Privacy Policy

    Last Updated: November 27, 2025

    Effective Date: November 27, 2025

    Your privacy is important to us. This policy explains how we collect, use, and protect your personal data.

    Data Protection & Privacy

    1. Introduction

    Guardian Volt Ltd ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Guardian Volt platform ("Service").

    This policy is compliant with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

    2. Data Controller

    Guardian Volt Ltd is the data controller responsible for your personal data.

    • Company: Guardian Volt Ltd
    • Email: privacy@guardianvolt.com
    • ICO Registration Number: C1839426
    • Data Protection Officer: privacy@guardianvolt.com
    • Supervisory Authority: Information Commissioner's Office (ICO)

    3. Information We Collect

    We collect the following categories of personal data:

    CategoryData TypesPurpose
    Identity DataName, email address, phone numberAccount creation and communication
    Contact DataBilling address, emailBilling and correspondence
    Financial DataBank account details, transaction history, balancesGenerating court reports, transaction tracking
    Ward/P DataName, DOB, address, care informationCourt reporting requirements
    Guardianship DataCourt case number, appointment date, reporting periodsCompliance and reporting
    Technical DataIP address, browser type, device informationSecurity and service improvement
    Usage DataFeatures used, pages visited, time spentService improvement
    Audit DataAll actions taken, timestamps, changes madeCompliance and security
    Document DataUploaded files (receipts, invoices, care plans)Court report documentation

    4. Legal Basis for Processing

    Under UK GDPR, we process your data based on the following lawful bases:

    PurposeLegal Basis
    Providing the ServiceContractual Necessity (Article 6(1)(b))
    OPG/Court reporting complianceLegal Obligation (Article 6(1)(c))
    AI transaction categorisationConsent (Article 6(1)(a))
    Fraud prevention and securityLegitimate Interests (Article 6(1)(f))
    Service improvementLegitimate Interests (Article 6(1)(f))
    Marketing communicationsConsent (Article 6(1)(a))

    5. Third-Party Data Processors

    We share your data with the following third-party service providers who process data on our behalf:

    ProviderPurposeData SharedLocation
    TrueLayerBank account connectivityBank credentials (via OAuth), transaction dataUK/EU
    Anthropic (Claude AI)Transaction categorisation, narrative generationTransaction descriptions, merchant namesUSA
    OpenAIBackup AI processingTransaction descriptions, merchant namesUSA
    StripePayment processingBilling information, payment methodUK/EU
    ClerkAuthenticationEmail, name, authentication tokensUSA
    Amazon Web Services (AWS)Cloud hosting and storageAll dataeu-west-2 (London)
    ResendEmail deliveryEmail address, notification contentUSA

    All third-party processors are bound by data processing agreements that require them to protect your data and only process it according to our instructions.

    6. AI Processing and Automated Decision-Making

    Important: Our Service uses artificial intelligence (AI) to process your data.

    What data is sent to AI providers?

    • Transaction descriptions (e.g., "TESCO STORES", "AMAZON.CO.UK")
    • Transaction amounts
    • Transaction dates
    • Merchant categories (when available)

    What data is NOT sent to AI providers?

    • Your name or identity
    • Bank account numbers
    • Ward/protected person identity
    • Your email or contact information

    How is AI data used?

    AI providers process transaction descriptions to suggest categorisations (e.g., "Food & Groceries", "Medical Expenses"). These are suggestions only. You have the right to review and modify all AI-generated categorisations before they appear in reports.

    Your Rights Regarding Automated Processing

    Under Article 22 of the UK GDPR, you have the right to:

    • Request human review of AI categorisation decisions
    • Express your point of view about AI decisions
    • Contest AI-generated categorisations
    • Opt out of AI processing (manual categorisation only)

    To exercise these rights, contact privacy@guardianvolt.com.

    7. International Data Transfers

    Some of our third-party processors (Anthropic, OpenAI, Clerk) are based in the United States. When we transfer your data outside the UK/EEA, we ensure adequate protection through:

    • Standard Contractual Clauses (SCCs): EU-approved contracts that provide data protection guarantees
    • Supplementary Measures: Additional technical and organisational safeguards
    • Data Processing Agreements: Contracts requiring processors to protect your data

    You can request a copy of the safeguards we use by contacting privacy@guardianvolt.com.

    8. Data Retention

    We retain your data for the following periods:

    Data TypeRetention PeriodReason
    Account DataDuration of account + 30 daysService provision
    Transaction Data7 years from transaction dateCourt/tax compliance requirements
    Generated Reports7 years from generationLegal compliance, audit requirements
    Audit Logs7 yearsRegulatory compliance, dispute resolution
    Uploaded Documents7 years or until account deletionCourt documentation requirements
    Bank Access TokensUntil disconnected or 90 days inactiveService functionality
    Marketing PreferencesUntil consent withdrawnConsent-based marketing

    After retention periods expire, data is securely deleted or anonymised. You can request earlier deletion, subject to our legal obligations.

    9. Your Rights

    Under UK GDPR, you have the following rights:

    • Right of Access: Request a copy of your personal data
    • Right to Rectification: Request correction of inaccurate data
    • Right to Erasure: Request deletion of your data ("right to be forgotten")
    • Right to Restrict Processing: Request limitation of data processing
    • Right to Data Portability: Receive your data in a portable format
    • Right to Object: Object to processing based on legitimate interests
    • Right to Withdraw Consent: Withdraw consent at any time
    • Right to Lodge a Complaint: Complain to the ICO (ico.org.uk)

    To exercise your rights: Email privacy@guardianvolt.com or use the data export/deletion features in Settings. We will respond within one month.

    10. Data Security

    We implement robust security measures to protect your data:

    • Encryption at Rest: AES-256 encryption for all stored data
    • Encryption in Transit: TLS 1.3 for all data transmission
    • Bank Token Encryption: AES-256-GCM with PBKDF2 key derivation
    • Multi-Factor Authentication: Required for all user accounts
    • Audit Logging: Complete audit trail of all actions
    • Access Controls: Role-based access to data
    • Regular Security Reviews: Ongoing security assessments

    11. Data Breach Notification

    In the event of a data breach that affects your personal data:

    • We will notify the ICO within 72 hours of becoming aware of a breach (where required)
    • We will notify you without undue delay if the breach poses a high risk to your rights
    • Notification will include: nature of the breach, likely consequences, and measures taken

    12. Cookies

    We use cookies and similar technologies to provide our Service. For detailed information about our cookie usage, please see our Cookie Policy.

    13. Children's Privacy

    Our Service is not intended for children under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

    14. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes by:

    • Updating the "Last Updated" date at the top of this policy
    • Sending an email notification for significant changes
    • Displaying a notice within the Service

    15. Contact Us

    For privacy-related questions or to exercise your rights:

    • Company: Guardian Volt Ltd
    • Privacy Email: privacy@guardianvolt.com
    • General Support: support@guardianvolt.com
    • ICO Registration Number: C1839426
    • Data Protection Officer: privacy@guardianvolt.com
    • Supervisory Authority: Information Commissioner's Office - ico.org.uk