Polyosync

Privacy Policy

Effective date: 21 September 2026

Version: 3.0

This Privacy Policy explains how FLR Holdings UK Limited (company number 16970627), operating Polyosync, processes personal information through Polyosync, its websites, applications, integrations, AI Employees, workflows and related services. It is intended to be read together with our Terms of Service, Cookie Policy and, where applicable, a Data Processing Agreement.

1. Who we are and the roles we perform

FLR Holdings UK Limited, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE, operates Polyosync. Depending on the processing activity, we may act as a controller of personal information relating to our own accounts, billing, security, support, website and service administration. For Customer Data that a business places into Polyosync or makes available through connected services, we generally act as a processor/service provider on that business's documented instructions.

The customer remains responsible for determining the purposes and lawful basis for processing personal information it controls. Where Polyosync acts as processor, the customer's instructions, the applicable agreement and our DPA govern the processing. Where we act as controller, this Privacy Policy describes our purposes and legal bases.

2. What information we process

  • Account and identity data: name, email address, authentication metadata, organisation membership, roles and account settings.
  • Business and workspace data: business profile information, configuration, operating rules, knowledge, workflows, permissions and AI Employee settings.
  • Connected Data: information made available through authorised integrations, which can include email, calendar, contacts, CRM records, documents, spreadsheets, support records, bookings, accounting records, analytics and other third-party data.
  • AI and workflow data: prompts/instructions, AI inputs and outputs, workflow definitions, tool calls, execution results, approvals and operational metadata.
  • Credentials and integration data: OAuth tokens, API keys and related connection metadata required to maintain an authorised integration.
  • Billing data: plan, subscription, invoice and payment-status information. Full payment-card details are handled by the applicable payment provider rather than stored by Polyosync as a complete card record.
  • Security and technical data: IP-related information, browser/device information, timestamps, authentication events, audit/security events, error information and service-usage metadata.
  • Support and communications: information you provide when contacting us, including support requests and related correspondence.

3. Where information comes from

We may receive information directly from you, from your organisation, from administrators of your workspace, from authorised integrations and third-party services, from devices and browsers used to access Polyosync, and from service providers that support security, billing, communications or other authorised functions. When a customer supplies Connected Data about other people, the customer is responsible for providing any notices required by applicable law.

4. Purposes and legal bases

We use personal information only for specified, relevant purposes. The legal basis depends on the particular processing activity and relationship with the individual.

  • Provide and administer the service: performance of a contract or steps requested before entering a contract.
  • Authenticate, secure and protect accounts: performance of a contract, legal obligations where applicable, and legitimate interests in preventing fraud, abuse and unauthorised access.
  • Operate integrations and authorised workflows: performance of a contract and, where Polyosync acts as processor, the customer's documented instructions.
  • Billing and financial administration: performance of a contract and compliance with legal obligations.
  • Service reliability, diagnostics and improvement: legitimate interests where the processing is necessary and proportionate, with appropriate safeguards.
  • Security, fraud prevention and incident response: legitimate interests and, where applicable, legal obligations.
  • Marketing communications: consent where required, or another lawful basis permitted by applicable marketing and privacy law. We provide an appropriate opt-out mechanism.
  • Legal compliance: compliance with applicable legal obligations.

Where we rely on legitimate interests, those interests include operating a secure, reliable SaaS service, protecting customers and users, preventing misuse, defending legal rights and improving service reliability. We consider the necessity of the processing and its impact on individuals before relying on this basis.

5. Customer Data, Connected Data and AI processing

Polyosync is designed to execute business work using data, tools and integrations authorised by the customer. We do not sell Customer Data or Connected Data. We do not use Connected Data for advertising, behavioural profiling, data brokerage or unrelated commercial purposes. We do not use Connected Data to train or fine-tune general-purpose AI or machine-learning models.

When an AI Employee or workflow uses a model provider, relevant information may be transmitted to that provider to generate an output or perform the requested operation. The information sent is determined by the enabled feature, context, permissions and workflow. We use provider configurations and contractual controls intended to prevent customer Connected Data from being used to train general-purpose models.

AI output may be probabilistic or inaccurate. Customers must configure appropriate permissions, approval policies, data boundaries and human review for consequential operations. Polyosync is not a substitute for professional, legal, medical, financial or other regulated advice.

6. Google user data

When Google services are connected, Polyosync requests and processes only the scopes needed for the enabled functionality. Depending on the connection, this may include Gmail, Calendar, Drive, Sheets, Analytics, Search Console, Ads or YouTube data.

Google user data is used only to provide the functionality the user or organisation has authorised. It is not sold, used for advertising or personalised advertising, used for creditworthiness or unrelated profiling, or used to train or fine-tune general-purpose AI/ML models. We do not request broader Google scopes merely for convenience.

Google access can be revoked through Google account controls or by disconnecting the integration in Polyosync. After disconnection, Polyosync stops using the connection for new authorised workflow activity and removes stored credentials when they are no longer required, subject to lawful retention, security, audit and backup requirements.

7. Sensitive and special-category information

Polyosync is a general business automation platform and is not intended to require special-category or highly sensitive personal information for ordinary use. Customers must not place sensitive information into an AI Employee, workflow or integration unless they have a lawful basis, appropriate configuration and contractual safeguards for doing so. Where a use case involves health, biometric, financial, criminal-offence, children's or other highly sensitive data, additional controls, contractual terms or a data protection impact assessment may be required.

8. When we share information

We may share information with service providers and subprocessors that host, secure, monitor, communicate, process payments, provide AI/model inference or deliver an explicitly requested integration. We may also disclose information to professional advisers, competent authorities where legally required, or a successor entity in a merger, acquisition or restructuring.

Service providers receive only information reasonably necessary for their role. We do not sell personal information, Customer Data or Connected Data and do not disclose it to unrelated third parties for their own advertising or data-brokerage purposes.

Our public legal documentation includes a subprocessor register framework. Provider details, locations and transfer mechanisms must be verified against actual contracts and production configuration before being treated as a definitive subprocessor list.

9. Human access and confidentiality

Polyosync does not provide routine human access to customer Connected Data for browsing or commercial use. Limited access may occur where specifically necessary for support, security or incident response, legal compliance, troubleshooting or technical maintenance. Access is restricted to authorised personnel with a legitimate need and is subject to confidentiality and access controls.

10. International transfers

Polyosync and its service providers may process personal information outside the UK. Where a restricted transfer under applicable UK data-protection law occurs, we use an applicable transfer mechanism, such as UK adequacy regulations or appropriate safeguards including the UK International Data Transfer Agreement or UK Addendum, where appropriate. Transfer risk assessments and supplementary measures are maintained where required.

The precise location of processing depends on the providers and features used. We do not make a blanket claim that all Polyosync data remains in the UK.

11. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, the service relationship, security and fraud prevention, legal and accounting obligations, dispute resolution, and the enforcement of agreements. Where a fixed period is not appropriate, the retention criterion is the continuing business or legal need for the information.

Account, workflow, integration, audit and security records can have different retention periods. Credentials are retained while an integration remains authorised and for the limited period reasonably required for secure disconnection, rotation or incident handling. When data is deleted from active systems, limited copies may remain in backups or security records until their scheduled expiry or where retention is required by law.

12. Customer controls

Customers control the business configuration that determines what Polyosync can access and what an AI Employee can do. Depending on the feature, controls include workspace membership and permissions, integration connection and disconnection, enabled tools and capabilities, approval requirements, workflow configuration and human handoff.

Customers can also request changes or deletion of personal information where applicable under the service agreement and data-protection law. Where Polyosync acts as a processor, the customer remains responsible for its instructions and for determining the appropriate data boundaries for its use case.

13. Subprocessors

Polyosync uses service providers and subprocessors for functions such as hosting, infrastructure, security, communications, billing, AI/model inference and requested integrations. We maintain a subprocessor register framework and apply contractual and access controls appropriate to the service relationship.

The definitive provider list, processing locations, transfer mechanisms and applicable notice process depend on the current production configuration and customer agreement. Enterprise customers can request the applicable subprocessor information as part of their security and privacy review.

14. Your data-protection rights

Depending on the applicable law and the circumstances, you may have rights to access, rectification, erasure, restriction, objection, data portability and withdrawal of consent where processing relies on consent. You may also have rights concerning automated decision-making and profiling where applicable.

If Polyosync processes information on behalf of a business customer, requests relating to that Customer Data will normally need to be directed to that customer, as the controller. We will provide reasonable assistance to the customer where required by the applicable agreement and law.

To exercise a right or raise a privacy concern, use the contact route provided on our Contact page and identify yourself and the nature of the request. We may need to verify identity before disclosing or changing information.

You also have the right to complain to the Information Commissioner's Office (ICO) or another competent supervisory authority where applicable. The ICO website is ico.org.uk.

15. Automated decision-making and profiling

Polyosync provides AI-generated recommendations, classifications, communications and business-process actions. Customers are responsible for configuring the service so that it is not used unlawfully for solely automated decisions that produce legal or similarly significant effects on individuals. Where applicable law gives individuals rights concerning automated decision-making or profiling, those rights remain applicable.

16. Security

We maintain technical and organisational measures appropriate to the risks of the service, including TLS for data in transit, protected server-side secrets, access controls, least-privilege principles, authentication and authorisation, tenant isolation, security and audit logging, monitoring, backups and incident-response processes. We continually assess and improve these controls.

No internet service can guarantee absolute security. Customers must also protect their credentials, configure permissions appropriately and promptly report suspected unauthorised access or security incidents.

17. Cookies and similar technologies

We use necessary authentication and security storage and may use optional analytics technologies only where the required consent has been obtained. Our Cookie Policy explains the current categories and how to change preferences.

18. Children

Polyosync is a business service and is not directed to children. Customers must not use the service to process children's personal information unless the applicable legal, contractual and safeguarding requirements have been addressed.

19. Changes to this Privacy Policy

We may update this Privacy Policy when our processing, service, legal obligations or security practices change. We will update the effective date and version when material changes are published. Where the law requires notice of a new use of personal information, we will provide that information before the new processing begins.

20. Contact

FLR Holdings UK Limited
Company number 16970627
3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE