Polestead is built so your most sensitive data can stay inside your own walls. This policy explains what personal data we handle, on what basis, and the choices you have.
This is a template prepared for Polestead's launch. Bracketed items marked [ ] must be completed and reviewed by qualified privacy counsel before publication.
For the vendor records, assessments, evidence, and incident data you bring into Polestead, you are the data controller and Polestead acts as your processor, handling that data only on your instructions under a data-processing agreement. For your account, billing, and how you interact with our website, Polestead is the controller. In self-hosted and air-gapped deployments, your operational data never reaches us at all.
To provide, secure, and improve the service; to authenticate users and administer accounts; to communicate about the service; to meet legal obligations; and, for the marketing site, to understand aggregate usage. We do not sell personal data.
Where GDPR applies, we rely on: performance of a contract (providing the service); legitimate interests (securing and improving the service, and B2B communications), balanced against your rights; consent (certain cookies and communications); and legal obligation. As a processor of your Customer Data, we act on your documented instructions.
Polestead does not run AI inference on its own infrastructure and does not use your data to train models. Where you enable AI features, they call your own provider under your keys (bring-your-own-key); that processing is governed by your agreement with the provider. A zero-AI configuration is available.
For the managed service, we use a limited set of subprocessors (for example hosting and email delivery), each under contract with appropriate safeguards. The current list, and the way to subscribe to change notifications, is published in our Trust Center. Self-hosted and air-gapped deployments use no Polestead subprocessors for your operational data.
Sovereignty is a matter of jurisdiction, not only geography. Self-hosted and air-gapped deployments keep your operational data within your own environment, removing cross-border transfer questions. The single-tenant EU cloud and managed SaaS options are EU-resident and single-tenant, and where any transfer is necessary we rely on appropriate safeguards such as Standard Contractual Clauses.
We retain account and billing data for as long as your subscription is active and as required for legal and accounting purposes. Customer Data in the managed service is retained per your configuration and deleted or exported at the end of the export window described in the Terms of Service.
Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing or withdraw consent. Where we act as processor for your Customer Data, we will support you in fulfilling data-subject requests. Contact privacy@polestead.com; you also have the right to complain to your supervisory authority.
We protect personal data with technical and organizational measures appropriate to the risk — described on our Security & compliance page. No system is perfectly secure, but security is central to how Polestead is built and operated.
Our marketing site uses a small number of cookies for essential functionality and aggregate analytics. You can manage non-essential cookies through the cookie controls on the site. The product application uses only the cookies necessary to keep you signed in and secure.
For privacy questions or to exercise your rights, contact privacy@polestead.com, or write to [Polestead legal entity name, registered address]. Our data protection contact is [DPO name / contact], where appointed.
For the vendor and assessment data you bring, you're the controller and we're your processor. For your account and site usage, we're the controller. Self-hosted keeps that data in your environment.
No. Inference runs on your own keys or not at all — we never receive your data for training and have nothing to train on.
Wherever you choose — on-premises, air-gapped, single-tenant EU cloud, or managed SaaS. Self-hosted and air-gapped remove cross-border questions entirely.
Access, correction, deletion, portability, restriction, and objection, depending on your jurisdiction. Email privacy@polestead.com to exercise them.