Legal

Privacy policy

Polestead is built so your most sensitive data can stay inside your own walls. This policy explains what personal data we handle, on what basis, and the choices you have.

Last updated: 20 July 2026 · Version 1.0

This is a template prepared for Polestead's launch. Bracketed items marked [ ] must be completed and reviewed by qualified privacy counsel before publication.

1 · Our role: controller vs processor

For the vendor records, assessments, evidence, and incident data you bring into Polestead, you are the data controller and Polestead acts as your processor, handling that data only on your instructions under a data-processing agreement. For your account, billing, and how you interact with our website, Polestead is the controller. In self-hosted and air-gapped deployments, your operational data never reaches us at all.

2 · What we collect

  • Account data — name, work email, organization, role, and authentication details.
  • Usage data — logs of how the managed service is used, for security and reliability.
  • Customer Data — the vendor and assessment content you upload (processed on your behalf).
  • Trust Center data — content you publish, and the visitor log of who accessed it.
  • Website data — limited analytics and cookie data when you visit our marketing site.

3 · How we use it

To provide, secure, and improve the service; to authenticate users and administer accounts; to communicate about the service; to meet legal obligations; and, for the marketing site, to understand aggregate usage. We do not sell personal data.

4 · Legal bases (GDPR)

Where GDPR applies, we rely on: performance of a contract (providing the service); legitimate interests (securing and improving the service, and B2B communications), balanced against your rights; consent (certain cookies and communications); and legal obligation. As a processor of your Customer Data, we act on your documented instructions.

5 · AI & your data

Polestead does not run AI inference on its own infrastructure and does not use your data to train models. Where you enable AI features, they call your own provider under your keys (bring-your-own-key); that processing is governed by your agreement with the provider. A zero-AI configuration is available.

6 · Subprocessors

For the managed service, we use a limited set of subprocessors (for example hosting and email delivery), each under contract with appropriate safeguards. The current list, and the way to subscribe to change notifications, is published in our Trust Center. Self-hosted and air-gapped deployments use no Polestead subprocessors for your operational data.

7 · International transfers

Sovereignty is a matter of jurisdiction, not only geography. Self-hosted and air-gapped deployments keep your operational data within your own environment, removing cross-border transfer questions. The single-tenant EU cloud and managed SaaS options are EU-resident and single-tenant, and where any transfer is necessary we rely on appropriate safeguards such as Standard Contractual Clauses.

8 · Retention

We retain account and billing data for as long as your subscription is active and as required for legal and accounting purposes. Customer Data in the managed service is retained per your configuration and deleted or exported at the end of the export window described in the Terms of Service.

9 · Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing or withdraw consent. Where we act as processor for your Customer Data, we will support you in fulfilling data-subject requests. Contact privacy@polestead.com; you also have the right to complain to your supervisory authority.

10 · Security

We protect personal data with technical and organizational measures appropriate to the risk — described on our Security & compliance page. No system is perfectly secure, but security is central to how Polestead is built and operated.

11 · Cookies

Our marketing site uses a small number of cookies for essential functionality and aggregate analytics. You can manage non-essential cookies through the cookie controls on the site. The product application uses only the cookies necessary to keep you signed in and secure.

12 · Contact

For privacy questions or to exercise your rights, contact privacy@polestead.com, or write to [Polestead legal entity name, registered address]. Our data protection contact is [DPO name / contact], where appointed.

FAQ

Privacy, answered.

Are you a controller or a processor?+

For the vendor and assessment data you bring, you're the controller and we're your processor. For your account and site usage, we're the controller. Self-hosted keeps that data in your environment.

Do you train AI on my data?+

No. Inference runs on your own keys or not at all — we never receive your data for training and have nothing to train on.

Where is my data stored?+

Wherever you choose — on-premises, air-gapped, single-tenant EU cloud, or managed SaaS. Self-hosted and air-gapped remove cross-border questions entirely.

What rights do I have?+

Access, correction, deletion, portability, restriction, and objection, depending on your jurisdiction. Email privacy@polestead.com to exercise them.