Privacy Policy

This Privacy Policy describes how Vistaguard (“Vistaguard,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with our security incident response and risk management platform (the “Service”).

1. Scope and Key Definitions

This policy distinguishes between two categories of data, as the rights and obligations differ for each:

“Account Data” refers to information about you as a user of Vistaguard your name, work email, company, role, and billing details.

“Customer Data” refers to the incident, ticket, alert, and operational data that you or your organization input into, or connect to, Vistaguard in the course of using the Service including data ingested from SIEM, EDR, firewall, or cloud security tools.

Where you use Vistaguard to manage your own organization, you are the “Controller” of your Account Data and Customer Data, and Vistaguard acts as a “Processor” (or “Service Provider”) on your behalf, consistent with applicable data protection law. Where you onboard external client organizations into Vistaguard, you remain responsible for your relationship with those organizations, and Vistaguard processes their data solely on your instructions.

2. Information We Collect

2.1 Information You Provide Directly: Account information (name, work email, job title, company name, and password stored as a salted hash); Billing information (billing address and payment details processed via a third-party payment processor; Vistaguard does not store full payment card numbers); Support communications; Organization and client onboarding data.

2.2 Customer Data Ingested Through the Service: When you connect a SIEM, firewall, EDR, or cloud security tool (e.g., AWS GuardDuty, AWS Security Hub), the Service ingests alert and log data necessary to manage tickets. This may include IP addresses, hostnames, device identifiers, user account identifiers, email metadata/content, indicators of compromise (IOCs), file hashes, threat intelligence data, and system logs.

2.3 Information Collected Automatically: Usage data (pages visited, features used, and actions taken); Device and connection information (IP address, browser type, operating system); Cookies and similar technologies.

2.4 Information from AI Processing: Vistaguard's AI features process Customer Data to generate outputs. Where AI processing is performed via a third-party large language model provider, only the minimum data necessary is transmitted, and such data is not used by Vistaguard or its sub-processors to train models for other customers, except where explicitly opted in.

3. How We Use Information

We use information to provide, operate, and maintain the Service, including ticket creation, AI analysis, and reporting features. We enforce role-based access controls, generate AI-powered summaries/playbooks, and monitor to prevent security incidents affecting the Service itself. We communicate regarding updates, security notices, billing, and support, and analyze aggregated, de-identified usage trends to improve the Service. We do not sell Account Data or Customer Data to third parties, and we do not use Customer Data for advertising purposes.

4. Legal Basis for Processing (GDPR and Similar Frameworks)

Where applicable data protection law requires a legal basis for processing personal data, we rely on the following:
Performance of a contract — to provide the Service you have subscribed to.
Legitimate interests — to secure the Service, prevent fraud, and improve product functionality, balanced against your rights.
Consent — where required, such as for optional marketing communications or opted-in AI training use.
Legal obligation — where processing is necessary to comply with applicable law.

5. How We Share Information

5.1 Sub-Processors and Service Providers: We share information with carefully vetted third parties who help us operate the Service, including cloud infrastructure providers (e.g., AWS), AI model providers, payment processors, and customer support tools. All sub-processors are contractually bound to data protection obligations.

5.2 Within Your Organization: Ticket and incident data related to each onboarded client organization is visible only to authorized users within your organization who have been granted appropriate access based on configured controls.

5.3 Legal Disclosures: We may disclose information where required to comply with a legal obligation, protect the rights and safety of Vistaguard, our customers, or the public.

5.4 No Sale of Personal Information: Vistaguard does not sell personal information as defined under applicable law, including the California Consumer Privacy Act (CCPA).

6. Data Security

We implement administrative, technical, and physical safeguards designed to protect Account Data and Customer Data, including: encryption of data in transit (TLS 1.2+) and at rest (AES-256); role-based access controls and the principle of least privilege; logging and monitoring of access to production systems; regular vulnerability scanning and penetration testing; and mandatory multi-factor authentication (MFA) availability. No method of transmission or storage is 100% secure.

7. Data Retention

Account Data is retained for as long as your account remains active, and for a limited period thereafter to comply with legal, accounting, or reporting obligations. Customer Data (tickets, incidents, logs) is retained according to the retention period configured in your plan, or as otherwise instructed by you, and is deleted or anonymized upon account termination. Backup copies may persist for a limited period following deletion requests, consistent with standard backup rotation cycles.

8. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data: Access, Correction, Deletion, Portability, Objection/Restriction, and Withdrawal of consent. To exercise these rights, contact us at privacy@vistaguard.io.

8.1 Nigeria Data Protection Act (NDPA) and NDPR: For data subjects in Nigeria, Vistaguard complies with the Nigeria Data Protection Act 2023.

8.2 European Economic Area and United Kingdom (GDPR / UK GDPR): We provide the rights outlined above and ensure appropriate safeguards (such as Standard Contractual Clauses) are in place for international data transfers.

8.3 California (CCPA/CPRA): California residents have the right to know what personal information is collected, request deletion, and opt out of the sale or sharing of personal information.

9. Cookies and Tracking Technologies

Essential cookies — required for login sessions and core functionality. These cannot be disabled without affecting the Service.
Analytics cookies — used to understand feature usage and improve the Service. Can be managed via your cookie preference settings.

We do not use third-party advertising cookies.

10. International Data Transfers

Vistaguard's infrastructure is hosted on Amazon Web Services. Depending on your selected region and configuration, data may be processed in data centers located outside your country of residence. Where such transfers occur, we implement appropriate safeguards, such as Standard Contractual Clauses, to ensure your data remains protected consistent with applicable law.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes via email or a prominent notice within the Service prior to the change becoming effective.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: privacy@vistaguard.io
Data Protection Officer: dpo@vistaguard.io
Mailing Address: [Insert Vistaguard registered business address]