1. Who we are

GuardianX is operated by the person or legal entity identified during onboarding or in the applicable license records ("we", "us"). For device-holder data collected on behalf of a Customer (parent or employer), that Customer acts as the data controller; we act as data processor, except where noted below. For privacy questions, contact contact@guardianx.it.

2. What we collect

We do not collect credentials (passwords, payment card numbers) from administered devices, and we do not operate covertly.

3. Legal basis

Where GDPR or similar law applies, we (or the Customer as controller) rely on: contractual necessity (providing the Service), legitimate interest (security, integrity verification), consent (where required, e.g. certain location or notification features), and legal obligation (e.g. record-keeping).

4. How we use data

To provide, secure and improve the Service; to detect abuse contrary to our Responsible Use Policy; to provide support; and to comply with legal obligations.

5. Sharing with third parties

6. International transfers

Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms required by applicable law.

7. Retention

Data is retained according to the retention period configured by the Customer's policy (from 30 days up to 2 years), and deleted automatically once that period expires, subject to legal hold requirements.

Rejected or abandoned license requests are retained only as long as reasonably necessary for review, fraud prevention and legal administration. Executed agreement evidence and payment-confirmation records may be retained for the applicable limitation, tax or record-keeping period. Access to these records is restricted to authorized platform administrators.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, or export of your personal data, and may object to or restrict certain processing. Where a Customer (parent/employer) is the controller, requests regarding administered-device data should first be directed to that Customer; we will assist as processor.

9. Children's data

GuardianX may process data about a minor when used by a parent or legal guardian for parental device management. In that context, the parent/guardian is the data controller responsible for the child's data and for complying with applicable children's-privacy law.

10. Security

See our Security page for technical and organizational measures, including encryption, access control and audit logging.

11. Cookies on this website

This marketing website does not use advertising or tracking cookies. Only strictly necessary, session-based technical storage (if any) is used.

12. Changes

We may update this Privacy Policy; material changes will be notified through the dashboard or by email before taking effect.

13. Contact

Privacy requests: see our Contact page.