Skip to content
G

GUARDYX AI

Legal

Guardyx AI Privacy Policy

Version 2.1

Effective May 14, 2026 · Last updated May 14, 2026

This Privacy Policy describes how Code Above Lab, Inc. d/b/a Guardyx AI (“Guardyx,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information in connection with the Guardyx AI platform, APIs, SDKs, hosted services, customer portal, integrations, websites, and related services (collectively, the “Services”).

This Privacy Policy applies to information Guardyx processes as a controller under applicable privacy laws.

Where Guardyx processes Customer Data on behalf of customers through the Services, Guardyx generally acts as a processor or service provider under applicable privacy laws, and such processing is governed by the applicable customer agreement and Data Processing Addendum (“DPA”).

Capitalized terms not defined in this Privacy Policy have the meanings set forth in the Guardyx AI Terms of Service.

Contents

  1. Scope and Roles
  2. Categories of Information We Collect
  3. AI Model Providers and Third-Party Services
  4. Human Review and Access Controls
  5. How We Use Information
  6. AI and Machine Learning Restrictions
  7. How We Share Information
  8. International Data Transfers
  9. Data Retention
  10. Security
  11. Automated Decision-Making
  12. Privacy Rights
  13. Categories of Personal Information Disclosed (California)
  14. Children’s Privacy
  15. Government Requests and Transparency
  16. Changes to this Privacy Policy
  17. Linked Policies and Trust Center
  18. Contact Information

1. Scope and Roles

1.1 Scope

This Privacy Policy applies to:

  • visitors to our websites;
  • prospective customers;
  • customer administrators and Authorized Users;
  • individuals interacting with our Services;
  • event participants;
  • support and sales communications.

This Privacy Policy does not apply to:

  • Customer Data processed solely on behalf of customers under the DPA;
  • third-party services not controlled by Guardyx.

1.2 Controller and Processor Roles

Guardyx acts as a controller for:

  • account registration information;
  • billing and subscription information;
  • website analytics and marketing data;
  • business contact information;
  • support and sales communications;
  • event registration and participation information;
  • security and fraud-prevention processing;
  • operational telemetry relating to operation of the Services.

Guardyx acts as a processor or service provider for Customer Data processed through the Services, including:

  • prompts;
  • tool payloads and responses;
  • workflow content;
  • approval snapshots;
  • execution events;
  • audit records containing customer workflow content.

Guardyx may independently determine the purposes and means of limited processing required for security, fraud prevention, legal compliance, or operational integrity as permitted under applicable law and the DPA.

The applicable customer agreement and DPA govern Guardyx’s processing of Customer Data.

The descriptions of Customer Data processing in this Privacy Policy are provided for transparency and informational purposes only and do not modify the DPA or customer agreements.

2. Categories of Information We Collect

2.1 Information You Provide

We may collect:

  • name;
  • employer and role information;
  • business contact information;
  • account credentials;
  • billing and payment information;
  • communications and support requests;
  • event registrations and marketing preferences.

Account credentials and authentication information may constitute sensitive personal information under certain laws.

2.2 Operational Service Metadata

Guardyx may collect operational metadata relating to the operation, security, reliability, and administration of the Services, including:

  • authentication and session activity;
  • API usage metadata;
  • workflow execution metadata;
  • approval workflow event metadata;
  • infrastructure telemetry;
  • device and browser information;
  • service reliability metrics;
  • fraud and abuse-detection signals;
  • IP address and approximate geolocation information;
  • behavioral security and authentication indicators;
  • metering and quota usage records.

Operational metadata generally does not include the substantive content of prompts, tool payloads, approval snapshots, or workflow content unless necessary for support, security, abuse prevention, legal compliance, or customer-authorized troubleshooting.

2.3 Customer Data and AI Workflow Content

Customers may process Customer Data through the Services, including:

  • prompts and outputs;
  • tool requests and responses;
  • workflow content;
  • approval snapshots;
  • audit logs;
  • telemetry associated with workflow execution;
  • execution events and governance records.

Guardyx processes such Customer Data as a processor or service provider on behalf of customers in accordance with the DPA and customer agreements.

2.4 Cookies and Similar Technologies

Guardyx and its service providers may use cookies, pixels, local storage, SDKs, and similar technologies to:

  • authenticate users;
  • secure the Services;
  • remember preferences;
  • analyze traffic and engagement;
  • monitor performance and reliability;
  • improve user experience.

Users may manage cookie preferences through browser settings or available consent mechanisms. See the Cookie Policy for details.

3. AI Model Providers and Third-Party Services

The Services may integrate with or route requests to third-party services, including:

  • cloud infrastructure providers;
  • AI model providers;
  • observability and telemetry vendors;
  • authentication providers;
  • payment processors;
  • customer support providers;
  • security and monitoring vendors.

Where configured by customers, prompts, tool payloads, workflow content, or outputs may be transmitted to third-party AI model providers or integration partners necessary to provide the Services.

Depending on the Services configuration, customers may be able to:

  • select among supported AI model providers;
  • configure retention or logging settings;
  • enable reduced-retention or zero-retention modes where supported;
  • restrict routing of Customer Data to specific providers or regions.

Guardyx maintains contractual and technical safeguards intended to limit unauthorized use of Customer Data by subprocessors and AI model providers.

In particular, Guardyx maintains contractual protections intended to prohibit unauthorized use of Customer Data by subprocessors and AI model providers for model training purposes except as expressly authorized by customers.

Additional information regarding subprocessors is available through Guardyx’s Trust Center and DPA.

4. Human Review and Access Controls

Authorized Guardyx personnel may access Customer Data or operational metadata where reasonably necessary to:

  • provide customer support;
  • investigate security incidents;
  • detect abuse or fraud;
  • maintain reliability and operational integrity;
  • comply with legal obligations;
  • troubleshoot customer-authorized technical issues.

Access to Customer Data is restricted using least-privilege access controls, logging, reviewer authorization controls, and confidentiality obligations.

Guardyx does not use Customer Data to train AI models except as expressly permitted under the DPA or other written agreement.

5. How We Use Information

5.1 Processing Purposes and Legal Bases

PurposeCategories of InformationLegal BasisIllustrative Retention
Provide and operate the ServicesAccount data, operational metadataContract performanceDuration of relationship plus applicable legal retention periods
Authentication and account securityCredentials, session data, telemetryLegitimate interests; legal obligationsGenerally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements
Billing and subscription managementBilling and payment informationContract performance; legal obligationsUp to 7 years
Fraud prevention and abuse detectionOperational metadata, telemetry, security eventsLegitimate interestsGenerally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements
Customer support and troubleshootingAccount information, support communications, customer-authorized workflow dataContract performance; legitimate interestsDuration of support relationship plus reasonable archival periods
Security monitoring and incident responseTelemetry, logs, operational metadataLegitimate interests; legal obligationsGenerally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements
Product reliability and operational analyticsAggregated or de-identified operational dataLegitimate interestsDe-identified retention periods vary by operational need
Marketing communicationsContact information and preferencesConsent or legitimate interests where permittedUntil opt-out or withdrawal of consent
Compliance with legal obligationsRelevant account, operational, or transactional informationLegal obligationsAs required by applicable law

Users may opt out of marketing communications using unsubscribe mechanisms included in communications or by contacting Guardyx.

6. AI and Machine Learning Restrictions

Unless expressly agreed otherwise in writing:

  • Guardyx does not use Customer Data to train foundation models or general-purpose AI models;
  • Guardyx does not sell Customer Data;
  • Guardyx does not share Customer Data for cross-context behavioral advertising.

Aggregated or de-identified data will not be used to train generative AI models, foundation models, or models intended to learn from or reproduce customer workflow content derived from Customer prompts, tool payloads, approval snapshots, or workflow content.

The foregoing does not restrict Guardyx’s use of aggregated or de-identified operational signals for:

  • operational security;
  • fraud and abuse prevention;
  • reliability engineering;
  • anomaly detection;
  • operational analytics.

For purposes of this Privacy Policy, “aggregated or de-identified” means information that:

  • cannot reasonably identify an individual or customer;
  • is not reasonably linkable to a specific individual or customer;
  • is subject to technical, administrative, and contractual measures designed to prevent re-identification.

7. How We Share Information

Guardyx may disclose information:

  • to subprocessors and service providers supporting the Services;
  • to cloud, security, observability, analytics, authentication, payment, support, and infrastructure providers;
  • to AI model providers where configured by customers;
  • in connection with mergers, acquisitions, financings, or corporate transactions;
  • to comply with legal obligations or legal process;
  • to protect rights, safety, integrity, or security of Guardyx, customers, users, or third parties.

Guardyx maintains a current subprocessor list through its Trust Center.

8. International Data Transfers

Guardyx may process information in the United States and other jurisdictions where Guardyx or its subprocessors operate.

Where required under applicable law, Guardyx implements safeguards for international data transfers, including:

  • the EU Standard Contractual Clauses (including applicable Module 2 and Module 3 transfers);
  • the UK International Data Transfer Addendum or UK transfer mechanisms;
  • transfer impact assessments where appropriate;
  • supplementary technical and organizational safeguards.

Additional details are provided in the DPA.

9. Data Retention

Guardyx retains information for periods reasonably necessary to:

  • provide the Services;
  • maintain security and operational integrity;
  • comply with legal obligations;
  • resolve disputes;
  • enforce agreements.

Illustrative retention periods may include:

CategoryTypical Retention Period
Account and subscription informationDuration of account relationship plus applicable legal retention periods
Billing and transaction recordsUp to 7 years
Security and operational logsGenerally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements
Backup systemsGenerally not more than 90 days unless extended due to disaster recovery procedures, legal obligations, or active security investigations
Marketing preferencesUntil withdrawal of consent or opt-out

Customer Data retention is governed by the applicable customer agreement and DPA.

10. Security

Guardyx maintains industry-standard administrative, technical, and organizational safeguards designed to protect information.

Such safeguards may include:

  • encryption in transit and at rest;
  • tenant-aware logical isolation and access controls;
  • least-privilege access controls;
  • audit logging and telemetry;
  • monitoring and incident response procedures;
  • vulnerability management practices;
  • reviewer access controls for approval workflows.

Additional security information may be available through Guardyx’s Trust Center.

No system can be guaranteed to be completely secure.

11. Automated Decision-Making

Guardyx does not use Customer Data to make solely automated decisions that produce legal or similarly significant effects regarding individuals.

Guardyx may use automated systems for security monitoring, fraud detection, abuse prevention, anomaly detection, operational analytics, or reliability engineering.

Such processing may include automated analysis of authentication activity, telemetry, or operational behavior patterns to identify suspected abuse, fraud, policy violations, or security risks.

Such processing is designed to support operational integrity and does not independently determine legal or similarly significant outcomes regarding individuals.

Customers may independently configure workflows, approvals, or AI systems that perform automated processing through the Services.

Customers are responsible for implementing appropriate human review and governance controls for such systems.

12. Privacy Rights

12.1 GDPR, UK GDPR, and Similar Jurisdictions

Subject to applicable law, individuals may have rights to:

  • access personal information;
  • correct inaccurate information;
  • request deletion;
  • restrict or object to processing;
  • receive a portable copy of information;
  • withdraw consent where applicable;
  • lodge complaints with supervisory authorities.

Guardyx responds to verified requests within one month as required by applicable law, subject to extensions permitted under applicable privacy laws.

Where Guardyx acts solely as a processor on behalf of customers, requests relating to Customer Data should generally be directed to the relevant customer.

12.2 California and Other U.S. State Privacy Rights

Depending on applicable law, residents of California and certain U.S. states may have rights to:

  • know categories of personal information collected and disclosed;
  • access personal information;
  • request deletion or correction;
  • obtain portable copies of information;
  • limit certain sensitive personal information processing where applicable;
  • opt out of certain profiling or targeted advertising activities where applicable;
  • not be discriminated against for exercising privacy rights.

Guardyx does not sell Customer Data, share Customer Data for cross-context behavioral advertising, or engage in targeted advertising using Customer Data.

Because Guardyx does not sell or share personal information for cross-context behavioral advertising, Guardyx does not provide a “Do Not Sell or Share My Personal Information” link.

California residents may also request information regarding certain disclosures under California Civil Code Section 1798.83.

Privacy requests may be submitted to privacy@guardyx.ai.

13. Categories of Personal Information Disclosed (California)

CategoryExamplesSources of CollectionBusiness PurposeCategories of RecipientsIllustrative Retention
IdentifiersName, email, account identifiersDirectly from users and customersAccount administration, authenticationService providers, infrastructure vendorsDuration of relationship plus applicable legal retention periods
Commercial InformationSubscription and billing recordsDirectly from customersBilling and account managementPayment providers, finance systemsUp to 7 years
Internet or Network ActivitySession activity, device metadata, telemetryAutomatically collected through the ServicesSecurity, reliability, analyticsInfrastructure and observability vendorsGenerally up to 13 months
Professional InformationEmployer, title, roleDirectly from users or customersAccount administration and salesCRM and support vendorsDuration of relationship plus reasonable archival periods
Sensitive Personal InformationCredentials and authentication informationDirectly from usersSecurity and authenticationIdentity and authentication providersCredentials retained for duration of account relationship; authentication and security logs generally retained up to 13 months unless otherwise required by law

Guardyx uses sensitive personal information only for permitted business purposes and not to infer characteristics about individuals.

14. Children’s Privacy

The Services are intended for business and enterprise use by individuals eighteen (18) years of age or older.

Guardyx does not knowingly collect personal information from individuals under eighteen (18) years of age, and in no event from children under thirteen (13).

Customers may not use the Services in violation of COPPA, GDPR Article 8, or similar children’s privacy laws.

15. Government Requests and Transparency

Guardyx may disclose information where required by law, legal process, or governmental request.

Where legally permitted, Guardyx may:

  • review requests for legal validity;
  • seek to narrow or challenge overbroad requests;
  • notify affected customers;
  • publish transparency reporting regarding governmental requests.

16. Changes to this Privacy Policy

Guardyx may update this Privacy Policy from time to time.

Material changes affecting rights or obligations will generally be communicated through the Services, email, or other reasonable means.

Where required by applicable law, Guardyx will obtain consent or provide additional notice before material changes become effective.

17. Linked Policies and Trust Center

Additional information may be available through:

18. Contact Information

Code Above Lab, Inc.

Operator of Guardyx AI

Privacy Contact: privacy@guardyx.ai

Legal Contact: legal@guardyx.ai

Website: https://guardyx.ai

Where required by applicable law, Guardyx will designate an EU or UK representative and publish corresponding contact details through its Trust Center or legal notices.

See also: Terms of Service · Data Processing Addendum · Acceptable Use Policy · Cookie Policy.