Effective: July 15, 2026. Last updated: July 15, 2026.
This Privacy Policy describes how WatchSuit ("we," "us," or "our") collects, uses, and shares information about you when you use our website, products, and services. By using WatchSuit you agree to the practices described below. WatchSuit publishes this privacy policy to satisfy GDPR Art. 13-14, CCPA § 1798.130, and CPRA disclosure obligations.
We collect the following categories of personal information from visitors to our website and from registered customers:
We rely on the following lawful bases under GDPR Art. 6:
At or before the point of collection, we provide you with a notice at collection describing the categories of personal information collected and the purposes for which they are used. The categories of personal information we collect are listed in Section 1 above. We use them for the purposes described in Section 4.
We do not sell or share your personal information for cross-context behavioral advertising. If that changes, we will provide a "Do Not Sell or Share My Personal Information" link in the footer of every page of our website.
We use the information we collect to:
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
California residents may exercise these rights by following the Submit a Data Request link below. We will respond within 45 days as required by CCPA § 1798.130.
California residents and EU data subjects may submit a request to access, delete, correct, or export their personal information using the mechanisms below. Each request is a formal data subject request and will be processed within the timeframe required by applicable law (45 days under CCPA, 30 days under GDPR).
We will verify your identity before fulfilling the request. You may also exercise your right to delete data associated with any prior right to access or right to know requests.
WatchSuit does not sell your personal information to third parties for monetary consideration, and we do not share it for cross-context behavioral advertising. If our practices change, California residents may opt out of sale or sharing by enabling the Global Privacy Control (GPC) signal in their browser, or by submitting a manual opt-out request through the data request form above.
To opt out of sale or sharing entirely, follow the Submit a Data Request link or send an email with the subject line "Opt Out of Sale" to privacy@watchsuit.polsia.app.
WatchSuit honors the Global Privacy Control (GPC) browser signal as a valid opt-out of sale or sharing for California residents. When we detect the GPC signal header (Sec-GPC: 1) being sent by your browser, we treat it as a universal opt-out signal and propagate it across all of your interactions with our website. We do not require you to submit a separate opt-out form when the GPC signal is present.
WatchSuit is not a covered entity or business associate under HIPAA, and we do not intentionally process Protected Health Information (PHI). However, customers whose monitoring targets involve health data handling are responsible for:
Customers who enter into a BAA with WatchSuit will receive a HIPAA compliant addendum covering the limited subprocess scope where incident response, breach notification, or breach response coordination is required. Our standard subprocessor list (see Section 11) and the uses and disclosures covered by your BAA are documented in the contract you signed.
In the event of a security incident that compromises unencrypted personal information, WatchSuit will notify affected customers without unreasonable delay and in any event within 60 days of discovery, consistent with HIPAA § 164.404. Notification will include:
Notify affected users via the email address associated with their WatchSuit account, and via a banner on the dashboard at next login.
WatchSuit relies on the following third-party processors and subprocessors to deliver the service. We update this list at least 30 days before adding a new subprocessor; existing customers may opt out of any new subprocessor for a full refund of the unused portion of their subscription.
| Subprocessor | Purpose | Location |
|---|---|---|
| Neon (Postgres hosting) | Database hosting | US (AWS us-east-1) |
| Render | Application hosting | US (Oregon) |
| Postmark | Transactional email | US |
| Stripe | Payments | US / Ireland |
| Polsia Analytics | First-party analytics (consent-gated) | US |
See the full subprocessor list at /subprocessors. We maintain a current business associate list for HIPAA-impacted customers under the BAA addendum.
We retain your personal information for as long as your account is active or as needed to provide the service. After account closure, we retain billing records for 7 years (for tax compliance) and aggregated, anonymized compliance scans indefinitely. You may request earlier deletion via the data request form.
We will post any material changes to this privacy policy on this page with an updated "Last updated" date. For significant changes we will provide direct notice via email at least 30 days in advance.
Questions about this privacy policy or our data practices? Email privacy@watchsuit.polsia.app or write to WatchSuit Privacy Office, P.O. Box 4129, Austin, TX 78701.