Privacy Policy

Last Updated: June 8, 2025

1. Introduction

GuardScan ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered email threat analysis platform ("Service").

Key Privacy Principles:

  • Minimal Data Collection: We collect only what's necessary for analysis
  • Temporary Processing: Email content is deleted within 7 days
  • No Permanent Storage: We don't store your personal communications
  • Transparent Processing: Clear information about how your data is used

2. Information We Collect

2.1 Email Content (Temporary Processing Only)

When you forward emails to GuardScan for analysis:

  • Email headers (From, To, Subject, timestamps)
  • Email body content (text and HTML)
  • Link URLs contained in emails
  • Attachment metadata (filename, size, type - not content)
  • Sender information (your email address for response delivery)

Important: This information is processed temporarily for analysis and automatically deleted within 7 days.

2.2 Analysis Results and Metadata

We retain the following for service improvement:

  • Threat analysis results (risk scores, patterns detected)
  • Anonymized content patterns (without personal information)
  • Performance metrics (analysis speed, accuracy rates)
  • Usage statistics (number of emails analyzed, peak times)

2.3 Account Information (Future Feature)

For registered accounts, we may collect:

  • Email address (for account access and communication)
  • Account preferences (language, notification settings)
  • Subscription information (billing data processed by third-party providers)

2.4 Technical Information

We automatically collect:

  • IP addresses (for security and geographic analysis)
  • Browser information (for website optimization)
  • Device identifiers (for abuse prevention)
  • Usage patterns (pages visited, features used)

2.5 Cookies and Tracking

We use essential cookies and similar technologies:

  • Essential cookies (required for service functionality)
  • Analytics cookies (website performance and usage)
  • Preference cookies (language and settings)

See our Cookie Policy for detailed information.

3. How We Use Your Information

3.1 Primary Service Delivery

  • Email threat analysis using AI and machine learning algorithms
  • Report generation with threat intelligence and risk assessment
  • Response delivery via email with analysis results
  • Performance optimization for faster and more accurate analysis

3.2 Service Improvement

  • Algorithm training using anonymized patterns (no personal data)
  • Threat intelligence enhancement with new attack patterns
  • Accuracy improvement through machine learning refinement
  • Feature development based on usage patterns and feedback

3.3 Security and Fraud Prevention

  • Abuse detection and prevention of service misuse
  • Security monitoring for unauthorized access attempts
  • Fraud prevention in payment processing (future feature)
  • Compliance monitoring with applicable laws and regulations

3.4 Communication

  • Service notifications about analysis results
  • Important updates regarding service changes or security issues
  • Customer support responses to inquiries and issues
  • Legal communications when required by law

4. Data Retention and Deletion

4.1 Email Content Retention

  • Immediate processing: Email content analyzed upon receipt
  • Temporary storage: Maximum 7 days for processing and quality assurance
  • Automatic deletion: All email content permanently deleted after 7 days
  • No backup retention: Deleted content is not recoverable

4.2 Analysis Results Retention

  • Analysis metadata: Retained for 12 months for service improvement
  • Anonymized patterns: Retained indefinitely for algorithm training
  • Performance metrics: Retained for 24 months for optimization
  • Error logs: Retained for 90 days for debugging and improvement

4.3 Account Data Retention (Future Feature)

  • Active accounts: Data retained while account is active
  • Deleted accounts: All personal data deleted within 30 days
  • Legal holds: Data may be retained longer if legally required

5. Data Sharing and Disclosure

5.1 We Do Not Sell Personal Data

GuardScan does not sell, rent, or trade your personal information to third parties for marketing purposes.

5.2 Service Providers

We may share data with trusted service providers:

  • Cloud infrastructure (AWS, Google Cloud) for processing and storage
  • Email delivery services for sending analysis results
  • Analytics providers for website performance monitoring
  • Payment processors for subscription billing (future feature)

All service providers are contractually bound to protect your data and use it only for specified purposes.

5.3 Legal Requirements

We may disclose information when required by law:

  • Legal process (subpoenas, court orders)
  • Law enforcement requests with proper legal basis
  • Regulatory compliance with cybersecurity reporting requirements
  • Public safety when there is imminent threat of harm

5.4 Business Transfers

In the event of merger, acquisition, or sale:

  • Users will be notified of any ownership changes
  • Data protection commitments will be maintained
  • Users may have options regarding data transfer

6. Data Security

6.1 Technical Safeguards

  • Encryption in transit (TLS 1.3 for all communications)
  • Encryption at rest (AES-256 for stored data)
  • Access controls (role-based permissions for staff)
  • Network security (firewalls, intrusion detection)

6.2 Operational Security

  • Regular security audits and vulnerability assessments
  • Employee training on data protection and privacy
  • Incident response procedures for potential breaches
  • Backup security with encrypted, geographically distributed storage

6.3 Data Minimization

  • Collect only necessary data for service functionality
  • Process data temporarily with automatic deletion
  • Anonymize data when possible for analytics and improvement
  • Regular data purging of unnecessary information

7. Your Privacy Rights

7.1 General Rights

  • Access: Request information about data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your personal data
  • Portability: Request transfer of your data to another service
  • Objection: Object to certain types of data processing

7.2 GDPR Rights (EU Residents)

If you are in the European Union, you have additional rights:

  • Right to be forgotten with complete data erasure
  • Data protection officer contact for privacy concerns
  • Supervisory authority complaints to your local data protection authority
  • Consent withdrawal for any consent-based processing

7.3 CCPA Rights (California Residents)

If you are a California resident:

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale (though we don't sell data)
  • Non-discrimination for exercising privacy rights

7.4 Exercising Your Rights

To exercise these rights:

  • Email: privacy@guardscan.io
  • Response time: Within 30 days of verified request
  • Identity verification: May be required for security
  • Free of charge: No cost for reasonable requests

8. International Data Transfers

8.1 Data Location

  • Primary processing: European Union (Ireland, Frankfurt)
  • Backup storage: Multiple EU data centers
  • AI processing: May involve US-based OpenAI services with appropriate safeguards

8.2 Transfer Safeguards

For any data transfers outside the EU:

  • Standard Contractual Clauses (SCCs) with service providers
  • Adequacy decisions when transferring to approved countries
  • Certification schemes ensuring appropriate data protection
  • Binding corporate rules for international service providers

9. Children's Privacy

GuardScan is not intended for use by children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware of such collection, we will delete the information immediately.

10. Changes to This Privacy Policy

10.1 Update Notifications

  • Email notification for material changes affecting your rights
  • Website posting of updated policy with effective date
  • Continued use constitutes acceptance of changes
  • Opt-out option if you disagree with material changes

10.2 Review Schedule

We review this Privacy Policy annually and update as needed for:

  • Legal compliance with new regulations
  • Service changes affecting data processing
  • Best practices in privacy protection
  • User feedback and concerns

11. Contact Information

11.1 Privacy Questions

For privacy-related questions or concerns:

  • Email: privacy@guardscan.io
  • Subject line: "Privacy Inquiry - [Your Concern]"
  • Response time: Within 5 business days

11.2 Data Protection Officer (EU)

For GDPR-related matters:

  • Email: dpo@guardscan.io
  • Address: [EU Business Address if applicable]

11.3 General Contact

  • Website: https://guardscan.io/contact
  • Business Address: [Your Business Address]
  • Phone: [Business Phone if applicable]

This Privacy Policy is effective as of June 8, 2025 and applies to all users of GuardScan services. By using our Service, you acknowledge that you have read and understood this Privacy Policy.