Legal

Privacy Policy

Effective Date: August 12, 2026Last Updated: August 12, 2026

1. Introduction and Scope

This Privacy Policy explains how Guardian IntelliTech Corporation ("Company," "we," "us," or "our") collects, uses, discloses, and protects information in connection with our website (guardianintellitech.com), our current corporate and investor-relations activities, and our planned products, including implantable and wearable devices (collectively, the "Devices") and our ShelterOS software platform ("ShelterOS"), together with related services (collectively, the "Services").

The Company is presently in a pre-commercial, development stage. As of the Effective Date above, no Device has been publicly deployed and the Company is not collecting biometric, health, or physiological data from any user. This Policy describes both our current practices, which today center on our corporate website and investor-facing communications, and the practices that will apply once Devices and ShelterOS are commercially available. Section 6 describes this in more detail. We will amend and reissue this Policy as our products move from development into commercial deployment.

This Policy applies to visitors to our website, prospective investors and partners who contact us, prospective and future users of our Devices, and ShelterOS customers and their authorized users.

2. Information We Collect Today

2.1 Information You Provide Directly

  • Contact information (name, email address, company or organization, and message content) submitted through our website contact form.
  • Information submitted in connection with an investor, partnership, or startup-program inquiry, including company details and the nature of the inquiry.
  • Account registration information for ShelterOS, including name, email, role, and organization, for customers who have been onboarded to the platform.

2.2 Information Collected Automatically

When you visit our website, we and our service providers automatically collect certain information through cookies and similar technologies, including your IP address, browser and device type, pages viewed, referring and exit pages, and the dates and times of your visits. We use this information to operate and secure our website, understand site usage, and, where applicable, measure the effectiveness of our investor and business-development communications.

3. Cookies, Analytics, and Your Choices

We use the following categories of cookies and similar technologies on our website:

  • Essential cookies, which are necessary for the website to function and cannot be disabled.
  • Analytics cookies, which help us understand how visitors use our site.
  • Advertising and cross-context behavioral advertising cookies, which may be used to deliver or measure the effectiveness of our marketing, including on third-party sites.

We do not sell personal information in exchange for money. However, our use of advertising and analytics cookies may constitute a "sale" or "sharing" of personal information under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), and a comparable form of "targeted advertising" or "sale" under the Colorado Privacy Act and similar laws in other states.

3.1 How to Opt Out

  • California and Colorado residents (and residents of other states with similar rights): You may opt out of the sale or sharing of your personal information and of targeted advertising by using the cookie preference tool available in our website footer, or by sending a request to [email protected].
  • Global Privacy Control: We recognize the Global Privacy Control ("GPC") signal. Where your browser or device sends a GPC signal, we will treat it as a valid opt-out request for that browser or device under the CCPA and Colorado Privacy Act.
  • Do Not Track: Because there is no accepted industry standard for responding to browser "Do Not Track" signals, we currently respond to GPC signals as described above rather than to Do Not Track headers.

Opting out of cookies will not affect our essential cookies, which are required for the website to operate.

4. How We Use Information

  • To operate, maintain, and secure our website and respond to inquiries submitted through our contact form, including startup-program, partnership, and investor-relations inquiries.
  • To communicate with ShelterOS account holders about their account and the Services.
  • To evaluate and improve our website, marketing, and business-development activities.
  • To comply with legal obligations and enforce our agreements.

5. How We Share Information

We do not sell personal information for money. Subject to Section 3 above regarding cookies and advertising technologies, we may share information as follows:

  • With service providers who perform functions on our behalf, such as website hosting, email delivery, and analytics, under contractual confidentiality and data-protection obligations.
  • With a ShelterOS customer, with respect to data relating to that customer's own use of the platform.
  • Where required by law, regulation, legal process, or governmental request.
  • In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy providing comparable protections.

6. Future Devices and Biometric or Health Data

This section describes our intended practices for the Devices described on our website. It applies once a Device is commercially available and actually collecting data from a user; it does not describe any data currently being collected, because no Device has yet been deployed.

Once a Device is commercially available, it may collect biometric identifiers and biometric information, and in some cases consumer health data, which may include neurological signals, cardiac data (such as heart rhythm, arterial pressure, and oxygen saturation), metabolic data (such as glucose and hydration markers), and other physiological data, together with associated device identifiers and timestamps ("Device Data").

Before any Device begins collecting Device Data from a user, we will:

  1. provide a clear, specific notice describing exactly what is collected and why;
  2. obtain the user's informed, written consent prior to collection, as required under applicable biometric privacy laws including the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and comparable laws in other states; and
  3. apply the retention and destruction schedule described in Section 8 below.

We will not use Device Data for product improvement, aggregated research, or the training of artificial intelligence or machine learning models unless we obtain separate, specific consent for that purpose at the time such use begins. We do not engage in any such use today.

7. International Users and Data Transfers

Guardian IntelliTech Corporation is a U.S. company, and our primary processing activities take place in the United States. Where we process personal data of individuals located in the European Economic Area, the United Kingdom, or Switzerland, we do so on the basis of your consent, the necessity of processing to perform a contract with you, our legitimate interests in operating and promoting our business, or compliance with a legal obligation, as applicable. Where we process special category data (such as health data) relating to individuals in these regions, we do so only with your explicit consent or another basis permitted under Article 9 of the General Data Protection Regulation.

Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States or another country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, as applicable.

Our representative for data protection matters relating to the European Economic Area and United Kingdom is: [to be designated].

8. Data Retention

We retain personal information collected through our website (such as contact-form and investor-inquiry submissions) for as long as reasonably necessary to respond to your inquiry and maintain our business records, and in any event for no longer than [INSERT PERIOD, e.g., 36 months] after our last interaction with you, unless a longer period is required by law.

Once Devices are deployed, biometric identifiers and biometric information will be permanently destroyed when the initial purpose for collection has been satisfied, or within [INSERT PERIOD] of the individual's last interaction with the Company or the Device, whichever occurs first, unless a longer retention period is required by law.

9. Your Privacy Rights

Depending on where you live, you may have the following rights with respect to your personal information: the right to know or access the personal information we hold about you; the right to request correction of inaccurate information; the right to request deletion of your information; the right to opt out of the sale or sharing of your information and of targeted advertising, as described in Section 3; the right to limit the use of sensitive personal information; the right not to receive discriminatory treatment for exercising your rights; and, where applicable under the GDPR, the right to data portability and the right to withdraw consent at any time.

To exercise any of these rights, contact us at [email protected]. We will verify your request using the information you provide and respond within 45 days, which we may extend by an additional 45 days when reasonably necessary, with notice to you. If we decline your request, we will explain why, and you may appeal that decision by replying to our response; we will respond to appeals within 60 days. If you are not satisfied with the outcome of an appeal, you may have the right to contact your state Attorney General or, for EEA/UK residents, your local data protection authority.

Authorized agents may submit a request on your behalf where permitted by law and accompanied by proof of authorization.

10. Data Security

We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal information, appropriate to our current stage as a development-stage company operating primarily a corporate website. These include the use of encrypted connections (HTTPS/TLS) for data submitted through our website, restricted internal access to personal information on a need-to-know basis, and confidentiality obligations for personnel and service providers who handle personal information.

11. ShelterOS Customer Data — Controller and Processor Roles

With respect to animal records, staff records, and other operational data that a ShelterOS customer enters into the platform, the ShelterOS customer is the data controller (or business, under applicable state law) and the Company acts as a service provider or processor on the ShelterOS customer's behalf. Requests to access, correct, or delete such data should generally be directed to the applicable ShelterOS customer in the first instance.

12. Children's Privacy

Our Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at [email protected] and we will take appropriate steps to delete it.

13. Changes to This Policy

We may update this Policy from time to time, including as our products move from development into commercial deployment. Material changes will be reflected by an updated "Last Updated" date and, where required by law, additional notice.

14. Contact Us

Questions about this Policy, or requests to exercise your privacy rights, may be directed to: [email protected].

General legal inquiries may be directed to: [email protected].

Guardian IntelliTech Corporation · P.O. Box 941272 · Houston, TX 77094