Legal

Privacy Policy

Effective date: August 20, 2026 · Last updated: August 20, 2026

This Privacy Policy explains how Badexy Technologies, LLC (“AquaGuard”, “we”, “us”) collects, uses, shares, and protects personal information when you use the AquaGuard water-safety platform - the website at aquaguardclean.com, the AquaGuard mobile applications, and related services (the “Service”). It should be read together with our Terms & Conditions.

We are the data controller for the personal information described here. If you have questions, contact us at info@badexytechnologies.com.

1. Information we collect

Information you provide

Email & password

When you create an account or sign in. Passwords are stored only as a salted hash (argon2) - we never store your password in plain text.

Account roles

Assigned to your account (e.g. consumer, regulator, manufacturer, distributor, retailer, admin).

Recall-alert subscription

Your email and an optional region if you subscribe to recall alerts.

Consumer reports

Details you submit about a suspected issue: brand name, optional product code, an optional location you enter, and a description of the issue. Reports are linked to your account.

Operator data

If you hold an operator role: product, inspection, recall, verdict, consignment, and risk-signal records you enter.

Support communications

Information you provide when you contact us.

Information collected automatically

Product codes you verify

To look up products and to build your on-device offline cache.

Device push token

If you enable push notifications in the mobile app, so we can send recall alerts to your device.

Local storage on your device

Your authentication tokens and an offline cache of products you have verified/synced, stored on your device so verification works without a connection. This stays on your device.

Basic technical data

Standard information such as IP address and request metadata processed by our hosting and security layers, and short-lived rate-limiting records, to operate and protect the Service.

Admin audit logs

Records of privileged administrative actions (e.g. role changes, account deletions), including actor and target identifiers, for security and accountability.

We do not intentionally collect special-category (sensitive) personal data. Please do not include health details or other sensitive information in free-text report fields unless necessary.

2. How we use your information

  • provide product verification and show safety, inspection, and recall information;
  • create and manage your account and authenticate you;
  • send recall and safety alerts you have subscribed to, and essential service messages;
  • receive, process, and route consumer reports and the safety signals derived from them;
  • operate the regulator, manufacturer, distributor, retailer, and administrator features;
  • detect risk, prevent abuse, enforce rate limits, and keep the Service secure;
  • maintain audit trails for privileged actions; and
  • comply with legal obligations and respond to lawful requests.

3. Legal bases (where GDPR or similar laws apply)

  • Contract - to provide the Service and manage your account.
  • Consent - for recall-alert subscriptions and push notifications (you can withdraw at any time).
  • Legitimate interests - to keep the Service secure and prevent fraud and abuse, balanced against your rights.
  • Legal obligation - where we must retain or disclose information by law.
  • Public interest - supporting product-safety and regulatory functions where applicable.

4. How we share information

We do not sell your personal information. We share it only as follows:

  • Regulators and authorised authorities. Consumer reports and the risk signals derived from them are made available to regulator accounts for triage and may inform enforcement action. This is a core purpose of the Service - if you submit a report, expect that regulators may see it.
  • Other operator roles, only as needed for the safety workflow (for example, a manufacturer sees the inspection behind a change to their own product’s status). Access is restricted by role.
  • Service providers (processors) acting on our instructions - for example our cloud hosting provider and our email delivery provider (used to send password-reset and recall emails), and push-notification networks. They may process data only to provide their service to us.
  • Legal and safety - where required by law, to comply with legal process, or to protect the rights, safety, and property of AquaGuard, our users, or the public.
  • Business transfers - in connection with a merger, acquisition, or sale of assets, subject to this Policy.

5. International transfers

Your information may be processed in the United States and other countries. Where we transfer personal data internationally, we use appropriate safeguards (such as standard contractual clauses) as required by applicable law.

6. Data retention

We keep personal information only as long as necessary for the purposes above. Account data is kept for the life of your account and deleted or anonymised within a reasonable period (typically 90 days) after closure, unless a longer period is required by law. Consumer reports and safety signals are retained while needed for safety and regulatory purposes and may be kept in de-identified form thereafter. Admin audit logs are retained for up to 24 months. Rate-limiting and other transient records are kept only briefly. Your on-device offline cache is controlled by you - clearing your browser or app storage removes it.

7. Your rights

Depending on where you live, you may have the right to access, correct, or delete your personal data; to object to or restrict certain processing; to withdraw consent; and to receive a portable copy of your data. You can:

  • update your account or unsubscribe from recall alerts at any time in the app;
  • disable push notifications in your device settings; and
  • request access to or deletion of your account and associated personal data by contacting info@badexytechnologies.com.

We will respond within the timeframe required by applicable law. You may also have the right to complain to your local data-protection authority.

8. How we protect information

We use technical and organisational measures appropriate to the risk, including argon2 password hashing, encrypted transport (HTTPS/TLS), token-based authentication, role-based access controls, rate limiting, and audit logging of privileged actions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Cookies and local storage

We use browser/app local storage to keep you signed in (authentication tokens) and to store your offline verification cache. The mobile app stores a push token if you enable notifications. We do not use the Service to run third-party advertising or cross-site tracking.

10. Children’s privacy

The Service is not directed to children under 18, and we do not knowingly collect their personal data. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, for material changes, take reasonable steps to notify you. Your continued use of the Service after changes take effect constitutes acceptance.

12. Contact

Badexy Technologies, LLC
5726 Lake Cyrus Blvd, Hoover, AL 35244, U.S.A.
Privacy enquiries: info@badexytechnologies.com