Privacy Policy
Last updated: 2 August 2026
What this covers
This policy covers both GuardianGaze products: the WordPress security plugin and the Enterprise security-ratings platform, together with guardiangaze.com. It replaces the separate policy that previously sat under /enterprise/legal/privacy.
Enterprise customers: the version that applies to your contract is the one signed in your order form or DPA. Contact [email protected] for the contract-specific version.
Who we are
The data controller is GuardianGaze Limited, a company registered in England and Wales with its registered office in London, United Kingdom. GuardianGaze Limited is a subsidiary of RedSecLabs Ltd. We are the controller for personal data processed in connection with both products and the public website.
What we collect
From the WordPress plugin:
- Your WordPress admin email address (to deliver scan reports and licence keys)
- Your site URL (to associate the licence and findings with your site)
- WordPress and plugin version numbers (to tailor scan logic)
- IP addresses of login attempts (for brute-force protection features, Pro only)
- Scan result data: file paths, suspicious code snippets, and database entry identifiers
From the Enterprise platform:
- Name, work email, IP address at sign-in, and audit-log entries for actions taken in the dashboard
From guardiangaze.com:
- Information you submit through contact or sign-up forms
- Account information (email, name, billing details via Stripe)
- IP address, user-agent and referrer
- Privacy-first analytics (page views, broad geography, referral source, no cross-site tracking)
What we don’t collect
- Passwords or password hashes
- Post or page content
- User data belonging to your site’s visitors
- File contents beyond short suspicious code snippets submitted for LLM analysis
- We do not scan your internal systems or ingest customer personal data from your platforms
How Enterprise scanning works
Enterprise scanning is performed from the public internet against assets attributed to an organisation, or via OAuth-scoped read access to cloud providers you have connected (AWS, Azure, GCP). It examines infrastructure (domains, subdomains, mail records, exposed services and certificates) and records information about organisations rather than about individuals.
Where such a scan incidentally surfaces personal data that is already published (for example, a name in a public WHOIS or certificate record), we process it on the basis of legitimate interests: assessing and reducing security risk in the supply chain. You can object to that processing at [email protected].
How we use it
- To operate both products and deliver scan results, ratings, alerts and reports
- To send transactional emails (licence keys, receipts, password resets)
- Account management, audit logging and security monitoring of our own platform
- To provide support when you contact us
- To improve detection quality using anonymised pattern data
- To comply with legal obligations
We do not sell personal data or use it for advertising.
Lawful basis
- Contractual necessity, account management and delivery of the service
- Legitimate interests, platform analytics, security monitoring, and the outside-in scanning described above
- Consent, marketing emails, which you can withdraw at any time via the unsubscribe link
- Legal obligation, where retention or disclosure is required by law
Where data is processed
The default region for the Enterprise platform is the United Kingdom. Other regions are available for customers with specific data-residency requirements; this is agreed in the customer order form. Data may be processed by infrastructure providers in the UK or EU. Where transfers occur outside the UK/EEA, we use Standard Contractual Clauses or equivalent mechanisms.
Sub-processors
The current sub-processor list for Enterprise customers is maintained in the customer DPA. Changes are notified to customers in advance via the contractual notice channel. See our Data Processing Addendum.
Retention
Plugin scan data is retained for the duration of your active subscription, or 90 days for free users, whichever is longer. Account data is retained until you request deletion. Enterprise retention periods are set out in the customer order form and DPA. Public-website analytics and contact-form submissions are retained for the period reasonably necessary to respond and follow up.
Your rights
Under UK and EU GDPR you have the right to access, correct, delete, restrict processing of, object to the processing of, and receive a portable copy of your personal data. To exercise any of these, email [email protected].
Cookies
See our separate Cookie policy for details on what cookies guardiangaze.com sets and how to control them.
Changes to this policy
We’ll notify you of material changes by email or by a notice on the site. Continued use after notice constitutes acceptance.
Contact
Privacy questions: [email protected]. Contract and DPA questions: [email protected].
If you are unhappy with how we handle your data you may complain to the UK supervisory authority, the Information Commissioner’s Office, at ico.org.uk.