Legal
Privacy Policy
Last updated September 9, 2026. This notice covers the GuardSource platform and this website.
Who we are
GuardResourceOne ("we", "us") provides GuardSource, a security enterprise management platform. This policy explains what personal data we collect through our website and platform, why we collect it, how long we keep it and what rights you have.
For personal data about our own website visitors and account holders, GuardResourceOne is the data controller. For personal data our customers put into GuardSource about their officers, sites and clients, our customer is the controller and GuardResourceOne is the processor acting on their instructions under our Data Processing Addendum.
What we collect
- Account data — name, work email, company, password hash or single sign-on identifier, role and account preferences.
- Billing data — billing contact, billing address, subscription plan, invoices and payment method tokens. Full card numbers are handled by our payment processor and never reach our servers.
- Operational data you enter — officer records, schedules, shift punches, GPS positions recorded during a shift, checkpoint scans, incident reports and attachments, client and site records.
- Technical data — IP address, browser and device type, pages requested, timestamps and error diagnostics.
- Communications — messages you send us through contact forms, demo requests, support tickets and email.
- Consent and audit records — the cookie choices you made and security-relevant events on your account, kept as evidence of compliance.
Why we use it, and our legal bases
| Purpose | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Provide and operate the platform | Account, operational, technical | Performance of a contract |
| Billing and collections | Account, billing | Performance of a contract |
| Security, fraud prevention and audit logging | Technical, audit | Legitimate interests; legal obligation |
| Support and service communications | Account, communications | Performance of a contract |
| Product analytics and site improvement | Technical, analytics | Consent |
| Marketing email | Account, communications | Consent (withdraw any time) |
| Tax, accounting and dispute records | Billing | Legal obligation |
Location data
GuardSource records an officer's position when they clock in or out, scan a checkpoint or trigger a duress alert. Position is captured at those events and while a shift is active where the customer has enabled continuous tracking — never outside a shift.
Our customers are responsible for telling their officers that location is recorded, for the lawful basis for that recording, and for setting the tracking configuration. We provide controls to limit tracking to shift hours and to set retention windows.
Who we share it with
We do not sell personal data and we do not share it for cross-context behavioural advertising.
We share data with the sub-processors listed on our sub-processors page, each under a written contract that limits them to processing on our instructions. We may also disclose data where legally required, or to a successor entity in a merger or acquisition, in which case we will notify affected customers.
International transfers
Where personal data leaves the UK or European Economic Area, we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, or on an adequacy decision where one applies. A copy of the relevant transfer mechanism is available on request.
How long we keep it
| Data | Retention |
|---|---|
| Active account and operational data | For the life of the account |
| Customer data after account closure | Deleted or returned within 30 days, unless law requires longer |
| Billing and tax records | 7 years from the transaction |
| Security audit logs | 2 years |
| Consent records | 3 years from the last consent event |
| Data subject requests | 3 years from completion |
| Website server logs | 90 days |
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive a portable copy, withdraw consent at any time, and not be subject to solely automated decisions with legal effect. California residents additionally have the right to know, delete, correct and opt out of sale or sharing — we do not sell or share personal data — and the right not to be discriminated against for exercising these rights.
You can exercise any of these from our data request page, or by emailing privacy@guardresourceone.com. Account holders can download their data and delete their account directly from the dashboard. We respond within 30 days and will tell you if we need an extension. You also have the right to complain to your local supervisory authority.
Security
We encrypt data in transit with TLS 1.2 or better and at rest with AES-256. Access to production data is role-based, least-privilege and logged. See our Security page for the full description of our controls and our current SOC 2 status.
Children
GuardSource is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children. If you believe a child's data has reached us, contact privacy@guardresourceone.com and we will delete it.
Changes to this policy
We will post any material change here and update the date at the top. Where the change affects how we rely on your consent, we will ask you again.
Exercise your rights
Submit a request through our data request form or email privacy@guardresourceone.com. We reply within 30 days.
