← Back to Shieldome

Data Processing Agreement

Last updated: August 7, 2026 · Effective: August 7, 2026 · Version 2.0

This DPA covers both Shieldome products: app.shieldome.com (SaaS platform) and shieldomescout.com (vulnerability assessment as a service). It is incorporated by reference into the Shieldome Terms of Service.
Contents
  1. Parties and Definitions
  2. Scope and Roles
  3. Processor Obligations
  4. Controller Obligations
  5. Sub-processors
  6. International Transfers
  7. Security Measures
  8. Data Retention and Deletion
  9. Data Subject Rights
  10. Personal Data Breach Notification
  11. Audit Rights
  12. Liability
  13. Termination
  14. Governing Law
  15. Contact

1. Parties and Definitions

"Shieldome" means NEMANJA MILJKOVIĆ PR RAČUNARSKO PROGRAMIRANJE SHIELDOME KRAGUJEVAC, a sole trader registered under the laws of the Republic of Serbia, operating the services at app.shieldome.com and shieldomescout.com ("Service Provider").

"Customer" means the legal entity or individual who has accepted the Shieldome Terms of Service ("Controller" in respect of Personal Data it submits to the platform).

"Personal Data", "Data Subject", "Processing", "Processor", "Controller", and "Supervisory Authority" have the meanings ascribed to them in Regulation (EU) 2016/679 (GDPR) and the Serbian Law on Personal Data Protection (LPDP).

"Services" means the web vulnerability assessment and performance scanning platform provided by Shieldome to the Customer under the Terms of Service.

"Sub-processor" means any third party engaged by Shieldome to carry out Processing activities on behalf of the Customer.

2. Scope and Roles

This DPA governs the Processing of Personal Data by Shieldome in connection with the provision of the Services. Shieldome acts in dual capacity:

2.1 Shieldome as Processor

With respect to scan data submitted by the Customer — including target URLs, IP overrides, scan results, finding details, and monitored domains — Shieldome acts as a Processor. Processing of such data is carried out solely on the Customer's documented instructions and for the purpose of delivering the Services.

2.2 Shieldome as Controller

With respect to account data, billing data, and usage logs — including the Customer's email address, name, payment records, and login activity — Shieldome acts as an independent Controller. Such Processing is governed by Shieldome's Privacy Policy at shieldome.com/privacy.

2.3 Categories of Personal Data Processed as Processor

CategoryExamples
Scan targets URLs, domain names, IP addresses submitted by the Customer for scanning
Scan results Vulnerability findings, severity ratings, HTTP response data, SSL certificate data
Configuration data Webhook URLs (encrypted), SSO secrets (encrypted), scan tags and notes
Integration metadata Alert configurations, monitored domain lists, PDF report content

The Customer confirms that scan targets and associated data do not intentionally include special categories of data as defined in GDPR Art. 9, nor Personal Data of minors.

3. Processor Obligations

Where Shieldome acts as Processor, it shall:

  1. Process Personal Data only on documented instructions from the Customer, unless required to do so by applicable law (in which case Shieldome will notify the Customer before Processing, unless prohibited by law).
  2. Ensure that persons authorised to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Art. 32 (see Section 7).
  4. Respect the conditions for engaging Sub-processors (see Section 5).
  5. Take appropriate measures to assist the Customer in responding to requests from Data Subjects exercising their rights.
  6. Assist the Customer in ensuring compliance with its obligations under GDPR Arts. 32–36 (security, breach notification, DPIAs, prior consultation).
  7. At the Customer's choice, delete or return all Personal Data after the end of the provision of Services, and delete existing copies unless applicable law requires storage.
  8. Make available to the Customer all information necessary to demonstrate compliance with the obligations in GDPR Art. 28 and allow for and contribute to audits (see Section 11).

4. Controller Obligations

The Customer, as Controller, shall:

  1. Ensure it has a lawful basis under applicable data protection law for submitting Personal Data to Shieldome for Processing.
  2. Ensure it holds valid authorisation to scan the target systems submitted to the platform.
  3. Provide accurate and complete instructions for Processing and notify Shieldome promptly of any changes to those instructions.
  4. Comply with applicable data protection laws in its own capacity as Controller.

5. Sub-processors

The Customer provides general written authorisation for Shieldome to engage Sub-processors. Shieldome will maintain an up-to-date list of Sub-processors and notify the Customer of any intended changes (additions or replacements) at least 14 days in advance. The Customer may object to a new Sub-processor on reasonable grounds within this period.

Current Sub-processors are listed below. Each Sub-processor is bound by a data processing agreement with obligations no less protective than those in this DPA.

Sub-processorPurposeLocationTransfer Safeguard
Amazon Web Services, Inc.
(ECS Fargate, RDS PostgreSQL, ElastiCache Redis, S3)
Cloud hosting, database, caching, file storage EU (Frankfurt, eu-central-1) — within the EEA No transfer mechanism required (data remains in EEA). AWS DPA applies.
Resend Inc. Transactional email delivery (scan notifications, alerts, billing receipts) United States EU Commission Standard Contractual Clauses (Decision 2021/914, Module 2 Controller→Processor). See also the Transfer Impact Assessment.
Google LLC OAuth 2.0 authentication ("Sign in with Google") United States EU Commission Standard Contractual Clauses. Only OAuth token exchange data is transmitted; no scan data is shared with Google.

6. International Transfers

All account and scan data is stored in AWS eu-central-1 (Frankfurt, Germany) — within the European Economic Area. No transfer mechanism is required for this storage.

Shieldome is incorporated in Serbia. Serbia benefits from an EU adequacy decision under GDPR Art. 45 (Commission Decision 2013/65/EU). Transfers of Personal Data from the EU/EEA to Shieldome in Serbia are therefore permitted without additional safeguards.

For transfers to Resend (US) and Google (US), Shieldome relies on the EU Commission Standard Contractual Clauses (2021/914). A Transfer Impact Assessment (TIA) is available at /legal/transfer_impact_assessment.html and concludes that the risk of government access to the limited data involved is LOW.

Where the Customer is itself an EU Controller transferring Personal Data to Shieldome as Processor, the applicable Module 2 SCC Annexes are provided at /legal/scc_annexes.html.

7. Security Measures

Shieldome implements and maintains the following technical and organisational security measures in accordance with GDPR Art. 32:

  • Encryption in transit: All communications between users and the platform use HTTPS/TLS 1.2 or higher.
  • Encryption at rest: Sensitive fields (webhook URLs, SSO client secrets) are encrypted using AES-256 (Fernet symmetric encryption). Database storage is encrypted at the volume level by AWS.
  • Password security: User passwords are hashed using bcrypt with a minimum work factor of 12. Plaintext passwords are never stored.
  • Two-factor authentication: TOTP-based 2FA is available to all users and enforced for administrator accounts.
  • Network isolation: Databases and caching services run in AWS VPC private subnets with no direct public internet access.
  • Role-based access control: Internal access to customer data is restricted to personnel with a documented need. Access rights are reviewed periodically.
  • API key security: API keys are stored in hashed form only; the plaintext key is shown once at creation and not retained.
  • Session security: Session cookies carry HttpOnly, Secure, and SameSite=Lax flags. Sessions expire after 7 days of inactivity.
  • Automated retention enforcement: A daily automated job purges Personal Data that has exceeded its retention period (see Section 8).
  • Incident response: Shieldome maintains an incident response procedure with breach notification obligations (see Section 10).

8. Data Retention and Deletion

Personal Data processed as Processor is retained for the minimum period necessary to fulfil the purpose for which it was submitted, as set out below. A daily automated job enforces these limits.

Data CategoryRetention PeriodNotes
Login and activity logs 90 days Purged automatically by daily cleanup job
Email delivery logs 180 days Retained for delivery troubleshooting; purged automatically
Scan results and findings 24 months from scan date Cleared after cutoff; Customer may delete earlier via the platform
Account data (profile, settings) Duration of account + 30 days after deletion request Deleted on account closure or upon Customer instruction
Billing records and invoices 7 years Required by Serbian Accounting Act and applicable tax law

Upon termination of the Services or written request from the Customer, Shieldome will, at the Customer's choice, securely delete or return all Personal Data within 30 days, except where continued storage is required by applicable law. Shieldome will confirm completion of deletion in writing upon request.

9. Data Subject Rights

Shieldome will assist the Customer in fulfilling Data Subject requests under GDPR Chapter III within the timeframes required by law. The following rights are supported:

  • Right of Access (Art. 15) — Shieldome will provide the Customer with the Personal Data it holds on a Data Subject within 5 business days of a documented request.
  • Right to Rectification (Art. 16) — Inaccurate data will be corrected upon Customer instruction.
  • Right to Erasure (Art. 17) — Personal Data will be deleted upon Customer instruction, subject to retention obligations under applicable law.
  • Right to Restriction (Art. 18) — Processing will be restricted upon Customer instruction pending resolution of a dispute.
  • Right to Data Portability (Art. 20) — Data can be exported in machine-readable JSON format via the /api/me/data-export endpoint, or upon written request from the Customer.
  • Right to Object (Art. 21) — The Customer may object to certain Processing activities on documented grounds; Shieldome will cease Processing unless compelling legitimate grounds exist.

10. Personal Data Breach Notification

In the event of a confirmed or reasonably suspected Personal Data Breach affecting data Processed on behalf of the Customer, Shieldome shall:

  1. Notify the Customer without undue delay and no later than 48 hours after becoming aware of the breach, by email to the account email address on record. Notification may be made in phases if not all information is immediately available.
  2. Provide the Customer, as soon as reasonably practicable, with:
    • A description of the nature of the breach, including categories and approximate number of Data Subjects and Personal Data records affected;
    • The name and contact details of the Data Protection Officer or other contact point;
    • A description of the likely consequences of the breach;
    • A description of measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
  3. Cooperate with the Customer and take reasonable steps to assist the Customer in meeting its obligation to notify the relevant Supervisory Authority within 72 hours of becoming aware of the breach (GDPR Art. 33).

The Customer is responsible for determining whether and how to notify the relevant Supervisory Authority and affected Data Subjects, based on information provided by Shieldome.

11. Audit Rights

Shieldome shall make available all information necessary to demonstrate compliance with its obligations under this DPA. The Customer (or its appointed auditor) may conduct an audit of Shieldome's data processing activities no more than once per calendar year, subject to:

  • At least 30 days' prior written notice to Shieldome;
  • The audit being conducted during business hours and in a manner that does not unreasonably disrupt Shieldome's operations;
  • The Customer and auditor signing a non-disclosure agreement acceptable to Shieldome before the audit commences;
  • The Customer bearing the cost of the audit.

Shieldome may satisfy audit requests by providing up-to-date third-party audit reports or certifications in lieu of a direct audit, where such reports cover the subject matter of the request.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Shieldome Terms of Service. Where Shieldome is liable for a breach of this DPA as Processor, its liability is limited to the direct damages caused by such breach. Neither party is liable for indirect, consequential, special, or exemplary damages arising under or in connection with this DPA.

13. Termination

This DPA remains in force for the duration of the Terms of Service and terminates automatically upon termination or expiry of those Terms. Obligations relating to data deletion (Section 8), breach notification (Section 10), and confidentiality survive termination for the periods specified therein or as required by applicable law.

14. Governing Law

This DPA is governed by the laws of the Republic of Serbia. Any disputes arising from or in connection with this DPA shall be subject to the exclusive jurisdiction of the competent courts in Serbia, unless otherwise required by mandatory consumer protection law in the Customer's jurisdiction.

Nothing in this DPA limits either party's rights to seek injunctive or other equitable relief in any competent court.

15. Contact

For all data protection matters, questions regarding this DPA, or to exercise any right described herein:

  • Email: [email protected]
  • Support: Open a ticket while logged in at app.shieldome.com

We aim to respond within 5 business days and to complete all requests within 30 days (extendable by a further 60 days for complex requests, with notice).

This DPA is incorporated by reference into the Shieldome Terms of Service. By accepting the Terms of Service, the Customer agrees to the terms of this DPA. No separate signature is required unless the Customer specifically requests a countersigned copy for their own records, in which case please contact [email protected].