modal-close
Polly small logo

Login:

modal-close Polly small logo

Add Polly to:

Slack
Zoom
Meet
Slides
Powerpoint

 

Trust center

Security and trust,
built into everything we do

See how Polly protects your data, meets compliance standards, and keeps your organization's information secure, with full transparency into our practices and certifications.

Contact Us

Compliance

SOC 2 Type II certification
EU-U.S. DPF Certified
UK Extension to the EU-U.S. DPF Certified
Swiss-U.S. DPF Certified
Annual 3rd-party penetration tests and audits conducted
Business Continuity and Disaster Recovery Plan

Resources

Security documentation

Privacy, Terms & FAQs

Performance, Analytics & Monitoring

Controls

Infrastructure security

  • Data encrypted in transit and at rest
  • SOC 2 Type II audited security program

Organizational security

  • Privacy program aligned with GDPR, SCC, and CCPA; EU-U.S. Data Privacy Framework certified, including the UK Extension and Swiss-U.S. DPF
  • Single Sign-On via Slack, Microsoft Entra ID (Azure AD), Zoom, or Google Workspace
  • Enterprise Grid support for large organizations

Product security

  • Reduced access scopes to help keep messages private
  • Tiered admin permissions for team and user management
  • Feature-specific permissions are requested only when a feature is enabled, and require Slack admin approval

Internal security procedures

  • Security program tested, audited, and certified
  • 99.5% uptime SLA for deployment at scale
  • Priority support for enterprise customers

Data collected

  • Customer personally identifiable information
  • Employee personally identifiable information
  • Personal health information

Subprocessors

Entity Name
Subprocessing Activity
Entity Country
Amazon Web Services, Inc.

Cloud Service Provider

United States

Amplitude, Inc.

Cloud-based Analytics Provider

United States

Mailgun Technologies Inc.

Cloud-based Email Notifications

United States

FAQ

How does Polly use my team’s data?

Polly uses your organization's data to deliver the service, including creating, processing, and displaying polls, surveys, and results for your team. Data is used to operate the product, support core functionality, and help admins and authorized users review insights generated in Polly. Polly does not read or store messages in your Slack workspace, in public, private, or group channels, with four exceptions: messages where Polly is mentioned directly, messages sent with a Polly slash command, private messages sent to the Polly app channel, and messages Polly itself publishes.

What data does Polly store from Microsoft Teams?

Polly reads and stores only the information required to deliver the service. This includes a user's name, used to display results and attribute votes and comments; their UPN and Azure AD object ID, used to send chat messages and attribute voting and authoring activity to the correct person; team names, used to identify where Polly is installed within a tenant; and channel names, so users can choose where to send surveys. Polly also stores survey content, meaning titles and questions, along with survey responses, meaning votes and comments, both of which are necessary to provide the service.

How can we request access to security documents like the SOC 2 Report or penetration test report?

You can request access directly through the Trust Center’s Request Access section. Submit the form with your business details and the documents you need, and Polly’s team will review the request before sharing restricted materials.