Legal Document

Privacy Policy

Your privacy matters to us. This policy explains how we collect, use, and protect your information.

Last updated: December 1, 2024
Effective: December 1, 2024

1. Introduction

Starkguard AI Governance Platform ("Starkguard," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI governance platform and related services.

By using Starkguard, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

Information You Provide

  • Account Information: Name, email address, company name, job title, and password when you create an account.
  • Organization Data: Information about your organization, including AI systems, risk assessments, compliance data, and governance documentation.
  • Assessment Responses: Your responses to governance assessments, self-assessments, and questionnaires.
  • Payment Information: Billing details processed securely through our payment provider (Stripe).

Information Collected Automatically

  • Usage Data: Information about how you interact with our platform, including features used and pages visited.
  • Device Information: Browser type, operating system, IP address, and device identifiers.
  • Cookies: We use cookies and similar technologies to enhance your experience and analyze usage patterns.

3. How We Use Your Information

We use the information we collect to:

Provide and maintain our AI governance platform
Process assessments and generate governance insights
Send transactional communications and security alerts
Provide customer support and respond to inquiries
Analyze usage patterns to improve our services
Comply with legal obligations and enforce our terms
Prevent fraud and ensure platform security
Personalize your experience on the platform

4. AI Processing and Data Usage

Starkguard uses artificial intelligence to provide features such as risk analysis, compliance insights, and recommendations. When using AI features:

Your assessment data may be processed by AI models to generate insights
We do not use your data to train general-purpose AI models
AI-generated insights enhance your governance program, not replace human judgment
You retain full control over your data and can export or delete it at any time

5. Data Sharing and Disclosure

We do not sell your personal information.

We may share your information with:

  • Service Providers: Third-party vendors who assist in operating our platform (hosting, analytics, payment processing)
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • Legal Requirements: When required by law or to protect our rights and safety
  • With Your Consent: When you explicitly authorize us to share information

6. Data Security

We implement industry-standard security measures to protect your data:

Encryption in Transit
TLS 1.3
Encryption at Rest
AES-256
Compliance
SOC 2 Type II
Access Control
Role-based (RBAC)

We also conduct regular security assessments, penetration testing, and maintain comprehensive backup and disaster recovery procedures.

7. Your Rights and Choices

Depending on your location, you may have the right to:

Access the personal information we hold about you
Correct inaccurate or incomplete information
Delete your personal information
Export your data in a portable format
Object to or restrict certain processing
Withdraw consent where applicable

GDPR (European Users)

We process your data under legal bases including contract performance, legitimate interests, consent, and legal obligations. Our Data Protection Officer can be reached at dpo@guardai.com.

CCPA (California Users)

California residents have the right to know what personal information is collected, request deletion, opt-out of data sales (we do not sell data), and non-discrimination for exercising privacy rights.

Data Retention

We retain your data for as long as your account is active or as needed to provide services. You can request deletion of your data at any time. Certain data may be retained for legal compliance, dispute resolution, or to enforce agreements.

International Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including Standard Contractual Clauses for transfers outside the European Economic Area.

8. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of Starkguard after changes constitutes acceptance of the updated policy.

Children's Privacy

Starkguard is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will delete it promptly.