"Shieldome" means NEMANJA MILJKOVIĆ PR RAČUNARSKO PROGRAMIRANJE SHIELDOME KRAGUJEVAC, a sole trader registered under the laws of the Republic of Serbia, operating the services at app.shieldome.com and shieldomescout.com ("Service Provider").
"Customer" means the legal entity or individual who has accepted the Shieldome Terms of Service ("Controller" in respect of Personal Data it submits to the platform).
"Personal Data", "Data Subject", "Processing", "Processor", "Controller", and "Supervisory Authority" have the meanings ascribed to them in Regulation (EU) 2016/679 (GDPR) and the Serbian Law on Personal Data Protection (LPDP).
"Services" means the web vulnerability assessment and performance scanning platform provided by Shieldome to the Customer under the Terms of Service.
"Sub-processor" means any third party engaged by Shieldome to carry out Processing activities on behalf of the Customer.
This DPA governs the Processing of Personal Data by Shieldome in connection with the provision of the Services. Shieldome acts in dual capacity:
With respect to scan data submitted by the Customer — including target URLs, IP overrides, scan results, finding details, and monitored domains — Shieldome acts as a Processor. Processing of such data is carried out solely on the Customer's documented instructions and for the purpose of delivering the Services.
With respect to account data, billing data, and usage logs — including the Customer's email address, name, payment records, and login activity — Shieldome acts as an independent Controller. Such Processing is governed by Shieldome's Privacy Policy at shieldome.com/privacy.
| Category | Examples |
|---|---|
| Scan targets | URLs, domain names, IP addresses submitted by the Customer for scanning |
| Scan results | Vulnerability findings, severity ratings, HTTP response data, SSL certificate data |
| Configuration data | Webhook URLs (encrypted), SSO secrets (encrypted), scan tags and notes |
| Integration metadata | Alert configurations, monitored domain lists, PDF report content |
The Customer confirms that scan targets and associated data do not intentionally include special categories of data as defined in GDPR Art. 9, nor Personal Data of minors.
Where Shieldome acts as Processor, it shall:
The Customer, as Controller, shall:
The Customer provides general written authorisation for Shieldome to engage Sub-processors. Shieldome will maintain an up-to-date list of Sub-processors and notify the Customer of any intended changes (additions or replacements) at least 14 days in advance. The Customer may object to a new Sub-processor on reasonable grounds within this period.
Current Sub-processors are listed below. Each Sub-processor is bound by a data processing agreement with obligations no less protective than those in this DPA.
| Sub-processor | Purpose | Location | Transfer Safeguard |
|---|---|---|---|
| Amazon Web Services, Inc. (ECS Fargate, RDS PostgreSQL, ElastiCache Redis, S3) |
Cloud hosting, database, caching, file storage | EU (Frankfurt, eu-central-1) — within the EEA | No transfer mechanism required (data remains in EEA). AWS DPA applies. |
| Resend Inc. | Transactional email delivery (scan notifications, alerts, billing receipts) | United States | EU Commission Standard Contractual Clauses (Decision 2021/914, Module 2 Controller→Processor). See also the Transfer Impact Assessment. |
| Google LLC | OAuth 2.0 authentication ("Sign in with Google") | United States | EU Commission Standard Contractual Clauses. Only OAuth token exchange data is transmitted; no scan data is shared with Google. |
All account and scan data is stored in AWS eu-central-1 (Frankfurt, Germany) — within the European Economic Area. No transfer mechanism is required for this storage.
Shieldome is incorporated in Serbia. Serbia benefits from an EU adequacy decision under GDPR Art. 45 (Commission Decision 2013/65/EU). Transfers of Personal Data from the EU/EEA to Shieldome in Serbia are therefore permitted without additional safeguards.
For transfers to Resend (US) and Google (US), Shieldome relies on the EU Commission Standard Contractual Clauses (2021/914). A Transfer Impact Assessment (TIA) is available at /legal/transfer_impact_assessment.html and concludes that the risk of government access to the limited data involved is LOW.
Where the Customer is itself an EU Controller transferring Personal Data to Shieldome as Processor, the applicable Module 2 SCC Annexes are provided at /legal/scc_annexes.html.
Shieldome implements and maintains the following technical and organisational security measures in accordance with GDPR Art. 32:
Personal Data processed as Processor is retained for the minimum period necessary to fulfil the purpose for which it was submitted, as set out below. A daily automated job enforces these limits.
| Data Category | Retention Period | Notes |
|---|---|---|
| Login and activity logs | 90 days | Purged automatically by daily cleanup job |
| Email delivery logs | 180 days | Retained for delivery troubleshooting; purged automatically |
| Scan results and findings | 24 months from scan date | Cleared after cutoff; Customer may delete earlier via the platform |
| Account data (profile, settings) | Duration of account + 30 days after deletion request | Deleted on account closure or upon Customer instruction |
| Billing records and invoices | 7 years | Required by Serbian Accounting Act and applicable tax law |
Upon termination of the Services or written request from the Customer, Shieldome will, at the Customer's choice, securely delete or return all Personal Data within 30 days, except where continued storage is required by applicable law. Shieldome will confirm completion of deletion in writing upon request.
Shieldome will assist the Customer in fulfilling Data Subject requests under GDPR Chapter III within the timeframes required by law. The following rights are supported:
/api/me/data-export endpoint, or upon
written request from the Customer.In the event of a confirmed or reasonably suspected Personal Data Breach affecting data Processed on behalf of the Customer, Shieldome shall:
The Customer is responsible for determining whether and how to notify the relevant Supervisory Authority and affected Data Subjects, based on information provided by Shieldome.
Shieldome shall make available all information necessary to demonstrate compliance with its obligations under this DPA. The Customer (or its appointed auditor) may conduct an audit of Shieldome's data processing activities no more than once per calendar year, subject to:
Shieldome may satisfy audit requests by providing up-to-date third-party audit reports or certifications in lieu of a direct audit, where such reports cover the subject matter of the request.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Shieldome Terms of Service. Where Shieldome is liable for a breach of this DPA as Processor, its liability is limited to the direct damages caused by such breach. Neither party is liable for indirect, consequential, special, or exemplary damages arising under or in connection with this DPA.
This DPA remains in force for the duration of the Terms of Service and terminates automatically upon termination or expiry of those Terms. Obligations relating to data deletion (Section 8), breach notification (Section 10), and confidentiality survive termination for the periods specified therein or as required by applicable law.
This DPA is governed by the laws of the Republic of Serbia. Any disputes arising from or in connection with this DPA shall be subject to the exclusive jurisdiction of the competent courts in Serbia, unless otherwise required by mandatory consumer protection law in the Customer's jurisdiction.
Nothing in this DPA limits either party's rights to seek injunctive or other equitable relief in any competent court.
For all data protection matters, questions regarding this DPA, or to exercise any right described herein:
We aim to respond within 5 business days and to complete all requests within 30 days (extendable by a further 60 days for complex requests, with notice).