Polarisk

Polarisk · Privacy

What we collect, and what we never collect

How Polarisk handles data, with the promise in plain English first and the formal notice underneath.

Last updated 26 July 2026. Applies to polarisk.co.uk, the Polarisk Assessment and the health surveillance platform.

In plain English

The promise

What we never do

  • We never show a psychosocial result for fewer than five responsesThe floor is enforced on the server, and it is applied to the group sizes your organisation declares to us. We cannot check those numbers from here, so opening a cycle records who attested to them and the signed report prints that name beside the figures. Complementary suppression stops a small group being recovered by subtraction, and response counts move in blocks of five while a cycle is open, so no one can watch a single person answer. The size of those blocks is fixed by us and cannot be varied by whoever is viewing the report. A July 2026 review found that it could be, and that two different settings gave two figures whose difference was one person. That is now closed.
  • We never build per-employee psychosocial dashboardsThere is no screen, anywhere, that shows how one named person answered a psychosocial survey.
  • We never give an employer the clinical detail behind a fitness outcomeYour organisation receives fit, fit with adjustments, or not fit, plus any recommended adjustment. Not the answers, the symptoms or the clinical reasoning.
  • We never put trackers on this websiteNo analytics, no advertising pixels, no third-party scripts, no hosted fonts. You can check the page source, and so can your network tab.
  • We never sell or share your data for marketingData is used to produce your report and run your programme, and for nothing else.

What we do

  • Both free tools store nothing on our serversThe readiness check and the surveillance check run and score entirely in your browser. Close the tab and they are gone.
  • Health surveillance answers go to a clinician, not to your employerThey are held as part of a clinical record controlled by the signing clinician, and every account able to open that record is named on it.
  • We hold data under a written agreementWith your organisation, for a defined period, with retention set per programme.

The formal notice

Who we are

Polarisk provides occupational health services: statutory health surveillance and physician-signed psychosocial risk assessment. In this notice, "we" and "Polarisk" mean the Polarisk business operating polarisk.co.uk. For anything in this notice, including a data protection request, contact us at privacy@polarisk.co.uk.

Controller, processor, and the third role

For visitors to this website, Polarisk is the data controller for the limited information described below.

For a psychosocial Assessment, your organisation is the controller for its workforce survey and Polarisk acts as its processor, under a written data processing agreement and on documented instructions.

For health surveillance there are three roles rather than two, and the third is the one most often got wrong. Your organisation is the controller: it decides that surveillance happens, who is in scope, and what is done with outcomes. Polarisk is its processor. The signing clinician is an independent controller of the clinical record and the professional judgment, because a clinician's duty of confidence is owed to the worker personally and is not the employer's to direct. It follows that an employer cannot instruct disclosure of the clinical detail behind an outcome, and the platform is built so it cannot be made to try.

What this website collects

This website uses no analytics, advertising or third-party tracking, and sets no non-essential cookies. Our hosting provider processes standard server logs, including IP address and request information, to deliver the site securely and guard against abuse. Booking a call is handled by our scheduling provider on its own pages; if you book, you provide that information directly to them under their privacy terms.

The free tools

The readiness check and the surveillance check run entirely in your browser. Answers are scored on your own device and are not sent to or stored on our servers. If you arrive with information in the web address, such as a sector or organisation size from an outreach link, it is used only to tailor what you see and is not recorded by us.

Health surveillance: what is processed

This is the part of our processing that involves special category data under UK GDPR Article 9, and it is described in full here rather than summarised.

  • Worker details, supplied by your employerName, employee reference, job title, department, site, night-shift status, and the statutory programmes the role triggers. Ordinary personal data.
  • Health questionnaire answers, supplied by the workerSymptom screening for the relevant programme: hearing, hand-arm vibration, respiratory, skin, night work or safety-critical fitness. Special category data.
  • The clinical assessmentDrafted findings, the clinician's reviewed findings, the clinical note and the disposition. Special category data.
  • The outcomeFit, fit with adjustments, or not fit pending review, with a validity date and any workplace adjustment the employer must make. Personal data, and deliberately carrying no diagnosis, symptom or clinical reasoning, which is why it is the only part the employer receives.
  • ProvenanceHow each set of answers arrived, who issued the link, and which clinician opened and signed the record, sealed into the record rather than reconstructed afterwards.

Lawful basis

Where Polarisk is controller for website data, our basis is our legitimate interest in running a secure website.

Where your organisation is controller, it relies on its own basis. For health surveillance that is typically its legal obligation in the field of employment under Article 6(1)(c), with the Article 9 condition for processing special category data usually being obligations in the field of employment and social protection, read with the relevant condition in the Data Protection Act 2018. The signing clinician additionally relies on the conditions available for the provision of health care and occupational medicine. Your DPIA should confirm the bases you rely on; ours is a processor's contribution to it, not a substitute for it.

Retention

Server logs are kept only as long as needed for security and troubleshooting, then deleted. Psychosocial Assessment data is held for the period set in the agreement with your organisation, then returned or securely deleted.

Health surveillance records are different, and the difference matters. Statutory retention for some exposure health records runs for up to forty years from the last entry, and records must be retained when a worker leaves rather than disposed of with the rest of their personnel file. The platform therefore does not delete clinical records on a worker's departure. The retention schedule applying to your programmes is agreed in writing before a programme begins.

Your rights

Under UK data protection law you have rights to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability, subject to the usual conditions and to the statutory retention duties described above.

For psychosocial survey answers, responses are aggregated and hold no identifier, so we frequently cannot single out one person's response. That is by design rather than an obstruction.

For health surveillance, a worker can ask for their own clinical record. Because the signing clinician is the independent controller of that record, a request for clinical detail is directed to them and we will help route it. Requests about the fitness outcome held by your employer go to your employer as controller.

You may complain to the Information Commissioner's Office at ico.org.uk at any time.

Sub-processors

Hosting and storage are provided by Netlify (Netlify, Inc.), which is our only sub-processor. There is no analytics provider, no advertising provider and no AI provider processing client data today. Any addition is notified to clients before it is enabled.

International

The product is built and delivered UK-first, and it is designed for UK employers and UK law. Application data, including health surveillance records, is currently stored and processed on our hosting provider's infrastructure in the United States (US East). That is a transfer outside the UK. Netlify's Data Processing Agreement provides for two routes. Netlify holds an active certification under the EU-US Data Privacy Framework and its UK Extension, and that certification is currently scoped to non-HR data. It also provides that the UK International Data Transfer Addendum is treated as executed between us, governed by the laws of England and Wales. Workforce health records are employee data, so we are confirming with Netlify which of those two routes applies to them rather than assuming, and we will give your data protection officer the answer in writing. We would rather show you an open question than a tidy answer we have not checked.

Security

The controls behind these commitments, and the items we have not yet closed, are set out on the security page in the detail a data protection officer needs.

Changes

If we change this notice we will update the date at the top. Material changes affecting an active engagement are raised with your organisation directly.

Contact

Privacy queries, data protection requests and anything else in this notice reach us at privacy@polarisk.co.uk. Our company registration details will be published here and in the footer once available.

For reviewers

The detail your DPO will ask for

Role boundaries, platform controls, sub-processors, retention and the open items we have not closed, set out for data protection officers and IT reviewers.