Effective Date: January 1, 2026
Polar Nite respects the privacy and confidentiality of the individuals and organizations whose information we collect, receive, access, process, or maintain.
This Privacy Policy explains how Polar Nite handles information obtained through our website, business operations, technical services, support activities, employment activities, and private business facilities.
Polar Nite currently provides services within the United States.
1. Scope of This Policy
This Privacy Policy applies to information Polar Nite collects, receives, accesses, maintains, or processes through:
- The Polar Nite website
- Email, telephone, chat, scheduling, and business communications
- Client onboarding and service delivery
- Managed IT and cybersecurity services
- Remote monitoring and technical management
- Technical support and service-management systems
- Microsoft 365 and cloud administration
- Backup and disaster-recovery services
- Network, server, workstation, and device management
- Security-camera and access-control administration
- Security and compliance consulting
- Billing and payment administration
- Employment and applicant activities
- Visits to Polar Nite’s private business facilities
Client-specific contracts, Business Associate Agreements, statements of work, data-processing agreements, and other signed agreements may impose additional or more restrictive privacy, security, retention, or notification requirements.
When a signed agreement imposes stricter requirements than this Privacy Policy, the applicable written agreement will control.
2. Information We Collect or Access
The information Polar Nite handles depends on the person or organization involved and the services being provided.
Website and Technical Information
The Polar Nite website does not currently provide user accounts, accept payments, sell products, or collect personal information through website forms.
Our hosting, security, spam-prevention, and website-service providers may automatically process limited technical information, including:
- IP addresses
- Browser and device information
- Access dates and times
- Requested pages
- Server and security logs
- Suspected spam, abuse, or malicious activity
This information is used to operate, maintain, secure, and troubleshoot the website.
Business and Contact Information
Polar Nite may collect information provided through email, telephone, scheduling services, support communications, meetings, referrals, or business relationships, including:
- Names
- Business names
- Job titles
- Email addresses
- Telephone numbers
- Business addresses
- Appointment information
- Communications and correspondence
- Client and prospect records
- Authorized client contacts
- Assigned authority levels
- Service requests
- Consulting and project records
Client Systems and Confidential Information
To provide technical, security, consulting, and administrative services, Polar Nite may receive privileged or administrative access to client systems and information.
Depending on the client and scope of work, this may include access to:
- Microsoft 365 and cloud environments
- Email, document-storage, and collaboration systems
- Servers, networks, computers, and managed devices
- Technical configurations and infrastructure designs
- User accounts and administrative permissions
- Security-camera systems and recordings
- Physical access-control systems
- Financial or accounting systems
- Legal or confidential business records
- Electronic protected health information
- Backup and disaster-recovery systems
- Security events, alerts, and activity logs
Polar Nite collects or accesses this information only as necessary to provide authorized technical, consulting, administrative, cybersecurity, hosting, monitoring, compliance, recovery, or support services for the applicable client.
Client information is not sold, rented, or used for unrelated purposes.
Technical Monitoring Information
Systems used to provide managed IT, security, remote administration, and backup services may automatically collect technical information such as:
- Device names and identifiers
- Usernames
- IP addresses
- Operating-system information
- Installed applications
- Device and system health
- Security alerts
- Login and identity events
- Endpoint activity
- Administrative changes
- Event and activity logs
- Backup status
- Network and system-performance information
Polar Nite uses this information to maintain systems, resolve technical issues, detect and investigate security events, administer client environments, support compliance, and protect client operations.
Polar Nite does not use its management tools to collect location data from client vehicles, personal mobile devices, or employees for tracking purposes.
Support and Service Records
Polar Nite may retain:
- Support tickets
- Chat transcripts
- Email correspondence
- Technician notes
- Service history
- Remote-support documentation
- Screenshots captured during support sessions
- Technical reports
- Security and compliance reports
- Records of administrative requests and approvals
Support calls and meetings are not routinely recorded.
Screenshots may be captured as part of normal support, troubleshooting, documentation, security, compliance, or service-continuity activities.
Clients are generally asked to save and close unrelated or sensitive work before remote support begins. Polar Nite makes reasonable efforts to avoid capturing unnecessary sensitive information and may redact or securely remove it when practical.
Individual client employees may access their own support records. Designated managers and approved points of contact may be granted access to broader organizational support records.
Payment Information
Polar Nite does not store complete payment-card or bank-account information.
Payments may be completed through checks, online payment providers, direct ACH transfers, wire transfers, or financial institutions.
The applicable payment provider or financial institution processes the underlying payment information under its own privacy and security practices.
Applicant and Employee Information
Polar Nite may collect employment and applicant information through email, job platforms, direct communication, screening providers, and employment documentation, including:
- Resumes and applications
- Employment history
- Contact information
- Interview records
- Background-check information
- Government-issued identification
- Social Security numbers
- Tax documentation
- Payroll records
- Direct-deposit information
- Training and compliance records
Background checks may be performed through an authorized third-party provider when appropriate and subject to applicable authorization and legal requirements.
Sensitive applicant and employee information is maintained separately from general client and operational information. Access is restricted to Polar Nite’s owner or another specifically authorized person when legally or operationally required.
Facility Security Information
Polar Nite operates a private business facility rather than a public retail location.
Visitors, contractors, delivery personnel, and service providers are admitted only by appointment or authorization and remain accompanied by authorized personnel while inside.
Polar Nite uses physical access-control and security-monitoring systems to protect personnel, equipment, infrastructure, confidential records, and regulated information.
These systems may collect or generate:
- Video
- Audio
- Images
- Motion events
- Access activity
- Security alerts
- AI-assisted security analytics
- Identification or tracking information used for facility security
Facility monitoring is used only when there is a legitimate security, safety, legal, compliance, investigation, or incident-related reason. It is not used for routine employee performance, attendance, or productivity monitoring.
Access to facility-security information is restricted to authorized personnel. Visitors who do not agree to facility monitoring may decline entry and request an alternative meeting method, such as a telephone or video meeting.
Because Georgia law distinguishes security surveillance from clandestine recording of private conversations, Polar Nite should maintain separate written employee and visitor notices addressing audio and AI-assisted monitoring.
3. How We Use Information
Polar Nite may use information to:
- Deliver managed IT and cybersecurity services
- Administer Microsoft 365 and cloud environments
- Maintain networks, servers, workstations, and devices
- Provide remote and on-site technical support
- Monitor system health and security
- Detect, investigate, and respond to threats
- Operate backup and disaster-recovery services
- Administer security-camera and access-control systems
- Document technical work and client environments
- Prepare client-specific technical, security, service, or compliance reports
- Provide consulting, planning, and project-design services
- Verify and complete authorized access changes
- Conduct employee onboarding and offboarding
- Schedule appointments
- Communicate about technical, consulting, billing, security, legal, and service matters
- Maintain required business, legal, audit, insurance, and compliance records
- Investigate security incidents
- Protect Polar Nite’s personnel, systems, facilities, and property
- Evaluate applicants and administer employment matters
- Meet legal, contractual, regulatory, and insurance obligations
Current communications are limited to necessary technical, consulting, scheduling, billing, security, legal, and service-related purposes.
Polar Nite does not currently conduct routine marketing-email campaigns. Any future marketing email will include an appropriate method for opting out of nonessential marketing communications.
4. Artificial Intelligence
Polar Nite may use artificial-intelligence tools to support planning, infrastructure design, calculations, general research, drafting, analysis, and operational efficiency.
Polar Nite does not knowingly submit confidential client information, credentials, regulated information, financial information, electronic protected health information, or other protected client content to public artificial-intelligence systems.
Generalized or de-identified experience may be used for internal technology, cybersecurity, or compliance training when the underlying client information is not exposed or disclosed.
AI-assisted analytics may also be used within authorized security and monitoring systems for threat detection, identity protection, physical security, and incident investigation.
5. Client Authorization and Access Changes
Polar Nite maintains documented client owners, approved managers, points of contact, and assigned authority levels.
Sensitive actions must be authorized by a documented client owner or approved manager. Such actions may include:
- Elevated or administrative access
- User-permission changes
- Information releases
- Employee onboarding or offboarding
- Credential changes
- Portal-access changes
- Managed-device changes
- Physical access-control changes
- Ownership or account transfers
Polar Nite generally requires both:
- Formal written approval by email; and
- Human verification through a telephone or video call.
This process is designed to reduce the risk of phishing, impersonation, fraudulent requests, unauthorized access, and account compromise.
6. Employee Access and Confidentiality
Access to client information is limited to authorized Polar Nite employees who need the information to perform their assigned duties.
Polar Nite maintains safeguards that may include:
- Role-based access
- Individually assigned accounts
- Multi-factor authentication
- Encryption in transit and at rest where supported
- Access and security reviews
- System and activity logging
- Protected backups
- Data-classification and handling procedures
Employees receive confidentiality, cybersecurity, and privacy training before being granted access to client systems or information.
Employees are also required to sign confidentiality or nondisclosure agreements.
Relevant administrative and security activity is reviewed regularly, including periodic monthly review where appropriate.
7. Service Providers
Polar Nite uses approved technology, hosting, security, cloud, documentation, credential-management, monitoring, support, payment, employment, and infrastructure providers to operate its business and deliver services.
These providers may store or process information only as necessary to provide authorized services to Polar Nite or its clients.
Polar Nite evaluates providers based on applicable:
- Security requirements
- Confidentiality obligations
- Contractual controls
- Operational needs
- Compliance requirements
- Risk considerations
Use of a service provider does not authorize that provider to use Polar Nite or client information for unrelated purposes.
8. Subcontractors and Third-Party Access
Polar Nite does not provide client information to subcontractors, vendors, or outside parties without the client’s written authorization, except where disclosure is legally required.
When a client authorizes outside access, Polar Nite may require the approved party to complete appropriate:
- Security reviews
- Confidentiality commitments
- Cybersecurity or privacy training
- Business Associate Agreements
- Data-protection agreements
- Security audits
- Other contractual or compliance requirements
Polar Nite may limit, delay, or refuse access when the requested arrangement does not satisfy applicable security, authorization, contractual, or compliance requirements.
9. Healthcare Information
When Polar Nite provides services involving electronic protected health information and acts as a business associate, Polar Nite enters into a Business Associate Agreement when required.
The applicable Business Associate Agreement governs the permitted uses, disclosures, safeguards, reporting obligations, retention requirements, and disposition of protected health information.
HHS provides model Business Associate Agreement provisions addressing authorized uses, safeguards, breach reporting, subcontractor obligations, and handling of protected health information.
10. Security Safeguards
Polar Nite maintains administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, alteration, loss, destruction, or disclosure.
These safeguards may include:
- Multi-factor authentication
- Role-based permissions
- Individual user accounts
- Encryption where supported
- Endpoint and identity-threat monitoring
- Security logging
- Access and activity reviews
- Protected backups
- Secure credential-management controls
- Employee cybersecurity and privacy training
- Confidentiality agreements
- Incident-response procedures
- Data-classification policies
- Secure media sanitization and destruction
- Physical access controls
- Vendor and service-provider reviews
The FTC advises businesses that collect sensitive information to maintain appropriate security, restrict access, keep privacy promises accurate, and dispose of information securely when required.
No storage, transmission, monitoring, or security method can guarantee absolute protection. Polar Nite therefore uses layered safeguards based on the type, sensitivity, location, and purpose of the information involved.
References to HIPAA, the FTC Safeguards Rule, NIST guidance, or other frameworks describe requirements or practices that may inform Polar Nite’s security program. They do not represent third-party certification unless expressly stated in writing.
11. Data Retention
Polar Nite generally retains business, client, technical, support, compliance, applicant, and employment records for a minimum of seven years.
Information may be retained longer when reasonably necessary for:
- Continued service
- Technical continuity
- Future client support
- Future hiring consideration
- Legal requirements
- Contractual obligations
- Compliance obligations
- Audits
- Insurance matters
- Security investigations
- Litigation
- Legal holds
- Other documented business requirements
Polar Nite does not routinely delete information solely because a client relationship has ended.
Credentials and Passwords
Active passwords and administrative credentials are treated differently from general business and technical records.
Credentials are retained only while needed to provide authorized services. They should be changed, transferred, disabled, or removed when:
- The client relationship ends
- An employee is offboarded
- Authority changes
- The client changes technology providers
- A security concern requires rotation
Facility Security Records
Facility security recordings and related security-event information are generally retained for approximately four to six months.
They may be retained longer when needed for:
- A security incident
- An investigation
- A legal hold
- Litigation
- An insurance matter
- A compliance requirement
- Another documented business need
Applicant Records
Applicant information is generally retained for at least seven years and may be retained longer because Polar Nite reviews previous applicants when future positions become available.
Former applicants may request deletion, subject to applicable legal, compliance, litigation-hold, retention, or active hiring requirements.
Anonymized Information
Polar Nite may retain anonymized or aggregated information indefinitely when it no longer identifies a specific person or client.
12. Deletion and Media Destruction
Polar Nite does not routinely delete records that remain subject to retention, legal, contractual, operational, security, or compliance requirements.
When deletion or destruction is required by law, contract, approved request, retention expiration, or documented operational need, Polar Nite uses methods appropriate to the media type and sensitivity of the information.
These methods may include:
- Secure erasure
- Cryptographic erasure
- Manufacturer-supported sanitization
- Approved overwriting procedures
- Physical destruction
Media that cannot be reliably sanitized may be physically destroyed.
Polar Nite documents completed media destruction, including the applicable device or media, date, method, and person who performed or verified the destruction.
Current NIST guidance recommends maintaining a media-sanitization program and selecting sanitization or destruction methods according to the media type and sensitivity of the information.
13. Client Reports and Internal Training
Polar Nite may prepare client-specific technical, security, compliance, infrastructure, or service reports.
Client-specific reports are provided only to an authorized client owner, manager, or approved point of contact.
Polar Nite may also create anonymized or aggregated internal reports regarding service trends, device status, security events, technical patterns, or compliance findings, provided the information does not identify a specific client or individual.
Generalized and de-identified service experience may be used for internal technology, cybersecurity, compliance, and employee training without exposing the underlying client data.
14. Security Incidents and Breach Notification
Polar Nite maintains an incident-response and breach-notification process.
When required, Polar Nite will notify affected clients according to applicable:
- Law
- Contract
- Business Associate Agreement
- Data-protection agreement
- Insurance obligation
- Compliance requirement
Polar Nite follows any notification timeframe imposed by the applicable obligation.
Relevant records may be preserved beyond normal retention periods when needed for an investigation, legal hold, audit, insurance matter, security incident, or litigation.
15. Legal Disclosures
Polar Nite does not voluntarily disclose client information or facility-security records to outside parties without authorization.
Information may be disclosed when Polar Nite is legally required to respond to:
- A valid subpoena
- A court order
- A lawful government request
- A legal process
- Another mandatory legal obligation
Polar Nite will seek to limit any disclosure to the information legally required.
16. Privacy Requests
Individuals and authorized client representatives may request access to, correction of, or deletion of applicable information by contacting:
Polar Nite may require verification of the requester’s identity and authority before acting on a request.
Polar Nite may deny or limit a request when retaining, restricting, or protecting the information is necessary for:
- Legal obligations
- Contractual obligations
- Security requirements
- Compliance
- Insurance
- Audits
- Active litigation
- Legal holds
- Employment obligations
- Applicable retention requirements
- Protection of Polar Nite or client systems
- Protection of another person’s or organization’s rights and security
17. Children’s Privacy
Polar Nite’s website and services are intended for businesses and adults.
Polar Nite does not knowingly direct its website or business services to children under 13 or knowingly collect personal information from children through its website.
18. Third-Party Websites and Services
The Polar Nite website may contain links to external scheduling, mapping, social-media, and other third-party services.
Those services are governed by their own privacy policies and terms.
Polar Nite is not responsible for the content, security, availability, data handling, or privacy practices of third-party websites and services.
19. Changes to This Privacy Policy
Polar Nite reviews this Privacy Policy at least annually and may update it sooner when its business practices, technology, services, risks, or legal requirements change.
Revised versions will be posted with an updated effective date.
20. Contact Information
Questions, privacy requests, or concerns may be submitted to:
Polar Nite
8744 Main St., Suite 401
Woodstock, GA 30188
8744 Main St., Suite 401
Woodstock, GA 30188
Email: support@polarnite.com