Terms of Service

Version v1.0 · Effective September 29, 2026

View previous versions

Polaris Terms of Service

Effective date: 1 September 2026 · Last updated: 1 September 2026 · Version: 1.0

Operated by: Hexifyer FZ-LLC

These Terms of Service ("these Terms") form the agreement between you and Hexifyer FZ-LLC for your use of Polaris. They cover the Polaris web application, the Polaris mobile applications, and any Polaris interface you connect to through our MCP surface.

A Polaris subscription belongs to an organisation, not to an individual. Your workspace administrator holds the account-level authority described in Section 3, consistent with the allocation of responsibility for data in our Privacy Policy. Every deletion, retention and turnaround figure in these Terms is the same figure that appears in our Privacy Policy and in the Data Processing Agreement (Schedule 3 to these Terms). If you identify any inconsistency, please notify us. The figure in the Privacy Policy governs.

1. Who we are and how this agreement is formed

Polaris is operated by Hexifyer FZ-LLC, a free zone company registered in Ras Al Khaimah, United Arab Emirates under licence number 47017173, at FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. In these Terms, "Polaris", "we" and "us" mean that company. "You" means the organisation on whose behalf the account is opened.

This agreement is formed when you create a Polaris account or first use the service, whichever occurs first. No signature is required. We record the date, time and account against which these Terms were accepted, and that record constitutes evidence of the agreement between us.

Authority to bind. The person who creates an account warrants that they are authorised to accept these Terms on behalf of their organisation. A Polaris subscription is held at organisation level, and acceptance binds the organisation and not only the individual who accepted.

Age. You must be at least 16 years old to hold a Polaris account. We do not knowingly provide the service to anyone younger. The same minimum age appears in our Privacy Policy.

2. Documents forming the agreement and order of precedence

The following documents also apply, and each governs its own subject matter:

  • Schedule 1, the Acceptable Use Policy, set out below these Terms on the same page, forms part of these Terms and sets the limits on how the service may be used.
  • Schedule 2, the AI Services Addendum, set out below these Terms on the same page, forms part of these Terms and governs the AI features and the credits that meter them.
  • Schedule 3, the Data Processing Agreement, set out below these Terms on the same page, forms part of these Terms and governs personal data we process on your behalf. It includes Standard Contractual Clauses and a security annex, and it is in force for every customer without separate signature.
  • Our Privacy Policy describes how we process personal data. Where the Privacy Policy and these Terms both state a figure, the Privacy Policy governs.

Where a signed order form exists between us, that order form prevails over these Terms to the extent of any conflict. Otherwise these Terms prevail over any content on our website, in our documentation or in our marketing material.

3. Accounts, roles and administrator authority

Polaris organises work in workspaces. A workspace has four roles: owner, administrator, editor and viewer. Content marked confidential is visible only to trusted editors and above.

Administrators act on your behalf. Administrators control who is a member of your workspace, the role each member holds, and what each member can access. When an administrator adds or removes a member, changes a role, disables a feature or deletes a workspace, they do so on your behalf and that action binds you. This reflects the allocation of responsibility in our Privacy Policy: for content inside your workspace, you determine how it is processed and we act on your instructions.

Accordingly, if a member of your workspace asks us to change or delete workspace content, we will refer them to your administrator and will not act on the request ourselves.

Credentials. You are responsible for keeping account credentials secure and for all activity carried out through your members' accounts. Two-factor authentication is available and we recommend that you use it. You must notify us promptly if you believe an account has been compromised.

Email addresses. Members cannot change their own account email address. That change is made by an administrator. You must keep at least one administrator contactable, as notices required by these Terms are given by email to administrators.

Removal of members. When a member is removed from a workspace, their access ends immediately and the seat becomes available for reassignment. The work they created remains in the workspace and belongs to you, not to them. If the removed member has no other workspace, their personal account enters the 14-day grace period described in Section 22 before it is deleted.

4. Scope of the licence

For as long as your subscription is active and paid, we grant you a non-exclusive, non-transferable, non-sublicensable right to use Polaris for your own internal business purposes, within the limits of your plan.

You must not, and must not permit anyone else to:

  • resell, rent, sublicense or otherwise make the service available to anyone outside your organisation, except as a viewer or member of your own workspace;
  • reverse engineer, decompile or attempt to derive the source code, model architecture or prompts behind the service, except to the extent that this restriction is unenforceable in your jurisdiction;
  • use the service, or anything learned from it, to build or train a competing product;
  • circumvent a plan limit, seat cap, credit allowance or rate limit, including by creating multiple accounts;
  • scrape, crawl or bulk-extract data from the service other than through an interface we provide for that purpose;
  • remove or obscure any Polaris notice or branding.

5. Plans, seats and limits

Each plan is subject to the following limits, which form part of these Terms:

LimitFreeProfessionalPremium
Seats52050
ViewersUnlimitedUnlimitedUnlimited
Active projects350Unlimited
Storage500 MB100 GB500 GB
AI credits each month103080

At the seat limit, no further members can be added until a seat is freed or the plan is upgraded. At the project limit, no further projects can be created. At the storage limit, new uploads are blocked. We do not delete stored content to create space, and we do not delete any content because a plan limit has been reached. Assets retain their full version history, which counts towards the storage allowance.

Fair use. We apply rate limits to protect the service, in particular to our MCP surface and to the chatbot. Where practicable, we will contact you before applying any restriction.

6. Changes to the service

We may add, alter or remove features of Polaris, subject to the following:

  • We will not materially reduce the core functionality of the plan you have paid for during the period for which you have paid.
  • If we retire a feature or move it to a higher plan, we will notify workspace administrators at least 30 days before the change takes effect. Moving a feature between plans is a change to this agreement, not only to our pricing, and is subject to the same notice as any other material change under Section 24.

7. Beta and pre-release features

Some features are released as beta, preview or early access. These features are provided as is and without warranty of any kind, may be changed or withdrawn at any time without notice, and are excluded from any commitment in these Terms regarding availability or support. Use of these features for production work is at your own risk, and you should export any content you cannot afford to lose.

8. AI features and credits

The AI Services Addendum (Schedule 2 to these Terms) governs the AI features in detail. The following commercial terms also apply.

Ownership of outputs. Task descriptions, summaries, drafts and any other outputs generated for you by our AI features belong to you, on the same terms as any other content you put into Polaris. AI models may produce similar outputs in response to similar prompts, so outputs may not be unique to you, and we make no representation of exclusivity in them.

Outputs are not advice and are not verified. AI outputs are generated automatically and may be inaccurate, incomplete or out of date. Polaris is designed to keep a person involved in reviewing outputs, and you must review an output before relying on it. Outputs are not professional, legal or financial advice.

No training on your content. Neither we nor the AI providers behind these features use your workspace content to train or improve models. Our providers may retain a request for up to 30 days for trust, safety and abuse monitoring, after which it is deleted. Our Privacy Policy and the sub-processor list in Section 21 of our Privacy Policy state the same, and name the providers and the countries in which they process data.

Credits. AI features are metered in credits. The number of credits an action consumes varies with the size of the work it performs, meaning the amount of text it reads and the amount it generates. A short summary consumes fewer credits than a long one, and the same action may consume different amounts at different times. Your remaining balance, and a breakdown of the credits consumed by each action, are shown on the credit usage page in your workspace.

Your plan includes a monthly allowance, which resets at the start of each billing period. Unused included credits do not roll over and expire at the end of the period. When an allowance is exhausted, AI features are unavailable until the next reset or until you purchase an add-on pack. Add-on credits are consumed only after included credits and expire twelve months from purchase. Credits have no cash value, are not refundable and cannot be transferred between workspaces.

Administrator control. An administrator can disable AI features for the whole workspace. Doing so deletes that workspace's embeddings and assistant chat history, as described in our Privacy Policy. Credits already consumed are not restored, and included credits continue to reset and expire as normal while the features are disabled.

Restrictions. The Acceptable Use Policy (Schedule 1 to these Terms) sets out the restrictions on use of the AI features, including prohibitions on prompt injection, on attempting to extract training data or another workspace's content, and on using outputs to build a competing model.

9. Third-party integrations

You may connect Polaris to services we do not control, including federated sign-in, integrations and external AI clients on our MCP surface. Any such connection is made at your own risk and is subject to the relevant provider's terms and privacy policy. We are not responsible for what a third-party service does with data you direct to it, and connecting a third-party service may result in content leaving Polaris. If a third party changes or withdraws its interface, the integration may stop working, and this does not constitute a failure of the service under these Terms.

10. Fees and billing

Fees are charged per seat, per billing period, at the price shown when you subscribe.

  • Seats. A seat is any workspace member with the owner, administrator or editor role. Viewers do not consume a seat and are not charged.
  • Seats added during a period are charged pro rata for the remainder of that period. Seats removed during a period free capacity immediately but are not refunded or credited for that period. The reduced seat count applies from the next renewal.
  • Payments are processed by Stripe. We do not see or store your card details. You authorise us to charge your saved payment method for fees, add-ons and applicable tax as they fall due.
  • Price changes take effect at your next renewal, and we will notify workspace administrators at least 30 days in advance. If you do not accept the new price, you may cancel before that renewal.

11. Currency, tax and invoicing

Currency. Fees are billed in US dollars. Where we offer another billing currency for your country, the currency is set when you subscribe and cannot be changed for the current term.

Tax. All prices are exclusive of value added tax and any other sales, use or withholding tax. Where we are required to collect tax on a sale to you, it is added at checkout and shown on your invoice.

Business customers. If you are registered for VAT, you must provide your tax registration number when you subscribe and keep it accurate. Where the law of your country applies a reverse charge to a supply from us, you are responsible for accounting for that tax. You are responsible for the accuracy of the number you provide and for any assessment resulting from an incorrect number. Payments to us are made without deduction or withholding. If a withholding is required by law, you will gross up the payment so that we receive the amount we would have received without it.

Invoices. We issue an invoice for each billing period to the administrator's billing contact, in the form required by the tax rules applicable to the sale. Invoices are retained for the statutory period and therefore remain after deletion of your workspace, as described in our Privacy Policy.

12. Renewal, upgrades and downgrades

Your subscription renews automatically at the end of each billing period, at the then-current price, until you cancel. No further authorisation is required for us to take the renewal payment.

Cancellation. You may cancel at any time from your workspace billing settings. Cancellation takes effect at the end of the period already paid for. You retain access until then, and no proration or refund is given for the unused part of the period.

Upgrades take effect immediately, and the difference is charged pro rata for the remainder of the period.

Downgrades take effect at the end of the current period, and no refund is given for the current period. Where you then hold more projects than the lower plan allows, the projects beyond the limit are locked, not deleted. They remain in your workspace, read-only, until you upgrade again or archive enough projects to come within the limit. The same applies to seats and storage. We do not delete your content because of a downgrade or because your workspace is inactive.

13. Failed payment and suspension

If a payment fails, our payment processor retries it over a period of time, and we email your administrator each time an attempt fails. Access to paid features follows your payment status automatically, and a workspace may lose paid features while a payment is outstanding. Before cancelling a subscription for non-payment, we send a final notice to the administrator.

If all attempts fail, the subscription is cancelled and the workspace reverts to the Free plan, with projects locked as described in Section 12. Non-payment does not result in deletion of your content. Your data remains in the workspace and remains exportable.

Independently of non-payment, we may suspend access immediately where use breaches the Acceptable Use Policy (Schedule 1 to these Terms), where use threatens the security or stability of the service, or where the law requires it. We will inform you of the reason and restore access when the cause is resolved.

14. Refunds, cancellation and the free trial

30-day money-back guarantee. If you notify us within 30 days of your first paid subscription, we will refund that payment in full. The guarantee is available once per organisation. It applies to a first subscription only, and not to a renewal, an upgrade or an add-on credit pack. Add-on packs are refundable only if unused.

After those 30 days, fees are not refundable. We do not refund or prorate the unused part of a billing period after cancellation, a downgrade, the removal of seats, or a period in which you did not use the service. Cancellation stops the next renewal and does not result in a refund for the current period.

Nothing in this Section removes a right to a refund that the law of your place of residence gives you and does not allow to be excluded by contract. Section 23 sets out how those rights apply.

Premium trial. New workspaces may use Premium free of charge for 14 days. No card is required to start the trial. When the trial ends, the workspace moves to the Free plan unless you subscribe. Your content is not deleted: projects beyond the Free limit are locked as described in Section 12, and Premium features cease. Trials are limited to one per organisation, are excluded from any availability or support commitment, and may be shortened or withdrawn for a workspace we believe is abusing them.

15. Your content and our licence to operate the service

All content you put into Polaris remains your property. This includes Second Brain captures, tasks and subtasks, comments, meeting notes, time logs, topics, custom field values, uploaded files and every version of them. We claim no ownership in any of it.

You grant us a non-exclusive, worldwide, royalty-free licence to host, store, copy, transmit, display and process your content only to the extent necessary to provide, secure and support the service for you, including processing it through the AI features you choose to use, and including the backups and disaster-recovery copies described in our Privacy Policy. The licence covers nothing else. It does not permit us to use your content to train models, to market to your members, to build datasets, or to show your content to anyone you have not given access to. The licence ends when your content is deleted, subject only to the backup and audit periods stated in Section 22.

Datasets and competing products. You must not build, train or compile a dataset, model or competing product from Polaris, from its output, or from data we make available to you, for commercial exploitation or for release, sale or disclosure outside your organisation. This does not restrict your own internal analysis or internal reporting on your own workspace content, which remains yours to use as you see fit. This restriction is separate from, and does not conflict with, our limited right to generate de-identified, aggregated data for internal telemetry and service improvement under clause 4 of the Data Processing Agreement (Schedule 3 to these Terms).

Your warranties regarding content. You warrant that you hold the rights necessary to put your content into Polaris and to permit us to process it as described above, and that your content does not infringe the rights of any third party or breach any law. Where your content includes material belonging to your own clients, such as code, designs, briefs or credentials, which may be subject to your contracts with those clients, the decision to put that material into Polaris is yours.

Hosting location. Polaris is hosted in Germany. Personal data you put into your workspace is therefore transferred out of the country in which you are located at the time you create it. Clause 14 of the Data Processing Agreement (Schedule 3 to these Terms) sets out the consequences: as between us, you are the exporter of that data, and obtaining any authorisation your own law requires for that transfer is your responsibility and not ours. This is an acknowledgement of where responsibility lies and not a warranty given by you to us. It is not subject to the indemnity in Section 21, and the absence of any local approval is not a breach of this agreement. It does not extend to your account and billing data, which we collect for our own purposes and for which we are responsible.

16. Our intellectual property and feedback

Polaris, including the software, interfaces, documentation, name and logo and all other materials we provide, remains our property, together with all intellectual property rights in it. These Terms grant you a right to use the service and nothing more.

Feedback. We may use any feedback or feature requests you send us freely, without obligation, payment or attribution, and feedback does not become your confidential information. This does not affect ownership of your content: a feature request is feedback, but the project data it describes is not.

Aggregated statistics. We may compile aggregated, de-identified statistics about how the service is used (such as feature adoption, performance and error rates) and use them to operate, secure and improve Polaris. These statistics are used internally only. We do not publish them, share them with or sell them to any third party, or use them in marketing, benchmarking reports or any other external material. They are derived from how the product is used and not from content within it, they never identify you, your members or your content, and this provision does not grant any right to use your content for any purpose. Clause 4 of the Data Processing Agreement (Schedule 3 to these Terms) sets out the same limits in full and governs in the event of any difference.

17. Acceptable use

The Acceptable Use Policy (Schedule 1 to these Terms) forms part of this agreement and applies to everyone who uses your workspace. It covers unlawful and infringing content, malware, attempts to gain unauthorised access, spam, excessive load, reselling or sharing access, and the AI-specific restrictions referred to in Section 8.

The Acceptable Use Policy may be updated separately from the rest of these Terms to address new forms of abuse. Material changes to it are subject to the same 30 days' notice as a material change to these Terms. If your workspace breaches it, we may act under Section 13, up to and including immediate suspension.

Removal of content. Where content breaches the Acceptable Use Policy, or the law requires us to take it down, we may remove or disable that specific content. This is the only circumstance in which we remove content you have put into Polaris, and it does not affect Section 22 regarding the non-deletion of your content for reasons of plan, payment or inactivity. When we remove or disable content, we inform your administrator of what was removed and why. The Acceptable Use Policy provides your administrator with a route to appeal any action we take, including such a removal.

18. Confidentiality and publicity

Each party may receive confidential information of the other. Each party agrees to use the other's confidential information only to perform this agreement, to protect it with at least the same care it applies to its own confidential information, and not to disclose it except to persons who need it and are bound by equivalent obligations. Your content is your confidential information for as long as you hold it in Polaris. This obligation does not apply to information that is public through no fault of the recipient, was already known to the recipient, or was independently developed, and it does not prevent a disclosure required by law. Where we are lawfully permitted to notify you before such a disclosure, we will do so.

Publicity. We will not use your name, logo or a description of your business in our marketing without your written consent. If you give consent, you may withdraw it, and we will then cease using it in new material.

19. Warranties, disclaimers and service levels

We warrant that the service will perform materially as described in our published documentation and that we will provide it with reasonable skill and care. If it does not, you must notify us and we will remedy the issue. This is your remedy for a breach of this warranty.

Except for that warranty, and to the fullest extent permitted by law, the service is provided as is. We disclaim all other warranties, express or implied, including warranties of merchantability, fitness for a particular purpose and non-infringement. We do not warrant that the service will be uninterrupted or error-free, that it will meet your requirements, or that AI outputs will be accurate.

We do not offer a financial service level agreement and do not commit to an uptime percentage. No uptime guarantee is given and no service credits are payable. We publish live and historical uptime on our public status page, design the service for reliability, and give advance notice of planned maintenance where practicable.

Support. Support is provided by email to support@hexifyer.com. Our business hours are Sunday to Thursday, 09:00 to 18:00 Gulf Standard Time (UTC+4), and we target a first reply within 24 hours during those hours. On paid plans, "priority support" and "dedicated support" mean that your request is placed ahead of Free-plan requests in the same queue. A response target is not a resolution time and is not a service level. No credits or refunds are payable if a response target is missed.

20. Limitation of liability

Neither party is liable for indirect, incidental, special or consequential loss, or for loss of profits, revenue, business or goodwill, or the cost of substitute services, even if the loss was foreseeable.

Each party's total liability under this agreement is limited to the greater of the fees you paid or owed us in the twelve months before the claim, or USD 100.

This limit does not apply to: your obligation to pay fees; either party's indemnity obligations under Section 21; a breach of the Acceptable Use Policy; either party's fraud or wilful misconduct; or any liability that cannot lawfully be limited.

21. Indemnities

You will defend us against, and indemnify us for, any third-party claim arising from your content, from your use of the service in breach of these Terms or the Acceptable Use Policy, or from your breach of the warranties in Section 15 regarding the rights you hold in your content.

We do not currently provide an intellectual property indemnity for the service itself. If a third party claims that Polaris as supplied by us infringes their rights, we will, at our own cost, do one of the following: obtain the right for you to continue using it, modify it so that the claim no longer applies, or terminate the affected subscription and refund the unused portion of any prepaid fees.

The indemnified party must notify the other party promptly, allow the other party to control the defence, and cooperate reasonably. Neither party may settle a claim in a way that admits the other party's liability without that party's consent.

22. Term, termination and your data

Term. This agreement continues for as long as you have a Polaris account. Your subscription term is the billing period you selected, renewing as described in Section 12.

Termination. You may cancel at any time, with effect from the end of the current period. Either party may terminate for a material breach that is not remedied within 30 days of written notice. We may suspend or terminate immediately for a breach of the Acceptable Use Policy, for non-payment after the final notice described in Section 13, or where the law requires it. We may also close a Free workspace that has been inactive. Closure of an inactive workspace does not mean that we delete its content on our own initiative, as set out below.

Export of your data. You may export your workspace at any time while it exists. We do not delete your content when a subscription ends, when a payment fails or when a workspace is inactive, and ending your subscription does not start any deadline for export. The workspace reverts to the Free plan and your data remains in place.

Once deletion of a workspace has been initiated, export is no longer available. You must request and receive the export before initiating deletion. The in-app deletion flow states this before you confirm.

Export requests may be sent to privacy@hexifyer.com, and we will deliver the export within 5 working days. The export is provided as a single archive containing a CSV file per entity type, with each row carrying its own key and its parent's key so that the structure of your workspace is preserved; your files in their original formats with a manifest; and a README stating the export date, the entity types included and anything excluded. Archived content is included.

Individual rights are not affected. The rule above applies to export of a whole workspace. An individual may request a copy of their own personal data at any time, including after deletion of a workspace has been initiated, and we handle such requests under our Privacy Policy within the deadlines stated there.

Deletion. The following periods are the same as those in our Privacy Policy:

  • Deleted items remain in trash for 30 days, during which they can be restored.
  • A deleted workspace or account enters a 14-day grace period, during which the deletion can be cancelled and the workspace or account restored. An export cannot be restored: cancelling a deletion restores your workspace, but an export that was not requested before deletion was initiated cannot be produced.
  • Deletion from our live systems is completed within 72 hours after the grace period ends.
  • Copies remain in encrypted backups for up to 14 days after that and are then removed. Backups are not restored to fulfil a request.
  • After deletion of a workspace, only invoices we are required by law to retain and 12 months of audit records are kept.
  • We do not delete your content for inactivity, for a downgrade or for non-payment. If any of these figures differ from our Privacy Policy, the Privacy Policy governs.

Survival. Sections 11 (tax and invoicing, as to amounts already due), 15 (your ownership), 16, 18, 20, 21, 23 and 24, and any accrued payment obligation, survive termination.

23. Governing law, disputes and language

This agreement is governed by the laws of the Dubai International Financial Centre, and the DIFC Courts have exclusive jurisdiction over any dispute arising from it. Before commencing proceedings, each party agrees to raise the matter in writing and to attempt in good faith, for 30 days, to resolve it.

Mandatory local rights. Nothing in this agreement removes a right that the law of your place of residence gives you and does not allow to be excluded by contract. If you are a consumer, those rights apply in addition to these Terms, and they prevail over any conflicting provision of these Terms.

Data protection law. The choice of law above governs this contract. It does not determine which data protection law applies to your personal data. That depends on where you and your members are located, and is addressed in our Privacy Policy and in the Data Processing Agreement (Schedule 3 to these Terms).

Language. These Terms are published in English and Arabic. In the event of any conflict between the two versions, the English version governs.

Sanctions and export controls. You warrant that you, your organisation and your members are not subject to any applicable sanctions regime and are not located in a country subject to comprehensive sanctions, and that you will not make the service available to anyone who is. We may suspend or terminate immediately if this ceases to be true.

24. Changes to these Terms, notices and general provisions

Changes. We may amend these Terms. A material change (a new obligation on you, a reduction in our commitments, a change to fees outside the mechanism in Section 10, or a change to how termination or deletion works) is announced at least 30 days before it takes effect, by email to workspace administrators and by notice in the product. Continued use of Polaris after that date constitutes acceptance. If you do not accept the change, you may cancel before it takes effect. All other changes (such as clarifications, corrections and rewording that does not change our practices) take effect on publication, and the last-updated date is changed. Previous versions are kept in a public archive, showing the wording of these Terms on any given date.

Notices. We give notice by email to your workspace administrators or in the product. You are responsible for keeping an administrator email address current. You give notice to us at support@hexifyer.com, or at privacy@hexifyer.com for matters relating to personal data.

Assignment. Neither party may assign this agreement without the other party's consent, except that either party may assign it in whole to a successor in a merger, acquisition or sale of substantially all assets, on notice.

Force majeure. Neither party is liable for a failure to perform caused by events beyond its reasonable control, including infrastructure or network failure at a provider, natural disaster, war or government action. This does not excuse any payment obligation.

General. If any provision is unenforceable, the remaining provisions continue in effect and that provision is limited to the minimum extent necessary. Failure to enforce a right is not a waiver of it. Nothing in these Terms creates a partnership, agency or employment relationship. These Terms, together with the documents listed in Section 2, constitute the entire agreement between us regarding the service and supersede all prior statements.

Schedule 1: Acceptable Use Policy

This Schedule forms part of the Polaris Terms of Service and sets out the uses of Polaris that are prohibited.

This Schedule applies to everyone who uses a Polaris workspace: the organisation that holds the subscription, its administrators, its members, its viewers, and anyone acting through an integration or an external client connected to a workspace. The subscription holder is responsible for its members' use of Polaris and for the actions of anything it connects to Polaris on its behalf.

1. Prohibited content

You must not upload, store, generate or share content that:

  • is unlawful where you are, where we are, or where the people it concerns are;
  • infringes another person's copyright, trademark, trade secret, patent or other right, including material you received under a contract that does not permit you to place it in a third-party tool;
  • sexually exploits or endangers a child, in any form;
  • harasses, threatens, defames or incites violence against a person or group;
  • contains malware, exploit code, or anything designed to damage or gain unauthorised access to a system;
  • you have no lawful basis to hold, including special-category personal data, payment card numbers, government identifiers or credentials belonging to other people. Polaris is not designed or certified to hold such data.

2. Security and third-party systems

You must not:

  • access, or attempt to access, a workspace, account, project or confidential topic to which you have not been given access;
  • probe, scan or test the security of the service, or circumvent any authentication, rate limit or permission check;
  • reverse engineer, decompile or attempt to derive the source code, model architecture or prompts underlying the service;
  • use Polaris to attack, overload or gain unauthorised access to any system outside it;
  • share, sell or publish credentials, session tokens or API keys, whether your own or another person's.

Security vulnerabilities must be reported to support@hexifyer.com, and we must be given a reasonable opportunity to remediate a vulnerability before it is disclosed to anyone else. We will not pursue any person who reports a vulnerability in good faith and does not exploit it, access other people's data, or disrupt the service.

3. Load, rate limits and automated access

The service is subject to rate limits, which apply in particular to our MCP surface and to the chatbot. You must not circumvent those limits, run automation designed to consume the maximum available capacity, or generate load that degrades the service for other customers.

Automated access is permitted only through an interface we provide for that purpose. Scraping or bulk extraction through the ordinary user interface is not permitted. Bulk export of your data is available through the export function described in these Terms.

4. Sharing, reselling and seat sharing

Each seat is for one person. You must not share a single account between several people, share credentials to remain within a seat cap, or create multiple accounts or workspaces to circumvent a plan limit.

The Premium trial and the 30-day money-back guarantee are each available once per organisation. Creating a new account, workspace or organisation in order to obtain either of them again, or repeatedly, is a breach of this Schedule. An organisation that requires a longer evaluation period may contact us to request an extension of its trial.

You must not resell, rent or sublicense access to Polaris, or make it available to anyone outside your organisation other than as a member or viewer of your own workspace. Adding a client as a viewer is permitted. Providing access to multiple clients through one shared login is not.

5. Messages sent through Polaris

Certain Polaris features send email, including invitations, notifications and meeting invites. You must not use them to send unsolicited bulk messages, marketing to people who have not requested it, phishing, or any message that misrepresents the identity of the sender. Workspace invitations may be sent only to people who work with you and must not be used as a means of contacting people for other purposes.

6. AI features

In addition to the restrictions above, when using the AI features you must not:

  • attempt prompt injection, meaning the placing of instructions in content so that the assistant behaves in a way its operator did not intend;
  • attempt to extract training data, model weights, system prompts, or another workspace's content through the assistant;
  • use outputs to train, fine-tune, benchmark or build a competing model or a competing product;
  • use the AI features to generate content prohibited by paragraph 1, or to produce material designed to deceive a person about who or what they are dealing with;
  • present an AI output as reviewed human work where another person is relying on it having been reviewed, or remove human review from a process that depends on it;
  • use an AI output as the basis for a decision with a legal or similarly significant effect on a person (hiring, firing, pay, discipline, credit, insurance, housing, or access to a service) without a person reviewing it first. Polaris is not a decision system, and, as stated in Section 8 of these Terms, outputs may be inaccurate.

Under paragraph 2 of the AI Services Addendum (Schedule 2 to the Terms), we do not train models on your content, and where a request reaches an AI provider it is retained for no more than 30 days for trust, safety and abuse monitoring and then deleted. AI requests are sent only to the providers named in the sub-processor list in Section 21 of our Privacy Policy.

An administrator can disable the AI features for an entire workspace. Paragraph 6 of the AI Services Addendum (Schedule 2 to the Terms) sets out what happens to existing AI data when the features are disabled.

7. Monitoring

We do not read or scan your workspace content. We do not review it for compliance with this Schedule, we run no automated scanning or classification over it to detect breaches, and nothing in this Schedule obliges us to do so. We hold operational data only: service logs, rate-limit and abuse signals, and audit records, retained for the periods stated in our Privacy Policy.

We act under this Schedule when a matter is reported to us, when an abuse signal is triggered, or when required by law. Where investigating a report requires access to specific content, we access only the content the report concerns, and we record that access.

When you use an AI feature, your request is sent to an AI provider, which may retain it for up to 30 days for its own trust, safety and abuse monitoring before deleting it. That monitoring is carried out by the provider and not by us. Our Privacy Policy names the providers and the locations in which they process data. This does not alter the rule that Polaris does not read your workspace content.

8. Enforcement

Where use of Polaris breaches this Schedule, we may, in proportion to the breach:

  • contact the workspace administrator and request that the breach be remedied;
  • restrict or disable a feature, an integration, or a specific member's access;
  • suspend the workspace immediately, under Section 13 of these Terms, where the breach threatens the security or stability of the service, harms another customer, or the law requires it;
  • remove or disable the specific content that breaches paragraph 1, or that we are legally required to remove;
  • terminate the agreement under Section 22 of these Terms for a material breach that is not remedied;
  • report the matter to a regulator or law enforcement authority where we are obliged to do so, or where the content concerns the safety of a child.

Removal of content. We remove content only where it breaches paragraph 1 or where the law requires its removal. Polaris does not remove content because a plan limit was reached, because a subscription ended, or because a workspace became inactive, and this paragraph is the only exception to that rule. Where we remove content, we notify the workspace administrator of what was removed and why, unless prohibited by law, and we keep a record of the removal. We do not remove more than the breach requires.

We will state the reason for any action we take, unless prohibited by law, and will restore access once the cause has been resolved. Suspension does not in itself delete any data: your data remains in the workspace and remains exportable as described in these Terms.

9. Appeals

If we restrict a feature, suspend a workspace, terminate an agreement or remove content, the workspace administrator may request a review of the decision. The request must be made within 90 days of the decision, either by replying to our notice or by writing to support@hexifyer.com with APPEAL at the start of the subject line, and must state the grounds on which the decision is disputed.

  • The review is carried out by a person who was not involved in the original decision.
  • We respond with a decision and our reasons: the action is upheld, reversed, or replaced with a lesser action.
  • Where the original decision is found to be wrong, we restore the access or content concerned and confirm this to you.

An appeal does not suspend the action under review, unless the matter can safely be left as it is pending the review. Where the law requires us to act, or where the content concerns the safety of a child, we may be unable to reverse the action, but we will still provide a decision and the reason for it.

10. Reporting

Reports of abuse, infringing content or a security vulnerability should be sent to support@hexifyer.com, stating what was observed, where and when. A link and a timestamp are usually sufficient. A report of infringement must identify the material, state the right held by the person reporting, and confirm that the report is made in good faith.

We acknowledge reports within 24 hours during our business hours (Sunday to Thursday, 09:00 to 18:00 Gulf Standard Time (UTC+4)) and notify the person reporting of the outcome once we have acted. Where a report concerns a workspace of which the person reporting is not a member, we cannot disclose its contents, only the action we took.

Urgent reports. Put URGENT at the start of the subject line if the report concerns:

  • content that sexually exploits or endangers a child;
  • a credible, immediate threat to a person's safety;
  • content whose continued availability is itself unlawful;
  • an active security compromise, such as a breach in progress, leaked credentials, or unauthorised access to a workspace.

Urgent reports are escalated outside business hours, including on Friday and Saturday, and are acted on as soon as they have been seen rather than at the start of the next business day. All other reports are subject to the 24-hour target above. If you are unsure whether a report is urgent, mark it URGENT.

11. Copyright complaints

If you believe that material in Polaris infringes a copyright you own or represent, write to support@hexifyer.com with COPYRIGHT at the start of the subject line, and include:

  • identification of the copyrighted work;
  • identification of the infringing material and its location, by a link or sufficient detail for us to locate it;
  • your name, address, telephone number and email address;
  • a statement that you believe in good faith that the use is not authorised by the owner, its agent, or the law;
  • a statement that the information in your notice is accurate, and that you are the owner or are authorised to act on the owner's behalf;
  • your physical or electronic signature.

Our response. We review each notice. Where the claim is clear, we remove or disable the material and notify the workspace administrator of what was removed, why, and who made the complaint. Where the claim is not clear, we may request further information before acting.

Counter-notices. The workspace whose material was removed may send us a counter-notice that identifies the material and its former location, states a good-faith belief that it was removed by mistake or misidentification, gives contact details, and is signed. We forward the counter-notice to the complainant. If the complainant does not notify us within 10 working days that it has commenced legal proceedings, we may restore the material.

Repeat infringers. Where a workspace is the subject of repeated, substantiated copyright complaints, we terminate its account. Such a termination is otherwise subject to the appeal process in paragraph 9.

12. Changes to this Schedule

A material change to this Schedule (a new restriction on how you may use the service, or a new enforcement power) is announced at least 30 days before it takes effect, by email to workspace administrators and by a notice in the product. Clarifications and corrections take effect on publication, and the last-updated date is changed. Previous versions are kept in a public archive.

Schedule 2: AI Services Addendum

This Schedule forms part of the Polaris Terms of Service and governs the AI features in Polaris.

This Schedule is incorporated into these Terms by reference and applies whenever anyone in your workspace uses an AI feature. Where this Schedule and the rest of these Terms both address a matter, this Schedule governs in relation to AI features. Where this Schedule and our Privacy Policy both state a figure, the Privacy Policy governs.

1. The AI features

The AI features are the parts of Polaris that use a language model to read or generate text on your behalf: the assistant, drafting and summarising, meeting notes, and the classification and routing that support them. They are metered in credits, as described in paragraph 5.

The AI features are available on every plan, in different amounts. An administrator can disable them for an entire workspace, with the consequences set out in paragraph 6.

2. Our commitments

We do not train models on your content. Neither we nor the providers of these features use your workspace content (your captures, tasks, comments, meeting notes, files or assistant conversations) to train, fine-tune or improve any model, whether our own or a provider's, including in aggregate form.

Requests are retained for no more than 30 days, and only for safety purposes. A provider processing one of your requests may retain it for up to 30 days for trust, safety and abuse monitoring, after which it is deleted. The retained request is used only to investigate misuse of the provider's service and for no other purpose. This period is the same as that stated in our Privacy Policy and in the sub-processor list in Section 21 of our Privacy Policy.

These commitments are made by us to you. We enforce them against our providers contractually and through configuration, and we publish the providers we use. The commitments are not affected by any change a provider makes to its own terms.

3. Where requests are sent

The sub-processor list in Section 21 of our Privacy Policy names every AI provider we use, the function each performs, and the country in which it processes data. All of them currently process data in the United States. That list is the authoritative list of providers. It is updated independently of this Schedule, and you may subscribe to changes and object to a new sub-processor as described in our Privacy Policy.

Requests are sent only to the providers in that list. Our routing is restricted to those providers, and automatic fallback to any other provider is not permitted. A new provider is added to the sub-processor list, with notice, before it receives any request.

All other matters concerning the location of your data (the region, the stores and the backups) are set out in our Privacy Policy and are not affected by the use of AI features.

4. Your content in the AI features

Use of an AI feature involves sending part of your workspace content to a provider for processing. Only the content the action requires is sent: the task you asked about, the meeting you asked to summarise, and the surrounding context the assistant needs to respond.

The licence you grant us under Section 15 of these Terms covers this processing and nothing further. It permits us to process your content to provide the service, including through AI. It does not permit us to use your content for training, to build datasets, or to disclose it to anyone who does not already have access to it in your workspace.

Permissions continue to apply. The assistant responds only from content that the person asking already has access to. It does not access projects to which that person has no access, and content in confidential topics remains restricted to trusted editors and above, as elsewhere in Polaris.

5. Credits

AI features are metered in credits. The number of credits an action consumes varies with the size of the work it performs, meaning the amount of text it reads and the amount it generates. A short summary consumes fewer credits than a long one, and the same action may consume different amounts at different times. Your remaining balance, and a breakdown of the credits consumed by each action, are shown on the credit usage page in your workspace.

ItemTerms
Monthly allowanceIncluded with your plan (10 on Free, 30 on Professional, 80 on Premium) and reset at the start of each billing period.
RolloverNone. Unused included credits expire at the end of the period in which they were granted.
Exhausted creditsAI features stop until the next reset, or until you purchase an add-on pack. No other part of your workspace is affected.
Add-on packsPurchased separately, consumed only after your included credits, and expire twelve months from purchase.
RestrictionsCredits have no cash value, cannot be transferred between workspaces, and cannot be exchanged for anything else.

Used credits are not refundable. This applies even where you claim the 30-day money-back guarantee under Section 14 of these Terms: that guarantee refunds your subscription payment in full, and credits already consumed are not separately refunded, credited or carried over. An unused add-on pack is refundable. An add-on pack that has been partly used is not.

If credits are metered incorrectly (for example, an action that failed but was charged, or a defect that consumed an allowance), notify us and we will correct it. Such a correction is not a refund.

6. Disabling AI features

An administrator can disable the AI features for the entire workspace. When the features are disabled:

  • they stop immediately for everyone in the workspace;
  • the workspace's embeddings and assistant chat history are deleted;
  • credits already consumed are not restored, and included credits continue to reset and expire as normal while the features are disabled;
  • no other content in the workspace is affected, and captures, tasks, comments, meetings and files remain unchanged.

Deletion follows the same timings as any other deletion in Polaris. The data is removed from our live systems within 72 hours, and copies in encrypted backups expire within 14 days after that and are not restored to serve a request. Section 9 of our Privacy Policy is the source of both figures and governs in the event of any inconsistency.

7. Outputs: ownership and responsibility

You own the outputs the AI features produce for you. As between you and us, an output such as a drafted task description, a summary or a set of meeting notes belongs to you, on the same terms as all other content you place in Polaris. We claim no ownership of outputs and assert no licence over them beyond what Section 15 of these Terms requires to operate the service.

Outputs may not be unique. Models produce similar responses to similar prompts. Another customer may receive a materially similar output, and we give no assurance of exclusivity or originality.

Outputs are provided as is. To the fullest extent permitted by law, we disclaim all warranties in relation to outputs, including as to accuracy, completeness, currency, reliability, fitness for a particular purpose and non-infringement. An AI output may be inaccurate. You must review an output before relying on it, and must not treat any output as professional, legal, medical or financial advice.

You are responsible for your use of outputs. As owner of an output, you bear legal responsibility for it, including for any claim that an output infringes copyright or other rights, and for the consequences of any decision taken on the basis of it. The indemnity in Section 21 of these Terms applies to outputs as it applies to the rest of your content. We do not provide an intellectual property indemnity for AI outputs.

Under paragraph 6 of the Acceptable Use Policy (Schedule 1 to the Terms), an AI output must not be the basis of a decision with a legal or similarly significant effect on a person (hiring, firing, pay, discipline, credit, insurance, housing, or access to a service) without a person reviewing it first.

8. Restrictions

The restrictions on use of the AI features are set out in paragraph 6 of the Acceptable Use Policy (Schedule 1 to the Terms). They prohibit prompt injection; attempts to extract training data, model weights, system prompts or another workspace's content; use of outputs to train, benchmark or build a competing model or product; generation of content prohibited by paragraph 1 of the Acceptable Use Policy; and use of an output for a consequential decision about a person without human review.

A breach of those restrictions is a breach of these Terms, and Section 13 of these Terms applies, up to and including immediate suspension.

9. Changes to this Schedule

A material change to this Schedule (a weakening of a commitment in paragraph 2, a new restriction, or a change to how credits are consumed or expire) is announced at least 30 days before it takes effect, by email to workspace administrators and by a notice in the product. Clarifications and corrections take effect on publication, and the last-updated date is changed. Previous versions are kept in a public archive.

The addition or replacement of an AI provider is a change to the sub-processor list in Section 21 of our Privacy Policy, not to this Schedule, and follows the notice and objection process described in Section 7 of our Privacy Policy.

Schedule 3: Data Processing Agreement

This Data Processing Agreement (the DPA) forms part of these Terms, which incorporate it by reference. It is in force for every customer from the moment these Terms are accepted, without signature.

This DPA governs the personal data that Polaris processes on your organisation's behalf. Data in Polaris falls into two categories. For the content inside your workspace, which we hold on your instructions and for no purpose of our own, your organisation is the controller and Polaris is the processor. For your account and billing records, Polaris is the controller, and our Privacy Policy is the disclosure for that data. This DPA governs the first category. Where this DPA and the Privacy Policy both state a figure, the Privacy Policy governs.

1. Formation and parties

Polaris is operated by Hexifyer FZ-LLC, a free zone company registered in Ras Al Khaimah, United Arab Emirates under licence number 47017173, at FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. In this DPA, “Polaris”, “we” and “us” mean that company. “You” means the organisation on whose behalf the workspace is held, being the organisation that accepted these Terms.

Formation. This DPA takes effect when your organisation accepts these Terms, which occurs when a Polaris account is created or first used. It applies for as long as we process personal data on your behalf. Obligations that by their nature must outlive it (confidentiality, deletion, and the transfer safeguards in Annex D) survive its termination.

No signature required. The Standard Contractual Clauses and the other transfer instruments described in Annex D are incorporated into this DPA and take effect with it. By accepting these Terms, each party is deemed to have signed them as of the date the agreement began. If your procurement process requires a countersigned copy, you may request one at privacy@hexifyer.com. The countersigned copy will have the same content.

Authority of administrators. Instructions under this DPA are given by a workspace owner or administrator, and an instruction from either of them binds your organisation. This reflects the authority given to them under Section 3 of these Terms. Accordingly, a member's request about workspace content is routed to your administrator and is not acted on by us.

2. Scope and order of precedence

This DPA covers personal data contained in your workspace content that we process on your behalf, as described in Annex A. It does not cover data for which we are the controller: your account record, your billing and invoicing data, aggregate usage data about how the product is used, and your correspondence with our support team. That data is covered by our Privacy Policy and is not governed by any DPA, because you do not instruct us in respect of it.

In the event of conflict between documents:

  • This DPA prevails over the rest of these Terms on any matter concerning personal data we process on your behalf.
  • Our Privacy Policy governs any figure, including a retention period, a deadline or a turnaround time. If a figure in this DPA differs from the corresponding figure in the Privacy Policy, we will honour the Privacy Policy figure and correct this DPA.
  • The Standard Contractual Clauses and the other instruments in Annex D prevail over the rest of this DPA to the extent of any conflict, for the transfers they cover.
  • Where a signed order form exists between us, it prevails over this DPA to the extent it expressly so provides.

3. Roles of the parties

Polaris holds two categories of data and acts in a different capacity for each. This allocation corresponds to Section 2 of our Privacy Policy.

DataYour roleOur role
Workspace content: Captures, ideas, Second Brain messages, tasks and subtasks, logs, meetings and meeting notes, comments, time logs, topics, custom field values, uploaded files and attachments, and the audit records of who did whatControllerProcessor. We process it on your documented instructions and for no purpose of our own.
Account, billing, usage and support data: account records and credentials, profile details, plan and invoices, aggregate product usage, correspondence with usNot applicable. You do not instruct us in respect of this data.Controller. Our Privacy Policy is the disclosure.

Where you act as a processor. If the content you put into Polaris belongs to your own client (for example, where you are an agency), you may be a processor rather than a controller for it. In that case we act as your sub-processor, you confirm that your controller has authorised our engagement, and Module Three of the Standard Contractual Clauses applies to the transfers instead of Module Two.

4. Instructions and restrictions on processing

We process personal data in your workspace only on your documented instructions, including with regard to transfers, unless a law to which we are subject requires otherwise. In that case we will inform you before processing, unless that law prohibits us from doing so.

Your instructions. Your instructions consist of: this DPA and these Terms; your use and configuration of the product, including the roles you assign, the features you enable, and whether AI features are switched on; and any further written instruction you send to privacy@hexifyer.com. We will inform you if we consider that an instruction breaches data protection law, and we may decline to follow it until the matter is resolved.

Restrictions on use of your content.

  • We do not sell your content, and we do not share it for advertising purposes.
  • We do not use it to train, fine-tune or improve any model, whether our own or a provider's. This commitment is contractual and is set out in full in paragraph 2 of the AI Services Addendum (Schedule 2 to the Terms).
  • We do not access it except to provide, secure and support the service, to follow your instructions, or where required by law. Staff access requires a business reason and is logged.
  • We do not disclose it to anyone other than the people in your workspace, the sub-processors referred to in Annex C, and the recipients of a legal request handled under clause 15.

De-identified and aggregated data. We generate de-identified and aggregated data from the operation of the service and use it for internal telemetry and to improve and secure Polaris, and for no other purpose. This includes understanding how features perform, where the product is slow or failing, how capacity is consumed, and where faults occur before a customer reports them. The following limits apply:

  • Internal use only. We do not publish de-identified or aggregated data, share or sell it to third parties, or use it in marketing, benchmarking reports or any other external product.
  • Irreversibility. Data is treated as de-identified only where it can no longer be attributed to an identified or identifiable person. We do not attempt re-identification.
  • Status of the data. Data that has been de-identified and aggregated is no longer personal data. This clause therefore operates as a limit on us rather than as a processing purpose you instruct.
  • Source of the data. What your members type, upload or record is not used to build these datasets. Telemetry is derived from how the product is used (events, volumes, timings, errors), not from content within it.

Section 15 of these Terms restricts building datasets from the service. That restriction applies to commercial and external datasets and does not prohibit the internal telemetry described in this clause.

5. Personnel

All Hexifyer personnel who can access personal data in your workspace are bound by confidentiality obligations under their employment or engagement contracts, and those obligations continue after their employment or engagement ends.

Access is limited to personnel who need it to operate or support the service, requires a business reason, and is logged. Our staff work from Cairo and elsewhere. All customer data is stored in Frankfurt, and staff access is remote access to data that remains there; it does not move your data to another country. Clause 14 and Annex D address the legal position.

6. Security

We implement and maintain the technical and organisational measures set out in Annex B, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risk to the individuals whose data is processed.

Annex B describes measures currently in place. Planned measures are not included. We may change a measure as the product and the threat environment change, but we will not reduce the overall level of protection. A material reduction is a change subject to clause 17.

Certifications. We do not currently hold SOC 2 or ISO 27001 certification. In place of certification we provide Annex B, the sub-processor list, a completed security questionnaire under clause 12, and this DPA. If certification is a requirement of your procurement process, contact us and we will inform you of our current position.

7. Sub-processors

You give us a general written authorisation to engage sub-processors to assist in delivering the service. All current sub-processors are named in the sub-processor list in Section 21 of our Privacy Policy, which is the authoritative list and is kept current. Annex C describes how that list relates to this DPA.

Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA, to the extent applicable to the service it provides. We remain fully liable to you for the acts and omissions of our sub-processors as if they were our own.

Notice of changes.

  • We add a new sub-processor to the sub-processor list, and email everyone subscribed to changes there, at least 30 calendar days before it begins processing your content.
  • You may object in writing within 30 calendar days of that notice, on reasonable grounds relating to data protection, by writing to privacy@hexifyer.com.
  • We will work with you to resolve the objection, normally by explaining the safeguards in place or by making a change to the service available where possible. If the objection cannot be resolved within a reasonable period, you may terminate the affected subscription without penalty.
  • The notice period and the objection period are of equal length. The new sub-processor does not begin processing your content until the notice period has expired.
  • Removal of a sub-processor does not require notice or an objection period. The sub-processor list and our configuration are updated in the same release.

Propagation of data subject rights. Where a data subject exercises a right that must be passed on to a sub-processor (such as an erasure or a correction that has reached a sub-processor), we propagate it to every affected sub-processor within 30 days, and we keep a written record of how each sub-processor is reached and how it responds.

8. AI providers

Polaris uses AI providers as sub-processors. They are listed in the sub-processor list with all other vendors, and the notice and objection process in clause 7 applies to them in the same way.

The following commitments apply to every AI provider we use:

  • No training on your content. Neither we nor any provider uses your workspace content to train, fine-tune or improve any model.
  • Provider retention of no more than 30 days, for trust, safety and abuse monitoring only, after which the data is deleted. This figure is the same as that stated in Sections 5 and 9 of our Privacy Policy, in the sub-processor list and in the AI Services Addendum (Schedule 2 to the Terms).

Named providers only. Every AI request leaves Polaris through a single gateway and is pinned to a named provider. Automatic fallback to a provider that is not in the sub-processor list is disabled. A request cannot be served by a model that is not disclosed in the sub-processor list.

The AI Services Addendum (Schedule 2 to the Terms) governs all other aspects of the AI features, including what they are, what an administrator can disable and who owns the outputs. Where the AI Services Addendum and this DPA both address the handling of personal data, this DPA governs.

9. Data subject requests

Individuals in your workspace have rights over their personal data: access, correction, erasure, restriction, objection, portability and withdrawal of consent. For workspace content, those rights are exercised against you as controller.

Requests received by us. If an individual in your workspace contacts us directly about content within it, we will not act on the request ourselves. We will acknowledge it, inform the individual that it has been routed to you, and pass it to your administrator within 6 working days. This is the period stated in our Privacy Policy for all rights requests.

Assistance. Rights requests are normally satisfied through the product: the roles, search, export and deletion tools in Polaris are available to your administrator without contacting us. Where the product cannot satisfy a request, we will assist you, taking into account the nature of the processing and the information available to us. We do not charge for this assistance.

A request concerning an individual's own account record, rather than your workspace content, is handled by us as controller under our Privacy Policy and within the periods stated there.

10. Assistance with assessments and regulators

We provide the information you reasonably need to meet your own obligations regarding security of processing, breach notification, data protection impact assessments and prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to us.

This information consists of this DPA, Annex B, the sub-processor list, our published policies and a completed security questionnaire under clause 12, and is provided free of charge. Where you require something bespoke (an assessment specific to your organisation, an unusual questionnaire, or engineering time to produce information we do not already hold), we will describe what it involves and agree the cost with you in writing before we begin. No charge applies unless agreed in advance in writing.

11. Personal data breaches

If we become aware of a personal data breach affecting personal data we process on your behalf, we will notify you without undue delay and in any event within 72 hours of becoming aware of it. This is the same period within which we notify a regulator.

The notification will describe, to the extent known: the nature of the breach; the categories and approximate number of individuals and records affected; the likely consequences; the measures taken or proposed; and a contact point. Where not all of this information is available at once, we will provide what is available and follow up with the remainder. We do not delay notification until the information is complete.

We will assist you in meeting your own notification obligations to regulators and affected individuals. We document every breach we identify, including breaches that do not meet a notification threshold, together with the reasons for that conclusion.

Notification of a breach is not an admission of fault by either party.

12. Audits and evidence of compliance

You are entitled to verify our compliance with this DPA as follows.

Documentation, once every 12 months. You may request:

  • Annex B, our Privacy Policy, our sub-processor list and any third-party audit report or certification we hold at the time. At the date of this version, we hold none.
  • Written answers to a security questionnaire. We respond within 30 days of receipt. Standard industry questionnaires are preferred, and we will inform you if a questionnaire is unusually long.
  • Any further information reasonably necessary to demonstrate compliance with this DPA, including the Standard Contractual Clauses.

Inspection. If our written answers do not provide what you reasonably need, or following a personal data breach on our systems, you or an auditor you appoint may inspect our processing, subject to the following conditions:

  • 21 days' written notice, with a proposed scope agreed in advance;
  • during business hours, without unreasonable interference with our operations;
  • the auditor is not a competitor of Polaris and is bound by confidentiality obligations at least as protective as those in our agreement;
  • the scope is limited to data and systems relevant to your processing, and the auditor is not given access to information about any other customer;
  • no more than once every 12 months, except following a breach affecting your data, in which case you may inspect within a reasonable period after the breach regardless of when you last did so;
  • at your cost, including our reasonable time in facilitating the inspection, as agreed with you in advance.

If an audit or inspection identifies a material issue, we will remedy it and inform you of the action taken. Findings and any information obtained in the process are confidential to both parties.

13. Return and deletion of data

When we cease processing on your behalf (because your subscription ends, you delete your workspace, or this DPA ends), you may choose whether we return your content or delete it.

Return. Return is provided by workspace export. On request to privacy@hexifyer.com, we deliver the export within 5 working days as a single archive containing: a CSV file per entity type, each row carrying its own key and its parent's key so that the structure of your workspace is preserved; your files in their original formats with a manifest; and a README stating the export date, the entity types included and anything excluded. Archived content is included.

You may export at any time while the workspace exists, and no deadline applies when a subscription ends. We do not delete your content for inactivity, for a downgrade or for non-payment. When a subscription ends, the workspace reverts to the Free plan and your content remains in place.

Export after deletion has started. Once a workspace deletion has been started, the export is no longer available. You must request and receive the export before starting deletion. The in-app deletion flow states this before you confirm.

Individual rights. This restriction applies only to the export of a whole workspace. An individual may request a copy of their own personal data at any time, including after a workspace deletion has started, and we handle that request under our Privacy Policy within the periods stated there. Nothing in this clause limits an individual's statutory rights.

Deletion. Deletion follows the figures in Annex E, which are the same as those stated in Section 9 of our Privacy Policy and Section 22 of these Terms. Items you delete remain in trash for 30 days. A deleted workspace or account is subject to a 14-day grace period during which the deletion can be cancelled. After that period, erasure from our live systems completes within 72 hours, and copies in encrypted backups expire within 14 days after that and are not restored to serve a request. If we restore a backup taken before a deletion, we re-apply the deletion to the restored data.

Data retained after deletion. We retain only invoices and tax records that the law requires us to keep (7 years under UAE corporate tax law, 5 years under Egyptian VAT law), and 12 months of audit records, retained so that a security incident can be scoped against records predating it. No workspace content is retained after a workspace is deleted.

Certification. On request and free of charge, we will certify in writing that deletion has been carried out, within 5 working days of its completion. We keep a record of each certification issued.

Notification emails. Polaris notification emails contain the content of the item to which they relate. Deleting an item in Polaris does not remove it from emails already delivered to recipients' mailboxes. Those copies are held in recipients' mail systems, outside our control, and cannot be recalled. Sections 9 and 16 of our Privacy Policy state the same.

14. Data location and international transfers

All Polaris workspace content, files and account records are stored in Frankfurt, Germany, in the AWS eu-central-1 region. This applies to every customer, regardless of location, and backups of both stores are held in the same region. Supabase holds authentication data and stored files; Render holds the primary database, the AI database and the application services; AWS provides the underlying infrastructure for both.

Narrower categories of data are sent to our platform and AI sub-processors and processed in those providers' own regions (currently the United States and Ireland), as stated for each provider in the sub-processor list.

Because customer data is written to Frankfurt when it is created, a transfer out of your country occurs at the point of collection and continuously thereafter. Annex D sets out the mechanisms governing that transfer: the Standard Contractual Clauses and the UK Addendum where they apply, a Swiss annex, and the position for the United Arab Emirates and Egypt. The allocation of responsibility for the transfer is set out below.

You are the data exporter. Personal data in your workspace leaves your country because you have chosen to place it in a service hosted in Germany. As between you and us, you are the exporter of that data and we are the importer. The rights, consents and approvals required for such a transfer attach to your relationship with the individuals concerned, with whom we have no relationship.

You acknowledge that it is your responsibility to hold: the necessary rights; the lawful basis; any consent; any notice to the individuals concerned; and any authorisation, registration or approval that a regulator in your country requires of you before personal data may be sent to a service hosted in Germany. This responsibility continues for as long as you use Polaris.

Acknowledgement, not warranty. This allocation records where responsibility sits. It is not a warranty given by you to us: it is not subject to the indemnity in Section 21 of these Terms, and a gap in your local approvals is not a breach of this DPA. If such a gap arises, we will assist you in documenting what we do with your data.

Our obligations. We disclose exactly what happens to your data, and Annexes A to E are drafted so that you can provide that information to a regulator. We do not obtain local licences, permits or approvals on your behalf, act as your representative before any authority, or adopt country-specific processing templates. Our obligations to you are those set out in this DPA, and they are the same for every customer in every market.

Exception for account, billing and support data. The allocation above does not apply to your account, billing and support data. For that data we are the controller and therefore the exporter, the responsibility is ours, and our Privacy Policy is the disclosure for it.

Our staff work from Cairo and elsewhere and access data that remains in Frankfurt. That access is remote access to data already held abroad, not a further transfer of it to Egypt, and Annex D treats it accordingly.

15. Government and law enforcement requests

If we receive a request from a government body, a law enforcement agency or a court for personal data we process on your behalf:

  • We will inform the requester that we hold the data on your behalf and direct them to you, so that you can respond as controller.
  • Where we cannot redirect the request, we will notify you before disclosing any data, unless we are legally prohibited from doing so, in which case we will notify you as soon as the prohibition permits.
  • We will challenge a request that appears unlawful, overbroad or not to follow proper legal process, and we will inform the authority that you have not authorised disclosure of your data.
  • If disclosure is required, we disclose only the minimum the request legally requires.
  • We keep a record of every such request and our response to it.

We have not built, and will not build, any means of bulk or direct government access to customer data.

16. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in Section 20 of these Terms. The cap in that Section applies to claims under this DPA and the rest of these Terms in aggregate, not separately.

These limitations do not affect the rights a data subject has directly against either party under the third-party beneficiary provisions of the Standard Contractual Clauses, or any liability that cannot be limited under the data protection law that applies to you.

17. Changes to this DPA

We may update this DPA to reflect a change in the law, a change in the transfer instruments in Annex D, or a change to how the service operates. A material change, meaning a change that weakens a commitment made in this DPA, takes effect at least 30 days after we announce it by email to workspace administrators and by a notice in the product. This is the same notice period used in Section 19 of our Privacy Policy and in these Terms. Clarifications and corrections take effect on publication, and the last-updated date is changed. Previous versions are kept in a public archive.

Changes to the sub-processor list are not changes to this DPA and are governed by clause 7.

Where a transfer instrument in Annex D is replaced by the body that issued it (for example, a new set of Standard Contractual Clauses or a new UK Addendum), the replacement applies from the date required by that body, and we will complete whatever it requires without the need for further agreement from you.

18. Countersigned copies and contact

This DPA is in force without signature. If your procurement process requires a countersigned copy, write to privacy@hexifyer.com and we will send one for signature with the annexes completed for your organisation.

Written instructions, sub-processor objections, security questionnaires, export requests, deletion certification requests and any other communication this DPA requires in writing are to be sent to the same address. Notices to you are sent to your workspace administrators at the email addresses on the account. Section 3 of these Terms asks you to keep at least one administrator contactable for this purpose.

Annex A: Details of the processing

Data exporter. You: the organisation holding the Polaris workspace, acting as controller (or as processor for your own client, in which case Module Three applies). You are the exporter of the personal data in your workspace, on the basis set out in clause 14. Contact details: those held on your account. Activities relevant to the transfer: use of Polaris to run your work.

Data importer. Hexifyer FZ-LLC, FOAM1588, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. Contact: privacy@hexifyer.com. Activities relevant to the transfer: providing the Polaris service. Role: processor.

Categories of data subject. Your workspace members: owners, administrators, editors and viewers. Individuals whose details your members enter into workspace content: clients, contacts, meeting attendees, and colleagues named in a task, a comment, a meeting note or a file. Recipients of notifications sent from your workspace.

Categories of personal data.

  • Identity and contact data: names, email addresses, profile photos, roles, workspace membership.
  • Content data: anything your members type, upload or record, including captures, ideas, Second Brain messages, tasks and subtasks, comments, logs, time entries, topics, custom field values, uploaded files and attachments.
  • Meeting data, where calendar sync or the AI notetaker is used: calendar events, titles, times, attendee email addresses, audio, transcripts and generated notes.
  • AI data: assistant conversations, and embeddings derived from workspace content.
  • Activity data: audit records of who did what and when.

Special categories. Polaris is not designed or intended for special categories of personal data, and the service does not request any. Such data may nonetheless reach us by two routes:

  • Free-text content. Captures, notes, comments and files are free text, and we cannot prevent a member entering information that falls within a special category. Where this occurs, the data is processed as ordinary content under the measures in Annex B.
  • Meeting audio, where the AI notetaker is used. A recorded meeting captures whatever is said in it. Speech is not filtered, and a conversation may turn to health, beliefs or any other special category. The audio, the transcript and the notes generated from it may therefore contain special category data.

As controller, you decide whether to use the notetaker, in which meetings and with whom. You are solely responsible for establishing a lawful basis for recording and for obtaining any consent or giving any notification that the law requires from the participants in your meetings (including participants who are not Polaris users and with whom we have no relationship), and for meeting the additional conditions that apply to special category data under the law that governs you. We do not obtain that consent, and nothing in the product obtains it on your behalf.

When the notetaker is used, it joins the meeting as a separate participant named Polaris AI Note Taker, visible in the participant list to everyone in the meeting for as long as it is present. This is a notice mechanism that enables you to discharge the responsibility described above. Notice is not consent. Where the law that governs your meeting requires consent from its participants, obtaining it remains your responsibility.

Nature and purpose of the processing. Hosting, storing, organising, retrieving, displaying, transmitting, backing up, securing and deleting workspace content in order to provide the Polaris service to you; generating and serving AI features you choose to use; delivering notifications you configure; and supporting you when you contact us.

Frequency. Continuous, for as long as you hold a Polaris workspace.

Duration. For the term of these Terms, and thereafter for the periods in Annex E. Sub-processors process for no longer than we do.

Transfers to sub-processors. Subject matter, nature and duration as described in the sub-processor list, one row per vendor. Infrastructure sub-processors process in Germany; platform and AI sub-processors process in their own named regions.

Competent supervisory authority. Where the Standard Contractual Clauses apply, the supervisory authority of the EEA member state in which you are established or, where you are not established in the EEA but the GDPR applies to you, the authority of the member state in which your EU representative is established. Annex D.4 names the FDPIC for Swiss transfers and Annex D.5 names the Egyptian Personal Data Protection Centre.

Annex B: Technical and organisational measures

MeasureDescription
EncryptionData is encrypted in transit over TLS, and at rest in every store described in clause 14: Supabase Auth, Supabase Storage, the Render primary database and the Render AI database, and their backups.
PseudonymisationWhere a person deletes their profile but their content remains in another workspace, their user data is anonymised and the content is retained without being attributed to them.
AuthenticationPassword hashing; optional two-factor authentication; federated sign-in with Google, Apple, Microsoft, LinkedIn and GitHub. Account email changes are administrator-mediated, not self-serve.
Access control within your workspaceFour roles (owner, administrator, editor, viewer) determining what each member can see and do. Topics can be marked confidential, restricting their content to trusted editors and above. The AI assistant answers only from content the requesting person can already see.
Access control for our staffLimited to personnel who need it to operate or support the service; requires a business reason; logged. Remote access only: the data remains in Frankfurt.
Logging and monitoringSign-ins, permission changes and content changes are recorded in an audit log, retained for 12 months so that an incident can be scoped against records predating it.
Confidentiality of personnelContractual confidentiality obligations that survive the end of employment or engagement, as described in clause 5.
Availability and resilienceManaged infrastructure with the redundancy operated by the platform providers; encrypted backups of both stores, held in the same region.
Restoring availability after an incidentRestoration from backup. Where a restored backup predates a deletion, the deletion is re-applied to the restored data so that deleted content is not reinstated.
Security of transferEncrypted in transit to every sub-processor. AI requests leave through a single gateway pinned to named providers, with automatic fallback disabled.
Physical securityProvided by AWS in eu-central-1 and inherited through Supabase and Render. Hexifyer does not, as a matter of course, hold customer data on its own premises or on staff devices.
Data minimisation and retentionThe retention periods in Annex E, one per category, applied automatically. We do not delete workspace content on our own initiative, and we do not retain it beyond the periods in Annex E.
Data quality and rectificationMembers and administrators can correct content directly in the product; account email changes are made through an administrator; clause 9 applies to anything the product cannot do.
Portability and erasureWorkspace export as specified in clause 13; deletion on the Annex E figures; deletion certification on request.
Sub-processor governanceWritten agreements with data protection terms no less protective than those in this DPA; an internal register recording, for each vendor, the agreement, the accountable owner and the means by which we require it to delete data; retained deletion certificates.
Incident managementA documented breach process meeting the 72-hour notification in clause 11, with documentation of every incident, including incidents below the notification threshold.
CertificationsNone. Polaris does not currently hold SOC 2 or ISO 27001 certification. Clause 12 sets out the evidence of compliance we provide.

Annex C: Sub-processors

The current list of sub-processors, with the purpose of each, the data it receives and the country in which it processes, is published in Section 21 of our Privacy Policy. That list forms part of this Annex and is the authoritative list. You can subscribe there to receive email notification of changes.

At the date of this version, sub-processors fall into three groups:

  • Infrastructure: Supabase (authentication and file storage) and Render (primary database, AI database and application services), both processing in Germany, with Amazon Web Services providing the underlying infrastructure in eu-central-1.
  • Platform: providers that deliver a specific feature and receive only the data that feature requires: payments and billing, transactional email, mobile push notifications, meeting transcription, and product analytics.
  • AI: the gateway through which every AI request passes, and the model providers to which it routes, all currently processing in the United States, subject to the commitments in clause 8.

Sign-in providers are not sub-processors. When you sign in with Google, Apple, Microsoft, LinkedIn or GitHub, that provider authenticates you under its own terms and provides us with the profile fields you approve. We do not instruct it to process any data on our behalf.

Annex D: Transfer mechanisms by region

Polaris stores all customer data in Frankfurt and applies one baseline to every customer in every market. That baseline rests on the two bodies of law that govern Polaris: the GDPR, which binds the infrastructure holding your data in Germany, and UAE Federal Decree-Law No. 45 of 2021, which governs Hexifyer as a company. This Annex sets out the instrument governing a transfer into that region, or out of it to a sub-processor, and our position under the other regimes in which we offer the service.

The baseline does not vary by country. Where the law that applies to you requires something beyond it (a local licence, a national standard contract, or an approval from a regulator), obtaining it is your responsibility, on the basis set out in clause 14. We will provide the information you need to obtain it. We will not obtain it on your behalf.

D.1 United Arab Emirates

Hexifyer FZ-LLC is established in a Ras Al Khaimah free zone, which has no data protection legislation of its own. Federal Decree-Law No. 45 of 2021 therefore applies to us, rather than the DIFC or ADGM regimes. Its Executive Regulations have not been issued. We apply the standard in this DPA to UAE-governed data and will adopt whatever the Executive Regulations require when they are issued, under clause 17.

D.2 European Economic Area

Where the GDPR applies to your processing and personal data is transferred to us, or onward to a sub-processor outside the EEA, the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 apply and are incorporated into this DPA, with the following selections:

  • Module Two (controller to processor) applies where you are a controller and we are your processor. Module Three (processor to processor) applies where you are a processor and we are your sub-processor.
  • Clause 7 (docking clause): applies.
  • Clause 9: Option 2, general written authorisation. The period for prior notice of sub-processor changes is the period in clause 7 of this DPA: 30 calendar days.
  • Clause 11: the optional independent dispute resolution language does not apply.
  • Clause 17: Option 1. The clauses are governed by the law of Ireland.
  • Clause 18(b): disputes are resolved before the courts of Ireland.
  • Annex I.A and I.B are Annex A of this DPA; Annex II is Annex B; Annex III is the sub-processor list referenced in Annex C.

By accepting these Terms, each party is deemed to have signed these clauses.

D.3 United Kingdom

Where the UK GDPR applies, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 applies, in the version current at the time of the transfer. Its Mandatory Clauses are incorporated by reference. Tables 1 to 3 are completed by Annexes A, B and C of this DPA. In Table 4, the exporter may end the Addendum as set out in section 19 of its Mandatory Clauses. Each party is deemed to have signed it.

D.4 Switzerland

Where the Swiss Federal Act on Data Protection (FADP) applies, the clauses in D.2 apply with the following adaptations: references to the GDPR are read as references to the FADP; the Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by the FADP; the clauses protect the data of legal entities to the extent the FADP does; and data subjects habitually resident in Switzerland may bring proceedings in Switzerland.

D.5 Egypt

Where Egypt's Personal Data Protection Law No. 151 of 2020 applies to you, personal data leaves Egypt at the moment it is created, because it is written to Frankfurt at that point and continuously thereafter. The transfer is therefore structural and continuous, and it applies to every Egyptian customer. Articles 14 to 16 of that Law govern the transfer. They permit a transfer where the destination affords a level of protection not lower than that provided by the Law, and they provide for licences and permits issued by the Personal Data Protection Centre.

Our position depends on our role:

  • Workspace content: you are the controller and we are your processor. This DPA is the instrument governing the transfer. It binds us by contract to the obligations in clauses 4 to 16 and to the measures in Annex B, and clause 7 flows those obligations down to every sub-processor that processes your content.
  • Account data: we are the controller. We rely on the level of protection available at the destination.

The destination is Germany, a member state of the European Union. The protection available there is as follows.

Requirement under Articles 14 to 16Position at the destination
A general data protection law binding on the recipientRegulation (EU) 2016/679, the General Data Protection Regulation, applies directly in Germany alongside the Bundesdatenschutzgesetz. Both bind the infrastructure sub-processors that hold the data there.
Individual rights, enforceable in practiceAccess, rectification, erasure, restriction, objection and portability under Articles 15 to 21, with the right to complain to a supervisory authority and to a judicial remedy under Articles 77 to 79. Clause 9 of this DPA sets out how we assist you in responding.
An independent supervisory authority with effective powersThe data protection authority of Hesse, the state in which Frankfurt is located, together with the federal and other state authorities, exercising the corrective and fining powers in Articles 58 and 83.
Security of processing and breach notificationArticles 32 to 34: security appropriate to the risk, notification to the authority within 72 hours, and notification to affected individuals where the risk is high. Clause 11 and Annex B apply the same standard and the same 72-hour period to us.
Limits on onward transferChapter V of the GDPR. Onward transfers from Germany to our platform and AI sub-processors are governed by the instruments in D.2 and by the flow-down and objection process in clause 7.
Purpose limitation and limits on retentionArticle 5. Our own limits are in clause 4, and the retention periods are in Annex E. Both apply to every Polaris customer, not only to customers in one region.

Licences and permits. Egypt has published no standard contractual clauses, no approved transfer instrument and no list of countries deemed to offer adequate protection. There is therefore no national template for us to adopt and nothing for us to sign on your behalf. Where the Personal Data Protection Centre requires a licence or permit for a transfer of this kind, obtaining it is your responsibility as exporter, under clause 14. For the purposes of an application we provide: the table above; Annex A, describing what is processed and about whom; Annex B, describing the measures protecting it; and Annex C, identifying every recipient and the country in which it processes.

Consent. We do not ask individual users to consent to the transfer. Consent can be withdrawn and is therefore not relied on for a single-region architecture, and we cannot collect a data subject's consent for content we hold as processor. Nothing in this section reduces any right the Law gives you or the individuals in your workspace.

Transfer register. This transfer is recorded in our internal cross-border transfer register, which records what is transferred, to which recipient and country, the mechanism relied on and the safeguards applied. You may request the information in that register relating to you under clause 12.

Annex E: Retention, deletion and response figures

ItemPeriod
Deleted items in trash30 days, fixed, then purged
Grace period after a workspace or account deletion is started14 days, cancellable throughout
Erasure from live systems, after the grace period or a verified requestWithin 72 hours
Last copy removed from encrypted backupsWithin 14 days of erasure from live systems
Meeting audio, transcripts and notes from the AI notetakerUntil you delete them or the workspace is deleted. No time limit and no automatic expiry, as for any other workspace content
Embeddings and other AI-derived dataDeleted in the same transaction as the content from which they were derived, and when an administrator switches off the AI features for the workspace
Audit and security logs12 months from the event
Retention by an AI providerUp to 30 days, trust and safety only, then deleted; never used for training
Invoices and tax records (statutory, retained after deletion)7 years (UAE corporate tax); 5 years (Egypt VAT)
Delivery of workspace export5 working days from request
Issue of deletion certification, on request5 working days from completion of deletion
Routing a member's rights request to you6 working days
Breach notification to youWithout undue delay, and in any event within 72 hours
Propagating an erasure or correction to sub-processorsWithin 30 days
Advance notice before a new sub-processor starts processing30 calendar days
Objection to a new sub-processor30 calendar days from notice
Response to a security questionnaire30 days, once every 12 months
Notice before an on-site inspection21 days
Notice of a material change to this DPA30 days

Polaris does not delete workspace content for inactivity, for a plan downgrade or for non-payment. Projects locked by a downgrade are retained until you delete them, without time limit.