Privacy Policy
Last updated: August 31, 2026
Global distribution. Payments and order processing are securely handled by our authorized global distribution partner, acting as Merchant of Record. That partner is responsible for all global tax collection, invoicing, and payment security.
This Privacy Policy explains what personal data Bastion Cyber — a sole proprietorship operating from Ciudad del Este, Alto Paraná Department, Republic of Paraguay (“we”, “us”) — collects when you buy, activate and run GhostShield EDR (the “Software”), how we use it, and what rights you have over it. We act as the data controller for the limited data described below.
The short version. Your payment data is handled entirely by our authorized Merchant of Record — we never see your card. From your server, the Software collects only the Hardware ID (HWID) needed to validate your license. The engine does not read the content of your legitimate files, does not harvest personal data from your systems, and any telemetry that leaves your host is encrypted in transit.
1. Scope
This policy covers the bastioncyber.online website, the purchase and licensing flow, and the data-handling behaviour of the Software installed on your servers. It does not cover third-party sites, your own customers’ data, or the internal processing of our payment provider, which is governed by its own policy.
2. Payment Data — Handled by Our Merchant of Record
An authorized Merchant of Record (MoR) is our reseller for all sales. The Merchant of Record collects and processes all payment and billing data for your purchase — including card or wallet details, billing address, tax identifiers and invoicing information — as an independent controller under its own privacy policy, and remits applicable taxes on our behalf.
Bastion Cyber never receives, processes or stores your card number, CVV, bank credentials or full payment instrument. From the Merchant of Record we receive only what is needed to fulfil and support your order: your email address, order and subscription identifiers, product and plan purchased, purchase date, subscription status, and the country used for tax purposes. Card data is handled by PCI-DSS compliant infrastructure on the Merchant of Record’s side.
3. What We Collect
Security Telemetry and Data Isolation: The GhostShield engine is designed on a “Zero Exfiltration” principle. Our agent strictly collects operational metadata and system behavior metrics, including: hardware identifiers (HWID) for license validation, process IDs (PIDs), system calls (syscalls), and mitigation alerts. We do NOT read, inspect, index, or upload your personal files, databases, documents, cryptographic keys, or passwords. Monitoring occurs purely by analyzing the operating system’s execution flow.
3.1 License and account data
- Email address — to deliver your license key (JWT), installer link, renewal and security notices, and to provide support.
- Hardware ID (HWID) — a non-reversible identifier derived from stable hardware and system attributes of the licensed server. It exists for one purpose: to bind a license to one machine and to perform dynamic license validation. It is not a browsing identifier, does not identify a natural person on its own, and is not used for profiling, advertising or tracking.
- Order metadata from the Merchant of Record, as listed in Section 2.
3.2 Support correspondence
If you contact support, we process the content of your message and anything you voluntarily attach
(for example log excerpts or uname -r output). Please redact anything sensitive before sending it.
3.3 Website and server logs
Our web server keeps standard technical logs (IP address, timestamp, user agent, requested path) for security, abuse prevention and troubleshooting, retained for a short period. We do not use advertising trackers or third-party analytics profiling on the site.
4. What the Engine Does NOT Do
This section is a categorical commitment about how GhostShield EDR behaves on your infrastructure:
- It does not read the content of your legitimate files. The engine inspects kernel events and metadata — syscall type, process identifiers, executable path, file path, inode, credentials, connection tuples — not the contents of your documents, databases, source code, configuration secrets, backups or customer records.
- It does not save or transmit personal data from your systems. We do not collect, store or receive your customers’ personal data, your business data, your credentials, your private keys, your email or your database records.
- It does not exfiltrate your files. No file body, memory dump or disk image is uploaded to us. Detection artefacts stay in local logs on your host, under your control.
- It does not read keystrokes, capture screens, record audio or monitor employee content.
- It does not phone home with your business data. Contact with our infrastructure is limited to license validation and, where enabled, update checks.
- It does not sell, rent, share or trade any data with advertisers or data brokers.
Where the engine must record an identifier to make a security decision auditable — such as the path of a binary that attempted an unauthorised action — that record is written to your local event log on your host. You decide what to do with it.
5. Telemetry and Encryption
Security telemetry generated by the Software is written locally by default. Where a deployment is configured to transmit telemetry or to validate a license, all traffic is encrypted in transit using modern TLS, and license artefacts are cryptographically signed so that they cannot be forged or silently altered. Telemetry consists of security event metadata and integrity signals — never file contents. Local event logs are stored with restrictive filesystem permissions on your server.
6. How We Use the Data
- To issue, validate, renew and revoke license keys (contract performance).
- To deliver the Software, updates and critical security notices (contract performance).
- To provide technical support and diagnose compatibility problems (contract performance).
- To detect and prevent license fraud, key sharing and abuse (legitimate interests).
- To comply with tax, accounting and legal obligations (legal obligation).
We do not use your data for automated decision-making that produces legal effects concerning you, and we do not build marketing profiles. We do not send marketing email unless you opt in, and every such message carries an unsubscribe link.
7. Legal Bases (GDPR)
Where the EU or UK GDPR applies, we rely on: Article 6(1)(b) (performance of a contract) for licensing, delivery and support; Article 6(1)(f) (legitimate interests) for fraud prevention, service security and abuse detection; Article 6(1)(c) (legal obligation) for tax and accounting records; and Article 6(1)(a) (consent) for optional marketing, which you may withdraw at any time.
8. Sharing and Sub-processors
We do not sell your personal data and we have never sold or shared personal data for cross-context behavioural advertising. We disclose data only to:
- Our authorized Merchant of Record (MoR) — payment, tax, invoicing, subscription management.
- Hosting and email providers — to run the website, license service and support mailbox.
- Professional advisers and authorities — where required by law, court order or a valid legal request, or to establish, exercise or defend legal claims.
- A successor entity — in a merger, acquisition or sale of assets, subject to this policy.
9. International Transfers
We operate from Paraguay and our providers may process data in the European Union, the United States or elsewhere. Where data is transferred out of the EEA, the UK or Paraguay, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses, the UK Addendum where applicable, and the adequacy or contractual mechanisms permitted under Brazil’s LGPD.
10. Retention
- License records (email, HWID, order metadata) — for the life of the subscription and for up to five (5) years afterwards, to honour reactivation, disputes and statutory record-keeping.
- Tax and billing records — for the period required by applicable tax law.
- Support correspondence — up to twenty-four (24) months after the ticket closes.
- Web server logs — typically up to ninety (90) days.
- Local security event logs on your servers — retained and deleted entirely by you.
When a retention period ends, data is deleted or irreversibly anonymised.
11. Your Rights — GDPR (EU/UK)
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to: access your personal data; obtain rectification of inaccurate data; request erasure (“right to be forgotten”); restrict processing; object to processing based on legitimate interests; receive your data in a portable, machine-readable format; withdraw consent at any time without affecting prior lawful processing; and lodge a complaint with your local supervisory authority.
12. Your Rights — CCPA/CPRA (California)
If you are a California resident, you have the right to know what personal information is collected, used and disclosed and the categories of sources and recipients; to request deletion; to request correction; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not process sensitive personal information for purposes requiring a right to limit. Categories collected in the last 12 months: identifiers (email), commercial information (order and subscription records), and device identifiers strictly for licensing (HWID). We do not knowingly collect biometric, geolocation, health or financial account data.
13. Your Rights — LGPD (Brazil)
Under Brazil’s Lei Geral de Proteção de Dados (Law 13.709/2018) you may request confirmation of processing, access, correction, anonymisation or deletion of unnecessary or excessive data, portability, information about shared parties, and revocation of consent, and you may petition the Autoridade Nacional de Proteção de Dados (ANPD).
14. Exercising Your Rights
Data Subject Rights (GDPR / LGPD): We respect global privacy regulations. If you wish to exercise your “Right to be Forgotten”, request a copy of the data associated with your account, or demand the deletion of your profile and server logs from our active database, please contact us.
Send your request to contact@bastioncyber.online from the email address on your account. We respond within thirty (30) days, or one (1) month under the GDPR (extendable by two further months for complex requests, with notice). We may ask for information to verify your identity. Requests are free unless manifestly unfounded or excessive. You may use an authorised agent where the law permits. Note that deleting the email and HWID tied to an active license terminates that license.
15. Security
We apply measures appropriate to the risk, including encryption in transit, cryptographic signing of license artefacts, least-privilege access, restrictive filesystem permissions, hardened systemd service isolation, and minimisation — we simply do not collect what we do not need. No system is perfectly secure, and we cannot guarantee absolute security.
16. Breach Notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two (72) hours of becoming aware of it where the GDPR requires it, notify the ANPD as required by the LGPD, and inform affected customers without undue delay.
17. Cookies
The website uses only strictly necessary technical cookies and equivalent local storage required for the checkout flow and basic session handling. We do not use advertising, profiling or cross-site tracking cookies. The checkout overlay is served by our Merchant of Record and may set cookies under its own policy.
18. Children
The Software is a business product and is not directed to children. We do not knowingly collect personal data from anyone under 18 (or under 16 where the GDPR applies). If you believe a child has provided us data, contact us and we will delete it.
19. Changes to This Policy
We may update this policy. The “Last updated” date above always reflects the current version, and material changes will be notified by email where reasonably practicable. Continued use after the effective date constitutes acceptance.
20. Contact
Bastion Cyber — sole proprietorship, acting as data controller
Ciudad del Este, Alto Paraná Department, Republic of Paraguay
Privacy and data-rights requests: contact@bastioncyber.online
Payment and billing data: processed by our authorized Merchant of Record, under its own
privacy policy.
See also our Terms of Service and Refund Policy.