1. About this policy
Guardian Security, Inc. and its affiliates (together, "Guardian", "we", "us") provide the Guardian Sentinel security platform and related professional and managed services. This Privacy Policy describes how we handle personal data when we act as a controller — that is, when we decide why and how the data is processed.
It applies to personal data we collect when you visit
guardian.com or any Guardian sub-domain, request a demonstration or
pricing, register for an event or webinar, download research, apply for a job, contact
support, join the partner programme, or administer a Guardian subscription on behalf of
your employer.
It does not apply to the security telemetry that a customer organisation sends to its Sentinel tenant. For that data Guardian acts as a processor under written instructions from the customer, and the Data Processing Addendum governs. Nor does it apply to any third-party website that a Guardian page happens to link to; those operators publish their own policies and we do not control them.
We have written this policy in plain English. Where a legal term of art is unavoidable we define it on first use. If any part of it is unclear, write to [email protected] and we will explain it — that request is itself useful feedback and we treat it that way.
2. Who we are and how to contact us
The controller for personal data described in this policy is Guardian Security, Inc., a Delaware corporation with its principal place of business at 1400 Congress Avenue, Suite 900, Austin, Texas 78701, United States.
For individuals in the European Economic Area, the controller is Guardian Security Ireland Limited, 2 Grand Canal Quay, Dublin 2, D02 A342, Ireland, which also acts as our Article 27 representative. For individuals in the United Kingdom, our UK representative is Guardian Security UK Limited, 30 Finsbury Square, London EC2A 1AG.
| Purpose | Contact | Response target |
|---|---|---|
| General privacy questions | [email protected] | 5 business days |
| Data subject rights requests | [email protected] | Acknowledged in 72 hours |
| Data Protection Officer | [email protected] | 10 business days |
| Security vulnerability reports | [email protected] | 8 business hours |
| Law enforcement requests | [email protected] | Per legal process |
| Postal correspondence | Attn: Privacy, 1400 Congress Ave, Suite 900, Austin TX 78701 | 15 business days |
Our Data Protection Officer reports to the General Counsel and has a standing right to raise concerns directly with the board. The DPO can be contacted confidentially and does not require you to route your question through an account manager.
3. When Guardian is a controller and when it is a processor
This distinction determines which document governs your data and who you should approach with a request, so it is worth two minutes of your time.
Where Guardian acts as a processor, we process personal data only on the customer's documented instructions, we do not determine the purposes, and we assist the customer in responding to requests from individuals. Where Guardian acts as a controller, this policy governs and you can approach us directly.
There is one narrow exception worth stating plainly: Guardian processes limited service telemetry — such as sensor health, ingest volume and feature usage counters — as a controller for the purposes of operating, securing and improving the service. That data is pseudonymised, is never used to profile individual end users, and is described in section 4.
4. Personal data we collect
We collect only what we need for a stated purpose, and we prefer not to hold data we cannot justify. The categories below are exhaustive for controller-role processing.
4.1 Data you give us
- Identity and contact data — name, job title, employer, work email address, work telephone number, country and preferred language.
- Account credentials — username, hashed password, multi-factor enrolment metadata and single sign-on identifiers for the Guardian console, partner portal or trust portal.
- Commercial and billing data — purchase orders, billing contact, tax identifiers, and payment card tokens held by our payment processor. Guardian never stores full payment card numbers.
- Support and correspondence data — the content of tickets, emails, chat transcripts and call notes, including any files you choose to attach.
- Recruitment data — curriculum vitae, work history, references, interview notes, work authorisation status and, where required by law and permitted locally, background screening results.
- Event data — registration details, dietary or accessibility requirements you tell us about, and session attendance.
- Marketing preferences — the topics you asked to hear about and the channels you consented to.
4.2 Data we collect automatically
- Device and connection data — IP address, browser type and version, operating system, screen dimensions, referring URL and time zone.
- Usage data — pages viewed, documents downloaded, links clicked, search terms entered on our site, and the duration of a session.
- Console service telemetry — pseudonymised records of which product features were used, error rates, sensor version distribution and ingest volume.
- Security logs — authentication attempts, administrative actions and anomalous access patterns relating to Guardian's own systems, which we retain to protect the service and its users.
4.3 Data we receive from others
- From your employer — if your organisation buys Guardian, an administrator may create a console account for you and supply your work contact details.
- From partners and distributors — contact details of individuals involved in a registered opportunity, provided under the partner agreement.
- From public and licensed business sources — company size, industry and firmographic attributes used to prioritise outreach. We do not buy behavioural profiles, and we do not enrich records with data about your personal life.
- From identity providers — where you sign in with your employer's single sign-on, we receive the identifiers your employer chose to release.
4.4 Data we deliberately do not collect
Guardian does not seek special category data — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation — through any of the channels described in this policy. The only exceptions arise where you volunteer it (for example, a dietary requirement at an event, or an accommodation request during recruitment), in which case we use it only for that purpose and delete it promptly afterwards.
5. Why we use personal data, and our legal bases
Under the GDPR, UK GDPR and equivalent laws we must have a lawful basis for each purpose. Ours are set out below. Where we rely on legitimate interests we have carried out and documented a balancing assessment, and you can request a summary of it.
| Purpose | Data categories | Legal basis |
|---|---|---|
| Providing and administering the service | Identity, account credentials, service telemetry | Performance of a contract |
| Responding to enquiries and demo requests | Identity and contact data, correspondence | Steps prior to entering a contract; legitimate interests |
| Billing, collections and tax records | Commercial and billing data | Performance of a contract; legal obligation |
| Providing customer support | Support and correspondence data | Performance of a contract |
| Direct marketing to business contacts | Identity and contact data, marketing preferences | Consent where required; otherwise legitimate interests |
| Measuring and improving our website | Device, connection and usage data | Consent for non-essential cookies |
| Securing our own platform and detecting abuse | Security logs, device and connection data | Legitimate interests; legal obligation |
| Product research and reliability engineering | Pseudonymised service telemetry | Legitimate interests |
| Recruitment and hiring decisions | Recruitment data | Steps prior to a contract; legitimate interests; consent where local law requires |
| Complying with legal and regulatory obligations | Any category, as required | Legal obligation |
| Establishing, exercising or defending legal claims | Any category, as required | Legitimate interests; legal claims |
On marketing specifically: we contact business people about business security software. We do not market to personal email addresses, we include an unsubscribe link in every commercial message, and unsubscribing takes effect within 48 hours across all Guardian sending systems rather than only the list you clicked from. Withdrawing marketing consent never affects the service your organisation receives.
6. Cookies and similar technologies
Our public website uses a small number of cookies and comparable technologies. Outside the strictly necessary category, none are set before you have given consent through the banner, and you can change your choice at any time from the cookie preferences link in the footer of any page.
| Category | What it does | Consent | Maximum lifetime |
|---|---|---|---|
| Strictly necessary | Session integrity, load balancing, CSRF protection, cookie choice storage | Not required | 12 months |
| Preferences | Remembers language, region and light or dark theme | Required | 12 months |
| Analytics | Aggregate page and campaign performance, first-party only | Required | 13 months |
| Marketing | Measures advertising effectiveness and limits repeat impressions | Required | 90 days |
We honour Global Privacy Control signals as an opt-out of sale and sharing where applicable law recognises them, and we treat a browser-level Do Not Track signal as a withdrawal of consent to analytics and marketing cookies even though no law currently obliges us to.
The authenticated Guardian console uses only strictly necessary cookies. There is no advertising technology, no session replay and no third-party analytics inside the product.
7. When and with whom we share personal data
We do not sell personal data. We have never sold personal data, and we do not share it for cross-context behavioural advertising as those terms are defined under US state privacy laws. We disclose personal data only in the circumstances below.
- Service providers and subprocessors acting on our documented instructions — cloud hosting, email delivery, support ticketing, payment processing and analytics. Each is contractually bound, security-assessed before engagement and reassessed annually. The current list is published on Trust & security.
- Guardian affiliates where necessary to provide the service, deliver support in your region or manage the customer relationship, under an intra-group data transfer agreement.
- Channel partners and distributors, where you have engaged with them or where they registered the opportunity, limited to what is necessary to serve you. Partners are separate controllers for their own use of that data.
- Professional advisers — auditors, lawyers, insurers and bankers — under duties of confidentiality.
- Acquirers in connection with a merger, acquisition, financing or sale of assets, subject to confidentiality obligations, and with notice to you if material changes to this policy follow.
- Government and law enforcement where we are legally compelled. We require valid legal process, we challenge overbroad or improperly served demands, and we notify the affected individual or customer unless prohibited by law — and where prohibited, we challenge the prohibition and notify as soon as it lapses.
8. International data transfers
Guardian operates globally, so personal data may be transferred to and processed in countries other than your own — principally the United States, the European Union and the United Kingdom, and in the regions listed in our compliance centre where a customer has selected them.
Where personal data leaves the EEA, the UK or Switzerland, we rely on one or more of the following:
- An adequacy decision by the European Commission or the UK government covering the destination country.
- Guardian Security, Inc.'s certification under the EU–US Data Privacy Framework, the UK Extension and the Swiss–US Data Privacy Framework.
- The 2021 Standard Contractual Clauses, with the UK International Data Transfer Addendum and the Swiss annex where relevant.
- Supplementary technical and organisational measures, including per-tenant encryption with customer-held keys, strict data minimisation and a documented policy of challenging unlawful access demands.
We publish a transfer impact assessment describing the legal regimes we have considered, the risks identified and the measures applied. It is reviewed annually and after any material change in law. You can request a copy at any time.
Customers who cannot accept international transfer at all can select an in-region deployment where telemetry, indices and backups never leave the chosen region, and where Guardian support access from outside the region requires the customer's per-case approval, recorded in the tenant audit log.
9. How long we keep personal data
We keep personal data only as long as we need it for the purpose we collected it for, plus any period required by law. Retention is enforced by automated deletion jobs rather than by policy alone, and the schedule is audited annually.
| Data category | Retention period | Trigger |
|---|---|---|
| Marketing contact records | 24 months | Last meaningful engagement |
| Enquiry and demo request data | 24 months | Date of enquiry, if no contract follows |
| Customer account and console users | Contract term + 90 days | Termination of the subscription |
| Support tickets and correspondence | 36 months | Ticket closure |
| Billing, invoicing and tax records | 7 years | End of the financial year |
| Unsuccessful job applications | 12 months (or as you consent) | Decision date |
| Website analytics | 13 months | Collection date |
| Guardian security logs | 24 months | Event date |
| Suppression list (do not contact) | Indefinite | Kept precisely so we do not contact you again |
Where we are required to preserve data for litigation or regulatory investigation, a legal hold suspends deletion for the affected records only, is documented, and is released as soon as the obligation ends.
10. How we protect personal data
We apply the same controls to our own data that we sell to our customers. In summary: encryption in transit with TLS 1.3 and at rest with AES-256-GCM; no standing production access for any employee; just-in-time, dual-approved and fully recorded administrative sessions; phishing-resistant multi-factor authentication for all staff; continuous monitoring by the Guardian Sentinel platform itself; and independent penetration testing at least quarterly.
A full description — including our secure development lifecycle, tenant isolation model, key hierarchy and incident notification commitments — is published on Trust & security, and our current attestations are listed in the compliance centre.
No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it and will notify affected individuals without undue delay where the law requires or where the notification would let you protect yourself.
11. Your privacy rights and how to exercise them
Depending on where you live, you may have some or all of the rights below. Guardian extends these rights to every individual worldwide as a matter of policy, whether or not local law obliges us to.
- Access — obtain confirmation of whether we process your personal data and receive a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where we no longer have a valid reason to keep it.
- Restriction — ask us to pause processing while a dispute about accuracy or legitimacy is resolved.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection — object to processing based on legitimate interests, and object to direct marketing at any time with no justification required.
- Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Non-discrimination — receive the same quality of service whether or not you exercise a privacy right.
- Complain — lodge a complaint with your supervisory authority. We would prefer you raise it with us first, but that is your choice and not a precondition.
11.1 How to make a request
Email [email protected] stating the right you wish to exercise and enough information for us to locate your records. We acknowledge every request within 72 hours and respond substantively within 30 days, extending by up to a further 60 days for genuinely complex requests — and if we extend, we tell you why.
We will ask you to verify your identity in proportion to the sensitivity of the request: a marketing opt-out needs nothing more than a reply from the address on file, whereas an access request covering support correspondence requires stronger verification. We do not charge a fee unless a request is manifestly unfounded or excessive, which in practice has never happened.
An authorised agent may submit a request on your behalf with written authorisation. If your request concerns data we process on behalf of a customer, we will forward it to that customer within five business days and tell you we have done so.
12. Region-specific disclosures
12.1 European Economic Area, United Kingdom and Switzerland
The controller and representative details are in section 2. Our lead supervisory authority is the Irish Data Protection Commission. You may also complain to the supervisory authority in your country of residence, place of work or the place of the alleged infringement. In the United Kingdom, that is the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner.
12.2 California and other US states
In the twelve months preceding the effective date of this policy, Guardian collected the categories of personal information described in section 4, for the purposes in section 5, from the sources in section 4.3, and disclosed them for business purposes to the recipients in section 7. Guardian has not sold personal information and has not shared it for cross-context behavioural advertising.
California residents have rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information. Guardian does not use or disclose sensitive personal information for purposes that trigger the limitation right. Equivalent rights are extended to residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware and every other US state with a comprehensive privacy law, including the right to appeal a refused request — appeals go to [email protected] and are decided within 45 days by someone who did not decide the original request.
Guardian does not knowingly process the personal information of consumers under 16 years of age, and therefore does not sell or share it.
12.3 Brazil
Processing is carried out in accordance with the Lei Geral de Proteção de Dados. Data subjects have the rights set out in Article 18, including confirmation of processing, access, correction, anonymisation, portability, deletion and information about shared use. Our Brazilian encarregado can be reached at [email protected].
12.4 Australia and New Zealand
We handle personal information in accordance with the Australian Privacy Principles and the New Zealand Privacy Act 2020. Complaints may be made to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner after you have given us a reasonable opportunity to respond.
12.5 Japan, Korea, Singapore and India
Processing complies with the Act on the Protection of Personal Information (Japan), the Personal Information Protection Act (Korea), the Personal Data Protection Act (Singapore) and the Digital Personal Data Protection Act (India), including their respective cross-border transfer, consent and grievance-officer requirements. Our grievance officer for India is reachable at [email protected].
12.6 Canada
Processing complies with PIPEDA and, where applicable, Quebec's Law 25, including the requirement to conduct privacy impact assessments before transferring personal information outside Quebec and to inform individuals of automated decision-making.
13. Automated processing, profiling and artificial intelligence
Guardian's product uses machine learning extensively to detect attacks. That processing operates on customer telemetry under the customer's instructions, not under this policy. What follows concerns automated processing of the controller-role data described here.
- We use automated scoring to prioritise sales outreach to organisations. It operates on firmographic attributes such as industry, size and technology footprint, not on individual behaviour, and it never produces a legal or similarly significant effect on a person.
- We use automated filtering to route support tickets and to detect abuse of our public systems. A human reviews any action that would restrict access.
- We do not use automated decision-making to make hiring decisions. Applicant tracking software organises applications; people read them and people decide. No candidate is rejected by an algorithm at Guardian.
- We do not use personal data collected under this policy to train generative models, and we do not send it to third-party model providers.
Where automated processing does take place, you have the right to obtain human intervention, to express your point of view and to contest the outcome. Write to [email protected] and a person will review it.
14. Changes to this policy, and how to reach us
We review this policy at least annually and whenever we make a material change to how we handle personal data. The effective date and version number at the top of this page always reflect the current text, and we maintain a dated archive of previous versions available on request.
For material changes we give at least 30 days' notice before they take effect, by email to registered account administrators and by a prominent notice on this page. If a change would require your consent, we will ask for it rather than assume it.
Questions, requests and complaints about this policy should go to [email protected], or by post to Guardian Security, Inc., Attn: Privacy, 1400 Congress Avenue, Suite 900, Austin, Texas 78701, United States. Our Data Protection Officer can be reached independently at [email protected].
If you are not satisfied with our response, you may complain to your supervisory authority. We would rather you told us first — every complaint we receive is reviewed by the DPO and reported to the board's audit and risk committee, because a privacy programme nobody complains about is usually one nobody is testing.
Guardian Security, Inc. · Privacy Policy version 7.2 · Effective 1 July 2026 · Supersedes version 7.1 of 14 January 2026. This English text is the authoritative version; translations are provided for convenience only.