Legal Disclosures & Governance
Last Revised: September 2026 // Cybersecurity Governance
1. Corporate Registry Identification
Entity: BrightCyberGuard
Registered Activity: Proactive Cybersecurity Services, Threat Intelligence, Compliance Auditing & Incident Response
Registered Address: Aleja 3 Maja 9, 30-062 Kraków, Poland
Electronic Correspondence: [email protected]
Direct Line: +48 721 654 908
2. Privacy Policy & Data Processing (GDPR)
In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation), personal contact data submitted through our consultation forms is processed exclusively for client communication, threat assessment delivery, security service provisioning, and statutory tax reporting obligations.
BrightCyberGuard does not sell, rent, or distribute personal information to unauthorized third-party data brokers. All submitted data is securely retained within encrypted EU-hosted cloud infrastructure in full compliance with ISO/IEC 27001 information security standards.
You retain the right to access, rectify, port, or erase your personal data at any time by contacting our Data Protection Officer at [email protected]. We will respond to all data subject access requests within the statutory 30-day window.
Data retention periods are defined as follows: engagement records are retained for 5 years following contract completion to satisfy statutory audit obligations; prospect communication data is retained for 24 months from last interaction; and marketing consent records are retained indefinitely until withdrawal.
3. Terms of Service
All cybersecurity services, threat intelligence reports, and compliance audit deliverables provided by BrightCyberGuard are governed by explicitly contracted Statements of Work (SOW) executed between the Client and BrightCyberGuard.
Upon complete settlement of all agreed commercial invoices, BrightCyberGuard grants the Client a perpetual, irrevocable, worldwide license to all deliverable materials, including threat reports, compliance documentation, and remediation playbooks generated during the engagement.
BrightCyberGuard maintains strict confidentiality regarding all client infrastructure details, vulnerability assessments, and incident response activities. All engagement data is encrypted at rest and in transit, and access is restricted to authorized personnel on a need-to-know basis.
The Client acknowledges that cybersecurity services operate on a best-effort basis. While BrightCyberGuard employs industry-leading methodologies and tools, no security service can guarantee absolute protection against all possible threats. BrightCyberGuard shall not be held liable for zero-day exploits or unforeseen attack vectors that circumvent established defense controls.
Either party may terminate an engagement with 30 days written notice. All completed work up to the point of termination shall be delivered to the Client, and any outstanding invoices for completed milestones shall remain due and payable.
5. Refund & Reimbursement Policy
BrightCyberGuard operates on a milestone-based payment structure. Upon engagement initiation, a 40% deposit is collected to secure analyst allocation and infrastructure provisioning. This deposit is non-refundable once resource allocation has commenced.
Remaining milestone payments become due upon documented delivery of each contractually defined deliverable. If a delivered deliverable materially fails to meet the specifications defined in the Statement of Work, the Client may request a remediation review within 14 days of delivery.
If remediation is unsuccessful after two revision cycles, the Client is entitled to a proportional refund for the specific undeliverable milestone, calculated as a percentage of the total engagement value. Refund requests must be submitted in writing to [email protected] with supporting documentation of the specification deviation.
All refunds are processed within 14 business days of approval and are returned via the original payment method. Retainer subscriptions may be cancelled with 30 days notice, with any prepaid monthly period fulfilled before cancellation takes effect.