ShieldedStack Privacy Policy
Effective date: 23 September 2026 Supersedes prior Policy dated 1 June 2026.
In production, you run ShieldedStack in your own environment. We do not connect to customer-operated production installations, and the Software does not phone home. Separately, we may make a temporary ShieldedStack-operated portal evaluation available to approved applicants. In that evaluation, we operate and can access the environment, including account, identity, access, service, and synthetic activity data. This Policy covers personal data handled through the website, evaluation requests and environments, private registry access, support, and customer relationships.
1. The Honest Summary
- Customer-operated production and on-premises trial deployments do not transmit usage data, logs, metrics, scan results, package metadata, vulnerability findings, identities, or other operational data to us during normal operation.
- A portal evaluation is different: it runs in an environment operated by ShieldedStack, and we can access and process its account, identity, access, service, and synthetic activity data to operate and support the evaluation.
- We also hold business/contact data you provide directly and ordinary access/security logs from interactions with our website, private registry, and support channels.
- We do not sell data. We do not run advertising. We do not profile you.
- We are established in Denmark. We are not subject to the United States CLOUD Act or analogous extraterritorial disclosure regimes that apply to US-headquartered providers.
2. What the Software Does Not Collect
To be explicit about the things a reasonable buyer assumes we collect and that we do not:
- The Software does not transmit usage data, logs, metrics, identifiers, or any other information to us during normal operation.
- We do not receive package names, package versions, registry traffic, scan results, vulnerability findings, or audit logs from your installation.
- We do not see your developers, your CI agents, your repository names, or your Keycloak identities through the Software's operation.
- License Key validation is performed locally on your installation using public-key cryptography. No remote call to us is required or made.
This is a contractual commitment under the applicable ShieldedStack Software License Agreement or Trial Agreement.
3. What We Collect and Why
3.1 Evaluation and Trial Requests
When you submit an evaluation or trial request form at /trial, we collect the fields you provide, including your name, work email, company, request type (portal evaluation or on-premises trial), and any optional ecosystem, evaluation objective, or notes.
The form is submitted to a Cloudflare Worker, which verifies a Cloudflare Turnstile token to prevent bot submissions, stores a hashed IP-derived rate-limit counter in Cloudflare KV for 24 hours, and sends the form contents to [email protected] via Resend. The submission is not stored in an application database. The email lands in our Proton Mail mailbox.
Why: to review requests manually, decide whether to offer an evaluation, arrange access or an on-premises trial where approved, and follow up with prospective customers. A request does not automatically provision an environment or guarantee access.
Lawful basis: legitimate interest in responding to inbound business enquiries (GDPR Article 6(1)(f)) and steps taken at your request before entering into a contract (Article 6(1)(b)).
3.2 Customer and Order Data
If you license ShieldedStack under an Order Form, we hold your organisation's legal name, the registered contact details on the Order Form, the License Key claims needed to issue and administer the license, and invoicing data.
Why: to perform the contract, issue License Keys, send invoices, provide support, and administer the customer relationship.
Lawful basis: performance of a contract (Article 6(1)(b)) and compliance with bookkeeping obligations under Danish law (Article 6(1)(c)).
3.3 Portal Evaluation Environment
If we approve a portal evaluation, we create a separate temporary ShieldedStack installation and account for your evaluator. The environment contains synthetic dependency activity generated within the deployment; it is not connected to your package registries, repositories, CI/CD systems, or production environment. Do not enter sensitive, personal, confidential, or proprietary data into the evaluation.
Because ShieldedStack operates the evaluation environment, we can access and process account and identity information, authentication and access logs, service and security logs, and the synthetic package activity and findings shown in the Portal. We use this information to provide, secure, troubleshoot, and administer the evaluation. Evaluation access is intended to last 7 days. After the evaluation ends, we manually disable access and remove the environment and its evaluation data; operational backups or records may persist for a limited period where technically necessary or legally required.
3.4 Private Registry and Artifact Access
ShieldedStack updates, upgrades, and trial artifacts may be delivered through Licensor-operated systems such as a private container registry. When you choose to pull images or access artifacts from those systems, standard access and security logs may be generated.
These logs may include requesting IP address, timestamp, account or credential identifier, requested artifact or endpoint, user agent, and access result. These logs are not Software telemetry. They are generated by customer-initiated access to Licensor systems outside normal Software operation.
Why: security, access control, abuse prevention, support, billing, and contract administration.
Lawful basis: legitimate interest in securing and operating our delivery systems (Article 6(1)(f)) and contract performance for customers (Article 6(1)(b)).
3.5 Support and Direct Communication
Emails you send to us, support tickets, and any attachments you choose to include are processed so we can respond to you. If you voluntarily send logs, screenshots, configuration snippets, package names, vulnerability findings, or other operational data, we process that information only to provide support and administer the relationship.
Do not send secrets, credentials, private keys, or regulated personal data unless we have agreed appropriate handling terms in writing.
Why: legitimate interest in providing support and operating the business (Article 6(1)(f)), and contract performance where you are a customer (Article 6(1)(b)).
3.6 Website Analytics
Our public website uses self-hosted Umami analytics, served from analytics.bytebard.org. Umami operates in cookieless mode and honours Do Not Track browser signals. Collected data points are page URL, referrer, browser and device type, country-level location derived from the IP address, and event timestamps. The IP address itself is not retained by Umami.
Why: understanding aggregate traffic to improve the website.
Lawful basis: legitimate interest (Article 6(1)(f)). No cookies or persistent identifiers are set.
4. Subprocessors
We use the following third parties to operate the website, evaluation environment, trial intake, contact channels, and customer communications. They do not have access to customer-operated production or on-premises trial installations or customer data processed by those installations. Portal evaluation data is processed in the ShieldedStack-operated evaluation environment as described above.
| Provider | Purpose |
|---|---|
| Cloudflare, Inc. | Hosts the public website, runs the evaluation/trial request form Worker, stores short-lived rate-limit counters, and provides Turnstile bot protection. Cloudflare may process visitor IP addresses transiently for DDoS protection and bot challenges. |
| Resend, Inc. | Delivers transactional emails such as trial form submissions and License Key delivery. Resend processes recipient address, sender address, and email content for delivery. |
| Proton AG (Switzerland) | Hosts our mailbox at the shieldedstack.com domain. Inbound emails are stored on Proton Mail infrastructure in Switzerland. |
Cloudflare and Resend are US-headquartered. Transfers to these providers rely on the EU Standard Contractual Clauses and supplementary measures described in their respective Data Processing Addenda. Proton is established in Switzerland, which the European Commission has determined provides an adequate level of data protection.
We will update this list when subprocessors change.
5. What We Are Not
For customer-operated production and on-premises trial deployments, we are not a processor or sub-processor of data processed by your installation. The Software runs on your infrastructure and does not transmit its operational data to us. This statement does not apply to a portal evaluation: we operate that temporary environment and can access and process its data as described in section 3.3.
For customer-operated production and on-premises trial deployments, no Data Processing Agreement is required between us in respect of data processed by your installation, because no processing relationship exists. This statement does not cover data processed in a ShieldedStack-operated portal evaluation. If your procurement or DPO team needs written confirmation of this position, contact [email protected].
6. Retention
- Evaluation and trial form submissions: retained in our Proton mailbox until they are no longer commercially relevant, typically up to 24 months after the last interaction, then deleted.
- Portal evaluation account, activity, and service data: removed when the evaluation environment is manually decommissioned after the 7-day evaluation, subject to limited operational backups and records retained where technically necessary or legally required.
- Customer and order data: retained for the duration of the customer relationship and thereafter as required by Danish bookkeeping law.
- Support correspondence: retained for up to 24 months after the last interaction unless a longer period is needed for an active customer relationship or legal obligation.
- Private registry and artifact access logs: retained for security, access-control, billing, and support purposes, typically up to 24 months unless a longer period is required to investigate abuse or comply with legal obligations.
- Rate-limit counters in Cloudflare KV: 24 hours, then deleted automatically.
- Umami analytics events: retained in aggregated form indefinitely. No individual identifiers are stored.
7. Sharing and Disclosure
We do not share personal data with third parties except:
- with the subprocessors listed in section 4, as necessary to operate the website, contact channels, and customer relationship;
- where required by law, valid Danish or EU legal process, or to protect rights, property, or safety.
We will resist overbroad or improper requests and will challenge any request that conflicts with EU law. We do not sell personal data. We do not share data with advertising networks or data brokers.
8. Your Rights Under the GDPR
If we hold personal data about you, you have the right to:
- access the data we hold about you;
- have inaccurate data corrected;
- have your data erased, subject to legal retention obligations;
- restrict or object to processing based on legitimate interest;
- receive your data in a portable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at
datatilsynet.dk.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
9. Security
Personal data we hold is stored on infrastructure with the following protections:
- HTTPS / TLS for website and form transport.
- End-to-end encryption at rest for Proton Mail where available.
- Multi-factor authentication on accounts under our control.
- Short-lived Cloudflare KV rate-limit counters.
- Access controls on private registry and artifact-delivery credentials.
If you believe a personal data incident has occurred involving us, notify [email protected]. Confirmed breaches affecting EU residents will be reported to Datatilsynet within 72 hours where required under GDPR Article 33.
10. International Transfers
Evaluation/trial form data, transactional email content, rate-limit counters, and website security data may be processed by Cloudflare and Resend, which are US-headquartered. Transfers rely on the EU Standard Contractual Clauses adopted by the European Commission in 2021 and on additional safeguards described by each provider. The portal evaluation environment is operated by ShieldedStack. Contact [email protected] for information about infrastructure providers used for a particular evaluation.
The Proton mailbox is hosted in Switzerland under the EU adequacy decision for Switzerland. We will prefer EU-only providers where commercially reasonable.
11. Updates to this Policy
We may update this Privacy Policy. If we make material changes, we will notify customers with an active Order Form by email before the change takes effect. For visitors and trial requesters, the current Policy at this URL is the operative version. The effective date is shown at the top.
12. Contact
Privacy questions, requests, or concerns: [email protected].