Pre-launch preview, Polestar GRC is not live yet. Signups, billing, and email are not operational.
Skip to main content

Polestar GRC Terms of Service

Version: 3.1, effective October 9, 2026

Published October 9, 2026. Replaces Version 3.0, effective October 8, 2026. Version 3.1 changes the provider: the Polestar GRC business was assigned to Jonathan Prine, an individual doing business as Polestar GRC, who signs these Terms as Owner. Version 3.1 also replaces the assignment terms in Section 25.2, which now allow one further assignment, to an LLC of which Jonathan Prine is the sole member, only after at least 30 days' notice and that company's signed assumption, with a right for you to terminate before it takes effect; changes nonprofit pricing in Section 5.13: 50% off every plan, applied for by uploading an IRS letter after creating an account, checked automatically with human review when the check is not conclusive; states in Section 5.6(a) that the 30-day annual refund is given when you ask for it within those 30 days, and lists the new refund rights in Section 5.6(c); adds Section 9.12 on the data we process and for how long; lists Google Workspace among our Subprocessors (Section 12.1); corrects the audit log retention statement in Section 18.5; and states our safeguards as they are today (Sections 7.4, 10.3, 12.1 and 15.1): backups are tested by a full restore at least once a year and after any change to the backup process rather than quarterly, application secrets are kept in an access-restricted file on our production server rather than in a secrets manager, and AI redaction applies to text, while PDF files and images that AI Features analyze are sent as uploaded. For a new customer this version applies from acceptance on or after October 9, 2026. For a customer that accepted an earlier version, Version 3.0 takes effect on November 7, 2026, as our notice of October 8, 2026 stated. The change of provider takes effect by assignment, under Section 25.2 of the version that customer accepted or with that customer's written consent, on the date stated in our notice of assignment. The assignment right added to Section 25.2 applies to that customer only after an administrator accepts this version, and the other changes in this version apply to that customer only after that acceptance too (Section 24.4). Every earlier version is archived at polestargrc.com/legal/archive.

These Terms of Service (the "Terms") are a binding agreement between Jonathan Prine, an individual doing business as Polestar GRC, with his principal place of business at 434 Kern St, Taft, CA 93268 ("Polestar GRC", "we", "us", "our"), and the organization that registers for or uses the Polestar GRC platform ("Customer", "you", "your").

Plain-English summary

This summary is for convenience and is not part of the agreement. The numbered sections control.

  • Polestar GRC is a HIPAA and state privacy compliance documentation tool for organizations. It is not legal advice, it does not make you compliant by itself, and it does not certify anyone.
  • Business use only. Users must be 18 or older, and the person who accepts for an organization must have authority to bind it.
  • A new workspace gets a 14-day free trial with no card. A paid subscription started at checkout also starts with a 14-day trial that needs a card and converts to a paid plan automatically unless you cancel first. This applies to your first subscription, to a move from a complimentary or beta plan, and to a returning customer's new subscription, with at most one checkout trial per organization in any 12 months.
  • Paid plans renew automatically every month or every year until you cancel. You can cancel online in one step from the Subscription page. You keep access to the end of the period you paid for.
  • Payments are not refunded for unused time, with the exceptions in Section 5.6. If you cancel an annual plan within 30 days after an annual charge, we refund that charge less one month at the plan's list monthly price (with your nonprofit discount, if you have one), once per organization in any 12 months.
  • Verified 501(c)(3) nonprofits get 50% off every plan. You apply after creating your account by uploading your IRS letter, and you pay the full price until the application is approved (Section 5.13).
  • If we raise the price of your plan, you keep your current price for 12 months. After that we tell you 7 to 30 days before a monthly price changes, and an annual plan changes only at renewal, as stated in the renewal reminder.
  • Partner features (for an IT provider or consultant that manages client workspaces) are available only under a Partner Agreement with us, and you always accept your own agreements with us. Section 26 applies.
  • You own your data. We use it only to run the Service for you. PHI is governed by the Business Associate Agreement (or the Subcontractor Business Associate Agreement), and state-mode data by the Data Protection Agreement. In HIPAA mode the Service does not accept new file uploads or incident details until your administrator accepts the agreement.
  • AI features can be wrong. A qualified person must review AI output before you rely on it. The in-app assistant is an automated AI tool, not a person.
  • When a subscription ends you have 30 days to export your data in read-only mode, then we delete it. A free trial workspace that never becomes a paid subscription is deleted 60 days after the trial ends. Audit log entries are kept six years.
  • Our liability is capped, with a separate cap for PHI claims in the BAA. Disputes go to informal resolution first, then to the courts of Kern County, California, or small claims court. There is no arbitration, and the arbitration clause in Version 2.0 is withdrawn for everyone.
  • We tell you 30 days before a material change to these Terms. Changes to the dispute, liability, fee or data terms need your acceptance.

1. Agreement, acceptance and order of precedence

1.1 Acceptance. You accept these Terms by checking the acceptance box when you create an account or a workspace, when you accept a new version of these Terms in the Service, or when you start a paid subscription. If you accept on behalf of an organization, you represent that you have authority to bind that organization, and "Customer" means that organization. An Authorized User who joins a workspace by invitation accepts these Terms and the AUP for that user's own use of the Service; the organization is bound through the administrator who accepted for it. If you do not have authority or do not agree, do not use the Service.

1.2 Electronic records. You consent to contracting electronically and to receiving notices, disclosures, invoices and records electronically at the email addresses of your Notice Contacts, consistent with the federal ESIGN Act (15 U.S.C. 7001 et seq.) and the California Uniform Electronic Transactions Act (Cal. Civ. Code 1633.1 et seq.). You may withdraw this consent by closing your account. For each acceptance we record the document, its version and SHA-256 fingerprint, the person who accepted and, where there is one, the workspace they accepted in, the date and time, the network address and the browser. You can request your acceptance records from legal@polestargrc.com.

1.3 Documents that make up the agreement. The agreement between you and us consists of, in this order of precedence if they conflict: (a) the Platform Agreement that applies to you (the Business Associate Agreement, the Subcontractor Business Associate Agreement or the Data Protection Agreement, each defined in Section 2), for the data it covers; (b) any order form or other document signed by both parties, and any Partner Agreement signed or accepted electronically with a recorded acceptance; (c) these Terms, including the automatic renewal terms shown to you and recorded with your consent when you started or changed a paid plan, which form part of Section 5 and control over Section 5 where they are more favorable to you; (d) the Acceptable Use Policy ("AUP") at polestargrc.com/legal/acceptable-use-policy; and (e) the Privacy Policy at polestargrc.com/legal/privacy-policy. The AUP and Privacy Policy are incorporated by reference.

1.4 Language. These Terms are written in English. The Service may display interface text in other languages; the English versions of these Terms, the AUP, the Privacy Policy and each Platform Agreement control.

2. Definitions

"AI Features" means features of the Service that send content to a large language model and return generated text, including policy drafting, assessment answer suggestions, document and evidence analysis, remediation suggestions, audit narratives and the in-app assistant. "AI Output" means the text an AI Feature returns.

"Authorized User" means an individual you or your Partner invites to your workspace, including your workforce members, contractors and consultants.

"BAA" means our Business Associate Agreement at polestargrc.com/legal/hipaa-baa, for customers that are HIPAA covered entities.

"Checkout Trial" means the free trial period at the start of a paid subscription described in Section 5.3.

"Client Workspace" means a workspace a Partner creates for one of its clients under Section 26. "Sandbox Workspace" means a Client Workspace a Partner creates for its own training and demonstration, labeled "Sandbox (no PHI)".

"Customer Data" means all data, files and content that you or your Authorized Users submit to or generate in the Service, including assessment answers, policies, evidence files, vendor and BAA records, training records, incident records, security scan results, chat messages, connected-account data and reports. Customer Data includes PHI where PHI is present.

"Documentation" means our published help content and the descriptions of the Service on polestargrc.com.

"DPA" means our Data Protection Agreement at polestargrc.com/legal/dpa-state-mode, for customers that are not HIPAA covered entities or business associates and that store sensitive personal or health information in the Service.

"Export Window" is defined in Section 18.3.

"Fees" means the amounts payable for the Service under Section 5 or, for Client Workspaces, under Section 26.

"Notice Contacts" means the workspace owner and the billing, Privacy Officer and Security Officer contacts recorded in your organization settings.

"Partner" means a consultant, managed service provider or other organization that has entered into a Partner Agreement with us and that we have enabled as a partner to provision and manage Client Workspaces under Section 26.

"Partner Agreement" means a separate agreement between us and a Partner, signed or accepted electronically with a recorded acceptance, that sets the commercial terms of the partner relationship.

"PHI" means Protected Health Information as defined at 45 CFR 160.103.

"Platform Agreement" means whichever of the BAA, the Subcontractor BAA or the DPA applies to your organization. References in these Terms to "the BAA" include the Subcontractor BAA where you are a business associate.

"Professional Services" means consulting, named compliance officer, advisory and audit-response services described in Section 6.

"Security Incident" means an unauthorized access to, or acquisition, disclosure, loss or destruction of, Customer Data in our possession that we know of or reasonably believe has occurred. It does not include unsuccessful attempts such as port scans, blocked malware or failed logins.

"Service" means the Polestar GRC platform, including its web application, AI Features, integrations, exports, Audit Rooms, white-label portals and related support.

"Subcontractor BAA" means our Subcontractor Business Associate Agreement at polestargrc.com/legal/hipaa-subcontractor-baa, for customers that are HIPAA business associates, under which we act as their subcontractor.

"Subprocessor" means a third party we engage to process Customer Data on our behalf.

"Workspace" means an organization account in the Service. "Workspace Trial" means the free trial described in Section 5.2.

3. Eligibility, accounts and Authorized Users

3.1 Business use only. The Service is offered to organizations and their Authorized Users for business purposes. It is not offered to consumers for personal, family or household use. We nevertheless apply the automatic renewal protections in Section 5 to every customer, including sole proprietors and nonprofit organizations.

3.2 Age. Every Authorized User must be at least 18 years old. We do not knowingly allow anyone under 18 to use the Service.

3.3 Account information. You must provide accurate registration and billing information and keep it current, including your Notice Contacts. We rely on the Notice Contacts for notices under these Terms.

3.4 Credentials and security. You are responsible for all activity under your workspace and your Authorized Users' accounts. Keep credentials confidential, do not share accounts, and tell us promptly at security@polestargrc.com if you suspect unauthorized access. Multi-factor authentication is available and your administrators can require it for your whole workspace; we recommend doing so.

3.5 Authorized Users. You are responsible for your Authorized Users' compliance with these Terms and the AUP, for the lawfulness of inviting them and of the information you provide about them, and for removing access when they leave. We send Authorized Users service emails on your behalf (invitations, reminders, training, policy acknowledgments, security alerts).

3.6 Workspaces created by a Partner. If a Partner created your workspace, Section 26 applies. In short: the Partner may see aggregate compliance metrics for your workspace but has no standing access to your data unless your administrator invites its staff; the Partner Agreement decides whether you or the Partner pays us for your workspace; you, not the Partner, accept your Platform Agreement; and you and the Partner are each responsible for your own obligations to us.

3.7 Our staff access. Our support and engineering staff may access your workspace to provide support, investigate security or abuse, or as required by law. Such access is limited to what is needed, is logged, and is subject to our confidentiality obligations and, for PHI, the BAA.

3.8 Multiple workspaces. One organization may hold more than one workspace, and one person may belong to several workspaces. Each workspace is a separate account with its own plan, Fees, Platform Agreement, data and Export Window, unless a signed order form groups them. The Workspace Trial is offered once per organization, and the Checkout Trial is offered as Section 5.3 describes. Creating additional workspaces, or cancelling and resubscribing, in order to obtain repeated free trials is not permitted, and we may decline a trial or end one early where we reasonably believe it is being used that way.

3.9 Notice Contacts. You will keep at least one Notice Contact who is a member of your organization and can act on billing, privacy and security notices. Until a Partner-created workspace has its own administrator, Section 26.3 decides who receives notices.

4. The Service and what it is not

4.1 What the Service does. The Service helps organizations prepare, document and maintain a HIPAA security and privacy program or, for organizations that are not HIPAA covered entities or business associates, a program framed around applicable state privacy and security laws. Features include guided Security Risk Assessments, policy templates and policy generation, evidence collection and expiry tracking, vendor and BAA tracking, workforce training, incident response workflows, compliance scoring, audit packages and Audit Rooms, security scanning and cloud evidence connectors, and AI Features.

4.2 Not legal advice. The Service, its templates, question banks, state-law summaries, AI Output, scores and reports are information and tools, not legal advice, and no attorney-client relationship is created. We are not a law firm. Laws change and depend on facts about your organization that only you and your advisers know. You are responsible for reviewing outputs with qualified counsel or compliance professionals before relying on them.

4.3 No compliance guarantee. Using the Service does not make you compliant with HIPAA, the HITECH Act, 42 CFR Part 2, any state law or any other standard, and does not guarantee the outcome of any audit, investigation, customer review or certification. A compliance score, readiness percentage, badge or report produced by the Service measures what has been recorded in the Service against our question set; it is not a determination of compliance by us or by any regulator. Compliance depends on how you implement and operate your program. We do not certify or attest to your compliance, and you will not represent that we have.

4.4 Not a medical records system. The Service is designed to hold compliance documentation, not patient charts. Do not use the Service as an electronic health record, a designated record set or a system of record for treatment, payment or operations. Upload PHI only where a feature is designed for it (for example, evidence or incident records) and only to the extent reasonably necessary to document compliance.

4.5 Compliance mode. At onboarding you tell us whether you are a HIPAA covered entity, a business associate or neither. If you say neither, the Service frames your program around state law. You are responsible for the accuracy of that answer and for telling us if it changes.

4.6 Changes to the Service. We improve the Service continuously and may add, change or remove features. We will not materially reduce the core functionality of your plan during a paid term without at least 30 days' notice and the right to terminate and receive a refund under Section 24.3.

4.7 Beta features. Features marked beta, preview or early access are provided as-is, may change or be withdrawn, and are excluded from any service level target.

5. Plans, free trials, Fees, automatic renewal and cancellation

5.1 Plans and prices. Current plans are Essentials, Professional and Advanced. As of the version date of these Terms the list prices are: Essentials USD 120 per month or USD 1,200 per year; Professional USD 250 per month or USD 2,500 per year; Advanced USD 450 per month or USD 4,500 per year, plus any applicable tax. Features by plan are published at polestargrc.com/pricing, which controls for new purchases. Nonprofit pricing is in Section 5.13. Fees for Client Workspaces are set in Section 26. Professional Services pricing is set in an order.

5.2 Workspace Trial. Each new organization's first workspace receives a 14-day free trial starting when the workspace is created. No payment method is required, and you will not be charged when it ends. If the Workspace Trial ends without a paid subscription, the workspace enters read-only mode: you and your Authorized Users can still sign in, view and export your data, request deletion, manage security and notification settings, and contact support, but cannot make other changes until you choose a plan. If no paid subscription starts, the workspace is deleted 60 days after the Workspace Trial ends, as Section 18.7 explains. We may change or end trial offers for new workspaces at any time.

5.3 Checkout Trial. Each paid subscription your organization starts through our checkout includes a 14-day free trial of the plan you select. This includes your organization's first subscription, a subscription that follows a complimentary, beta or pilot plan under Section 5.14, and a new subscription by a returning organization whose earlier subscription has ended. Your organization receives at most one Checkout Trial in any 12 months: a subscription started within 12 months after your organization's last Checkout Trial began has no trial, is charged when you subscribe, and the checkout says so before you pay. You must provide a payment method to start it. AT THE END OF THE CHECKOUT TRIAL YOUR PAYMENT METHOD WILL BE CHARGED THE PLAN PRICE SHOWN AT CHECKOUT, PLUS ANY APPLICABLE TAX, AUTOMATICALLY, AND THE PLAN WILL THEN RENEW AUTOMATICALLY UNDER SECTION 5.4, UNLESS YOU CANCEL BEFORE THE TRIAL ENDS. Before you pay, the checkout shows the trial end date, the first charge date and amount, and how to cancel, and asks you to agree to those terms separately. You can cancel at any time before the trial ends from the Subscription page and you will not be charged. If you chose an annual plan, we email your billing Notice Contacts a reminder at least three days before the Checkout Trial ends, stating the date and amount of the first annual charge, the refund terms in Section 5.6 and how to cancel. If we ever offer a Checkout Trial longer than 14 days, we will send the same reminder for monthly plans.

5.4 Automatic renewal. PAID SUBSCRIPTIONS RENEW AUTOMATICALLY UNTIL YOU CANCEL. A monthly plan renews every month and an annual plan renews every year, on the same day of the month or year as your first charge. At each renewal we charge the payment method on file the price stated in the automatic renewal terms you agreed to, as changed by any price change made under Section 5.10, plus any applicable tax. By subscribing you consent to these recurring charges. The automatic renewal terms shown at checkout, which you agree to separately before you pay, state the refund terms in Section 5.6 in full. Our notices: (a) right after you subscribe, an email that confirms the plan, price, billing interval, any trial end date and first charge date, the refund terms in Section 5.6, and how to cancel; (b) for annual plans, a reminder between 30 and 40 days before each renewal stating the renewal date, the amount, any change in price under Section 5.10, the refund terms in Section 5.6, the deadline to cancel and how to cancel; (c) for monthly plans, a renewal notice before renewals and in any case at least once in every 12-month period, stating the plan, the amount and frequency of charges, the refund terms in Section 5.6 and how to cancel; and (d) a notice before any price change under Section 5.10. These notices are sent to your billing Notice Contacts as legal notices and are not affected by a marketing unsubscribe.

5.5 How to cancel. You may cancel at any time, online and in one step, with the Cancel subscription button on the Subscription page in your dashboard. You may also cancel through the billing portal link on that page, or by emailing billing@polestargrc.com from a Notice Contact's address; we process email cancellations the same business day we receive them and confirm them by email. Cancellation takes effect at the end of the current billing period (or, during a Checkout Trial, at the end of the trial); you keep access until then and you will not be charged again. We email a confirmation of every cancellation with the end date. After the period ends the workspace becomes read-only and Section 18 applies. We do not charge cancellation fees. Where a Partner pays for a Client Workspace, the Partner manages its plan while the workspace is attached; see Section 26.6.

5.6 Refunds. Fees are paid in advance for each billing period. PAYMENTS ALREADY MADE ARE NOT REFUNDED, INCLUDING FOR THE UNUSED PART OF A MONTHLY OR ANNUAL PERIOD, EXCEPT IN THE CASES LISTED BELOW.

(a) Annual plans, 30-day window. If you cancel an annual plan within 30 days after we charge you for a year (the first annual charge or a renewal charge) and ask for a refund under this Section 5.6(a) within those 30 days, we will refund that charge less one month at the plan's list monthly price, reduced by your nonprofit discount under Section 5.13 if you have one, together with the matching part of any tax. The subscription and your access end when we issue the refund, and Section 18 applies. This refund is available once per organization in any 12-month period. It does not apply to Professional Services, to a Client Workspace that a Partner pays for, or where we end your subscription for breach of these Terms or the AUP.

(b) Late or incomplete renewal reminder. If we did not send the annual renewal reminder described in Section 5.4(b) between 30 and 40 days before an annual renewal, or the reminder left out an item Section 5.4(b) requires, and you cancel and ask for a refund of that renewal charge, we will refund it in full, together with any tax on it.

(c) Refunds these Terms or a Platform Agreement provide: Sections 4.6, 9.6, 18.4, 19.2, 21.1, 24.3 and 25.2 of these Terms; Sections 4.2, 10.2 and 15.7 of the BAA; Sections 4.2, 9(c), 11.2 and 16.7 of the Subcontractor BAA; and Section 5.2 of the DPA.

(d) Refunds the law that applies to you requires, including after a price increase (Section 5.10).

(e) Refunds or credits we choose to give in our discretion.

In any other case, if you cancel in the middle of a period you keep access until the period ends rather than receiving a refund. We issue each refund under this Section to the original payment method within 10 business days after you ask for a refund that qualifies or, where no request is needed, after the event that requires it. Our Refund Policy at polestargrc.com/legal/refund-policy summarizes these rules; if it and this Section differ, this Section controls.

5.7 Plan changes. A plan change takes effect immediately, whether it is an upgrade, a downgrade or a change between monthly and annual billing. For an upgrade, the pro-rated difference for the rest of the current period is added to your next invoice. For a downgrade, the unused part of the higher plan is credited on your next invoice, and features of the higher plan end when the change is made. Your renewal date does not change. Before you confirm, the Change Plan page shows the new price, when it applies and the amount of the pro-rated charge or credit, and asks you to agree to the new automatic renewal terms.

5.8 Payment processing and failed payments. Payments are processed by Stripe, Inc. under the Stripe Services Agreement and Stripe's privacy policy. We do not store full card numbers. You authorize us and Stripe to charge your payment method for Fees and applicable taxes. If a payment fails, Stripe will retry it and we will email your billing Notice Contacts on the first, third and seventh days. If payment has not succeeded 14 days after the first failure, we will cancel the subscription, stop further charge attempts for that invoice, and email you; the workspace then becomes read-only and Section 18 applies. You remain responsible for Fees for any period of service you received before cancellation.

5.9 Taxes. Fees exclude sales, use, value added, goods and services and similar taxes. You are responsible for those taxes except taxes on our income. If we are required to collect tax we will add it to your invoice unless you give us a valid exemption certificate.

5.10 Price changes. We may change the list price of a plan. If we increase the price of a plan you already subscribe to:

(a) Price hold. You keep your current price for 12 months after the date the increase takes effect for new purchases.

(b) Monthly plans. After the 12-month hold, we will email your billing Notice Contacts no fewer than 7 and no more than 30 days before the first monthly charge at the new price.

(c) Annual plans. We do not change the price of an annual plan during a paid year. A new price applies only from a renewal date that falls after the 12-month hold ends, and we state it in the renewal reminder sent 30 to 40 days before that renewal (Section 5.4(b)).

Each notice states the current price, the new price, the date of the first charge at the new price, that the plan renews automatically, and how to cancel. If you do not agree, cancel before that charge and you will not be charged the new price; for an annual plan, Section 5.6(a) also applies after the renewal charge. Where the law that applies to you requires your affirmative consent to a higher price, or a right to cancel and receive a refund after the first higher charge, we will meet that requirement.

5.11 Promotions and discounts. Promotion codes and discounts are subject to the conditions stated when offered, apply only to the subscription and period stated, and may not be combined with each other or with nonprofit pricing unless we say so. When a promotional price ends, the regular price you agreed to at checkout applies, as stated in your automatic renewal terms.

5.12 Billing disputes. Tell us about any billing error within 60 days of the invoice date at billing@polestargrc.com. We will investigate in good faith and correct errors. This does not limit any right you have under law or under your card issuer's rules.

5.13 Nonprofit pricing. Organizations recognized by the IRS as exempt under section 501(c)(3) of the Internal Revenue Code may receive nonprofit pricing, which is 50% off the list price of every plan, monthly or annual. To apply, an owner or administrator of your workspace, after creating your account, enters your organization's legal name and EIN and uploads your IRS determination letter or IRS affirmation letter in the Service. We check each application right after the upload: an AI review of the letter and a lookup of the EIN in a public nonprofit registry. If that check confirms that the letter is an IRS letter for a 501(c)(3) organization and that the EIN, the 501(c)(3) status and the name match, the application is approved. If the check is not conclusive, a person on our staff reviews the application, usually within one business day, and approves or denies it; we do not deny an application without that review, and a denial states the reason and how to apply again. Until we approve the application, you are charged the full list price. After approval, the nonprofit price applies to your first charge if your subscription is still in its free trial, and otherwise from your next renewal. It is not applied retroactively: charges made before approval are not refunded or adjusted. We email the nonprofit price and the date it starts to your workspace's owners and administrators, and it then applies at each renewal under Section 5.4. You must tell us within 30 days if your exempt status is revoked or lapses. If your organization stops qualifying, we will give your billing Notice Contacts notice in the way Section 5.10(b) (monthly plans) or Section 5.10(c) (annual plans) describes, the regular price will apply only from your next renewal after that notice, and you may cancel before then. The 12-month hold in Section 5.10(a) does not apply to the end of a nonprofit discount. Nonprofit pricing does not apply to Client Workspaces that a Partner pays for.

5.14 Complimentary and pilot plans. We may provide a plan without charge or at a reduced price for a pilot, beta or other arrangement we confirm in writing. Such a plan has no automatic renewal charge unless you later start a paid subscription, ends on the date we state (or on 30 days' notice if none is stated), and is then treated as an ended subscription under Section 18. If you start a paid subscription through our checkout when it ends, Section 5.3 gives you a 14-day Checkout Trial unless your organization had one in the previous 12 months.

6. Professional Services

6.1 Scope. We may offer Professional Services such as consultation sessions, monthly advisory hours, named Security Officer or Privacy Officer support, and audit or incident response support. Professional Services are purchased through an order or statement of work that states scope, price and term, and are governed by these Terms unless the order says otherwise.

6.2 Nature of the services. Professional Services are compliance program support provided by compliance professionals. They are not legal advice, do not create an attorney-client relationship, and are not a substitute for your own counsel. Where we provide a named Security Officer or Privacy Officer, that person supports your program under your direction; your organization remains the covered entity or business associate responsible for its obligations, including the designation and ultimate accountability of its officers under 45 CFR 164.308(a)(2) and 164.530(a).

6.3 Fees for Professional Services. Fees are stated in the order. Hourly work is billed in quarter-hour increments. Travel, if any, is billed at cost with your prior approval. Professional Services fees are non-refundable once the work is performed.

7. Customer Data

7.1 Ownership. You own your Customer Data. We claim no ownership of it.

7.2 License to us. You grant us a non-exclusive, worldwide, royalty-free license to host, copy, process, transmit, display and create derivative works of Customer Data solely to provide, secure, support and improve the Service for you, to comply with law, and as you otherwise direct in writing. This license ends when your Customer Data is deleted under Section 18, except for copies we must keep under Section 18.5.

7.3 Your responsibilities. You are responsible for the accuracy and lawfulness of Customer Data, for having the rights and consents needed to submit it and to let us process it, and for complying with laws that apply to it. You will not submit PHI before the applicable Platform Agreement is in effect (Section 8), and you will submit only the minimum PHI reasonably necessary.

7.4 Connected accounts and integrations. Some features let you connect third-party systems (for example a GitHub installation, an AWS account through a cross-account role, Azure, Datadog, a container registry, an email provider or a Slack webhook). You authorize us to access those systems with the credentials and permissions you provide, solely to deliver the feature you enabled. Grant the least privilege the Documentation describes (read-only wherever possible). You are responsible for the security of the credentials you give us, for your agreements with those third parties, and for revoking access when you no longer want the feature. We store credentials in our database on encrypted storage, encrypt the settings of the AWS CloudTrail, Azure activity log and Datadog log connectors, including their keys and secrets, a second time with our own application key, and delete credentials when you disconnect the integration or your workspace is deleted.

7.5 Security scanning. If you use scanning features (code, dependency, secret, infrastructure, container, cloud posture or dynamic web scanning), you represent that you own or are authorized in writing to test every repository, account and host you add, and you accept that active scanning can generate load, alerts or log entries on your systems. You must complete our ownership verification for web targets. Scan results, including any credentials or secrets our scanners detect in your systems, are Customer Data and are visible to your administrators; treat them as sensitive.

7.6 Sharing you direct. Audit Rooms, partner portals, exported packages, Slack alerts and similar features share Customer Data with people you choose. Sharing is at your direction and risk. External auditors who use an Audit Room link are not our users; we log their access, expire links on the schedule you set, and let you revoke links at any time.

7.7 Usage data and de-identified data. We may collect and use data about how the Service is used (feature usage, performance, error and security telemetry) to operate, secure, support and improve the Service and to produce aggregate statistics. We may use Customer Data that is not PHI to create de-identified or aggregated data that cannot reasonably identify you, your Authorized Users or any individual, and we may use and retain that data for any lawful purpose. We will maintain technical and organizational measures to keep that data de-identified, will not attempt to re-identify it, and will contractually prohibit anyone we share it with from re-identifying it. We will de-identify PHI only as your Platform Agreement permits and only under 45 CFR 164.514(a) to (c). We do not use Customer Data or PHI to train AI models, and we contractually require our AI providers not to do so.

7.8 Feedback. If you give us suggestions or feedback, we may use them without obligation to you. Feedback does not include Customer Data.

8. Protected Health Information and the Platform Agreements

8.1 Which agreement applies. During onboarding and in the BAA Tracker you tell us whether your organization is a HIPAA covered entity (health care provider, health plan or clearinghouse), a HIPAA business associate or subcontractor, or neither. Covered entities accept the BAA; business associates accept the Subcontractor BAA; organizations outside HIPAA that store sensitive personal or health information accept the DPA. A Partner accepts the Subcontractor BAA for its own workspace; a client in a Client Workspace accepts its own Platform Agreement under Section 26.4. You are responsible for choosing correctly and for telling us if your status changes.

8.2 The Platform Agreement controls. Your Platform Agreement governs the data it covers (PHI under the BAA or Subcontractor BAA; Protected Data under the DPA) and controls over these Terms for that data in the event of conflict. Each Platform Agreement sets its own terms for permitted uses, safeguards, incident reporting, subprocessors, individual rights, return and destruction, liability for the data it covers, and execution.

8.3 Accepting a Platform Agreement. You accept the applicable Platform Agreement electronically in the Service, and only there. The signer must be an administrator of your workspace and have authority to bind your organization, and must enter your organization's legal name and their own name and title and confirm that authority, in the BAA Tracker or in the dialog the Service shows when an upload is blocked under Section 8.4. We record an execution record (your organization's legal name as entered, the workspace, signer, title, account email, the confirmation of authority, date and time, network address, browser, method of acceptance, version and SHA-256 fingerprint of the published text), keep the executed copy in the BAA Tracker, and email the signer and the workspace owner a link to it. Each published version is signed electronically for Polestar GRC by Jonathan Prine, Owner, as stated in its execution section. If your organization requires a negotiated or wet-signed agreement, contact legal@polestargrc.com before uploading regulated data.

8.4 Regulated data before acceptance. In a workspace in HIPAA mode, including a trial workspace and a Client Workspace, the Service does not accept new file uploads (such as evidence files and agreement documents) or the narrative text of incident and breach records until an administrator of that workspace has accepted the applicable Platform Agreement under Section 8.3. Until then you can still open an incident record with structured details (date discovered, category, severity and approximate counts), and the Service gives it a title made from its date and category. The dialog that explains the block also lets an administrator accept the Platform Agreement in the same place. The block never stops you from viewing, downloading (including audit package and evidence ZIP files) or deleting anything already stored. Do not put PHI, or sensitive personal or health information about your clients, into the Service by any other route, or into fields the block does not cover, until the applicable Platform Agreement is in effect. If you do, you breach these Terms, but we will still handle that data as the Platform Agreement requires once it is accepted, and the safeguards in Section 15 apply in the meantime. No one whose access comes through a Partner may accept a Platform Agreement for a Client (Section 26.4).

8.5 Termination. Termination or expiration of these Terms terminates your Platform Agreement, and its return-or-destruction provisions apply to the data it covers in addition to Section 18.

9. Data processing terms for personal information that is not PHI

This Section applies to personal information in Customer Data that is not governed by a Platform Agreement, including information about your Authorized Users for every customer and, for customers that have not accepted the DPA, information about your clients or patients. Where you have accepted the DPA, the DPA governs Protected Data and controls over this Section for that data. This Section is intended to satisfy the service provider and processor contract requirements of the California Consumer Privacy Act (Cal. Civ. Code 1798.100(d) and 1798.140(ag), and 11 CCR 7051), the Washington My Health My Data Act (RCW 19.373), Nevada's consumer health data law (NRS 603A.400 to 603A.550) and the other US state privacy laws listed in our Privacy Policy. If you need a separately signed data processing agreement beyond the DPA, contact privacy@polestargrc.com.

9.1 Roles. You are the business or controller (or the processor acting for your own client), and we are your service provider or processor.

9.2 Instructions and purposes. We process personal information only on your documented instructions, which are these Terms, the Documentation and your configuration of the Service, and only for the business purposes of providing, securing, supporting and improving the Service for you, complying with law, and as you otherwise instruct in writing. We will tell you if we believe an instruction violates applicable law.

9.3 Prohibitions. We will not sell or share personal information (as those terms are defined under the CCPA), will not retain, use or disclose it for any purpose other than the business purposes above or outside the direct business relationship with you, and will not combine it with personal information we receive from others except as the CCPA permits for a service provider.

9.4 Compliance and notice. We will comply with the obligations that apply to a service provider or processor under applicable privacy laws and provide the same level of privacy protection they require. We will notify you if we determine we can no longer meet these obligations. You may take reasonable steps to stop and remediate unauthorized use, including by suspending the affected processing.

9.5 Confidentiality and personnel. Our personnel who access personal information are bound by confidentiality obligations and trained on privacy and security.

9.6 Subprocessors. We may engage Subprocessors to process personal information under written terms at least as protective as this Section. Our current list is in Section 10 of the Privacy Policy, with a change log. Before a new Subprocessor processes your Customer Data we will give your Notice Contacts at least 30 days' notice by email and by in-product notice, naming the Subprocessor, its function and its location. If you object on reasonable data-protection grounds within that period and we cannot resolve the objection, you may terminate the affected subscription before the change takes effect and receive a pro-rated refund of prepaid Fees for the remainder of the term. In an emergency (for example, replacing a failed provider to keep the Service running) we may make the change on shorter notice and will give notice as soon as practicable, with the same right to object and terminate. We remain responsible for our Subprocessors' performance.

9.7 Consumer requests. We will forward to you any request we receive directly from an individual about personal information you control, within five business days, and will not respond substantively except as you direct or as law requires. We provide export, correction and deletion tools in the Service to help you respond, and we will provide reasonable additional assistance within ten business days of your request.

9.8 Security and incidents. We maintain the safeguards in Section 15 and notify you of Security Incidents under Section 15.4.

9.9 Deletion and return. At the end of the Export Window we delete or de-identify personal information as described in Section 18, except as we must retain it by law.

9.10 Audits. On written request no more than once every 12 months, we will complete a reasonable security and privacy questionnaire and provide copies of our then-current third-party assessments or certifications, if any. If applicable law gives you a right to a more extensive audit, it will be conducted on reasonable notice, during business hours, at your expense, by an independent auditor bound by confidentiality, and without access to other customers' data.

9.11 Consumer health data. If you are a regulated entity under the Washington My Health My Data Act or Nevada's consumer health data law, this Section is the binding contract that sets out our processing instructions, and we will assist you in meeting your obligations under those laws as they apply to the Service.

9.12 Data and duration. The personal information we process under this Section is the information about Authorized Users, your contacts and, where you have not accepted the DPA, your clients or patients that you place in the Service, as described in Section 3 of the Privacy Policy. We process it for the term of these Terms and then for the Export Window and the deletion periods in Section 18.

10. AI features

10.1 What they are. AI Features use large language models to draft policies, suggest assessment answers from your evidence, analyze uploaded configuration files and evidence, compare your documents to templates, suggest remediation, narrate audit findings, analyze scan results, and power the in-app assistant. AI Features are labeled in the Service. They are optional; you can use the Service without them. Separately, we use the same AI processing to check the IRS letter you upload when you apply for nonprofit pricing (Section 5.13).

10.2 Who processes AI requests. AI requests are processed by Anthropic Claude models running on Amazon Bedrock, a service of Amazon Web Services, under our business associate agreement with AWS. Requests are processed in AWS regions in the United States; AWS may route a request to any of its US regions to serve it. Under the AWS terms that govern Bedrock, prompts and outputs are not stored by the model service after the response, are not used to train models, and are not available to the model developer. Our AWS account does not store your prompts or outputs either: we do not turn on Amazon Bedrock model invocation logging. We do not enable any setting that permits human review of your content by AWS or anyone else, and we will not use a model that requires it without first giving notice under Section 9.6. We send AI requests only to providers that are under a business associate agreement with us. If we change AI providers or how they process your content, we will update the Subprocessor list and give notice under Section 9.6.

10.3 What we send and how we reduce identifiers. Before a request leaves our systems we run automated redaction. For the in-app assistant, the redaction covers patterns that look like Social Security numbers, dates of birth, phone numbers, email addresses, medical record numbers, payment card numbers, street addresses and personal names, and the assistant stores only the redacted text. For other AI Features the redaction covers Social Security numbers, phone numbers, dates of birth, labeled medical record numbers and payment card numbers in text; names, email addresses and free-text descriptions are not removed. When an AI Feature analyzes evidence files you uploaded, a PDF file or image is sent as uploaded, without redaction, and a text file (plain text, CSV, JSON or HTML) is sent after redaction of the same patterns the in-app assistant removes. The IRS letter in a nonprofit application is also sent as uploaded (Section 5.13). Automated redaction is pattern based and will miss some identifiers. Do not enter patient-identifying details into text AI Features. Use document analysis only for documents you are permitted to disclose to us under your Platform Agreement, and never for records subject to 42 CFR Part 2.

10.4 Outputs may be wrong. AI OUTPUT IS GENERATED AUTOMATICALLY FROM YOUR INPUTS AND OUR PROMPTS. IT MAY BE INCOMPLETE, INACCURATE, OUT OF DATE, OR INAPPROPRIATE FOR YOUR SITUATION, AND IT MAY CITE RULES, CASES OR FACTS THAT DO NOT EXIST. AI OUTPUT IS NOT LEGAL, MEDICAL, SECURITY OR COMPLIANCE ADVICE AND IS NOT A SUBSTITUTE FOR REVIEW BY QUALIFIED COUNSEL OR COMPLIANCE PROFESSIONALS. A qualified person must review AI Output before you adopt it as a policy, record it as an assessment answer, submit it to a regulator, auditor or customer, or act on it. An AI-suggested assessment answer is a suggestion until one of your users accepts or edits it. You are responsible for your use of AI Output.

10.5 Ownership of outputs. As between you and us, you own the AI Output generated from your Customer Data, subject to our rights in the underlying templates and prompts and to the fact that similar output may be generated for other customers.

10.6 Limits. AI usage is subject to monthly usage limits that vary by plan and are shown in your workspace. We may throttle or pause AI Features to protect the Service or stay within provider limits. We may change the models we use, subject to Section 10.2.

10.7 Restrictions. Do not use AI Features to generate content that violates the AUP, to attempt to extract our prompts or another customer's data, or to build a competing model or dataset.

10.8 The in-app assistant is automated. The in-app assistant (currently named "Polestar Pal") is an AI system, not a person. It can explain HIPAA terms and help you find features, but it cannot change your plan, cancel your subscription, accept an agreement or make commitments for us. Statements it makes about prices, plans or these Terms do not modify these Terms; the pricing page, your automatic renewal terms and these Terms control. To reach a person, use the support page or support@polestargrc.com.

10.9 Your own AI disclosures. If you use AI Output in communications with patients, clients or the public, you are responsible for any disclosure, review or consent that laws applying to you require for AI-generated content.

11. Acceptable use

You and your Authorized Users must comply with the AUP, which is part of these Terms. In short: use the Service lawfully (AUP Section 1); do not attack it or other customers (AUP Section 2); do not scan or test systems you do not own or have written authorization to test (AUP Section 3); keep PHI out of places it does not belong and keep AI inputs free of patient identifiers (AUP Section 4); share Audit Room links and partner access responsibly (AUP Section 5); stay within fair use limits (AUP Section 6); and do not misrepresent outputs of the Service as certifications or legal opinions. Good-faith security research is covered by AUP Section 7. We may suspend or remove content and accounts under Section 17 for violations.

12. Third-party services and Subprocessors

12.1 Subprocessors. We use Subprocessors to host and operate the Service, including Amazon Web Services (infrastructure, storage, backups and Bedrock AI), Twilio SendGrid (outbound email), Twilio (SMS, if you enable it), Stripe (payments), Google LLC (Google Workspace, which hosts the mailboxes that receive the email you send us), and any error monitoring or analytics provider listed in the Privacy Policy. The current list, each Subprocessor's role, location and whether it may handle PHI, and a change log are in Section 10 of the Privacy Policy. Section 9.6 governs notice of changes. Before a Subprocessor may handle PHI, we have a business associate agreement with it, as the BAA and Subcontractor BAA require. The Privacy Policy states whether our business associate agreement with Google is in place; until it is, we do not ask you to email PHI to us, and you must not do so (AUP Section 4). Our emails and SMS messages are designed to contain no PHI and no text that you or your users typed: they say that an item is waiting and link to the Service, where the content stays behind sign-in. Twilio SendGrid and Twilio therefore receive no PHI by design, and we do not have business associate agreements with them.

12.2 Third-party services you connect. Services you connect under Section 7.4 and links you share under Section 7.6 are governed by your agreements with those third parties. We are not responsible for them.

12.3 Open source and templates. The Service includes open source software under its own licenses, and the policy templates and state-law content are our proprietary works licensed to you under Section 13.

13. Intellectual property and licenses

13.1 Our property. We and our licensors own the Service, including software, templates, question banks, state-law content, prompts, designs, trademarks and Documentation, and all improvements to them. Except for the licenses in this Section, we reserve all rights.

13.2 License to you. During your subscription (and during any Workspace Trial, Checkout Trial, read-only period or Export Window, for the uses those allow) we grant you a limited, non-exclusive, non-transferable, non-sublicensable license to access and use the Service and Documentation for your internal business purposes in accordance with these Terms.

13.3 Your generated documents. Policies, procedures, reports and other documents you generate and customize for your organization in the Service are yours to use internally, to provide to your auditors, customers, regulators and advisers, and to keep after your subscription ends. You may not sell, publish or distribute our templates or question banks as such, or use them to build a competing product. A Partner's rights to use the Service for its clients are in Section 26.

13.4 Restrictions. You will not, and will not allow anyone to: copy, modify or create derivative works of the Service except as permitted above; reverse engineer or attempt to extract source code, prompts or models except where law prohibits this restriction; resell, sublicense, rent or provide the Service to third parties except as a Partner under Section 26 or to your own Authorized Users; remove proprietary notices; access the Service to build a competitive product; or use automated means to scrape the Service beyond documented interfaces.

13.5 Trademarks. "Polestar GRC" and our logos are our trademarks. You may not use them without our written permission, except that Partners may use them as Section 26 allows. We may identify you as a customer only with your written consent.

14. Confidentiality

14.1 Definition. "Confidential Information" means non-public information disclosed by one party to the other in connection with the Service that is marked confidential or that a reasonable person would understand to be confidential, including Customer Data, security information, pricing and product roadmaps. It excludes information that is or becomes public without breach, was already known to the recipient without restriction, is independently developed, or is received from a third party without restriction.

14.2 Obligations. The recipient will use Confidential Information only to perform under these Terms, will protect it with at least reasonable care, and will disclose it only to its personnel, advisers and Subprocessors who need it and are bound by comparable obligations. The recipient may disclose Confidential Information when required by law or court order after giving the discloser prompt notice (where legally permitted) and reasonable cooperation to seek protection.

14.3 Duration. These obligations last during the agreement and for three years after it ends, except that obligations for trade secrets last as long as they remain trade secrets, obligations for PHI are governed by the BAA, and obligations for personal information last as long as we hold it.

15. Security

15.1 Our commitments. We maintain administrative, physical and technical safeguards appropriate to the sensitivity of Customer Data. As of the version date of these Terms, these include: encryption of data in transit using TLS 1.2 or higher and at rest using AES-256; organization-scoped access controls enforced on every API procedure; role-based permissions within workspaces and for our own staff; multi-factor authentication with workspace-wide enforcement available; session limits of 12 hours absolute and 30 minutes idle by default; credential hashing with bcrypt; rate limiting and lockouts; security event and audit logging; time-limited signed links for files; encrypted daily backups stored off the server, which we test by restoring a full copy at least once a year and after any change to the backup process (most recently on October 8, 2026); application secrets kept in a file on the production server that only the deployment account and the server administrator can read, and never in source control; least-privilege cross-account roles for cloud connectors; automated identifier redaction on AI text requests (Section 10.3); and signature verification on inbound webhooks. A current description is in the Security section of polestargrc.com/legal (the "Security Page"), which we update as our controls change. We will not materially reduce the overall level of protection during your subscription.

15.2 Your responsibilities. Security is shared. You are responsible for your accounts, devices, networks, Authorized Users, the permissions you grant, the credentials you connect, what you upload, and who you share with.

15.3 No perfect security. No system is completely secure. We do not promise that the Service will be free of vulnerabilities or that unauthorized access will never occur, but we will meet the commitments in this Section and the Platform Agreement.

15.4 Security Incident notice. We will notify your Notice Contacts of a Security Incident affecting your Customer Data without unreasonable delay and no later than seven (7) calendar days after we discover it, with the information we have then, and will update you as we learn more. We will not wait to finish our investigation before giving this notice. We will ask the Notice Contact who receives the notice to confirm receipt. A notice that describes PHI or Protected Data is delivered inside the Service, with an email that says a notice is waiting and does not itself contain that data. We will cooperate reasonably with your own notification obligations. For data covered by a Platform Agreement, that agreement's reporting terms also apply and control where they are more specific or stricter. If you are subject to the FTC Health Breach Notification Rule or a state consumer health data law, this notice is intended to satisfy our obligations as your service provider under those rules.

15.5 Vulnerability reports. Report suspected vulnerabilities to security@polestargrc.com. AUP Section 7 describes our good-faith security research terms.

16. Service levels, support and accessibility

16.1 Availability target. We aim to make the Service available at least 99.5% of the time each calendar month, excluding scheduled maintenance (announced in advance where practicable and performed outside US business hours where possible), emergency maintenance, and causes outside our reasonable control. This target is a goal, not a warranty, and no service credits or other remedies attach to it unless a separately signed service level agreement says otherwise.

16.2 Support. Email and in-product support is included with every plan during US business hours. Advanced plans receive priority handling. Clients in a Client Workspace receive first-line support from their Partner under Section 26.7. Professional Services are separate (Section 6).

16.3 Maintenance and changes. We may suspend the Service briefly for maintenance. We will try to minimize disruption.

16.4 Accessibility. We design the Service to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA and work to fix reported barriers. Our current conformance status and known exceptions are published in the accessibility statement at polestargrc.com/legal (Accessibility section). Report an accessibility barrier, or request an accessible format of any document we provide, at support@polestargrc.com; we will respond within five business days. If your organization needs our help to meet an accessibility obligation of its own (for example under 45 CFR 84.84), tell us and we will provide our conformance information and work with you in good faith.

17. Suspension

17.1 When we may suspend. We may suspend all or part of your access, with notice where practicable, if: (a) your use presents a security risk to the Service or others; (b) you or an Authorized User materially violates the AUP; (c) Fees are more than 14 days overdue after notice; (d) we are required to by law or a government order; or (e) your use would subject us or others to liability.

17.2 Scope and restoration. We will limit a suspension to what is reasonably needed and lift it once the cause is resolved. During suspension you can still export Customer Data and contact support unless law or the security of others prevents it. Suspension does not relieve you of payment obligations for the suspended period unless the suspension was caused solely by our error.

18. Term, termination, export and deletion

18.1 Term. These Terms start when you first accept them and continue until your account is closed or terminated.

18.2 Termination. You may terminate by cancelling all subscriptions (Section 5.5) and requesting deletion of your workspace, or by emailing legal@polestargrc.com. Either party may terminate for material breach if the breach is not cured within 30 days after written notice, or immediately if cure is not possible. We may terminate immediately if you become insolvent or if required by law.

18.3 Export Window. For 30 days after your last paid subscription for a workspace ends, after these Terms terminate, or after a Partner detaches a Client Workspace under Section 26.8 (the "Export Window"), the workspace is in read-only mode and you may export your Customer Data using the built-in export tools (data export, evidence packages, audit log export and PDF reports). We email your Notice Contacts when the Export Window starts, with its end date and the scheduled deletion date. We will provide reasonable assistance on request. You can end the Export Window early by starting a paid subscription, which cancels the scheduled deletion. Exports after the Export Window may not be possible.

18.4 Deletion. At the end of the Export Window we will delete your workspace's Customer Data from our production systems, including evidence files in storage, connected-account credentials, AI assistant history, scan results and other records of the workspace, within 30 days, and we email your Notice Contacts before deletion starts. You may also request deletion at any time from the Data Deletion page; the workspace is then read-only for a 30-day grace period during which an owner can cancel the request, and deletion runs at the end of that period. Deleted data is removed from encrypted backups within 90 days after the Export Window (or grace period) ends, as backup media rotate. We will confirm deletion in writing on request. We will delete or de-identify the personal data of Authorized Users who have no other workspace with us. If you terminate because of our uncured material breach, we will refund prepaid Fees for the period after termination.

18.5 What we keep. We retain: audit log entries for six years from creation, to support the six-year documentation retention in 45 CFR 164.316(b)(2), after which they are purged; records of your acceptance of these Terms, the AUP, the Privacy Policy and your Platform Agreement, and records of your consent to automatic renewal terms and of the billing notices we sent you, for six years after the workspace is deleted; billing and tax records for seven years; email and SMS opt-out records so we can honor them; and information we must keep by law or to resolve disputes. Retained data stays subject to Sections 14 and 15 and, for PHI, the BAA.

18.6 Survival. Sections 1.3, 2, 4.2 to 4.4, 5 (as to amounts owed and refunds due), 7.1, 7.7, 7.8, 8.5, 9.9, 10.4, 13, 14, 15.4, 18.3 to 18.7, 19, 20, 21, 22, 23, 25 and 26.8 survive termination.

18.7 Unconverted and inactive workspaces. If a workspace's Workspace Trial ends and no paid subscription starts, the workspace stays read-only and we delete it under Section 18.4, with deletion from our production systems complete no later than 60 days after the Workspace Trial ended, unless a paid subscription starts first. We email its Notice Contacts at least 30 days before that deletion starts. If a read-only workspace whose paid subscription has ended has no sign-in for 12 months, we will email its Notice Contacts that the workspace will be deleted, and delete it under Section 18.4 no earlier than 30 days after that email unless a paid subscription starts or an owner asks us to keep it for a stated period. A Sandbox Workspace is deleted when its Partner's own account is deleted.

19. Warranties and disclaimers

19.1 Mutual. Each party represents that it has the authority to enter into these Terms and that doing so does not violate any other agreement it has.

19.2 Our warranty. We warrant that the Service will perform materially in accordance with the Documentation and that we will provide it with reasonable skill and care. Your exclusive remedy for breach of this warranty is for us to correct the non-conformity or, if we cannot do so within 30 days of your notice, for you to terminate the affected subscription and receive a pro-rated refund of prepaid Fees for the remainder of the term.

19.3 Disclaimer. EXCEPT AS EXPRESSLY STATED IN THIS SECTION 19 AND IN THE PLATFORM AGREEMENT, THE SERVICE, PROFESSIONAL SERVICES, DOCUMENTATION, TEMPLATES AND AI OUTPUT ARE PROVIDED "AS IS" AND "AS AVAILABLE". TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. WITHOUT LIMITING THE FOREGOING, WE DO NOT WARRANT THAT USE OF THE SERVICE WILL RESULT IN COMPLIANCE WITH HIPAA OR ANY OTHER LAW, THAT YOU WILL PASS ANY AUDIT, INVESTIGATION OR REVIEW, THAT ANY SCORE OR REPORT REFLECTS YOUR ACTUAL COMPLIANCE, THAT THE SERVICE WILL BE UNINTERRUPTED, TIMELY, SECURE OR ERROR-FREE, THAT DEFECTS WILL BE CORRECTED, OR THAT AI OUTPUT, TEMPLATES, STATE-LAW SUMMARIES OR SCAN RESULTS WILL BE ACCURATE, COMPLETE OR CURRENT. Some jurisdictions do not allow certain disclaimers; in that case the disclaimers apply to the fullest extent permitted.

19.4 Descriptions of the Service. Descriptions of templates, features or outputs as written "to" or "for" HIPAA or a state law mean that we drafted them with reference to that law. They are not a statement that using them makes you compliant.

20. Limitation of liability

20.1 No indirect damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, BUSINESS OPPORTUNITIES OR DATA (OTHER THAN THE COSTS OF RESTORING DATA WE WERE OBLIGED TO PROTECT), HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

20.2 General cap. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS, THE AUP, THE PRIVACY POLICY AND THE SERVICE WILL NOT EXCEED THE GREATER OF (A) THE FEES PAID OR PAYABLE FOR THE AFFECTED WORKSPACE IN THE TWELVE MONTHS IMMEDIATELY BEFORE THE EVENT GIVING RISE TO THE CLAIM AND (B) USD 1,000.

20.3 Data protection claims. Liability relating to PHI is governed by Section 11 of the BAA or Section 12 of the Subcontractor BAA. Each provides a separate cap for PHI claims, in addition to the cap in Section 20.2, equal to the greater of two times the Fees paid or payable in the prior twelve months or USD 50,000, which rises to USD 100,000 while our cyber liability insurance has an aggregate limit of USD 2,000,000 or more; mutual indemnification for breaches of that agreement and of HIPAA, inside that cap; and a statement of the insurance we carry. Liability relating to Protected Data under the DPA is subject to the separate cap in Section 11 of the DPA, which is the same as the PHI cap. For all Customer Data, the reasonable, documented costs of investigating a Security Incident caused by a party's breach, of the notifications that law requires, and of credit monitoring or identity protection where law requires it or it is reasonably necessary to mitigate harm to individuals, are direct damages and are not excluded by Section 20.1.

20.4 Exclusions. THE LIMITATIONS IN SECTIONS 20.1 AND 20.2 DO NOT APPLY TO: (A) CUSTOMER'S DEFENSE AND PAYMENT OBLIGATIONS UNDER SECTION 21.2(a) TO 21.2(c); (B) A PARTY'S FRAUD, GROSS NEGLIGENCE OR WILLFUL MISCONDUCT; (C) CUSTOMER'S OBLIGATION TO PAY FEES; (D) CUSTOMER'S INFRINGEMENT OR MISAPPROPRIATION OF OUR INTELLECTUAL PROPERTY OR BREACH OF SECTION 13.4; OR (E) LIABILITY THAT CANNOT BE LIMITED BY APPLICABLE LAW, INCLUDING UNDER CALIFORNIA CIVIL CODE SECTION 1668. OUR DEFENSE AND PAYMENT OBLIGATIONS UNDER SECTION 21.1 ARE NOT SUBJECT TO SECTIONS 20.1 AND 20.2 AND ARE INSTEAD SUBJECT TO A SEPARATE CAP EQUAL TO THE GREATER OF (I) THREE TIMES THE FEES PAID OR PAYABLE FOR THE AFFECTED WORKSPACE IN THE TWELVE MONTHS IMMEDIATELY BEFORE THE CLAIM AND (II) USD 25,000. CUSTOMER'S OBLIGATIONS UNDER SECTION 21.2(d) ARE SUBJECT TO THE CAP IN SECTION 20.2. INDEMNITIES IN A PLATFORM AGREEMENT ARE SUBJECT TO THAT AGREEMENT'S OWN CAP AND ARE NOT AFFECTED BY THIS SECTION 20.4.

20.5 Basis of the bargain. The parties agree that these limitations reflect a reasonable allocation of risk given the price of the Service and that we would not offer the Service at that price without them. The limitations apply even if a remedy fails of its essential purpose. HIPAA civil money penalties are imposed by law on the party that incurs them; they are reallocated between the parties only to the extent a Platform Agreement's indemnification provisions say so.

20.6 One regime. Sections 20.1, 20.2 and 20.4 apply to claims under a Platform Agreement except as that Platform Agreement expressly modifies them. The exclusion in Section 20.4(B) applies to claims under a Platform Agreement as well.

20.7 Free use. During a Workspace Trial, a Checkout Trial before the first charge, or use of a Sandbox Workspace, the cap in Section 20.2(B) applies.

21. Indemnification

21.1 By us. We will defend you and your officers, directors and employees against any third-party claim alleging that the Service, as provided by us and used in accordance with these Terms, infringes or misappropriates that third party's patent, copyright, trademark or trade secret, and we will pay the damages, costs and reasonable attorneys' fees finally awarded or agreed in settlement. If such a claim is made or appears likely, we may modify the Service to be non-infringing, obtain a license, or, if neither is commercially reasonable, terminate the affected subscription and refund prepaid Fees for the remainder of the term. We have no obligation for claims arising from Customer Data, your connected systems, your modifications, combination with items we did not provide, or use after we told you to stop. Our obligations under this Section 21.1 are subject to the separate cap in Section 20.4.

21.2 By you. You will defend us and our officers, directors, employees and Subprocessors against any third-party claim, including claims by regulators, individuals, Authorized Users or your clients, arising from: (a) Customer Data, including allegations that it was collected or submitted unlawfully or infringes rights; (b) your or your Authorized Users' use of the Service in violation of these Terms, the AUP or law; (c) your scanning or connecting of systems you did not own or were not authorized to test; or (d) your compliance decisions, representations to regulators or auditors, or reliance on the Service or AI Output without the review these Terms require, except to the extent the claim arises from our breach of these Terms or a Platform Agreement. You will pay the damages, costs and reasonable attorneys' fees finally awarded or agreed in settlement.

21.3 Process. The indemnified party must give prompt written notice of the claim (delay excuses the indemnifying party only to the extent it is prejudiced), give the indemnifying party sole control of the defense and settlement (except that no settlement may impose obligations or admissions on the indemnified party without its consent, not to be unreasonably withheld), and provide reasonable cooperation at the indemnifying party's expense. The indemnified party may participate with its own counsel at its own expense.

21.4 Exclusive remedy. This Section states each party's sole liability and exclusive remedy for the third-party claims it covers, except as a Platform Agreement provides.

21.5 Platform Agreements. The mutual indemnities in the BAA and the Subcontractor BAA for breaches of those agreements and of HIPAA, including government investigations and enforcement actions, apply in addition to this Section, follow the process in Section 21.3, and are subject to the liability cap in that agreement.

22. Dispute resolution

22.1 Informal resolution first. Before starting a lawsuit, the party with a dispute must send a written notice describing it and the relief sought to the other party (to us at legal@polestargrc.com; to you at your Notice Contacts' email addresses), and the parties will try in good faith to resolve it for at least 30 days, including by a video call if either party asks. Time limits for bringing a claim are paused during this period. This step does not apply to a claim in small claims court or to a request for urgent relief under Section 22.3.

22.2 Courts. Disputes that are not resolved informally will be decided in the courts described in Section 23. These Terms contain no agreement to arbitrate.

22.3 Small claims and urgent relief. Either party may bring an individual claim in small claims court in Kern County, California or in the county where you are located, if the claim qualifies, and may seek temporary or preliminary injunctive relief in any court of competent jurisdiction to protect its intellectual property, its Confidential Information or the security of the Service.

22.4 Class and representative action waiver. TO THE EXTENT PERMITTED BY LAW, EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER ONLY IN ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY CLASS, CONSOLIDATED OR REPRESENTATIVE PROCEEDING.

22.5 Judicial reference only by later agreement. These Terms do not require that any dispute be decided by a referee. After a dispute has arisen, the parties may agree, in a separate writing signed by both of them, to have it decided by a referee under California Code of Civil Procedure section 638. Neither party is obliged to agree.

22.6 Time limit for claims. To the extent permitted by law, a claim by either party arising out of or relating to these Terms or the Service must be brought within two years after the claiming party discovered, or reasonably should have discovered, the facts giving rise to it; otherwise it is barred. This applies in the same way to claims by you and claims by us, including our claims for unpaid Fees. It does not shorten any period that the law does not allow to be shortened, and it does not apply to claims based on fraud. A claim for defense or indemnity under Section 21 or a Platform Agreement may be brought within two years after the underlying third-party claim or government action is first made against the party seeking defense or indemnity.

22.7 Attorneys' fees. Each party pays its own attorneys' fees and costs in any dispute, unless a statute that cannot be waived by contract provides otherwise.

22.8 Withdrawal of the Version 2.0 arbitration clause. Version 2.0 of these Terms, effective 2026-10-01, contained an agreement to arbitrate, an arbitration class waiver and an opt-out in its Sections 22.2 to 22.5. We withdraw those sections completely, for you and for us. From October 8, 2026, the date we gave notice of this withdrawal, we will not ourselves seek to require arbitration of any dispute with you. From November 7, 2026, which is 30 days after that notice, neither you nor we may start or require arbitration of any dispute under Version 2.0 or any other version of these Terms, and disputes are resolved only in court under this Section 22 and Section 23. This withdrawal applies to every customer on that date, whether or not an administrator has yet accepted this version, and Section 24.4 does not delay it.

23. Governing law and venue

These Terms are governed by the laws of the State of California and applicable federal law of the United States, without regard to conflict-of-laws rules. Subject to Section 22, the exclusive venue for any dispute is the Superior Court of California, County of Kern, or the United States District Court for the Eastern District of California, in each case to the extent that court has jurisdiction over the dispute. Each party consents to personal jurisdiction and venue in those courts and waives any objection based on inconvenient forum. The choice of California law in this Section does not take away any protection that the law of the state where you are located gives you and that cannot be waived by contract. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

24. Changes to these Terms

24.1 How we change them. We may update these Terms. Each version has a version number and effective date at the top and a SHA-256 fingerprint we record with each acceptance. Every earlier version stays available at polestargrc.com/legal/archive.

24.2 Notice. For material changes we will give at least 30 days' notice before the effective date by email to your Notice Contacts and by in-product notice, with a summary of what changed. For non-material changes (clarifications, typographical corrections, changes required by law, new features that do not reduce your rights) we may post the update with a new effective date and note it in the archive.

24.3 Your choices. If you do not agree to a material change, you may terminate before it takes effect by notice to legal@polestargrc.com or by cancelling under Section 5.5, and we will refund prepaid Fees for the period after termination. Changes do not apply retroactively to a dispute that arose, or to a claim that was notified under Section 22.1, before the effective date.

24.4 When a new version applies to you. A change to Sections 5, 7, 9, 10.2, 18, 20, 21, 22 or 23, or any change that reduces our obligations or increases your Fees, applies to an existing customer only when an administrator accepts the new version in the Service. We will ask for that acceptance at sign-in once notice under Section 24.2 has been given. Until it is accepted, the version you last accepted continues to apply until the end of your current billing period; if the new version has not been accepted by then, either party may end the subscription at that time without further charge, and the prior version governs any dispute about the period before. Other changes apply to an existing customer on their effective date. The withdrawal of the Version 2.0 arbitration clause in Section 22.8 applies to every customer on the date stated there, without acceptance.

25. General

25.1 Entire agreement. These Terms, together with the documents listed in Section 1.3, are the entire agreement between the parties about the Service and supersede all prior or contemporaneous agreements, proposals and representations on that subject. Terms in your purchase order or vendor forms do not apply unless we sign them.

25.2 Assignment. Neither party may assign these Terms without the other's prior written consent, except that either party may assign them without consent to a successor in a merger, acquisition or sale of all or substantially all of its assets or of the business to which these Terms relate, on written notice, provided the successor assumes all obligations, including those under the Platform Agreement. In addition, we may assign these Terms, together with the Platform Agreement, to Polestar GRC, LLC, a limited liability company of which Jonathan Prine is the sole member (the "LLC"), without your consent, on these terms. (a) We will give your Notice Contacts at least 30 days' notice by email and in-product notice before the assignment takes effect, stating the LLC's exact legal name, its state of organization and entity number, and the effective date. (b) Before the effective date, the LLC will assume these Terms and the Platform Agreement in a writing signed for the LLC, and will have in place the written agreements Section 9.6 and the Platform Agreement require with each Subprocessor. (c) On the effective date, the Service will give you an updated executed copy of your Platform Agreement naming the LLC. (d) The Service, the locations where Customer Data is stored and the Subprocessors will not change because of the assignment. (e) You may terminate these Terms and the Platform Agreement by notice to legal@polestargrc.com before the effective date and receive a refund of prepaid Fees for the period after termination. (f) Jonathan Prine remains responsible for obligations that arose before the effective date. Any other attempted assignment is void. These Terms bind permitted successors and assigns. We may use Subprocessors under Section 12.

25.3 Notices. Legal notices to us go to legal@polestargrc.com with a copy by mail to Polestar GRC, Attn: Jonathan Prine, 434 Kern St, Taft, CA 93268. Notices to you go to your Notice Contacts' email addresses and in-product, and are effective when sent unless we receive a delivery failure, in which case we will try another administrator on the account and, for billing notices, show the notice in the Service.

25.4 Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disasters, war, terrorism, labor disputes, government action, failures of the internet or of third-party providers not caused by the affected party, or widespread utility outages, provided it uses reasonable efforts to mitigate. Payment obligations and our obligations under Section 15.4 are not excused.

25.5 Export and sanctions. The Service is offered from the United States. You represent that you are not located in, or a resident of, a country or territory subject to comprehensive US sanctions, and that you are not on any US government restricted-party list. You will comply with US export control and sanctions laws in using the Service.

25.6 US government customers. If you are a US government entity, the Service is a commercial item and commercial computer software documentation, and government rights are limited to those granted to all customers under these Terms.

25.7 Independent contractors. The parties are independent contractors. Nothing creates a partnership, joint venture, agency, fiduciary or employment relationship.

25.8 No third-party beneficiaries. There are no third-party beneficiaries to these Terms, except that the indemnified persons in Section 21 may enforce Section 21.

25.9 Waiver and severability. A waiver must be in writing. Failure to enforce a provision is not a waiver. If any provision is held unenforceable, it will be enforced to the maximum extent permissible and the rest remains in effect.

25.10 Interpretation. Headings and the plain-English summary are for convenience only. "Including" means "including without limitation". No rule of construction against the drafter applies.

25.11 Publicity. We will not use your name or logo in marketing without your written consent. You may state that you use Polestar GRC.

25.12 Counterparts and electronic signatures. Where a signed document is required, electronic signatures and counterparts are valid.

25.13 How these Terms are executed. These Terms are accepted electronically under Section 1.1 and need no handwritten signature. We are bound by each published version from its effective date. A copy of the version you accepted, with your acceptance record, is available on request. This version is issued and signed electronically for Polestar GRC by Jonathan Prine, Owner, on October 9, 2026. Jonathan Prine adopted this electronic signature with the intent to sign each published version.

Polestar GRC, by Jonathan Prine, Owner

26. Partners and partner-managed workspaces

26.1 Who this Section applies to. This Section applies to each Partner and to each organization whose workspace a Partner created (a "Client"). Partner features are available only to an organization that has entered into a Partner Agreement with us and that we have enabled as a Partner. The Partner Agreement sets the commercial terms of the relationship, such as any discount or referral share, pilot limits and payment terms, and controls over this Section where they conflict, except that it cannot reduce a Client's rights under Sections 26.4, 26.5, 26.7 and 26.8. As of the version date, partner features are switched off for every organization until a Partner Agreement is in place; Section 26.12 describes how an IT provider or consultant can refer organizations to us in the meantime.

26.2 Partner accounts. A Partner keeps its own workspace, which is a full compliance workspace for its own program; the Partner Agreement states whether it is charged for. A Partner may create one Sandbox Workspace for training and demonstration. A Sandbox Workspace must not contain PHI or real personal information about patients or clients. The Partner accepts these Terms and the Subcontractor BAA for its own workspace.

26.3 Creating Client Workspaces. A Partner may create a Client Workspace only for an organization that has authorized it to do so, and only with accurate information about the Client's name, state, compliance mode and HIPAA role. Until the Client's administrator accepts the invitation, the Partner staff member who created the workspace is its owner and Notice Contact; when the Client's first administrator accepts, ownership and the Notice Contact role pass to that administrator, who confirms or corrects the Client's compliance mode and HIPAA role at that time.

26.4 Client acceptance and Platform Agreement. The Client's administrator accepts these Terms and the AUP for the Client when accepting the invitation. Before any PHI or other regulated data is placed in a Client Workspace, the Client must accept its own Platform Agreement with us in the Client Workspace, and Section 8.4 applies there in the same way as in any other workspace. A Partner, and anyone whose access to the Client Workspace comes through the Partner, may not accept these Terms or a Platform Agreement on a Client's behalf, and the Service refuses such an acceptance. Everything in a Client Workspace, whoever entered it, is governed by the Client's own Platform Agreement. The Partner will not place PHI in a Client Workspace, and will not ask the Client to, until the applicable agreement is in effect.

26.5 Access to Client data. A Partner sees aggregate compliance metrics for each attached Client Workspace. Partner staff have no access to a Client Workspace's data unless the Client's administrator invites them, and then only with the role the Client assigns. A Partner may not represent outputs of the Service as its own certification, opinion or attestation, and must not misstate the Client's compliance status to anyone.

26.6 Fees for Client Workspaces. The Partner Agreement states whether a Client pays us directly under Section 5 or the Partner pays us for the Client Workspace, and on what terms. Where the Partner pays: the Client sees no Polestar GRC checkout or charge; Sections 5.4 to 5.6, 5.8 and 5.10 apply to the Partner's subscription, with the Partner as the customer; and if the Partner is more than 30 days late in paying for a Client Workspace, we may offer the Client a direct subscription and, once the Client accepts it under Section 5, bill the Client directly. We will not end a Client's access because of the Partner's non-payment without first notifying the Client. During a pilot under a Partner Agreement the Partner pays us nothing unless the Partner Agreement says otherwise. What the Partner charges its Client is between them.

26.7 Partner responsibilities to Clients. The Partner is responsible for its own contract with each Client, for first-line support, for telling the Client how to reach us for privacy, security and deletion requests, and for passing on to the Client any notice we ask it to pass on. We may contact a Client directly about security, privacy, legal or billing matters.

26.8 Detaching a Client. When a Partner offboards a Client, or the Partner account ends, the Client Workspace is detached. We email the Client's Notice Contacts on the day of detachment and again before the end of the Export Window. The Client keeps read-only access with full export for 30 days (the Export Window under Section 18.3), during which it may start its own subscription with its data intact by accepting these Terms, its Platform Agreement and the automatic renewal terms. If it does not, Section 18.4 applies. If the Partner was paying for the Client Workspace, it stops being billed for it on detachment. We may continue to serve the Client directly after the Partner leaves.

26.9 Brand and white-label. A Partner may display its own name and logo in its portal and on its subdomain of polestargrc.com, and may refer to the Service as "powered by Polestar GRC". The Partner must not remove our legal notices, links to these Terms, the AUP, the Privacy Policy or the Platform Agreements, and must not state or imply that it is the provider of the Service's hosting or the counterparty to a Client's Platform Agreement with us.

26.10 Partner indemnity. The Partner will defend us against any third-party claim by a Client arising from the Partner's own acts or omissions, including creating a Client Workspace without authority, placing PHI in breach of Section 26.4, or misrepresenting the Service, on the terms of Section 21.

26.11 Ending partner status. Either party may end the Partner's partner status on 30 days' notice. Each attached Client Workspace is then detached under Section 26.8, and the Partner's own workspace continues as a direct workspace under Section 5.

26.12 Referrals. An IT provider, consultant or other organization that is not a Partner may refer organizations to us. A referred organization signs up itself, accepts these Terms and its own Platform Agreement, and pays us directly under Section 5. The referrer is not our agent, cannot accept any agreement for the referred organization, and has no access to its workspace unless the organization invites the referrer's staff, in which case the organization is responsible for having any business associate or processor agreement with the referrer that the law requires. We do not pay cash referral fees; a referral may come with a promotion code under Section 5.11.

27. Contact

Polestar GRC (Jonathan Prine, an individual doing business as Polestar GRC) 434 Kern St, Taft, CA 93268, United States

Legal notices: legal@polestargrc.com Privacy: privacy@polestargrc.com Security: security@polestargrc.com Abuse: abuse@polestargrc.com Billing and cancellations: billing@polestargrc.com Support and accessibility: support@polestargrc.com


Earlier versions of these Terms of Service: Version 3.0, effective October 8, 2026, Version 2.0, effective October 1, 2026 and the draft dated August 1, 2026, published from September 21, 2026 to October 1, 2026. Every version of our legal documents is listed at polestargrc.com/legal/archive.