Data Processing Terms
UK GDPR terms applying when Polaris processes personal data for a workspace customer.
Last updated: 13 June 2026
Legal review required
These initial terms are intended to reflect standard UK GDPR processor obligations. They must be reviewed alongside Polaris's final legal entity details, subprocessor list, retention schedule and security controls before paid general availability.
1. Scope and roles
These Data Processing Terms form part of the Terms and Conditions. They apply where a workspace customer is a controller and Polaris processes personal data on that customer's behalf as processor. Terms such as controller, processor, personal data, processing and data subject have the meanings given in the UK GDPR and Data Protection Act 2018.
2. Customer instructions and compliance
Polaris will process customer personal data only on documented customer instructions, including instructions inherent in using the service, unless UK law requires otherwise. If legally permitted, Polaris will inform the customer before processing required by law. Polaris will notify the customer if an instruction appears to infringe applicable data-protection law.
3. Confidentiality and security
Polaris will ensure that people authorised to process customer personal data are subject to confidentiality obligations and will maintain appropriate technical and organisational measures proportionate to the risk. These measures include tenant isolation, access controls, private object storage, encryption provided by managed infrastructure, logging and secure development practices.
4. Subprocessors
The customer gives general authorisation for Polaris to use subprocessors needed to provide the service. Polaris will require subprocessors to protect personal data under obligations that are materially consistent with these terms and remains responsible for their processing as required by applicable law. The current Subprocessor Register identifies providers, purposes and primary processing locations.
5. Data-subject requests and compliance assistance
Taking account of the nature of processing and information available to it, Polaris will provide reasonable assistance with data-subject requests, security obligations, data-protection impact assessments and regulatory consultations. If Polaris receives a request relating to customer-controlled data, it will direct the requester to the customer unless legally prohibited.
6. Personal data breaches
Polaris will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. Polaris will provide available information reasonably needed for the customer to assess and meet its notification obligations and will take reasonable steps to contain, investigate and remediate the breach.
7. International transfers
Polaris will not make a restricted transfer of customer personal data unless permitted under UK data-protection law. Where required, Polaris will use an applicable adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another lawful safeguard, together with any required transfer risk assessment.
8. Return and deletion
At the end of the service, Polaris will delete or return customer personal data on the customer's instruction unless applicable law requires continued retention. Deletion from backups and operational systems may occur over a reasonable period consistent with documented retention and recovery processes.
9. Information and audits
Polaris will make information reasonably necessary to demonstrate compliance with these terms available to the customer. Subject to appropriate confidentiality, security and proportionality controls, Polaris will support reasonable audits or inspections where required by UK data-protection law.
10. Processing details
| Subject matter | Providing and securing the Polaris operational collaboration platform. |
|---|---|
| Duration | For the workspace subscription or early-access period, plus documented retention and deletion periods. |
| Nature and purpose | Hosting, organising, transmitting, securing, backing up and supporting customer-submitted support data. |
| Data subjects | Workspace users, customer contacts, support requesters and other people represented in customer-submitted data. |
| Personal data | Identity and contact details, account data, support messages, attachments, operational records and other data submitted by or for the customer. |
| Special category data | Not intentionally required by Polaris. Customers should avoid submitting it unless necessary, lawful and appropriately protected. |
11. Governing law
These Data Processing Terms are governed by the laws of England and Wales and are subject to the jurisdiction stated in the Terms and Conditions.