Privacy Policy
Effective Date: March 16, 2026
1. Introduction
SXGuard ("Company", "we", "us", or "our"), a company incorporated under the laws of Switzerland with its registered office at Gubelstrasse 24, 6300 Zug, Switzerland, is committed to protecting your privacy and personal data.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website at https://www.sxguard.com, use our SaaS platform, mobile applications, and related services (collectively, the "Services").
This Privacy Policy has been drafted in compliance with the Swiss Federal Act on Data Protection (nFADP, in force since September 1, 2023), its implementing ordinance (DPO/VDSG), and the European Union General Data Protection Regulation (EU) 2016/679 "GDPR" to the extent applicable.
2. Data Controller
The data controller responsible for the processing of your personal data is:
SXGuard
Address: Gubelstrasse 24, 6300 Zug, Switzerland
Email: privacy@sxguard.com
Data Protection Officer: dpo@sxguard.com
If you are located in the European Economic Area (EEA) and have questions about the processing of your personal data, you may also contact our Data Protection Officer at the address above.
3. Personal Data We Collect
We collect and process the following categories of personal data depending on how you interact with our Services:
- Category
- Data Types
- Purpose & Legal Basis
- Account Data
- Name, email address, phone number, company name, job title
- Contract performance (Art. 6(1)(b) GDPR); Legitimate interest (Art. 31 nFADP)
- Authentication Data
- Hashed passwords, MFA tokens, session identifiers, login timestamps
- Contract performance; Security of processing (Art. 32 GDPR)
- Payment Data
- Billing address, payment method details (processed by third-party payment processor), transaction history
- Contract performance; Legal obligation (Art. 6(1)(c) GDPR)
- Usage Data
- Features used, session duration, interaction logs, device type, operating system, browser type
- Legitimate interest in service improvement (Art. 6(1)(f) GDPR)
- Technical Data
- IP address, device identifiers, log files, error reports, performance metrics
- Legitimate interest in security and service stability
- Communication Data
- Support tickets, emails, chat transcripts with support team
- Contract performance; Legitimate interest in customer service
3.1 Special Categories of Data
We do not intentionally collect special categories of personal data (such as racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data). If you inadvertently provide such data, we will delete it upon becoming aware, unless processing is required by law.
3.2 Children’s Data
The Services are not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
3.3 Data from Third Parties
We may receive personal data from third parties such as business partners, identity verification providers, public databases, and social media platforms (where you have authorized sharing). We process such data in accordance with this Privacy Policy and applicable law.
4. How We Use Your Data
We process your personal data for the following purposes and on the following legal bases:
- To provide, maintain, and improve the Services (contract performance);
- To create and manage your Account (contract performance);
- To process payments and billing (contract performance; legal obligation);
- To communicate with you regarding the Services, including service announcements, technical notices, and support responses (legitimate interest);
- To personalize your experience and deliver relevant content (legitimate interest);
- To monitor and analyze usage trends and improve service quality (legitimate interest);
- To detect, prevent, and address security incidents, fraud, and technical issues (legitimate interest);
- To comply with legal obligations, regulatory requirements, and lawful requests (legal obligation);
- To enforce our Terms and Conditions and protect our rights (legitimate interest);
- To send marketing communications where you have provided consent (consent).
4.1 Automated Decision-Making
We may use automated processing for security threat detection and fraud prevention. Such processing does not produce legal effects or similarly significant effects on you. If automated decision-making is used in a manner that produces such effects, we will inform you and provide the right to obtain human intervention.
5. Cookies and Tracking Technologies
This website (www.sxguard.com) does not set cookies and does not use analytics, advertising, or other tracking technologies. No consent banner is shown because no consent-requiring cookies or trackers are in use.
5.1 External Media
The map on our contact page is provided by Google Maps and is loaded only after you click “Show map”. When you choose to load it, your IP address is transmitted to Google LLC and Google may set its own cookies; this is subject to Google’s privacy policy. Until you click, no data is sent to Google.
5.2 Future Changes
If we introduce cookies or analytics in the future, we will update this policy and, where required, obtain your consent before any non-essential cookies are set. You may additionally configure your browser to block or delete cookies at any time.
5.3 Do Not Track
Our Services currently do not respond to "Do Not Track" (DNT) browser signals. We will update this policy if we adopt DNT compliance in the future.
6. Data Sharing and Disclosure
We do not sell your personal data. We may share your data with the following categories of recipients:
- Service Providers: Third-party vendors who process data on our behalf (e.g., hosting, payment processing, analytics, customer support). These providers are contractually bound to process data only as instructed and implement appropriate security measures.
- Professional Advisors: Legal, accounting, and compliance advisors under professional confidentiality obligations.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your data may be transferred to the acquiring entity.
- Legal Requirements: Where disclosure is required by law, regulation, court order, or governmental request.
- Safety and Rights: To protect the rights, property, or safety of the Company, our users, or the public.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside of Switzerland and the European Economic Area (EEA). We ensure that such transfers are protected by appropriate safeguards in accordance with Art. 16–17 nFADP and Chapter V of the GDPR, including:
- Transfers to countries recognized by the Swiss Federal Council or the European Commission as providing an adequate level of data protection;
- Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914);
- Binding Corporate Rules (BCRs) where applicable;
- Your explicit consent for specific transfers where no other safeguard applies.
A copy of the relevant safeguards may be obtained by contacting us at privacy@sxguard.com.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. The following table summarizes our retention periods:
- Data Category
- Retention Period
- Justification
- Account Data
- Duration of account + 30 days
- Service provision and data export period
- Payment & Billing Data
- 10 years from transaction date
- Swiss commercial law (Art. 958f CO) and tax obligations
- Usage & Technical Data
- 24 months from collection
- Service improvement and security analysis
- Communication Data
- 36 months from last interaction
- Service quality and dispute resolution
- Log Files
- 90 days (rolling)
- Security monitoring and incident response
When personal data is no longer required, it is securely deleted or anonymized in accordance with our data retention procedures.
9. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, in compliance with Art. 8 nFADP and Art. 32 GDPR. These measures include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256);
- Access controls and role-based permissions;
- Regular security assessments, penetration testing, and vulnerability scanning;
- Multi-factor authentication for privileged access;
- Incident response procedures with notification obligations under Art. 24 nFADP and Art. 33–34 GDPR;
- Employee security awareness training and confidentiality agreements.
No system is completely secure. While we strive to protect your data, we cannot guarantee absolute security. You are encouraged to use strong passwords and protect your Account credentials.
10. Your Rights
Depending on your location and applicable law, you have the following rights regarding your personal data:
10.1 Rights Under Swiss nFADP
- Right of access (Art. 25 nFADP): You may request information about whether and how we process your personal data.
- Right to data portability (Art. 28 nFADP): You may request your data in a commonly used electronic format.
- Right to rectification: You may request correction of inaccurate personal data.
- Right to deletion: You may request erasure of your data, subject to legal retention obligations.
- Right to object: You may object to processing based on legitimate interests.
10.2 Additional Rights Under GDPR (EEA Residents)
- Right to restriction of processing (Art. 18 GDPR);
- Right not to be subject to automated decision-making (Art. 22 GDPR);
- Right to withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3) GDPR);
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
10.3 Exercising Your Rights
To exercise any of the above rights, please contact us at dpo@sxguard.com. We will respond within thirty (30) days. We may request verification of your identity before processing your request. In complex cases, we may extend the response period by an additional sixty (60) days, with prior notification.
10.4 Supervisory Authorities
You have the right to lodge a complaint with the competent data protection authority:
Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch
EEA: The supervisory authority of your Member State of residence.
11. Third-Party Links and Services
The Services may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of such third parties. We encourage you to review their privacy policies before providing any personal data.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. Material changes will be communicated via the Services or by email at least thirty (30) days before taking effect. The "Effective Date" at the top of this policy indicates the date of the latest revision.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us at:
SXGuard
Attn: Data Protection Officer
Address: Gubelstrasse 24, 6300 Zug, Switzerland
Email: dpo@sxguard.com
General Inquiries: privacy@sxguard.com
Website: https://www.sxguard.com
© 2026 SXGuard. All rights reserved.