ShieldedStack Privacy Policy

Effective date: 1 June 2026 Supersedes prior Policy dated 17 October 2025.


ShieldedStack is software you run on your own infrastructure. We do not host it for you, we do not connect to your installation, and the Software does not phone home. This Policy covers the limited personal data we hold about you in connection with the website, contact channels, trial requests, private registry access, support, and customer relationships.

1. The Honest Summary

  • The ShieldedStack Software does not transmit usage data, logs, metrics, scan results, package metadata, vulnerability findings, identities, or other operational data to us during normal operation.
  • The routine personal data we hold is business/contact data you provide directly, plus ordinary access/security logs from customer-initiated interactions with our website, private registry, trial systems, and support channels.
  • We do not sell data. We do not run advertising. We do not profile you.
  • We are established in Denmark. We are not subject to the United States CLOUD Act or analogous extraterritorial disclosure regimes that apply to US-headquartered providers.

2. What the Software Does Not Collect

To be explicit about the things a reasonable buyer assumes we collect and that we do not:

  • The Software does not transmit usage data, logs, metrics, identifiers, or any other information to us during normal operation.
  • We do not receive package names, package versions, registry traffic, scan results, vulnerability findings, or audit logs from your installation.
  • We do not see your developers, your CI agents, your repository names, or your Keycloak identities through the Software's operation.
  • License Key validation is performed locally on your installation using public-key cryptography. No remote call to us is required or made.

This is a contractual commitment under the applicable ShieldedStack Software License Agreement or Trial Agreement.

3. What We Collect and Why

3.1 Trial Requests

When you submit the trial request form at /trial, we collect the fields you provide: name, work email, organisation, country, package ecosystems you use, and any free-text notes you choose to include.

The form is submitted to a Cloudflare Worker, which verifies a Cloudflare Turnstile token to prevent bot submissions, stores a hashed IP-derived rate-limit counter in Cloudflare KV for 24 hours, and sends the form contents to [email protected] via Resend. The submission is not stored in an application database. The email lands in our Proton Mail mailbox.

Why: to evaluate trial requests, issue License Keys, and follow up with prospective customers.

Lawful basis: legitimate interest in responding to inbound business enquiries (GDPR Article 6(1)(f)) and steps taken at your request before entering into a contract (Article 6(1)(b)).

3.2 Customer and Order Data

If you license ShieldedStack under an Order Form, we hold your organisation's legal name, the registered contact details on the Order Form, the License Key claims needed to issue and administer the license, and invoicing data.

Why: to perform the contract, issue License Keys, send invoices, provide support, and administer the customer relationship.

Lawful basis: performance of a contract (Article 6(1)(b)) and compliance with bookkeeping obligations under Danish law (Article 6(1)(c)).

3.3 Private Registry and Artifact Access

ShieldedStack updates, upgrades, and trial artifacts may be delivered through Licensor-operated systems such as a private container registry. When you choose to pull images or access artifacts from those systems, standard access and security logs may be generated.

These logs may include requesting IP address, timestamp, account or credential identifier, requested artifact or endpoint, user agent, and access result. These logs are not Software telemetry. They are generated by customer-initiated access to Licensor systems outside normal Software operation.

Why: security, access control, abuse prevention, support, billing, and contract administration.

Lawful basis: legitimate interest in securing and operating our delivery systems (Article 6(1)(f)) and contract performance for customers (Article 6(1)(b)).

3.4 Support and Direct Communication

Emails you send to us, support tickets, and any attachments you choose to include are processed so we can respond to you. If you voluntarily send logs, screenshots, configuration snippets, package names, vulnerability findings, or other operational data, we process that information only to provide support and administer the relationship.

Do not send secrets, credentials, private keys, or regulated personal data unless we have agreed appropriate handling terms in writing.

Why: legitimate interest in providing support and operating the business (Article 6(1)(f)), and contract performance where you are a customer (Article 6(1)(b)).

3.5 Website Analytics

Our public website uses self-hosted Umami analytics, served from analytics.bytebard.org. Umami operates in cookieless mode and honours Do Not Track browser signals. Collected data points are page URL, referrer, browser and device type, country-level location derived from the IP address, and event timestamps. The IP address itself is not retained by Umami.

Why: understanding aggregate traffic to improve the website.

Lawful basis: legitimate interest (Article 6(1)(f)). No cookies or persistent identifiers are set.

4. Subprocessors

We use the following third parties to operate the website, trial intake, contact channels, and customer communications. None of them have access to ShieldedStack installations or customer data processed by the Software.

ProviderPurpose
Cloudflare, Inc.Hosts the public website, runs the trial form Worker, stores short-lived rate-limit counters, and provides Turnstile bot protection. Cloudflare may process visitor IP addresses transiently for DDoS protection and bot challenges.
Resend, Inc.Delivers transactional emails such as trial form submissions and License Key delivery. Resend processes recipient address, sender address, and email content for delivery.
Proton AG (Switzerland)Hosts our mailbox at the shieldedstack.com domain. Inbound emails are stored on Proton Mail infrastructure in Switzerland.

Cloudflare and Resend are US-headquartered. Transfers to these providers rely on the EU Standard Contractual Clauses and supplementary measures described in their respective Data Processing Addenda. Proton is established in Switzerland, which the European Commission has determined provides an adequate level of data protection.

We will update this list when subprocessors change.

5. What We Are Not

We are not a processor or sub-processor of any data your ShieldedStack installation processes. The Software runs on your infrastructure, scans packages and produces findings locally, and never transmits any of that to us.

No Data Processing Agreement is required between us in respect of data processed by your installation, because no processing relationship exists. If your procurement or DPO team needs written confirmation of this position, contact [email protected].

6. Retention

  • Trial form submissions: retained in our Proton mailbox until they are no longer commercially relevant, typically up to 24 months after the last interaction, then deleted.
  • Customer and order data: retained for the duration of the customer relationship and thereafter as required by Danish bookkeeping law.
  • Support correspondence: retained for up to 24 months after the last interaction unless a longer period is needed for an active customer relationship or legal obligation.
  • Private registry and artifact access logs: retained for security, access-control, billing, and support purposes, typically up to 24 months unless a longer period is required to investigate abuse or comply with legal obligations.
  • Rate-limit counters in Cloudflare KV: 24 hours, then deleted automatically.
  • Umami analytics events: retained in aggregated form indefinitely. No individual identifiers are stored.

7. Sharing and Disclosure

We do not share personal data with third parties except:

  • with the subprocessors listed in section 4, as necessary to operate the website, contact channels, and customer relationship;
  • where required by law, valid Danish or EU legal process, or to protect rights, property, or safety.

We will resist overbroad or improper requests and will challenge any request that conflicts with EU law. We do not sell personal data. We do not share data with advertising networks or data brokers.

8. Your Rights Under the GDPR

If we hold personal data about you, you have the right to:

  • access the data we hold about you;
  • have inaccurate data corrected;
  • have your data erased, subject to legal retention obligations;
  • restrict or object to processing based on legitimate interest;
  • receive your data in a portable format;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

9. Security

Personal data we hold is stored on infrastructure with the following protections:

  • HTTPS / TLS for website and form transport.
  • End-to-end encryption at rest for Proton Mail where available.
  • Multi-factor authentication on accounts under our control.
  • Short-lived Cloudflare KV rate-limit counters.
  • Access controls on private registry and artifact-delivery credentials.

If you believe a personal data incident has occurred involving us, notify [email protected]. Confirmed breaches affecting EU residents will be reported to Datatilsynet within 72 hours where required under GDPR Article 33.

10. International Transfers

Trial form data, transactional email content, rate-limit counters, and website security data may be processed by Cloudflare and Resend, which are US-headquartered. Transfers rely on the EU Standard Contractual Clauses adopted by the European Commission in 2021 and on additional safeguards described by each provider.

The Proton mailbox is hosted in Switzerland under the EU adequacy decision for Switzerland. We will prefer EU-only providers where commercially reasonable.

11. Updates to this Policy

We may update this Privacy Policy. If we make material changes, we will notify customers with an active Order Form by email before the change takes effect. For visitors and trial requesters, the current Policy at this URL is the operative version. The effective date is shown at the top.

12. Contact

Privacy questions, requests, or concerns: [email protected].