Privacy Policy

Effective: 2026-08-12 · Version v2026.08.12b

1. Controller

Guard Core is operated by Guard Core ("we", "us"). For all privacy-related enquiries:

If you are located in the EU, UK, EEA, or Switzerland, you may also lodge a complaint with your local Data Protection Authority. A directory is maintained at edpb.europa.eu.

2. What we collect and why

We process personal data only for the purposes described below, based on the lawful bases set out in Article 6 GDPR.

CategoryLawful basisRetention
Account data (username, encrypted email, hashed password, encrypted 2FA secret)Art 6(1)(b) - contractAccount lifetime + 30 days post-deletion-request
Security event data (IPs, user agents, request paths, threat indicators)Art 6(1)(f) - legitimate interest + Art 6(1)(b)30-365 days per plan tier; Enterprise unlimited
Billing data (Stripe customer, subscription, invoice history)Art 6(1)(b) + Art 6(1)(c) - legal obligation7 years (legal obligation)
Usage telemetry (aggregate page views, feature usage)Art 6(1)(a) - consent24 months aggregated
Consent records (choices, policy version, IP address at consent)Art 6(1)(c) - demonstrate consent (Art 7(1))6 years after last change
Audit logs (administrative actions, DSR requests)Art 6(1)(c) + Art 6(1)(f)6 years
Service and account email (quota, agent connectivity, onboarding/setup state, outdated version notices)Art 6(1)(b), contract; Art 6(1)(f) fallback for free-tier accountsSame as Account data; send log deleted with the account
Product and marketing email (occasional feature/product announcements)Art 6(1)(a), consentSame as Account data; governed by consent while active

We send two kinds of email tied to your account. Service email tells you about the operational state of your account and the product you are running, for example that you are close to or over your monthly event quota, that a security agent you configured has stopped reporting, that you have not finished setting up an organisation, project, or agent connection, or that the guard-core version you are running is outdated. We send these because they relate to the contract you have with us or, if you are on the free tier with no paid contract, because we have a legitimate interest in keeping you informed about the state of the service you are actively running. Product and marketing email covers occasional announcements about new features or product changes. We only send this to you if you have given consent, and you can grant or withdraw that consent at any time from your account settings or by emailing [email protected]; withdrawing is exactly as easy as granting, and does not affect the lawfulness of anything already sent. You can object to service email sent under legitimate interest at any time (see Section 5); an objection to marketing email specifically is honoured automatically, without further review. Every email we send, service or marketing, carries a one-click unsubscribe link. The log of which emails were sent, suppressed, or failed, and why, is retained for as long as your account exists and is included if you request a copy of your data.

When you grant or withdraw consent while signed in, whether by ticking the marketing checkbox at signup or through the consent controls in your account settings, we record the IP address the request came from at that moment; this is stored to help demonstrate a valid consent record as required by Art 7(1) GDPR, under the same Art 6(1)(c) legal-obligation basis as the rest of the consent record, is encrypted at rest, is never returned by any API endpoint, and is retained for the same 6 years as the rest of the record, after which it is deleted with it. If we cannot determine an IP address for a given request, the field is left blank rather than blocking the consent action.

We do not process special categories of data (Art 9 GDPR). We do not engage in automated decision-making producing legal effects (Art 22 GDPR).

3. Sub-processors

A live list is maintained at /subprocessors. We notify customers of material changes at least 30 days in advance. Current sub-processors:

  • Stripe Payments Europe Ltd - payment processing (IE, with onward US transfers under SCCs + EU-US DPF)
  • Functional Software, Inc. (Sentry) - error tracking (US, SCCs)
  • New Relic, Inc. - application performance monitoring (US, SCCs)
  • Hetzner Online GmbH - infrastructure (Finland, EEA)
  • Proton AG (Proton Mail) - transactional email (Switzerland; Commission adequacy decision 2024/2696)

IP geolocation and ASN enrichment run in-process against locally-hosted MaxMind-format databases. No end-user IP address is transferred to MaxMind or IPInfo for this, so neither is a sub-processor for that purpose.

4. International transfers

Where personal data is transferred outside the EEA, we rely on:

  • EU Commission Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914)
  • EU-US Data Privacy Framework where applicable
  • Commission adequacy decisions (e.g., Switzerland - 2024/2696)

Copies of our SCCs with each sub-processor are available on request at [email protected].

5. Your rights

You may exercise the following rights at any time via app.guard-core.com/settings/privacy or by emailing [email protected]. We respond within one calendar month, extendable to three months under Art 12(3) GDPR with notice.

  • Access (Art 15) - receive a copy of your data
  • Rectification (Art 16) - correct inaccurate or incomplete data
  • Erasure (Art 17) - “right to be forgotten”, subject to legal retention obligations
  • Restriction (Art 18) - require us to limit processing
  • Portability (Art 20) - machine-readable export in JSON or CSV
  • Object (Art 21), to processing based on legitimate interest, including service email sent to free-tier accounts; objections to marketing email are honoured automatically
  • Withdraw consent (Art 7(3)) - at any time, without affecting prior processing
  • Not be subject to solely-automated decisions (Art 22) - not applicable, we do not engage in such decision-making

6. Security

  • TLS 1.2+ on all connections
  • AES-256-GCM at rest; application-level field encryption for email, IP addresses in audit logs, 2FA secrets, and agent-to-core telemetry payloads
  • Argon2 password hashing, with a bcrypt verification fallback for legacy hashes that upgrades automatically on next login; optional TOTP two-factor
  • Role-based access control; production access logged and MFA-gated
  • Master key held in environment variables, never committed to version control; rotated per policy
  • Agent-to-core telemetry encrypted with AES-256-GCM using per-project keys derived from the master key
  • Append-only audit logging retained for 6 years
  • Vulnerability management and periodic penetration testing

7. Breach notification

If we become aware of a personal data breach likely to result in risk to your rights and freedoms, we will:

  • Notify the competent supervisory authority within 72 hours (Art 33)
  • Notify affected data subjects without undue delay where the breach is likely to result in high risk (Art 34)
  • Publish a public advisory on our status page

8. Cookies

See our Cookie Policy.

9. Age requirement

The Service is a professional B2B offering intended for software engineers, security engineers, and DevOps teams operating production applications. It is not marketed to or directed at children. Because the Service does not constitute an “information society service offered directly to a child” within the meaning of Article 8 GDPR, we do not operate a parental-consent flow. We do not knowingly collect personal data from anyone under 16; if we become aware that we have, we will delete it without undue delay.

10. Changes to this policy

We notify users of material changes via in-app notification and email at least 30 days before they take effect. Historical versions are preserved in our repository changelog. Continued use of the Service after an effective date constitutes acceptance of the revised policy.

11. Contact

Privacy enquiries, data-subject requests, and complaints: [email protected] - Data Protection Contact: Renzo Franceschini.