Legal

Privacy Notice

How TerraSecure handles personal data across the Guardian platform and website.

Last updated 17 August 2026

1. Who we are

TerraSecure operates Guardian, a security testing and vulnerability management platform. TerraSecure is the data controller for personal data described in this notice. Contact us at privacy@terrasecure.co.

Where you use Guardian as an employee of a customer organization, that organization controls the security data in its workspace and TerraSecure acts as processor for that content.

2. Data we collect and why

  • Account data — name, work email, login credentials, organization and role. Used to create and secure your account and provide the service. Legal basis: performance of a contract.
  • Service content — assets you register, scan configurations, findings, remediation records, compliance evidence and uploaded files. Used to deliver the platform. Legal basis: performance of a contract.
  • Endpoint agent telemetry — hostname, OS and patch level, installed software versions, disk encryption, firewall and screen-lock status, device identifiers. Used to produce security posture reporting. Legal basis: legitimate interests of the customer organization in securing its estate.
  • Usage and technical data — IP address, device and browser information, audit logs, page and feature usage. Used for security, fraud prevention, troubleshooting and product improvement. Legal basis: legitimate interests.
  • Support and enquiry data — messages, demo requests and support cases. Used to respond to you. Legal basis: legitimate interests or steps prior to a contract.
  • Marketing data — contact details where you opt in. Legal basis: consent, withdrawable at any time.

3. Who we share data with

  • Service providers and subprocessors that host our infrastructure, run our database and authentication, send email and provide support tooling.
  • Our payment processor, for subscription payments, billing, tax calculation and invoicing. Card details are handled by the processor, not by TerraSecure.
  • Professional advisers such as legal and accounting firms.
  • Authorities or regulators where required by law or to defend legal claims.

We do not sell personal data.

4. International transfers

Our providers may process data outside your country, including outside the UK and EEA. Where that happens we rely on adequacy decisions or Standard Contractual Clauses together with appropriate technical safeguards.

5. Retention

Account and workspace data is retained while your subscription is active and for up to 30 days after termination, after which it is deleted or anonymised. Audit logs and security records are retained for up to 12 months, and billing records for as long as tax and accounting law requires.

6. Your rights

Subject to applicable law you may request access to your personal data, correction, erasure, restriction of processing, portability, and object to processing based on legitimate interests. You may withdraw consent at any time. We respond within one month. You also have the right to complain to your data protection supervisory authority.

To exercise any right, email privacy@terrasecure.co.

7. Security

We apply appropriate technical and organisational measures, including encryption in transit and at rest, tenant isolation enforced at the database layer, role-based access control, optional multi-factor authentication and audit logging of privileged actions.

8. Cookies

We use strictly necessary cookies for authentication, session management and security; these cannot be disabled without breaking the service. Where we use analytics cookies to understand product usage, they are used only in aggregate. You can manage or clear cookies in your browser settings at any time.

9. Changes

We will update this notice as our service changes and will post the revised version here with a new date. Material changes will be notified in-app or by email.