01Introduction
Polaris (“Polaris”, “we”, “our”, or “us”) provides software licensing infrastructure, analytics, validation, and entitlement management services for software publishers, developers, studios, and digital product companies.
We are committed to protecting personal information and processing data responsibly, securely, and in accordance with applicable privacy laws, including the UK General Data Protection Regulation (UK GDPR), EU GDPR, and other applicable international privacy regulations.
This Privacy Policy explains how Polaris collects, uses, stores, and protects personal information when you visit our website, use our services, or interact with our platform.
02Our Role
Polaris primarily acts as a Data Processor on behalf of our customers, who remain responsible for determining how and why personal data is processed.
Our customers are typically software vendors who use Polaris to manage software licensing, activations, subscriptions, analytics, and related workflows.
Where Polaris collects information directly for its own business operations, such as customer account administration, support, billing, and website operation, Polaris acts as a Data Controller.
03Information We Collect
Customer Account Information
When organisations create and manage Polaris accounts, we may collect:
- Name
- Business email address
- Company name
- Job title or role
- Authentication credentials
- API keys
- Billing information
- Support communications
- Account activity records
Licensing & End User Information
Our customers may store information relating to software license holders within the Polaris platform, including:
- Name
- Email address
- License identifiers
- Product ownership information
- Subscription status
- Purchase references
- Activation records
- Device identifiers
- Hardware fingerprints (where enabled by the customer)
Analytics & Telemetry Data
Applications integrating Polaris may generate operational telemetry including:
- License validation events
- Product version information
- Usage metrics
- Device and environment metadata
- Geographic region information
- Error logs
- Session information
- Feature utilisation data
- Activation frequency
- Revenue attribution metadata
Where practical, Polaris uses aggregated or pseudonymised data to minimise the use of personally identifiable information.
Security & Audit Information
To maintain platform security and reliability, we may collect:
- IP addresses
- Authentication events
- Access logs
- API request logs
- Administrative actions
- Security alerts
- System integrity events
04How We Use Information
Polaris uses personal information to:
- Provide and operate the platform
- Issue and validate software licenses
- Manage subscriptions and entitlements
- Deliver analytics and reporting
- Detect fraud, abuse, piracy, and unauthorised usage
- Improve platform performance and reliability
- Provide customer support
- Manage billing and invoicing
- Comply with legal and regulatory obligations
- Protect the security and integrity of our systems
Polaris does not sell personal data.
05Legal Basis for Processing
Where Polaris acts as a Data Controller, we process personal information based on one or more of the following legal grounds:
- Performance of a contract
- Legitimate business interests
- Compliance with legal obligations
- Consent, where required by law
Where Polaris acts as a Data Processor, personal information is processed on behalf of customers and in accordance with their instructions.
07Data Sharing
Polaris may share information with trusted service providers that assist us in operating the platform.
These providers may include:
- Cloud infrastructure providers
- Authentication providers
- Payment processors
- Monitoring and security providers
- Email delivery providers
- Customer support providers
All third parties are required to process information securely and only for authorised purposes.
Polaris does not sell customer or end-user personal information.
08International Data Transfers
Polaris may process or store data in multiple jurisdictions depending on infrastructure configuration and customer requirements.
Where personal data is transferred internationally, Polaris may rely upon:
- UK International Data Transfer Agreements (IDTA)
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Appropriate contractual safeguards
Additional information regarding international transfers may be provided upon request.
09Data Retention
Polaris retains personal information only for as long as necessary to:
- Provide services
- Meet contractual obligations
- Maintain security records
- Comply with legal requirements
- Support customer-configured retention policies
For customers whose subscription has been cancelled or terminated, account data, customer records, license information, activation records, analytics data, and other service related information may remain accessible for up to 30 days following the subscription end date. This period allows customers to export and retain any information they require.
After the 30 day retention period has expired, Polaris may permanently delete or anonymise such information.
Where appropriate, information may be anonymised or securely deleted once it is no longer required.
10Security
Polaris implements technical and organisational safeguards designed to protect personal information, including:
- Encryption in transit and at rest
- Role-based access controls
- Multi-factor authentication support
- Audit logging
- Secure key and secret management
- Infrastructure monitoring
- Vulnerability management
- Backup and recovery procedures
No method of transmission or storage is completely secure; however, we take reasonable measures to protect the information entrusted to us.
11Your Rights
Depending on your location and applicable law, you may have rights including:
- Access to your personal information
- Correction of inaccurate information
- Deletion of personal information
- Restriction of processing
- Objection to processing
- Data portability
- Withdrawal of consent where processing relies on consent
If Polaris processes your information on behalf of one of our customers, we may direct your request to that customer as the Data Controller.
12Children’s Privacy
Polaris services are not intended for individuals under the age of 16 and we do not knowingly collect personal information from children.
13Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or operational practices.
The latest version will always be available on our website, together with the date of the most recent update.
14Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
For data protection enquiries, access requests, or privacy concerns, please contact us using the details above.
15Enterprise Privacy & Compliance
Polaris is designed around privacy-by-design and data minimisation principles.
Our platform architecture aims to:
- Minimise collection of unnecessary personal information
- Support pseudonymisation and aggregation where practical
- Provide customer-controlled retention and deletion capabilities
- Support GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and other major privacy frameworks
- Maintain secure processing environments
- Enable enterprise-grade governance and compliance workflows
Additional compliance documentation, subprocessor information, and Data Processing Agreements may be made available upon request.
