# Polestar GRC Privacy Policy

Version: 3.1, effective October 9, 2026

Published October 9, 2026. Replaces Version 3.0, effective October 8, 2026. Version 3.1 changes the business that operates Polestar GRC (Section 1). The operator named in earlier versions of this Policy assigned the Polestar GRC business to Jonathan Prine, an individual doing business as Polestar GRC, on the date stated in our notice of assignment to customers. How we collect, use and disclose information does not change because of that assignment. Version 3.1 also describes how we verify an application for the nonprofit discount: the letter and EIN you submit, the AI review of the letter, the public nonprofit registry lookup and how long we keep the letter (Sections 3.1, 3.3, 4, 5 and 12); adds Google Workspace, which hosts our mailboxes, to the Subprocessor list (Section 10); states why we keep audit log entries six years (Sections 12 and 14); corrects the Minnesota and consumer health data citations (Section 15); sends notices of changes to each workspace's Notice Contacts (Sections 10 and 19); and states our safeguards as they are today (Sections 3, 5, 10 and 13): we do not use a secrets manager, application secrets are kept in an access-restricted file on our production server, backups are tested by a full restore at least once a year and after any change to the backup process, and PDF files and images that AI features analyze are sent as uploaded. For people whose information we held before October 8, 2026, any change made in Version 3.0 that is material under Section 19 takes effect on November 7, 2026, 30 days after our notice of October 8, 2026. Every earlier version is archived at polestargrc.com/legal/archive.

This Privacy Policy explains how Jonathan Prine, an individual doing business as Polestar GRC ("Polestar GRC", "we", "us"), collects, uses, discloses and protects information when you visit polestargrc.com or a partner portal hosted on a polestargrc.com subdomain, create an account, or use the Polestar GRC platform (the "Service"). It describes what our systems actually do as of the version date.

## Summary

- We collect the account, billing, usage and content data needed to run a compliance platform for organizations. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your data to train AI models.
- Protected Health Information that a healthcare customer stores in the Service is governed by our Business Associate Agreement or Subcontractor Business Associate Agreement. Sensitive personal and health information stored by customers outside HIPAA is governed by our Data Protection Agreement. Those agreements, not this Policy, control that data.
- AI features, including the in-app compliance assistant, send text and, for document analysis, the documents you choose, to Anthropic Claude models running on Amazon Bedrock in Amazon Web Services' United States Regions. Amazon does not store or train on that content, and Anthropic has no access to it.
- We set one cookie, for sign-in. We do not use advertising, analytics or session-recording tools. Our pages load a typeface from Google Fonts, which sees your IP address and browser details (Section 8).
- You can export, correct and delete your data from the Service, and you can ask us for help at privacy@polestargrc.com. We honor privacy requests from residents of every US state whether or not a specific state law requires it.

## 1. Who we are and the roles we play

Polestar GRC is operated by Jonathan Prine, an individual doing business as Polestar GRC, at 434 Kern St, Taft, CA 93268, United States. Jonathan Prine, doing business as Polestar GRC, is the business (the "controller" under many state laws) responsible for the information described in item 1 below. We process data in the United States.

We handle information in two capacities:

1. As a business (a "controller" under many state laws) for information about visitors to our website, people who contact us, people who register accounts, workspace owners, billing contacts and partners, and for usage of the Service. This Policy describes that processing.

2. As a service provider, processor or HIPAA business associate for the content our customers store in their workspaces, including information about their workforce, clients, patients, vendors and systems ("Customer Data"). We process Customer Data only on the customer's instructions, under our Terms of Service and the platform agreement the customer has accepted: the Business Associate Agreement ("BAA") for HIPAA covered entities, the Subcontractor Business Associate Agreement for HIPAA business associates, or the Data Protection Agreement ("DPA") for organizations outside HIPAA. If you are an employee, contractor, auditor, client or patient of one of our customers, see Section 17.

## 2. PHI is governed by the BAA; state-mode data by the DPA

When a HIPAA covered entity or business associate stores Protected Health Information ("PHI") in the Service, we are its business associate or subcontractor. We use and disclose that PHI only as the BAA or Subcontractor BAA and 45 CFR Parts 160 and 164 permit, and those agreements control over this Policy wherever the two differ. When an organization that is not regulated by HIPAA stores sensitive personal or health information about its clients, the DPA governs that data in the same way. Nothing in this Policy gives us rights in PHI or DPA-protected data beyond those agreements.

## 3. Information we collect

### 3.1 Information you give us

Account and profile: name, work email address, password (stored only as a bcrypt hash), multi-factor authentication secret and hashed recovery codes if you enable MFA, session timeout preference, language and interface preferences.

Organization: workspace name, organization type, state, approximate headcount, compliance mode (HIPAA or state), whether you are a HIPAA covered entity or business associate, contact details for your Security Officer, Privacy Officer, IT contact, legal contact and emergency coordinator (names, emails, phone numbers), allowed email domains for invitations, branding assets for partners, and, if you apply for the nonprofit discount, your organization's legal name, its EIN and the IRS determination or affirmation letter you upload.

Billing: plan, billing interval, invoice and payment status, and the Stripe customer and subscription identifiers. Card details are entered on pages hosted by Stripe, Inc. and are collected and stored by Stripe, not by us.

Communications: contact form submissions (name, email, organization, message), support tickets and replies, emails you send us, and SMS verification and delivery records if you enable SMS.

Phone number: only if you enable SMS alerts; we verify it with a one-time code first.

Legal records: when you accept the Terms of Service or a platform agreement we record the signer's name and title, account email, the version and SHA-256 fingerprint of the text accepted, the date and time, the network address and the browser.

Audit Room visitors: when an external auditor opens an Audit Room link, we record the email address the auditor enters, the comments the auditor posts, and access events (time and IP address) for the customer's audit trail.

Customer Data: assessment answers, policies and their version history and acknowledgments, evidence files, vendor and BAA records, training assignments and completions, incident and breach records, risk register entries, compliance scores, audit packages, compliance assistant conversations (stored only after automated redaction), results of security scans you run (which can include credentials or secrets our scanners detect in your own systems), and data pulled from cloud accounts, log platforms and code repositories you connect. Customer Data may include personal information about your workforce and, for healthcare customers, PHI or consumer health data governed by the BAA or DPA.

Connected-system credentials: GitHub App installation identifiers, cross-account role ARNs and external IDs for AWS, Azure and Datadog credentials, container registry credentials, email provider API keys and Slack webhook URLs that you choose to connect. We keep these in our database on encrypted storage, encrypt the settings of the AWS CloudTrail, Azure activity log and Datadog log connectors, including their keys and secrets, a second time with our own application key, and use them only for the feature you enabled.

### 3.2 Information we collect automatically

Log and device data: IP address, browser and operating system, pages and features used, timestamps and error details. Our pages send no referrer information to other sites.

Security and audit events: sign-ins and failures, MFA events, password changes, permission changes, data exports, agreement downloads, administrative actions and other events our customers need for a HIPAA audit trail. Audit log entries record the acting user, action, resource, time and IP address.

Product analytics: first-party events (such as sign-up, assessment started or completed, trial ended, plan changed) stored in our own database. We do not send these events to an outside analytics company.

AI usage metrics: for each AI request we store the feature used, model, token counts, cost, and the number and types of identifiers our redaction removed. We do not store prompt text, except that the compliance assistant stores the redacted conversation so you can see your history (Section 6).

Cookies and browser storage: described in Section 8.

### 3.3 Information from other sources

Stripe sends us payment status, invoice and subscription events. Twilio SendGrid and Twilio send us delivery, bounce, complaint and unsubscribe events for email and SMS we send. A partner that creates a client workspace gives us the client's organization name, organization type, state, compliance mode, HIPAA role and administrator email (Section 16). When you apply for the nonprofit discount we look up the EIN you entered in a public nonprofit registry, ProPublica Nonprofit Explorer, which republishes IRS records; the lookup sends only the EIN, and we receive the organization's public record (its name, location, 501(c) subsection and IRS ruling date). We do not buy personal information from data brokers.

## 4. How we use information

We use information to:

- Provide, operate, secure, maintain and support the Service and any Professional Services.
- Create and manage accounts, authenticate users, enforce workspace and role permissions, and detect and prevent fraud, abuse and security incidents.
- Process payments, send invoices and receipts, handle failed payments, send the renewal and trial-end notices our Terms describe, and verify nonprofit eligibility (Section 5, Nonprofit verification). We use the letter and EIN you submit for nonprofit verification only to decide whether your organization qualifies for the discount.
- Send service messages: invitations, password resets, MFA notices, policy acknowledgment and training reminders, evidence and agreement expiry reminders, deletion notices, security alerts, billing notices, and SMS alerts if you enable them.
- Send onboarding and product emails during and after your trial, which you can opt out of at any time (Section 14).
- Run the AI features you use (Sections 5 and 6).
- Produce aggregate, de-identified statistics about how the Service is used so we can improve it. We do not use Customer Data or PHI to train AI models, and our AI provider terms prohibit it.
- Comply with law, respond to lawful requests, and enforce our agreements.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about anyone. We do not use automated decision-making that produces legal or similarly significant effects on individuals.

## 5. AI processing

Some features use large language models: drafting and customizing policies, suggesting assessment answers from your evidence, reading uploaded evidence and configuration files, comparing your documents to templates, suggesting remediation, writing audit narratives, analyzing security scan findings, reading the IRS letter in a nonprofit discount application, and the compliance assistant described in Section 6.

Provider and location. AI requests are sent to Anthropic Claude models on Amazon Bedrock under our agreement with Amazon Web Services, which includes a HIPAA business associate addendum covering Bedrock. We call Bedrock from AWS US East (N. Virginia) using a United States cross-Region inference profile, so Bedrock may process a request in any AWS commercial Region in the United States that the profile includes; requests stay on the AWS network and inside the United States. Under the Bedrock service terms, prompts and outputs are not stored by the model service after the response, are not used to train models, and are not available to the model developer: Anthropic has no access to Bedrock's model deployment accounts, prompts or outputs. We do not turn on Amazon Bedrock model invocation logging, so our AWS account does not keep a copy of prompts or outputs. Our own fixed instruction text may be held in the provider's prompt cache for a few minutes.

What we remove before sending. Before a request leaves our systems we run automated redaction. For the compliance assistant, redaction covers patterns that look like Social Security numbers, dates of birth, phone numbers, email addresses, medical record numbers, payment card numbers, street addresses and personal names. For the other AI features, redaction covers Social Security numbers, phone numbers, dates of birth, labeled medical record numbers and payment card numbers in text; names, email addresses and free-text descriptions are not removed. When a feature analyzes evidence files you uploaded, a PDF file or image is sent as you uploaded it, without redaction, and a text file (plain text, CSV, JSON or HTML) is sent after redaction of the same patterns the compliance assistant removes. Redaction is pattern based and will miss some identifiers.

Nonprofit verification. When you apply for the nonprofit discount, the IRS letter you upload is sent, as you uploaded it, to the same AI provider under the same terms, which reads it and reports whether it is an IRS determination or affirmation letter for a 501(c)(3) organization and the name, EIN and date printed on it. We compare that with the legal name and EIN you entered and with the public registry record described in Section 3.3. The automated check can approve an application; it never denies one. A person on our staff reviews every application the check does not approve, and only that person can deny it.

Outputs. AI outputs can be wrong. They are not legal, medical or compliance advice and must be reviewed by a qualified person before you rely on them. We store what the model returned in your workspace as part of the feature (for example, a draft policy) so you can review and edit it.

Limits. AI usage is capped per workspace per month by plan. We log token counts and costs, not prompt content.

## 6. The in-app compliance assistant

The chat assistant inside the Service is an AI system, not a person. It is available only to signed-in users.

What it uses. To answer, the assistant receives your redacted message, recent messages from the same conversation, the page you are on, and facts about your workspace that it may quote, such as your compliance mode, plan, assessment progress and compliance score. It does not receive the contents of your evidence files.

What we keep. We store the redacted text of your messages and the assistant's replies, a count of the identifiers removed, and automated quality and safety flags, so you and your workspace administrators can see the history. Conversations are kept for the life of the workspace and are deleted when the workspace is deleted (Section 12).

Escalation to a person. The assistant can open a support ticket for your workspace. If you describe a suspected breach, a regulator letter, a subpoena or a regulator inquiry, it files an urgent ticket right away; for anything else it tells you what the ticket would say and files it only if you agree. The ticket contains a summary written by the assistant, the page you were on and the category, and our support staff will read it. The assistant files only a small number of tickets per workspace per day. You can always contact support directly instead.

Please do not enter patient or client details in the assistant. It is designed to answer compliance questions, not to process records.

## 7. Analytics and error monitoring

As of the version date, polestargrc.com and partner portals do not load any third-party analytics, advertising, social media or session-recording tools. Our usage statistics come from first-party events stored in our own database (Section 3.2).

We do not currently use a third-party error monitoring service. Server errors are written to our own logs, which we keep for up to 90 days.

The application can be configured to use other analytics tools. We will not turn one on in production until we have updated this Policy and the Subprocessor list, given the notice in Section 10, and, for any tool that would run on signed-in pages, put a business associate agreement or equivalent data protection terms in place.

## 8. Cookies and similar technologies

Cookie we set:

| Name | Purpose | Type | Lifetime |
|---|---|---|---|
| app_session_id | Signed session token that keeps you signed in; HttpOnly and Secure | Strictly necessary | Up to 12 hours (shorter if idle for 30 minutes, or as your administrator sets) |

Browser storage (kept in your browser, not sent to us automatically): theme, language, onboarding progress, sidebar width and layout, dismissed notices, and, during an Audit Room visit, the auditor email you entered (cleared when the browser tab closes).

Requests to others when our pages load:

| Who | When | What they receive | Why |
|---|---|---|---|
| Google LLC (Google Fonts) | Every page of polestargrc.com and partner portals | Your IP address, browser user agent and the font request; no page address, because our pages send no referrer | To deliver the Inter typeface |
| Stripe, Inc. | Only when you go to Stripe-hosted checkout or the billing portal | Whatever you enter on Stripe's pages and Stripe's own cookies | Payment processing and fraud prevention under Stripe's privacy policy |

We do not use advertising cookies, social media pixels or cross-site trackers, and we do not allow third parties to collect personal information about your online activities over time and across other websites through our Service. Blocking app_session_id will prevent sign-in.

Do Not Track and Global Privacy Control. Because we do not sell or share personal information or engage in cross-site tracking, our handling does not change in response to a Do Not Track signal. We treat a Global Privacy Control signal as a valid request to opt out of sale and sharing for the browser that sends it and any account signed in from it; because we do no selling or sharing, the opt-out is already in effect for every visitor. You can confirm the status of any opt-out request by emailing privacy@polestargrc.com.

## 9. How we disclose information

We disclose personal information only:

1. To Subprocessors that process it on our behalf under written contracts that limit their use to our instructions and require confidentiality and security, and, where PHI could be involved, a business associate agreement (Section 10).
2. At your direction, to people and systems you choose: external auditors through Audit Rooms, the partner that manages your workspace (Section 16), Slack channels you connect, GitHub repositories you connect (we post findings as pull request comments if you enable that), and recipients of reports and packages you export.
3. To our professional advisers (lawyers, accountants, insurers, auditors) under confidentiality obligations.
4. To comply with law, regulation, legal process or an enforceable government request; to enforce our agreements; or to protect the rights, safety or property of our customers, users, the public or us. For Customer Data, the BAA or DPA controls: where the law permits, we tell the affected customer first so it can object, and we disclose only what the demand requires.
5. In a merger, acquisition, financing, reorganization or sale of assets, to the successor or prospective successor under confidentiality obligations at least as protective as this Policy, with notice to customers before their data becomes subject to a different privacy policy. Any successor remains bound by the BAA and DPA.

We do not disclose personal information to data brokers or advertisers.

## 10. Subprocessors

The table lists the companies that process personal information or Customer Data for us as of the version date. We keep this list and a change log current on this page. We give each workspace's Notice Contacts (as defined in the Terms of Service) at least 30 days' notice by email and in-product notice before a new Subprocessor processes Customer Data, with the right to object described in the Terms of Service and the DPA.

| Subprocessor | Service | Location | Data | PHI possible | Business associate agreement |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. | Hosting (EC2), database, S3 file storage, backups, KMS, Bedrock AI | United States (us-east-1; Bedrock may process in other US Regions, Section 5) | All Service data | Yes | Yes, AWS Business Associate Addendum |
| Twilio Inc. (SendGrid) | Email delivery | United States | Recipient names and email addresses, and short messages that say an item is waiting (an invitation, reminder, notice or reply) with a link into the Service. Emails do not carry text that customers or their users typed. | No, by design. The content stays in the Service behind sign-in. | No. None is needed, because SendGrid receives no PHI by design. Twilio does not offer a business associate agreement for SendGrid. |
| Twilio Inc. | SMS delivery for verification codes and opted-in alerts | United States | Phone numbers, one-time codes and short alert text | No, by design. SMS alerts say only that an item is waiting. | No. None is needed, because SMS messages contain no PHI by design. |
| Stripe, Inc. | Payment processing, invoicing, billing portal | United States | Billing contact name and email, billing details and payment method (held by Stripe) | No | Not required (payment processing) |
| Google LLC (Google Fonts) | Font delivery (Section 8) | United States and other countries where Google operates | IP address and browser user agent of page visitors | No | Not applicable |
| Google LLC (Google Workspace) | Email for our support, billing, privacy, security, legal and abuse mailboxes | United States and other countries where Google operates | Messages and attachments people send to those mailboxes | Possible, if a customer emails it despite our instructions | Not yet. We have not accepted Google's business associate amendment for Google Workspace. Until we do, we do not ask anyone to email PHI or Protected Data to us, the BAA (Section 2.11) and the Acceptable Use Policy (Section 4) tell customers not to, and PHI that reaches a mailbox anyway is moved into the customer's workspace or deleted once the issue is resolved. |

Model developer. Anthropic, PBC develops the Claude models we use through Amazon Bedrock. Anthropic does not receive or have access to our prompts or outputs, so it is not a Subprocessor.

Change log:

- October 9, 2026 (Version 3.1): Google LLC (Google Workspace) is added. Google Workspace hosts the mailboxes that receive the email people send to our support, billing, privacy, security, legal and abuse addresses, and it should have been listed before. Its row states that we have not yet accepted Google's business associate amendment and how we keep PHI out of those mailboxes until we do. We give each workspace's Notice Contacts notice of this addition by email and in-product notice under Section 9.6 of the Terms of Service and Section 5.2 of the DPA, with the right to object described there. When we accept Google's business associate amendment we will update the row and give the 30 days' notice that Section 4.2 of the BAA and of the Subcontractor BAA require before Google Workspace may receive PHI under it. The existing Google LLC row is relabeled Google LLC (Google Fonts).
- October 8, 2026 (Version 3.0): Anthropic, PBC is no longer listed as a Subprocessor, because it has no access to prompts or outputs sent through Amazon Bedrock. Sentry, PostHog and Umami are no longer listed, because none of them is enabled in production. Google LLC is added for font delivery. The Twilio SendGrid and Twilio rows now state that emails and SMS messages carry no PHI by design and that we have no business associate agreement with Twilio.
- October 1, 2026 (Version 2.0): list published.

Third parties you connect are not our Subprocessors; they act under your own agreements with them: GitHub, Inc. (code scanning through the Polestar GitHub App), Amazon Web Services, Microsoft Azure and Datadog (evidence connectors using your accounts), container registries, your email provider and Slack Technologies (alerts). A partner that manages your workspace is your service provider, not ours (Section 16).

## 11. Why we process (legal bases)

We are a US company serving US organizations. Where a law asks for a basis for processing, ours are: performance of our contract with you (providing the Service, billing, support); our legitimate interests in securing the Service, preventing abuse, improving the product and communicating with customers, balanced against your interests; your consent where we ask for it (SMS alerts, optional product emails); and compliance with legal obligations (tax, accounting, HIPAA documentation retention, responding to lawful requests). For PHI and DPA-protected data, those agreements and the law define what we may do.

## 12. How long we keep information

| Information | Retention |
|---|---|
| Account and workspace data | For the life of the workspace, then deleted on the schedule below |
| Customer Data (assessments, policies, evidence, records, assistant conversations, scan results) | Until you delete it or the workspace is deleted. After a subscription ends you have a 30-day read-only Export Window; deletion from production then completes within 30 days. A workspace whose free trial ends without a paid subscription is deleted from production no later than 60 days after the trial ends. You can request deletion at any time from the Data Deletion page (30-day period during which an owner can cancel). |
| Support tickets, including tickets the assistant files | For the life of the workspace, then deleted with it |
| Connected-system credentials | Until you disconnect the integration or the workspace is deleted |
| Audit log entries | Six years from creation, then purged automatically. We keep them that long so we and our customers can document Security Rule activity for the six years HIPAA requires for documentation (45 CFR 164.316(b)(2)(i)). |
| Terms and platform agreement acceptance records | Six years after the workspace is deleted, as legal records |
| Billing and tax records | Seven years |
| Nonprofit discount applications (the legal name, EIN and IRS letter you submit, and the result of the check) | While your workspace exists. The letter and the application are deleted when the workspace is deleted. The audit log entries recording each application and its outcome are kept for six years like other audit log entries, and the discounted charges are part of the billing records kept for seven years. |
| Email and SMS delivery logs | Deleted with the workspace |
| Email and SMS opt-out records | Kept so we can honor the opt-out |
| Expired invitations | Purged 90 days after they expire |
| Export download links | Purged 7 days after they expire |
| Backups | Encrypted backups rotate and are purged within 90 days after a workspace's Export Window ends, so a deleted record can remain in an encrypted backup for up to 90 days. Backups are not accessible through the Service and are restored only for disaster recovery. |
| Contact form submissions and support email | Reviewed and deleted annually, unless part of an open matter |
| Server and security logs that are not audit log entries | Up to 90 days |

When a workspace is deleted we delete tenant data, remove evidence files from storage, and anonymize the accounts of users who belong to no other workspace. A placeholder workspace record remains only so retained audit log entries stay consistent until they are purged.

## 13. How we protect information

We maintain administrative, physical and technical safeguards appropriate to the sensitivity of the data, including: encryption in transit (TLS 1.2 or higher) and at rest (AES-256); organization-scoped access controls on every API procedure; role-based permissions for customers and our own staff; multi-factor authentication with workspace-wide enforcement available; bcrypt password hashing; session limits of 12 hours absolute and 30 minutes idle by default; brute-force lockouts and rate limiting; security event and audit logging; time-limited signed links for files; encrypted daily backups stored off the server, which we test by restoring a full copy at least once a year and after any change to the backup process (most recently on October 8, 2026); application secrets kept in a file on the production server that only the deployment account and the server administrator can read, and never in source control; least-privilege cross-account roles for cloud connectors; automated identifier redaction on AI text requests (Section 5); and signature verification on inbound webhooks. Our staff access customer workspaces only for support, security or legal reasons, and that access is logged. No method of transmission or storage is completely secure. If a security incident affects your data we will notify the workspace owner without unreasonable delay and within the time set by the Terms of Service and by the BAA, Subcontractor BAA or DPA that applies to you, and we will meet the notification requirements of that agreement and of applicable law.

## 14. Your rights and choices

These tools and rights are available to everyone we hold information about, wherever you live.

Access and portability. Workspace administrators can export the organization's data from the Data Export page, build evidence packages, export audit logs and download reports. Any user can request a copy of their own personal data by emailing privacy@polestargrc.com.

Correction. Update your name, email and preferences in account settings and organization details in workspace settings. For anything you cannot change yourself, email us.

Deletion. Workspace owners can delete the workspace from the Data Deletion page (30-day cancellable period). Individuals can ask us to delete their account by emailing privacy@polestargrc.com; if you belong to a customer's workspace we will coordinate with that customer, and some records (audit logs, legal acceptance records, billing records) are kept for the periods in Section 12 for the reasons given in Section 12.

Marketing and product emails. Every non-essential email we send identifies us, includes our postal address and an unsubscribe link, and supports one-click unsubscribe in mail clients. You can also manage categories on the Email Preferences page. We honor opt-outs within 10 business days and usually immediately. We will still send security, legal, billing and account notices that are necessary to run the Service.

SMS. SMS alerts are off by default and require you to verify your number. Turn them off on the Email Preferences page or reply STOP to any message. Message and data rates may apply.

Opt-out of sale, sharing and targeted advertising. We do not sell or share personal information or use it for targeted advertising or profiling, so there is nothing to opt out of; we honor Global Privacy Control signals in any case (Section 8).

How to make a request. Email privacy@polestargrc.com, or write to the address in Section 21. Because we operate exclusively online and have a direct relationship with our users, email is our primary request method. We confirm receipt within 10 business days and respond within 45 calendar days; if we need up to 45 more days we will tell you why within the first 45.

Verification and authorized agents. We verify requests by matching them to the email address on the account, by sending a confirmation link, or by asking for information only the account holder would know. You may use an authorized agent; we will ask for proof of authorization and may confirm the request directly with you.

Appeals. If we decline a request, we will tell you why and how to appeal. Send appeals to privacy@polestargrc.com with "Appeal" in the subject. We respond within 45 days. If you are not satisfied you may contact your state attorney general.

No discrimination. We will not deny service, charge different prices or provide a different level of service because you exercised a privacy right.

## 15. State-specific disclosures

### 15.1 Comprehensive state privacy laws

Most US states with comprehensive privacy laws apply only above size thresholds; all exempt PHI handled under HIPAA, several also exempt HIPAA covered entities and business associates as organizations, and all except California exclude information about people acting in an employment or business-to-business capacity, which describes nearly all of the personal information we hold as a business. As of the version date we are below the thresholds that would make us a "business" under the California Consumer Privacy Act or a "controller" under the other states' laws listed below. We describe them because our customers need to know how we fit into their own compliance, and because we honor the rights they create for every US resident anyway (Section 14). Thresholds are our understanding as of the version date.

California (California Consumer Privacy Act, as amended by the California Privacy Rights Act, Cal. Civ. Code 1798.100 et seq., and its regulations at Cal. Code Regs. tit. 11, 7000 et seq.). Applies to for-profit businesses with more than USD 26,625,000 in annual gross revenue (the 2025 adjusted figure), or that buy, sell or share the personal information of 100,000 or more consumers or households, or that derive 50% or more of annual revenue from selling or sharing personal information.

For California residents, in the preceding 12 months:

| Category (Civ. Code 1798.140(v)) | Examples | Source | Purposes (Section 4) | Disclosed for a business purpose to |
|---|---|---|---|---|
| Identifiers | Name, email, IP address, account ID | You; your organization; partners | Account, security, support, billing, service messages | AWS, Twilio SendGrid, Twilio (SMS), Stripe, Google Workspace (email you send us), Google Fonts (IP only) |
| Customer records (Civ. Code 1798.80(e)) | Name, phone, billing details | You; Stripe | Billing, service messages | AWS, Stripe, Twilio |
| Commercial information | Plan, invoices, subscription history | You; Stripe | Billing, renewals | AWS, Stripe |
| Internet or network activity | Log, usage and audit events | Automatically | Security, audit trail, product improvement | AWS |
| Geolocation | Approximate location derived from IP address only | Automatically | Security | AWS |
| Professional or employment information | Job title, organization, compliance roles | You; your organization | Providing the Service | AWS, Twilio SendGrid |
| Sensitive personal information | Account log-in with password or MFA credentials | You | Authentication and security only | AWS |
| Inferences | Product usage patterns | Derived from usage | Product improvement | None |

We did not sell or share personal information and have no actual knowledge of selling or sharing the personal information of anyone under 16. We use sensitive personal information only to provide the Service and secure accounts, which are purposes for which no right to limit is required (Cal. Code Regs. tit. 11, 7027(m)); we therefore do not offer a separate right to limit. We retain each category as described in Section 12. California residents have the rights to know, access, delete and correct personal information, to opt out of sale or sharing, and not to be retaliated against for exercising these rights. California "Shine the Light" (Civ. Code 1798.83): we do not disclose personal information to third parties for their direct marketing purposes. Our customer contracts contain the service provider terms required by Civ. Code 1798.100(d) and 1798.140(ag) (Terms of Service Section 9 and DPA Section 2).

Other comprehensive state laws. Virginia (Va. Code 59.1-575 et seq.), Colorado (C.R.S. 6-1-1301 et seq.), Connecticut (Conn. Gen. Stat. 42-515 et seq., as amended by Public Act 25-113 effective July 1, 2026, which lowers the general threshold to 35,000 consumers and removes the threshold for controllers of sensitive data), Utah (Utah Code 13-61-101 et seq.), Texas (Tex. Bus. and Com. Code ch. 541), Oregon (ORS 646A.570 et seq.), Montana (Mont. Code 30-14-2801 et seq.), Delaware (6 Del. C. ch. 12D), Iowa (Iowa Code ch. 715D), Nebraska (Neb. Rev. Stat. 87-1101 et seq.), New Hampshire (RSA ch. 507-H), New Jersey (N.J.S.A. 56:8-166.4 et seq.), Tennessee (Tenn. Code 47-18-3201 et seq.), Minnesota (Minn. Stat. 325M.10 to 325M.21), Maryland (Md. Code Com. Law 14-4601 et seq.), Indiana (Ind. Code 24-15), Kentucky (KRS 367.3611 et seq.) and Rhode Island (R.I. Gen. Laws 6-48.1). Residents of these states have rights to access, correct, delete and obtain a copy of their personal data, to opt out of targeted advertising, sale and significant profiling, and to appeal, which we honor as described in Section 14. Oregon residents may ask for the list of specific third parties that received their data; our list is Section 10. Texas's medical records privacy law (Tex. Health and Safety Code ch. 181) applies HIPAA-like duties to anyone who handles PHI in Texas; we meet them through the BAA.

### 15.2 Consumer health data laws

Washington (My Health My Data Act, RCW 19.373), Nevada (NRS 603A.400 to 603A.550) and Connecticut (Conn. Gen. Stat. 42-526) regulate consumer health data that is not protected health information under HIPAA (in Washington, RCW 19.373.100(1)(a)(i)). Washington and Nevada have no size thresholds, and Connecticut's consumer health data rules apply to any person doing business in the state that is not exempt under Conn. Gen. Stat. 42-526(b).

Our own data. These laws protect people acting in a personal or household capacity, not people acting in an employment context (RCW 19.373.010; NRS 603A.425; Conn. Gen. Stat. 42-515). The information we collect as a business is about our customers' staff and contacts acting in their work roles, so we do not collect consumer health data for our own purposes and we do not operate as a regulated entity under these laws.

Our customers' data. When a customer that is not regulated by HIPAA stores consumer health data in its workspace, we are that customer's processor. We process it only under the binding contract these laws require (the DPA, which sets out our processing instructions under RCW 19.373.060, NRS 603A.530 and Conn. Gen. Stat. 42-521), we restrict access to people who need it, we never sell it, and we do not use geofencing. The customer is responsible for its own consumer health data privacy policy and consents. If you send us a request about that data we will forward it to the customer within five business days.

### 15.3 Nevada website operators

Nevada residents may submit a verified request directing us not to sell covered information we have collected about them (NRS 603A.345). We do not sell covered information, but you may send a request to privacy@polestargrc.com and we will confirm it within 60 days. To review or ask us to correct the covered information we hold, use the tools and contacts in Section 14. We notify users of material changes as described in Section 19.

### 15.4 California website operators

This Policy is posted for the purposes of the California Online Privacy Protection Act (Cal. Bus. and Prof. Code 22575 to 22579). Our Do Not Track statement is in Section 8. We do not permit third parties to collect personally identifiable information about your online activities over time and across different websites when you use the Service.

## 16. Partners and white-label portals

Some customers may reach us through a managed service provider or other partner that has a Partner Agreement with us. Partner features are available only under a Partner Agreement, and as of the version date they are switched off for every organization. When they are on, a partner can brand a portal on a polestargrc.com subdomain and can create and manage client workspaces, and the Partner Agreement decides whether the partner or the client pays us. The rest of this Section describes partner features when they are on.

When a partner creates your workspace, the partner gives us your organization's name, type, state, compliance mode (HIPAA or state), HIPAA role and the administrator email we invite, and the partner's user is recorded as the workspace's provisioning owner until ownership is transferred to you. The partner can see your workspace's invitation emails and status, member count, assessment progress, published policy count and training completion, and it can resend invitations and end its management of your workspace. The partner can see Customer Data inside your workspace only if your organization gives its users access.

The partner is your service provider, not ours. Your contract with the partner governs what it does with your information. We process your workspace data under our Terms and the platform agreement your organization accepts, and the partner cannot change those terms. If the partner chose the wrong compliance mode or HIPAA role for your organization, change it in workspace settings and accept the correct agreement before you store regulated data. A partner cannot accept a platform agreement for your organization; your own administrator must accept it in the Service.

If an IT provider or consultant referred you to us without being a partner, it is not our partner or agent. You sign up and accept your agreements yourself, and the referrer has no access to your workspace unless you invite its staff.

## 17. People whose information is in a customer's workspace

If you are an employee, contractor or auditor invited to a customer's workspace, the customer controls your information. We process it to give you access, to send the training, policy and reminder emails the customer configures, and to keep the audit trail the customer needs. You can unsubscribe from non-essential emails and ask the customer to remove you.

If you are a client or patient of one of our customers, we do not have a relationship with you, we do not know whether your information is in a customer's workspace, and we cannot act on it without the customer's instruction. Please contact that organization. It can use the Service's export, correction and deletion tools, and we will assist it as the BAA, DPA or Terms require.

## 18. Children and international users

The Service is for organizations and their adult staff. We do not direct it to children and do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact privacy@polestargrc.com and we will delete it. Health information about minors stored by a customer is PHI or DPA-protected data processed only under the BAA or DPA.

We process and store data only in the United States, and we market the Service only to US organizations. Partners may not provision workspaces for organizations outside the United States without our written agreement. If you are in the European Economic Area, the United Kingdom, Switzerland or another jurisdiction with data transfer rules, contact privacy@polestargrc.com before onboarding so we can decide whether we can put the required transfer terms in place.

## 19. Changes to this Policy

We post updated versions on this page with a new version number and effective date. For material changes we notify each workspace's Notice Contacts (as defined in the Terms of Service) by email and in-product notice at least 30 days before the change takes effect. We will not use personal information we already hold in a materially different way without your consent where the law requires it. Prior versions are archived at polestargrc.com/legal/archive.

## 20. Accessibility

This Policy is available as a web page and as a downloadable file at polestargrc.com/legal/privacy-policy.md. If you need it in another format, contact privacy@polestargrc.com.

## 21. Contact

Privacy questions, requests and appeals: privacy@polestargrc.com

Security issues: security@polestargrc.com

Mail: Polestar GRC, Attn: Privacy, 434 Kern St, Taft, CA 93268, United States

---

Earlier versions of this Privacy Policy: [Version 3.0, effective October 8, 2026](https://polestargrc.com/legal/archive/privacy-policy-v3.0) and [Version 2.0, effective October 1, 2026](https://polestargrc.com/legal/archive/privacy-policy-v2.0). Every version of our legal documents is listed at [polestargrc.com/legal/archive](https://polestargrc.com/legal/archive).
