Clear expectations for information shared with GuardResolution.
This plain-language policy explains how information from a Microsoft 365 Security Baseline Review request is used, protected, retained, and deleted.
GuardResolution is the service name used on this site. The legal entity name, business address, effective date, and any governing-law details should be added after owner review.
Confidentiality
Your environment is yours to control.
Information shared for an agreed review is treated as confidential and used for the purpose it was provided. We do not sell intake information. If access to Microsoft 365 or another system is needed, the access method and scope should be agreed in advance and limited to what is necessary.
Confidentiality does not cover information that is already public or known to us without a duty of confidence, is independently developed, is shared with your permission, or must be disclosed by law or to address a serious safety or security concern. A specific incident-notification commitment should be added after owner review if one is intended.
GuardResolution should access only the tenant, accounts, devices, and records included in the agreed scope. The client remains responsible for granting appropriate access, maintaining backups, approving changes, and removing temporary access when work ends.
The review is not a request to provide unrestricted credentials. Use least-privilege, temporary, or read-only access where practical, and use an agreed secure method for any sensitive material.
Hosting, database, email, and other infrastructure providers may process information on GuardResolution's behalf. The specific provider list, processing locations, and cross-region transfer details are not stated until confirmed by the owner.
Provider access should be limited to the services needed to operate the request and review workflow, with contractual and technical safeguards appropriate to the data.
Retention and deletion
Keep it only as long as the work requires.
Intake details, review notes, findings, and related communications may be retained for as long as reasonably needed to evaluate a request, deliver the agreed work, support follow-up, maintain business records, or meet legal obligations. A specific retention period and backup rotation schedule should be confirmed before publication.
To request deletion or ask a privacy question, email guardresolution@polsia.app. We may need to verify the request and clarify what information is in scope. Deletion from active systems may not immediately remove information from backups or records we must retain.
Questions or requests
Ask before you share sensitive context.
Contact GuardResolution about privacy, deletion, confidentiality, or the safest way to provide information for a review.