NetGuard Privacy Policy

Privacy Policy

Effective Date: 1 January 2025 Last Updated: 1 January 2025 Version: 1.0

This Privacy Policy describes how NetGuard Technologies, Inc. ("NetGuard", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use our compliance automation platform and related services. Please read this policy carefully.

Contents

  1. Information We Collect
  2. How We Use Your Information
  3. How We Share Your Information
  4. Data Retention
  5. Security of Your Data
  6. Your Rights and Choices
  7. Cookies and Tracking Technologies
  8. International Data Transfers
  9. Children's Privacy
  10. Third-Party Links and Services
  11. Changes to This Policy
  12. Contact Us
01

Information We Collect

We collect information you provide to us directly, information collected automatically when you use our services, and information from third-party sources.

1.1 Information You Provide Directly

1.2 Information Collected Automatically

1.3 Information from Third-Party Services

When you connect third-party services (AWS, Okta, Azure, GCP, GitHub, GitLab, Cisco Meraki, Palo Alto Panorama), we collect configuration data and security metadata from those services strictly for the purpose of evaluating compliance controls. We do not collect, store, or access the contents of your data stored in those services.

Important: NetGuard uses read-only access to your infrastructure. We collect configuration metadata (e.g., security group rules, IAM policies, MFA settings) — we do not read your business data, databases, files, or communications.

02

How We Use Your Information

We use the information we collect for the following purposes:

PurposeLegal Basis
Providing and operating the NetGuard platformContract performance
Running automated compliance scans and generating reportsContract performance
User authentication and account securityContract performance / Legitimate interest
Sending service notifications (scan results, alerts)Contract performance
Providing customer supportContract performance / Legitimate interest
Improving platform performance and reliabilityLegitimate interest
Analytics and product developmentLegitimate interest
Sending marketing communications (with opt-in)Consent
Complying with legal obligationsLegal obligation
Preventing fraud and enforcing our Terms of ServiceLegitimate interest / Legal obligation

We do not sell your personal information to third parties. We do not use your compliance data to train machine learning models without explicit consent.

03

How We Share Your Information

We may share your information in the following limited circumstances:

3.1 Service Providers

We engage trusted third-party service providers who process data on our behalf, including cloud infrastructure (AWS), database hosting, email delivery, payment processing, and analytics. All providers are contractually bound to handle data in accordance with this policy and applicable law.

3.2 Within Your Organisation

Users within your organisation may view compliance scan results, control statuses, and reports as permitted by the role-based access controls configured by your organisation's administrator.

3.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of NetGuard, our customers, or the public.

3.4 Business Transfers

If NetGuard is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

3.5 With Your Consent

We may share your information for any other purpose with your explicit consent.

We never: sell your data to advertisers, share your compliance results with competitors, or use your infrastructure credentials for any purpose other than running your authorised compliance scans.

04

Data Retention

We retain your data for as long as your account is active or as needed to provide services. Specific retention periods:

Data TypeRetention Period
Account and profile dataFor the duration of the account, plus 90 days after deletion
Compliance scan results and reports3 years (or as required by applicable regulations)
Integration credentialsDeleted immediately upon integration removal or account deletion
Audit logs and access logs2 years
Support communications3 years from last interaction
Billing records7 years (as required by financial regulations)
Anonymised usage analyticsIndefinitely (non-identifiable)

Upon account deletion, we will delete or anonymise your personal data within 90 days, except where retention is required by applicable law.

05

Security of Your Data

We implement industry-standard security measures to protect your information:

No method of transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable security measures, we cannot guarantee absolute security. If you discover a security vulnerability, please contact us at [email protected] immediately.

06

Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you.
RectificationRequest correction of inaccurate or incomplete personal data.
ErasureRequest deletion of your personal data, subject to legal retention requirements.
RestrictionRequest restriction of processing of your personal data in certain circumstances.
PortabilityReceive your data in a structured, machine-readable format.
ObjectionObject to processing based on legitimate interests or for direct marketing.
Withdraw ConsentWithdraw consent at any time where processing is based on consent.
Lodge a ComplaintFile a complaint with your local data protection authority.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.

Marketing Opt-Out

You may opt out of marketing communications at any time by clicking "Unsubscribe" in any marketing email, or by contacting us at [email protected]. Transactional and service communications (e.g., scan results, security alerts) cannot be disabled while your account is active.

07

Cookies and Tracking Technologies

We use cookies and similar technologies to operate our platform:

Cookie TypePurposeDuration
Essential / SessionAuthentication tokens (JWT), session management, CSRF protectionSession / 24 hours
PreferencesUser interface preferences (theme, layout settings)1 year
AnalyticsAnonymous usage analytics to improve the platform90 days
SecurityFraud detection and abuse preventionSession

We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings. Disabling essential cookies will prevent you from using the platform.

08

International Data Transfers

NetGuard operates globally. Your data may be transferred to and processed in countries outside your country of residence, including the United States. When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not recognised as providing adequate data protection, we use:

By using our services, you acknowledge and consent to these transfers.

09

Children's Privacy

NetGuard is a business-to-business (B2B) platform intended for use by organisations and their employees. Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a person under 18, we will take steps to delete that information promptly.

10

Third-Party Links and Services

The NetGuard platform may contain links to third-party websites or integrate with third-party services. This Privacy Policy applies only to NetGuard. We are not responsible for the privacy practices of any third-party websites or services. We encourage you to review the privacy policies of any third-party services you connect to or interact with through our platform.

11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the way we operate our platform. When we make material changes, we will:

Your continued use of the platform after the effective date of any changes constitutes your acceptance of the updated policy.

12

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

NetGuard Technologies, Inc.
Attn: Privacy Team
Email: [email protected]
Security concerns: [email protected]
Website: netguard.io

For EU/EEA residents, our Data Protection Officer can be reached at [email protected]. You also have the right to lodge a complaint with your local supervisory authority.