Privacy at a glance
We collect only the information reasonably needed to provide, secure, support, and improve GuardVerge. We do not sell personal data. Where GuardVerge processes security or endpoint data for an organization, that organization controls the data and GuardVerge acts on its instructions.
1 Scope and our role
This Privacy Policy applies to GuardVerge websites, customer account and licensing services, hosted portals, support interactions, and related services that link to this Policy (collectively, the “Services”). “GuardVerge,” “we,” “us,” and “our” refer to the provider of those Services.
For website, account, billing, and direct support data, GuardVerge generally determines why and how personal data is processed and acts as a controller or business under applicable privacy law.
For security, user, audit, policy, and endpoint data submitted to the Services by or for a customer organization (“Customer Data”), the customer organization generally acts as the controller or business and GuardVerge acts as its processor or service provider. If your account is provided by your employer or another organization, please direct requests about Customer Data to that organization first.
2 Personal data we collect
The information we collect depends on how you interact with the Services and may include:
- Account and contact data: name, work email address, organization, account identifiers, login credentials, and communication preferences.
- Commercial and billing data: selected plan, license quantity, billing address, transaction status, invoices, and limited payment details received from a payment provider. Payment card information may be collected directly by the payment provider.
- Security and endpoint data: device and user identifiers, operating-system and software details, IP address, enrollment status, security-policy configuration, policy events or violations, administrative-rights events, and audit records.
- Usage and technical data: browser type, device type, pages or features used, dates and times of access, approximate location derived from IP address, diagnostic data, and error logs.
- Support and communications data: messages, attachments, call or meeting details, feedback, and information you provide when requesting help.
We collect data directly from you, automatically from browsers and enrolled devices, from the organization that manages your access, and from service providers supporting authentication, payments, hosting, or support.
3 How and why we use personal data
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, licenses, security features, endpoint management, support, and requested Services. | Performance of a contract; steps requested before entering a contract. |
| Authenticate users, prevent fraud or misuse, maintain audit records, and protect customers and the Services. | Legitimate interests in security and service integrity; legal obligations where applicable. |
| Process purchases, administer subscriptions, collect amounts due, and maintain transaction records. | Performance of a contract; compliance with tax, accounting, and other legal obligations. |
| Operate, troubleshoot, analyze, and improve the reliability and usability of the Services. | Legitimate interests in operating and improving the Services. |
| Respond to inquiries and send service, security, policy, and account notices. | Performance of a contract; legitimate interests in customer support and communication. |
| Send optional product news or marketing communications. | Consent where required; otherwise legitimate interests. You may opt out at any time. |
| Establish, exercise, or defend legal claims and comply with lawful requests. | Legal obligations and legitimate interests in protecting legal rights. |
Where we rely on legitimate interests, we consider the impact on individuals and do not use that basis where our interests are overridden by applicable data-protection rights. Where processing is based on consent, you may withdraw consent at any time without affecting earlier processing.
6 Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain security and audit history, comply with legal and accounting requirements, resolve disputes, and enforce agreements.
Retention periods vary according to the type of data, customer instructions and contract terms, account status, security needs, legal limitation periods, and applicable law. When data is no longer required, we delete or anonymize it, unless it must be preserved in backups for a limited period or retained by law.
7 International data transfers
GuardVerge and its service providers may process personal data in countries other than the country where you live. Those countries may have different data-protection laws. Where required, we use recognized safeguards for international transfers, such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism. You may contact us for more information about safeguards relevant to your data.
8 Data security
We use reasonable administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or loss. These measures are selected according to the nature of the data and relevant risks.
No method of transmission or storage is completely secure. You are responsible for protecting your credentials, using available security controls, and promptly notifying us if you suspect unauthorized access to your account.
9 Your privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- request access to or a copy of your personal data;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- restrict or object to certain processing;
- receive certain data in a portable format;
- withdraw consent where processing is based on consent;
- opt out of marketing communications; and
- appeal a decision or complain to your local data-protection authority.
To exercise a right, contact us using the details below. We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising an applicable privacy right.
10 Automated decision-making
GuardVerge security features may automatically identify events, calculate security status, or flag activity for review based on customer-configured policies. GuardVerge does not use website or account data to make decisions that produce legal or similarly significant effects about individuals solely by automated means. Customer organizations remain responsible for how they configure security policies and use resulting alerts or reports.
11 Children's privacy
The Services are intended for organizations and business users, not children. We do not knowingly collect personal data directly from children under 16. If you believe a child has provided personal data to us, please contact us so we can take appropriate action.
12 Changes to this Policy
We may update this Privacy Policy to reflect changes to the Services, our practices, or applicable law. We will post the revised Policy on this page and update the “Last updated” date. If changes materially affect your rights, we will provide additional notice where required.
13 Contact us
For questions, privacy requests, or concerns about this Policy or our handling of personal data, contact:
GuardVerge Privacy Email: support@guardverge.com Please use the subject line “Privacy request.”If GuardVerge processes your data on behalf of a customer organization, we may refer your request to that organization. You may also have the right to lodge a complaint with the data-protection or privacy regulator in your jurisdiction.