Skip to main content

LEGAL

Privacy Policy

This policy explains what personal data MindPolar collects, why, and what you can do about it. It is written to describe what MindPolar's systems actually do — where something is not yet built, this policy says so plainly rather than describing it as done.

Document status

Version 1.0.0Last updated August 23, 2026Not yet in effect

This document is a draft prepared to describe MindPolar's systems accurately. It is not legal advice, and it requires review by qualified legal counsel before it governs any account, transaction, or data processing.

1

Who is responsible for your data

Legal entityMindPolar Pvt Ltd
Corporate Identification NumberU62099OD2025PTC047911
Registered address[TO BE SUPPLIED BY OWNER]
Privacy contacthello@mindpolarai.com (interim — a dedicated privacy/DPO address should replace this before publication)

MindPolar is two different things to two different kinds of personal data, and the distinction below governs the rest of this policy. This is not a stylistic choice — GDPR Art. 28 and the DPDP Act 2023 impose materially different duties on a controller than on a processor.

1.1

Where MindPolar is the controller, and where it is the processor

Your own MindPolar account — your name, login email, profile photo, sessions, authentication records, and your own security-activity history — is data MindPolar controls: you are the data subject, and MindPolar decides why and how it is processed.

If you are added to MindPolar as an employee, contractor, or other person inside a customer organization's directory — your work email, employee number, department, job position, employment dates, or reporting line — the organization that added you is the controller of that data, and MindPolar processes it only on that organization's documented instructions, under a Data Processing Agreement. If you have a question about that data, your employer's own privacy notice governs it, and MindPolar will direct your request back to them.

2

What personal data MindPolar processes

Identity data — MindPolar is the controller
CategoryDataSource
Account identityFull name, email address, profile photoYou, at sign-up or in account settings
AuthenticationPassword (hashed, never stored in plain text), session tokens, email-verification and password-reset tokensGenerated by the system when you sign up, sign in, or request a reset
PreferencesTimezone, formatting locale, light/dark themeYou, in account settings
Security activityLogin events, password changes, email changes, deactivation/erasure requests, plus the IP address and user agent for eachCaptured automatically by the system
Organization membershipWhich organizations you belong to, your role, your job title in eachYou (creating/joining) or an organization admin (inviting you)
Employee-directory data — MindPolar is the processor; the customer organization is the controller
CategoryData
IdentityDisplay name, given name, family name, employee number, work email
EmploymentEmployment status (active / former), start date, end date
StructureDepartment, team, work location, job position, who they report to

This data is entered by a customer organization's own administrators. MindPolar does not collect it directly from the individual it describes, and does not decide what is collected, for how long, or for what purpose. If you are an employee whose data appears here and you are not a MindPolar account holder yourself, direct your data-protection questions to your employer.

Technical data
CategoryDataPurpose
Rate-limiting signalA one-way cryptographic hash (HMAC) of your IP address plus the action attemptedPrevent credential-stuffing and abuse of authentication endpoints — the raw IP is never stored, only an irreversible pseudonym
CookiesSee the Cookie PolicyKeep you signed in; remember your last-used workspace

4

Who MindPolar shares data with

MindPolar uses infrastructure sub-processors to operate the service. The current list — the same one the Data Processing Agreement discloses under Art. 28 — is below.

Sub-processorRoleRegion
Amazon Web Services, Inc.Cloud infrastructure: compute, database, object storage, cache, CDN, and transactional email delivery.ap-south-1 (Mumbai, India)

AWS is the only sub-processor MindPolar uses today. No analytics, advertising, error-tracking, customer-support, or session-replay third party is integrated into the product. If that changes, this list is updated before the new vendor goes live — not after.

MindPolar does not sell personal data and does not share it with data brokers. Personal data may be disclosed where required by law, a valid court order, or a lawful request from a competent authority — MindPolar will notify the affected person first, unless legally prohibited from doing so.

5

International data transfers

RegionProviderWhat's processed there
ap-south-1 — Mumbai, IndiaAmazon Web ServicesAll personal data MindPolar processes today. The platform runs from this single region; there is no second region and no data stored outside it as part of normal operation.

CloudFront, the content-delivery layer in front of the web and API applications, may route a request in transit through an edge location outside India as part of ordinary internet routing. This does not mean data is stored there, and CloudFront edge caching is not used for personal data responses.

GAP — NOT YET BUILT

India does not currently hold an EU adequacy decision (GDPR Art. 45)

The moment MindPolar processes an EU or EEA resident's personal data, that transfer becomes a GDPR Chapter V restricted transfer, requiring a transfer mechanism (Standard Contractual Clauses) plus a documented Transfer Impact Assessment — disclosure alone does not make it lawful. No EU-resident customer has been onboarded yet, so this has not arisen in practice. No SCCs have been executed and no Transfer Impact Assessment has been performed. Both must be in place before, not after, the first EU customer's data starts flowing. No EU-region deployment exists or is scheduled in the current infrastructure configuration. This section gains a row in the table above the day any of that changes — it is not rewritten.

6

How long MindPolar keeps your data

DataRetention
Your account, while activeIndefinitely, until you deactivate or erase it
Deactivated accountIndefinitely — deactivation is reversible; signing back in restores it
Erased account14-day grace window, fully reversible; irreversibly purged after, enforced in the database itself
Deleted infrastructure backupsUp to 7 days, disaster-recovery only, never reachable as a self-service restore
Organization deletionCurrently a reversible administrative action; an organization's records are retained until erasure is carried out. An automated purge window is not yet in operation — to request erasure of an organization's records, contact privacy@mindpolarai.com
Your own security-activity historyDeleted together with your account, with no independent retention
An organization's shared audit trail (who invited whom, who changed what)Survives the acting person's own erasure — only their identifying link is removed, a non-identifying label remains, because the audience is the organization's other members
Employee-directory data after someone leaves an organizationRetained indefinitely as a terminal record; identifiers are scrubbed on that person's own account erasure, but employee number, department, position, dates, and reporting position are retained for the organization's audit history
GAP — NOT YET BUILT

There is no retention-expiry mechanism in this system

No job, schedule, or policy currently deletes or anonymises data because it has aged past a defined period — the only deletions that happen are the ones a person or organization explicitly triggers. A former employee's non-identifying directory record, and the pseudonymised rate-limit signal, can persist indefinitely today. This is stated plainly because claiming a retention period this system does not enforce would be a false statement to a regulator.

7

Your rights

  • Access (GDPR Art. 15) — a copy of the personal data MindPolar holds about you.
  • Rectification (Art. 16) — correct inaccurate data. For identity data this is self-service today: name, email, and password are all correctable in-product.
  • Erasure (Art. 17) — see the 14-day grace-window process above.
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20).
  • Objection (Art. 21), including to processing based on legitimate interest.
  • Withdraw consent at any time, without affecting processing already carried out (Art. 7(3)).
  • Lodge a complaint with a supervisory authority — your own country's data protection authority.
  • Right to access information about your personal data and its processing (DPDP Act 2023 §11).
  • Right to correction and erasure (§12).
  • Right to grievance redressal, and to approach the Data Protection Board of India if unresolved (§13).
  • Right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity (§14).

Most of the above are self-service today inside your account settings. For anything not self-service — an access request, a portability request, an objection — contact privacy@mindpolarai.com.

NOTE

If your request is about employee-directory data

MindPolar is the processor, not the controller, of that data. If you contact MindPolar directly, MindPolar will tell you who the controller is and forward your request to them — MindPolar does not independently rectify or erase employee-directory data outside the controlling organization's instruction.

8

The Data Processing Agreement

If you are a customer organization, your relationship with MindPolar for employee-directory data is additionally governed by a Data Processing Agreement, which sets out MindPolar's obligations as processor, the sub-processor list, and the safeguard for any future cross-border transfer.

9

Security

Measures applied to the data MindPolar controls and processes:

  • Encryption in transit (TLS) for every connection to the web application and API.
  • Encryption at rest for the database (AWS Aurora) and object storage (AWS S3).
  • Tenant isolation enforced in the database itself — Postgres Row-Level Security, forced on every organization-scoped table, so an application bug cannot leak one organization's data into another's query.
  • Least-privilege AWS IAM roles per function; no long-lived AWS access keys used by the application at runtime.
  • Passwords are hashed, never stored or logged in plain text.
  • Pseudonymisation of IP addresses used for rate-limiting.

No system is unbreakable, and this section is not a guarantee.

10

Data breach notification

Where a breach of personal data creates a risk to individuals, MindPolar will notify affected customer organizations, and — where MindPolar is the controller — affected individuals, without undue delay, consistent with GDPR Art. 33/34 and DPDP Act 2023 §8(6).

11

Automated decision-making

MindPolar does not perform automated decision-making that produces legal or similarly significant effects on an individual. The product's organizational maturity diagnostic produces a score about the organization as a whole, from answers the organization's own people submit — it does not profile or score an individual, and no output is used to make an automated decision about any specific person.

12

Children's data

GAP — NOT YET BUILT

No age-verification mechanism exists

MindPolar is a B2B product not directed at children, and does not knowingly collect data from anyone under the age of legal majority in their jurisdiction. No age-gating mechanism exists in the product today — stated as a gap, not a control.

13

Changes to this policy

MindPolar will update this policy as the product, its sub-processors, or its data-residency footprint change, posting the new version and effective date at the top of this page and in the changelog below.

GAP — NOT YET BUILT

Version acceptance is not yet recorded

MindPolar does not currently record which version of this policy a given user accepted at sign-up — only that a policy was accepted, not which one. Until that changes, the version in force for any past acceptance cannot be reconstructed from system data alone.

Version history

  1. v1.0.0Pending — not yet published

    Initial draft, pending legal review.