Shieldome d.o.o. ("Shieldome", "we", "us") operates the web security platform at app.shieldome.com. The platform performs passive vulnerability assessments and performance analysis of websites you are authorised to test. We do not perform active exploitation or penetration testing.
For the purpose of EU data protection law, Shieldome acts as:
Contact: [email protected]
We do not sell, rent, or share your personal data with third parties for marketing purposes. We do not run advertising on the platform.
For users in the EU/EEA, we process your data on the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Providing the service, account management, billing | Art. 6(1)(b) — performance of contract |
| Security logging, fraud and abuse prevention | Art. 6(1)(f) — legitimate interest |
| Sending transactional emails | Art. 6(1)(b) — performance of contract |
| Retaining billing records | Art. 6(1)(c) — legal obligation (tax law) |
| Optional analytics cookies | Art. 6(1)(a) — consent |
We retain data only as long as necessary for the purpose it was collected:
| Data category | Retention period | Basis |
|---|---|---|
| Login / activity events | 90 days | Security monitoring; purged automatically by daily cleanup job |
| Email delivery logs | 180 days | Delivery troubleshooting; purged automatically |
| Scan results | 24 months from scan date | Scan history feature; results cleared after cutoff |
| Account data | Duration of account + 30 days after deletion | Service provision; deleted on account closure |
| Billing records (invoices, transaction records) | 7 years | Serbian Accounting Act / EU tax law requirement |
| Support tickets | Until account deletion or 3 years, whichever is later | Dispute resolution |
A daily automated job purges data that has exceeded its retention period. You can also request immediate deletion at any time (see Section 10).
We use the following sub-processors to deliver the service. Each is bound by a data processing agreement and adequate transfer safeguards:
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Amazon Web Services (ECS, RDS, ElastiCache, S3) | Cloud hosting, database, storage | EU (Frankfurt, eu-central-1) | AWS DPA / SCCs |
| Resend Inc. | Transactional email delivery | United States | EU Commission SCCs (Module 2) |
| Google LLC | OAuth login ("Sign in with Google") | United States | EU Commission SCCs |
We do not share your personal data with any other third parties except as required by law (e.g. valid court order or regulator request).
Your account and scan data is stored in AWS eu-central-1 (Frankfurt, Germany) — within the European Economic Area. No transfer safeguard is required for this storage.
Shieldome is incorporated in Serbia. Serbia has received an EU adequacy decision under GDPR Art. 45 (Commission Decision 2013/65/EU), meaning data transfers between Serbia and the EU/EEA are permitted without additional safeguards.
For transfers to Resend (US) and Google (US), we rely on the EU Commission Standard Contractual Clauses (2021/914, Module 2). A Transfer Impact Assessment concluded the risk of government access to personal data in these transfers is low given the nature and volume of data involved.
| Cookie | Purpose | Expiry | Consent required |
|---|---|---|---|
session |
User authentication session | 7 days (rolling) | No — strictly necessary |
lang |
Language preference | 1 year | No — strictly necessary |
| Analytics cookies | Aggregate usage analytics | Up to 1 year | Yes — set only after consent via cookie banner |
You can withdraw analytics cookie consent at any time by clearing your browser cookies or using the preference link in the site footer.
Under GDPR (and the Serbian Law on Personal Data Protection), you have the following rights regarding your personal data:
To exercise any other right, or to request account deletion, please open a support ticket while logged in, or email us at [email protected]. We will respond within 30 days. We may ask you to verify your identity before fulfilling the request.
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with a supervisory authority:
We would, however, appreciate the opportunity to address your concerns directly before you contact a supervisory authority — please reach out to us first.
We will notify registered users of material changes via email at least 14 days before they take effect. The updated policy will be posted at this URL with a revised "Last updated" date. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
For any privacy-related questions, to exercise your rights, or to report a concern:
We aim to respond to all privacy requests within 5 business days and to complete them within 30 days (extendable by a further 60 days for complex requests, with notice).