Privacy Policy

This policy explains how Guardexia processes personal data under UK GDPR and the Data Protection Act 2018.

1. Roles

For customer account administration data, Guardexia typically acts as a controller. For operational data uploaded by customers (including reconciliation inputs that may contain personal data), Guardexia typically acts as a processor on behalf of the customer.

2. Data we process

3. Lawful bases

We process personal data to perform a contract, to comply with legal obligations (where applicable), and for legitimate interests such as maintaining the security and integrity of the Service.

4. Retention

We retain data for as long as needed to provide the Service and meet legitimate operational and legal requirements. Customers may request export or deletion subject to contractual and legal constraints.

5. Security

We apply access controls, transport encryption, audit logging and operational security practices to protect data.

6. International transfers

If data is transferred outside the UK, we will use appropriate safeguards such as UK Addendum/SCCs where required.

7. Your rights

You may have rights including access, rectification, erasure, restriction, objection and data portability. To exercise rights, contact us.

8. Contact

Email: [email protected]