Privacy Policy

Last updated: July 2026

1. Data We Process

MuleGuard processes compliance-related data including customer screening information, transaction data, sanctions screening results, KYC/KYB profiles, and case management data. This data is processed to provide compliance, risk detection, and regulatory reporting services.

2. Data Residency

Customer data is stored in the deployment region selected by the client. We support cloud, private cloud, on-premise, hybrid, and air-gapped deployment models. Data residency is configurable per tenant.

3. Data Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Secrets are managed via a secure vault. Encryption keys are rotated periodically.

4. Data Retention

Data retention periods are configurable per tenant and per data type, in accordance with applicable regulatory requirements. Retention policies are enforced automatically via scheduled automation.

5. Access Control

Access to customer data is governed by role-based access control (RBAC). All access is logged in an immutable audit trail. Four-eyes approval is enforced for sensitive operations.

6. Your Rights

Under GDPR, PDPA, and other applicable regulations, you have the right to access, rectify, erase, and export your personal data. Contact your account administrator to exercise these rights.

7. Sub-Processors

MuleGuard uses cloud infrastructure providers for hosting. A list of sub-processors is available upon request. All sub-processors are bound by data processing agreements.

8. Contact

For privacy questions, contact your account manager or visit our Trust Center.