SecurityPrivacy FAQ

Privacy FAQ

This page addresses frequently asked questions and common privacy topics for Polyaxon.

If you don't find a solution to your issue here, reach out to [email protected]

Do you use customer data to train AI models?

No. Polyaxon does not train or fine-tune ML models on Client Data. See terms of service for more details.

How long is data retained?

Polyaxon retains metadata until the user deletes it by default, regardless of plan. Activity logs and audit trail are retained for 3 months for plans with the feature enabled by default, and the service can offer a custom retention interval for customers with custom needs. See managing personal data for more details.

How can we delete data?

All customer metadata stored on Polyaxon servers is eradicated upon a customer's termination of service and deletion of account after a pre-deletion cleanup and a 4-hour waiting period to prevent accidental cancellation. Data can also be deleted upon request and via Polyaxon's REST API and UI. Users have the ability to remove individual metadata via bulk delete buttons.

How do you delete data after the End of the Contract?

All customer metadata stored on Polyaxon servers is eradicated upon a customer's termination of service and deletion of account after a pre-deletion cleanup and a 4-hour waiting period to prevent accidental cancellation.

How does your data classification policy look like?

Our Data Classification Policy organizes all information to ensure it receives the appropriate level of security based on its sensitivity. Data is categorized into three levels: Confidential for sensitive customer and employee data, Internal Use for default business information, and Public for information with no access restrictions. Each classification level has specific handling rules, such as limiting access to Confidential data on a strict need-to-know basis, to prevent unauthorized disclosure.

How does your data protection policy look like?

Our Data Protection Policy ensures all customer data at rest is stored on encrypted volumes, with direct employee access to production systems disabled by default. We enforce strict logical separation of customer data at both the database and API layers to prevent unauthorized access, while continuously monitoring our cloud infrastructure. Any necessary access to production data is granted on a temporary, need-to-know basis with explicit leadership approval, and all personnel are bound by non-disclosure agreements.

How does your data retention policy look like?

Our Data Retention Policy states that customer data is retained for as long as an account remains active. Once an account is voluntarily closed, the associated data enters an expired state and is permanently removed after a pre-deletion cleanup and a 4-hour waiting period to prevent accidental cancellation. For involuntarily suspended accounts, a grace period is provided to resolve any issues before the account is closed and the standard data deletion process begins.