Privacy Policy (GDPR)

X-Guard BV (hereinafter: X Guard) aims to comply not only with the letter but also with the spirit of the General Data Protection Regulation (GDPR). This European regulation imposes strict obligations on organizations regarding the processing, storage, and protection of personal data. This document contains X-Guard's privacy statement, with further explanations and additions specifically related to the implementation and compliance with the GDPR within our organization.

  • Legal entity: X-Guard BV
  • Chamber of Commerce number: 06081323
  • Address: Amarilstraat 20, 7554 TV Hengelo OV

1. Contact details of the controller and FG

X-Guard BV is the controller within the meaning of the GDPR. For any questions regarding this privacy policy or the exercise of your rights, please contact our Data Protection Officer (DPO). Within X-Guard, the role of DPO is equivalent to that of the Chief Information Security Officer (CISO).

The official and only source where our CISO/FG's details are published is: https://privacy.x-guard.nl/ciso/.

2. Legal bases for processing

X-Guard processes personal data solely on the basis of the grounds recognised in the GDPR:

  • Permission for the use of cookies of the data subject;
  • Execution of an agreement to which the data subject is a party;
  • Legal obligations to which X-Guard is subject;
  • Legitimate interest from X-Guard or a third party, whereby the interests and fundamental rights of the data subjects are always taken into account.

3. Specific rights of data subjects

In addition to the right to access, correction, and deletion, data subjects have the following additional rights under the GDPR:

  • Right to data portability: the right to receive personal data in a structured, commonly used and machine-readable format and to transmit it to another party;
  • Right to restriction of processing: the right to temporarily suspend the processing of personal data;
  • Right to object: the right to object to processing based on legitimate interest or direct marketing.

X-Guard does not provide services to children under the age of 13 and does not process personal data of this category. For users between the ages of 13 and 18, data may only be processed if written permission has been obtained from parents or legal guardians.


4. Right to Complaint

If you believe that X-Guard is not processing your personal data lawfully, you have the right to lodge a complaint with the supervisory authority:

Personal Data Authority (www.autoriteitpersoonsgegevens.nl).


5. International transfer

X-Guard processes personal data exclusively within the European Economic Area (EEA). No transfer outside the EEA takes place. Should this be necessary in the future, we will only work with parties that offer appropriate safeguards in accordance with the GDPR, such as standard contractual clauses or an adequacy decision from the European Commission.


6. Cookies and tracking

X-Guard uses cookies and similar technologies to optimize the functioning of our services and to analyze their use. Cookies are used for, among other things:

  • Functional purposes: to make the basic functionality of our services work;
  • Analytical purposes: to gain insight into the use and performance of our services;
  • Preferences: to remember language and settings;
  • Security: to prevent abuse and increase security.

You can manage or block cookies through your browser settings. However, disabling cookies may impact the functionality of our services. A complete and up-to-date overview of the types of cookies and their purposes is available in our separate cookie policy.


7. Information about data storage and processing

For substantive and detailed answers to all questions regarding the way in which X-Guard stores, processes and protects personal data, we refer you to our official and exclusive information source: https://privacy.x-guard.nl/data-points/In the published there data points We meticulously record which categories of data we collect, where this data is physically hosted, and what retention periods apply.

This source serves as the only official location for this information and also offers the option to subscribe to updates, ensuring stakeholders are always fully informed of current changes.


8. General

X-Guard services can be used by users in a variety of ways: for consulting or disseminating information, for communicating with third parties, or for creating new content. When you share data with us, for example by creating an X-Guard account, you enable us to further enhance the quality and functionality of our services.

We believe it is essential that you gain a clear insight into:

  • the nature and scope of the data we collect, and the purpose of this collection;
  • the manner in which we use and apply this data;
  • the options you retain regarding access, modification or deletion of your data.

X-Guard's privacy policy applies to all services we offer, including those made available through our partners, such as applications for Android and iOS devices. This policy does not apply to third-party services, which have their own separate privacy statements.


9. Use of X-Guard information

For an up-to-date, complete and binding list of subprocessors that process personal data on behalf of X-Guard, we refer exclusively to our official publication: https://privacy.x-guard.nl/subprocessors/This page explains in detail what a subprocessor This section describes how the selection process takes place and under what contractual and legal terms access to data is granted. It is also possible to subscribe to notifications about changes. This is the only official location where we publish such changes.


10. Summary of stored data

A wide range of data objects are stored within the X-Guard product landscape, all of which perform a vital function in the core functionality of the system. Examples include user accounts, devices, assets (including people or emergency buttons), geographic zones, alarm events, and detailed log files. These entities may contain personal data, including identifiers such as names, phone numbers, and email addresses, as well as technical data relating to devices and their interactions.

A current, continuous and complete listing of the entities managed by X-Guard, with further explanation regarding hosting location and retention periods, can only be consulted via: https://privacy.x-guard.nl/data-points/. You can also receive notifications for updates via this source.


11. Purposes of data processing

The data collected by X-Guard is used for:

  • the delivery, maintenance, security and optimization of our services;
  • the continuous development of new functionalities and product innovations;
  • ensuring the safety of users and the integrity of systems;
  • maintaining communication with and supporting customers and users;
  • compliance with relevant laws and regulations and associated obligations.

12. Retention Periods

The retention periods applicable to personal data are communicated exclusively through our official sources:


13. Access, modification and deletion of data

Users retain the right to access, correct, or delete their personal data at any time. Examples include:

  • modifying profile data associated with an X-Guard account;
  • the management of information shared with third parties;
  • the portability of data to other services;
  • deleting user accounts within the application.

Additionally, a removal request can be submitted through our official website: https://privacy.x-guard.nl/gdpr-deletion-request/.

Cookies can be managed through your browser settings. However, please note that disabling cookies may negatively impact the functionality of our services.


14. Data sharing

X-Guard only shares personal data under the following circumstances:

  • after obtaining explicit and informed consent;
  • with domain administrators, if your account is managed by such an administrator;
  • with external processors, provided that they demonstrably act under our instructions and provide appropriate safeguards;
  • if this is necessary to comply with a legal obligation.

Anonymized or non-personally identifiable data may be shared for statistical and analytical purposes, such as trend reporting.

If a party has signed data processing agreement (DPA) If you wish to receive this, you can formally request it via: https://privacy.x-guard.nl/request-signed-dpa/.


15. Data Security

To protect the data we process, X-Guard takes a range of technical and organisational measures, including:

  • complete encryption of data transport and data storage using SSL/TLS;
  • periodic review and revision of internal procedures, including physical security measures;
  • restricting access to personal data to strictly authorized personnel subject to confidentiality agreements and strict contractual obligations.

16. ISO 27001 standard

X-Guard BV is proud to announce that we are October 27, 2025 our ISO 27001 certification We have achieved the globally recognized standard for Information Security Management Systems (ISMS). This milestone underscores our continued commitment to maintaining the highest levels of data security, operational integrity, and privacy-focused service.

Our certification is valid until October 27, 2028 and reaffirms our continued commitment to excellence in information security management.

Download our official certificate here: ISO 27001 certificate.


17. Access rights and logging

X-Guard applies the principle of minimum access rights Consistently. This means that employees only have access to data that is strictly necessary for performing their specific tasks. This minimizes the risk of unauthorized or unintended access.

It is also all access to personal data loggedThese log files allow us to transparently track which employees have accessed which data and at what time. This not only ensures accountability but also facilitates rapid detection and remediation of potential incidents.


18. Assessment of personnel

X-Guard personnel are periodically and systematically evaluated on various dimensions, including competence level, professional knowledge of information security and compliance with internal policies. In this way, we ensure that employees not only possess the required skills but also act in accordance with applicable standards and guidelines. This contributes substantially to the continuity, reliability, and quality of our services.


19. Compliance and cooperation

  • Periodic audits and checks on compliance with this privacy policy;
  • Active and constructive cooperation with supervisory authorities in the event of complaints or investigations.

18. Data Protection Impact Assessment (DPIA)

X-Guard performs where necessary Data Protection Impact Assessments (DPIAs) A DPIA is a legally required analysis under the GDPR when data processing is likely to pose a high risk to the rights and freedoms of data subjects. The aim is to identify and minimize privacy risks at an early stage, in accordance with the principle privacy by design en privacy by default.

Our DPIAs include:

  • a description of the processing and the purposes;
  • an assessment of necessity and proportionality;
  • an inventory of possible risks;
  • recording of measures to mitigate risks (such as encryption, access restriction and data minimization).

For more details, please refer to our official DPIA page: https://privacy.x-guard.nl/dpia/This is the only official source with up-to-date information about our DPIA approach.


19. Changes to this policy

Changes to this privacy policy will be announced on this page without exception. If the changes are substantial, users will also be notified through a separate notice. Previous versions of this policy are carefully archived and will remain available for review.


Version date: November 7 2025