Legal

GDPR Compliance

How Guardian Gaze complies with the EU General Data Protection Regulation and protects the rights of EU/EEA users.

1. Our Commitment

RedSecLabs is committed to GDPR compliance. Guardian Gaze was designed with a privacy-first architecture and minimal data collection as the default. We process personal data only where necessary and with a valid legal basis.

2. Legal Basis for Processing

We process personal data under the following legal bases:

  • Contract performance: To deliver the security scanning service you signed up for
  • Legitimate interest: To improve our detection capabilities and protect users from threats
  • Consent: For optional features like AI scanning, marketing emails, and analytics

3. Your Rights Under GDPR

As an EU/EEA data subject, you have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a machine-readable format
  • Restriction: Restrict processing of your data in certain circumstances
  • Objection: Object to processing based on legitimate interest
  • Withdraw consent: Withdraw consent at any time without affecting prior processing

To exercise any of these rights, contactemail protected. We will respond within 30 days.

4. Data Processing Agreements

We maintain Data Processing Agreements (DPAs) with all sub-processors, including Anthropic (AI analysis) and our hosting providers. DPAs are available upon request.

5. International Transfers

Data may be transferred outside the EU/EEA for processing (e.g., AI analysis via US-based Anthropic API). Such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.

6. Data Protection Officer

For GDPR enquiries, contact our Data Protection team:email protected

You also have the right to lodge a complaint with your local Data Protection Authority.