Privacy Policy
What data we collect about you, why, how long we keep it, whom we entrust it to, and which rights you may exercise against us.
Privacy Policy
Document version: 2.2 In force from: 1 September 2026 Previous version: 1.0 of 11 June 2026 Scope: the website https://guardiso.com together with all of its subpages, and the Guardiso platform available after signing in
§ 1. Who is responsible for the data and how to contact us
-
The entity operating the Guardiso website and platform is Guardiso Michał Lewandowski, ulica Święty Marcin 29/8, 61-806 Poznań, tax identification number (NIP) 6060011996, statistical number (REGON) 381263810, trading under the Guardiso brand. In the remainder of this document that entity is referred to as Guardiso.
-
Email address for all matters concerning the protection of personal data: kontakt@guardiso.com. Reports of vulnerabilities and security incidents are accepted at security@guardiso.com. The address for postal correspondence is the same as the address given in paragraph 1.
-
Guardiso has not appointed a data protection officer, because in Guardiso's assessment none of the cases listed in Article 37(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the GDPR) applies. All data protection matters are handled directly by the owner, at the address indicated in paragraph 2.
-
Throughout this document we use the following terms:
- Guardiso — the entity identified in paragraph 1;
- Customer — a business that has entered into an agreement with Guardiso for the use of the platform, including one using the free trial period;
- User — a natural person who signs in to the platform within the Customer's account, including the person who created that account;
- Data Subject — any natural person whose data is processed, including a User and a person whose data has been entered into the platform by the Customer.
-
Guardiso provides its service on a subscription basis, through a web browser. The service is addressed to businesses. Some Customers are sole traders and, in defined situations, benefit from the protection provided for consumers — those matters are governed by the terms of service, while this document concerns the protection of personal data only.
§ 2. Guardiso's two roles — this is the most important part of this document
-
In relation to personal data Guardiso acts in two different roles, depending on which data is concerned. That distinction determines who establishes the purposes of processing, to whom a Data Subject addresses their requests, and who is responsible for the lawfulness of the processing.
-
Guardiso as controller (Article 4(7) GDPR). This covers the data of the person creating the account and of the remaining Users, the Customer's billing data, data on the use of the website and the platform, and correspondence addressed to Guardiso. Within that scope it is Guardiso that decides on the purposes and means of processing, and it is Guardiso that is responsible for giving effect to the rights of the Data Subject.
-
Guardiso as processor (Article 4(8) GDPR). This covers all personal data that the Customer itself enters or uploads into the platform — data of its employees and contractors, of persons holding roles in the information security management system, of persons reporting incidents, of representatives of its suppliers and business partners, and of auditors to whom it has granted access. The controller of that data is the Customer, and Guardiso processes it solely on the Customer's documented instructions, within the scope and for the purpose set out in the data processing agreement concluded with the Customer. Guardiso does not process that data for its own purposes; in particular, it does not use it for marketing purposes, for building profiles, or for training artificial intelligence models.
-
The division of roles in tabular form:
| Category of data | Who is the controller | Legal basis for processing | How long we retain it |
|---|---|---|---|
| User account data: first name and surname, email address, profile picture retrieved from the Google account, role in the organisation, date and outcome of sign-in | Guardiso | Article 6(1)(b) GDPR for a person who has entered into the agreement themselves. Article 6(1)(f) GDPR for a User invited by the Customer — the legitimate interest being to enable performance of the agreement concluded with their employer and to secure access to the account | For as long as the account exists. After the account is deleted we erase the data no later than within 30 days |
| Billing data: company name, address, tax identification number, email address for invoices, history of payments and issued invoices | Guardiso | Article 6(1)(b) GDPR as regards settlement of the agreement, and Article 6(1)(c) GDPR as regards accounting and tax obligations | Five years, counted from the end of the calendar year in which the tax payment deadline fell. The obligation follows from Article 74 of the Polish Accounting Act of 29 September 1994 (ustawa o rachunkowości) and Article 86 § 1 of the Polish Tax Ordinance Act of 29 August 1997 (Ordynacja podatkowa) |
| Data on the use of the website and the platform: internet protocol (IP) address, browser type and version, timestamp, address of the subpage visited, authentication result, error records | Guardiso | Article 6(1)(f) GDPR — the legitimate interest being to ensure the security of the platform, to detect abuse and to keep the service running | For as long as the account exists. We erase it together with the account. We do not declare a shorter period until we have implemented automated deletion — an undertaking that we could not enforce today would be illusory |
| Correspondence addressed to Guardiso: content of the message, sender's address, attachments | Guardiso | Article 6(1)(b) GDPR where the matter concerns the agreement, or Article 6(1)(f) GDPR — the legitimate interest being to handle the enquiry and to defend against claims | For as long as the matter is being handled, and thereafter until expiry of the limitation period for claims connected with business activity, in accordance with Article 118 of the Polish Civil Code of 23 April 1964 (Kodeks cywilny) |
| Data of persons entered into the platform by the Customer: employees, contractors, persons responsible for roles, persons reporting incidents, contact persons at suppliers, auditors | The Customer. Guardiso is the processor | The basis is established by the Customer as controller. Guardiso processes that data solely on the Customer's instructions, on the basis of Article 28 GDPR and the data processing agreement concluded | For as long as the Customer's account exists. After the service ends the Customer has 30 days to download the data itself, after which we erase it |
| Activity log within the platform: who approved a document, who acknowledged a policy, who changed a risk assessment, who downloaded evidence | The Customer. Guardiso is the processor. The same record also serves Guardiso for security purposes and within that scope Guardiso is the controller | On the Customer's side — the basis is established by the Customer, for whom the log is audit evidence. On Guardiso's side — Article 6(1)(f) GDPR | For as long as the Customer's account exists |
| Content of prompts submitted to artificial intelligence features and content of the generated responses | The Customer, as regards content originating from its documentation. Guardiso is the processor. The controller of the data on the mere fact and cost of using the feature is Guardiso | On the Customer's side — the basis is established by the Customer. On Guardiso's side — Article 6(1)(b) GDPR as regards settlement of the limits arising from the plan | The content of the prompt and of the response — for as long as the Customer's account exists. The usage record — for as long as the account exists and for the billing period |
| Data of persons visiting the public pages and submitting forms available without signing in | Guardiso | Article 6(1)(a) GDPR where the processing is based on consent given when the form is submitted, or Article 6(1)(f) GDPR — the legitimate interest being to respond to the enquiry and to keep the website secure | Until the matter is settled or consent is withdrawn, and thereafter until expiry of the limitation period for claims |
- If you are an employee, a contractor or a contact person of a company that uses Guardiso, and you wish to exercise your rights in relation to the data listed in rows five and six of the table — address your request to your employer or to the company that entered your data, because it is that company that is the controller. The way a request that reaches us is handled is described in § 11 paragraph 5.
§ 3. Where we obtained your data if we did not receive it from you
-
The obligation to provide information about the source of the data follows from Article 14 GDPR and applies to situations in which the data has not been collected from the Data Subject. At Guardiso there are several such situations and we list them explicitly.
-
An invitation to the platform issued by the Customer. If your employer or principal has created an account with Guardiso and invited you to the team, we received from them your email address and, frequently, also your first name, surname and role in the organisation. The source of the data is then the Customer that entered it. As regards your account and authentication data the controller is Guardiso, and this document constitutes performance of the information obligation towards you.
-
Data entered by the Customer into the registers kept in the platform. The Customer enters into the platform the data of persons responsible for tasks and controls, of persons reporting incidents, of contact persons at its suppliers, and of auditors. The sole source of that data is the Customer. Guardiso does not obtain it on its own, does not supplement it from other sources and does not verify whether it is true. The controller is the Customer and it is the Customer that performs the information obligation towards those persons.
-
Signing in with a Google account. If you choose to sign in with a Google account, we receive from Google the email address, first name and surname, and the profile picture assigned to that account. We do not receive the password and have no access to it.
-
Checking an email address against a database of known breaches. On the Customer's instruction the platform checks whether email addresses in the Customer's domain have appeared in publicly known data breaches. The check is carried out by the Have I Been Pwned service, to which only the email address is transmitted. We never transmit or store passwords. The result of the check is placed in the Customer's register and it is the Customer that is its controller.
-
The scope of the data obtained from those sources is limited to the categories listed in § 2 paragraph 4. We do not obtain data from social media services, we do not buy databases and we do not combine the Customer's data with data from other sources.
§ 4. Profiling and automated decision-making
-
We do not carry out profiling of natural persons within the meaning of Article 4(4) GDPR. We do not create interest profiles and we do not evaluate by automated means the personal characteristics, economic situation, health, reliability or behaviour of Users.
-
We do not take decisions in relation to you based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22(1) GDPR. We do not carry out automated assessment of applications, we do not refuse access to the service on the basis of machine analysis alone, and we do not set prices on the basis of a User's behaviour.
-
The numerical indicators that the platform calculates — the level of compliance with a standard, the level of risk, the degree of completion of tasks, the timeliness of evidence — relate to the Customer's organisation and not to a natural person. They are the results of calculations on data entered by the Customer and serve as material for the Customer's own decision.
-
The platform records whether a given person has acknowledged a policy, accepted a document or completed training. These are records of facts, not assessments of a person. If the Customer uses those records for its own assessment of an employee, it does so as controller, in its own name and on its own responsibility. Guardiso neither formulates nor suggests such assessments.
-
The rules concerning artificial intelligence features, including the nature of the proposals they generate, are described in § 7.
§ 5. To whom we disclose data — the complete list of sub-processors
- The list below is complete as at the date given in the header and covers all entities to which we entrust the processing of personal data in connection with the provision of the service. This same list of nine entities constitutes Annex 2 to the data processing agreement and Annex 2 to the terms of service. If the list published at https://guardiso.com/subprocessors differs from the table below, the table in this document and in the data processing agreement prevails, and Guardiso removes the discrepancy without delay.
| Entity | Role | What data reaches it | Where it processes data | Basis for transfer outside the EEA |
|---|---|---|---|---|
| Scaleway, S.A.S. | Infrastructure: application servers, database, file storage | All data stored in the platform, including account data, documents, evidence and registers | Poland, Warsaw region | Not applicable — the data does not leave the European Economic Area |
| Fakturownia sp. z o.o. | Issuing invoices | Purchaser's invoicing data: name, address, tax identification number | Poland | Not applicable — the data does not leave the European Economic Area |
| Stripe Payments Europe, Limited | Payment and subscription handling | Billing data: company name, address, tax identification number, email address. We neither see nor store payment card data — it goes directly to Stripe | Ireland, with an intra-group transfer to the United States | Standard contractual clauses — Commission Implementing Decision (EU) 2021/914 |
| Google Ireland Ltd. and Google LLC | Signing in with a Google account, that is, identity provider | Email address and first name from the Google account of the person signing in, only where they choose that sign-in method. We do not receive the password | Ireland, with an intra-group transfer to the United States | Commission Implementing Decision (EU) 2023/1795 — EU–US Data Privacy Framework |
| Cloudflare, Inc. | Domain name servers, protection against denial-of-service attacks, web application firewall | Internet protocol addresses and headers of requests passing through the edge network. The content of requests is not stored | United States, with edge network nodes also in the European Union | Commission Implementing Decision (EU) 2023/1795 — EU–US Data Privacy Framework |
| Plus Five Five, Inc. (the Resend service) | System email: sign-in links, invitations, notifications | Recipient's email address, first name and surname, content of the system message | United States: that is where the provider stores the data. The eu-west-1 region we selected governs only where email is sent from | Standard contractual clauses (Commission Implementing Decision (EU) 2021/914), Module Two, incorporated into the provider's data processing agreement. The provider additionally declares compliance with the EU–US Data Privacy Framework |
| Anthropic Ireland, Limited | Language model: the Guardiso Assistant (Asystent Guardiso), generation of draft documents and analyses | The content of the User's prompt and the context passed for analysis. The scope is described in § 7 | United States: the provider's servers. The party to the agreement is the company established in Dublin, Ireland | Standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, Modules Two and Three |
| OpenAI Ireland Ltd. | Conversion of text into vectors for the purposes of searching the knowledge base | Fragments of the text of documents and questions converted into numerical vectors | United States: processing outside the European Economic Area. The party to the agreement is the Irish company | Standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 |
| Superlative Enterprises Pty Ltd (the Have I Been Pwned service) | Checking whether an email address has appeared in a known data breach | The email address submitted for checking. We do not transmit passwords | United States: a Microsoft Azure data centre in the western part of the country. The entity's registered office is in the state of Queensland, Australia | Standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated by reference into the data processing agreement concluded with that entity |
-
Apart from the entities in the table, data may be disclosed to bodies authorised under the law, in particular to the courts, the public prosecutor's office and supervisory authorities, solely to the extent following from a request that is binding on us. We assess each such request as to its legal basis and scope and, unless the law prohibits it, we inform the Customer of it.
-
Data may be disclosed to Guardiso's advisers, in particular its accounting and legal advisers, to the extent necessary for the performance of their task and subject to confidentiality.
-
We do not sell personal data. We do not make it available to third parties for marketing purposes. The only exception is described in § 13(1): with your consent, Google is told that a trial account was created by someone who came from our ad.
-
We inform the Customer at least 30 days in advance of any intention to add a new sub-processor or to replace an existing one. Within that period the Customer may raise a reasoned objection on the terms described in the data processing agreement. The basis for this obligation is Article 28(2) GDPR.
§ 6. Transfers of data outside the European Economic Area
-
The basic principle: platform data stays in Poland. The database, files, documents, evidence, registers and organisation configuration are stored in a data centre in Warsaw and do not leave the European Economic Area.
-
Exceptions are situations in which a sub-processor operating outside that area is needed to perform a specific function. All such cases are listed in the table in § 5, together with the country of processing and the basis for the transfer. We make no other transfers outside the European Economic Area.
-
The transfer bases we rely on come from Chapter V of the GDPR:
- an adequacy decision issued by the European Commission on the basis of Article 45 GDPR. We rely on it in relation to entities entered on the list of participants in the EU–US Data Privacy Framework established by Commission Implementing Decision (EU) 2023/1795 of 10 July 2023;
- standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, on the basis of Article 46(2)(c) GDPR.
-
For every sub-processor outside the European Economic Area we verify, before cooperation begins, whether the indicated basis is current, in particular whether the entity appears on the list of participants in the EU–US Data Privacy Framework. If a basis ceases to apply, we suspend the transfer or replace the basis with another one permitted by Chapter V of the GDPR.
-
We make a copy of the safeguards applied to the transfer available on request, in accordance with Article 46(1) GDPR. Please address such a request to the address indicated in § 1 paragraph 2.
§ 7. Artificial intelligence
-
Selected features of the platform use artificial intelligence. These are: the Guardiso Assistant answering questions, generation of drafts of policies and other documents, suggested answers to security questionnaires, preliminary assessment of controls, and searching the knowledge base. The model providers are Anthropic Ireland, Limited and OpenAI Ireland Ltd.
-
What we send to the model provider. We transmit only what is needed to carry out the specific instruction:
- the content of the question or instruction that the User has typed in;
- the fragment of the documentation, register or control to which the feature invoked relates;
- the name of the standard to which the task relates, together with basic information about the organisation needed to tailor the content, such as its name and industry;
- in the case of searching the knowledge base — fragments of text converted into numerical vectors, from which the original document cannot be reconstructed.
-
What we do not send. The following do not reach the model provider: passwords and authentication data, encryption keys, payment card data, files and attachments uploaded as evidence, the full content of registers, or any data of other Customers.
-
A reservation we must state plainly. We do not automatically filter the content that a User types into the prompt field. If a User types personal data there, it will be transmitted to the model provider together with the question. We recommend not including personal data in the content of questions unless it is necessary in order to obtain an answer.
-
Model training. In accordance with the terms of service for programmatic access and the data processing agreements concluded, the model providers do not use the transmitted content to train or fine-tune models. The transmitted content is retained by the provider only for the time necessary to handle the request and to detect abuse, after which it is deleted.
-
Who is responsible for content generated by the model. Content generated by artificial intelligence has the character of proposals and drafts. It is not legal advice or an expert opinion. It requires reading, correction and approval by a human before it becomes part of the Customer's documentation. Until approved, the platform marks it in the interface as generated by artificial intelligence.
-
Who is responsible for decisions taken on the basis of that content. The decision to accept, amend or reject a proposal is always taken by a human on the Customer's side. The Customer is responsible for the content of its own documentation and for the consequences of decisions taken on the basis of it, including the outcome of inspection, audit and certification proceedings. Guardiso does not provide legal assistance or advice within the meaning of the regulations on the legal professions.
-
Transparency. Marking interactions with artificial intelligence and content generated by it gives effect to the transparency obligations under Article 50 of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 on artificial intelligence.
-
When the features are triggered. Artificial intelligence features operate on the User's instruction, and not in the background across the entire documentation. The only exception is the preparation of the knowledge base for searching: documents and questions added to the knowledge base are automatically converted into vectors, because without this the search does not work.
-
The provisions of this section do not alter the rule set out in § 4 paragraph 2: the platform does not take decisions in relation to a Data Subject based solely on automated processing.
§ 8. How long we retain data
-
The retention periods for the individual categories of data are set out in the table in § 2 paragraph 4. The paragraphs below describe what happens to the data after the use of the service ends.
-
After an account is deleted we erase the data without undue delay, no later than within 30 days of the request. Before erasure the Customer has the opportunity to download its data from the platform itself.
-
Database backups are made once every 24 hours and retained for seven days. This means that data erased from the database disappears from the backups no later than seven days after erasure. Until then the backups are covered by the same safeguards as production data.
-
For longer than indicated in the table we retain only such data as we are required by law to retain, above all accounting and tax documents, and data necessary for the establishment, exercise or defence of claims — until expiry of the limitation period.
-
The key encrypting personal data assigned to the Customer's organisation is kept in a separate vault and is deleted together with the data. Deletion of the key means that the data encrypted with it becomes unreadable also in those copies in which it is still technically present.
§ 9. Data security
-
We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR. The most important of these are:
- encryption — connections are encrypted without exception, and personal data is encrypted at rest with the AES-256-GCM algorithm;
- a separate key for each organisation — compromise of one Customer's key does not expose another Customer's data;
- separation of Customer data — every read and write is filtered by an organisation identifier determined on the server side, never on the basis of data sent by the browser;
- restricted staff access — the owner of Guardiso has no standing access to Customer data; every access requires a request with a justification and approval by the Customer, is limited in time and fully logged, and the Customer may revoke it at any moment;
- network — the database is accessible only from a private network, with an allowlist of addresses;
- separation of environments — the production environment, the test environment and the environment intended for security testing have separate databases, separate keys and separate secrets; there is no real Customer data in the non-production environments;
- certification — Guardiso's information security management system is certified as compliant with the ISO/IEC 27001 standard by TÜV NORD, the certificate being valid from 17 July 2026 to 16 July 2029.
-
We do not operate a round-the-clock on-call service. We handle reports, alerts and correspondence on business days, between 9:00 and 17:00 Polish time. We say this plainly, because it matters for the moment at which we become aware of an event and for the running of the time limits described in § 10.
-
No safeguard provides absolute certainty. If you notice a vulnerability or an irregularity, please report it to security@guardiso.com.
§ 10. Personal data breaches
-
Where Guardiso is the controller — that is, in relation to the data listed in § 2 paragraph 2 — we notify a personal data breach to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) without undue delay and no later than within 72 hours of becoming aware of the breach, in accordance with Article 33(1) GDPR. If the breach is likely to result in a high risk to the rights or freedoms of the Data Subject, we also communicate it to that person without undue delay, in accordance with Article 34 GDPR.
-
Where the Customer is the controller — that is, in relation to the data listed in § 2 paragraph 3 — we notify the breach to the Customer without undue delay and no later than within 48 hours of becoming aware of the breach, providing the information that enables the Customer to perform its own obligation under Article 33 GDPR. That time limit is identical to the one recorded in § 9 paragraph 4 of the data processing agreement and follows from the fact that we do not operate a round-the-clock on-call service. In matters of personal data protection the data processing agreement takes precedence. Notification to the supervisory authority and communication to the data subjects are then made by the Customer as controller. The basis for our obligation is Article 33(2) GDPR and the data processing agreement.
-
The time limits under paragraphs 1 and 2 start to run from becoming aware of the breach, that is, from the moment at which we obtained knowledge of it. Given the rule described in § 9 paragraph 2, becoming aware occurs during working hours.
-
A notification contains at least: a description of the nature of the breach, the categories and approximate number of persons and records concerned by the breach, a description of the likely consequences, a description of the measures taken and proposed to address it, and contact details for further clarification.
-
We record every breach in an internal register of breaches, irrespective of whether it was notifiable, in accordance with Article 33(5) GDPR.
§ 11. Your rights and how to exercise them
- In relation to the data for which Guardiso is the controller, you have the following rights:
| Right | What it means | Basis |
|---|---|---|
| Access to data | You may obtain confirmation as to whether we process your data and receive a copy of it | Article 15 GDPR |
| Rectification | You may request the correction of inaccurate data and the completion of incomplete data | Article 16 GDPR |
| Erasure of data | You may request erasure of the data where one of the grounds set out in the provision applies | Article 17 GDPR |
| Restriction of processing | You may request that we only store the data, without further operations | Article 18 GDPR |
| Data portability | You may receive the data in a machine-readable format and transmit it to another controller | Article 20 GDPR |
| Objection | You may object to processing based on legitimate interest, on grounds relating to your particular situation | Article 21 GDPR |
| Withdrawal of consent | If the processing was based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out earlier | Article 7(3) GDPR |
| Complaint to the supervisory authority | You may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ulica Stawki 2, 00-193 Warszawa | Article 77 GDPR |
-
How to submit a request. A message to kontakt@guardiso.com is enough. We do not require a form or any particular format. It is helpful to indicate in the message which right the request concerns and which account or email address. A request may also be submitted by post, to the address indicated in § 1 paragraph 1.
-
Confirmation of identity. If we have reasonable doubts as to the identity of the person submitting the request, we will ask for additional information enabling us to confirm it, in accordance with Article 12(6) GDPR. Please do not send scans of identity documents unless we expressly ask for them.
-
The time within which we respond. We respond without undue delay and no later than within one month of receiving the request. If the request is complex or if a number of requests are received at once, we may extend the time limit by a further two months, informing you of the extension and its reasons within the first month. Basis: Article 12(3) GDPR. Giving effect to a request is free of charge; a fee or a refusal is permitted by Article 12(5) GDPR only in the case of manifestly unfounded or excessive requests.
-
A request concerning data for which the Customer is the controller. If a request concerns data entered into the platform by the Customer, we cannot deal with it on the merits, because we are not its controller and we may not act without the Customer's instruction. In such a case we forward the request to the Customer without delay and no later than within three business days, and inform the person submitting the request of this, indicating who the controller is. That time limit is identical to the one recorded in § 9 paragraph 2 of the data processing agreement. Within the platform the Customer has the tools to search for, produce, rectify and erase data that are needed to handle such a request itself.
-
Irrespective of a complaint to the supervisory authority, you have the right to an effective judicial remedy, in accordance with Article 79 GDPR.
§ 12. Children's data
-
The Guardiso service is not addressed to persons under sixteen years of age. It is a tool for businesses, and an account is created using a company email address.
-
We do not knowingly collect the data of persons under sixteen years of age and we do not address any content or communications to them. The age limit corresponds to the threshold indicated in Article 8(1) GDPR for information society services.
-
If we learn that an account has been created by a person under sixteen years of age, or that such data has reached us in another way, we will erase it without delay. If you are a parent or guardian and you suspect that a child's data has reached Guardiso, write to kontakt@guardiso.com.
-
If the data of a person under sixteen years of age has been entered into the platform by the Customer, the controller of that data is the Customer and it is the Customer that is responsible for the basis for processing it. On receiving such information we notify the Customer.
§ 13. Cookies
-
On the website and in the platform we use cookies and similar technologies to the extent necessary for the operation of the service, session authentication, remembering the choice of language and ensuring security. On the public pages, and only with your consent to the “Marketing” category, we also use the Google Ads tag. It checks whether a trial account was created by someone who came from our Google ad. The legal basis is consent under Article 6(1)(a) GDPR. You can withdraw it at any time in the cookie settings. Google Ireland Limited receives the information about the ad click and the account creation as a separate controller.
-
A detailed list of the files used, their purpose and their storage period is set out in a separate Cookies Policy, available at https://guardiso.com/cookies.
§ 14. Changes to the policy and version history
-
We may amend the policy, in particular where the law, the scope of the service or the list of sub-processors changes. We give notice of every material change at least 30 days in advance, by email or by a message in the platform.
-
The current version is always available at https://guardiso.com/privacy. The version number and the date from which it applies are given in the header of the document.
-
Version history:
| Version | Date | What changed |
|---|---|---|
| 1.0 | 11 June 2026 | First published version of the policy: categories of data, purposes and legal bases, retention periods, list of recipients, international transfers, section on artificial intelligence systems, rights of individuals, cookies |
| 2.0 | 1 September 2026 | Separation of the roles of controller and processor, together with a table assigning a role to each category of data. Added information on the source of data that does not come from the Data Subject. Added a section on profiling and automated decision-making. The list of sub-processors was completed to nine entities and the place of processing and the basis for transfer outside the European Economic Area were indicated for each. The section on artificial intelligence was expanded to cover the scope of the data transmitted, the question of model training and responsibility for content and for decisions. Added the manner of, and time limit for, handling requests, the rules for notifying personal data breaches, provisions on children's data, and the version history. The retention period for backups was clarified and undertakings that we are not in a position to meet today were removed |
| 2.2 | 24 September 2026 | Added information on the Google Ads tag on the public pages. With the visitor's consent it checks whether a trial account was created by someone who came from our ad |