Data Processing Agreement
1) Scope
This agreement applies whenever Polzy processes personal data on behalf of a customer through the service, and meets Article 28 of the GDPR. The customer is the controller; Polzy B.V. is the processor. It forms part of the Terms of Service and takes precedence over them on anything about personal data. It lasts as long as Polzy processes personal data for the customer.
2) Details of the processing
- Subject matter and purpose: providing Polzy to the customer — collecting feedback through surveys and messages, analysing it with scores, themes and summaries, and the actions, workflows and reports built on it.
- Nature: hosting, storage, analysis (including by AI), sending messages, export and deletion.
- Data subjects: the people the customer invites or adds — employees, customers, event attendees, other respondents — and the customer’s own users.
- Personal data: names, email addresses and phone numbers; the fields the customer defines, such as department or plan; survey answers and comments; messages and their delivery records; sign-in and usage records. The customer decides whether a survey is anonymous.
- Special categories: none are needed for the service, with one exception the customer controls: where safety signals are switched on, a comment a respondent writes may itself reveal data about health or sex life (Art. 9 GDPR) — self-harm or sexual abuse, for example. Polzy processes such a comment only to route it to the reviewers the customer names, on the customer’s instructions and under the customer’s lawful basis (usually Art. 9(2)(b), (c) or (g)). If the customer chooses to ask for special categories in a survey, it is responsible for the lawful basis and for telling respondents.
3) Instructions
Polzy processes personal data only on the customer’s documented instructions, which are the Terms, this agreement and the customer’s use of the product’s settings, unless EU or member-state law requires otherwise — in which case we tell the customer first, unless that law forbids it. If an instruction appears to breach data protection law, we say so before acting on it.
4) Confidentiality
Everyone at Polzy with access to customer data is bound by confidentiality, and access is limited to what their role requires. When Polzy staff open a customer’s workspace to help, the session is recorded in the customer’s audit log.
5) Security measures
Polzy maintains the technical and organisational measures in the annex below and on the Security page, and keeps them under review. We may improve them, but never lower the overall level of protection.
6) Sub-processors
The customer gives general authorisation for the sub-processors in the sub-processor register. We give at least 30 days’ notice by email before adding or replacing one. Within that period the customer may object on reasonable data-protection grounds; if we cannot resolve the objection, the customer may end the affected service and we refund the unused part of any period paid in advance. Every sub-processor is bound by obligations at least as protective as these, and Polzy remains responsible to the customer for its sub-processors’ performance.
7) Assistance
The product lets customers export, correct and delete personal data themselves, and lets respondents delete their own answers to an identified survey from the survey’s privacy notice. Where a request cannot be handled that way, we assist within 30 days. We also give the customer the information it reasonably needs for a data protection impact assessment, a prior consultation with a supervisory authority, or its own security obligations.
8) Personal data breaches
We notify the customer without undue delay, and in any case within 48 hours of becoming aware of a breach affecting their data, at the organisation owner’s email address. The notice says what happened, the categories and approximate number of people and records concerned, the likely consequences, and what we have done and propose to do; what is not yet known follows as soon as it is. We do not notify authorities or data subjects on the customer’s behalf unless it asks us to.
9) International transfers
Customer data is hosted in the European Union (Fly.io, Amsterdam). Where a sub-processor processes data outside the EEA, the transfer is covered by the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework, as listed in the sub-processor register, with additional measures where a transfer assessment calls for them.
10) Deletion and return
The customer can export its data at any time and delete a workspace, or close its organisation, from Settings. The workspace is then read-only for 14 days — everything can still be opened and exported, and the deletion can be cancelled — and is then deleted with everything in it. A closed organisation’s plan stops at the end of the period already paid for and its account is deleted once its last workspace is gone. Issued invoices, and the purchases behind them, are kept for as long as tax law requires. Copies in backups are removed as the backups are replaced, within 35 days (to be confirmed: the backup job is built but not yet running in production). The audit log of what was done in the customer’s workspaces is kept as security evidence until each event’s own 400-day period ends, and is then deleted. On request, we confirm the deletion in writing.
11) Audits
We make available the information needed to demonstrate compliance with this agreement, and answer the customer’s reasonable security questionnaires. Where that is not enough, the customer, or an independent auditor it appoints under a duty of confidentiality, may audit Polzy with at least 30 days’ notice, during business hours and at most once a year — more often if a supervisory authority requires it or after a breach. Each party bears its own costs, unless the audit reveals a material breach by Polzy.
12) Liability
Liability under this agreement is governed by the liability section of the Terms of Service.
13) Annex: technical and organisational measures
- Hosting and isolation: the application, database and job queue run in the EU (Fly.io, Amsterdam) on a private network. Every query is scoped to the workspace it runs in, and every request passes a tenant check that automated tests cover.
- Encryption: TLS for all traffic; storage volumes encrypted at rest (to be confirmed for the database volume); credentials for connected systems and two-step verification secrets encrypted again, with a key kept outside the database, before storage; passwords stored only as hashes.
- Access control: roles inside each workspace; two-step verification with an authenticator app and single-use recovery codes, which an organisation can require for every administrator; a session length and the email domains members may come from, set by each organisation; repeated failed sign-ins lock the account for a while.
- Anonymity by design: anonymous answers are stored without name, email, IP address, browser or invitation; grouped results below the privacy floor are suppressed in the query that computes them, on every filter, export and API call.
- Safety signals (Art. 9 GDPR): a comment that may reveal special categories is encrypted again before storage, with a key kept outside the database; it is read only by the reviewers the customer names — never by the writer’s reporting line, and never by Polzy staff in a customer’s name — and every read is in the audit log; a respondent who asks to be contacted chooses whether the reviewers see their name, and that name and any address are encrypted the same way; dismissed signals are deleted after 90 days and confirmed ones 12 months after they are closed, unless the customer sets another period. Questions go to privacy@polzy.ai.
- Logging and monitoring: an append-only audit log of administrative actions and every access by Polzy staff, kept for 400 days; error tracking in the EU; continuous monitoring and a public status page.
- Availability and backups: daily database backups, encrypted before they leave the server, kept for 35 days, with a quarterly restore test (to be confirmed: built and tested, not yet running in production).
- Data minimisation and retention: answers deleted nightly once past the workspace’s retention period; message text, links and addresses removed after 30 to 365 days; deletion of a workspace after a 14-day read-only period.
- People and suppliers: confidentiality for everyone with access, access limited to what each role needs, sub-processors bound by data processing agreements.
- Incidents and vulnerabilities: breaches notified within 48 hours; vulnerabilities reported to security@polzy.ai are answered within two working days.