Last updated: 18 July 2026
This Privacy Policy applies to the website aigovernance.ae ("Site") and the GUARD GRC platform at guard.aigovernance.ae ("Platform"), both operated by GUARD GRC L.L.C-FZ, registered in Meydan Free Zone, Dubai, United Arab Emirates.
We build governance software, so we hold ourselves to the standard we help our clients meet. This policy states plainly what we collect, where it is stored, which providers process it, and what rights you have.
GUARD GRC L.L.C-FZ is the controller for personal data we collect about you directly: your account details, website enquiries, and marketing preferences.
For content your organisation places inside its Platform workspace (uploaded documents, assessment answers, business profiles), your organisation is the controller and we act as processor on its instructions, under our Data Processing Addendum. If you have a question about content in your employer's workspace, your first point of contact is your employer.
For any data protection enquiry, contact: support@guardgrc.com
| Purpose | Legal basis |
|---|---|
| Deliver Platform services and provide support | Performance of contract |
| Generate governance outputs (policies, assessments, reports) from your inputs | Performance of contract |
| Process transactions and manage Subscriptions | Performance of contract |
| Send service communications, security notices, and maintenance updates | Legitimate interest |
| Send marketing communications and newsletters | Your consent (opt out at any time) |
| Analyse Site usage to improve our services (anonymised statistics) | Legitimate interest, with opt-out at any time |
| Maintain security, prevent abuse, and keep audit records | Legitimate interest |
| Accounting, tax records, and legal compliance | Legal obligation |
The Platform uses AI models to generate governance outputs. Because we ask our clients to demand this level of transparency from their vendors, here is ours:
Clients who require zero data retention arrangements with our AI providers can reach us via our contact page, and we will arrange this with the provider.
Platform data, including your account and Customer Content, is stored on a dedicated private server in the United Kingdom operated by Hostinger. This is not shared cloud infrastructure; the full application stack, database, and file storage run on hardware dedicated to GUARD.
Some processing involves transfers outside the UAE and the UK: AI generation (Anthropic, US), search embeddings (OpenAI, US), and email delivery (Google, US/EU). We put contractual safeguards in place with each provider consistent with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for DIFC-based clients, the DIFC Data Protection Law No. 5 of 2020. The UK is recognised as an adequate jurisdiction by the DIFC Commissioner of Data Protection.
We do not sell personal data. We share it only with the service providers that run the Platform and the Site, under data processing terms and only for the purposes stated. The full list, naming each provider, what it receives, and where it processes, is maintained in one place: aigovernance.ae/sub-processors. We may also disclose data where required by law or to protect our legal rights.
| Data | Retention |
|---|---|
| Account data | While your account is active; deleted within 12 months of termination |
| Customer Content | While your account is active; deleted within 90 days of account termination |
| Generated documents and audit records in your workspace | Same as Customer Content |
| Transaction and tax records | 7 years, as required by law |
| Marketing data | Until you withdraw consent |
| Security logs | Up to 12 months |
You may request an export of your Customer Content in a structured, commonly used format at any time while your account is active, and within 30 days of termination.
Security measures include tenant isolation enforced at the database layer through row-level security, encryption in transit (TLS 1.2 or higher), one-way password hashing, a default-deny host firewall, automated backups, a strict Content Security Policy, and an append-only audit trail for governance actions. Administrative interfaces do not expose customer governance content; system-level access is limited to operating the service, including assembling the AI requests you initiate and fulfilling export and deletion requests, and is confidentiality-bound and logged. Our full security posture is described in the GUARD Data Handling and Security Overview, available on request. No system is completely secure, and we cannot guarantee absolute security, but transparency about our measures is part of how we operate.
Regardless of your location, you can:
For clients in the UAE, we apply the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). For DIFC-based clients, we comply with the DIFC Data Protection Law No. 5 of 2020. Where the GDPR applies to you, these rights operate as set out there.
To exercise any right, email support@guardgrc.com. We respond within 30 days. If you are unsatisfied with our response, you may raise the matter with the UAE Data Office or, for DIFC matters, the DIFC Commissioner of Data Protection.
The Site and Platform are intended for business users aged 18 or over. We do not knowingly collect data from children.
We may update this Privacy Policy periodically. Material changes will be notified by email or Platform notification. The "Last updated" date at the top identifies the current policy.
GUARD GRC L.L.C-FZ
Meydan Free Zone, Dubai, United Arab Emirates
Email: support@guardgrc.com
Questions about this policy? Get in touch