Privacy Policy
Last updated: August 4, 2026
GuardON is a cybersecurity awareness and training platform. This policy explains what personal data we process, why, on what legal basis, and what rights you have β in accordance with Brazil's Lei Geral de ProteΓ§Γ£o de Dados (LGPD) and the EU General Data Protection Regulation (GDPR), as applicable.
1. Who we are
GuardON operates this platform as a provider of security awareness training services. Depending on the type of data and context, GuardON acts as a controller (the client organization's own account data, billing data, platform usage data) or as a processor/subprocessor (data belonging to a client organization's employees, processed on that organization's behalf β see section 5).
2. Data we collect
We collect the following categories of personal data:
- Account data: name, email, role, department, preferred language and time zone.
- Optional demographic signal: self-declared age range at sign-up, used only as a vulnerability signal to personalize training β never shared outside the platform.
- Channel contact data: phone number or other channel identifiers, only if the user actively chooses to configure them.
- Behavioral and risk data: phishing/smishing/vishing simulation outcomes, security-assessment answers, risk scores and their history over time, course and training-module progress.
- AI-generated behavioral profile: an internal model (preferred channel, optimal contact time, learning style, topics to avoid) used exclusively to personalize the training content shown to you.
- Content the user chooses to publish: real-world experience reports voluntarily shared on the platform, and related comments.
- Technical data: essential and functional cookies (see section 12), request-time IP address, authentication logs.
3. How we use your data
We use the data above to: operate and personalize security-awareness simulations and training; calculate your behavioral risk score and adapt content difficulty and frequency; generate progress reports for the client organization (aggregated by role, not detailed personal content, unless the organization has legitimate access to that detail); comply with legal and regulatory security-awareness obligations (e.g. NIS2, DORA, ISO 27001, SOC 2); and keep the platform itself secure and reliable.
4. Legal basis for processing
Depending on jurisdiction and data type, processing relies on: performance of a contract (delivering the service the client organization has purchased); the client organization's legitimate interest, as an employer, in training and protecting its workforce against real cybersecurity threats; compliance with a legal obligation; and, where applicable, your explicit consent (for example, when optionally configuring additional contact channels).
5. Roles: controller and processor
When an organization ("Client") engages GuardON to train its employees, the Client is the controller of those employees' personal data β it decides who is invited, which simulations run, and is responsible for having a valid legal basis for that training within its own workforce. GuardON acts as a processor, handling that data only on the Client's instructions and for the purposes described in this policy. If you are an employee of a Client organization, you may exercise your data-subject rights with us and/or with your organization β see section 11.
6. Who we share your data with
We do not sell personal data. We share data only with the following categories of third parties, strictly necessary to operate the service, all contractually bound to protect data to the same standard we do:
- Database infrastructure and hosting provider, to store and serve the platform.
- Authentication and identity-management provider, to securely generate and validate access sessions.
- Transactional email delivery provider, to send phishing simulations and platform communications by email.
- Language-model (AI) providers, to auto-generate personalized simulation and training content.
- A URL/IP/domain reputation lookup service, used only in the optional threat-analysis feature, when the user themselves submits an address for review.
- Public authorities, when required by law.
7. International transfers
Some of the providers above may process data outside your country of residence. In those cases, we ensure appropriate transfer mechanisms (standard contractual clauses or equivalent) in compliance with LGPD and/or GDPR, as applicable.
8. How long we keep your data
Account and behavioral data are kept while your account remains active with the client organization. Security audit logs are kept for up to 12 months and then automatically deleted. After an account-deletion request (see section 11), associated personal and behavioral data is removed within a reasonable period, except where the law requires it to be retained longer (for example, for tax or legal-defense purposes).
9. Security
We apply technical and organizational measures to protect your data, including encryption in transit, role-based access control, logical isolation between client organizations, audit logging of administrative actions, and rate limiting against automated abuse. No system is fully immune to incidents; in the event of a data breach affecting you, we will notify authorities and/or data subjects within the timeframes required by law.
10. Your rights
Subject to applicable law (LGPD art. 18 and/or GDPR arts. 15-22), you have the right to: confirm the existence of processing; access your data; correct incomplete, inaccurate or outdated data; request deletion of your data; obtain a portable copy of your data in a structured format; object to processing based on legitimate interest; and lodge a complaint with the competent data-protection authority (Brazil's ANPD, or your EU country's supervisory authority).
11. How to exercise your rights
You can download a structured copy of all personal and behavioral data we hold about you at any time, directly from your account settings ("Download my data"). You can also delete your account directly from settings, which triggers removal of associated data as described in section 8. For any other request related to your rights, or if you're an employee of a client organization and prefer to contact us directly rather than your organization, write to privacy@guardon.me.
12. Cookies
We use essential cookies (required to keep you authenticated) and functional cookies (to remember preferences like theme and language). We do not currently use analytics or advertising cookies; if that changes, we will ask for your explicit consent before enabling them. You can manage your cookie preferences at any time via the "Manage cookies" link in the site footer.
13. Children's data
The platform is not intended for direct use by individuals under 16. If we become aware that we have collected data from a minor without the legally required consent of a parent or guardian, we will delete that data.
14. Changes to this policy
We may update this policy periodically to reflect changes to our practices or applicable law. The date at the top of this page indicates the latest version. Material changes will be communicated prominently within the platform.
15. Contact
For questions about this policy or the processing of your personal data, contact us at privacy@guardon.me.
