Home

Privacy Policy

Effective date: 13 April 2026

1. Data Controller

The controller of your personal data is Guardiso — a sole proprietorship operated by Michal Lewandowski, based in Poland. Contact details for the controller are provided in section 10.

Data protection contact:

2. Data We Collect

We collect the following categories of personal data:

CategoryDetailsSource
Account dataEmail address, full name, profile pictureGoogle OAuth
Organization dataCompany name, industry, size, locationProvided by user
Usage dataAccess logs, IP addresses, browser type, in-app actionsAutomatic
User contentPolicies, risks, controls, evidence, questionnairesProvided by user

3. Purposes & Legal Bases

We process your data on the following legal bases (GDPR Art. 6):

PurposeLegal Basis
Service delivery (account, dashboard, ISMS features)Art. 6(1)(b) — contract performance
Security & fraud preventionArt. 6(1)(f) — legitimate interest
Communications (transactional email, notifications)Art. 6(1)(b) — contract performance
AI processing (policy generation, analysis)Art. 6(1)(b) — contract performance
Legal obligations (accounting, taxes)Art. 6(1)(c) — legal obligation

4. Data Retention

Data TypeRetention Period
Account & organization dataUntil account deletion
User content (policies, risks, etc.)Until account deletion
Access & usage logs90 days
Billing data5 years (legal obligation)

After account deletion, your data will be permanently removed within 30 days. Backups are purged within 90 days.

5. Data Recipients

We share your data with the following entities to the extent necessary for service delivery:

RecipientPurposeLocation
Scaleway SASApplication hosting, database, object storage, container registryWarsaw, Poland
Anthropic PBCAI Copilot query processing (optional) — query text only, transient processingUS (SCC + DPA)
OpenAI LLCGenerating embedding vectors for semantic search across the knowledge base (RAG)US (SCC + DPA)
Google LLCOAuth 2.0 authenticationUS / EU
Resend IncTransactional email (invitations, notifications, password resets)US (SCC)
Stripe IncSubscription payment processing — Guardiso never stores card dataUS / Ireland (SCC + DPA)
Cloudflare IncDNS, DDoS protection, WAF, edge cachingUS / EU (DPA)

A full list of subprocessors is available at /subprocessors.

6. International Transfers

Your data is stored on Scaleway servers in Warsaw (Poland), within the European Union.

AI features are optional. When a user uses AI Copilot, only the query content (for example a policy text to generate) is sent to Anthropic PBC (US). For semantic search across the knowledge base, document fragments are processed by OpenAI LLC (text-embedding-3-small model) to generate embedding vectors. Both providers operate under DPAs and Standard Contractual Clauses (SCCs), do not retain content after the request completes and do not use customer data to train AI models.

Subscription payments are handled by Stripe Inc (US / Ireland). Guardiso never sees or stores full payment card data — card details are passed directly to Stripe through their secure forms. Transfer is based on Stripe SCCs and DPA.

Your database, files, policies, risks, evidence and organisation configuration never leave the Scaleway data center in Warsaw.

7. Your Rights

Under GDPR, you have the following rights:

  • Right of accessyou can request a copy of your personal data
  • Right to rectificationyou can request correction of inaccurate data
  • Right to erasureyou can request deletion of your data ("right to be forgotten")
  • Right to portabilityyou can receive your data in a machine-readable format
  • Right to restrictionyou can request restriction of processing in certain situations
  • Right to objectyou can object to processing based on legitimate interest

To exercise your rights, contact us at info@guardiso.com.

You also have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

8. Cookies

We use cookies for proper service operation, authentication, and language preferences. For detailed information, see our Cookie Policy.

9. Changes to This Policy

We reserve the right to update this privacy policy. We will notify you of material changes via email or in-app notification with 30 days' advance notice.

10. Contact

If you have questions about this privacy policy or data processing, please contact us: