Privacy Policy

Last Updated: October 31, 2025

Effective Date: October 31, 2025

Introduction

FireGuard ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our fire extinguisher compliance tracking software platform (the "Service").

This policy complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.

By using our Service, you agree to the collection and use of information in accordance with this policy.


1. Information We Collect

1.1 Personal Information You Provide

When you register for and use our Service, we collect:

  • Account Information: Email address, name, password (encrypted), role within your organization
  • Organization Information: Organization name, business address, contact information
  • Location Data: Building/facility names, addresses, geographic coordinates
  • Extinguisher Information: Equipment details, QR codes, installation locations
  • Inspection Records: Inspection dates, findings, inspector names, compliance status
  • Uploaded Content: Inspection photos, documents, notes

1.2 Information Automatically Collected

When you access our Service, we automatically collect:

  • Usage Data: Pages viewed, features used, time spent, click patterns
  • Device Information: Browser type, operating system, device identifiers
  • Network Data: IP address, geographic location (country/city), ISP information
  • Performance Data: API response times, error logs, service availability metrics
  • Cookies and Similar Technologies: Session tokens, preferences, authentication state

1.3 Information from Third Parties

We may receive information from:

  • Authentication Providers: If you use single sign-on (SSO) services (future feature)
  • Payment Processors: Transaction data, billing information (future feature)
  • Business Partners: Integration data from connected services (future feature)

2. How We Use Your Information

2.1 Service Delivery

We use your information to:

  • Provide, operate, and maintain the Service
  • Process inspections and generate compliance reports
  • Enable QR code scanning and equipment tracking
  • Calculate compliance status per NFPA 10 and OSHA 1910.157
  • Analyze inspection photos using AI technology
  • Send compliance alerts and notifications
  • Provide customer support and respond to inquiries

2.2 Service Improvement

We use your information to:

  • Analyze usage patterns and optimize performance
  • Develop new features and improve existing functionality
  • Debug technical issues and prevent fraud
  • Conduct security audits and threat detection
  • Perform quality assurance testing

2.3 Communication

We use your information to:

  • Send service-related notifications (inspection due dates, compliance alerts)
  • Provide account updates and security notices
  • Respond to support requests
  • Send optional marketing communications (with your consent)

We use your information to:

  • Comply with legal obligations and regulatory requirements
  • Enforce our Terms of Service and other agreements
  • Protect our rights, privacy, safety, or property
  • Respond to legal requests from authorities

We process your personal data under the following legal bases:

  • Contract Performance: Processing necessary to provide the Service you requested
  • Legitimate Interests: Fraud prevention, security, service improvement
  • Legal Obligation: Compliance with laws, regulations, court orders
  • Consent: Marketing communications, optional features (withdrawable anytime)

4. How We Share Your Information

4.1 Service Providers

We may share your information with trusted third-party service providers:

  • Cloudflare: Infrastructure provider (edge computing, CDN, security)
  • AI Analysis Providers: Photo analysis services (Cloudflare Workers AI)
  • Email Services: Notification delivery (future integration)
  • Payment Processors: Billing and subscription management (future integration)

All service providers are contractually bound to protect your data and use it only for specified purposes.

4.2 Business Transfers

If we undergo a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred to the successor entity. We will notify you of any such change and provide choices regarding your information.

We may disclose your information if required to:

  • Comply with legal obligations (subpoenas, court orders, regulations)
  • Protect rights, property, or safety of FireGuard, users, or the public
  • Investigate fraud, security issues, or Terms of Service violations

We may share information for other purposes with your explicit consent.

4.5 De-identified and Aggregated Data

We may share anonymized, aggregated data that cannot identify you (e.g., industry benchmarks, usage statistics).


5. Data Security

5.1 Security Measures

We implement industry-standard security measures to protect your information:

  • Encryption in Transit: TLS 1.3 for all data transmission
  • Encryption at Rest: Data stored in encrypted databases (Cloudflare D1, R2)
  • Password Security: PBKDF2 hashing with 100,000 iterations, salted
  • Authentication: JWT tokens with HMAC SHA-256 signatures, 7-day expiration
  • Access Controls: Role-based access control (RBAC), multi-tenant data isolation
  • Security Headers: HSTS, CSP, X-Frame-Options, X-Content-Type-Options
  • Rate Limiting: Protection against brute force and DoS attacks (100 req/min)
  • SQL Injection Prevention: Parameterized queries, input sanitization
  • Regular Audits: Automated security testing, vulnerability scanning

5.2 Data Breach Notification

In the event of a data breach that affects your personal information, we will:

  • Notify affected users within 72 hours (GDPR requirement)
  • Notify relevant supervisory authorities as required by law
  • Provide information about the breach, affected data, and remediation steps
  • Offer assistance and support to affected users

5.3 Limitations

No security system is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.


6. Data Retention

6.1 Retention Periods

We retain your information for as long as necessary to provide the Service and comply with legal obligations:

  • Account Information: Retained while your account is active
  • Inspection Records: Retained for 7 years (OSHA recordkeeping requirement)
  • Compliance Data: Retained per regulatory requirements (typically 5-7 years)
  • Usage Logs: Retained for 90 days for security and debugging purposes
  • Backup Data: Retained for 30 days in encrypted backups

6.2 Data Deletion

When you delete your account or request data deletion:

  • Personal information is deleted within 30 days
  • Compliance records may be retained longer to meet legal obligations
  • Backup copies are deleted according to our backup retention schedule (30 days)
  • Aggregated, anonymized data may be retained indefinitely

7. Your Privacy Rights

7.1 GDPR Rights (EU/EEA/UK Residents)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Limit how we process your data
  • Data Portability: Receive your data in a structured, machine-readable format
  • Object: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for processing (where consent is the legal basis)
  • Lodge a Complaint: File a complaint with your supervisory authority

7.2 CCPA/CPRA Rights (California Residents)

You have the right to:

  • Know: What personal information we collect, use, disclose, and sell
  • Access: Request a copy of your personal information (twice per year)
  • Delete: Request deletion of your personal information
  • Opt-Out: Opt out of the "sale" or "sharing" of personal information (we do not sell data)
  • Correct: Request correction of inaccurate personal information
  • Limit Use: Limit use of sensitive personal information
  • Non-Discrimination: Not be discriminated against for exercising your rights

7.3 How to Exercise Your Rights

To exercise any of these rights:

  1. In-App: Use the Settings page > Privacy & Data section
  2. Email: Send a request to privacy@fireguard.example.com
  3. Written Request: Mail to [Company Address]

We will respond within 30 days (or as required by applicable law).

Verification: We may request additional information to verify your identity before processing requests.


8. Cookies and Tracking Technologies

8.1 Types of Cookies We Use

  • Essential Cookies: Required for authentication, session management, security
  • Session tokens (JWT stored in localStorage)
  • CSRF protection tokens
  • Functional Cookies: Remember your preferences and settings
  • Language preferences
  • UI customization settings
  • Analytics Cookies: Understand how you use the Service (future feature)
  • Usage metrics, page views, feature usage

Essential cookies cannot be disabled without preventing the Service from functioning.

For optional cookies, you can:

  • Manage preferences in Settings > Privacy & Data
  • Use browser settings to block or delete cookies
  • Use browser extensions for cookie management

Note: Disabling cookies may limit Service functionality.

8.3 Do Not Track (DNT)

We currently do not respond to DNT browser signals, as there is no industry-wide standard. We will update this policy if standards are established.


9. Third-Party Services

9.1 Cloudflare

Our Service is hosted on Cloudflare's edge network. Cloudflare processes data on our behalf and is GDPR-compliant. Review Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/

9.2 Workers AI

Inspection photos are analyzed using Cloudflare Workers AI. Images are processed transiently and not permanently stored by the AI provider. AI analysis results (structured data) are stored in our database.

9.3 Future Integrations

As we add third-party integrations (email, SMS, payment processors), we will update this policy and notify you of changes.


10. International Data Transfers

10.1 Data Location

Your data is processed and stored on Cloudflare's global edge network, which may include servers in multiple countries. Cloudflare provides:

  • Standard Contractual Clauses (SCCs) for GDPR compliance
  • Adequacy Decisions where available
  • Data Localization options for specific jurisdictions (future feature)

10.2 Safeguards

We ensure appropriate safeguards for international transfers:

  • Encryption in transit and at rest
  • Contractual data protection obligations
  • Compliance with regional data protection laws

11. Children's Privacy

Our Service is not intended for children under 16 (or the applicable age of consent in your jurisdiction).

We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us immediately, and we will delete it.


12. Changes to This Privacy Policy

12.1 Policy Updates

We may update this Privacy Policy to reflect:

  • Changes in our data practices
  • New features or services
  • Legal or regulatory requirements
  • Industry best practices

12.2 Notification

We will notify you of material changes by:

  • Email notification to your registered address
  • Prominent notice on the Service (banner or modal)
  • Update to the "Last Updated" date at the top of this policy

Continued use of the Service after changes constitutes acceptance of the updated policy.

12.3 Review Frequency

We review this policy at least annually and update as necessary.


13. Data Protection Officer

For GDPR-related inquiries, you may contact our Data Protection Officer:

Email: dpo@fireguard.example.com Address: [Company Address]


14. Supervisory Authority

If you are in the EU/EEA/UK, you have the right to lodge a complaint with your data protection supervisory authority:

  • EU: Find your authority at https://edpb.europa.eu/about-edpb/board/members_en
  • UK: Information Commissioner's Office (ICO) - https://ico.org.uk/

15. Contact Information

For privacy-related questions, concerns, or requests:

Email: privacy@fireguard.example.com Support: Use the in-app support feature or visit [support.fireguard.example.com] Address: [Company Legal Address]


16. Specific Jurisdictions

16.1 California Residents (CCPA/CPRA)

Personal Information Collection (Last 12 Months):

CategoryExamplesCollectedBusiness Purpose
IdentifiersName, email, IP addressYesAccount management, authentication
Commercial InformationSubscription data, usage patternsYesService delivery, billing
Internet ActivityBrowsing history, interactionsYesService improvement, analytics
GeolocationIP-based location, facility addressesYesService delivery, compliance tracking
Professional InformationRole, organizationYesMulti-tenant access control
InferencesUsage patterns, preferencesYesService optimization

We do not sell or share personal information for cross-context behavioral advertising.

Retention Justification: Data retained for service delivery, legal compliance, and regulatory requirements (OSHA, NFPA).

Sensitive Personal Information: We collect passwords (encrypted) and precise geolocation (facility addresses). This data is used only for specified business purposes and not for additional purposes without consent.

16.2 European Union Residents (GDPR)

Data Controller: FireGuard is the data controller for your personal information.

Legal Representative (if applicable): [EU Representative Name and Address]

Data Transfer Mechanisms: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for international data transfers.

16.3 United Kingdom Residents

We comply with the UK GDPR and Data Protection Act 2018. Our UK representative (if required): [UK Representative].

16.4 Other Jurisdictions

We comply with applicable data protection laws in all jurisdictions where we operate, including:

  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Brazil: Lei Geral de Proteção de Dados (LGPD)
  • Australia: Privacy Act 1988

17. Compliance Certifications

17.1 Current Compliance

  • GDPR Compliant
  • CCPA/CPRA Compliant
  • OWASP Top 10 Security Standards
  • Cloudflare's SOC 2 Type II (infrastructure)

17.2 Planned Certifications

  • ISO 27001 (Information Security Management)
  • SOC 2 Type II (our application)
  • Privacy Shield Framework (if reinstated)

Appendix: Definitions

Personal Information/Data: Information that identifies, relates to, or could reasonably be linked with you or your household.

Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.

Data Controller: The entity that determines the purposes and means of processing personal data.

Data Processor: The entity that processes personal data on behalf of the data controller.

Sensitive Personal Information: Social security numbers, financial account details, biometric data, health information, precise geolocation (CPRA definition).


By using FireGuard, you acknowledge that you have read, understood, and agree to this Privacy Policy.


End of Privacy Policy