Agentic Risk & Exposure System
IMPORTANT NOTICE
This Privacy Policy explains how SX Capital AG ("SXGuard," "we," "us," or "our") collects, uses, stores, shares, and protects personal data in connection with the ARES platform, our website, and related services. It should be read together with the ARES Terms of Service. Please read it carefully.
1.1 SX Capital AG, a company incorporated in Switzerland under commercial register number CHE-203.998.242 and trading as SXGuard, is the data controller responsible for the personal data described in this Privacy Policy. Our registered office is at Gubelstrasse 24, Zug 6300, Switzerland.
1.2 This Privacy Policy applies to personal data we process in connection with: (i) the ARES platform and associated services; (ii) the SXGuard website at www.sxguard.com; (iii) communications with prospective customers, partners, and event attendees; and (iv) our sales, marketing, and support activities.
1.3 This Privacy Policy does not apply to the security scan data and vulnerability findings that Customers generate through their use of the ARES platform. Our handling of that data is governed by the ARES Terms of Service and the data processing terms set out therein, under which we typically act as a data processor on the Customer's behalf. See Section 9 (Our Role: Controller vs. Processor) for further detail.
To help you understand this Policy, the following terms have the meanings set out below:
We collect personal data in the following ways and categories.
When you register for access to ARES, request a demonstration, or contact us, we collect the information you submit, which may include:
When an account is created on the ARES platform, we process account credentials and authentication data, including usernames, hashed passwords, and API keys associated with the account. We do not store passwords in plain text.
When you use the platform or visit our website, we may automatically collect technical data, including IP address, browser type and version, device identifiers, operating system, access timestamps, pages viewed, and actions taken within the platform. This data helps us operate, secure, and improve our services.
Our website uses cookies and similar tracking technologies to operate the site, remember preferences, analyse traffic, and — where applicable — support marketing activities. You can control cookies through your browser settings and our cookie consent mechanism. For details, see Section 8 (Cookies).
If you interact with us at an industry event (such as GISEC or it-sa), subscribe to communications, or engage with our marketing campaigns, we may collect your contact details and records of your interactions and preferences for the purpose of following up and providing relevant information about our products.
We do not seek to collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health, or biometric data) through our standard business activities. Please do not submit such data to us unless specifically requested and lawfully justified.
We process personal data only where we have a lawful basis to do so. The table below summarises our principal processing activities, the purposes, and the corresponding lawful basis under the GDPR and nFADP.
Account & registration data
Purpose of Processing: To create and manage your account, authenticate users, and provide access to the platform
Lawful Basis: Performance of contract
Contact & enquiry data
Purpose of Processing: To respond to your enquiries, demo requests, and support tickets
Lawful Basis: Legitimate interests / Pre-contractual steps
Usage & technical data
Purpose of Processing: To operate, secure, monitor, and improve the platform and detect misuse
Lawful Basis: Legitimate interests
Billing & transaction data
Purpose of Processing: To process payments, issue invoices, and maintain financial records
Lawful Basis: Performance of contract / Legal obligation
Marketing & event data
Purpose of Processing: To send relevant product communications and follow up on leads
Lawful Basis: Consent / Legitimate interests
Cookies & analytics data
Purpose of Processing: To analyse website performance and tailor content
Lawful Basis: Consent (non-essential) / Legitimate interests (essential)
Security & audit logs
Purpose of Processing: To protect the platform, investigate incidents, and meet compliance obligations
Lawful Basis: Legitimate interests / Legal obligation
Where we rely on consent as our lawful basis, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, and you have the right to object as described in Section 7.
We do not sell your personal data. We share personal data only in the limited circumstances described below.
We engage trusted third-party service providers to help us deliver our services — including cloud hosting, payment processing, analytics, customer support, and communications. These providers process personal data only on our instructions and under written agreements that require appropriate safeguards. A current list of our material sub-processors is available on request.
We may share your personal data with our affiliated entities and authorised representatives for the purposes of sales, customer relationship management, and regional service delivery, where permitted by applicable law and subject to appropriate safeguards.
We may disclose personal data where required to do so by law, regulation, court order, or a valid request from a competent authority, or where necessary to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of SXGuard, our customers, or others.
If SXGuard is involved in a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to the receiving party honouring the commitments set out in this Privacy Policy.
6.1 As a Swiss company serving customers internationally — including in the European Economic Area, the United Kingdom, the Gulf Cooperation Council region, and elsewhere — your personal data may be transferred to and processed in countries outside your country of residence, including countries that may not provide the same level of data protection.
6.2 Where we transfer personal data from Switzerland or the EEA to a country that has not been recognised as providing an adequate level of data protection, we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the Swiss addendum where applicable), together with supplementary measures where necessary.
6.3 You may request further information about the safeguards we apply to international transfers by contacting us using the details in Section 12.
Depending on your location and applicable law, you have the following rights in relation to your personal data:
7.1 To exercise any of these rights, please contact us using the details in Section 12. We will respond within the timeframe required by applicable law (under the GDPR, generally within one month). We may need to verify your identity before fulfilling a request.
7.2 If you are in the EEA, you may lodge a complaint with your local data protection authority. If you are in Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC). You also have the right to a judicial remedy.
9.1 In respect of the personal data described in this Privacy Policy — such as account, contact, marketing, and website data — SXGuard acts as the data controller, determining the purposes and means of processing.
9.2 In respect of the data that Customers process through the ARES platform in the course of their security testing activities — including any personal data contained within scan targets, findings, or reports — SXGuard acts as a data processor, processing such data solely on the documented instructions of the Customer, who is the controller. The terms governing this relationship are set out in the ARES Terms of Service and, where applicable, a separate Data Processing Agreement.
10.1 We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.
10.2 As a general guide: account data is retained for the duration of the customer relationship and for a reasonable period thereafter; billing and transaction records are retained for the period required by applicable tax and commercial law (typically up to ten years under Swiss law); and marketing data is retained until you opt out or after a period of inactivity.
10.3 Upon termination of a customer relationship, Customer Data is handled in accordance with the ARES Terms of Service, which provide a window for data export followed by deletion.
We implement reasonable and appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or destruction. These measures include encryption of data in transit (TLS 1.2 or higher), access controls and least-privilege principles, sandboxed execution environments, audit logging, and regular security assessments. While we work hard to protect your data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have a complaint, please contact us:
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Effective Date" at the top of this Policy and, where appropriate, notify you by email or through a notice on our website. We encourage you to review this Policy periodically.