Guardz platform retention vs. the Guardz DPA
The Guardz Data Processing Agreement (DPA) covers Guardz's data-processing and deletion obligations — including the deletion or return of customer personal data following service cessation, in accordance with the applicable deletion timelines. The DPA does not itself specify how long data is retained in the Guardz product during an active subscription, or how quickly Guardz actually deletes data on request. Those specifics are set out below.
What does Guardz Ingest?
Source | What Guardz ingests |
Microsoft 365 / Entra ID, Google Workspace | Raw telemetry, ingested directly by Guardz — not Microsoft's or Google's own native alerts. This telemetry powers ITDR detection and supports investigations. |
Third-party security tools (e.g., EDR, email security) | The full alert generated by the tool, plus its metadata. Benign content (such as email bodies or files) and continuous raw telemetry are not ingested by Guardz — that data stays within the third-party tool and may be accessed by Guardz on an ad hoc basis during an investigation. |
Retention by Data Type
Data type | Retention period | Notes |
Alerts, incidents, and issues (all sources) | Indefinite | Once an event from any connected source is surfaced as a Guardz alert, incident, or issue, it is retained indefinitely. |
Ingested productivity cloud logs (Microsoft 365 / Entra ID, Google Workspace) | 90 days from ingestion | Searchable by Guardz for analysis and investigation, not directly by the customer. If the source platform ages an event out of its own retention window sooner, Guardz's ingested copy still remains available for the full 90 days. |
Underlying data in third-party security tools (e.g., endpoint telemetry, email content) | Set by the tool's own retention policy | This data is not ingested by Guardz (only the resulting alert and metadata are, per above), so it remains subject to that third-party tool's own retention policy, subscription tier, and any retention settings configured within the tool itself. Guardz may access this data on an ad hoc basis during an investigation. |
"Guardz Managed" vs. Direct Use of Third-party Controls
Retention in a connected third-party security tool is not modified or shortened by being a "Guardz Managed" customer. It follows that tool's own policy, subscription tier, and configured settings, the same as it would for a customer using the tool directly.
Data Deletion after Account Cessation
When a customer's account is deleted, associated customer data is deleted within 24 hours. Ingested productivity cloud logs (Microsoft 365/Entra ID and Google Workspace) are the exception: they are deleted 90 days from their original ingestion date regardless of when the account itself is deleted.
Exporting Data
Alerts and issues can be exported via the Guardz API. Raw logs and underlying telemetry are not exportable by customers through Guardz; ingested cloud log data remains available for Guardz's own analysis for 90 days from ingestion.
