Privacy Policy
Effective date: 10 October 2026.
1. Who we are
This policy is issued by Sam Mulliner, doing business as Valvayn, Texas, United States. The full postal address is provided in contracts and on request to [email protected]. (“we”, “us”), the provider of Ward. Contact for privacy questions: [email protected]. EU/UK representative: Valvayn has not appointed an EU or UK representative. Ward is offered to organisations in the United States; it is not currently marketed to customers in the EU or UK..
2. What this policy covers
- This website. What happens when you visit it.
- Business contacts. What we do with information you send us, for example when you request access.
- The Ward service. How personal data is handled when an organisation uses Ward. For that data the organisation (your employer, if you use a managed browser at work) decides what is collected and why; we process it on its behalf under our Data Processing Addendum.
3. This website
- No cookies, no analytics, no tracking. This website sets no cookies, uses no analytics or advertising tools, and loads no third-party scripts, fonts, images or embeds. See the Cookie Notice.
- Server logs. Like any web server, the server that delivers this website may record your IP address, browser user agent, the page requested and the time, to deliver the site and protect it from abuse. These logs are kept for 30 days. Legal basis: our legitimate interest in operating a secure website.
- The contact form does not submit anything to us. It opens your own email app with a pre-filled message; nothing is sent until you send that email yourself.
4. When you contact us
If you email us, we receive your name, email address, organisation and whatever you include in your message. We use it to reply, to discuss access to Ward and, if you become a customer, to manage that relationship. Legal basis: our legitimate interests in responding to enquiries and running our business, or taking steps at your request before entering into a contract. We keep this correspondence for as long as needed for those purposes and then delete it.
5. The Ward service
Ward is designed to collect security metadata, not content.
- Inspected on the device, never sent to us: page contents, prompts, messages, clipboard contents, typed text, form values, file contents, passwords, cookies and tokens, keystrokes, full URLs, and the sensitive values Ward detects.
- Sent to the Ward server as metadata: hostnames and application categories, account type and domain, the action and policy decision, classification names and match counts, file names, types and sizes, account identifiers (by default only for corporate accounts), business justifications that users choose to type, and device information such as operating system, browser and extension versions and installed extensions.
- Administrator accounts: names, email addresses, roles, sign-in credentials (stored as hashes) or a Microsoft Entra ID link, sessions, and an audit log of administrative actions.
For this data the customer organisation is the controller and we act as its processor, following its instructions and our Data Processing Addendum. If you use Ward through your employer and want to exercise your rights, contact your employer; we will help them respond. We act as an independent controller only for the limited data we need to manage our contract with the customer (such as billing contacts) and to keep our service secure.
Where a customer runs Ward on its own infrastructure, we do not receive this data unless the customer shares it with us, for example in a support request.
6. Who we share personal data with
- Subprocessors that help us run the service, listed on our subprocessor page.
- Authorities, where the law requires it.
- A successor, if our business is reorganised or sold, under the same protections.
We do not sell personal data and do not use it for advertising.
7. International transfers
Hosting provider and data location: Infrastructure operated by Valvayn in Texas, United States. Traffic passes through Cloudflare's edge network (TLS termination and DDoS protection).. Where personal data is transferred outside the UK or the European Economic Area, we use recognised safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
8. How long we keep data
- Website server logs: 30 days.
- Business correspondence: as long as needed for the purposes above.
- Ward service data: as configured by the customer. Security events are deleted after 180 days by default. After a customer’s contract ends we delete service data within 30 days, as set out in the Data Processing Addendum.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete or restrict the use of your personal data, to object to processing based on legitimate interests, and to data portability. To exercise these rights about data we control, email [email protected]. For Ward service data, contact the organisation that deployed Ward. You also have the right to complain to a data protection supervisory authority, such as the Information Commissioner’s Office in the UK or the authority in your EU country.
10. Security
How we protect the service is described on our Security & Privacy page.
11. Children
This website and the Ward service are intended for businesses and are not directed at children.
12. Changes
We will update this policy when our practices change and show the effective date at the top. Material changes affecting customers are also notified as described in our agreements.