Privacy, security, and data processing commitments.
This page summarizes how Shieldify handles personal data, security logs, verification cookies,
subprocessors, retention, customer requests, and operational security for the Shieldify Lynx platform.
Shieldify provides managed website protection, traffic intelligence, application firewall controls,
verification pages, and customer/admin dashboards. We process data only to operate, secure, improve,
and support these services.
Controller and processor roles
For Shieldify account, billing, support, and platform administration data, Shieldify generally acts as a
controller. For protected website traffic processed on behalf of a customer, Shieldify generally acts as
a processor and the customer remains the controller of its visitor data.
Data categories
We may process account information, login/session metadata, website configuration, domain/origin data,
IP addresses, timestamps, hostnames, request method, request path, user agent, status code, cache status,
security decision results, WAF events, challenge status, and operational audit records.
Purposes
Data is used to provide the service, authenticate users, protect websites, detect and mitigate attacks,
investigate incidents, generate customer-visible reports, provide support, prevent abuse, and meet legal
or security obligations.
Legal bases
Depending on the context, processing is based on contract performance, legitimate security interests,
legal obligations, or consent where required. Security cookies and verification data are treated as
strictly necessary for service security.
Cookie and security cookie notice
Cookies used for security, not advertising
Shieldify uses cookies and local browser storage to keep the panel secure and to distinguish legitimate
visitors from automated or suspicious traffic. Shieldify does not use advertising cookies by default.
Type
Purpose
Typical duration
Panel session cookies
Keep authenticated users signed in and protect dashboard access.
Session or configured account lifetime
CSRF/security cookies
Prevent unauthorized form submissions and cross-site request abuse.
Short-lived or session-based
Website verification cookies
Remember that a visitor passed Shieldify verification during active protection.
Short-lived security window
Advanced verification tokens
Support stronger verification for suspicious clients during active protection.
Short-lived security window
Theme preference
Remember light or dark mode preference on Shieldify pages.
Until changed or cleared by the user
Data Processing Agreement
DPA summary for customers
When Shieldify processes protected website traffic on behalf of a customer, Shieldify processes personal data
only according to the customer's documented instructions and only for providing and securing the Shieldify
service. A signed customer-specific DPA can be provided on request.
Confidentiality
Personnel and administrators with access to customer data are required to handle it confidentially and only for authorized operational purposes.
Security measures
Shieldify maintains technical and organizational measures covering access control, encryption in transit, monitoring, backup, incident response, and production isolation.
Subprocessors
Shieldify uses a limited set of service providers. Customers can request the current subprocessor list and relevant changes.
Assistance
Shieldify assists customers with data subject requests, security questions, audit information, and incident response where relevant to the service.
Deletion and return
On termination or verified request, Shieldify deletes or returns customer-controlled data unless retention is required for legal, billing, backup, or security reasons.
Audit support
Reasonable security documentation, policies, and evidence can be made available to customers, reviewers, or public authorities under appropriate confidentiality terms.
Subprocessors
Service providers used by Shieldify
Shieldify keeps subprocessor use limited and purpose-specific. PrivateCaptcha is self-hosted by Shieldify in
the current deployment, so visitor verification does not require sending captcha traffic to an external
captcha vendor.
Provider
Purpose
Data involved
Hosting and network provider
Server hosting, bandwidth, network routing, and infrastructure availability.
Protected traffic, logs, platform data hosted on Shieldify-controlled servers.
Shieldify-managed database and storage, internal
Panel data, website configuration, statistics, logs, and backups on Shieldify-controlled infrastructure.
Account data, site configuration, operational logs, and security events. Not a separate external subprocessor in the standard deployment.
Discord
Optional customer/admin webhook notifications.
Configured incident summaries and site names. Raw request bodies are not intentionally sent.
Email provider, if enabled
Transactional email such as account, support, or system messages.
Email address and message metadata required for delivery.
PrivateCaptcha, self-hosted
Advanced visitor verification during active protection.
Verification challenge metadata processed on Shieldify-controlled infrastructure.
Log retention policy
Retention targets
Shieldify keeps operational and security logs only as long as they are useful for protection, troubleshooting,
abuse prevention, legal compliance, or customer support.
Data type
Standard target
Reason
Traffic/request logs
30 days
Traffic visibility, support, debugging, and attack investigation.
WAF audit and security event logs
14 to 30 days
Rule tuning, false-positive review, and security incident analysis.
Admin audit logs
90 to 180 days
Administrative accountability, change review, and abuse investigation.
Account and billing records
As legally required
Contract, accounting, and legal obligations.
Backups
Rolling backup window
Disaster recovery and service continuity.
Incident-related records may be retained longer where needed to investigate abuse, protect customers, comply
with law, or preserve evidence.
Data minimization
Request and WAF log minimization
Body minimization
Shieldify avoids collecting request bodies by default where possible. Security logs focus on metadata and
rule decisions needed to detect and explain attacks.
Query and URI handling
Request paths and query strings may be security-relevant and can appear in logs. Customers should avoid
placing sensitive personal data in URLs. Shieldify can assist with targeted exclusions or redaction needs.
Customer visibility
Customer screens show useful security and traffic information. Internal engine, infrastructure, and stack
details are restricted to admin-only operational views.
Purpose limitation
Traffic and security data is used for protection, diagnostics, reporting, and abuse prevention, not for
advertising profiling.
DSAR, export, and deletion
Data subject and customer request process
Requests can be sent to contact@shieldify.ee. Shieldify verifies the
requester, determines whether Shieldify is acting as controller or processor, and responds within applicable
legal timelines. GDPR requests are targeted for response within 30 days unless an extension is legally allowed.
Receive and verify: confirm identity, account ownership, and request scope.
Route correctly: protected website visitor requests may need to be handled by the customer as controller.
Export or access: provide account data or relevant customer-controlled records where applicable.
Correct or delete: update or remove eligible data unless retention is required for security, legal, billing, backup, or dispute reasons.
Confirm completion: document the action and provide a clear response.
Breach notification
Security incident procedure
If Shieldify identifies a personal data breach or serious security incident, the response process is to
investigate, contain, assess impact, preserve relevant evidence, and notify affected customers without undue
delay. Where Shieldify acts as controller, Shieldify will notify supervisory authorities or affected
individuals when legally required.
Containment
Limit exposure, rotate affected secrets, restrict access, and isolate affected systems where needed.
Assessment
Identify data categories, affected customers, time window, root cause, and likely risk.
Notification
Provide available details, mitigation steps, and contact channel so customers can meet their own obligations.
Admin access and audit policy
Restricted operational access
Administrative access is limited to authorized Shieldify operators who need it for service operation, customer
support, incident response, and security maintenance. Internal diagnostics are separated from customer-facing
screens so sensitive infrastructure details are not exposed to ordinary users.
Least privilege
Access is granted based on operational need and reviewed when roles or responsibilities change.
Audit logging
Administrative changes and sensitive operations are logged where technically available for investigation and accountability.
Change control
Production changes are tracked, tested where practical, and operationally reviewed before or after deployment.
Customer websites are provisioned with per-site configuration, logs, security controls, and operational separation.
Monitoring
Runtime load, traffic pressure, WAF events, attack waves, endpoint signals, and operational logs are monitored for availability and security.
Backup and recovery
Operational backups and recovery procedures support continuity while respecting retention and deletion requirements.
Incident response
Shieldify maintains procedures for detection, containment, investigation, communication, and post-incident improvement.
This Trust Center is an operational summary, not legal advice. Customer-specific legal terms, DPAs, and review
evidence can be provided through contact@shieldify.ee.