GuardSync by Eden Labs
Privacy Policy
Last updated: October 9, 2026
1Introduction
GuardSync is a workforce management product for security operations, made by Eden Labs ("GuardSync," "we," "our," or "us"). It includes an Admin Console, a Guard App, and a Field Officer (Staff) App.
This policy also covers versions of GuardSync that Eden Labs provides to client organizations under their own name, such as Black Belt - GuardSync.
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and what rights users may have.
2Scope
This Privacy Policy applies to:
- Guard App users (security guards)
- Staff App users (staff/supervisors)
- Admin Console users (administrators)
- Organizations using GuardSync
3Information We Collect
We collect the following categories of data:
A. Account and Identity Data
- Name
- Phone number
- Email address
- Password (stored as a one-way hash)
- Employee ID (if assigned)
- Organization and site assignment information
- Role data (guard, staff, admin)
B. Biometric and Identity Verification Data
- Facial descriptor templates used for face verification checks
- Profile photo (if provided)
- Government ID numbers and documents your employer asks you to provide (for example Aadhaar or PAN)
- Bank account details used for payroll
Note: We use facial descriptor data to confirm identity during clock-in and random face verification checks. We do not use facial descriptors for purposes unrelated to workforce verification in this app.
C. Attendance and Work Activity Data
- Clock-in and clock-out timestamps
- Hours worked
- Assigned site and shift information
- Face check status (for example: pending, passed, failed, expired)
- Patrol checkpoint logs
- Leave requests and their status
- Conveyance requests (permission to leave an assigned area)
- Responses to wake alerts on night shifts
- Field reports, including any audio or video you record and submit
D. Location Data
- GPS coordinates (latitude, longitude)
- Accuracy metadata (if provided)
- Time of each location ping
- Location sent with an SOS alert
Note: Location data is recorded during active shifts (for example, periodic updates according to system configuration).
E. Organization and Operational Data
- Organization profile details (such as name, invite code, contact details)
- Site details and site contact information
- Payroll records (for example: days worked, rates, deductions, net pay status)
F. Technical and Security Data
- Authentication tokens and authorization metadata
- Basic API and system logs needed for security, troubleshooting, and reliability
4How We Use Information
We use personal data to:
- Create and manage user accounts
- Authenticate users and maintain secure access
- Process guard enrollment and admin authorization workflows
- Verify identity for clock-in and random face checks
- Record attendance and generate payroll data
- Run patrols, leave, conveyance and field reporting workflows
- Send SOS alerts, with location, to the organization's administrators
- Monitor shift location updates and last known guard location for operations
- Detect misuse, prevent fraud, and improve security
- Maintain, debug, and improve app performance
- Comply with legal obligations
5Legal Bases for Processing
Depending on your jurisdiction, we may rely on one or more of the following legal bases:
- Performance of a contract
- Legitimate interests (for example, workforce management and security operations)
- Legal obligation
- Consent (especially where required for biometric processing)
Organizations using GuardSync are responsible for obtaining any employee notices, acknowledgments, or consent required by applicable law.
7Data Retention
We retain data for as long as needed to provide services and meet legal, operational, and security requirements.
Current app behavior includes:
- Configurable location-data retention window (default set in system configuration)
- Archival of older location records from active tables
- Cleanup of older completed or expired face check records
- Longer retention of attendance and payroll records where needed for business and compliance purposes
Retention periods may vary by organization policy and legal requirements.
8Security Measures
We use reasonable technical and organizational safeguards, including:
- Password hashing
- Encryption of sensitive identity fields, such as government ID numbers
- Token-based authentication
- Role-based access controls
- Rate limiting for sensitive endpoints (such as login)
- Database and infrastructure controls suitable for operational security
No method of storage or transmission is completely secure. We cannot guarantee absolute security.
9International Transfers
If data is stored or processed in jurisdictions outside your country, we take steps intended to provide appropriate protection as required by applicable law.
10Your Rights
Depending on local law, users may have rights to:
- Access personal data
- Correct inaccurate data
- Delete data
- Restrict or object to certain processing
- Data portability
- Withdraw consent where processing is based on consent
Requests should be directed to your employer/organization administrator first, or to us using the contact details below where appropriate. To ask for your account and personal data to be deleted, email us from the address linked to your account.
11Children
GuardSync is intended for professional workforce use and is not directed to children.
12Third-Party Services
GuardSync may rely on third-party infrastructure or libraries for hosting, authentication support, analytics, or facial processing capabilities. Their processing is governed by their own policies and contractual terms.
13Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions will be posted with a revised "Last Updated" date.
14Contact Information
For privacy questions or requests, contact: