Trust and data handling

Clear expectations for information shared with GuardResolution.

This plain-language policy explains how information from a Microsoft 365 Security Baseline Review request is used, protected, retained, and deleted.

GuardResolution is the service name used on this site. The legal entity name, business address, effective date, and any governing-law details should be added after owner review.

Collect what helps us scope the work
A request may include your name, work email, organization, team size, Microsoft 365 environment summary, service interest, and questions. Please do not place passwords, MFA codes, API keys, or other secrets in the form or in ordinary email.
Use information to respond and deliver
We use intake information to respond to your request, confirm scope, plan and conduct an agreed review, prepare findings, discuss recommendations, and communicate about follow-up work you ask us to consider.
Limit access and handle it carefully
Access is intended to be limited to people and service providers who need the information for the review or its operation. We use reasonable administrative and technical safeguards, but no online system can promise absolute security.

Confidentiality

Your environment is yours to control.

Information shared for an agreed review is treated as confidential and used for the purpose it was provided. We do not sell intake information. If access to Microsoft 365 or another system is needed, the access method and scope should be agreed in advance and limited to what is necessary.

Confidentiality does not cover information that is already public or known to us without a duty of confidence, is independently developed, is shared with your permission, or must be disclosed by law or to address a serious safety or security concern. A specific incident-notification commitment should be added after owner review if one is intended.

Microsoft 365 and customer data

GuardResolution should access only the tenant, accounts, devices, and records included in the agreed scope. The client remains responsible for granting appropriate access, maintaining backups, approving changes, and removing temporary access when work ends.

The review is not a request to provide unrestricted credentials. Use least-privilege, temporary, or read-only access where practical, and use an agreed secure method for any sensitive material.

Providers and transfers

Hosting, database, email, and other infrastructure providers may process information on GuardResolution's behalf. The specific provider list, processing locations, and cross-region transfer details are not stated until confirmed by the owner.

Provider access should be limited to the services needed to operate the request and review workflow, with contractual and technical safeguards appropriate to the data.

Retention and deletion

Keep it only as long as the work requires.

Intake details, review notes, findings, and related communications may be retained for as long as reasonably needed to evaluate a request, deliver the agreed work, support follow-up, maintain business records, or meet legal obligations. A specific retention period and backup rotation schedule should be confirmed before publication.

To request deletion or ask a privacy question, email guardresolution@polsia.app. We may need to verify the request and clarify what information is in scope. Deletion from active systems may not immediately remove information from backups or records we must retain.

Questions or requests

Ask before you share sensitive context.

Contact GuardResolution about privacy, deletion, confidentiality, or the safest way to provide information for a review.

Email GuardResolution
Ready to discuss a review?Request a review