This policy explains how Guardexia processes personal data under UK GDPR and the Data Protection Act 2018.
For customer account administration data, Guardexia typically acts as a controller. For operational data uploaded by customers (including reconciliation inputs that may contain personal data), Guardexia typically acts as a processor on behalf of the customer.
We process personal data to perform a contract, to comply with legal obligations (where applicable), and for legitimate interests such as maintaining the security and integrity of the Service.
We retain data for as long as needed to provide the Service and meet legitimate operational and legal requirements. Customers may request export or deletion subject to contractual and legal constraints.
We apply access controls, transport encryption, audit logging and operational security practices to protect data.
If data is transferred outside the UK, we will use appropriate safeguards such as UK Addendum/SCCs where required.
You may have rights including access, rectification, erasure, restriction, objection and data portability. To exercise rights, contact us.
Email: [email protected]