Legal
Guardyx AI Privacy Policy
Version 2.1
Effective May 14, 2026 · Last updated May 14, 2026
This Privacy Policy describes how Code Above Lab, Inc. d/b/a Guardyx AI (“Guardyx,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information in connection with the Guardyx AI platform, APIs, SDKs, hosted services, customer portal, integrations, websites, and related services (collectively, the “Services”).
This Privacy Policy applies to information Guardyx processes as a controller under applicable privacy laws.
Where Guardyx processes Customer Data on behalf of customers through the Services, Guardyx generally acts as a processor or service provider under applicable privacy laws, and such processing is governed by the applicable customer agreement and Data Processing Addendum (“DPA”).
Capitalized terms not defined in this Privacy Policy have the meanings set forth in the Guardyx AI Terms of Service.
Contents
- Scope and Roles
- Categories of Information We Collect
- AI Model Providers and Third-Party Services
- Human Review and Access Controls
- How We Use Information
- AI and Machine Learning Restrictions
- How We Share Information
- International Data Transfers
- Data Retention
- Security
- Automated Decision-Making
- Privacy Rights
- Categories of Personal Information Disclosed (California)
- Children’s Privacy
- Government Requests and Transparency
- Changes to this Privacy Policy
- Linked Policies and Trust Center
- Contact Information
1. Scope and Roles
1.1 Scope
This Privacy Policy applies to:
- visitors to our websites;
- prospective customers;
- customer administrators and Authorized Users;
- individuals interacting with our Services;
- event participants;
- support and sales communications.
This Privacy Policy does not apply to:
- Customer Data processed solely on behalf of customers under the DPA;
- third-party services not controlled by Guardyx.
1.2 Controller and Processor Roles
Guardyx acts as a controller for:
- account registration information;
- billing and subscription information;
- website analytics and marketing data;
- business contact information;
- support and sales communications;
- event registration and participation information;
- security and fraud-prevention processing;
- operational telemetry relating to operation of the Services.
Guardyx acts as a processor or service provider for Customer Data processed through the Services, including:
- prompts;
- tool payloads and responses;
- workflow content;
- approval snapshots;
- execution events;
- audit records containing customer workflow content.
Guardyx may independently determine the purposes and means of limited processing required for security, fraud prevention, legal compliance, or operational integrity as permitted under applicable law and the DPA.
The applicable customer agreement and DPA govern Guardyx’s processing of Customer Data.
The descriptions of Customer Data processing in this Privacy Policy are provided for transparency and informational purposes only and do not modify the DPA or customer agreements.
2. Categories of Information We Collect
2.1 Information You Provide
We may collect:
- name;
- employer and role information;
- business contact information;
- account credentials;
- billing and payment information;
- communications and support requests;
- event registrations and marketing preferences.
Account credentials and authentication information may constitute sensitive personal information under certain laws.
2.2 Operational Service Metadata
Guardyx may collect operational metadata relating to the operation, security, reliability, and administration of the Services, including:
- authentication and session activity;
- API usage metadata;
- workflow execution metadata;
- approval workflow event metadata;
- infrastructure telemetry;
- device and browser information;
- service reliability metrics;
- fraud and abuse-detection signals;
- IP address and approximate geolocation information;
- behavioral security and authentication indicators;
- metering and quota usage records.
Operational metadata generally does not include the substantive content of prompts, tool payloads, approval snapshots, or workflow content unless necessary for support, security, abuse prevention, legal compliance, or customer-authorized troubleshooting.
2.3 Customer Data and AI Workflow Content
Customers may process Customer Data through the Services, including:
- prompts and outputs;
- tool requests and responses;
- workflow content;
- approval snapshots;
- audit logs;
- telemetry associated with workflow execution;
- execution events and governance records.
Guardyx processes such Customer Data as a processor or service provider on behalf of customers in accordance with the DPA and customer agreements.
2.4 Cookies and Similar Technologies
Guardyx and its service providers may use cookies, pixels, local storage, SDKs, and similar technologies to:
- authenticate users;
- secure the Services;
- remember preferences;
- analyze traffic and engagement;
- monitor performance and reliability;
- improve user experience.
Users may manage cookie preferences through browser settings or available consent mechanisms. See the Cookie Policy for details.
3. AI Model Providers and Third-Party Services
The Services may integrate with or route requests to third-party services, including:
- cloud infrastructure providers;
- AI model providers;
- observability and telemetry vendors;
- authentication providers;
- payment processors;
- customer support providers;
- security and monitoring vendors.
Where configured by customers, prompts, tool payloads, workflow content, or outputs may be transmitted to third-party AI model providers or integration partners necessary to provide the Services.
Depending on the Services configuration, customers may be able to:
- select among supported AI model providers;
- configure retention or logging settings;
- enable reduced-retention or zero-retention modes where supported;
- restrict routing of Customer Data to specific providers or regions.
Guardyx maintains contractual and technical safeguards intended to limit unauthorized use of Customer Data by subprocessors and AI model providers.
In particular, Guardyx maintains contractual protections intended to prohibit unauthorized use of Customer Data by subprocessors and AI model providers for model training purposes except as expressly authorized by customers.
Additional information regarding subprocessors is available through Guardyx’s Trust Center and DPA.
4. Human Review and Access Controls
Authorized Guardyx personnel may access Customer Data or operational metadata where reasonably necessary to:
- provide customer support;
- investigate security incidents;
- detect abuse or fraud;
- maintain reliability and operational integrity;
- comply with legal obligations;
- troubleshoot customer-authorized technical issues.
Access to Customer Data is restricted using least-privilege access controls, logging, reviewer authorization controls, and confidentiality obligations.
Guardyx does not use Customer Data to train AI models except as expressly permitted under the DPA or other written agreement.
5. How We Use Information
5.1 Processing Purposes and Legal Bases
| Purpose | Categories of Information | Legal Basis | Illustrative Retention |
|---|---|---|---|
| Provide and operate the Services | Account data, operational metadata | Contract performance | Duration of relationship plus applicable legal retention periods |
| Authentication and account security | Credentials, session data, telemetry | Legitimate interests; legal obligations | Generally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements |
| Billing and subscription management | Billing and payment information | Contract performance; legal obligations | Up to 7 years |
| Fraud prevention and abuse detection | Operational metadata, telemetry, security events | Legitimate interests | Generally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements |
| Customer support and troubleshooting | Account information, support communications, customer-authorized workflow data | Contract performance; legitimate interests | Duration of support relationship plus reasonable archival periods |
| Security monitoring and incident response | Telemetry, logs, operational metadata | Legitimate interests; legal obligations | Generally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements |
| Product reliability and operational analytics | Aggregated or de-identified operational data | Legitimate interests | De-identified retention periods vary by operational need |
| Marketing communications | Contact information and preferences | Consent or legitimate interests where permitted | Until opt-out or withdrawal of consent |
| Compliance with legal obligations | Relevant account, operational, or transactional information | Legal obligations | As required by applicable law |
Users may opt out of marketing communications using unsubscribe mechanisms included in communications or by contacting Guardyx.
6. AI and Machine Learning Restrictions
Unless expressly agreed otherwise in writing:
- Guardyx does not use Customer Data to train foundation models or general-purpose AI models;
- Guardyx does not sell Customer Data;
- Guardyx does not share Customer Data for cross-context behavioral advertising.
Aggregated or de-identified data will not be used to train generative AI models, foundation models, or models intended to learn from or reproduce customer workflow content derived from Customer prompts, tool payloads, approval snapshots, or workflow content.
The foregoing does not restrict Guardyx’s use of aggregated or de-identified operational signals for:
- operational security;
- fraud and abuse prevention;
- reliability engineering;
- anomaly detection;
- operational analytics.
For purposes of this Privacy Policy, “aggregated or de-identified” means information that:
- cannot reasonably identify an individual or customer;
- is not reasonably linkable to a specific individual or customer;
- is subject to technical, administrative, and contractual measures designed to prevent re-identification.
8. International Data Transfers
Guardyx may process information in the United States and other jurisdictions where Guardyx or its subprocessors operate.
Where required under applicable law, Guardyx implements safeguards for international data transfers, including:
- the EU Standard Contractual Clauses (including applicable Module 2 and Module 3 transfers);
- the UK International Data Transfer Addendum or UK transfer mechanisms;
- transfer impact assessments where appropriate;
- supplementary technical and organizational safeguards.
Additional details are provided in the DPA.
9. Data Retention
Guardyx retains information for periods reasonably necessary to:
- provide the Services;
- maintain security and operational integrity;
- comply with legal obligations;
- resolve disputes;
- enforce agreements.
Illustrative retention periods may include:
| Category | Typical Retention Period |
|---|---|
| Account and subscription information | Duration of account relationship plus applicable legal retention periods |
| Billing and transaction records | Up to 7 years |
| Security and operational logs | Generally up to 13 months unless extended for investigations, customer-configured retention settings, legal obligations, or documented security requirements |
| Backup systems | Generally not more than 90 days unless extended due to disaster recovery procedures, legal obligations, or active security investigations |
| Marketing preferences | Until withdrawal of consent or opt-out |
Customer Data retention is governed by the applicable customer agreement and DPA.
10. Security
Guardyx maintains industry-standard administrative, technical, and organizational safeguards designed to protect information.
Such safeguards may include:
- encryption in transit and at rest;
- tenant-aware logical isolation and access controls;
- least-privilege access controls;
- audit logging and telemetry;
- monitoring and incident response procedures;
- vulnerability management practices;
- reviewer access controls for approval workflows.
Additional security information may be available through Guardyx’s Trust Center.
No system can be guaranteed to be completely secure.
11. Automated Decision-Making
Guardyx does not use Customer Data to make solely automated decisions that produce legal or similarly significant effects regarding individuals.
Guardyx may use automated systems for security monitoring, fraud detection, abuse prevention, anomaly detection, operational analytics, or reliability engineering.
Such processing may include automated analysis of authentication activity, telemetry, or operational behavior patterns to identify suspected abuse, fraud, policy violations, or security risks.
Such processing is designed to support operational integrity and does not independently determine legal or similarly significant outcomes regarding individuals.
Customers may independently configure workflows, approvals, or AI systems that perform automated processing through the Services.
Customers are responsible for implementing appropriate human review and governance controls for such systems.
12. Privacy Rights
12.1 GDPR, UK GDPR, and Similar Jurisdictions
Subject to applicable law, individuals may have rights to:
- access personal information;
- correct inaccurate information;
- request deletion;
- restrict or object to processing;
- receive a portable copy of information;
- withdraw consent where applicable;
- lodge complaints with supervisory authorities.
Guardyx responds to verified requests within one month as required by applicable law, subject to extensions permitted under applicable privacy laws.
Where Guardyx acts solely as a processor on behalf of customers, requests relating to Customer Data should generally be directed to the relevant customer.
12.2 California and Other U.S. State Privacy Rights
Depending on applicable law, residents of California and certain U.S. states may have rights to:
- know categories of personal information collected and disclosed;
- access personal information;
- request deletion or correction;
- obtain portable copies of information;
- limit certain sensitive personal information processing where applicable;
- opt out of certain profiling or targeted advertising activities where applicable;
- not be discriminated against for exercising privacy rights.
Guardyx does not sell Customer Data, share Customer Data for cross-context behavioral advertising, or engage in targeted advertising using Customer Data.
Because Guardyx does not sell or share personal information for cross-context behavioral advertising, Guardyx does not provide a “Do Not Sell or Share My Personal Information” link.
California residents may also request information regarding certain disclosures under California Civil Code Section 1798.83.
Privacy requests may be submitted to privacy@guardyx.ai.
13. Categories of Personal Information Disclosed (California)
| Category | Examples | Sources of Collection | Business Purpose | Categories of Recipients | Illustrative Retention |
|---|---|---|---|---|---|
| Identifiers | Name, email, account identifiers | Directly from users and customers | Account administration, authentication | Service providers, infrastructure vendors | Duration of relationship plus applicable legal retention periods |
| Commercial Information | Subscription and billing records | Directly from customers | Billing and account management | Payment providers, finance systems | Up to 7 years |
| Internet or Network Activity | Session activity, device metadata, telemetry | Automatically collected through the Services | Security, reliability, analytics | Infrastructure and observability vendors | Generally up to 13 months |
| Professional Information | Employer, title, role | Directly from users or customers | Account administration and sales | CRM and support vendors | Duration of relationship plus reasonable archival periods |
| Sensitive Personal Information | Credentials and authentication information | Directly from users | Security and authentication | Identity and authentication providers | Credentials retained for duration of account relationship; authentication and security logs generally retained up to 13 months unless otherwise required by law |
Guardyx uses sensitive personal information only for permitted business purposes and not to infer characteristics about individuals.
14. Children’s Privacy
The Services are intended for business and enterprise use by individuals eighteen (18) years of age or older.
Guardyx does not knowingly collect personal information from individuals under eighteen (18) years of age, and in no event from children under thirteen (13).
Customers may not use the Services in violation of COPPA, GDPR Article 8, or similar children’s privacy laws.
15. Government Requests and Transparency
Guardyx may disclose information where required by law, legal process, or governmental request.
Where legally permitted, Guardyx may:
- review requests for legal validity;
- seek to narrow or challenge overbroad requests;
- notify affected customers;
- publish transparency reporting regarding governmental requests.
16. Changes to this Privacy Policy
Guardyx may update this Privacy Policy from time to time.
Material changes affecting rights or obligations will generally be communicated through the Services, email, or other reasonable means.
Where required by applicable law, Guardyx will obtain consent or provide additional notice before material changes become effective.
17. Linked Policies and Trust Center
Additional information may be available through:
- Guardyx AI Terms of Service;
- Guardyx AI Data Processing Addendum (DPA);
- Guardyx AI Acceptable Use Policy (AUP);
- Guardyx Security Addendum;
- Guardyx Trust Center;
- Guardyx Subprocessor List.
18. Contact Information
Code Above Lab, Inc.
Operator of Guardyx AI
Privacy Contact: privacy@guardyx.ai
Legal Contact: legal@guardyx.ai
Website: https://guardyx.ai
Where required by applicable law, Guardyx will designate an EU or UK representative and publish corresponding contact details through its Trust Center or legal notices.
See also: Terms of Service · Data Processing Addendum · Acceptable Use Policy · Cookie Policy.