Privacy Policy
Your trust and your data aren't for sale, and never will be. Here's exactly what we hold, why, and for how long, for our members and for our own team.
TL;DR
- We do not, and never will, sell your data.
- We only collect what we need to run your membership and our services.
- When your membership ends, we automatically delete your data within one month.
- We only share the minimum necessary with trusted suppliers (listed below).
- When you ask us to get your data deleted or restricted, we share your details with the companies we contact, and make clear they may only use them for that purpose.
- If you ask us to stop marketing contact, we share your details with Royal Mail, the DMA and the Preference Services, only for that purpose.
- You're always in control: you can ask to see, correct or delete your data at any time.
Our promise
We do not, and will never, sell your personal data. Not to advertisers. Not to marketers. Not to anyone.
We treat every piece of personal information you share with us as a responsibility and a trust. Whether you're a member, an employee or a partner, your information is used only for the purposes you've agreed to, and nothing more.
Who we are
guardID Limited, registered in England & Wales, is the data controller for the personal data described here. You can contact our Data Protection Officer at dpo@guardid.app.
What we collect, and why
- Membership details (name, email, and the addresses, phone numbers, previous names and other identifiers you ask us to protect): to find and remove your data, and to run your requests. Lawful basis: performance of our contract with you.
- Account and billing records (plan, payment transaction history): to take payment and meet our accounting and tax obligations. Lawful basis: contract and legal obligation.
- Messages you send us (for example, through our contact form or by email): to reply to you. Lawful basis: legitimate interests in responding to enquiries.
- Basic technical data when you visit this website (IP address, browser and device type, pages requested): to deliver and secure the site. Lawful basis: legitimate interests in running a secure website. See our Cookie Policy for the little we store in your browser.
If you add under-18s to a Family plan, we process their details only to protect them, on the authority of their parent or guardian. We do not make any decisions about you based solely on automated processing.
Who we share data with
We only share the minimum data necessary with trusted suppliers who help us deliver our services. We carry out due diligence on every supplier, put strong data protection agreements in place, and require them to meet the same high standards we hold ourselves to. We also take every reasonable technical and organisational step to lock down and protect your data.
Our suppliers
- Cloudflare: hosts and secures this website. Processes technical data (such as your IP address) for every request.
- Google Fonts: serves the typeface used on this website. Your browser requests the font files from Google, which receives your IP address and browser details; no cookies are involved.
- FormSubmit: delivers messages sent through our contact form to our inbox. Receives the name, email address and message you enter.
Some of these suppliers may process data outside the UK. Where they do, we rely on UK adequacy regulations or appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum.
Data shared to carry out your requests
As a member, you're asking us to get your data deleted, restrict its processing, or object to its use. To do that, we share your details with the companies and organisations involved, solely to carry out that request, and we clearly instruct them never to use that data for anything else.
If you ask us to suppress marketing contact, we may also share relevant contact details with Royal Mail, the Data & Marketing Association (DMA), and the Mailing, Telephone or Fax Preference Services, again only to action those specific requests and prevent unwanted contact.
How long we keep your data
When you stop being a member, we automatically delete all your membership data within one month of your final subscription day, securely and in line with our data retention policy. The only exception is basic records such as your payment transaction history, which we keep for financial reporting as the law requires, never for marketing or sale.
If you apply for a role with us and are unsuccessful, we delete your details within 2 months, unless you ask us to keep them for future opportunities.
Your rights
You have the right to:
- access the data we hold about you;
- ask us to correct or delete it;
- restrict or object to its use;
- receive a copy of data you gave us in a portable format; and
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, email our Data Protection Officer at dpo@guardid.app.
Contact and complaints
If you have any questions or concerns about how we handle your data, contact our Data Protection Officer at dpo@guardid.app. If you're not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
For past, current and future team members, our employee privacy policy is published here too.
In summary
We exist to serve our members, not to trade in their information. Your trust is not a product; it's a privilege, and we intend to keep it that way.
Why this is public. We believe every company should make all of its privacy policies known, not just the one its customers see. How an organisation treats its own people's data says a lot about how it will treat yours. So we publish our employee privacy policy openly, right here, for anyone to read.
TL;DR
We respect your privacy and protect your data like it's our own.
- We only collect personal data we genuinely need to employ and pay you.
- We never sell or misuse your personal information.
- We keep your personal data only as long as the law or genuine business needs require, then delete it securely.
- The work you create with us (documents, code, designs and so on) belongs to guardID and may be kept indefinitely as work product.
- We share only what's necessary with trusted payroll, benefits and legal partners.
- You can always ask to access, correct or delete your personal data.
Applies to: all employees, workers and contractors of guardID Limited, which is the data controller for this data.
Our commitment
We respect your privacy and the personal information you share with us as part of your work. We're committed to handling your data fairly, securely and transparently, and to keeping only what we genuinely need for as long as we need it.
What we collect
During your time working with us, we collect and store the information needed to manage your employment, including:
- contact details (name, address, phone, email);
- identification and right-to-work information;
- payroll and bank details;
- performance, training and attendance records;
- emergency contact information; and
- any other data required by law or necessary for your role.
We will never collect more data than we need to meet our legal, contractual or operational responsibilities.
How we use your data
We use your personal information to:
- manage your employment and payroll;
- meet legal and regulatory requirements;
- communicate with you as part of your work;
- provide benefits, training and support; and
- maintain a safe, fair and compliant workplace.
We rely on the contract between us, our legal obligations as an employer, and our legitimate interests in running the business. Your personal data will never be sold or shared for marketing.
How long we keep it
We keep personal data about you only as long as necessary: usually for the duration of your employment and a limited period afterwards, to meet legal, tax or contractual obligations. When that period ends, your personal data is securely deleted.
However, any content, materials or work you create in the course of your employment, including documents, designs, written materials, code, creative works or other outputs, is company work product. It remains the property of guardID and may be kept indefinitely as part of our business records and intellectual property.
Who we share it with
We may share limited information with:
- payroll and benefits providers;
- pension and insurance providers;
- IT and system administrators; and
- legal and regulatory authorities, when the law requires it.
We always share the minimum necessary and make sure every third party handles your data securely and lawfully.
Your rights
You have the right to:
- access the personal data we hold about you;
- ask us to correct or delete it; and
- restrict or object to its use, where the law allows.
To exercise these rights, email our Data Protection Officer at dpo@guardid.app, or speak to your manager or a director. If you believe your data has been mishandled, you can also contact the Information Commissioner's Office (ICO) at ico.org.uk.
In summary
Your personal data is yours, and we protect it as such. We'll only keep what we must, for as long as we must. The work you create with us, however, is part of our shared legacy, and remains with guardID as part of our professional record.