Perform data analytics – Better understand
utilization, capacity, and performance.
Personal data is processed for display and reporting
purposes only.
For a detailed listing of the specific data elements
processed, please contact your Poly representative
to request the companion non-public white paper for
this product.
HOW CUSTOMER DATA IS STORED
AND PROTECTED
The RealAccess database server is in a SSAE 16
Type II certified data center in the United States that
runs dedicated databases and application servers.
When the RealAccess database server receives data
from the customer, it is verified for integrity,
processed, and saved in the database.
Poly may change the location of the RealAccess
database server and details of any such change shall
be set forth in the latest copy of this white paper
available on Poly’s website.
For transferring personal data of EU customers to the
US, Poly uses an Intragroup Data Transfer
Agreement incorporating the EU Standard
Contractual Clauses as the transfer mechanism.
The RealAccess database and application servers
reside in the data center behind a fully patched
firewall that is also managed. Access for any services
not required by RealAccess is blocked.
DATA PORTABILITY
RealAccess customer admins and users who have
access to the portal can download all customer data
from the RealAccess portal.
THIRD-PARTY PROVIDERS (SUBPROCESSORS)
Poly shares customer information with service
providers, contractors, or other third parties to
assist in providing and improving the service. All
sharing of information is carried out consistent with
the Poly Privacy Policy.
DATA DELETION AND RETENTION
All information collected from the customer is
stored in the multi-tenant database with email
domain information configured as the access
control mechanism. Nothing is transmitted outside
of RealAccess. All data is self-contained in the
database in the data center.
Poly may retain customer data for as long as
needed to provide the customer the RealAccess
service. After a customer’s subscription terminates
or expires, Poly will delete personal data within one
year of termination or expiration of the service.
When a customer makes a request for deletion
(privacy@poly.com), Poly will delete the requested
data 30 days, unless the data is required to be
retained for Poly’s legitimate interests or if needed
to provide the service to customer. Poly may
“anonymize” personal data in lieu of deletion. The
anonymization process is irreversible and includes
but is not limited to searching and sanitizing all
customer-specific data (e.g., name, site
information, and IP address) with randomly
generated alphanumeric characters.
CHANGE MANAGEMENT
A formal change management process is followed
by all teams at Poly to minimize any impact on the
services provided to the customers. All changes
implemented to Polycom RealConnect for Office
365 service go through vigorous QA testing where
all functional and security requirements are
verified. Once QA approves the changes, they are
pushed to a staging environment for UAT (User
Acceptance Testing). Only after final approval from
stakeholders, changes are implemented in
production. All scheduled changes are applied
during regularly scheduled maintenance periods.
While emergency changes are processed on a
much faster timeline, risk is evaluated, and
approvals are obtained from stakeholders prior to
applying any changes in production.