Skip to content

Privacy Policy

Last updated: April 2026

1. Who we are

Polar Bear ("we", "us", "our") operates the People Ops Diagnostic at people-ops-index.vercel.app. For any privacy-related inquiries, please contact us at alexey.lobachev@gmail.com.

2. What data we collect

When you use the People Ops Diagnostic, we collect:

  • Name and email address — provided by you before starting the diagnostic
  • Diagnostic answers — your responses to the 25 survey questions
  • Scores and results — calculated from your answers (overall score, dimension scores, maturity stage)
  • Marketing preference — whether you opted in to receive monthly updates
  • Usage data — standard web analytics (page views, device type) via cookies, if you consent

3. Why we collect it

  • To deliver your results — we email your diagnostic results to the address you provide (legitimate interest)
  • To send updates — if you opt in, we send monthly insights on people operations (consent)
  • To improve the diagnostic — we use aggregated, anonymised data to improve our questions and scoring (legitimate interest)
  • For benchmarking — once we have enough responses, we may provide anonymised comparison data showing where participants fall relative to others

4. Legal basis for processing

  • Legitimate interest — delivering the diagnostic results you requested, and improving our service
  • Consent — sending marketing communications (you can withdraw consent at any time)

5. How we store and protect your data

Your data is stored securely in a PostgreSQL database hosted by Neon (via Vercel). Access is restricted to authorised personnel only. We use HTTPS for all data transmission and follow industry-standard security practices.

6. Third parties

We use the following third-party services:

  • Resend — email delivery (your name and email are shared to send results)
  • Vercel — website hosting and database infrastructure
  • CookieYes — cookie consent management

We do not sell your data to third parties.

7. Data retention

We retain your diagnostic data for as long as it is needed for benchmarking and service improvement. You may request deletion at any time by contacting us at alexey.lobachev@gmail.com.

8. Your rights

Under GDPR, you have the right to:

  • Access — request a copy of the data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data
  • Portability — receive your data in a machine-readable format
  • Withdraw consent — unsubscribe from marketing emails at any time

To exercise any of these rights, email alexey.lobachev@gmail.com. We will respond within 30 days.

9. Cookies

We use cookies to manage your consent preferences and, if you agree, for analytics. You can manage your cookie preferences at any time using the cookie banner. Necessary cookies (e.g., session management) are used without consent as they are essential for the website to function.

10. Changes to this policy

We may update this policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.