Privacy

Privacy Policy

How Polysync collects, uses, stores, and protects your information.

Effective Date: May 1, 2025  ·  Last Updated: May 25, 2026

1

Introduction

Polysync Pty Ltd ("Polysync", "we", "us", or "our") operates the Polysync data pipeline orchestration platform, available as a SaaS application on the Microsoft Azure Marketplace. This Privacy Policy explains what information we collect, why we collect it, how we use and store it, and the choices you have.

We are an Australian company and comply with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth). Where we process the personal data of individuals in the European Economic Area or the United Kingdom, we also act in accordance with the General Data Protection Regulation and the UK GDPR.

By accessing or using Polysync, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not access the Service.

1.1 Our Role: Controller and Processor

Polysync acts as a data controller for the account, billing, and operational data required to provide the Service — for example, the identity claims received when you sign in, Azure Marketplace subscription metadata, run history, audit records, and support communications. For these categories we determine the purposes and means of processing and are responsible for the obligations a controller owes under the GDPR and UK GDPR.

For customer data processed through the cloud platforms you connect, Polysync generally acts as a data processor on behalf of the customer (the data controller). We process that data only on your documented instructions — the jobs, tasks, schedules, and parameter mappings you configure — and we do not determine the purposes for which your connected platforms are used. Where Polysync acts as a processor, the processing is governed by a Data Processing Agreement that incorporates the terms required by Article 28 of the GDPR; you can request one at support@polysync.com.au.

2

Information We Collect

2.1 Account Information

When you sign in via Microsoft Entra ID, we receive the following claims from Microsoft about your identity:

  • Your display name and email address.
  • Your Microsoft Entra ID object identifier (oid) and tenant identifier (tid).
  • Your Polysync tenant assignment and role (Administrator or Operator).

2.2 Configuration Data

Data you provide while using the Service, including platform connection details, job and task definitions, schedules, concurrency profiles, dependency graphs, parameter mappings, and tags. This data is stored in a SQL schema dedicated to your tenant.

2.3 Operational Data

Data the Service generates while operating on your behalf, including run history, run status, dispatcher logs, and audit records of administrative actions. Operational data is stored in the same tenant schema as your configuration data.

2.4 Usage & Telemetry

We collect application telemetry through Microsoft Application Insights to operate the Service, diagnose problems, and improve performance. This may include:

  • Pages requested and features used.
  • Browser type, operating system, and device class.
  • Performance metrics, exceptions, and error stack traces.
  • Session duration and approximate interaction patterns.

Telemetry is associated with your tenant for support purposes but is not used for advertising or sold to third parties.

2.5 Marketplace Subscription Data

When you subscribe through the Azure Marketplace, Microsoft transmits subscription metadata to us so we can provision and manage your tenant. This includes your Azure tenant identifier, plan identifier, term, status, quantity, and the email address of the purchaser. Billing and payment information itself is held by Microsoft and is not shared with Polysync.

2.6 Credentials & Secrets

How platform credentials are handled. Polysync supports two arrangements for credentials used to call the cloud platforms you orchestrate:
  • Bring your own vault. You link your own secret store (Azure Key Vault, AWS Secrets Manager, Google Cloud Secret Manager, or HashiCorp Vault). Polysync stores only a reference to the secret. The secret value is read on demand at dispatch time and is not persisted by Polysync.
  • Managed vault. If you do not link your own vault, Polysync can hold the credential in its managed Azure Key Vault. Access is gated by the same tenant-claims model that protects your other data, and the secret is not exposed to other tenants.
In both arrangements, secret values are not written to the application database and are not retained in application logs.
4

Data Storage & Security

4.1 Hosting

Polysync is hosted on Microsoft Azure. The primary processing region for the production Service is Australia East (Sydney). Disaster-recovery and backup data may be replicated to another Azure region within the same sovereign boundary. If you require deployment in a different region, contact us at support@polysync.com.au.

4.2 Tenant Isolation

Each customer's configuration, operational data, and run history is stored in a dedicated SQL schema. Tenant identity is enforced server-side from identity claims rather than from URL parameters, headers, or client state.

4.3 Encryption

  • In transit. All client and inter-service communication is encrypted using TLS 1.2 or higher.
  • At rest. Application data is encrypted at rest using Azure-managed encryption keys.
  • Secret material. Credentials and other secrets are held in a key vault (your own or our managed Azure Key Vault), not in the application database.

4.4 Access Controls

Access to the application is authenticated exclusively through Microsoft Entra ID. Within Polysync, the Administrator and Operator roles determine what each user can do. Access by Polysync personnel to production systems is limited to authorised staff, logged, and used only to operate the Service and respond to support requests.

5

Sub-Processors

We engage the following sub-processors to provide the Service. Each is bound by contractual obligations to protect the data they process on our behalf.

  • Microsoft Corporation. Azure (hosting, compute, database, storage, Key Vault, Entra ID identity, Application Insights telemetry, and Marketplace subscription management). Processing region: Australia (primary), with the possibility of replication to other Microsoft regions for disaster recovery.

When you connect your own cloud platforms (Azure, Google Cloud, or others as they become supported) through Polysync, those platforms act on your instructions and are governed by their own terms and privacy notices, not by this policy.

We will provide reasonable advance notice of any new sub-processor we intend to engage so that customers subject to a Data Processing Agreement can exercise any objection rights described in that agreement.

6

Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We disclose information only in the following circumstances:

  • Sub-processors. As described in Section 5.
  • Legal requirements. When required by law, regulation, legal process, or a lawful request from an authority with competent jurisdiction, as further described in Section 6.1.
  • Business transfers. In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will give notice before personal data becomes subject to a different privacy policy.
  • With your consent. For any other purpose with your express consent.

6.1 Mandatory Disclosure Required by Law

In limited circumstances we may be legally compelled to disclose personal data — for example, in response to a court order, subpoena, warrant, or a binding request from a law-enforcement, regulatory, or government authority with competent jurisdiction. Where we are compelled to disclose, we will:

  • Limit the disclosure to the personal data we are legally required to provide.
  • Where we are lawfully permitted to do so, notify the affected customer before disclosing, so they can seek to challenge or narrow the request. Some legal processes prohibit us from giving notice, in which case we are unable to inform you.
  • Where the request concerns customer data for which Polysync acts as a data processor, direct the requesting authority to the customer (the data controller) wherever it is lawful and practicable to do so, rather than disclosing the data ourselves.
7

Data Retention

We retain your configuration and operational data for as long as your subscription is active. Run history is retained according to the limits of your subscription plan.

If your Azure Marketplace subscription is cancelled or expires, your tenant data is retained for a 30-day grace period and is then permanently deleted, including the tenant database schema. Backup copies are overwritten on the normal backup-rotation cycle (typically within 35 days of deletion).

Telemetry data collected through Application Insights is retained for the period configured in that service (typically 90 days) and is not used to identify you outside the support context.

8

Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

Access Request a copy of the personal data we hold about you.
Rectification Request correction of inaccurate or incomplete data.
Erasure Request deletion of your personal data, subject to legal obligations.
Portability Receive your data in a structured, machine-readable format.
Objection Object to processing based on legitimate interests.
Restriction Request that we limit the processing of your data.

To exercise any of these rights, contact us at support@polysync.com.au. We will respond within 30 days of receiving a verifiable request.

You also have the right to lodge a complaint with a data-protection authority. In Australia this is the Office of the Australian Information Commissioner (OAIC). In the European Economic Area or the United Kingdom, this is the supervisory authority in your country of residence.

You also have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you. Polysync automates the scheduling and dispatch of the data jobs you configure, but it does not use your personal data to carry out automated decision-making or profiling of this kind within the meaning of Article 22 of the GDPR.

9

Cookies & Local Storage

Polysync uses cookies and browser local storage only for purposes that are strictly necessary to operate the Service. We do not use advertising cookies and do not embed third-party tracking pixels.

  • Authentication cookies. Maintain your signed-in session with Microsoft Entra ID.
  • Anti-forgery tokens. Protect against cross-site request forgery.
  • Theme preference. Remember your light or dark mode choice in local storage.
10

Third-Party Services You Connect

When you connect your own cloud platforms or vaults to Polysync, those services act on your instructions. Their handling of your data is governed by their own privacy notices. Polysync stores only the configuration needed to call them and the reference to the credential held in your chosen vault.

11

International Data Transfers

The primary processing region for the Service is Australia East. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with cross-border transfer requirements, your data may be transferred to Australia for processing. We rely on appropriate transfer mechanisms (including the Standard Contractual Clauses adopted by the European Commission and the UK International Data Transfer Addendum) where required.

12

Children's Privacy

Polysync is a business-to-business service and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete it promptly.

13

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you through the application or by email.

14

Contact Us

For privacy enquiries, data-subject requests, or to request a Data Processing Agreement, please contact us:

Polysync Pty Ltd (Australia)