← Back to GuardRadar

Privacy Policy

Last updated: 24 August 2026

This Privacy Policy explains how Fully Stacked Ltd (company number [COMPANY NUMBER]), trading as GuardRadar (“we”, “us”, “our”), collects and uses personal data when you visit guard-radar.com, contact us, or enquire about our services.

Two roles, clearly separated. For this marketing website and sales enquiries, we are the data controller. When a security company uses the GuardRadar product, that company is usually the controller for guard and shift data; we act as their processor under our Terms of Service and Data Processing Agreement. Guard-facing privacy is handled by each client using our guard privacy notice template.

1. Who we are

Data controller: Fully Stacked Ltd (trading as GuardRadar)
Registered office: [REGISTERED OFFICE ADDRESS], United Kingdom
ICO registration: [ICO REGISTRATION NUMBER]
Privacy contact: [email protected]
General enquiries: [email protected]

2. What data we collect

Website visitors

  • Technical logs: IP address, browser type, device type, referring URL, pages viewed, and timestamps. Collected via our hosting/CDN (Cloudflare) for security, abuse prevention, and reliability.
  • Cookie / local storage data: your cookie-banner preference (see our Cookie Policy).

Contact and demo enquiries

When you submit our contact form or email us, we collect the details you provide, typically:

  • name
  • work email address
  • company name
  • team size (optional)
  • message content
  • date/time of submission and your consent record

Form submissions are processed via Formspree (form backend) and stored in our internal CRM for follow-up.

Sales and marketing

If you are a prospective B2B customer, we may also hold business contact details obtained from public sources (for example company websites or directories) where permitted. We keep an audit trail of outreach and opt-out requests.

GuardRadar product (summary)

This policy focuses on the website. If you use GuardRadar as a customer, guard names, PINs (stored hashed), sign-in/out times, spot-check responses, optional GPS coordinates on supported plans, incident notes, and shift records are processed to deliver the service. That processing is governed by our DPA with your organisation. GPS is captured at sign-in, spot checks, and incidents on eligible plans — not as continuous background tracking.

3. How we use your data and lawful bases

PurposeDataLawful basis (UK GDPR)
Respond to enquiries and provide demos Contact form / email details Legitimate interests (running a B2B SaaS business) and, where required, consent recorded at submission
Operate and secure the website Technical logs, essential cookies Legitimate interests (security, fraud prevention, service delivery)
B2B sales follow-up Business contact details Legitimate interests (marketing to relevant security companies). You may object or opt out at any time.
Legal and accounting obligations Records required by law Legal obligation / legitimate interests

We do not sell personal data. We do not use website advertising trackers.

4. Who we share data with

We use carefully selected service providers who process data only on our instructions:

  • Cloudflare — CDN, DDoS protection, TLS (may process IP addresses).
  • Formspree — contact form delivery.
  • Email provider — transactional and support email.
  • Hosting (EEA) — GuardRadar application infrastructure is hosted in the European Economic Area (for example Hetzner, Germany).
  • Professional advisers — lawyers, accountants, insurers where necessary.
  • Authorities — when required by law or to protect rights and safety.

We require processors to implement appropriate security and confidentiality measures. A current list is available on request.

5. International transfers

We aim to keep personal data in the UK / EEA. Where a provider processes data outside the UK, we use appropriate safeguards such as the UK International Data Transfer Agreement or adequacy regulations, as applicable.

6. How long we keep data

  • Contact / sales enquiries: up to 24 months after last meaningful contact, unless you become a customer or ask us to delete sooner.
  • Customer account data: for the life of the contract plus up to 30 days, then deleted or returned per the DPA.
  • Server logs: typically up to 90 days for security.
  • Marketing opt-out list: kept indefinitely to honour your request.

7. Your rights

Under UK data protection law you have rights including access, rectification, erasure, restriction, objection, and data portability (where applicable). You also have the right to withdraw consent where processing is consent-based, without affecting prior lawful processing.

To exercise your rights, email [email protected]. We respond within one month. You may complain to the Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint.

8. Security

We use TLS encryption in transit, access controls, hashed credentials in the product, rate limiting, and regular review of our hosting configuration. No method of transmission over the internet is 100% secure; we work to maintain appropriate technical and organisational measures.

9. Children

GuardRadar is a B2B service for security companies. Our website is not directed at children under 18 and we do not knowingly collect their data.

10. Changes

We may update this policy from time to time. Material changes will be posted here with a new “last updated” date. For active customers we will provide additional notice where appropriate.

Terms of Service Cookie Policy Disclaimer Contact