Opens in a new tab
ISO 9001 · ISO 27001 · HIPAA · GDPR & EU AI Act readyMeet us at TechEx Europe, Amsterdam, 19–20 Oct

Home › Legal

Privacy policy

Legal

This policy explains how Polus Solutions Europe B.V. processes personal data when you visit polussolutions.eu, contact us, or work with us. We keep it in plain language and we do not collect more than we need.

1. Who is responsible

Polus Solutions Europe B.V., [Street and number], [Postcode] [City], the Netherlands, registered with the Dutch Chamber of Commerce under number [KvK number], is the controller for the processing described in this policy. Questions about privacy go to [email protected]. For client engagements in which we process personal data on a client’s instructions, we act as processor under a data processing agreement; see section 8.

2. What we collect and why

We process personal data for the purposes below. For each purpose we state the legal basis under Article 6 of the GDPR.

We do not sell personal data, we do not use it for automated decision-making with legal effect, and we do not use personal data from clients or visitors to train AI models.

3. Where the data comes from

Almost all personal data comes from you: forms on this website, email, meetings and event registrations. For business development we may use publicly available professional information, for example a LinkedIn profile or a company website, limited to name, role, employer and business contact details. You can object to that at any time.

4. Who receives the data

Access inside Polus is limited to the people who need it for the purposes above. We use a small number of service providers that process data on our behalf under processor agreements: website hosting, email and office tooling, a meeting scheduler, and a CRM. The current list of sub-processors, with their location and role, is available on request from [email protected] and is published for clients in the data processing agreement. We share personal data with authorities only when the law requires it.

5. Transfers outside the EEA

Client engagements for European clients are delivered by Polus Solutions Europe B.V. together with Polus Solutions in India. Where personal data leaves the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses with supplementary measures, or on an adequacy decision where one applies. Client data stays in client-controlled systems by default; EU-only processing is available for engagements that require it.

6. How we protect data

Polus Solutions is ISO 27001 certified. Personal data is protected by access control on a need-to-know basis, multi-factor authentication, encryption in transit and at rest, logging, and documented incident response. If a personal data breach is likely to result in a risk to you, we notify the Dutch Data Protection Authority within 72 hours and inform you without undue delay where the law requires it.

7. Your rights

You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to processing, to receive a copy in a portable format, and to withdraw consent at any time without affecting processing that took place before withdrawal. Send your request to [email protected]; we respond within one month. You can also lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or the supervisory authority in your own country.

8. When we process data for clients

In client engagements we often handle personal data that belongs to our client or its customers, for example when building or operating a system. In those cases the client is the controller and Polus is the processor. Our data processing agreement sets out the instructions, security measures, sub-processors, audit rights and deletion at the end of the engagement. See the data processing agreement page for details.

9. Cookies and third-party content

This website uses only strictly necessary cookies unless you consent to optional analytics. Fonts are loaded from Google Fonts, which means your browser sends a request, including your IP address, to Google when a page loads; we plan to self-host fonts before public launch so that this request disappears. Details are in the cookie policy.

10. Changes

We update this policy when our processing changes. The version number and date at the top tell you which version you are reading; material changes are announced on this page.