How Polysync collects, uses, stores, and protects your information.
Effective Date: May 1, 2025 · Last Updated: August 25, 2026
Polysync Data Solutions Pty Ltd (ABN 87 683 785 686) ("Polysync", "we", "us", or "our") operates the Polysync data pipeline orchestration platform, available as a SaaS application on the Microsoft Azure Marketplace. This Privacy Policy explains what information we collect, why we collect it, how we use and store it, and the choices you have.
We are an Australian registered company and comply with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth). Where we process the personal data of individuals in the European Economic Area or the United Kingdom, we also act in accordance with the General Data Protection Regulation and the UK GDPR.
By accessing or using Polysync, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not access the Service.
Polysync acts as a data controller for the account, billing, and operational data required to provide the Service — for example, the identity claims received when you sign in, Azure Marketplace subscription metadata, run history, audit records, and support communications. For these categories we determine the purposes and means of processing and are responsible for the obligations a controller owes under the GDPR and UK GDPR.
For customer data processed through the cloud platforms you connect, Polysync generally acts as a data processor on behalf of the customer (the data controller). We process that data only on your documented instructions — the jobs, tasks, schedules, and parameter mappings you configure — and we do not determine the purposes for which your connected platforms are used. Where Polysync acts as a processor, the processing is governed by a Data Processing Agreement that incorporates the terms required by Article 28 of the GDPR; you can request one at support@polysync.com.au.
When you sign in via Microsoft Entra ID, we receive the following claims from Microsoft about your identity:
oid) and tenant identifier (tid).Data you provide while using the Service, including platform connection details, job and task definitions, schedules, concurrency profiles, dependency graphs, parameter mappings, and tags. This data is stored in a SQL schema dedicated to your tenant.
Data the Service generates while operating on your behalf, including run history, run status, dispatcher logs, and audit records of administrative actions. Operational data is stored in the same tenant schema as your configuration data.
We collect application telemetry through Microsoft Application Insights to operate the Service, diagnose problems, and improve performance. This may include:
Telemetry is associated with your tenant for support purposes but is not used for advertising or sold to third parties.
When you subscribe through the Azure Marketplace, Microsoft transmits subscription metadata to us so we can provision and manage your tenant. This includes your Azure tenant identifier, plan identifier, term, status, quantity, and the email address of the purchaser. Billing and payment information itself is held by Microsoft and is not shared with Polysync.
The table below states, for each purpose, the categories of information from section 2 that we use and the lawful basis we rely on under the GDPR and UK GDPR. Where the Australian Privacy Act 1988 applies, we handle the same information in accordance with the Australian Privacy Principles.
Our legitimate-interests assessment. Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. The processing involved is limited to operational telemetry and security records, it is what a customer would reasonably expect of a managed service, it is not used for advertising, profiling or automated decision-making, and you may object to it at any time using the contact details in section 15.
We do not collect or process special categories of personal data (Article 9) or criminal-offence data (Article 10), and the Service is not designed to receive them.
Polysync is hosted on Microsoft Azure. The primary processing region for the production Service is Australia East (Sydney). Disaster-recovery and backup data may be replicated to another Azure region within the same sovereign boundary. If you require deployment in a different region, contact us at support@polysync.com.au.
Each customer's configuration, operational data, and run history is stored in a dedicated SQL schema. Tenant identity is enforced server-side from identity claims rather than from URL parameters, headers, or client state.
Access to the application is authenticated exclusively through Microsoft Entra ID. Within Polysync, the Administrator and Operator roles determine what each user can do. Access by Polysync personnel to production systems is limited to authorised staff, logged, and used only to operate the Service and respond to support requests.
Polysync includes an optional AI assistant, the Polysync Copilot, which helps you configure platforms, jobs, tasks, and schedules using natural language. This section explains how it works and what happens to the information you give it.
The Copilot is built on the Azure OpenAI Service, running on a model deployment inside Polysync's own Microsoft Azure subscription. Your prompts are not sent to OpenAI directly, nor to any third-party AI provider outside the Microsoft Azure boundary described in Section 4.1.
Where your Copilot messages are processed. The model deployment is provisioned in Australia East and any data the service stores at rest stays in that region. The deployment uses Microsoft's global standard deployment type, under which Microsoft may route an individual request to any Azure region where that model is available. We therefore cannot promise that the processing of a Copilot message takes place in Australia. This applies only to the Copilot; the rest of the Service is processed as described in Sections 4.1 and 12. If you need your Copilot messages processed only in a specific region, turn the Copilot off as described in Section 5.6 and use the Setup screens instead.
When you send a message to the Copilot, the following is transmitted to the Azure OpenAI Service:
Nothing that identifies you personally is sent to the model. Your name, email address, user account identifier, role, and IP address are not transmitted to the Azure OpenAI Service, and Polysync does not attach an end-user identifier to its requests. The only way personal information can reach the model is if you type it into the Copilot yourself.
Credentials and secret values are never sent to the model. Secrets remain in the key vault described in Section 4.3 and are referred to only by reference, never by value. You should not paste passwords, keys, connection strings, or other secret material into the Copilot.
Prompts and responses processed through the Azure OpenAI Service are not used to train, retrain, or improve any Microsoft or OpenAI foundation model, and are not shared with other customers. This is a contractual commitment Microsoft makes to Polysync as an Azure OpenAI Service customer. Polysync does not use your Copilot conversations to train models of its own.
Copilot conversations are held in memory for the life of your browser session only. They are not written to the Polysync database, and closing the session or clearing the conversation discards them. Under the Azure OpenAI Service terms, Microsoft may retain prompts and responses for a limited period (up to 30 days) solely to detect and prevent abuse and misuse; that data is accessible only to authorised Microsoft personnel for that purpose and is not used for any other purpose.
The Copilot assists you; it does not act on its own initiative. It responds only when you send it a message, and it cannot create, change, delete, or run anything by itself. Any such action is held by Polysync and shown to you with the exact details of what will change; it is carried out only after you approve it, and you can reject it instead. You remain in control of and responsible for every change made to your environment.
AI-generated output can be incomplete or incorrect. You should review what the Copilot proposes before you rely on it or apply it to production workloads. The Copilot does not make automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 of the GDPR, and it is not used for profiling.
Using the Copilot is entirely optional. Every action it can perform is also available directly through the Polysync interface, so you can operate the Service fully without ever using it.
The Copilot is enabled by default. An administrator in your organisation can turn it off for everyone at any time under Settings › Polysync Copilot; when it is off, the assistant is hidden for every user and no data is sent to the Azure OpenAI Service. No functionality is lost — configuration is simply entered manually through the Setup screens.
If you believe the Copilot has produced harmful, biased, or inappropriate output, or has behaved unexpectedly with your data, please report it to support@polysync.com.au. We investigate every report and use the findings to improve the assistant's safeguards.
We engage the following sub-processors to provide the Service. Each is bound by contractual obligations to protect the data they process on our behalf.
Services used only on our public marketing pages — Google Analytics and YouTube video hosting — are not sub-processors of the Service: they receive no data from the signed-in application, and no customer configuration, credential, or pipeline data is shared with them. They are described in Section 10.
When you connect your own cloud platforms (Azure, Google Cloud, or others as they become supported) through Polysync, those platforms act on your instructions and are governed by their own terms and privacy notices, not by this policy.
We will provide reasonable advance notice of any new sub-processor we intend to engage so that customers subject to a Data Processing Agreement can exercise any objection rights described in that agreement.
We do not sell, rent, or trade your personal information. We disclose information only in the following circumstances:
In limited circumstances we may be legally compelled to disclose personal data — for example, in response to a court order, subpoena, warrant, or a binding request from a law-enforcement, regulatory, or government authority with competent jurisdiction. Where we are compelled to disclose, we will:
We retain your configuration and operational data, including your task run history, for as long as your subscription is active. We do not delete run history on an age-based schedule while your subscription continues, because it is the record you rely on to audit and troubleshoot your own pipelines. Your subscription plan sets the number of task runs included per month; it is not a limit on how long we keep the resulting history.
If your Azure Marketplace subscription is cancelled or expires, or your free trial ends, your tenant data is retained for a 30-day grace period and is then permanently deleted by an automated process. That deletion drops the tenant database schema, and with it all of your platform, job, task, schedule and run-history data, and removes all user account records for your tenant. If you resubscribe or are reinstated during the grace period, the scheduled deletion is cancelled automatically and no data is lost.
Two records survive deletion by design. First, we keep a redacted tenant record containing no personal data, because the organisation name, domain, directory identifier and all purchaser and beneficiary contact details are erased, so that billing and invoicing history we are required to retain for tax and accounting purposes remains coherent. Second, we write an internal deletion log entry as an audit record of the deletion. It holds the tenant and schema identifiers, the organisation name, the reason and the outcome. It contains no individual's name, email address, credentials or operational data.
Deleting data from our live systems does not immediately remove it from backups already taken. We keep two kinds of database backup, and data persists in them for different periods after deletion: short-term point-in-time backups are overwritten on a rolling 35-day cycle, and long-term backup copies (weekly, monthly and annual) expire on their own schedule, so data may remain in a long-term copy for up to twelve months after deletion. We do not edit backups to remove individual records, because altering a backup destroys its integrity as a means of recovering from data loss or a security incident. If we ever restore from a backup taken before a deletion, we re-apply that deletion afterwards.
Telemetry data collected through Application Insights is retained for the period configured in that service (typically 90 days) and is not used to identify you outside the support context.
Depending on your jurisdiction, you have the following eight rights with respect to your personal data:
To exercise any of these rights, contact us at support@polysync.com.au. We will respond within 30 days of receiving a verifiable request. Where we act as a processor on behalf of your organisation, which is the case for the configuration and operational data in your tenant, we will refer your request to that organisation, which is the controller, and assist it in responding.
Where we rely on your consent for a specific purpose, you may withdraw it at any time; withdrawal does not affect processing carried out before you withdrew. Exercising any of these rights is free of charge and will not result in the Service being withdrawn or degraded.
You also have the right to lodge a complaint with a data-protection authority. In Australia this is the Office of the Australian Information Commissioner:
In the European Economic Area or the United Kingdom, you may complain to the supervisory authority in your country of residence, place of work, or the place where the alleged infringement occurred. In the UK this is the Information Commissioner's Office (ico.org.uk). You are not required to contact us first, though we would welcome the chance to resolve your concern directly.
You also have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you. Polysync automates the scheduling and dispatch of the data jobs you configure, but it does not use your personal data to carry out automated decision-making or profiling of this kind within the meaning of Article 22 of the GDPR.
Inside the Polysync application, we use cookies and browser local storage only for purposes that are strictly necessary to operate the Service. We do not use advertising cookies, and no third-party tracking runs in the signed-in application.
Our public marketing pages, meaning the home page and pages such as About, Support, Documentation, and the Azure Marketplace hand-off page, use Google Analytics 4 to measure how people find and move through the site, and how many visitors continue to our Azure Marketplace listing. This helps us understand which content is useful. Google Analytics sets its own cookies and receives your IP address (which Google truncates), page URLs, and approximate location.
Google Analytics does not run on the signed-in application, so your use of the Setup Studio, Monitor, and Copilot is never sent to Google. You can opt out site-wide using the Google Analytics Opt-out Browser Add-on, or by using any browser setting or extension that blocks analytics scripts. Blocking it does not affect the functionality of the site.
Our home page embeds a product demonstration video hosted on YouTube. The
video does not load and YouTube sets no cookies until you click play. When
you do, we use YouTube's privacy-enhanced mode
(youtube-nocookie.com), and your interaction with the player is
governed by
Google's Privacy Policy.
When you connect your own cloud platforms or vaults to Polysync, those services act on your instructions. Their handling of your data is governed by their own privacy notices. Polysync stores only the configuration needed to call them and the reference to the credential held in your chosen vault.
The primary processing region for the Service is Australia East. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with cross-border transfer requirements, your data may be transferred to Australia for processing. We rely on appropriate transfer mechanisms (including the Standard Contractual Clauses adopted by the European Commission and the UK International Data Transfer Addendum) where required.
One exception: the Polysync Copilot. Messages you send to the Copilot may be processed by Microsoft in any Azure region where the underlying model is available, which may be outside Australia and outside your own jurisdiction. The same transfer mechanisms apply, and the Copilot can be turned off entirely as described in Section 5.6. Section 5.1 explains this in full.
Polysync is a business-to-business service and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you through the application or by email.
For privacy enquiries, data-subject requests, or to request a Data Processing Agreement, please contact us:
Polysync has not appointed a Data Protection Officer. We have assessed the criteria in Article 37 of the GDPR and none applies: we are not a public authority, our core activities do not consist of processing that requires regular and systematic monitoring of data subjects on a large scale, and we do not process special categories of data or criminal-offence data on a large scale. Under the Australian Privacy Act we are likewise not required to appoint one.
Responsibility for privacy compliance sits with the Polysync director named below, who is the point of contact for all privacy matters, data-subject requests, and regulator correspondence. We keep this assessment under review and will appoint a Data Protection Officer, and publish their contact details here, if our processing changes such that Article 37 applies.
PRIVACY -Polysync Data Solutions Pty Ltd is established in Australia and has no establishment in the European Economic Area or the United Kingdom. We have not appointed an Article 27 representative, on the basis that our processing of EEA and UK personal data is occasional, is limited to business-contact and service-operation data, is not large-scale, and does not involve special categories of data, which is the exemption in Article 27(2)(a). EEA and UK individuals may contact us directly at the address above, and we will respond in English within the statutory time limits. If our processing ceases to meet that exemption we will appoint a representative and publish their details here.