← POLARIS

Privacy Policy

Effective: 4 June 2026

Template for review. This is a starting draft and must be reviewed by a qualified data-protection adviser before commercial use.

1Who we are

Erarta AI Ltd ("Erarta", "we", "us") operates the POLARIS platform. For personal data described in this policy, Erarta is the data controller. We can be reached at hello@erarta.ai.

2Scope

This policy covers personal data we process about visitors to polaris.erarta.ai and authorised users of the POLARIS dashboard and APIs. Where we process personal data on behalf of a customer as part of transaction screening, we act as a processor under that customer's instructions and the applicable data processing agreement.

3Data we collect

Contact & account data: name, work email, company, and credentials of authorised users.
Usage data: logs, API requests, IP address, and diagnostic events used to operate and secure the Service.
Transaction metadata: on-chain addresses and transaction data submitted for screening — generally not personal data, but processed under the relevant customer agreement.

4Why we process it (legal bases)

We process personal data to provide and secure the Service and perform our contract (Art. 6(1)(b) GDPR), to comply with legal obligations (Art. 6(1)(c)), and for our legitimate interests in operating, improving and protecting the Service (Art. 6(1)(f)). Where required, we rely on consent (Art. 6(1)(a)), which you may withdraw at any time.

5Sub-processors & hosting

We use vetted infrastructure sub-processors to run the Service, including Supabase (managed PostgreSQL, EU region) and Amazon Web Services (compute and storage). Data is hosted in the European Union. A current list of sub-processors is available on request.

6International transfers

Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

7Retention

We retain account data for the life of the account and as required to meet legal and contractual obligations. Compliance evidence may be retained for the statutory periods required by applicable regulation (e.g. MiCA / DORA). We delete or anonymise data when it is no longer needed.

8Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. You may also lodge a complaint with your supervisory authority. To exercise your rights, contact hello@erarta.ai.

9Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, append-only audit logging, and least-privilege practices.

10Changes

We may update this policy from time to time. Material changes will be notified through the Service or by email, and the effective date above will be updated.

11Contact

Privacy questions or requests: hello@erarta.ai.