Privacy Policy

Agentic Risk & Exposure System

IMPORTANT NOTICE

This Privacy Policy explains how SX Capital AG ("SXGuard," "we," "us," or "our") collects, uses, stores, shares, and protects personal data in connection with the ARES platform, our website, and related services. It should be read together with the ARES Terms of Service. Please read it carefully.

1. Who We Are and Scope of This Policy

1.1 SX Capital AG, a company incorporated in Switzerland under commercial register number CHE-203.998.242 and trading as SXGuard, is the data controller responsible for the personal data described in this Privacy Policy. Our registered office is at Gubelstrasse 24, Zug 6300, Switzerland.

1.2 This Privacy Policy applies to personal data we process in connection with: (i) the ARES platform and associated services; (ii) the SXGuard website at www.sxguard.com; (iii) communications with prospective customers, partners, and event attendees; and (iv) our sales, marketing, and support activities.

1.3 This Privacy Policy does not apply to the security scan data and vulnerability findings that Customers generate through their use of the ARES platform. Our handling of that data is governed by the ARES Terms of Service and the data processing terms set out therein, under which we typically act as a data processor on the Customer's behalf. See Section 9 (Our Role: Controller vs. Processor) for further detail.

2. Key Definitions

To help you understand this Policy, the following terms have the meanings set out below:

1. "Personal Data"
Any information relating to an identified or identifiable natural person, such as a name, email address, phone number, or online identifier.
2. "Processing"
Any operation performed on personal data, including collection, recording, storage, use, disclosure, transfer, and deletion.
3. "Data Controller"
The party that determines the purposes and means of processing personal data. For the activities in this Policy, that is SXGuard.
4. "Data Processor"
A party that processes personal data on behalf of, and under the instructions of, a Data Controller.
5. "Data Subject" or "You"
The natural person to whom the personal data relates — including website visitors, prospective customers, and Authorized Users of the platform.
6. "GDPR"
The EU General Data Protection Regulation (Regulation (EU) 2016/679).
7. "nFADP"
The revised Swiss Federal Act on Data Protection, in force since 1 September 2023.
8. "Sub-Processor"
A third-party service provider engaged by SXGuard to process personal data in connection with the delivery of our services.

3. Personal Data We Collect

We collect personal data in the following ways and categories.

3.1 Data You Provide Directly

When you register for access to ARES, request a demonstration, or contact us, we collect the information you submit, which may include:

  • Full name
  • Business email address
  • Business telephone number
  • Business name and company website
  • Business country and job role or title
  • The content of any enquiry, message, or support request you send us

3.2 Account and Authentication Data

When an account is created on the ARES platform, we process account credentials and authentication data, including usernames, hashed passwords, and API keys associated with the account. We do not store passwords in plain text.

3.3 Usage and Technical Data

When you use the platform or visit our website, we may automatically collect technical data, including IP address, browser type and version, device identifiers, operating system, access timestamps, pages viewed, and actions taken within the platform. This data helps us operate, secure, and improve our services.

3.4 Cookies and Similar Technologies

Our website uses cookies and similar tracking technologies to operate the site, remember preferences, analyse traffic, and — where applicable — support marketing activities. You can control cookies through your browser settings and our cookie consent mechanism. For details, see Section 8 (Cookies).

3.5 Marketing and Event Data

If you interact with us at an industry event (such as GISEC or it-sa), subscribe to communications, or engage with our marketing campaigns, we may collect your contact details and records of your interactions and preferences for the purpose of following up and providing relevant information about our products.

3.6 Data We Do Not Intentionally Collect

We do not seek to collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health, or biometric data) through our standard business activities. Please do not submit such data to us unless specifically requested and lawfully justified.

4. How and Why We Use Your Data

We process personal data only where we have a lawful basis to do so. The table below summarises our principal processing activities, the purposes, and the corresponding lawful basis under the GDPR and nFADP.

Account & registration data

Purpose of Processing: To create and manage your account, authenticate users, and provide access to the platform

Lawful Basis: Performance of contract

Contact & enquiry data

Purpose of Processing: To respond to your enquiries, demo requests, and support tickets

Lawful Basis: Legitimate interests / Pre-contractual steps

Usage & technical data

Purpose of Processing: To operate, secure, monitor, and improve the platform and detect misuse

Lawful Basis: Legitimate interests

Billing & transaction data

Purpose of Processing: To process payments, issue invoices, and maintain financial records

Lawful Basis: Performance of contract / Legal obligation

Marketing & event data

Purpose of Processing: To send relevant product communications and follow up on leads

Lawful Basis: Consent / Legitimate interests

Cookies & analytics data

Purpose of Processing: To analyse website performance and tailor content

Lawful Basis: Consent (non-essential) / Legitimate interests (essential)

Security & audit logs

Purpose of Processing: To protect the platform, investigate incidents, and meet compliance obligations

Lawful Basis: Legitimate interests / Legal obligation

Where we rely on consent as our lawful basis, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, and you have the right to object as described in Section 7.

5. How We Share Your Data

We do not sell your personal data. We share personal data only in the limited circumstances described below.

5.1 Service Providers and Sub-Processors

We engage trusted third-party service providers to help us deliver our services — including cloud hosting, payment processing, analytics, customer support, and communications. These providers process personal data only on our instructions and under written agreements that require appropriate safeguards. A current list of our material sub-processors is available on request.

5.2 Affiliated Entities

We may share your personal data with our affiliated entities and authorised representatives for the purposes of sales, customer relationship management, and regional service delivery, where permitted by applicable law and subject to appropriate safeguards.

5.3 Legal and Regulatory Disclosure

We may disclose personal data where required to do so by law, regulation, court order, or a valid request from a competent authority, or where necessary to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of SXGuard, our customers, or others.

5.4 Business Transfers

If SXGuard is involved in a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to the receiving party honouring the commitments set out in this Privacy Policy.

6. International Data Transfers

6.1 As a Swiss company serving customers internationally — including in the European Economic Area, the United Kingdom, the Gulf Cooperation Council region, and elsewhere — your personal data may be transferred to and processed in countries outside your country of residence, including countries that may not provide the same level of data protection.

6.2 Where we transfer personal data from Switzerland or the EEA to a country that has not been recognised as providing an adequate level of data protection, we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the Swiss addendum where applicable), together with supplementary measures where necessary.

6.3 You may request further information about the safeguards we apply to international transfers by contacting us using the details in Section 12.

7. Your Privacy Rights

Depending on your location and applicable law, you have the following rights in relation to your personal data:

  • Right of access — to obtain confirmation of whether we process your data and a copy of that data.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure — to request deletion of your data in certain circumstances (the "right to be forgotten").
  • Right to restriction — to request that we limit the processing of your data in certain circumstances.
  • Right to data portability — to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Right to object — to object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent — where processing is based on consent, to withdraw it at any time.
  • Right to lodge a complaint — to complain to a data protection supervisory authority (see Section 7.2).

7.1 To exercise any of these rights, please contact us using the details in Section 12. We will respond within the timeframe required by applicable law (under the GDPR, generally within one month). We may need to verify your identity before fulfilling a request.

7.2 If you are in the EEA, you may lodge a complaint with your local data protection authority. If you are in Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC). You also have the right to a judicial remedy.

8. Cookies and Tracking Technologies

8.1 Cookies are small text files placed on your device when you visit a website. We use the following categories of cookies:

  • Strictly necessary cookies — required for the website and platform to function; these cannot be disabled.
  • Functional cookies — remember your preferences and settings.
  • Analytics cookies — help us understand how visitors use our website so we can improve it.
  • Marketing cookies — used to deliver and measure the relevance of advertising; set only with your consent.

8.2 Where required by law, we obtain your consent before placing non-essential cookies. You can manage your cookie preferences at any time through our cookie consent banner or your browser settings. Disabling certain cookies may affect the functionality of our website.

9. Our Role: Controller vs. Processor

9.1 In respect of the personal data described in this Privacy Policy — such as account, contact, marketing, and website data — SXGuard acts as the data controller, determining the purposes and means of processing.

9.2 In respect of the data that Customers process through the ARES platform in the course of their security testing activities — including any personal data contained within scan targets, findings, or reports — SXGuard acts as a data processor, processing such data solely on the documented instructions of the Customer, who is the controller. The terms governing this relationship are set out in the ARES Terms of Service and, where applicable, a separate Data Processing Agreement.

10. Data Retention

10.1 We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.

10.2 As a general guide: account data is retained for the duration of the customer relationship and for a reasonable period thereafter; billing and transaction records are retained for the period required by applicable tax and commercial law (typically up to ten years under Swiss law); and marketing data is retained until you opt out or after a period of inactivity.

10.3 Upon termination of a customer relationship, Customer Data is handled in accordance with the ARES Terms of Service, which provide a window for data export followed by deletion.

11. How We Protect Your Data

We implement reasonable and appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or destruction. These measures include encryption of data in transit (TLS 1.2 or higher), access controls and least-privilege principles, sandboxed execution environments, audit logging, and regular security assessments. While we work hard to protect your data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. How to Contact Us

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have a complaint, please contact us:

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Effective Date" at the top of this Policy and, where appropriate, notify you by email or through a notice on our website. We encourage you to review this Policy periodically.