Data Processing Agreement
Last updated: 8 August 2026
This agreement applies where you use Poly to process personal data for which you are the controller — for example, a business account whose staff put customer information into a chat, a workspace, or an agent. It forms part of the Terms of Service.
It is written to Article 28 of the UK and EU GDPR. Where Article 28(3) requires a contract to stipulate something, there is a section below saying what we do about it, in the same words we would use to describe the code.
Where this agreement does not apply
For your own personal use of Poly, you are not a controller and we are not your processor — we are the controller of that data and the Privacy Policy governs it. This document is for the case where you are answerable to someone else for data you put into Poly.
Roles and subject matter
- Controller: you. Processor: Polysystems, Inc.
- Subject matter: providing the Poly platform — chat, agents, workspaces, documents, research, mail and the other surfaces you use.
- Duration: for as long as your account is open, plus the deletion period described below.
- Categories of data subject: whoever you choose to write about. We do not control that and cannot enumerate it for you.
- Categories of personal data: likewise — whatever you submit. Prompts and uploads are free text and free files.
Special category data. Psychological assessment results generated in Psyche are health-adjacent and we treat them as Article 9 special category data. They are processed only on explicit consent, recorded as a psyche_*consent against your account, and withdrawing that consent stops the processing. Do not put other people's special category data into Poly unless you have your own lawful basis for doing so.
(a) We process only on your documented instructions
Your instructions are: this agreement, the Terms, the settings on your account, and the requests you make through the product. We do not process your content for any other purpose.
We do not train models on your content.Prompts and files are sent to model providers to produce a response and are not used to improve anyone's model. Where a provider's own terms would allow training, we use the configuration that switches it off.
If we ever believe an instruction of yours requires us to break the law, we will tell you rather than quietly comply or quietly refuse.
(b) Confidentiality
Everyone at Poly with access to customer content is under a written duty of confidence that survives their leaving. Access is limited to people who need it for support, security or debugging, and is logged.
(c) Security
Measures currently in place:
- TLS in transit; encryption at rest for databases and object storage.
- Authentication by short-lived signed tokens with refresh; API keys stored only as a SHA-256 hash, so a database dump does not yield a usable credential.
- Role and ownership checks on every record — queries are scoped by user or workspace at the database layer, not filtered in the client.
- Wallet keys are never transmitted to us. A seed is encrypted in your browser under a passphrase we have never seen, so wallet compromise is not something a breach of ours can cause.
- Sandboxed, network-isolated, ephemeral execution for user-supplied code.
- Audit logging of security-relevant events, including deletion requests.
We do not currently hold ISO 27001 or SOC 2 certification. If a certificate is a procurement requirement for you, we do not meet it today and would rather you knew now.
(d) Sub-processors
You give general authorisation for us to engage sub-processors. We remain responsible for what they do with your data, and each is bound by terms no weaker than these.
| Category | What they handle |
|---|---|
| Model providers | Prompts and files you send for inference, and the responses |
| Cloud hosting and databases | Everything stored, at rest |
| Object storage and CDN | Uploaded files, generated media |
| Payment processing | Billing identifiers and transaction records. Never card numbers — we never see them |
| Email delivery | Transactional messages, and mail you send through Poly Mail |
| Error and performance monitoring | Diagnostic data, which can incidentally include content in an error |
This list is by category rather than by name, and that is a real limitation. Article 28 contemplates your being told which sub-processors we use so that you can object to one. A categorical list does not let you do that. We publish categories because a named list that goes stale is worse than an honest general one — but if you need names and a change-notification commitment in writing, ask legal@poly.inc and we will provide them for your account.
Local models are not a sub-processor at all. If you run Ollama or OMM on your own machine, those prompts never leave it.
(e) Helping you answer data subjects
Product features do most of this without needing us in the loop: you can export your data, delete individual items, and delete the account outright. Where a request needs something the product cannot do, write to privacy@poly.inc and we will help within the statutory period.
If a data subject contacts us directly about data you control, we will not answer on your behalf — we will point them at you and tell you it happened.
(f) Helping with breaches, impact assessments and consultation
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time rather than waiting for a complete picture. You are the one who has to notify a regulator within 72 hours, so a late notice from us is a failure of ours.
We will give you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority.
(g) Deletion and return
You can export your data at any time from the product, and delete the account from Settings > Account.
Deleting an account marks it deleted immediately and starts a 30-day grace period, during which it can be restored. After 30 days an automated sweep permanently purges the account and its data. Backups age out on their own cycle within the same window.
Two exceptions, and both are limits on what we are able to do rather than choices:
- Billing and tax records are kept for as long as tax law requires — typically seven years.
- Anything written to a public blockchain is permanent and outside anyone's deletion right, including ours. Nothing we do removes it.
(h) Information and audits
We will make available the information you need to verify that we are meeting these obligations, and respond to security questionnaires.
Audit here means answering, not admitting. We do not currently offer on-site inspection or third-party audit access to our infrastructure, and we hold no third-party audit report to offer in its place. Article 28(3)(h) contemplates both; we meet the first half. If your own regulator requires more, tell us before you rely on this document.
International transfers
Poly operates from the United States and our sub-processors are largely US-based, so data from the EEA or the UK is transferred out of it.
We do not have counter-signed Standard Contractual Clauses in place with you, and we have not completed a transfer impact assessment. This is the largest gap in this document and it is stated here rather than buried: if you are exporting EEA or UK personal data and need a documented Chapter V transfer mechanism, we cannot yet give you one. Write to legal@poly.inc before you rely on Poly for that processing.
Agents you publish or sell
If you publish an agent, other people can run it. If you sell one through Poly Credit, buyers' prompts reach your agent and you become a controller or processor of that data in your own right — this agreement does not cover you in that direction. The obligations that would apply to you are set out in the Poly Credit seller agreement.
Liability, order of precedence and changes
The limitations of liability in the Terms apply to this agreement. Where this agreement and the Terms conflict on the processing of personal data, this agreement wins.
We will give notice before changing this document in a way that reduces your protection. Questions: dpo@poly.inc.
Not legally reviewed
This was written from what the software does, by the people who built it, and has not been reviewed by a lawyer. It is offered because an accurate description of our processing is more useful to you than a template describing somebody else's — but have your own counsel read it before relying on it, particularly the transfers section.