrict, suspend, or discontinue any part of the Website at any time without notice or liability to you.

10. Changes to These Terms

We may update these Terms of Use at any time. Updated Terms take effect when posted on the Website. Your continued use of the Website after posting constitutes acceptance of the updated Terms. We recommend checking this page periodically.

11. Governing Law and Jurisdiction

These Terms of Use are governed by the federal laws of the United Arab Emirates as applicable in the Emirate of Dubai and the local laws of the Emirate of Dubai. Any dispute arising from or related to your use of the Website, or these Terms, shall be subject to the exclusive jurisdiction of the courts of Dubai, United Arab Emirates.

12. Contact

For enquiries about these Terms: BURO ONE MANAGEMENT CONSULTANCIES L.L.C Dubai, United Arab Emirates Email: info@buro-1.com

Acceptable Use Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This Acceptable Use Policy ("AUP") applies to anyone who accesses or uses the Buro 1 website, the Pulse platform, APIs, or any related service (together, the "Services"). If you are a registered Pulse customer, this AUP supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and any signed agreement between you and Buro 1; in the event of conflict, that agreement controls.

Buro 1 may update this AUP from time to time. Continued use of the Services after an update constitutes acceptance.

1. Prohibited Conduct

You must not, and must not permit or assist anyone else to:

1.1 Unlawful and Harmful Use

  • Use the Services in violation of any applicable law, regulation, or third-party right

  • Upload, transmit, store, or process unlawful, defamatory, threatening, abusive, harassing, deceptive, fraudulent, or obscene material

  • Use the Services to facilitate, encourage, or assist any unlawful activity

1.2 Security Abuse

  • Upload or transmit malware, ransomware, spyware, viruses, worms, Trojan horses, or any other harmful code

  • Attempt to gain unauthorised access to the Services, Buro 1 systems, another customer's account or data, or any third-party system or network

  • Conduct denial-of-service attacks, load attacks, stress tests, vulnerability scans, or penetration tests without Buro 1's prior written approval

  • Bypass, disable, or interfere with authentication controls, access controls, rate limits, usage limits, seat limits, billing controls, or any other security or technical mechanism

  • Distribute phishing or credential-harvesting content

1.3 Misuse of the Platform

  • Send spam, unlawful marketing, or communications that violate anti-spam or telecommunications rules

  • Scrape, crawl, harvest, or extract content or data by automated means without Buro 1's written consent

  • Reverse engineer, decompile, disassemble, copy, train on, or attempt to derive source code, non-public APIs, models, prompts, architecture, workflows, or trade secrets, except to the extent applicable law prohibits this restriction

  • Resell, sublicense, timeshare, or provide third-party access to the Services except as expressly permitted in a signed agreement

  • Impersonate any person or entity or misrepresent your affiliation

1.4 Data Restrictions

  • Submit regulated health information, payment card data, government identifiers, children's data, biometric data, financial account credentials, or other highly sensitive data, unless expressly permitted in a signed Order Form or Data Processing Addendum

  • Submit personal data without a lawful basis, required notices, and required consents

1.5 High-Risk Use

  • Use the Services in any environment where failure could cause death, personal injury, catastrophic property damage, environmental harm, or critical-infrastructure disruption, unless Buro 1 expressly agrees in writing

2. Enforcement

Buro 1 may investigate suspected violations of this AUP. Buro 1 may throttle, suspend, or terminate access — in whole or in part, with or without notice — where Buro 1 reasonably believes a violation has occurred or may occur, or where necessary to protect the security, integrity, or availability of the Services, other customers, or third parties.

Buro 1 is not liable for any action taken in good faith under this AUP, including suspension or termination of access.

3. Reporting Violations

To report suspected violations of this AUP, contact info@buro-1.com. To report suspected security vulnerabilities, see our Vulnerability Disclosure Policy.

4. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Security at Buro 1

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Security is foundational to how we build and operate the Pulse platform. This Security Statement describes the technical and organisational measures we apply to protect customer data.

This page is informational. It does not create warranties, representations, or contractual commitments. The Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum govern Buro 1's contractual security obligations; in the event of conflict, those agreements control.

1. Infrastructure and Hosting

  • The Pulse platform runs on enterprise-grade cloud infrastructure: Microsoft Azure (application hosting, database, backend, authentication, storage and monitoring — hosted in the UAE region).

  • Our infrastructure providers maintain independent security and compliance programmes, including certifications such as SOC 2 and ISO 27001 at the infrastructure layer.

  • Buro 1 does not operate its own physical data centers; physical security is managed by our infrastructure providers.

2. Data Encryption

  • In transit: all traffic between your browser and the platform is encrypted using TLS 1.2 or higher.

  • At rest: customer data is encrypted at rest at the infrastructure layer.

3. Tenant Isolation

  • Pulse is a multi-tenant platform with row-level security (RLS) enforced at the database layer.

  • Each customer entity's data is logically separated. Access policies are enforced on every query — not only at the application layer.

4. Access Control

  • Role-based access controls govern what each user can see and do within the platform.

  • Internal access to production systems and customer data is restricted to personnel who need it to perform their role, protected by strong authentication.

  • Access is revoked promptly when no longer required.

5. Application Security

  • Secure development practices, including code review before production deployment

  • Dependency and vulnerability monitoring

  • Rate limiting and abuse protection on authentication and API endpoints

  • Logging and monitoring of security-relevant events

6. Backups and Continuity

  • Automated backups are maintained at the infrastructure layer for disaster-recovery purposes.

  • See our Backup, Business Continuity and Disaster Recovery Statement for details.

7. Incident Response

  • Buro 1 maintains an incident response process covering detection, containment, investigation, remediation, and — where required by law or contract — notification.

  • See our Incident Response and Breach Notification Statement for details.

8. Personnel

  • Buro 1 personnel and contractors with access to customer data are bound by written confidentiality and IP obligations before receiving access.

9. Sub-Processors

  • We use a small, disclosed set of infrastructure providers, each bound by contractual data protection obligations. See our Sub-Processor List.

10. Shared Responsibility

Security is shared between Buro 1 and each customer. Customers are responsible for:

  • Safeguarding their accounts, passwords, API keys, and administrator credentials

  • Provisioning and de-provisioning their own users promptly, and reviewing user access

  • Securing their own devices, networks, browsers, and integrations

  • Exporting and independently backing up their data where they require independent retention

  • Ensuring the data they submit is lawful and appropriate for the platform

  • Promptly reporting suspected unauthorised access to Buro 1

11. No Absolute Security

No software, network, or security programme can be guaranteed to be error-free or immune from attack. Security controls reduce risk; they cannot eliminate it. Buro 1 does not warrant that the Services will be free from vulnerabilities, unauthorised access, or security incidents. Buro 1's contractual responsibilities in relation to security are as set out in the applicable agreement.

12. Reporting a Vulnerability

If you believe you have found a security vulnerability in a Buro 1 service, please report it confidentially — see our Vulnerability Disclosure Policy, or email info@buro-1.com. Do not publicly disclose or exploit suspected vulnerabilities.

13. Security Documentation

Enterprise customers may request additional security information (questionnaires, summaries) under confidentiality via info@buro-1.com. Buro 1 does not disclose sensitive internal security architecture, vulnerability details, or information that could increase security risk.

Security at Buro 1

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Security is foundational to how we build and operate the Pulse platform. This Security Statement describes the technical and organisational measures we apply to protect customer data.

This page is informational. It does not create warranties, representations, or contractual commitments. The Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum govern Buro 1's contractual security obligations; in the event of conflict, those agreements control.

1. Infrastructure and Hosting

  • The Pulse platform runs on enterprise-grade cloud infrastructure: Microsoft Azure (application hosting, database, backend, authentication, storage and monitoring — hosted in the UAE region).

  • Our infrastructure providers maintain independent security and compliance programmes, including certifications such as SOC 2 and ISO 27001 at the infrastructure layer.

  • Buro 1 does not operate its own physical data centers; physical security is managed by our infrastructure providers.

2. Data Encryption

  • In transit: all traffic between your browser and the platform is encrypted using TLS 1.2 or higher.

  • At rest: customer data is encrypted at rest at the infrastructure layer.

3. Tenant Isolation

  • Pulse is a multi-tenant platform with row-level security (RLS) enforced at the database layer.

  • Each customer entity's data is logically separated. Access policies are enforced on every query — not only at the application layer.

4. Access Control

  • Role-based access controls govern what each user can see and do within the platform.

  • Internal access to production systems and customer data is restricted to personnel who need it to perform their role, protected by strong authentication.

  • Access is revoked promptly when no longer required.

5. Application Security

  • Secure development practices, including code review before production deployment

  • Dependency and vulnerability monitoring

  • Rate limiting and abuse protection on authentication and API endpoints

  • Logging and monitoring of security-relevant events

6. Backups and Continuity

  • Automated backups are maintained at the infrastructure layer for disaster-recovery purposes.

  • See our Backup, Business Continuity and Disaster Recovery Statement for details.

7. Incident Response

  • Buro 1 maintains an incident response process covering detection, containment, investigation, remediation, and — where required by law or contract — notification.

  • See our Incident Response and Breach Notification Statement for details.

8. Personnel

  • Buro 1 personnel and contractors with access to customer data are bound by written confidentiality and IP obligations before receiving access.

9. Sub-Processors

  • We use a small, disclosed set of infrastructure providers, each bound by contractual data protection obligations. See our Sub-Processor List.

10. Shared Responsibility

Security is shared between Buro 1 and each customer. Customers are responsible for:

  • Safeguarding their accounts, passwords, API keys, and administrator credentials

  • Provisioning and de-provisioning their own users promptly, and reviewing user access

  • Securing their own devices, networks, browsers, and integrations

  • Exporting and independently backing up their data where they require independent retention

  • Ensuring the data they submit is lawful and appropriate for the platform

  • Promptly reporting suspected unauthorised access to Buro 1

11. No Absolute Security

No software, network, or security programme can be guaranteed to be error-free or immune from attack. Security controls reduce risk; they cannot eliminate it. Buro 1 does not warrant that the Services will be free from vulnerabilities, unauthorised access, or security incidents. Buro 1's contractual responsibilities in relation to security are as set out in the applicable agreement.

12. Reporting a Vulnerability

If you believe you have found a security vulnerability in a Buro 1 service, please report it confidentially — see our Vulnerability Disclosure Policy, or email info@buro-1.com. Do not publicly disclose or exploit suspected vulnerabilities.

13. Security Documentation

Enterprise customers may request additional security information (questionnaires, summaries) under confidentiality via info@buro-1.com. Buro 1 does not disclose sensitive internal security architecture, vulnerability details, or information that could increase security risk.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Sub-Processor List

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Buro 1 uses the third-party service providers ("sub-processors") listed below to deliver the Pulse platform and related services. Each sub-processor is bound by contractual data protection obligations consistent with our Privacy Policy, the applicable Data Processing Addendum ("DPA"), and applicable law.

This page is the authoritative, current list of Buro 1 sub-processors referenced in our Privacy Policy, the Pulse Clickwrap Agreement, and each signed DPA. In the event of conflict with a signed agreement, the signed agreement controls.

Current Sub-Processors

  • Microsoft Azure
    Service: Application hosting, database, backend infrastructure, authentication, storage, transactional email delivery, monitoring
    Data processed: Customer Data, account data, authentication data, notification content, technical data
    Location: United Arab Emirates

Infrastructure Location

Customer Data submitted to the Pulse platform is stored and processed on Microsoft Azure infrastructure hosted in the United Arab Emirates.

Changes to This List

Buro 1 may add, replace, or remove sub-processors from time to time.

  • Notification: we update this page when sub-processors change. Customers with a signed DPA that requires notice of new sub-processors will be notified in accordance with the DPA (by email to the account or nominated contact address). This page itself creates no notification obligations beyond those in a signed DPA.

  • Objection: if a signed DPA grants you an objection right, you may object on reasonable data protection grounds within the period stated in the DPA. If no resolution is reasonably available, your remedy is as stated in the DPA.

To subscribe to sub-processor change notifications, email info@buro-1.com with the subject "Sub-processor notifications".

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Support Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This Support Policy describes standard support for the Pulse platform. It supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and any signed Order Form; in the event of conflict, the signed agreement or Order Form controls. Enhanced support tiers, if purchased, are described in the applicable Order Form.

1. Support Channels

  • Email: info@buro-1.com

  • In-product: the support channel within the Pulse platform, where available

  • Any additional channel stated in your Order Form

2. Support Hours

Unless your Order Form states otherwise, support is provided during Buro 1's normal business hours, Monday to Friday, 9:00–18:00 Gulf Standard Time (UTC+4), excluding UAE public holidays and Buro 1 company holidays.

3. Severity Levels and Target Response Times

Buro 1 prioritises issues by severity. Target first-response times below are goals, not guarantees, unless a signed Service Level Agreement ("SLA") states otherwise. Failure to meet a target does not constitute a breach and creates no liability, credit, or refund.

  • S1 — Critical
    Definition: Platform unavailable for all users of an entity, or confirmed data-integrity issue, with no workaround
    Target first response: 4 business hours

  • S2 — High
    Definition: Major feature unavailable or materially degraded; workaround difficult
    Target first response: 8 business hours

  • S3 — Normal
    Definition: Feature impaired but usable; reasonable workaround exists
    Target first response: 2 business days

  • S4 — Low
    Definition: Questions, cosmetic issues, feature requests
    Target first response: 5 business days

Buro 1 assigns severity based on customer impact, security risk, number of affected users, reproducibility, and whether a workaround exists, and may reclassify issues as information develops.

4. What Support Includes

  • Troubleshooting platform errors and unexpected behaviour

  • Guidance on standard platform features and configuration

  • Investigation of suspected bugs and defects

  • Account and access assistance

5. What Support Does Not Include

Unless expressly included in an Order Form or a signed Statement of Work:

  • Custom development, customisation, or integration work

  • Training beyond standard onboarding materials

  • Data migration, data cleansing, or bulk data entry

  • Support for customer networks, devices, browsers, or third-party systems

  • Support for customer-built integrations or unsupported configurations

  • Issues caused by customer misuse, user error, or use outside the applicable agreement

Bespoke work is available as professional services under a signed Statement of Work at Buro 1's then-current rates.

6. Customer Cooperation

Effective support depends on you. Please provide accurate descriptions, screenshots, logs, reproduction steps, and timely responses. Buro 1 may close tickets where the requester is unresponsive for ten (10) business days.

7. No Guaranteed Resolution

Unless a signed SLA states otherwise, Buro 1 does not guarantee response times, resolution times, root-cause analysis delivery, or continuous support availability.

8. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Refund and Cancellation Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This policy explains how subscription cancellations and refunds work for the Pulse platform. It supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and your Order Form; in the event of conflict, the signed Order Form and the Clickwrap Agreement control.

1. Subscription Term and Auto-Renewal

  • Unless your Order Form states otherwise, subscriptions run on a 12-month rolling term and renew automatically for successive periods at the then-current price.

  • Buro 1 will send a renewal reminder to your account email at least fourteen (14) days before renewal where required by applicable law.

2. How to Cancel

  • To cancel, give written notice to info@buro-1.com, or follow the cancellation procedure in your Order Form. Order Forms typically require notice at least thirty (30) days before the renewal date; if your Order Form does not specify a notice period, cancellation is effective if notice is given before the renewal date.

  • Cancellation takes effect at the end of the current subscription period. Access continues until then.

  • Cancellation does not relieve you of amounts already owed.

3. Refunds

  • Fees are non-refundable except as expressly stated in your Order Form, this policy, or as required by applicable law.

  • No refunds or credits are provided for partial periods, unused users or capacity, downgrade differences, or periods where the platform was available but unused.

  • Downtime is remedied by extra service days (capped at 30 days per 12-month period; or SLA credits where a signed SLA applies), and qualifying security incidents by free months (capped at 2 per 12-month period), per the Clickwrap Agreement — these in-kind remedies are exclusive, are not cash, and are not refundable.

  • If Buro 1 terminates your subscription without cause, or an extended force majeure event triggers termination under the Clickwrap Agreement, Buro 1 will refund prepaid fees for the unused remainder of the affected period. No refund is due where Buro 1 terminates or suspends for cause (including non-payment, unlawful use, or breach).

4. Free Trials and Pilots

  • Trial, evaluation, and pilot access is free of charge and carries no refund obligation.

  • If you do not convert to a paid subscription, trial data may be deleted after the trial ends.

5. Professional Services

  • Fees for professional services (implementation, configuration, integration, training, consulting) are governed by the applicable signed Statement of Work or Change Order and are non-refundable once the work is performed.

6. Your Data After Cancellation

  • After termination or expiry, you have a 30-day window to export your data in a machine-readable format. After that window, your data may be permanently deleted. See the Backup, Business Continuity and Disaster Recovery Statement and your agreement for details.

7. Consumer Rights

If applicable law grants you non-waivable rights (including consumer refund rights), nothing in this policy limits those rights.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Vulnerability Disclosure Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Buro 1 welcomes reports from security researchers and customers who believe they have identified a vulnerability in a Buro 1 service. This policy explains how to report responsibly and what you can expect from us.

This policy is not an invitation to test our systems and does not create a bug-bounty programme, a contract, or any entitlement to reward. Active security testing (scanning, penetration testing, load testing) of Buro 1 services requires Buro 1's prior written approval — see the Acceptable Use Policy and the Pulse Clickwrap Agreement.

1. How to Report

Email info@buro-1.com with the subject line "Security vulnerability report", including:

  • A description of the suspected vulnerability and its potential impact

  • Steps to reproduce (URLs, request/response samples, screenshots)

  • The date and time you observed the issue

  • Your contact details for follow-up

Please report in confidence and give us a reasonable opportunity to investigate and remediate before any disclosure to third parties.

2. Rules of Engagement

When investigating or reporting a suspected vulnerability, you must not:

  • Access, copy, modify, or delete data belonging to Buro 1 or any other customer — if you inadvertently access another party's data, stop immediately and report it

  • Degrade, disrupt, or deny service to any Buro 1 system or user

  • Use social engineering, phishing, or physical intrusion

  • Run automated scanners, brute-force tools, or denial-of-service tests

  • Publicly disclose, sell, or share the vulnerability or any related data with third parties

  • Demand payment or other consideration as a condition of disclosure

3. What You Can Expect

  • We aim to acknowledge reports promptly.

  • We investigate reports, prioritise based on severity, and work to remediate confirmed vulnerabilities.

  • We aim to keep reporters informed of progress where reasonably practicable.

This section describes our practice; it does not create contractual obligations, deadlines, or liability.

4. Good-Faith Safe Harbour

If you comply with this policy in full and act in good faith, Buro 1 does not intend to initiate legal action against you for your good-faith, proportionate research activities that led to the report. This safe harbour does not apply to any activity listed in Section 2, does not bind third parties or authorities, and does not authorise violations of applicable law.

5. Scope

In scope: the Buro 1 website, the Pulse platform, and Buro 1-operated APIs. Out of scope: third-party services and infrastructure operated by our providers (Microsoft Azure) — please report issues in those platforms to the relevant provider under their own disclosure programmes.

6. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Backup, Business Continuity and Disaster Recovery Statement

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This statement describes how Buro 1 approaches backups, business continuity, and disaster recovery for the Pulse platform.

This page is informational. It does not create warranties, service level commitments, or contractual obligations. Buro 1's contractual commitments regarding backups, data retention, and availability are set out exclusively in the Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, Order Form, Data Processing Addendum, or Service Level Agreement; in the event of conflict, those documents control.

1. Operational Backups

  • Automated backups of platform databases are maintained at the infrastructure layer (Microsoft Azure, UAE region) on a regular schedule for disaster-recovery purposes.

  • Backups are encrypted and access-restricted.

  • Operational backups exist to restore the platform, not to serve as an archival service for individual customer records. Restoration of specific customer records is not guaranteed unless expressly provided in a signed Order Form or SLA.

2. Customer Backup Responsibility

  • Customers are responsible for exporting and independently backing up their data where they require independent retention, using the export tools provided in the platform.

  • Buro 1 is not responsible for loss of data caused by a customer's failure to maintain independent backups, customer deletion or modification of data, credential compromise, or configuration choices.

3. Business Continuity

  • The Pulse platform is built on managed cloud infrastructure (Microsoft Azure) with provider-level redundancy, failover, and monitoring.

  • Buro 1 has no single physical point of failure under its own control: the platform is fully cloud-hosted and can be operated and administered remotely.

  • Key operational knowledge, configuration, and code are maintained in version-controlled repositories with restricted access.

4. Disaster Recovery

  • In the event of infrastructure loss, the platform is designed to be restored from infrastructure-layer backups.

  • Recovery targets (informational, not contractual): recovery point objective (RPO) of up to 24 hours; recovery time objective (RTO) of up to 72 hours for full platform restoration, depending on the nature of the event and our infrastructure providers.

  • Events affecting our infrastructure providers themselves (regional cloud outages, provider failures) may extend recovery times and are outside Buro 1's reasonable control.

5. Data Retention and Deletion

Summary of standard retention (the applicable agreement controls):

  • Active subscription
    Standard treatment: Data retained for the duration of the subscription

  • Termination or expiry
    Standard treatment: 30-day export window, after which data may be permanently deleted

  • Backup purge
    Standard treatment: Deleted data may persist in encrypted backups for up to 90 days, or longer where legally required

  • Legal records
    Standard treatment: Contracts and invoices retained 5 years or as required by UAE law

6. Continuous Improvement

Buro 1 reviews its backup and recovery arrangements periodically and as the platform and its infrastructure evolve. This statement will be updated to reflect material changes.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Incident Response and Breach Notification Statement

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This statement describes how Buro 1 responds to security incidents affecting the Pulse platform and how customers are notified.

This page is informational. Buro 1's contractual obligations regarding security incidents and breach notification are set out exclusively in the Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum ("DPA"); in the event of conflict, those documents control.

1. Definitions

  • A Security Incident is a confirmed breach of Buro 1's security controls that results in unauthorised access to or disclosure of Customer Data processed by Buro 1.

  • Unsuccessful attempts (blocked attacks, port scans, failed logins, denial-of-service attempts that do not compromise data) are not Security Incidents and do not trigger notification.

2. Our Incident Response Process

  • Detect
    What we do: Monitoring, logging, alerts, and reports from users, researchers, and providers

  • Contain
    What we do: Isolate affected systems, revoke compromised credentials, block attack vectors

  • Assess
    What we do: Determine scope, affected data, affected customers, and root cause

  • Remediate
    What we do: Fix the vulnerability, restore normal operation, harden controls

  • Notify
    What we do: Notify affected customers and authorities where required (Section 3)

  • Review
    What we do: Post-incident review and corrective actions

3. Customer Notification

  • Where a Security Incident affects your Customer Data and notification is required by applicable law or your DPA, Buro 1 will notify you without undue delay after confirming the incident.

  • Notification will be sent to your account email address or the contact nominated in your agreement, and will include — to the extent known at the time — the nature of the incident, categories of data affected, measures taken, and recommended customer actions. Information may be provided in phases as the investigation develops.

  • Notification may be delayed where required by law enforcement, legal obligations, or where immediate disclosure would compromise containment or investigation.

  • Notification of, or response to, a Security Incident is not an acknowledgement of fault or liability. Buro 1's notification obligations are only those imposed by applicable law or a signed DPA; this page creates no additional obligations.

4. Regulatory Notification

Where required, Buro 1 notifies competent authorities in accordance with applicable law, including UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL).

5. Customer Responsibilities

  • Promptly report suspected unauthorised access, credential compromise, or unusual activity to info@buro-1.com.

  • Cooperate with reasonable investigation, containment, and remediation efforts — including preserving logs, rotating credentials, and disabling affected integrations.

  • Where the incident originates from your own users, credentials, devices, networks, configurations, or integrations, you are responsible for your own incident handling and any notifications you are required to make.

6. Reporting a Suspected Incident or Vulnerability

  • Suspected incidents affecting your account: info@buro-1.com (subject: "Security incident")

  • Suspected vulnerabilities: see our Vulnerability Disclosure Policy

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

BURO ONE MANAGEMENT CONSULTANCIES L.L.C · Dubai, United Arab Emirates · info@buro-1.com · All legal documents

Circle icon

We transform organizations.

Your success is next.

Start your project now by booking a one-on-one consultation with our expert.

Team working in an office watching at a presentation
Last update
July 15, 2026

Terms of Use

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")
Chevron Right
The agreements and policies that govern the Buro 1 website and the Pulse platform. If you have a signed agreement with Buro 1 (Order Form, DPA, SOW, SLA), it controls over these pages. For registered platform users, the Pulse Clickwrap Agreement controls over the informational sections below. Each section below carries its own effective date and version. The End User License Agreement and the Privacy Policy are published as separate documents.

A Data Processing Addendum (DPA) is available for signature on request. A Service Level Agreement (SLA) is available to Enterprise customers by signed agreement. Contact info@buro-1.com.

These Terms of Use govern your access to and use of the Buro 1 website ("Website"). Use of the Pulse platform is governed by a separate agreement — the Pulse Clickwrap Agreement (End-User Licence Agreement) — which applies when you register as a platform user. By accessing the Website, you agree to these Terms of Use. If you do not agree, do not use the Website.

1. Who We Are

BURO ONE MANAGEMENT CONSULTANCIES L.L.C is a limited liability company registered in the United Arab Emirates (). We develop and operate the Pulse business intelligence and operations platform.

2. Using the Website

2.1 Permitted Use

You may use the Website for lawful purposes consistent with these Terms. You must not:

  • Use the Website in violation of any applicable law or regulation

  • Transmit unsolicited commercial messages (spam)

  • Attempt to gain unauthorised access to any system, account, or data

  • Introduce malware, viruses, or any other malicious or harmful code

  • Scrape, crawl, or harvest content from the Website without our written consent

  • Impersonate any person or entity or misrepresent your affiliation with any person or entity

2.2 Platform Access

Certain sections of the Website may link to or require a Pulse platform account. Platform access is governed exclusively by the Pulse Clickwrap Agreement accepted at registration.

3. Intellectual Property

All content on the Website — including text, graphics, photographs, logos, design, icons, software code, and data compilations — is owned by or licensed to Buro 1 and is protected under UAE and international intellectual property law.

Nothing on this Website grants you any licence or right to use any Buro 1 intellectual property, trademark, or trade name without our prior written consent. Unauthorised use may give rise to a claim for damages and may constitute a criminal offence.

4. No Warranties

The Website and its content are provided "as is" and "as available" without any representation or warranty, express or implied, including without limitation warranties of merchantability, fitness for a particular purpose, title, or non-infringement.

We do not warrant that:

  • The Website will be uninterrupted, timely, secure, or error-free

  • Any content is accurate, complete, reliable, or current

  • The Website is free from viruses or other harmful components

Nothing on the Website constitutes legal, financial, tax, or professional advice. You should obtain appropriate professional advice before taking any action based on content on this Website.

5. Third-Party Links

The Website may contain links to third-party websites. These links are provided for convenience only. We do not endorse, control, or accept responsibility for the content, privacy practices, security, or availability of any third-party site. Access to any linked third-party site is entirely at your own risk.

6. Exclusion of Liability

The Website is provided free of charge for general information. To the fullest extent permitted by applicable law, Buro 1, its owners, officers, employees, and contractors accept no liability whatsoever to you or any third party arising out of or in connection with the Website or its content — including any direct, indirect, incidental, special, consequential, or punitive damages; loss of profits, revenue, data, goodwill, or business opportunity; or damage to equipment or loss of data — and you agree that you have no claim of any kind against them in connection with the Website.

This exclusion applies regardless of the form of action (contract, tort, strict liability, or otherwise) and even if Buro 1 has been advised of the possibility of such damages. If and only to the extent applicable law does not permit a liability to be excluded, that liability is limited to the minimum amount permitted by law

7. Privacy

Your use of the Website is also governed by our Privacy Policy, which describes how we collect, use, and protect your personal data. The Privacy Policy is incorporated into these Terms by reference.

8. Acceptable Use

You must not use the Website to:

  • Post, transmit, or distribute unlawful, defamatory, threatening, abusive, harassing, or obscene content

  • Facilitate, encourage, or assist any unlawful activity

  • Interfere with or disrupt the security, integrity, or availability of the Website or any connected network or system

  • Collect or harvest information about other users without their consent

We reserve the right to suspend or permanently block access for any user who violates these Terms, without notice or liability

9. Changes to the Website

We may modify, restrict, suspend, or discontinue any part of the Website at any time without notice or liability to you.

10. Changes to These Terms

We may update these Terms of Use at any time. Updated Terms take effect when posted on the Website. Your continued use of the Website after posting constitutes acceptance of the updated Terms. We recommend checking this page periodically.

11. Governing Law and Jurisdiction

These Terms of Use are governed by the federal laws of the United Arab Emirates as applicable in the Emirate of Dubai and the local laws of the Emirate of Dubai. Any dispute arising from or related to your use of the Website, or these Terms, shall be subject to the exclusive jurisdiction of the courts of Dubai, United Arab Emirates.

12. Contact

For enquiries about these Terms: BURO ONE MANAGEMENT CONSULTANCIES L.L.C Dubai, United Arab Emirates Email: info@buro-1.com

Acceptable Use Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This Acceptable Use Policy ("AUP") applies to anyone who accesses or uses the Buro 1 website, the Pulse platform, APIs, or any related service (together, the "Services"). If you are a registered Pulse customer, this AUP supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and any signed agreement between you and Buro 1; in the event of conflict, that agreement controls.

Buro 1 may update this AUP from time to time. Continued use of the Services after an update constitutes acceptance.

1. Prohibited Conduct

You must not, and must not permit or assist anyone else to:

1.1 Unlawful and Harmful Use

  • Use the Services in violation of any applicable law, regulation, or third-party right

  • Upload, transmit, store, or process unlawful, defamatory, threatening, abusive, harassing, deceptive, fraudulent, or obscene material

  • Use the Services to facilitate, encourage, or assist any unlawful activity

1.2 Security Abuse

  • Upload or transmit malware, ransomware, spyware, viruses, worms, Trojan horses, or any other harmful code

  • Attempt to gain unauthorised access to the Services, Buro 1 systems, another customer's account or data, or any third-party system or network

  • Conduct denial-of-service attacks, load attacks, stress tests, vulnerability scans, or penetration tests without Buro 1's prior written approval

  • Bypass, disable, or interfere with authentication controls, access controls, rate limits, usage limits, seat limits, billing controls, or any other security or technical mechanism

  • Distribute phishing or credential-harvesting content

1.3 Misuse of the Platform

  • Send spam, unlawful marketing, or communications that violate anti-spam or telecommunications rules

  • Scrape, crawl, harvest, or extract content or data by automated means without Buro 1's written consent

  • Reverse engineer, decompile, disassemble, copy, train on, or attempt to derive source code, non-public APIs, models, prompts, architecture, workflows, or trade secrets, except to the extent applicable law prohibits this restriction

  • Resell, sublicense, timeshare, or provide third-party access to the Services except as expressly permitted in a signed agreement

  • Impersonate any person or entity or misrepresent your affiliation

1.4 Data Restrictions

  • Submit regulated health information, payment card data, government identifiers, children's data, biometric data, financial account credentials, or other highly sensitive data, unless expressly permitted in a signed Order Form or Data Processing Addendum

  • Submit personal data without a lawful basis, required notices, and required consents

1.5 High-Risk Use

  • Use the Services in any environment where failure could cause death, personal injury, catastrophic property damage, environmental harm, or critical-infrastructure disruption, unless Buro 1 expressly agrees in writing

2. Enforcement

Buro 1 may investigate suspected violations of this AUP. Buro 1 may throttle, suspend, or terminate access — in whole or in part, with or without notice — where Buro 1 reasonably believes a violation has occurred or may occur, or where necessary to protect the security, integrity, or availability of the Services, other customers, or third parties.

Buro 1 is not liable for any action taken in good faith under this AUP, including suspension or termination of access.

3. Reporting Violations

To report suspected violations of this AUP, contact info@buro-1.com. To report suspected security vulnerabilities, see our Vulnerability Disclosure Policy.

4. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Security at Buro 1

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Security is foundational to how we build and operate the Pulse platform. This Security Statement describes the technical and organisational measures we apply to protect customer data.

This page is informational. It does not create warranties, representations, or contractual commitments. The Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum govern Buro 1's contractual security obligations; in the event of conflict, those agreements control.

1. Infrastructure and Hosting

  • The Pulse platform runs on enterprise-grade cloud infrastructure: Microsoft Azure (application hosting, database, backend, authentication, storage and monitoring — hosted in the UAE region).

  • Our infrastructure providers maintain independent security and compliance programmes, including certifications such as SOC 2 and ISO 27001 at the infrastructure layer.

  • Buro 1 does not operate its own physical data centers; physical security is managed by our infrastructure providers.

2. Data Encryption

  • In transit: all traffic between your browser and the platform is encrypted using TLS 1.2 or higher.

  • At rest: customer data is encrypted at rest at the infrastructure layer.

3. Tenant Isolation

  • Pulse is a multi-tenant platform with row-level security (RLS) enforced at the database layer.

  • Each customer entity's data is logically separated. Access policies are enforced on every query — not only at the application layer.

4. Access Control

  • Role-based access controls govern what each user can see and do within the platform.

  • Internal access to production systems and customer data is restricted to personnel who need it to perform their role, protected by strong authentication.

  • Access is revoked promptly when no longer required.

5. Application Security

  • Secure development practices, including code review before production deployment

  • Dependency and vulnerability monitoring

  • Rate limiting and abuse protection on authentication and API endpoints

  • Logging and monitoring of security-relevant events

6. Backups and Continuity

  • Automated backups are maintained at the infrastructure layer for disaster-recovery purposes.

  • See our Backup, Business Continuity and Disaster Recovery Statement for details.

7. Incident Response

  • Buro 1 maintains an incident response process covering detection, containment, investigation, remediation, and — where required by law or contract — notification.

  • See our Incident Response and Breach Notification Statement for details.

8. Personnel

  • Buro 1 personnel and contractors with access to customer data are bound by written confidentiality and IP obligations before receiving access.

9. Sub-Processors

  • We use a small, disclosed set of infrastructure providers, each bound by contractual data protection obligations. See our Sub-Processor List.

10. Shared Responsibility

Security is shared between Buro 1 and each customer. Customers are responsible for:

  • Safeguarding their accounts, passwords, API keys, and administrator credentials

  • Provisioning and de-provisioning their own users promptly, and reviewing user access

  • Securing their own devices, networks, browsers, and integrations

  • Exporting and independently backing up their data where they require independent retention

  • Ensuring the data they submit is lawful and appropriate for the platform

  • Promptly reporting suspected unauthorised access to Buro 1

11. No Absolute Security

No software, network, or security programme can be guaranteed to be error-free or immune from attack. Security controls reduce risk; they cannot eliminate it. Buro 1 does not warrant that the Services will be free from vulnerabilities, unauthorised access, or security incidents. Buro 1's contractual responsibilities in relation to security are as set out in the applicable agreement.

12. Reporting a Vulnerability

If you believe you have found a security vulnerability in a Buro 1 service, please report it confidentially — see our Vulnerability Disclosure Policy, or email info@buro-1.com. Do not publicly disclose or exploit suspected vulnerabilities.

13. Security Documentation

Enterprise customers may request additional security information (questionnaires, summaries) under confidentiality via info@buro-1.com. Buro 1 does not disclose sensitive internal security architecture, vulnerability details, or information that could increase security risk.

Security at Buro 1

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Security is foundational to how we build and operate the Pulse platform. This Security Statement describes the technical and organisational measures we apply to protect customer data.

This page is informational. It does not create warranties, representations, or contractual commitments. The Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum govern Buro 1's contractual security obligations; in the event of conflict, those agreements control.

1. Infrastructure and Hosting

  • The Pulse platform runs on enterprise-grade cloud infrastructure: Microsoft Azure (application hosting, database, backend, authentication, storage and monitoring — hosted in the UAE region).

  • Our infrastructure providers maintain independent security and compliance programmes, including certifications such as SOC 2 and ISO 27001 at the infrastructure layer.

  • Buro 1 does not operate its own physical data centers; physical security is managed by our infrastructure providers.

2. Data Encryption

  • In transit: all traffic between your browser and the platform is encrypted using TLS 1.2 or higher.

  • At rest: customer data is encrypted at rest at the infrastructure layer.

3. Tenant Isolation

  • Pulse is a multi-tenant platform with row-level security (RLS) enforced at the database layer.

  • Each customer entity's data is logically separated. Access policies are enforced on every query — not only at the application layer.

4. Access Control

  • Role-based access controls govern what each user can see and do within the platform.

  • Internal access to production systems and customer data is restricted to personnel who need it to perform their role, protected by strong authentication.

  • Access is revoked promptly when no longer required.

5. Application Security

  • Secure development practices, including code review before production deployment

  • Dependency and vulnerability monitoring

  • Rate limiting and abuse protection on authentication and API endpoints

  • Logging and monitoring of security-relevant events

6. Backups and Continuity

  • Automated backups are maintained at the infrastructure layer for disaster-recovery purposes.

  • See our Backup, Business Continuity and Disaster Recovery Statement for details.

7. Incident Response

  • Buro 1 maintains an incident response process covering detection, containment, investigation, remediation, and — where required by law or contract — notification.

  • See our Incident Response and Breach Notification Statement for details.

8. Personnel

  • Buro 1 personnel and contractors with access to customer data are bound by written confidentiality and IP obligations before receiving access.

9. Sub-Processors

  • We use a small, disclosed set of infrastructure providers, each bound by contractual data protection obligations. See our Sub-Processor List.

10. Shared Responsibility

Security is shared between Buro 1 and each customer. Customers are responsible for:

  • Safeguarding their accounts, passwords, API keys, and administrator credentials

  • Provisioning and de-provisioning their own users promptly, and reviewing user access

  • Securing their own devices, networks, browsers, and integrations

  • Exporting and independently backing up their data where they require independent retention

  • Ensuring the data they submit is lawful and appropriate for the platform

  • Promptly reporting suspected unauthorised access to Buro 1

11. No Absolute Security

No software, network, or security programme can be guaranteed to be error-free or immune from attack. Security controls reduce risk; they cannot eliminate it. Buro 1 does not warrant that the Services will be free from vulnerabilities, unauthorised access, or security incidents. Buro 1's contractual responsibilities in relation to security are as set out in the applicable agreement.

12. Reporting a Vulnerability

If you believe you have found a security vulnerability in a Buro 1 service, please report it confidentially — see our Vulnerability Disclosure Policy, or email info@buro-1.com. Do not publicly disclose or exploit suspected vulnerabilities.

13. Security Documentation

Enterprise customers may request additional security information (questionnaires, summaries) under confidentiality via info@buro-1.com. Buro 1 does not disclose sensitive internal security architecture, vulnerability details, or information that could increase security risk.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Sub-Processor List

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Buro 1 uses the third-party service providers ("sub-processors") listed below to deliver the Pulse platform and related services. Each sub-processor is bound by contractual data protection obligations consistent with our Privacy Policy, the applicable Data Processing Addendum ("DPA"), and applicable law.

This page is the authoritative, current list of Buro 1 sub-processors referenced in our Privacy Policy, the Pulse Clickwrap Agreement, and each signed DPA. In the event of conflict with a signed agreement, the signed agreement controls.

Current Sub-Processors

  • Microsoft Azure
    Service: Application hosting, database, backend infrastructure, authentication, storage, transactional email delivery, monitoring
    Data processed: Customer Data, account data, authentication data, notification content, technical data
    Location: United Arab Emirates

Infrastructure Location

Customer Data submitted to the Pulse platform is stored and processed on Microsoft Azure infrastructure hosted in the United Arab Emirates.

Changes to This List

Buro 1 may add, replace, or remove sub-processors from time to time.

  • Notification: we update this page when sub-processors change. Customers with a signed DPA that requires notice of new sub-processors will be notified in accordance with the DPA (by email to the account or nominated contact address). This page itself creates no notification obligations beyond those in a signed DPA.

  • Objection: if a signed DPA grants you an objection right, you may object on reasonable data protection grounds within the period stated in the DPA. If no resolution is reasonably available, your remedy is as stated in the DPA.

To subscribe to sub-processor change notifications, email info@buro-1.com with the subject "Sub-processor notifications".

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Support Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This Support Policy describes standard support for the Pulse platform. It supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and any signed Order Form; in the event of conflict, the signed agreement or Order Form controls. Enhanced support tiers, if purchased, are described in the applicable Order Form.

1. Support Channels

  • Email: info@buro-1.com

  • In-product: the support channel within the Pulse platform, where available

  • Any additional channel stated in your Order Form

2. Support Hours

Unless your Order Form states otherwise, support is provided during Buro 1's normal business hours, Monday to Friday, 9:00–18:00 Gulf Standard Time (UTC+4), excluding UAE public holidays and Buro 1 company holidays.

3. Severity Levels and Target Response Times

Buro 1 prioritises issues by severity. Target first-response times below are goals, not guarantees, unless a signed Service Level Agreement ("SLA") states otherwise. Failure to meet a target does not constitute a breach and creates no liability, credit, or refund.

  • S1 — Critical
    Definition: Platform unavailable for all users of an entity, or confirmed data-integrity issue, with no workaround
    Target first response: 4 business hours

  • S2 — High
    Definition: Major feature unavailable or materially degraded; workaround difficult
    Target first response: 8 business hours

  • S3 — Normal
    Definition: Feature impaired but usable; reasonable workaround exists
    Target first response: 2 business days

  • S4 — Low
    Definition: Questions, cosmetic issues, feature requests
    Target first response: 5 business days

Buro 1 assigns severity based on customer impact, security risk, number of affected users, reproducibility, and whether a workaround exists, and may reclassify issues as information develops.

4. What Support Includes

  • Troubleshooting platform errors and unexpected behaviour

  • Guidance on standard platform features and configuration

  • Investigation of suspected bugs and defects

  • Account and access assistance

5. What Support Does Not Include

Unless expressly included in an Order Form or a signed Statement of Work:

  • Custom development, customisation, or integration work

  • Training beyond standard onboarding materials

  • Data migration, data cleansing, or bulk data entry

  • Support for customer networks, devices, browsers, or third-party systems

  • Support for customer-built integrations or unsupported configurations

  • Issues caused by customer misuse, user error, or use outside the applicable agreement

Bespoke work is available as professional services under a signed Statement of Work at Buro 1's then-current rates.

6. Customer Cooperation

Effective support depends on you. Please provide accurate descriptions, screenshots, logs, reproduction steps, and timely responses. Buro 1 may close tickets where the requester is unresponsive for ten (10) business days.

7. No Guaranteed Resolution

Unless a signed SLA states otherwise, Buro 1 does not guarantee response times, resolution times, root-cause analysis delivery, or continuous support availability.

8. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Refund and Cancellation Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This policy explains how subscription cancellations and refunds work for the Pulse platform. It supplements the Pulse Clickwrap Agreement (End-User Licence Agreement) and your Order Form; in the event of conflict, the signed Order Form and the Clickwrap Agreement control.

1. Subscription Term and Auto-Renewal

  • Unless your Order Form states otherwise, subscriptions run on a 12-month rolling term and renew automatically for successive periods at the then-current price.

  • Buro 1 will send a renewal reminder to your account email at least fourteen (14) days before renewal where required by applicable law.

2. How to Cancel

  • To cancel, give written notice to info@buro-1.com, or follow the cancellation procedure in your Order Form. Order Forms typically require notice at least thirty (30) days before the renewal date; if your Order Form does not specify a notice period, cancellation is effective if notice is given before the renewal date.

  • Cancellation takes effect at the end of the current subscription period. Access continues until then.

  • Cancellation does not relieve you of amounts already owed.

3. Refunds

  • Fees are non-refundable except as expressly stated in your Order Form, this policy, or as required by applicable law.

  • No refunds or credits are provided for partial periods, unused users or capacity, downgrade differences, or periods where the platform was available but unused.

  • Downtime is remedied by extra service days (capped at 30 days per 12-month period; or SLA credits where a signed SLA applies), and qualifying security incidents by free months (capped at 2 per 12-month period), per the Clickwrap Agreement — these in-kind remedies are exclusive, are not cash, and are not refundable.

  • If Buro 1 terminates your subscription without cause, or an extended force majeure event triggers termination under the Clickwrap Agreement, Buro 1 will refund prepaid fees for the unused remainder of the affected period. No refund is due where Buro 1 terminates or suspends for cause (including non-payment, unlawful use, or breach).

4. Free Trials and Pilots

  • Trial, evaluation, and pilot access is free of charge and carries no refund obligation.

  • If you do not convert to a paid subscription, trial data may be deleted after the trial ends.

5. Professional Services

  • Fees for professional services (implementation, configuration, integration, training, consulting) are governed by the applicable signed Statement of Work or Change Order and are non-refundable once the work is performed.

6. Your Data After Cancellation

  • After termination or expiry, you have a 30-day window to export your data in a machine-readable format. After that window, your data may be permanently deleted. See the Backup, Business Continuity and Disaster Recovery Statement and your agreement for details.

7. Consumer Rights

If applicable law grants you non-waivable rights (including consumer refund rights), nothing in this policy limits those rights.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Vulnerability Disclosure Policy

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

Buro 1 welcomes reports from security researchers and customers who believe they have identified a vulnerability in a Buro 1 service. This policy explains how to report responsibly and what you can expect from us.

This policy is not an invitation to test our systems and does not create a bug-bounty programme, a contract, or any entitlement to reward. Active security testing (scanning, penetration testing, load testing) of Buro 1 services requires Buro 1's prior written approval — see the Acceptable Use Policy and the Pulse Clickwrap Agreement.

1. How to Report

Email info@buro-1.com with the subject line "Security vulnerability report", including:

  • A description of the suspected vulnerability and its potential impact

  • Steps to reproduce (URLs, request/response samples, screenshots)

  • The date and time you observed the issue

  • Your contact details for follow-up

Please report in confidence and give us a reasonable opportunity to investigate and remediate before any disclosure to third parties.

2. Rules of Engagement

When investigating or reporting a suspected vulnerability, you must not:

  • Access, copy, modify, or delete data belonging to Buro 1 or any other customer — if you inadvertently access another party's data, stop immediately and report it

  • Degrade, disrupt, or deny service to any Buro 1 system or user

  • Use social engineering, phishing, or physical intrusion

  • Run automated scanners, brute-force tools, or denial-of-service tests

  • Publicly disclose, sell, or share the vulnerability or any related data with third parties

  • Demand payment or other consideration as a condition of disclosure

3. What You Can Expect

  • We aim to acknowledge reports promptly.

  • We investigate reports, prioritise based on severity, and work to remediate confirmed vulnerabilities.

  • We aim to keep reporters informed of progress where reasonably practicable.

This section describes our practice; it does not create contractual obligations, deadlines, or liability.

4. Good-Faith Safe Harbour

If you comply with this policy in full and act in good faith, Buro 1 does not intend to initiate legal action against you for your good-faith, proportionate research activities that led to the report. This safe harbour does not apply to any activity listed in Section 2, does not bind third parties or authorities, and does not authorise violations of applicable law.

5. Scope

In scope: the Buro 1 website, the Pulse platform, and Buro 1-operated APIs. Out of scope: third-party services and infrastructure operated by our providers (Microsoft Azure) — please report issues in those platforms to the relevant provider under their own disclosure programmes.

6. Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Backup, Business Continuity and Disaster Recovery Statement

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This statement describes how Buro 1 approaches backups, business continuity, and disaster recovery for the Pulse platform.

This page is informational. It does not create warranties, service level commitments, or contractual obligations. Buro 1's contractual commitments regarding backups, data retention, and availability are set out exclusively in the Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, Order Form, Data Processing Addendum, or Service Level Agreement; in the event of conflict, those documents control.

1. Operational Backups

  • Automated backups of platform databases are maintained at the infrastructure layer (Microsoft Azure, UAE region) on a regular schedule for disaster-recovery purposes.

  • Backups are encrypted and access-restricted.

  • Operational backups exist to restore the platform, not to serve as an archival service for individual customer records. Restoration of specific customer records is not guaranteed unless expressly provided in a signed Order Form or SLA.

2. Customer Backup Responsibility

  • Customers are responsible for exporting and independently backing up their data where they require independent retention, using the export tools provided in the platform.

  • Buro 1 is not responsible for loss of data caused by a customer's failure to maintain independent backups, customer deletion or modification of data, credential compromise, or configuration choices.

3. Business Continuity

  • The Pulse platform is built on managed cloud infrastructure (Microsoft Azure) with provider-level redundancy, failover, and monitoring.

  • Buro 1 has no single physical point of failure under its own control: the platform is fully cloud-hosted and can be operated and administered remotely.

  • Key operational knowledge, configuration, and code are maintained in version-controlled repositories with restricted access.

4. Disaster Recovery

  • In the event of infrastructure loss, the platform is designed to be restored from infrastructure-layer backups.

  • Recovery targets (informational, not contractual): recovery point objective (RPO) of up to 24 hours; recovery time objective (RTO) of up to 72 hours for full platform restoration, depending on the nature of the event and our infrastructure providers.

  • Events affecting our infrastructure providers themselves (regional cloud outages, provider failures) may extend recovery times and are outside Buro 1's reasonable control.

5. Data Retention and Deletion

Summary of standard retention (the applicable agreement controls):

  • Active subscription
    Standard treatment: Data retained for the duration of the subscription

  • Termination or expiry
    Standard treatment: 30-day export window, after which data may be permanently deleted

  • Backup purge
    Standard treatment: Deleted data may persist in encrypted backups for up to 90 days, or longer where legally required

  • Legal records
    Standard treatment: Contracts and invoices retained 5 years or as required by UAE law

6. Continuous Improvement

Buro 1 reviews its backup and recovery arrangements periodically and as the platform and its infrastructure evolve. This statement will be updated to reflect material changes.

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

Incident Response and Breach Notification Statement

BURO ONE MANAGEMENT CONSULTANCIES L.L.C ("Buro 1", "we", "us", "our")

Effective date: July 15, 2026 Last updated: July 15, 2026 Version: 1.0

This statement describes how Buro 1 responds to security incidents affecting the Pulse platform and how customers are notified.

This page is informational. Buro 1's contractual obligations regarding security incidents and breach notification are set out exclusively in the Pulse Clickwrap Agreement (End-User Licence Agreement), any signed agreement, and any signed Data Processing Addendum ("DPA"); in the event of conflict, those documents control.

1. Definitions

  • A Security Incident is a confirmed breach of Buro 1's security controls that results in unauthorised access to or disclosure of Customer Data processed by Buro 1.

  • Unsuccessful attempts (blocked attacks, port scans, failed logins, denial-of-service attempts that do not compromise data) are not Security Incidents and do not trigger notification.

2. Our Incident Response Process

  • Detect
    What we do: Monitoring, logging, alerts, and reports from users, researchers, and providers

  • Contain
    What we do: Isolate affected systems, revoke compromised credentials, block attack vectors

  • Assess
    What we do: Determine scope, affected data, affected customers, and root cause

  • Remediate
    What we do: Fix the vulnerability, restore normal operation, harden controls

  • Notify
    What we do: Notify affected customers and authorities where required (Section 3)

  • Review
    What we do: Post-incident review and corrective actions

3. Customer Notification

  • Where a Security Incident affects your Customer Data and notification is required by applicable law or your DPA, Buro 1 will notify you without undue delay after confirming the incident.

  • Notification will be sent to your account email address or the contact nominated in your agreement, and will include — to the extent known at the time — the nature of the incident, categories of data affected, measures taken, and recommended customer actions. Information may be provided in phases as the investigation develops.

  • Notification may be delayed where required by law enforcement, legal obligations, or where immediate disclosure would compromise containment or investigation.

  • Notification of, or response to, a Security Incident is not an acknowledgement of fault or liability. Buro 1's notification obligations are only those imposed by applicable law or a signed DPA; this page creates no additional obligations.

4. Regulatory Notification

Where required, Buro 1 notifies competent authorities in accordance with applicable law, including UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL).

5. Customer Responsibilities

  • Promptly report suspected unauthorised access, credential compromise, or unusual activity to info@buro-1.com.

  • Cooperate with reasonable investigation, containment, and remediation efforts — including preserving logs, rotating credentials, and disabling affected integrations.

  • Where the incident originates from your own users, credentials, devices, networks, configurations, or integrations, you are responsible for your own incident handling and any notifications you are required to make.

6. Reporting a Suspected Incident or Vulnerability

  • Suspected incidents affecting your account: info@buro-1.com (subject: "Security incident")

  • Suspected vulnerabilities: see our Vulnerability Disclosure Policy

Contact

BURO ONE MANAGEMENT CONSULTANCIES L.L.CDubai, United Arab Emirates Email: info@buro-1.com

BURO ONE MANAGEMENT CONSULTANCIES L.L.C · Dubai, United Arab Emirates · info@buro-1.com · All legal documents

Circle icon

We transform organizations.

Your success is next.

Start your project now by booking a one-on-one consultation with our expert.

Team working in an office watching at a presentation