Guard.ch
ProductIntegrationsPricing
Home/Legal/Privacy Policy

Privacy Policy

How Guard.ch collects, uses, retains, and protects personal data. Questions about your data? Email us.

Effective May 26, 2026 · Last updated September 23, 2026

On this page

  1. 1. Introduction and scope
  2. 2. Controller and contact
  3. 3. EU and UK representatives
  4. 4. Data we collect
  5. 5. Purposes and legal bases
  6. 6. Investigation content and third-party data subjects
  7. 7. Retention
  8. 8. Recipients and subprocessors
  9. 9. International transfers
  10. 10. Your rights
  11. 11. US state privacy rights
  12. 12. Other jurisdictions
  13. 13. Children
  14. 14. Security
  15. 15. Cookies
  16. 16. Automated analysis, verdicts, and automated decision-making
  17. 17. Breach notification
  18. 18. Changes to this policy
  19. 19. Governing law and dispute resolution

1. Introduction and scope

Guard.ch is a website investigation service operated by Zesiger.net. An investigation begins when you submit a target URL. We open it in an isolated browser we host and make the content available to you live while the investigation runs.

The browser captures network requests, console output, cookies set by the visited site, TLS certificate details, whois and IP lookups, and the URL itself. We use these signals to generate an automated analysis and verdict.

This Privacy Policy explains how we process personal data when you visit https://guard.ch, register an account, pay for the Service, run investigations, or contact us. It is written to satisfy the information duties of the revised Swiss Federal Act on Data Protection (FADP, in force since 1 September 2023, Articles 19 to 21), Article 13 of the EU General Data Protection Regulation (GDPR), and the UK GDPR. Section 11 adds disclosures for residents of US states with consumer privacy laws, and Section 12 covers other jurisdictions.

One account, two services. Guard.ch and browser.lol are operated by the same entity and share one account system, one API, and one database. A single account serves both services: the account, authentication, session-token, and billing records described in this Policy are stored once and are used for whichever of the two services you use. This Policy describes processing in connection with Guard.ch; processing specific to browser.lol features is described in the privacy policy published on browser.lol.

Who is responsible for which data. We are the controller for accounts, billing, security logs and support data. We process submitted URLs and investigation content on your behalf as a processor. For limited purposes such as platform security, abuse prevention and legal compliance, we act as an independent controller. Section 6 explains these roles in detail.

2. Controller and contact

The entity responsible for the processing of personal data described in this Policy (the "Controller") is:

Controller
Zesiger.net (registered name), trading as Guard.ch, Switzerland
Legal representative
Janis Zesiger
Privacy contact
[email protected]

We have not appointed a data protection officer because none of the thresholds that would require one applies to our processing. You can reach us at [email protected] for all data protection matters. The full statutory disclosure, including the registered address, the commercial-register identifiers, and the competent supervisory authority, is published in the Legal notice; postal mail reaches us at the address listed there.

Switzerland is recognised by the European Commission as providing an adequate level of data protection (Commission Decision 2000/518/EC, maintained under the GDPR), and by the United Kingdom under its adequacy regulations. Personal data transferred from the EEA or the UK to our Swiss establishment does not require additional transfer safeguards.

3. EU and UK representatives

Under Article 27 GDPR and Article 27 UK GDPR, controllers established outside the EU or the UK that offer services to data subjects there may be required to designate a local representative in writing, unless a narrow exception applies. Guard.ch has not currently appointed an Article 27 representative in the EU or in the UK.

EU representative
None currently appointed.
UK representative
None currently appointed.
Direct contact
[email protected]

Disclosure. EU/EEA and UK data subjects and supervisory authorities can reach us directly at [email protected] for all data protection matters. If we appoint a representative, we will publish the representative's name, address, and contact details in this Section without delay.

4. Data we collect

We practice data minimisation: we collect only what we need to deliver the Service, comply with the law, bill correctly, and keep the platform secure.

4.1 Account data

  • Email address, first and last name where provided, country, verification status, newsletter preference, default browser language and keyboard layout, workspace membership, workspace role metadata, and subscription and feature access details.
  • Password hash (bcrypt) when you use email-and-password sign-in.
  • Authentication factors: WebAuthn passkey credential IDs, public keys, authenticator metadata, transports and labels; OAuth or SSO identifiers returned by Microsoft Azure / Entra ID or workspace SSO when you use those sign-in methods; Google profile data used to provision or look up the account when you choose Google sign-in.
  • Session records: opaque session or API-token references, issuing IP address, user-agent / browser metadata, active status, and expiry timestamps.

4.2 Payment metadata

  • Plan, billing cycle, cycle start, plan expiry, subscription or payment status, workspace billing customer ID, and order/payment references.
  • Payment processor references such as customer, checkout, subscription, refund, dispute, or portal identifiers at Stripe, where they apply.
  • Billing name, billing address, VAT or tax identifiers, and invoice data where you provide them through a payment provider, an order form, or an invoice workflow. We do not see or store full card numbers; card data subject to payment security requirements is handled by the payment processor.

4.3 Investigation content

Guard.ch shows you what a website does during an investigation. When you submit a URL, we open it in an isolated browser and show you the page and observations live. The analysis also covers URLs the browser reaches during the investigation, including popups, redirects and embedded tracker frames. The submitted URL is only the starting point. An investigation shows:

  • What the visited site renders on screen, streamed to you live during the investigation (no video or audio recording is stored).
  • Network traffic: request and response URLs, methods, headers, status codes, remote IP addresses, tracker classification, and the bodies of textual requests and responses (JSON, XML, forms, plain text, WebSocket text frames, Server-Sent Events), subject to the caps below.
  • Cookies set by any origin the page contacts, and localStorage / sessionStorage changes, with their values.
  • Page intelligence: console output, JavaScript errors, technology detection, TLS certificate details, a whois record for the investigated domain, and IP geolocation and ASN data for the hosts the page contacted.
  • The automated analysis output: risk scores, classifications, and, where an AI-assisted summarisation feature is used, the generated summary and verdict text. Content submitted to an AI feature is processed by the AI summarisation subprocessor listed in the Subprocessor Register; a separate provider analyses only aggregated operational logs and never receives investigation content. The register also sets out each provider’s retention and model-training terms. See Section 16 on what the verdict is and is not.

The following limits apply to data captured by live analysis during an investigation:

  • Interactions are not recorded. The analysis does not retain clicks, keystrokes, focus changes, scrolling or values entered into page fields as interaction events.
  • Character caps clip general string fields (default 5,000 characters), request bodies and WebSocket / Server-Sent Events messages (default 8,192), and response bodies held in memory (default 32,768). Very long lists (for example network requests or console output) keep the most recent entries once a documented size is reached. The original length is preserved and any truncation is flagged in the product.
  • Binary bodies are skipped. Images, fonts, audio, video, PDFs, WebAssembly, archives, and other binary payloads are never held at all.
  • Automatic session end. Investigations end automatically after a period with nobody connected to them and at a maximum session duration; the applicable time limits are shown in the product. When an investigation ends, its live evidence disappears with it, and you can end an investigation early from the dashboard at any time.

Beyond these limits, an investigation shows content as observed. This description forms part of your instruction to us under Article 28 GDPR. Section 6.3 explains how we handle and delete this content. Your responsibilities as controller under Section 6.2 apply to everything the investigation reveals.

4.4 Technical and security logs

  • Server access logs: timestamp, IP address, user-agent, requested path, HTTP status, bytes transferred, referrer.
  • Application logs identifying user ID, session ID, workspace ID, and the code path that produced the log line.
  • Rate-limit counters, abuse-detection signals, and Web Application Firewall events.

4.5 Support correspondence

  • Email threads, attachments, and the metadata our email system records when you contact [email protected] or other support addresses.

5. Purposes and legal bases

Every processing activity below has at least one valid legal basis under Article 6(1) GDPR. For UK individuals, references to GDPR provisions in this Policy are to be read as references to the corresponding provisions of the UK GDPR and the Data Protection Act 2018.

PurposeData categoriesLegal basis
PurposeCreate and operate your account, authenticate sign-in, and manage passkeys.Data categoriesAccount data, authentication factors.Legal basisPerformance of contract, Art. 6(1)(b) GDPR.
PurposeBill for the Service, issue invoices, collect VAT, meet bookkeeping duties.Data categoriesPayment metadata, billing address.Legal basisPerformance of contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) (Swiss CO Art. 957 ff., Swiss VAT Act).
PurposeRun investigations, deliver the live stream, show what the page does while the investigation runs, generate the automated analysis.Data categoriesInvestigation content (acting as processor on your behalf), workspace state.Legal basisPerformance of contract, Art. 6(1)(b); processing on documented instructions, Art. 28 GDPR (the Service agreement is the instruction).
PurposeSecure the platform: abuse prevention, fraud detection, rate-limit enforcement, WAF.Data categoriesTechnical and security logs, IP addresses, and, where necessary, investigation metadata.Legal basisLegitimate interest, Art. 6(1)(f) GDPR: keeping the Service available and free of abuse.
PurposeRespond to support, legal, and regulatory requests.Data categoriesSupport correspondence, account data.Legal basisPerformance of contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c).
PurposeComply with court orders, lawful access requests, sanctions and export-control screening.Data categoriesAccount data, payment metadata, logs.Legal basisLegal obligation, Art. 6(1)(c) GDPR; legitimate interest, Art. 6(1)(f), where the obligation arises under non-EEA law.
PurposeDefend or pursue legal claims.Data categoriesPersonal data relevant to the claim.Legal basisLegitimate interest, Art. 6(1)(f); legal claims exemption, Art. 9(2)(f) where special-category data is involved.

We do not rely on consent (Art. 6(1)(a)) for any processing necessary to run the Service. Where consent is the basis (for example, optional product communications), you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

Processing under Swiss law. The FADP does not require a legal basis for every private-sector processing operation. Instead, our processing complies with the principles of Articles 6 and 8 FADP (lawfulness, good faith, proportionality, purpose limitation, accuracy, and data security) and does not unlawfully breach the personality rights of data subjects (Arts. 30 and 31 FADP). Where we rely on legitimate interest under the GDPR, the corresponding overriding-interest justification under Art. 31 FADP applies.

6. Investigation content and third-party data subjects

Guard.ch exists to analyse URLs that you do not control: phishing kits, malware droppers, suspect ads, credential-harvesting pages, scams reported to your security team. When we open such a URL inside our isolated browser, the page may legitimately or illegitimately contain personal data about people who are not our customers (the suspected attacker, the operator of a fraudulent site, a victim quoted in the page, a named target of social engineering).

6.1 Roles

  • You (the customer) choose the target and are the controller for the decision to investigate a particular URL and for what the resulting investigation content contains. You determine the purpose (incident response, fraud investigation, abuse takedown, research) and the means by selecting Guard.ch as the tool.
  • Guard.ch is the processor for that investigation content under Article 28 GDPR. We process it only to provide the Service, on your documented instructions and under the Data Processing Agreement, and we apply the security measures listed in our Security Statement.
  • Guard.ch is an independent controller for limited categories of investigation data where we process it for our own purposes: detecting and preventing abuse of the platform, securing our infrastructure, and complying with legal obligations (for example, a binding order from a Swiss authority). We do not use investigation content for any other purpose of our own.
  • Guard.ch is the controller for your account, billing, telemetry, security logs, and support correspondence. Those are described elsewhere in this Policy.

If you use the Service as a private individual for purely personal purposes, the GDPR's household exemption (Art. 2(2)(c)) may mean the GDPR does not apply to your own activity. Our obligations under this Policy are unaffected either way.

6.2 Customer obligations

As controller for investigation content, you are responsible for having a valid legal basis to investigate the target and to incidentally process personal data of third parties whose information appears in the investigation. Common bases include legitimate interest (Art. 6(1)(f)) for fraud and security investigations, legal obligation (Art. 6(1)(c)) for regulated entities, and Art. 9(2)(f) or 10 GDPR exemptions when special categories or criminal-offence data are involved. Where applicable law requires a Data Protection Impact Assessment (Art. 35 GDPR), you must complete one before instructing us to investigate at scale.

6.3 Our safeguards

  • Investigation content exists only during the investigation on the server running it. Live analysis data stays in memory and temporary browser files stay in an isolated container (the environment running the browser). When the investigation ends, the container and its files are deleted. Nothing remains on the server between investigations, and no long-term copy is stored anywhere.
  • Investigation servers are in the EU and, to reduce delays, in Singapore, Salt Lake City and Beauharnois. Account and service records, including account, workspace, billing and investigation records and database backups, are stored long term in Helsinki in the EEA. Section 9 describes the transfer safeguards for locations outside the EEA.
  • Access to investigation content is limited to the account running it and authorised platform engineers acting on documented support tickets.
  • We do not mine, profile, monetise, or use investigation content to train models.
  • Section 4.3 describes our data minimisation measures and their limits, including password masking, character limits, exclusion of binary content and truncation of very long lists, so you can decide what is appropriate to submit.

6.4 Data subject requests concerning investigation content

If a third-party data subject contacts Guard.ch about content seen inside an investigation, we will forward the request to the customer acting as controller without identifying any other customer or investigation, and assist that customer in responding within the GDPR statutory deadline. We will not respond to the substance of the request ourselves because we are the processor of that content, not the controller, except where we process the same data as an independent controller under Section 6.1 (in which case Section 10 applies to that processing). Note that once an investigation has ended we hold no copy of what it showed.

6.5 No link sharing

The Service offers no link sharing and no public reports. Investigation content is private to your account, subject to the support access described in Section 6.3.

7. Retention

We keep personal data only as long as it is needed for a lawful purpose or a legal retention duty applies. The main retention periods are in the table below.

CategoryRetention windowReason
CategoryInvestigation content (every plan).Retention windowFor the duration of the investigation; deleted automatically when it ends.ReasonProvide live browsing and analysis.
CategoryAccount data.Retention windowLifetime of the account plus a 30-day grace period after account deletion, then erasure.ReasonPerformance of contract; grace period for account reactivation.
CategoryInvoices, VAT records, accounting evidence.Retention window10 years from the end of the fiscal year.ReasonSwiss Code of Obligations Art. 958f; Swiss VAT Act.
CategoryAuthentication logs (success and failure).Retention window180 days.ReasonSecurity monitoring and incident response.
CategoryApplication and access logs.Retention window30 to 90 days, depending on log class.ReasonTroubleshooting, abuse handling.
CategorySupport correspondence.Retention window3 years from the last message.ReasonSupport quality, follow-up questions, and the defence of legal claims.
CategoryBackups containing any of the above.Retention windowRotated within 35 days. If we restore a backup, data scheduled for deletion is deleted again during the next purge.ReasonOperational resilience.

Where a specific window is not listed, we determine retention by these criteria: whether the data is still needed for the purpose it was collected for, whether a statutory retention or limitation period applies, and whether the data is subject to a legal hold or an ongoing dispute.

8. Recipients and subprocessors

We disclose personal data only to recipients that have a contractual basis to receive it and a documented need. The full, versioned list of subprocessors (storage, edge compute, network and bot protection, identity, payments, email, AI analysis) is published in the Subprocessor Register, including each provider's role, location, and the safeguards in place.

Recipient categories:

  • Infrastructure providers hosting our storage and edge-streaming layers (see Section 9).
  • Network, DNS, and bot-protection providers (TLS termination, WAF, rate limiting, challenge widgets).
  • Federated identity providers, only when you choose to sign in with them.
  • Payment processors handling card data and invoicing.
  • Transactional email providers for account verification, password reset, billing notices.
  • AI providers that analyse content you submit to AI features, and providers that analyse operational logs without receiving investigation content.
  • Tax authorities, courts, and regulators when compelled by binding law in our jurisdiction.
  • Professional advisors (lawyers, auditors) under confidentiality obligations.

We do not sell personal data and we do not share it for cross-context behavioural advertising. If the business were ever transferred (merger, acquisition, asset sale), personal data could be disclosed to the acquirer under confidentiality; we would notify you and this Policy would continue to apply until amended under Section 18.

9. International transfers

We are established in Switzerland. Account and service records, including account records and the production database, are stored long term at Hetzner Online GmbH's datacenter in Helsinki, Finland (EU/EEA). Investigation content is handled separately, as described in Section 6.3.

To reduce streaming delays, we also run browser servers outside the EEA. They host the isolated browser, render the page and temporarily hold browser files and live analysis data. Section 6.3 describes how this content is deleted when the investigation ends.

Other subprocessors may process additional categories of personal data:

  • Stripe, Inc. processes payment records for customers billed outside the EEA, the UK and Switzerland.
  • Google Workspace sends transactional emails. The contract is with Google Ireland Limited; Google LLC may process email data in the United States.
  • Cloudflare provides network and bot protection.
  • Google and Microsoft provide federated sign-in when you choose it.
  • OpenRouter, Inc. in the United States processes every model request: content you submit to AI features and, separately, aggregated operational logs.
  • Serper runs web searches for the model; WhoisJSON is the fallback for WHOIS lookups. Neither provider publicly states where it processes data.
  • We use Google Web Risk to check hostname reputation.

The role, location and safeguards for each provider are listed in the Subprocessor Register.

LocationRolePersistent storageTransfer mechanism
LocationHelsinki, Finland.RolePrimary storage, application backend, database, object storage.Persistent storageYes (encrypted at rest).Transfer mechanismEEA. Adequate under Swiss law; no additional mechanism required for EEA or UK data.
LocationSingapore (SG).RoleBrowser hosting, rendering and streaming for APAC investigations.Persistent storageTemporary only; deleted when the investigation ends.Transfer mechanismSingapore holds no Swiss or EU adequacy decision. EU Standard Contractual Clauses (processor-to-processor module) and the Swiss FDPIC-recognised equivalent, plus encryption in transit (TLS 1.3, DTLS-SRTP) for the analyst stream.
LocationSalt Lake City, Utah, USA.RoleBrowser hosting, rendering and streaming for North America.Persistent storageTemporary only; deleted when the investigation ends.Transfer mechanismThe USA holds no general Swiss or EU adequacy decision, and this provider is not certified under the EU-US Data Privacy Framework. EU Standard Contractual Clauses (processor-to-processor module) and the Swiss FDPIC-recognised equivalent, plus a transfer impact assessment on file and encryption in transit.
LocationBeauharnois, Quebec, Canada.RoleBrowser hosting, rendering and streaming for North America.Persistent storageTemporary only; deleted when the investigation ends.Transfer mechanismCanada's commercial sector (PIPEDA) is recognised as adequate by both the European Commission (Decision 2002/2/EC) and Switzerland. Standard Contractual Clauses and the Swiss equivalent are additionally in place as an additional safeguard.

For transfers to US-based subprocessors, where an individual vendor is certified under the EU-US Data Privacy Framework and its Swiss extension (as identified for each provider in the Subprocessor Register), that certification is the primary transfer mechanism and the EU Standard Contractual Clauses operate as a fallback; for all other US transfers the EU Standard Contractual Clauses and the Swiss FDPIC-recognised equivalent apply. Guard.ch itself is a Swiss entity and is not, and cannot be, certified under the Data Privacy Framework.

Where the UK GDPR applies to a transfer, we rely on the UK adequacy regulations for Switzerland and the EEA and on contractual safeguards equivalent to those described above for onward transfers. A copy of the SCCs and the relevant transfer impact assessments is available on written request to [email protected].

10. Your rights

You have the rights below in respect of the personal data we process about you as controller, under the Swiss FADP, the GDPR, or the UK GDPR as applicable to you. Where we process data as a processor on behalf of one of our customers, exercise those rights with that customer; we will assist them within the statutory deadlines.

  • Right of access (Art. 15 GDPR; Art. 25 FADP). Obtain confirmation of whether we process your data, a copy of it, and information about purposes, recipients, retention, and sources.
  • Right to rectification (Art. 16 GDPR; Art. 32(1) FADP). Correct inaccurate data and complete incomplete data.
  • Right to erasure (Art. 17 GDPR; Art. 32(2)(c) FADP). Have your data deleted when one of the conditions applies, subject to overriding legal retention duties listed in Section 7.
  • Right to restriction (Art. 18 GDPR). Pause processing while a dispute is resolved.
  • Right to data portability (Art. 20 GDPR; Art. 28 FADP). Receive your account data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to object (Art. 21 GDPR). Object to processing based on legitimate interests on grounds related to your particular situation. Under the FADP you may object to processing as such; we will stop unless a justification under Art. 31 FADP applies.
  • Right not to be subject to automated decisions (Art. 22 GDPR; Art. 21 FADP). See Section 16: we do not subject you to automated decisions that produce legal effects concerning you.
  • Right to withdraw consent (Art. 7(3) GDPR). Where consent is the basis, withdraw it at any time.
  • Right to lodge a complaint. Contact the Swiss Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern, Swiss FDPIC); if you are in the EEA, your local supervisory authority (Find your EEA supervisory authority in the European Data Protection Board’s list); if you are in the UK, the Information Commissioner's Office (UK ICO); or the authority competent at your place of residence.

To exercise any right, write to [email protected]. Exercising your rights is free of charge except in the narrow cases where the law allows a fee for manifestly unfounded or excessive requests. We will respond without undue delay and at the latest within one month of receipt (Art. 12(3) GDPR; 30 days under Art. 25(7) FADP), extendable where the law permits for complex requests. We may ask you to confirm your identity to prevent unlawful disclosure.

11. US state privacy rights

This Section applies to residents of US states with consumer privacy laws, including California (CCPA as amended by the CPRA), Colorado, Connecticut, Utah, Virginia, Texas, Oregon, and other states, only to the extent those laws apply to Guard.ch and to the personal data at issue. It supplements the rights listed in Section 10 and does not reduce any rights you have under the GDPR, Swiss FADP, or another applicable law.

The categories of personal data we collect are described in Section 4. They include account and authentication data, payment metadata, investigation content, which exists only while the investigation runs, technical and security logs, support correspondence, and analytical outputs produced by the Service. Sources include you, your workspace or employer, the isolated browser investigation you instruct us to run, payment and identity providers you choose to use, security providers, and public or third-party lookup sources used for URL analysis.

We use those categories for the purposes described in Section 5: providing the Service, authenticating users, billing, security and abuse prevention, support, legal compliance, and defending or pursuing legal claims. We disclose personal data to the recipient categories in Section 8 and to the subprocessors listed in the Subprocessor Register.

  • No sale or advertising sharing. We do not sell personal information or share it for cross-context behavioural advertising as “sell” and “share” are defined under the CCPA/CPRA. We have not done so in the preceding 12 months. We do not use personal information for targeted advertising under other state laws, and we do not use advertising cookies or ad pixels. We have no actual knowledge of selling or sharing the personal information of consumers under 16. Because we do not sell or share information for these advertising purposes, there is no related sale or sharing to opt out of; preference signals such as Global Privacy Control do not change that.
  • Sensitive personal data. The content of an investigation, which exists only while the investigation runs, may incidentally include credentials, account identifiers, precise geolocation, financial information, government identifiers, health information, communications content, or other sensitive data if such information is visible on or submitted to a page you instruct us to open. We process that content only while the investigation runs to provide, secure and support the Service as described in this Policy. We delete it when the investigation ends and do not use it to infer characteristics about US consumers.
  • US privacy requests. Where applicable, you may ask us to confirm whether we process your personal information, request access to it, ask for it to be deleted or corrected, obtain it in a portable format, receive information about disclosures, and limit the use of sensitive personal information where state law grants that right. The opt-out rights for sale, sharing, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects are noted for completeness; we do not engage in those activities as described above.
  • Appeals and authorised agents. Where state law grants an appeal right, you may appeal a denied request by replying to our decision email; we will respond within the statutory appeal deadline and, if we deny the appeal, tell you how to contact your state attorney general or privacy regulator. Authorised agents may submit requests where state law permits, but we may require proof of authority and may ask the data subject to verify identity directly.
  • No discrimination. We will not deny service, charge a different price, or provide a different level of service because you exercised a privacy right, except where the requested deletion or restriction makes it impossible to provide the Service or where a lawful exception applies.

Submit US state privacy requests to [email protected]. We will verify requests to protect against unauthorised disclosure or deletion, and will respond within the deadline required by the applicable state law.

12. Other jurisdictions

The Service is offered worldwide. If you are located in a jurisdiction whose data protection law grants you rights beyond those described in this Policy (for example Brazil's LGPD, Canada's PIPEDA, or Australia's Privacy Act), we will honour any additional rights that those laws require us to uphold when processing your personal data. Nothing in this Policy limits any protection that the mandatory law of your place of habitual residence grants you and that cannot be waived by agreement.

To exercise a right under any such law, write to [email protected] and tell us which jurisdiction's law you are invoking. We will assess applicability in good faith and respond within the deadline that law requires, or within one month if it sets none.

13. Children

Guard.ch is a professional security tool. It is not directed at children and we do not knowingly process personal data of users under 16, which is also the minimum age set by our Terms of Service (or the minimum age at which you can validly consent to those Terms in your jurisdiction, if higher). If you believe a person under 16 has registered an account, contact [email protected] and we will close the account and delete the data unless the law requires us to retain specific elements.

14. Security

We implement technical and organisational measures appropriate to the risk, in line with Article 32 GDPR and Article 8 FADP. Encryption in transit (TLS 1.3, DTLS-SRTP for WebRTC) and at rest, hardened isolated browser containers, least-privilege production access with an append-only audit log for sensitive operations, and regular vulnerability management are part of the baseline.

No method of transmission or storage is completely secure. Our Security Statement describes the architecture, the isolation of investigation traffic and the current status of our certifications.

15. Cookies

Guard.ch uses strictly necessary cookies and equivalent local-storage entries to keep you signed in and protect your dashboard session against cross-site request forgery. We also use security cookies set by Cloudflare and payment cookies set by Stripe in the embedded card checkout. We do not use advertising cookies or third-party advertising trackers, and we do not sell or share personal data for cross-context behavioural advertising. The complete inventory, the legal basis, and how to clear or refuse storage are documented in the Cookie Policy. Cookies captured inside the isolated browser during an investigation belong to the sites visited there and are covered by Sections 4.3 and 6 of this Policy, not by the Cookie Policy.

16. Automated analysis, verdicts, and automated decision-making

The Service produces automated analysis of investigated websites: risk scores, classifications, AI-generated summaries, and a verdict. That output is an analytical opinion about the investigated website, produced by automated tooling at a point in time from the signals observed during that investigation. It is not legal, financial, or other professional advice, not a determination about any person, and not a guarantee that a site is safe or unsafe. You remain responsible for how you act on it.

We do not subject you, as the user of the dashboard, to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR or Article 21 FADP. Verdicts and risk scores are made about pages, not about the customer who submitted them and not about identifiable third parties; they support your triage and produce no legal or similarly significant effect on any data subject.

Our security tooling may automatically rate-limit, challenge, or block traffic that matches abuse patterns. These measures protect the platform, are short-lived, and do not produce legal effects; if you believe you were blocked in error, contact [email protected] and a human will review the decision.

17. Breach notification

We operate a written incident response process. When Article 33 GDPR applies to a personal data breach as defined in Article 4(12), we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to natural persons’ rights and freedoms. Where Article 24 FADP applies because a breach is likely to result in a high risk to data subjects, we notify the competent authority as soon as possible.

Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (Art. 34 GDPR), unless the data was encrypted with a strong key we have not lost, the high risk has been mitigated by subsequent measures, or individual notification would involve disproportionate effort (in which case we will issue a public communication).

For incidents concerning investigation content where we act as processor, we will notify the affected customer acting as controller without undue delay and in any event within 48 hours after becoming aware of the breach. We provide the information reasonably available to us so the customer acting as controller can meet its own notification duties under Articles 33 and 34 GDPR (supervisory authority and data subjects).

18. Changes to this policy

We update this Policy when our processing or the law changes, or when we can describe existing practices more clearly. The current version, its effective date and summaries of earlier changes appear below. We give registered customers reasonable advance notice of material changes by email or in the dashboard. Minor clarifications take effect on publication. Continued use after a change takes effect constitutes acceptance only where applicable law permits it; where consent is needed, we will ask for it.

VersionEffective dateSummary of changes
Version1.4Effective date2026-09-23Summary of changesRemoved the product analytics disclosures: Guard.ch no longer uses PostHog or any other product analytics, session recording or error tracking on its website and dashboard.
Version1.3Effective date2026-09-01Summary of changesInvestigation content is available only during live investigations, with no stored captures, exports or snapshot link sharing. Clarified browser locations in Singapore, Salt Lake City and Beauharnois, and Helsinki as the location for records stored long term (Sections 4.3, 6, 7 and 9).
Version1.2Effective date2026-06-10Summary of changesUpdated shared-account disclosures, regional privacy rights, processing roles, retention and international transfers. Added verdict limitations and a single privacy contact: [email protected].
Version1.1Effective date2026-06-05Summary of changesClarified EU representative status, plan-specific capture limits, capture caps, account and payment data fields, US state privacy rights, and processor breach notification timing.
Version1.0Effective date2026-05-26Summary of changesInitial publication of the Guard.ch Privacy Policy.

19. Governing law and dispute resolution

This Privacy Policy is governed by the substantive laws of Switzerland, without regard to conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

The courts at the seat of the operator (Schmiedrued, canton of Aargau, Switzerland) have jurisdiction over disputes arising from or in connection with this Policy. This choice of law and venue does not deprive you of the protection of mandatory data protection or consumer protection provisions of the law of your place of habitual residence, and it does not affect mandatory forum rules that allow you to bring or defend a claim at your place of residence.

This clause also does not affect your right to lodge a complaint with the Swiss FDPIC, with your local EEA supervisory authority, with the UK ICO, or to pursue a judicial remedy under Article 79 GDPR or the equivalent provision of the law applicable to you. Should any provision of this Policy be held invalid or unenforceable, the remaining provisions remain in effect, and the invalid provision is to be read as the enforceable provision that comes closest to its intent.

Guard.ch

Guard.ch is operated by Zesiger.net in Schmiedrued, Switzerland. Account and workspace data is stored in the EU. Live findings are not saved as reports or recordings. Saved browser profiles remain available for later sessions.

Product

  • Overview
  • Pricing
  • Start an investigation

Integrations

  • Extensions
  • MCP
  • API and CDP
  • SSO

Company

  • About
  • Contact
  • Talk to sales

Trust

  • Security
  • DPA
  • Subprocessors
© 2026 Zesiger.net · UID CHE-488.503.816EnglishDeutsch
Legal noticePrivacyCookiesTermsWithdraw from a contract