Privacy Policy
Last updated:
What personal data Ward handles, why, for how long, who receives it and how to exercise your rights.
In short
- Ward analyzes companies using public sources. The personal data we handle is limited: your email and domain (if you give them), your account, and what you write to Ward AI or upload to the Analyzer.
- We don’t sell personal data, we don’t share it for advertising, and we don’t build profiles of people.
- The website uses only essential cookies and local storage: no analytics, advertising or third-party cookies (Cookie Notice).
- Some providers are in the U.S. We tell you which ones and what safeguard applies (GDPR, the EU-U.S. Data Privacy Framework or standard contractual clauses).
- Each kind of data has its own retention period: the waitlist up to 12 months, the trial report 30 days, Ward AI conversations 90 days.
- To access, copy, correct, delete, object to or port your data, email onboarding@resend.dev. If you live in California, see “California residents” below.
1.Who is responsible
Ward (“Ward”) is the controller of the personal data described in this policy, except where it acts as a processor (see “When Ward acts as a processor”).
- Controller
- Ward
- Privacy contact
- onboarding@resend.dev
2.What Ward does, in plain terms
Ward looks at how a company appears from the internet and explains what someone who wanted to attack it could take advantage of. It does this with public and technical sources. It doesn’t attack anyone and it doesn’t need access to your systems.
Ward hasn’t opened yet. Today we only handle data from the website and the waitlist. The rest of this policy describes the service that will open, and its processing starts when it opens.
What it does:
- Queries public sources about the domain: DNS records, certificate records, domain registration records and third-party databases (reputation lists, vulnerabilities, leaks).
- Visits your home page once, the way a browser would, and requests three standard public files (robots.txt, sitemap.xml and security.txt). It doesn’t follow links or probe other paths.
- Monitors the domains you subscribe to and emails you about changes.
- Ward AI answers your questions about findings and about the company’s situation.
- The Analyzer reads an email, a link or a file you send it from the inside, without running it or opening the link.
What it never does: scan ports, try passwords, send malicious payloads, or get into your devices.
3.Where the data goes
The diagram summarizes what comes in, what is looked up outside, and what is kept and for how long. The same content is written out below it.
- In
- What you see and fill in on the website (visits, forms and the waitlist).
- Your email and, if you enter it, your domain.
- Your account, what you do in the dashboard, and what you write to Ward AI.
- The emails, links and files you send to the Analyzer.
- Looked up outside
- Public and technical sources about the domain (DNS, certificates, third-party lists), with only what each query needs.
- Our providers for hosting, email, database, artificial intelligence and, if enabled, Google Web Risk.
- Kept for
- The waitlist, up to 12 months. The trial report, 30 days.
- The session, 30 days. Ward AI conversations, 90 days.
- The Analyzer: the email body and code excerpts, 7 days; the rest, about 13 months.
4.What data we handle and why
For each processing activity we state what we use the data for, the legal basis (Article 6 GDPR), what the data is, how long we keep it, who receives it and whether it leaves the European Economic Area (EEA).
| Processing | Legal basis | How long |
|---|---|---|
| Waitlist | Consent (Art. 6.1.a) | Up to 12 months, or until you unsubscribe |
| Website and security | Legitimate interests (Art. 6.1.f) | Hosting logs; limits, up to one day |
| Trial report | Legitimate interests (Art. 6.1.f) | 30 days |
| Account and sign-in | Contract (Art. 6.1.b) | While the account is active |
| Dashboard | Contract (Art. 6.1.b) | While the account is active; events, 365 days |
| Analyzer and Ward AI | Contract (Art. 6.1.b) | Analyzer: 7 days and 13 months; Ward AI: 90 days |
Waitlist (launch notice)
- Purpose
- Telling you once, when Ward opens. If you also enter a domain in the home page notice, we will scan it when we open and send the report to that email. We don’t use the email or the domain for anything else and we don’t sell or share them.
- Legal basis
- Your consent (Art. 6.1.a), given when you submit the form, which states what the email is used for. You can withdraw it at any time by emailing onboarding@resend.dev; this doesn’t affect what was processed before.
- Data
- Your email; the plan you were interested in (if you choose one); the domain (only if you enter it); the language, the form you signed up from, and the date. In our database, also a keyed hash (HMAC) of your IP address, only to prevent abuse.
- Retention
- Until the launch notice or until you unsubscribe, and at most 12 months after you signed up. With our own database, the daily cleanup deletes expired entries. Until we have one, contacts are kept in Resend, and we delete them by hand when the period ends.
- Recipients
- Our database or, until we have one, a Resend contact list (processor). Hosting is provided by Vercel.
- Transfers
- Yes, to the U.S. (Resend and Vercel), with the safeguards described in the section “Processors and sub-processors”. Bot protection: a hidden field, a minimum fill time and a limit on sends per IP. If the email was already on the list, the response is the same, so we don’t reveal who is on it.
Website visits and security
- Purpose
- Serving the website, keeping it secure and preventing abuse (for example, mass use of a form or of the trial report).
- Legal basis
- Legitimate interests (Art. 6.1.f) in the security and continuity of the service. You can object by writing to the contact address.
- Data
- IP address and technical details of each request (browser, date, page), which the hosting provider records in its logs. For usage limits we keep only a keyed hash (HMAC) of the IP, never the IP itself. A strictly necessary cookie remembers the language (see the Cookie Notice).
- Retention
- Hosting logs, for the period Vercel sets. Limit counters last as long as each limit’s window (from one hour to one day) and are deleted in the daily cleanup.
- Recipients
- Vercel (hosting).
- Transfers
- Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.
Trial report (free scan of one domain)
- Purpose
- Scanning the domain you give us and showing you the result: the score, how many problems there are and how you could be attacked. No account or email is needed.
- Legal basis
- Legitimate interests (Art. 6.1.f) in providing the scan you ask for and in preventing its use against third parties. The impact is minimal: only public technical information about companies is consulted. You can object by writing to the contact address.
- Data
- The domain; the technical results (DNS, certificates, web headers…); a random browser identifier (a strictly necessary cookie; in the database we only store its hash); and a keyed hash (HMAC) of the IP for limits.
- Retention
- 30 days. If you create an account from the same browser within 7 days after the scan, the scan moves to your account.
- Recipients
- Vercel, the database, Inngest (background tasks, internal identifiers only), Google Web Risk if enabled, and the sources described in “External data sources.”
- Transfers
- Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.
Accounts and sign-in
- Purpose
- Creating and managing your account, signing in with a one-time link (no password), and telling people and organizations apart.
- Legal basis
- Performance of a contract or pre-contract steps at your request (Art. 6.1.b). Account security is based on legitimate interests (Art. 6.1.f).
- Data
- Email, name (optional), language, sign-up and last-sign-in dates, your role in the organization and the organization’s name. For sign-in links and sessions we store only a hash of the code, never the code itself.
- Retention
- While the account is active. Sign-in links are valid for 15 minutes and are deleted in the daily cleanup; the session lasts 30 days. If you ask us to close the account, we delete its data, except what the law requires us to keep, which is blocked while claims could still be made.
- Recipients
- The database, Resend (sends the sign-in link) and Vercel.
- Transfers
- Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.
Dashboard
- Purpose
- Providing the service you subscribe to: regularly monitoring domains, showing findings and their history, managing them with your team, alerting you by email (immediate alerts, a weekly summary and expiry notices) and receiving DMARC reports.
- Legal basis
- Performance of a contract (Art. 6.1.b).
- Data
- Domains and the organization; results and findings; how they are handled (status, notes, comments and the files you attach: images or PDFs); the event history; your alert preferences; integration keys you add (encrypted); and, in aggregated DMARC reports, the IP addresses of sending servers and sender domains.
- Retention
- While the account is active. Event history, 365 days; DMARC reports, 13 months by default. If a domain or an organization is deleted, everything connected to it is deleted too.
- Recipients
- Vercel, the database, Inngest (scheduled tasks), Resend (alerts) and external sources.
- Transfers
- Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.
Alert recipients named by a customer
- Purpose
- Sending alerts or the weekly summary to people the customer names (for example, its IT lead or its adviser).
- Legal basis
- Legitimate interests (Art. 6.1.f) of the customer and of Ward in the information reaching the person who must act. The person first receives a confirmation email and nothing is sent until they confirm; they can unsubscribe with one click in each message.
- Data
- Email, language, which alerts they receive and from what severity, the confirmation date and a hash of the unsubscribe code.
- Retention
- Until the person unsubscribes or the customer removes them.
- Recipients
- The database and Resend.
- Transfers
- Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.
Monitoring the team’s email accounts
- Purpose
- Alerting the customer if the company email accounts it names appear in data breaches or on devices infected with malware.
- Legal basis
- The customer is the controller and must have its own legal basis (usually its legitimate interest in protecting its systems); Ward acts as processor. The customer must inform the people concerned.
- Data
- Email addresses, name (optional), the result of the lookup (name and date of the breach, types of data affected) and what you do about it. Passwords found are never stored.
- Retention
- While the account is being monitored and the customer’s account is active.
- Recipients
- The breach sources we query receive the domain or the addresses to check (see “External data sources”), in addition to our infrastructure providers.
- Transfers
- Yes, to the U.S., through our providers, with the safeguards described in the section “Processors and sub-processors”.
Ward AI’s Analyzer (suspicious emails, links and files)
- Purpose
- Analyzing a suspicious email (an .eml file or pasted source), a link or a file to say whether it looks like fraud, showing the result in the dashboard, alerting administrators if it is dangerous, and grouping the analyses of the same campaign.
- Legal basis
- Performance of a contract (Art. 6.1.b). The customer is responsible for the content it uploads, which may include third parties’ personal data (for example, the sender), and Ward acts as processor. The team must be informed.
- Data
Email: the subject and sender (trimmed), the sanitized body text stored encrypted, and the technical details of the analysis (authentication, domains, disabled links, and the name, type, size and fingerprint of attachments). The .eml you upload is not stored, and attachments are never stored or opened.
Link: the URL without query parameters or fragment, the registrable domain and the technical signals. The full URL with parameters is not stored.
File: never the file itself. Only the trimmed name, the real type detected, the size, the SHA-256 fingerprint and the signals from static analysis. If the file contains suspicious code, short excerpts (up to 1,500 characters) are stored encrypted, never the whole code.
In all three cases: who ran the analysis (only owners, administrators and that person can see it), the verdict, the reasons and, if marked, the answer to “Have you clicked yet?”.
- Retention
- The email body and code excerpts, 7 days. The rest of the analysis (verdict, signals and metadata), 395 days (about 13 months).
- Recipients
- OpenRouter and the AI model receive a summary of the signals and, if there is any, sanitized and delimited text (never the file, nor the URL with parameters, nor email addresses; for code, up to 2,000 characters). Link addresses without parameters are checked against Google Web Risk if that source is enabled. Ward reads files from the inside, code included, but never visits a link or runs a file.
- Transfers
- Yes, to the U.S. (OpenRouter, the model provider, Google and our infrastructure), with the safeguards described in the section “Processors and sub-processors”.
Ward AI (assistant)
- Purpose
- Helping you understand and fix a finding step by step (the finding chat) and answering questions about the company’s situation (general chat).
- Legal basis
- Performance of a contract (Art. 6.1.b): used only when the person opens the chat.
- Data
- Your messages and the context we send with them: the finding you ask about or, in the general chat, a summary of the company’s situation (domains, scores, titles of the most serious findings and counts; no secrets, technical evidence or third parties’ personal data). We also keep usage counters, without content. Don’t enter passwords or unnecessary personal data.
- Retention
- 90 days for conversations and their messages.
- Recipients
- OpenRouter, which routes the request to Anthropic’s model (today, Claude Haiku 5.5). We ask that only providers that don’t collect the data be used (data_collection = deny), and OpenRouter says it doesn’t train on it. Ward AI also writes explanations of public vulnerabilities (CVEs) from public data, with no customer data.
- Transfers
- Yes, to the U.S. (OpenRouter and Anthropic), with the safeguards described in the section “Processors and sub-processors”.
Questions and requests you send us
- Purpose
- Answering what you ask us or request, including the exercise of your rights.
- Legal basis
- Legitimate interests (Art. 6.1.f) in replying to whoever writes to us and, for rights requests, legal obligation (Art. 6.1.c).
- Data
- Your email, your name if you give it, the content of the message and our reply.
- Retention
- The time needed to handle the request and, afterwards, blocked while claims could still be made.
- Recipients
- The company’s email provider, as processor.
- Transfers
- We don’t move them out of the EEA; if the email provider processes them outside it, it does so with safeguards equivalent to those in this section.
5.External data sources
To scan a domain, Ward queries public and technical sources (DNS, domain registries, certificates) and third-party databases (reputation lists, vulnerabilities, leaks). These sources only receive what each query needs: usually a domain name, an IP address or a web address. This is company data and, except in isolated cases (for example, a sole trader with a domain in their own name), it is not personal data. The customer’s website receives a single visit to its home page and three standard public files. The full list, with licenses, is on the Sources page.
When a source receives personal data (for example, the email addresses being monitored), we treat it as a sub-processor. These are the ones active today, with their country (the list is generated from our source registry, so it only names the ones switched on):
- Cert Spotter (United States)
- GitHub (United States)
Where the country says “to be confirmed,” we are confirming it. The safeguards for each transfer are described in the next section.
6.Processors and sub-processors
These are the providers that process data on our behalf. With each one we sign the data processing agreement required by Article 28 GDPR. Some only take part when the related feature is switched on, and we say so. The links go to the provider’s documents where we checked the safeguard (consulted on October 8, 2026).
Vercel
- Company
- Vercel Inc.
- Location
- United States (and other countries where Vercel or its providers run infrastructure)
- What it does
- Hosting and running the website and the service.
- Data it receives
- Everything that goes through the website: the IP address and technical details of each request, and what is sent in forms.
- Transfer safeguard
- Vercel states that it is certified under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of July 10, 2023), and its data processing agreement also includes the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914).
Inngest
- Company
- Inngest Inc.
- Location
- United States (its databases are located there)
- What it does
- Runs the scheduled and background jobs: periodic scans, alerts and the daily cleanup.
- Data it receives
- Internal identifiers (of domains, scans and submissions) and counts. We don't send it email addresses or the content of the analyses.
- When it is involved
- Only once there are accounts and scheduled jobs, that is, after launch.
- Transfer safeguard
- Standard contractual clauses of the European Commission or another appropriate safeguard under Article 46 of the GDPR.
Resend
- Company
- Plus Five Five, Inc. (Resend)
- Location
- United States
- What it does
- Sends our emails (sign-in links, alerts and summaries) and, while there is no database of our own, stores the waitlist as a contact list (the email and, if configured, the domain entered in the notice on the home page).
- Data it receives
- Recipient email addresses, the content of each message and, for the waitlist, only the email address (and the domain, if one was entered and we have set Resend to keep it).
- Transfer safeguard
- Resend states that it complies with the EU-U.S. Data Privacy Framework and its UK Extension, and its data processing agreement includes the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914).
OpenRouter
- Company
- OpenRouter, Inc.
- Location
- United States
- What it does
- Artificial intelligence gateway: receives what we send to Ward AI (chat and Analyzer) and routes it to the model.
- Data it receives
- Chat messages and the context we send with them, and the summary of signals from what is analyzed with Analyzer. See “Ward AI” and “Analyzer” above.
- When it is involved
- Only when Ward AI is on.
- Transfer safeguard
- OpenRouter says in its privacy policy that, to transfer data outside the European Economic Area, it relies on standard contractual clauses approved by the European Commission (Article 46 GDPR). We also ask, in every request, that it only use providers that don't collect the data (the “data_collection: deny” option), and OpenRouter says it doesn't use inputs or outputs to train models.
Anthropic
- Company
- Anthropic PBC
- Location
- United States
- What it does
- Provider of the language model we use today (Claude Haiku 5.5), the one that writes Ward AI's replies. Ward doesn't contract with Anthropic: it receives requests through OpenRouter.
- Data it receives
- The same that OpenRouter routes to the model.
- When it is involved
- Only when Ward AI is on.
- Transfer safeguard
- Standard contractual clauses of the European Commission or another appropriate safeguard under Article 46 of the GDPR.
Google (Web Risk)
- Company
- Google Cloud
- Location
- United States (and other countries where Google runs infrastructure)
- What it does
- Web Risk service: says whether a web address is flagged as dangerous (malware or phishing).
- Data it receives
- The web address being checked (your domain's or, in Analyzer, a link's without query parameters or fragment).
- When it is involved
- Only when this source is on.
- Transfer safeguard
- Google Cloud's data processing addendum applies the European Commission's standard contractual clauses to transfers outside the EEA, unless Google adopts another recognized transfer solution, in which case it informs us.
Base de datos
- Location
- To be defined (EU or United States, depending on the provider)
- What it does
- Managed Postgres where accounts, domains, scans and everything else described in this policy are stored. During the pre-launch there may not be one.
- Data it receives
- All account and service data.
- When it is involved
- Only once there is a database. Before using it, this section will name the provider.
- Transfer safeguard
- Standard contractual clauses of the European Commission or another appropriate safeguard under Article 46 of the GDPR.
If we turn on phishing-mailbox intake (which would use Cloudflare to receive messages) or payments (Stripe), we will add them to this list before using them. Changes of provider are reflected here with the update date.
7.International transfers
Some of our providers are in the U.S. or process data there. To make those transfers lawful, we rely on, depending on the provider:
- the EU-U.S. Data Privacy Framework, which the European Commission found adequate on July 10, 2023 (Implementing Decision (EU) 2023/1795), for certified companies;
- the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914); or
- another appropriate safeguard under Article 46 of the GDPR.
Each processor entry says which one applies. You can ask for a copy of the safeguards by emailing onboarding@resend.dev. More information on the Data Privacy Framework is at dataprivacyframework.gov(opens in a new tab).
8.How long we keep data
Each processing activity’s period is in its entry above. In summary:
| Data | Period |
|---|---|
| Waitlist | Until the launch notice or unsubscribe, and at most 12 months |
| Account and service data | While the account is active |
| Sign-in link | 15 minutes, single use |
| Session | 30 days, or until you sign out |
| Trial report | 30 days (7 days to move it to an account) |
| Event history | 365 days |
| DMARC reports | 13 months by default |
| Ward AI conversations | 90 days |
| Analyzer: email body and code | 7 days |
| Analyzer: the rest of the analysis | About 13 months |
| Hosting logs | The period set by the provider |
After those periods we delete the data or anonymize it. What the law requires us to keep is blocked and used only to handle possible claims.
9.Security and breach notification
- All communications are encrypted (HTTPS).
- For access codes and sessions we store only an encrypted hash, and for IP addresses only a keyed hash (HMAC), never the value itself.
- The body of analyzed emails, code excerpts and integration keys are stored encrypted.
- Each organization’s data is separated in the database with row-level security: one organization cannot see another’s data.
- Only people who need the data to provide the service can access it.
If a security breach affects personal data, we will notify the Spanish Data Protection Agency within 72 hours where required (Article 33 GDPR), and the people affected without undue delay where the risk is high (Article 34). For U.S. residents, we will notify them as their state’s laws require.
10.When Ward acts as a processor
When a customer entrusts us with other people’s data (the team emails being monitored, alert recipients, the content the Analyzer examines, notes and attachments), the customer is the controller of that processing and Ward acts as processor: it only handles that data to provide the service to the customer and on its instructions, with the security measures in this policy and with the sub-processors listed here. The customer must have a legal basis for it and inform the people concerned.
The data processing agreement (Article 28 GDPR) will be published before the paid plans launch and is accepted when you subscribe.
11.Your rights (GDPR)
You can exercise these rights at any time, free of charge:
- access: to know what data we hold about you and receive a copy;
- rectification: to correct inaccurate data;
- erasure: to have your data deleted when it is no longer needed, you withdraw consent, or there is no other basis for processing it;
- objection: to object to processing based on legitimate interests;
- restriction: to ask us to stop using the data while a question is resolved;
- portability: to receive the data you gave us in a common format;
- withdrawal of consent, where processing is based on consent (for example, the waitlist).
To exercise them, email onboarding@resend.dev and tell us which right you want to use. We may ask you to verify your identity. We reply within one month at most (extendable by two more months if the request is very complex; we would tell you). If a customer of ours is the controller of the data, we will tell you whom to contact.
If you believe we don’t process your data lawfully, you can complain to the Spanish Data Protection Agency (www.aepd.es(opens in a new tab); electronic office: sedeagpd.gob.es(opens in a new tab)). We would rather you wrote to us first so we can try to resolve it. If you live in another EU country, you can also contact the data protection authority there.
12.Automated decisions and profiling
The Ward Score and the findings are calculated by an automated system from public technical signals about a domain, that is, about a company and its infrastructure, not about a person. They don’t produce legal effects for anyone and don’t affect anyone in a similar way (Article 22 GDPR): they help the company fix its problems, and nobody uses them to decide about a person. We also don’t build profiles of people for commercial purposes.
The same is true of the Analyzer’s verdict on an email, link or file and of Ward AI’s answers: they are automated guidance that a person reviews and applies. If you think a result is wrong, tell us. Usage limits automatically and temporarily block excessive requests, with no further consequences.
13.Children
Ward is a service for businesses and is not directed to anyone under 16. We don’t knowingly collect data from anyone under that age. If we find we have, we delete it. We also don’t knowingly collect personal information from children under 13, as the Children’s Online Privacy Protection Act (COPPA) requires.
14.California residents (CCPA and CPRA)
This section is the notice for California residents required by the California Consumer Privacy Act (CCPA), as amended by the CPRA. It explains which categories of information we collect, why, and to whom we disclose it.
Categories we collect
| Category | Examples at Ward | Collected? |
|---|---|---|
| Identifiers | Email, name (optional) and an encrypted hash of your IP address | Yes |
| Account data | Role in the organization, language and organization name | Yes |
| Technical and usage data | Logs of each request to the hosting provider, access dates | Yes |
| Content you send us | Messages to Ward AI; emails, links and files sent to the Analyzer; notes and attachments | Yes |
| Commercial information | Plan you subscribe to or are interested in | Yes |
| Sensitive personal information | We don’t ask for it. An analyzed email or file may contain it, and it is handled only for the analysis | We don’t seek it |
| Inferences and profiles | We don’t build profiles of people | No |
Where it comes from
From you (when you sign up, use the dashboard or write to us), from your browser and device (the website and its technical logs), and from public sources about companies.
Why we use it and to whom we disclose it
For the purposes of each processing activity in this policy, not for advertising. We disclose it only to our processors (hosting, email, database, artificial intelligence and, if enabled, Google Web Risk), and only to provide the service.
Sale and “sharing”
We don’t sell personal information or share it for cross-context behavioral advertising, and we don’t use advertising trackers. For that reason there is no “Do Not Sell or Share” link and we have nothing to opt out of. We don’t use sensitive personal information beyond what the service requires.
Your rights
- To know what personal information we have about you, and to receive a copy.
- To ask us to correct it or delete it, except what the law requires us to keep.
- Not to be treated differently (in price or service quality) for exercising your rights.
To exercise them, email onboarding@resend.dev. We may ask for information to verify your identity, and an authorized agent may submit the request for you. We respond within 45 days at most; if we need more time, we may extend it by another 45 days and tell you. If we deny a request, you can ask us to review it. A Global Privacy Control (GPC) signal from your browser changes nothing, because we don’t sell or share personal information.
15.Other U.S. states
Several states have privacy laws similar to California’s (for example, Virginia, Colorado, Connecticut, Utah and Texas). Depending on the state and the thresholds each law sets, they give similar rights: to know what data we hold, to obtain a copy, to correct or delete it, and to opt out of targeted advertising, sale or certain profiling. We will handle those requests through the same address, onboarding@resend.dev, using a procedure similar to the one for California.
16.Commercial emails
The emails we send to tell you about the launch or the launch offer are commercial. We send them only to people who have consented (Article 21 of Spain’s LSSI-CE and the GDPR). We also comply with the U.S. CAN-SPAM Act: each email identifies Ward and the company, includes our postal address and a working unsubscribe link, and we process each unsubscribe within 10 business days.
17.Changes to this policy
We may update this policy, for example when we open a new feature or change providers. The current version is the one on this page, with the date of the last update at the top. If a change is significant and we have your email through an account, we will tell you before it takes effect.