G

GUARDYX AI

AI Agent Control Plane

Legal

Guardyx AI Privacy Policy

Version 2.1

Effective May 14, 2026 · Last updated May 14, 2026

This Privacy Policy describes how Code Above Lab, Inc. d/b/a Guardyx AI (“Guardyx,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information in connection with the Guardyx AI platform, APIs, SDKs, hosted services, customer portal, integrations, websites, and related services (collectively, the “Services”).

This Privacy Policy applies to information Guardyx processes as a controller under applicable privacy laws.

Where Guardyx processes Customer Data on behalf of customers through the Services, Guardyx generally acts as a processor or service provider under applicable privacy laws, and such processing is governed by the applicable customer agreement and Data Processing Addendum (“DPA”).

Capitalized terms not defined in this Privacy Policy have the meanings set forth in the Guardyx AI Terms of Service.

Contents

  1. Scope and Roles
  2. Categories of Information We Collect
  3. AI Model Providers and Third-Party Services
  4. Human Review and Access Controls
  5. How We Use Information
  6. AI and Machine Learning Restrictions
  7. How We Share Information
  8. International Data Transfers
  9. Data Retention
  10. Security
  11. Automated Decision-Making
  12. Privacy Rights
  13. Categories of Personal Information Disclosed (California)
  14. Children’s Privacy
  15. Government Requests and Transparency
  16. Changes to this Privacy Policy
  17. Linked Policies and Trust Center
  18. Contact Information

1. Scope and Roles

1.1 Scope

This Privacy Policy applies to:

This Privacy Policy does not apply to:

1.2 Controller and Processor Roles

Guardyx acts as a controller for:

Guardyx acts as a processor or service provider for Customer Data processed through the Services, including:

Guardyx may independently determine the purposes and means of limited processing required for security, fraud prevention, legal compliance, or operational integrity as permitted under applicable law and the DPA.

The applicable customer agreement and DPA govern Guardyx’s processing of Customer Data.

The descriptions of Customer Data processing in this Privacy Policy are provided for transparency and informational purposes only and do not modify the DPA or customer agreements.

2. Categories of Information We Collect

2.1 Information You Provide

We may collect:

Account credentials and authentication information may constitute sensitive personal information under certain laws.

2.2 Operational Service Metadata

Guardyx may collect operational metadata relating to the operation, security, reliability, and administration of the Services, including:

Operational metadata generally does not include the substantive content of prompts, tool payloads, approval snapshots, or workflow content unless necessary for support, security, abuse prevention, legal compliance, or customer-authorized troubleshooting.

2.3 Customer Data and AI Workflow Content

Customers may process Customer Data through the Services, including:

Guardyx processes such Customer Data as a processor or service provider on behalf of customers in accordance with the DPA and customer agreements.

2.4 Cookies and Similar Technologies

Guardyx and its service providers may use cookies, pixels, local storage, SDKs, and similar technologies to:

Users may manage cookie preferences through browser settings or available consent mechanisms. See the Cookie Policy for details.

3. AI Model Providers and Third-Party Services

The Services may integrate with or route requests to third-party services, including:

Where configured by customers, prompts, tool payloads, workflow content, or outputs may be transmitted to third-party AI model providers or integration partners necessary to provide the Services.

Depending on the Services configuration, customers may be able to:

Guardyx maintains contractual and technical safeguards intended to limit unauthorized use of Customer Data by subprocessors and AI model providers.

In particular, Guardyx maintains contractual protections intended to prohibit unauthorized use of Customer Data by subprocessors and AI model providers for model training purposes except as expressly authorized by customers.

Additional information regarding subprocessors is available through Guardyx’s Trust Center and DPA.

4. Human Review and Access Controls

Authorized Guardyx personnel may access Customer Data or operational metadata where reasonably necessary to:

Access to Customer Data is restricted using least-privilege access controls, logging, reviewer authorization controls, and confidentiality obligations.

Guardyx does not use Customer Data to train AI models except as expressly permitted under the DPA or other written agreement.

5. How We Use Information

5.1 Processing Purposes and Legal Bases

PurposeCategories of InformationLegal BasisIllustrative Retention
Provide and operate the ServicesAccount data, operational metadataContract performanceDuration of relationship plus applicable legal retention periods
Authentication and account securityCredentials, session data, telemetryLegitimate interests; legal obligationsGenerally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements
Billing and subscription managementBilling and payment informationContract performance; legal obligationsUp to 7 years
Fraud prevention and abuse detectionOperational metadata, telemetry, security eventsLegitimate interestsGenerally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements
Customer support and troubleshootingAccount information, support communications, customer-authorized workflow dataContract performance; legitimate interestsDuration of support relationship plus reasonable archival periods
Security monitoring and incident responseTelemetry, logs, operational metadataLegitimate interests; legal obligationsGenerally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements
Product reliability and operational analyticsAggregated or de-identified operational dataLegitimate interestsDe-identified retention periods vary by operational need
Marketing communicationsContact information and preferencesConsent or legitimate interests where permittedUntil opt-out or withdrawal of consent
Compliance with legal obligationsRelevant account, operational, or transactional informationLegal obligationsAs required by applicable law

Users may opt out of marketing communications using unsubscribe mechanisms included in communications or by contacting Guardyx.

6. AI and Machine Learning Restrictions

Unless expressly agreed otherwise in writing:

Aggregated or de-identified data will not be used to train generative AI models, foundation models, or models intended to learn from or reproduce customer workflow content derived from Customer prompts, tool payloads, approval snapshots, or workflow content.

The foregoing does not restrict Guardyx’s use of aggregated or de-identified operational signals for:

For purposes of this Privacy Policy, “aggregated or de-identified” means information that:

7. How We Share Information

Guardyx may disclose information:

Guardyx maintains a current subprocessor list through its Trust Center.

8. International Data Transfers

Guardyx may process information in the United States and other jurisdictions where Guardyx or its subprocessors operate.

Where required under applicable law, Guardyx implements safeguards for international data transfers, including:

Additional details are provided in the DPA.

9. Data Retention

Guardyx retains information for periods reasonably necessary to:

Illustrative retention periods may include:

CategoryTypical Retention Period
Account and subscription informationDuration of account relationship plus applicable legal retention periods
Billing and transaction recordsUp to 7 years
Security and operational logsGenerally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements
Backup systemsGenerally not more than 90 days unless extended due to disaster recovery procedures, legal obligations, or active security investigations
Marketing preferencesUntil withdrawal of consent or opt-out

Customer Data retention is governed by the applicable customer agreement and DPA.

10. Security

Guardyx maintains industry-standard administrative, technical, and organizational safeguards designed to protect information.

Such safeguards may include:

Additional security information may be available through Guardyx’s Trust Center.

No system can be guaranteed to be completely secure.

11. Automated Decision-Making

Guardyx does not use Customer Data to make solely automated decisions that produce legal or similarly significant effects regarding individuals.

Guardyx may use automated systems for security monitoring, fraud detection, abuse prevention, anomaly detection, operational analytics, or reliability engineering.

Such processing may include automated analysis of authentication activity, telemetry, or operational behavior patterns to identify suspected abuse, fraud, policy violations, or security risks.

Such processing is designed to support operational integrity and does not independently determine legal or similarly significant outcomes regarding individuals.

Customers may independently configure workflows, approvals, or AI systems that perform automated processing through the Services.

Customers are responsible for implementing appropriate human review and governance controls for such systems.

12. Privacy Rights

12.1 GDPR, UK GDPR, and Similar Jurisdictions

Subject to applicable law, individuals may have rights to:

Guardyx responds to verified requests within one month as required by applicable law, subject to extensions permitted under applicable privacy laws.

Where Guardyx acts solely as a processor on behalf of customers, requests relating to Customer Data should generally be directed to the relevant customer.

12.2 California and Other U.S. State Privacy Rights

Depending on applicable law, residents of California and certain U.S. states may have rights to:

Guardyx does not sell Customer Data, share Customer Data for cross-context behavioral advertising, or engage in targeted advertising using Customer Data.

Because Guardyx does not sell or share personal information for cross-context behavioral advertising, Guardyx does not provide a “Do Not Sell or Share My Personal Information” link.

California residents may also request information regarding certain disclosures under California Civil Code Section 1798.83.

Privacy requests may be submitted to privacy@guardyx.ai.

13. Categories of Personal Information Disclosed (California)

CategoryExamplesSources of CollectionBusiness PurposeCategories of RecipientsIllustrative Retention
IdentifiersName, email, account identifiersDirectly from users and customersAccount administration, authenticationService providers, infrastructure vendorsDuration of relationship plus applicable legal retention periods
Commercial InformationSubscription and billing recordsDirectly from customersBilling and account managementPayment providers, finance systemsUp to 7 years
Internet or Network ActivitySession activity, device metadata, telemetryAutomatically collected through the ServicesSecurity, reliability, analyticsInfrastructure and observability vendorsGenerally up to 13 months
Professional InformationEmployer, title, roleDirectly from users or customersAccount administration and salesCRM and support vendorsDuration of relationship plus reasonable archival periods
Sensitive Personal InformationCredentials and authentication informationDirectly from usersSecurity and authenticationIdentity and authentication providersCredentials retained for duration of account relationship; authentication and security logs generally retained up to 13 months unless otherwise required by law

Guardyx uses sensitive personal information only for permitted business purposes and not to infer characteristics about individuals.

14. Children’s Privacy

The Services are intended for business and enterprise use by individuals eighteen (18) years of age or older.

Guardyx does not knowingly collect personal information from individuals under eighteen (18) years of age, and in no event from children under thirteen (13).

Customers may not use the Services in violation of COPPA, GDPR Article 8, or similar children’s privacy laws.

15. Government Requests and Transparency

Guardyx may disclose information where required by law, legal process, or governmental request.

Where legally permitted, Guardyx may:

16. Changes to this Privacy Policy

Guardyx may update this Privacy Policy from time to time.

Material changes affecting rights or obligations will generally be communicated through the Services, email, or other reasonable means.

Where required by applicable law, Guardyx will obtain consent or provide additional notice before material changes become effective.

17. Linked Policies and Trust Center

Additional information may be available through:

18. Contact Information

Code Above Lab, Inc.

Operator of Guardyx AI

Privacy Contact: privacy@guardyx.ai

Legal Contact: legal@guardyx.ai

Website: https://guardyx.ai

Where required by applicable law, Guardyx will designate an EU or UK representative and publish corresponding contact details through its Trust Center or legal notices.

See also: Terms of Service · Data Processing Addendum · Acceptable Use Policy · Cookie Policy.