Exit and Data Portability Terms
What you take with you, in which formats, exactly when your data disappears, and how cancellation works. The question that should be answered before you sign, not after.
Exit and Data Portability Terms
Document version: 15 September 2026 Previous version: 8 September 2026 This document applies from: 1 September 2026 Document address: https://guardiso.com/wyjscie-z-uslugi
This document answers the question the Customer asks before signing the contract, not after it has been terminated: how it will end its relationship with Guardiso and what it will take with it.
This document describes: what data the Customer may download and in what formats, how long it has to do so, when and how data is deleted — including from backups, what happens to the key that encrypts its data, and which assistance with migration to another provider is free of charge and which is chargeable.
This document forms an integral part of the Agreement and is made available free of charge, in a form that allows it to be downloaded, reproduced and stored.
Table of contents
- Purpose of this document, who it binds and how it relates to the other documents
- Definitions
- General principle — the data belongs to the Customer and leaves together with the Customer
- What exactly the Customer may download and in what formats
- What the Export does not cover and what its current limitations are
- When data may be downloaded — during the term of the Agreement and after it ends
- Release of a Complete Data Set by Guardiso on request
- Termination of the Agreement — how to give notice and when it takes effect
- Deletion of data from the production environment
- Deletion of data from backups
- What remains despite deletion
- The key that encrypts the Customer's data
- Assistance with migration to another provider and the charges for it
- Exit of a single company from an account operated by a Consultant
- Forced exit — suspension, termination and discontinuation of the Service
- Rights that survive the end of the Agreement
- Switching to another provider of data processing services
- Amendments to the document and final provisions
§ 1. Purpose of this document, who it binds and how it relates to the other documents
-
This document brings together in one place rules that have so far been spread across § 22 of the Terms of Service, § 11 of the Data Processing Agreement, § 11 of the Service Level Agreement and §§ 12 and 16 of the End User Licence Agreement. This document does not replace those provisions.
-
This document binds Guardiso and the Customer. It also applies to the Trial Period, subject to the reservations expressly indicated.
-
The order of precedence of the documents is set out in § 23 of the Terms of Service. In matters concerning the protection of personal data, the Data Processing Agreement prevails.
-
Where this document grants the Customer a broader right than a document of higher precedence, it remains effective to that extent, in accordance with § 23(4) of the Terms of Service.
-
Capitalised terms that are not defined in § 2 have the meaning given to them in the Terms of Service and in the End User Licence Agreement.
-
In relation to a Protected Customer, the provisions of this document apply subject to mandatory consumer protection law.
§ 2. Definitions
-
Export — the downloading of Customer Data using the functions made available for that purpose in the Platform, performed by the Customer itself.
-
Complete Data Set — a set of Customer Data prepared and released by Guardiso at the Customer's request, under § 7.
-
Download Period — the period of thirty days after the end of the Agreement during which the Customer retains the ability to download Customer Data.
-
Audit Package — an archive made available in the Platform comprising the register of controls, the register of policies, the risk register and the evidence register together with the files attached to them, prepared for a selected standard.
-
Encryption Key — a cryptographic key assigned exclusively to a single Organisation, with which the personal data of that Organisation is encrypted.
-
Cryptographic Erasure — the permanent deletion of the Encryption Key, causing the data encrypted with it to become unreadable to everyone, including Guardiso, also in backups.
-
Consultant and Consultant's Client — have the meaning given to them in § 1(5) of the End User Licence Agreement.
-
Data Act — Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828, which has applied since 12 September 2025. Guardiso is a provider of data processing services within its meaning.
-
Switching — the procedure described in § 17, by which the Customer moves Customer Data to a data processing service of a different provider covering the same service type, or to its own ICT infrastructure, or asks for that data to be erased without being moved anywhere.
-
Transitional Period — the period during which the Agreement continues to apply, Guardiso provides the Service to an unchanged extent and assists the Customer with Switching. The rules are set out in § 17(3).
§ 3. General principle — the data belongs to the Customer and leaves together with the Customer
-
Customer Data is the property of the Customer. Guardiso acquires no rights to it beyond the extent necessary to provide the Service and does not use it for its own purposes. Customer Data is not used to train artificial intelligence models.
-
Guardiso does not obstruct exit. In particular, Guardiso:
- does not make the release of Customer Data conditional on a waiver of claims, on the signing of a statement that no objections are raised, or on the making of any other statement unrelated to the release of the data;
- does not charge any fee for termination of the Agreement or for switching provider;
- does not charge any fee for the Export itself, for the first release of a Complete Data Set, or for any action necessary for Switching;
- does not withhold the release of Customer Data because of arrears in payment for the Service — Guardiso pursues arrears separately, under the general rules.
-
The Customer's right to download its own data is contractual in nature and is available to it regardless of whether the data contains personal data. It should not be confused with the right to data portability available to a natural person under Article 20 of Regulation (EU) 2016/679 of the European Parliament and of the Council, which is available to the data subject against the controller of that data, and not to the Customer against Guardiso.
-
Guardiso describes below the factual position as at the date of this version of the document. Where there is something that Guardiso is currently unable to do, or does not do, this is stated expressly. A commitment that Guardiso would not honour would be worse for the Customer than no commitment at all.
§ 4. What exactly the Customer may download and in what formats
- During the term of the Agreement and during the Download Period the Customer may download the following data itself, using the functions made available in the Platform:
| What the Customer downloads | Source | Formats |
|---|---|---|
| Policies and procedures — individually | Policies module | PDF, DOCX, Markdown |
| Policies and procedures — complete set | Policies module | ZIP archive containing documents in the formats listed above |
| Register of controls together with implementation status and the Statement of Applicability | Audit Package | CSV in a ZIP archive |
| Risk register | Audit Package | CSV in a ZIP archive |
| Evidence register together with the attached files | Audit Package | CSV in a ZIP archive and the evidence files in the form in which they were uploaded |
| Compliance summary for a standard | Audit Package | Text file in a ZIP archive |
| Audits and audit reports | Audits module | DOCX, PDF, XLSX |
| Assessments and self-assessments | Assessments module | XLSX, PDF, DOCX |
| Security questionnaires together with the answers | Questionnaires module | CSV, XLSX |
| Register of consents | GDPR compliance module | CSV |
| Data processing agreements collected by the Customer | GDPR compliance module | ZIP archive |
| Compliance reports | Reports module | PDF, DOCX |
| Attachments and files uploaded by the Customer | The module into which they were uploaded | The form in which they were uploaded |
-
Data for which the Platform does not currently provide an export button is released by Guardiso on request under § 7, in CSV or JSON format. This concerns in particular those registers that the Audit Package does not cover, and the entries in the activity log within the Organisation.
-
The log of access by Guardiso personnel to Customer Data. The Customer sees in the Platform the access requests and the entries relating to grants that are still running. Guardiso releases a compilation of the entire log, including grants whose time has already expired, on request and free of charge.
-
The formats indicated in paragraph 1 are commonly used and machine-readable formats within the meaning of § 11(4) of the Data Processing Agreement. The name and the meaning of every column in the data sets listed in paragraph 1 are set out in the public register of data structures and data formats at https://guardiso.com/formaty-danych, described in § 17(11).
-
The Customer may download data repeatedly and without quantitative limits, subject to the prohibition on automated retrieval of content outside the export functions and the Application Programming Interface, described in the Acceptable Use Policy.
§ 5. What the Export does not cover and what its current limitations are
Guardiso provides the information below so that the Customer can plan its exit, rather than discover a limitation on the day when it is already too late.
-
There is currently no single button that downloads the entire content of an Organisation in one file. The Export is performed module by module and by means of the Audit Package. Guardiso prepares a complete set of data in a single collection on request, under § 7.
-
The Audit Package covers no more than fifty evidence files. Files exceeding that limit must be downloaded separately from the evidence module. In a separate information file, the package lists:
- evidence items that exist in the register but have no file attached at all;
- files that could not be retrieved when the package was created;
- files omitted because the limit was exceeded.
Guardiso does this deliberately, so that the number of entries in the register is not confused with the number of documents that actually exist.
-
Backups cover the Platform database. The scope of backups of the files held in object storage, including attachments uploaded by the Customer, is not covered by any Guardiso commitment — this is stated expressly in § 11(2) of the Service Level Agreement. The Customer is advised to download copies of its documents itself during the term of the Agreement, and not only when the Agreement ends.
-
Guardiso has not so far carried out a documented test of restoring data from a backup and for that reason does not declare a guaranteed recovery time or a guaranteed scope of data restoration. A backup does not replace an Export performed by the Customer itself.
-
The Export does not cover the Content Library in unprocessed form — that is, the collection of templates, control catalogues and mappings in the form in which Guardiso makes them available to all Customers. The Customer downloads its own documentation created on the basis of those materials. The rules are set out in § 8 of the End User Licence Agreement.
-
The Export does not cover the Platform code, its technical configuration or Guardiso's internal records that do not concern the Customer's Organisation.
-
Guardiso does not undertake to release data in a format that allows it to be loaded directly into another provider's system. For information security management system documentation there is no generally accepted data exchange standard. Guardiso releases data in commonly used and machine-readable formats, together with a description of the file structure.
§ 6. When data may be downloaded — during the term of the Agreement and after it ends
-
During the term of the Agreement the Customer may download data at any time, itself, without notifying Guardiso and free of charge.
-
After the end of the Agreement, Customer Data remains available for thirty days. During the Download Period the Customer retains the ability to log in and to use the export functions described in § 4. The Platform then operates in read-only mode: the screens from which data is downloaded remain active, while the functions used to enter and change data are switched off and any attempt to write is refused. After logging in, the Customer sees a message about the Download Period in progress together with the date on which it ends.
-
The Download Period runs from the day on which the Agreement ends, that is to say from the expiry of the paid Billing Period or from the day on which the Agreement was terminated for another reason.
-
Guardiso reminds the Customer of the Download Period and of the choice available to it between the return and the deletion of the data, no later than on the day on which provision of the Service ends, by email to the Account Owner's address. That obligation follows from § 11(2) of the Data Processing Agreement.
-
Trial Period. After the end of the Trial Period without a paid Agreement being concluded, the Download Period applies on the same terms. The Customer retains the ability to download the documents prepared during the Trial Period.
-
If the Customer requests deletion of the Account and of the Organisation before the Download Period expires, Guardiso proceeds with deletion once the Account Owner has confirmed the request. Such a request constitutes a waiver of the remaining part of the Download Period.
-
Where the Customer has requested Switching, the longer timetable set out in § 17 applies. The period for downloading data then runs from the end of the Transitional Period, and not from the end of the Agreement.
§ 7. Release of a Complete Data Set by Guardiso on request
-
The Customer may request that Guardiso prepare and release a Complete Data Set. The request is submitted by email to kontakt@guardiso.com. Guardiso requires no form and no statement of reasons.
-
Deadline for submitting the request. The request must be submitted during the Download Period. Guardiso will act on a request submitted after that period only if the data has not yet been deleted.
-
Deadline for release. Guardiso prepares and releases the Complete Data Set within fourteen days of receiving the request.
-
Scope. The Complete Data Set comprises the register data in CSV or JSON format and the documents and evidence in the formats in which they were uploaded or created, together with a description of the file structure. The limitations described in § 5 apply accordingly and are stated expressly in the description accompanying the Complete Data Set.
-
Delivery channel. The Complete Data Set is delivered through a secured channel agreed with the Customer.
-
Charges. One preparation of a Complete Data Set after provision of the Service has ended is free of charge. In the course of Switching, every preparation of a Complete Data Set is free of charge, in accordance with § 13(1)(2). Outside Switching, for each subsequent preparation in the same matter, and for release in an individually agreed form, Guardiso may claim remuneration corresponding to the work involved, agreed before the work is commenced.
-
Confirmation. At the Customer's request, Guardiso issues a confirmation of the release of the Complete Data Set stating the date and the scope.
§ 8. Termination of the Agreement — how to give notice and when it takes effect
-
The Customer may terminate the Agreement at any time, without giving reasons, by email to kontakt@guardiso.com or by cancelling the Subscription in the payment operator's portal, which is reached through the button in the billing settings of the Platform. The statement is submitted by the Account Owner or by a person authorised by the Account Owner.
-
Termination of a paid Agreement takes effect upon the expiry of the paid Billing Period. Until then the Customer uses the Service to an unchanged extent.
-
Termination of the Agreement means that the Subscription does not renew for a further Billing Period.
-
No refund of the fee is due for a Billing Period that has already begun, unless the basis for the ending of the Agreement is withdrawal from the contract by a Protected Customer, a lack of conformity of the digital service with the contract, an objection to a change of the documents or another circumstance indicated in the Terms of Service. Those rules are set out in the Terms of Service and take precedence over this paragraph.
-
The Customer does not have to give a reason for terminating. Guardiso may ask for the reason, but the answer is voluntary and the absence of an answer does not delay either the termination or the release of the data.
-
Guardiso confirms receipt of the statement of termination, stating the day on which the Agreement ends and the day on which the Download Period ends.
§ 9. Deletion of data from the production environment
-
The choice belongs to the Customer. After provision of the Service has ended, Guardiso, depending on the Customer's decision, either returns Customer Data to it or deletes that data and then deletes all existing copies of it. This principle follows from Article 28(3)(g) of Regulation (EU) 2016/679 and from § 11 of the Data Processing Agreement.
-
The deadline for submitting the statement of choice is thirty days from the end of provision of the Service and coincides with the Download Period.
-
The absence of a statement means that deletion has been chosen. Guardiso does not delete data before the deadline for submitting the statement has expired.
-
Deletion takes place within fourteen days after the expiry of the deadline referred to in paragraph 2. This means that Customer Data is deleted from the production environment no later than on the forty-fourth day after provision of the Service has ended. After the expiry of the Download Period and before deletion, the data is no longer available to the Customer in the Platform.
-
Confirmation of deletion. At the Customer's request, Guardiso issues a confirmation of the deletion of Customer Data, in writing or provided in documentary form, stating the date and the scope.
-
The provisions of this paragraph apply accordingly to the ending of provision of the Service in relation to a single Organisation operated within the Customer's account.
-
Where the Customer has requested Switching, the periods under this paragraph run from the end of the data retrieval period described in § 17(5), and not from the end of provision of the Service. The forty-fourth day referred to in paragraph 4 is then postponed by the duration of the Switching.
§ 10. Deletion of data from backups
-
How backups work. Backups of the Platform database are created automatically once every twenty-four hours and are retained for seven days, after which they are overwritten in the normal cycle. The backups are stored in the Warsaw region at the infrastructure provider and are covered by the same safeguards as production data.
-
What this means for the Customer — we say it plainly. Data deleted from the production environment does not disappear from backups at the same moment. It disappears as the backups in which it still appears expire, that is to say no later than seven days after its deletion from the Platform. Guardiso does not delete individual records from existing backups, because doing so would compromise their integrity and render them useless as backups.
-
Until they expire, the backups remain covered by the Data Processing Agreement and by the same protective measures as production data.
-
Aggregate period. Counting in aggregate: a Download Period of thirty days, deletion within fourteen days after its expiry, and the expiry of backups within seven days after deletion, Customer Data disappears in full no later than on the fifty-first day after provision of the Service has ended.
-
Copies made outside the daily cycle. If, outside the cycle described in paragraph 1, any other copy of Customer Data exists that was made for a specific documented purpose, Guardiso identifies it to the Customer on request and states its purpose and the date of its deletion. Until it is deleted, such a copy remains covered by the Data Processing Agreement.
-
Consistency with the other documents. The seven-day period is identical with § 22(6) of the Terms of Service, with § 11(7) of the Data Processing Agreement, with § 11(1) of the Service Level Agreement and with § 8(3) of the Privacy Policy. Earlier versions of the Terms of Service indicated for backups a cycle of no more than ninety days; the seven-day period corresponds to the factual position and is more favourable to the Customer, and therefore — in accordance with § 23(4) of the Terms of Service — it prevails in every case.
§ 11. What remains despite deletion
-
The deletion of Customer Data does not cover data that Guardiso is required by law to retain. This means in particular:
- invoices and tax documentation — for the period resulting from tax and accounting legislation;
- data necessary to establish, pursue or defend claims — until the expiry of the limitation period.
-
Guardiso retains the data indicated in paragraph 1 as a controller, on the terms described in the Privacy Policy, and not as a processor acting on the Customer's instructions. That data does not include the Customer's compliance documentation or its registers.
-
Deletion does not cover anonymised and aggregated data from which neither a person's identity can be reconstructed nor the data attributed to the Customer. Guardiso does not create such collections from Customer Data for the purposes of its own product without a separate legal basis.
-
Apart from the cases indicated in paragraph 1, Guardiso does not retain any part of Customer Data.
§ 12. The key that encrypts the Customer's data
-
Each Organisation has its own Encryption Key — a separate key using the AES-256-GCM standard, held in a dedicated vault at the cloud provider, with version history, an access log and access rights control. Compromise of one Organisation's key does not expose another Organisation's data.
-
On ordinary termination of the Agreement the Encryption Key is deleted together with Customer Data, within the period indicated in § 9(4).
-
Cryptographic Erasure on request. The Customer may request deletion of the Encryption Key earlier, using the function available in the Platform. The effect is as follows:
- personal data encrypted with that key becomes permanently unreadable to everyone, including Guardiso;
- the effect also extends to backups in which the data is still technically present — without any need to compromise the integrity of those backups;
- this solution makes it possible to give effect to a request for erasure of data referred to in Article 17 of Regulation (EU) 2016/679, without destroying backups.
-
Who may do this. Deletion of the Encryption Key may be carried out solely by the Owner of the Customer's Organisation, after entering the required confirmation phrase. Guardiso personnel cannot do this, not even where an access request has been approved. On Guardiso's side, an operation of this weight requires a separate documented emergency procedure, not a button.
-
A warning that has to be stated plainly. If the Customer deletes the Encryption Key before downloading its data, restoring the data encrypted with that key is permanently impossible, including from a backup. Guardiso informs the Customer of this before the operation is carried out and requires confirmation. This principle is identical with § 11(5) of the Service Level Agreement.
-
The reversibility window on the vault provider's side. The cloud provider's vault first deletes a secret reversibly, for a period of thirty days, and only then permanently. Recovering the key during that period requires the involvement of the vault provider. Guardiso does not undertake that recovery will be possible, and does not present that window as a safeguard against a mistake.
-
Key rotation. The Customer may at any time initiate replacement of the Encryption Key in the Organisation settings. Rotation does not cause any loss of data.
-
Every operation on the Encryption Key, whether successful or unsuccessful, is recorded in a log available to the Customer.
§ 13. Assistance with migration to another provider and the charges for it
The principle we start from. Only additional support that goes beyond reasonable assistance with Switching may be charged for. Everything that is necessary for the Customer to recover its data and move it elsewhere is free of charge. That is the position today and it will stay that way. From 12 January 2027 Article 29(1) of the Data Act prohibits any charge for actions necessary for Switching, so Guardiso could not introduce such a charge in future either.
-
What is free of charge:
- use of the export functions described in § 4 throughout the term of the Agreement, during the Transitional Period and during any period for retrieving data, with no quantitative limits;
- preparation and release of a Complete Data Set under § 7 each time it is needed in the course of Switching, including a repeat release where the previous one turned out to be incomplete or damaged;
- a description of the structure of the released files, including the meaning of individual columns and fields, provided in advance of the release where the Customer wants to see the structure first;
- answers to questions about the structure and the meaning of the data, given on Business Days as part of support, including where the question comes from the new provider authorised by the Customer;
- working meetings with the Customer and with the new provider devoted to explaining the structure of the released data, to an extent reasonable for the volume of the Customer's data;
- a description of what each field in the released data means, drawn up so that the new provider can match those fields to its own data structure itself;
- information about risks to continuity of the Service in the course of Switching that are known to Guardiso;
- maintaining the Service and its security during the Transitional Period, on the terms set out in § 17(3);
- delivery of the data through a secured channel, together with the network traffic involved in retrieving it;
- confirmation of the release of the data and confirmation of its deletion;
- deletion of Customer Data and deletion of the Encryption Key.
-
What is chargeable. Only additional support that the Customer asks for and that is not necessary for Switching may be charged for:
- converting Customer Data into the import form of a particular system of another provider, that is to say work on a form of the data other than the formats indicated in § 4;
- writing software or scripts for the new provider to move the data;
- work on the new provider's side, including loading the data into its system and configuring that system;
- participation in the new provider's implementation work going beyond explaining the structure of the released data, in particular running the migration project, workshops and training for its team;
- release of data in an individually agreed form for purposes other than Switching.
-
Three rules that limit what may be charged for:
- none of the activities listed in paragraph 2 is a condition for the release of Customer Data or for Switching. Declining any of them neither withholds nor delays the release of the data or the Switching;
- the remuneration corresponds to the work involved and is agreed before the work is commenced. Without such agreement Guardiso does not commence the work and does not charge the Customer any amount;
- Guardiso does not apply fees for the ending of the relationship or for Switching. Where there is doubt as to whether a given activity is necessary for Switching, that doubt is resolved in the Customer's favour and the activity is free of charge.
-
What Guardiso does not do — and we say it plainly:
- it does not transfer data directly into another provider's system and does not carry out work on that provider's side;
- it does not undertake that the released data can be loaded into another provider's system without conversion. For information security management system documentation there is no generally accepted data exchange standard today;
- it is not responsible for whether, and within what time, another provider will accept and load the data;
- it does not currently make available an open application programming interface to facilitate Switching. The factual position is set out in § 17(13);
- it does not maintain a source code escrow arrangement or a third-party data escrow account. A Customer for whom such a safeguard is important should raise the matter before concluding the Agreement. Guardiso will discuss it individually, but no such arrangement exists today.
-
Guardiso does not refuse to cooperate with the Customer's new provider and does not make the release of data conditional on who that provider is.
§ 14. Exit of a single company from an account operated by a Consultant
-
Where an Organisation is operated by a Consultant for a Consultant's Client, the settlements and mutual obligations between them are a matter solely between them and do not affect the Consultant's obligations towards Guardiso.
-
The Consultant ensures that the Consultant's Client is able to obtain the documentation collected in the Organisation operated for that client, using the export functions described in § 4. That obligation follows from § 4(7) of the End User Licence Agreement.
-
Transfer of the Organisation to the Consultant's Client's account. Upon a joint application by the Consultant and the Consultant's Client, Guardiso may transfer the Organisation together with its data to an account indicated by the Consultant's Client. Such a transfer:
- does not occur by force of this document and requires confirmation by Guardiso;
- is carried out manually, and accordingly Guardiso does not undertake any deadline for carrying it out;
- requires the destination account to hold a paid Plan covering the operation of that Organisation.
-
Dispute between the Consultant and the Consultant's Client. Guardiso does not resolve disputes between a Consultant and a Consultant's Client. Until a joint application by both parties or a final decision of a competent authority, Guardiso maintains the existing state of affairs. This does not limit Guardiso's obligations under personal data protection law towards the entity that is the controller of the data collected in that Organisation.
-
The ending of the Partner Agreement does not of itself cause the deletion of Organisations operated by the Consultant or the ending of the Subscription. The consequences of the ending of the Partner Agreement are described in § 23 of that agreement.
§ 15. Forced exit — suspension, termination and discontinuation of the Service
-
Suspension of access for reasons attributable to the Customer. Before suspension, the Customer is given the opportunity to download Customer Data. If the suspension was immediate because the breach endangered the security of other Customers' data, Guardiso makes the data available by another means once the threat has ceased. These rules are described in § 15(5) of the Acceptable Use Policy and in § 15(4) of the End User Licence Agreement.
-
Termination of the Agreement by Guardiso for important reasons does not deprive the Customer of the rights described in §§ 4, 6, 7 and 9 of this document. Guardiso does not use loss of data as a sanction.
-
Arrears in payment. Arrears in payment for the Service are not a ground for refusing to release Customer Data. Guardiso pursues arrears separately.
-
Discontinuation of the Service by Guardiso. If Guardiso decides to discontinue provision of the Service, it:
- notifies Customers with a notice period of no less than thirty days, by email to the Account Owner's address and by a message in the Platform;
- provides a Download Period of no less than thirty days counted from the day on which provision of the Service is discontinued;
- refunds the fee for the unused part of the paid Billing Period;
- on request, prepares a Complete Data Set on the terms set out in § 7, free of charge.
-
Paragraph 4 point 1 does not apply where provision of the Service is discontinued for reasons beyond Guardiso's control. In that case Guardiso notifies Customers immediately upon becoming aware of the circumstance and performs the remaining obligations to the extent actually possible.
§ 16. Rights that survive the end of the Agreement
-
After the end of the Agreement the Customer retains the right to use the documents created in the Platform — policies, procedures, registers, evidence and reports — for the purposes of its own organisation, without any time limit, including the right to present them to auditors, certification bodies, counterparties and authorities. This principle is set out in § 12(1) of the End User Licence Agreement.
-
The Customer retains the right to use content generated automatically at its instruction, without any limitation as to purpose, time or territory, in accordance with § 9(3) of the End User Licence Agreement.
-
The following continue to apply after the end of the Agreement:
- the prohibitions concerning the Content Library, described in § 8 of the End User Licence Agreement;
- the obligation of confidentiality of both parties — for three years from the end of the Agreement;
- the provisions on liability, on the governing law and on the competent court;
- settlement of amounts due that arose before the end of the Agreement.
-
The end of the Agreement does not deprive the Customer of the right to submit a complaint concerning the period during which the Service was provided.
§ 17. Switching to another provider of data processing services
This paragraph implements Chapter VI of the Data Act, comprising Articles 23 to 31. That Chapter gives the Customer the right to switch to another provider of data processing services and imposes on Guardiso the obligations set out below. Each paragraph names the provision it implements.
-
What the Customer may request (Article 25(3)). The Customer may at any time, without giving reasons, request Switching. The request covers one of three options:
- moving Customer Data to a data processing service of a different provider covering the same service type;
- moving Customer Data to the Customer's own ICT infrastructure;
- erasing Customer Data without moving it to another provider.
The request is submitted by email to kontakt@guardiso.com. The Customer states which of the three options it chooses no later than the expiry of the notice period under paragraph 2. Where option 1 is chosen, the Customer identifies the new provider so that Guardiso can cooperate with it.
-
Notice period: two months at most (Article 25(2)(d)). The notice period preceding the initiation of Switching is two months at most and runs from the day on which Guardiso received the request. Guardiso initiates Switching without undue delay after receiving the request, unless the Customer indicates a later day. The initiation of Switching does not depend on how much of the paid Billing Period remains, nor on the settlement of arrears in payment for the Service.
-
Transitional Period: thirty days at most (Article 25(2)(a)). The Transitional Period begins on the expiry of the notice period and lasts thirty calendar days at most. During that time:
- the Agreement continues to apply and Guardiso provides the Service to an unchanged extent. Continuity of the Service is maintained throughout the Transitional Period, including any extension of it. Guardiso does not switch off during that time any function the Customer was using before the request was made;
- Guardiso provides reasonable assistance with Switching, free of charge, to the Customer and to third parties authorised by the Customer, including the new provider. The scope of that assistance is set out in § 13(1);
- Guardiso maintains a high level of data security throughout the Switching, including when the data is transferred and during the retrieval period under paragraph 5. The Complete Data Set is delivered through a secured channel agreed with the Customer;
- Guardiso states plainly any risks to continuity in the provision of the functions and the Service on its own side that are known to it. The risks known to Guardiso as at the date of this version of the document are described in § 5. Guardiso notifies the Customer of any further risk without undue delay after becoming aware of it.
For any part of the Transitional Period falling after the expiry of the paid Billing Period, Guardiso charges the subscription fee at the existing rate, pro rata for the number of days. That is an ordinary fee for providing the Service and not a switching charge within the meaning of Article 2(35) of the Data Act.
-
A single extension of the Transitional Period (Article 25(5) and (4)). The Customer may extend the Transitional Period once, by a period that the Customer itself considers more appropriate for its own purposes. A statement made before the Transitional Period expires is sufficient. Guardiso does not require reasons and cannot object to the extension. Paragraph 3 applies in full to the extended period.
Where keeping to the thirty-day Transitional Period is technically unfeasible, Guardiso notifies the Customer of that within fourteen Business Days of receiving the request, gives proper reasons for the unfeasibility and indicates an alternative Transitional Period not exceeding seven months. Continuity of the Service is maintained throughout that period as well. This reservation does not limit the Customer's right to a single extension.
-
Data retrieval period: at least thirty days after the Transitional Period (Article 25(2)(g)). After the end of the Transitional Period, including any extension of it, the Customer has at least thirty calendar days to retrieve Customer Data. During that time the Customer retains the ability to log in, to use the export functions described in § 4 and to request the release of a Complete Data Set under § 7. The functions used to enter and change data are switched off during that period, on the terms set out in § 6(2). This period runs independently of the Download Period described in § 6 and may not be shorter than it.
-
When the Agreement ends (Article 25(2)(c)). The Agreement ends:
- upon the successful completion of the Switching;
- on the expiry of the notice period, where the Customer chose to have Customer Data erased without moving it to another provider.
Guardiso notifies the Customer that the Agreement has ended, stating its last day and the day on which the retrieval period under paragraph 5 ends. The rules on refunding the fee for the unused part of the paid Billing Period are set out in the Terms of Service; § 8(4) of this document applies.
-
Deletion of data after Switching (Article 25(6)). Guardiso deletes Customer Data from the production environment within fourteen days after the expiry of the retrieval period under paragraph 5. Backups in which the data still appears expire no later than seven days after deletion, on the terms set out in § 10. The Encryption Key is deleted together with the data, in accordance with § 12(2). At the Customer's request, Guardiso issues a confirmation of deletion stating the date and the scope. Paragraphs 9, 10 and 11 apply accordingly, save that the periods run from the end of the retrieval period under paragraph 5.
-
The data the Customer takes with it (Article 25(2)(e)). The Customer takes all of its Organisation's data, other than the data listed in paragraph 9. Part of that data the Customer downloads itself using the export functions described in § 4. The remainder Guardiso releases in a Complete Data Set on request, under § 7, in CSV or JSON format, with documents and files in the form in which they were uploaded or created. The specification comprises:
- policies, procedures and internal standards, together with their versions, approvals, comments and staff acknowledgements;
- the register of controls, together with implementation status, links to risks and evidence, and the Statement of Applicability together with the justifications for the selection of controls;
- the risk register, together with the history of changes, the adopted risk appetite and risk quantification;
- the evidence register, together with the evidence files, the schedules for collecting them and the chain of custody records;
- internal audits: checklists, audit findings, corrective actions and audit evidence;
- assessments and self-assessments, including security readiness surveys and security questionnaires together with the answers, the assignments and the answer library;
- incidents and nonconformities, together with the course of each case, notifications to the supervisory authority and improvement records;
- the Customer's vendors and subprocessors: the vendor register, their questionnaires, the risk assessment history and the Customer's own list of subprocessors;
- GDPR compliance documentation: the record of processing activities, the register of consents, the cookie consent log, data processing agreements collected by the Customer, data protection impact assessments, legitimate interest assessments, transfer impact assessments, data subject requests, breach notifications, retention rules, the register of transfers and privacy notices;
- management system documentation: the scope of the system, the context analysis, interested parties, security objectives, processes and resources, management reviews, metrics and measurement records;
- business continuity: continuity plans, the business impact analysis, teams, scenarios, tests and the communication plan;
- security operations: vulnerabilities, patch records, penetration test findings, configuration items and security events;
- assets and processes: the asset register, asset discovery results, information classification and retention schedules;
- training and the employee lifecycle: courses, assignments, test results, certificates and phishing awareness campaigns;
- access reviews together with the decisions taken;
- tasks, corrective actions and projects run within the Organisation;
- key risk indicators together with their measurements, board meetings and recommendations, and the records of compliance status over time;
- the compliance portal for the Customer's own customers: its configuration, the documents shared through it and the log of access to them;
- the register of artificial intelligence systems together with approval records;
- the legal register and the legal requirements assigned to the Organisation;
- domain security assessments together with their findings;
- Account and Organisation data: the Organisation profile, members, roles and permission assignments, invitations and settings;
- the activity log within the Organisation and the log of access by Guardiso personnel to Customer Data;
- the agreements concluded by the Customer with Guardiso together with the evidence of their conclusion, and signature requests and documents signed in the Platform;
- billing documents: the invoices issued to the Customer and the payment history;
- attachments and files uploaded by the Customer in any module, in the form in which they were uploaded.
-
Data excluded from porting (Article 25(2)(f)). This specification is exhaustive. A reason is given for each item. None of the exclusions impedes or delays Switching:
- the Content Library in unprocessed form, that is to say document templates, control catalogues, mappings between standards and the knowledge base in the form in which Guardiso makes them available to all Customers. Reason: they are trade secrets of Guardiso and are protected by copyright of Guardiso and of third parties, and Article 2(38) of the Data Act excludes such assets from exportable data. The Customer takes its own documentation created on the basis of those materials, without any time limit, in accordance with § 16(1);
- the Platform code, its technical configuration and its architecture. Reason: they concern the internal functioning of the service and are trade secrets of Guardiso. They contain no Customer Data;
- technical infrastructure logs, that is to say server records, performance metrics and diagnostic traces. Reason: they concern the internal functioning of the service, they cover the traffic of many Customers at once, and releasing them would expose other Customers' data and the Platform's safeguards. This exclusion does not cover the activity log within the Customer's Organisation or the log of access by Guardiso personnel, both of which the Customer takes under paragraph 8(23);
- search vectors and indexes, that is to say the numerical representation of the Customer's content created so that search can recognise the meaning of words. Reason: it carries no content beyond what the Customer takes anyway, it is useless outside the Platform and it can be recreated from the released documents;
- access keys to the Application Programming Interface, secrets for notification endpoints and access passwords to the Customer's compliance portal. Reason: Guardiso holds them only as a cryptographic hash and does not know their wording, so it cannot release it. The Customer creates new credentials with the new provider;
- a backup as a separate collection. Reason: a backup is a technical image of the entire Platform database, covering the data of all Customers. The Customer receives its own production data; releasing an image of the database would expose other Customers' data;
- Guardiso's internal records that do not concern the Customer's Organisation, including commercial correspondence and other Customers' data. Reason: they are not Customer Data.
Guardiso applies no other exclusion. If the Customer identifies data that appears neither in paragraph 8 nor in paragraph 9, Guardiso releases it on the terms set out in paragraph 8.
-
Exit support and information on the procedure (Article 25(2)(b) and Article 26(1)(a)). Guardiso supports the Customer in preparing and carrying out its exit strategy for the Service. Information on how Switching proceeds, by what routes and in what formats the data leaves, and what technical limitations are known to Guardiso, is set out in §§ 4, 5, 7 and in this paragraph. Guardiso provides that information free of charge before the Agreement is concluded and, on request, during its term as well.
-
Register of data structures and data formats (Article 26(1)(b)). The list of the data the Customer downloads, stating where it downloads it from and in what format, is set out in § 4 of this document. The document is published at the permanent address https://guardiso.com/wyjscie-z-uslugi and kept up to date on the terms set out in § 18(3). A description of the structure of the released files, that is to say the meaning of the individual columns and fields, is supplied by Guardiso with every release of data and is provided free of charge on request before the release as well.
Guardiso publishes a dictionary of the fields of every data set at https://guardiso.com/formaty-danych. The page is public and requires no account, so that the Customer's procurement team, its lawyer and a new provider nominated by it can check it before the Agreement is concluded. For each data set the page states its name, the place in the Platform from which it is downloaded, the name and format of the file, and the name, type of value and meaning of every column, in Polish, English and Dutch. The page carries the date on which it was last updated.
Guardiso publishes the same register in a machine-readable form at https://guardiso.com/api/formaty-danych, free of charge and without an account, so that a new provider can load it into its own tools.
The page and its machine-readable form are generated directly from the same definitions that the export functions use when building the file. The register therefore cannot describe columns other than those the Customer actually receives.
Guardiso does not apply open interoperability specifications or harmonised standards for the exchange of information security management system documentation, because there is no generally accepted exchange standard for such documentation today. In addition to the register, the Customer also receives a description of the file structure from kontakt@guardiso.com, free of charge and before making a request.
-
Jurisdiction of the infrastructure and protection against access by third-country authorities (Article 28).
- Jurisdiction. The ICT infrastructure on which Guardiso processes Customer Data, that is to say the application servers, the database, the file storage and the vault holding the encryption keys, is located in Poland, in the Warsaw region, at the provider Scaleway, S.A.S., which is established in France. That infrastructure is subject to Polish law and to the law of the European Union, and its provider is additionally subject to French law. Customer Data does not leave the European Economic Area other than in the cases identified in the list of subprocessors;
- Subprocessors. Guardiso publishes the current list of subprocessors, together with the country of processing and the legal basis for each transfer outside the European Economic Area, at https://guardiso.com/subprocessors. The same list forms Annex 2 to the Data Processing Agreement. Guardiso notifies the Customer of any intended change of subprocessor at least thirty days in advance, and the Customer may object;
- Contractual measures. § 10 of the Data Processing Agreement requires Guardiso to verify every request from an authority, to limit any disclosure strictly to the data covered by the request, and to notify the Customer without undue delay, no later than within forty-eight hours and before the data is disclosed. A judgment of a court or a decision of an authority of a third country may be given effect only where it is based on an international agreement in force, in accordance with Article 48 of Regulation (EU) 2016/679. Guardiso does not act on such requests outside that route. Guardiso imposes the same obligation on its subprocessors by contract;
- Organisational measures. Guardiso has not granted and does not grant any authority or service permanent, direct or automated access to Customer Data. Access by Guardiso personnel to Customer Data requires a request stating the scope, the duration and the reasons, together with the Customer's approval; it is time-limited and recorded in a log. Emergency access is permitted only in the event of an actual security incident and is subject to notification of the Customer within seven days, in accordance with § 5(4) and (5) of the Data Processing Agreement;
- Technical measures. The personal data of each Organisation is encrypted with its own Encryption Key as described in § 12. That key may be deleted only by the Owner of the Customer's Organisation. Once the Encryption Key has been deleted, the data encrypted with it is unreadable to Guardiso as well, and therefore cannot be disclosed to anyone in readable form;
- Guardiso also publishes and keeps up to date the information in this paragraph at https://guardiso.com/security and https://guardiso.com/subprocessors.
-
Open application programming interface to facilitate Switching (Article 30(2)). That provision requires a provider of a service such as Guardiso to make open interfaces available to the Customer and to the new provider, free of charge. Guardiso does not make such an interface available today and says so plainly. The factual position as at the date of this version of the document is as follows:
- access keys to the Application Programming Interface are created by Customers on the Professional and Enterprise Plans. The interface currently allows only the security questionnaire answer library to be read. The remaining registers of the Organisation cannot be read through it. The documentation of the interface is available after logging in, not publicly;
- the route by which data is released is the export from the Platform described in § 4 and the release of a Complete Data Set under § 7. That route is free of charge, has no quantitative limits and requires neither a particular Plan nor an access key;
- the structure of the released files is, by contrast, available programmatically, free of charge and without an account, at https://guardiso.com/api/formaty-danych, described in paragraph 11. A new provider can therefore prepare the loading of the data before the Customer releases it.
Guardiso does not present the position described in points 1, 2 and 3 as compliance with Article 30(2) of the Data Act. A Customer for whom programmatic access to its own data is a condition of choosing a provider should raise the matter before concluding the Agreement.
-
Switching charges (Article 29). Guardiso does not charge, and has never charged, any fee for Switching or for terminating the Agreement. All actions necessary for Switching are free of charge, including the transfer of the data and the network traffic involved. The details are set out in § 13. From 12 January 2027 any charge for actions necessary for Switching is prohibited under Article 29(1) of the Data Act. The ordinary subscription fee for a period during which the Service is provided is not a switching charge.
-
Good faith cooperation (Article 27). Guardiso cooperates in good faith with the Customer and with the new provider identified by the Customer, so that Switching is effective and timely and continuity of the Service is preserved. Guardiso does not refuse to cooperate because of who the new provider is, and does not make the release of data conditional on any statement by the Customer that is unrelated to the release of the data.
-
Relationship with the other provisions (Article 23). Where the Customer has requested Switching, the periods under this paragraph replace those under §§ 6, 8 and 9 and are longer than them. In all other respects those paragraphs apply unchanged. Where any document forming part of the legal relationship between the parties provides for a shorter period or a narrower right than this paragraph, this paragraph prevails, in accordance with § 23(4) of the Terms of Service. A mandatory provision of the Data Act prevails over any contractual provision.
§ 18. Amendments to the document and final provisions
-
Amendments to this document are announced by Guardiso with thirty days' notice, notifying the Customer by email to the Account Owner's address and by a message in the Platform. The absence of an objection within that period constitutes acceptance of the amendment. An objection entitles the Customer to terminate the Agreement with a refund of the fee for the unused part of the Billing Period.
-
An amendment may not shorten the Download Period or narrow the scope of data subject to release as compared with the position as at the date on which the Customer concluded the Agreement, unless the Customer expressly agrees to this.
-
Guardiso undertakes to update the content of § 5, § 13(4) and § 17(11) and (13) upon every change in the factual position, in particular once a unified export of an entire Organisation has been made available, once the file limit in the Audit Package has been removed, once the first documented test of restoring data from a backup has been carried out, and once an open application programming interface facilitating Switching has been made available. The register of data structures and data formats announced in the previous version of this document was published on 15 September 2026 at https://guardiso.com/formaty-danych and is kept up to date with every change to the structure of the released files.
-
The governing law is Polish law. The choice of Polish law does not deprive a Protected Customer resident in another Member State of the European Union of the protection afforded by the mandatory provisions of the law of the State of its residence.
-
The rules described in § 27 of the Terms of Service apply to the resolution of disputes.
-
If any provision of this document proves to be invalid or ineffective, the remaining provisions remain in force.
-
This document is drawn up in Polish. Where a translation into another language is made available, the Polish version prevails in the event of any discrepancy.
-
Contact for matters covered by this document:
| Matter | Channel |
|---|---|
| Termination of the Agreement, a request for release of a Complete Data Set, a request for deletion of data, a statement of the choice between return and deletion | kontakt@guardiso.com |
| Security matters, including questions about the Encryption Key and vulnerability reports | security@guardiso.com |
| Deletion of the Encryption Key | solely by the Customer itself in the Platform, by the Organisation Owner — see § 12(4). Guardiso does not perform this operation upon a request sent by email |
| Written correspondence | Guardiso Michał Lewandowski, ulica Święty Marcin 29 lokal 8, 61-806 Poznań |
- Version history:
| Version | Date | Scope of change |
|---|---|---|
| 1 September 2026 | 1 September 2026 | First release. Consolidation into a single document of the exit rules previously spread across the Terms of Service, the Data Processing Agreement, the Service Level Agreement and the End User Licence Agreement. Express statement of the limitations of the Export and of the actual period for deleting data from backups. |
| 8 September 2026 | 8 September 2026 | Drafting correction to the header. The editorial note about the publication date was replaced with the date from which the document applies. No term was changed. |
| 15 September 2026 | 15 September 2026 | Implementation of Chapter VI of the Data Act. § 17 rewritten as a complete switching procedure: a notice period of no more than two months, a transitional period of no more than thirty days with a right to a single extension, continuity of the Service, free reasonable assistance, an exhaustive specification of the data that is ported and of the data that is excluded, a retrieval period of at least thirty days after the transitional period, and the deletion periods. § 13 rewritten so that only additional support going beyond reasonable assistance may be charged for. Added information on the jurisdiction of the infrastructure, on the measures against access by third-country authorities and on the state of the application programming interface. Corrected to match the factual position: the channel for submitting requests and statements, and the extent of the access log visible in the Platform. Later the same day, once the missing functionality had been built: § 17(11) now points to the public register of data structures and data formats at https://guardiso.com/formaty-danych together with its machine-readable form, and § 6(2) describes the Download Period as a working read-only mode rather than as an intention. |