← Back to Shieldome

Privacy Policy

Last updated: August 7, 2026 · Effective: August 7, 2026

Contents
  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. Legal Basis (GDPR)
  5. Data Retention
  6. Sub-processors and Data Sharing
  7. International Transfers
  8. Data Security
  9. Cookies
  10. Your Rights
  11. Complaints
  12. Changes to This Policy
  13. Contact

1. Who We Are

Shieldome d.o.o. ("Shieldome", "we", "us") operates the web security platform at app.shieldome.com. The platform performs passive vulnerability assessments and performance analysis of websites you are authorised to test. We do not perform active exploitation or penetration testing.

For the purpose of EU data protection law, Shieldome acts as:

  • Controller — for your account, billing, and usage data (we decide the purpose and means of processing).
  • Processor — for scan data relating to websites you submit (we process it on your instruction).

Contact: [email protected]

2. What Data We Collect

Account data

  • Email address, full name, phone number (optional), country / timezone
  • Password hash (bcrypt — we never store plaintext passwords)
  • TOTP secret if you enable two-factor authentication
  • OAuth token reference if you log in via Google

Scan data

  • Target URLs and IP overrides you submit
  • Scan results, finding details, severity ratings
  • Scan tags, notes, and PDF reports you generate
  • Monitored domains and SSL certificate data for your alert configurations

Usage and security data

  • Login timestamps, IP addresses, user-agent strings
  • Session tokens (stored in a secure, HttpOnly cookie)
  • API key identifiers (hashed; we never store the key itself)

Payment data

  • Billing plan tier, token balance, subscription period
  • Transaction status, approval codes, card brand and last 4 digits (received from payment processor — full card numbers are never stored on our servers)
  • Invoice records required by Serbian tax law

Integration data

  • Webhook URLs for Slack, Teams, Discord, PagerDuty, OpsGenie — stored encrypted at rest using AES-256 (Fernet)
  • SSO client secrets for SAML/OIDC integrations — stored encrypted at rest

Support data

  • Messages you send through the in-app support ticket system
  • Email correspondence with [email protected]

3. How We Use Your Data

  • To provide, operate, and improve the scanning service
  • To send transactional emails (scan complete, cert expiry alerts, password reset, billing receipts)
  • To prevent abuse and verify that targets you scan are authorised
  • To generate PDF reports you request
  • To send security-relevant notifications via webhooks you configure
  • To maintain billing records as required by law

We do not sell, rent, or share your personal data with third parties for marketing purposes. We do not run advertising on the platform.

4. Legal Basis (GDPR)

For users in the EU/EEA, we process your data on the following legal bases:

Processing activityLegal basis
Providing the service, account management, billing Art. 6(1)(b) — performance of contract
Security logging, fraud and abuse prevention Art. 6(1)(f) — legitimate interest
Sending transactional emails Art. 6(1)(b) — performance of contract
Retaining billing records Art. 6(1)(c) — legal obligation (tax law)
Optional analytics cookies Art. 6(1)(a) — consent

5. Data Retention

We retain data only as long as necessary for the purpose it was collected:

Data categoryRetention periodBasis
Login / activity events 90 days Security monitoring; purged automatically by daily cleanup job
Email delivery logs 180 days Delivery troubleshooting; purged automatically
Scan results 24 months from scan date Scan history feature; results cleared after cutoff
Account data Duration of account + 30 days after deletion Service provision; deleted on account closure
Billing records (invoices, transaction records) 7 years Serbian Accounting Act / EU tax law requirement
Support tickets Until account deletion or 3 years, whichever is later Dispute resolution

A daily automated job purges data that has exceeded its retention period. You can also request immediate deletion at any time (see Section 10).

6. Sub-processors and Data Sharing

We use the following sub-processors to deliver the service. Each is bound by a data processing agreement and adequate transfer safeguards:

Sub-processorPurposeLocationSafeguard
Amazon Web Services (ECS, RDS, ElastiCache, S3) Cloud hosting, database, storage EU (Frankfurt, eu-central-1) AWS DPA / SCCs
Resend Inc. Transactional email delivery United States EU Commission SCCs (Module 2)
Google LLC OAuth login ("Sign in with Google") United States EU Commission SCCs

We do not share your personal data with any other third parties except as required by law (e.g. valid court order or regulator request).

7. International Transfers

Your account and scan data is stored in AWS eu-central-1 (Frankfurt, Germany) — within the European Economic Area. No transfer safeguard is required for this storage.

Shieldome is incorporated in Serbia. Serbia has received an EU adequacy decision under GDPR Art. 45 (Commission Decision 2013/65/EU), meaning data transfers between Serbia and the EU/EEA are permitted without additional safeguards.

For transfers to Resend (US) and Google (US), we rely on the EU Commission Standard Contractual Clauses (2021/914, Module 2). A Transfer Impact Assessment concluded the risk of government access to personal data in these transfers is low given the nature and volume of data involved.

8. Data Security

  • All data in transit is encrypted via HTTPS/TLS 1.2+
  • Passwords are hashed with bcrypt (work factor 12)
  • Sensitive fields (webhook URLs, SSO secrets) are encrypted at rest using AES-256 (Fernet symmetric encryption)
  • Databases run in a private VPC subnet with no public internet access
  • CSRF protection is enforced on all state-changing requests
  • Session cookies carry HttpOnly, Secure, and SameSite=Lax flags
  • Two-factor authentication (TOTP) is available and encouraged for all accounts
  • Role-based access controls limit who can access customer data within our organisation

9. Cookies

CookiePurposeExpiryConsent required
session User authentication session 7 days (rolling) No — strictly necessary
lang Language preference 1 year No — strictly necessary
Analytics cookies Aggregate usage analytics Up to 1 year Yes — set only after consent via cookie banner

You can withdraw analytics cookie consent at any time by clearing your browser cookies or using the preference link in the site footer.

10. Your Rights

Under GDPR (and the Serbian Law on Personal Data Protection), you have the following rights regarding your personal data:

  • Access (Art. 15) — receive a copy of the personal data we hold about you
  • Rectification (Art. 16) — correct inaccurate or incomplete data
  • Erasure (Art. 17) — request deletion ("right to be forgotten"); we will delete your account and associated data within 30 days
  • Restriction (Art. 18) — ask us to pause processing while a dispute is resolved
  • Portability (Art. 20) — receive your data in a machine-readable format for transfer to another service
  • Objection (Art. 21) — object to processing based on legitimate interest
Download your data
You can download a complete JSON export of your Shieldome account data (profile, scans, allowed sites, payment history, support tickets) at any time while logged in:
⬇ Download my data (JSON)

To exercise any other right, or to request account deletion, please open a support ticket while logged in, or email us at [email protected]. We will respond within 30 days. We may ask you to verify your identity before fulfilling the request.

11. Complaints

If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with a supervisory authority:

  • EU/EEA residents — contact the data protection authority in your country of residence. A list of EU DPAs is available at edpb.europa.eu.
  • Serbia — contact the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti) at poverenik.rs.

We would, however, appreciate the opportunity to address your concerns directly before you contact a supervisory authority — please reach out to us first.

12. Changes to This Policy

We will notify registered users of material changes via email at least 14 days before they take effect. The updated policy will be posted at this URL with a revised "Last updated" date. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

13. Contact

For any privacy-related questions, to exercise your rights, or to report a concern:

  • Email: [email protected]
  • Support ticket: available while logged in at app.shieldome.com

We aim to respond to all privacy requests within 5 business days and to complete them within 30 days (extendable by a further 60 days for complex requests, with notice).