ShieldifyLynx
Platform Protection Intelligence Operations FAQ Trust Center
Sign in Contact
Platform Protection Intelligence Operations FAQ Trust Center Sign in
Shieldify Trust Center

Privacy, security, and data processing commitments.

This page summarizes how Shieldify handles personal data, security logs, verification cookies, subprocessors, retention, customer requests, and operational security for the Shieldify Lynx platform.

Last updated: June 11, 2026 Contact: contact@shieldify.ee
Privacy Cookies DPA Subprocessors Retention Minimization Data Rights Breach Notice Admin Access Security Measures
Privacy Policy

How Shieldify uses data

Shieldify provides managed website protection, traffic intelligence, application firewall controls, verification pages, and customer/admin dashboards. We process data only to operate, secure, improve, and support these services.

Controller and processor roles

For Shieldify account, billing, support, and platform administration data, Shieldify generally acts as a controller. For protected website traffic processed on behalf of a customer, Shieldify generally acts as a processor and the customer remains the controller of its visitor data.

Data categories

We may process account information, login/session metadata, website configuration, domain/origin data, IP addresses, timestamps, hostnames, request method, request path, user agent, status code, cache status, security decision results, WAF events, challenge status, and operational audit records.

Purposes

Data is used to provide the service, authenticate users, protect websites, detect and mitigate attacks, investigate incidents, generate customer-visible reports, provide support, prevent abuse, and meet legal or security obligations.

Legal bases

Depending on the context, processing is based on contract performance, legitimate security interests, legal obligations, or consent where required. Security cookies and verification data are treated as strictly necessary for service security.

Cookie and security cookie notice

Cookies used for security, not advertising

Shieldify uses cookies and local browser storage to keep the panel secure and to distinguish legitimate visitors from automated or suspicious traffic. Shieldify does not use advertising cookies by default.

TypePurposeTypical duration
Panel session cookies Keep authenticated users signed in and protect dashboard access. Session or configured account lifetime
CSRF/security cookies Prevent unauthorized form submissions and cross-site request abuse. Short-lived or session-based
Website verification cookies Remember that a visitor passed Shieldify verification during active protection. Short-lived security window
Advanced verification tokens Support stronger verification for suspicious clients during active protection. Short-lived security window
Theme preference Remember light or dark mode preference on Shieldify pages. Until changed or cleared by the user
Data Processing Agreement

DPA summary for customers

When Shieldify processes protected website traffic on behalf of a customer, Shieldify processes personal data only according to the customer's documented instructions and only for providing and securing the Shieldify service. A signed customer-specific DPA can be provided on request.

Confidentiality

Personnel and administrators with access to customer data are required to handle it confidentially and only for authorized operational purposes.

Security measures

Shieldify maintains technical and organizational measures covering access control, encryption in transit, monitoring, backup, incident response, and production isolation.

Subprocessors

Shieldify uses a limited set of service providers. Customers can request the current subprocessor list and relevant changes.

Assistance

Shieldify assists customers with data subject requests, security questions, audit information, and incident response where relevant to the service.

Deletion and return

On termination or verified request, Shieldify deletes or returns customer-controlled data unless retention is required for legal, billing, backup, or security reasons.

Audit support

Reasonable security documentation, policies, and evidence can be made available to customers, reviewers, or public authorities under appropriate confidentiality terms.

Subprocessors

Service providers used by Shieldify

Shieldify keeps subprocessor use limited and purpose-specific. PrivateCaptcha is self-hosted by Shieldify in the current deployment, so visitor verification does not require sending captcha traffic to an external captcha vendor.

ProviderPurposeData involved
Hosting and network provider Server hosting, bandwidth, network routing, and infrastructure availability. Protected traffic, logs, platform data hosted on Shieldify-controlled servers.
Shieldify-managed database and storage, internal Panel data, website configuration, statistics, logs, and backups on Shieldify-controlled infrastructure. Account data, site configuration, operational logs, and security events. Not a separate external subprocessor in the standard deployment.
Discord Optional customer/admin webhook notifications. Configured incident summaries and site names. Raw request bodies are not intentionally sent.
Email provider, if enabled Transactional email such as account, support, or system messages. Email address and message metadata required for delivery.
PrivateCaptcha, self-hosted Advanced visitor verification during active protection. Verification challenge metadata processed on Shieldify-controlled infrastructure.
Log retention policy

Retention targets

Shieldify keeps operational and security logs only as long as they are useful for protection, troubleshooting, abuse prevention, legal compliance, or customer support.

Data typeStandard targetReason
Traffic/request logs30 daysTraffic visibility, support, debugging, and attack investigation.
WAF audit and security event logs14 to 30 daysRule tuning, false-positive review, and security incident analysis.
Admin audit logs90 to 180 daysAdministrative accountability, change review, and abuse investigation.
Account and billing recordsAs legally requiredContract, accounting, and legal obligations.
BackupsRolling backup windowDisaster recovery and service continuity.

Incident-related records may be retained longer where needed to investigate abuse, protect customers, comply with law, or preserve evidence.

Data minimization

Request and WAF log minimization

Body minimization

Shieldify avoids collecting request bodies by default where possible. Security logs focus on metadata and rule decisions needed to detect and explain attacks.

Query and URI handling

Request paths and query strings may be security-relevant and can appear in logs. Customers should avoid placing sensitive personal data in URLs. Shieldify can assist with targeted exclusions or redaction needs.

Customer visibility

Customer screens show useful security and traffic information. Internal engine, infrastructure, and stack details are restricted to admin-only operational views.

Purpose limitation

Traffic and security data is used for protection, diagnostics, reporting, and abuse prevention, not for advertising profiling.

DSAR, export, and deletion

Data subject and customer request process

Requests can be sent to contact@shieldify.ee. Shieldify verifies the requester, determines whether Shieldify is acting as controller or processor, and responds within applicable legal timelines. GDPR requests are targeted for response within 30 days unless an extension is legally allowed.

  1. Receive and verify: confirm identity, account ownership, and request scope.
  2. Route correctly: protected website visitor requests may need to be handled by the customer as controller.
  3. Export or access: provide account data or relevant customer-controlled records where applicable.
  4. Correct or delete: update or remove eligible data unless retention is required for security, legal, billing, backup, or dispute reasons.
  5. Confirm completion: document the action and provide a clear response.
Breach notification

Security incident procedure

If Shieldify identifies a personal data breach or serious security incident, the response process is to investigate, contain, assess impact, preserve relevant evidence, and notify affected customers without undue delay. Where Shieldify acts as controller, Shieldify will notify supervisory authorities or affected individuals when legally required.

Containment

Limit exposure, rotate affected secrets, restrict access, and isolate affected systems where needed.

Assessment

Identify data categories, affected customers, time window, root cause, and likely risk.

Notification

Provide available details, mitigation steps, and contact channel so customers can meet their own obligations.

Admin access and audit policy

Restricted operational access

Administrative access is limited to authorized Shieldify operators who need it for service operation, customer support, incident response, and security maintenance. Internal diagnostics are separated from customer-facing screens so sensitive infrastructure details are not exposed to ordinary users.

Least privilege

Access is granted based on operational need and reviewed when roles or responsibilities change.

Audit logging

Administrative changes and sensitive operations are logged where technically available for investigation and accountability.

Change control

Production changes are tracked, tested where practical, and operationally reviewed before or after deployment.

Separation of views

Customers receive clear protection information. Low-level engine, stack, and infrastructure detail remains admin-only.

Security TOMs

Technical and organizational measures

Encryption

TLS is used for panel and protected website traffic. Sensitive production secrets are kept out of public code and configuration outputs.

Access control

Panel authentication, session security, CSRF protection, role-aware admin views, and strict origin controls protect management functions.

Isolation

Customer websites are provisioned with per-site configuration, logs, security controls, and operational separation.

Monitoring

Runtime load, traffic pressure, WAF events, attack waves, endpoint signals, and operational logs are monitored for availability and security.

Backup and recovery

Operational backups and recovery procedures support continuity while respecting retention and deletion requirements.

Incident response

Shieldify maintains procedures for detection, containment, investigation, communication, and post-incident improvement.

This Trust Center is an operational summary, not legal advice. Customer-specific legal terms, DPAs, and review evidence can be provided through contact@shieldify.ee.

ShieldifyLynx

Machine-learning web protection built for real traffic.

PlatformDDoS protectionApplication firewallTraffic intelligence
ProductDashboardFAQSign inContact
TrustTrust CenterPrivacy PolicySecurity CookiesDPASubprocessors
ShieldifyCompanySupportSecurity
© 2026 Shieldify. All rights reserved.One platform. Complete protection.