Privacy Policy
How Polaris IT & Security Consulting handles information in Secure Document Courier · Effective January 1, 2026 · Version 2026-08-03
1. Our role
For information that a Customer organization or its clients place in the Service, the Customer is the "data controller" and Polaris IT & Security Consulting is a "service provider" / "processor" that handles the information only on the Customer's documented instructions and does not sell it or use it for its own purposes. This policy describes the platform's practices; each Customer may also have its own privacy notice governing its relationship with its clients.
2. Information we process
Account data: name, email address, role, organization, authentication credentials (stored only as salted hashes), and multi-factor settings. Document data: the files you upload and their metadata (filename, size, type, timestamps), stored encrypted. Operational data: audit and security logs recording actions such as sign-in, upload, download, and administrative changes. We do not use advertising or third-party tracking cookies.
3. Why we process it
To provide the Service: authenticating users, delivering documents to the right organization and people, enforcing access controls and retention, securing the platform, keeping audit records, and complying with law. We do not sell personal data and do not use it for targeted advertising or profiling.
4. Sharing
We share information only: within your own organization according to role and assignment; with sub-processors that host or secure the platform under contract; and where required by law or to protect the Service. We do not disclose one organization's data to another — organizations are strictly isolated.
5. Retention
Documents are deleted automatically after the retention window configured by the organization that gave you access (14 days by default; the window in force is shown inside the portal), unless a longer period is legally required or a documented legal hold applies. Signed records are retained for a separately stated legal-records period. Account and audit records are retained as needed to operate the Service and meet legal obligations, then deleted or de-identified.
6. Security
We protect information with envelope encryption at rest, encryption in transit, multi-factor authentication, organization-scoped least-privilege access, and audit logging. See our Security & Data-Handling disclosure for detail.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a portable copy of your personal data, and to opt out of certain processing. Because Polaris IT & Security Consulting usually acts as a processor, please direct requests to the Customer organization that invited you; where Polaris IT & Security Consulting is the controller, contact us at jgonzalez@polarisnitcs.com and we will respond as required by law. Residents of Indiana have rights under the Indiana Consumer Data Protection Act to the extent it applies.
8. Data-breach notification
If a breach of security affecting personal information occurs, we will notify affected Customers without unreasonable delay and support notifications to affected individuals and regulators within the timelines required by law — including, under Indiana law, notice to affected individuals and the Indiana Attorney General within 45 days. Encrypted data whose encryption keys were not compromised may be exempt from notification.
9. Children
The Service is intended for business use and is not directed to children under 13, and we do not knowingly collect their personal data.
10. Changes and contact
We may update this policy; material changes are posted here with a new effective date. Contact: jgonzalez@polarisnitcs.com.