Privacy Policy
Last updated: June 23, 2026
WardenAuth ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use the WardenAuth platform, and describes the rights you have under the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR.
1. Data Controller
The data controller responsible for your personal data is WardenAuth, [registered legal entity name], [registered address]. You can contact us about any privacy matter at privacy@wardenauthz.com.
Where we are required to appoint a representative in the European Economic Area (EEA) under Article 27 GDPR, our representative can be contacted at the same address. Data-protection enquiries can also be sent to dpo@wardenauthz.com.
2. Information We Collect
Account information: Email address, organization name, and password (hashed) when you register.
Usage data: Access evaluation counts, API requests, audit log entries generated by your use of the Service.
Billing information: Billing is processed by Stripe. We store only your Stripe customer ID and subscription status — we never store raw card numbers.
Technical data: IP addresses, user agent strings, and Lambda execution logs for security and debugging purposes.
3. How We Use Your Information and Legal Bases
We only process your personal data where we have a lawful basis to do so under Article 6 GDPR. The bases we rely on are:
- Performance of a contract (Art. 6(1)(b)) — to provide, operate, and maintain the Service, manage your account, and process your subscription.
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, detect and prevent abuse and fraud, debug, and improve the Service. We balance these interests against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — to comply with accounting, tax, and other legal requirements.
- Consent (Art. 6(1)(a)) — where we specifically ask for it, such as optional communications. You may withdraw your consent at any time.
We do not sell your personal data to third parties. We do not use your data to train AI models.
4. Data Storage and Security
Your data is stored in Amazon DynamoDB in the AWS region where your account was provisioned. Data is encrypted at rest and in transit. We use AWS Cognito for authentication, which handles password hashing and MFA.
We implement access controls, audit logging, and the principle of least privilege across our infrastructure. However, no system is 100% secure and we cannot guarantee absolute security.
5. International Data Transfers
Your personal data is stored on Amazon Web Services infrastructure in the AWS region where your account was provisioned. Where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards recognised under the GDPR — principally the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum — supplemented by technical measures such as encryption in transit and at rest. A copy of the relevant safeguards is available on request.
6. Data Retention
We retain your account data for as long as your account is active. Audit logs are retained for 90 days by default. When you delete your account, all associated personal data is purged within 30 days, except where a longer retention period is required to comply with a legal obligation.
7. Sub-processors
We use the following sub-processors to deliver the Service:
- Amazon Web Services (AWS) — infrastructure (DynamoDB, Lambda, Cognito, SES)
- Stripe — payment processing
Each sub-processor is bound by a data processing agreement and appropriate transfer safeguards as required by Articles 28 and 44–49 GDPR.
8. Your Rights Under the GDPR
If you are located in the EEA or the UK, you have the right to:
- Access (Art. 15) — request a copy of your personal data
- Rectification (Art. 16) — correct inaccurate or incomplete data
- Erasure (Art. 17) — request deletion of your data ("right to be forgotten")
- Restriction (Art. 18) — restrict how we process your data in certain circumstances
- Portability (Art. 20) — receive your data in a structured, machine-readable format
- Objection (Art. 21) — object to processing based on our legitimate interests
- Withdraw consent (Art. 7(3)) — withdraw any consent you have given, at any time
To exercise any of these rights, email privacy@wardenauthz.com. We will respond within one month as required by Article 12 GDPR (this period may be extended by up to two further months for complex requests). You also have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your data lawfully.
9. Automated Decision-Making
We do not make decisions that produce legal or similarly significant effects concerning you based solely on automated processing, including profiling, within the meaning of Article 22 GDPR.
10. Cookies
We use session storage (not persistent cookies) strictly to maintain your authentication state. These are essential for the Service to function and do not require consent under the ePrivacy Directive. We do not use tracking cookies or third-party analytics.
11. Children's Privacy
The Service is not directed at children under 16, consistent with Article 8 GDPR. We do not knowingly collect personal information from children. If you believe a child has provided us data, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact
Privacy questions or data requests: privacy@wardenauthz.com