Privacy Policy
Last updated: 21 June 2026
Template notice: This is a starting-point policy. Have it reviewed by legal counsel and tailored to your actual data practices before you collect data from real customers.
1. Who we are
ShieldFlow ("ShieldFlow", "we", "us") provides an AI-powered governance, risk and compliance platform. This policy explains what personal data we process and why. For privacy questions, contact privacy@shieldflow.com.
2. Data we collect
- Account data: your name, work email, and password (stored only as a salted hash).
- Workspace data: the company, controls, evidence files, policies, vendors and notes you create.
- Integration data: read-only metadata you choose to sync (e.g. repository or user-security summaries). Access tokens are stored to enable syncs you initiate.
- Usage data: basic logs and, if enabled, privacy-friendly analytics to keep the service reliable.
3. How we use it
To provide and secure the service, generate the compliance features you request, communicate with you about your account, and meet legal obligations. We do not sell your data.
4. Legal bases (GDPR)
We process data to perform our contract with you, on the basis of our legitimate interests in running and securing the service, and to comply with legal obligations. Where required, we rely on your consent and you may withdraw it at any time.
5. Sub-processors
We use trusted vendors to run the service, including infrastructure and database hosting, authentication, email delivery, payment processing, and AI inference. Each processes data only as needed to provide their service under a data-processing agreement.
6. Data retention
We keep your data for as long as your account is active. You can delete your workspace data at any time, and we delete or anonymise data within a reasonable period after account closure, except where retention is legally required.
7. Security
Data is encrypted in transit, access is restricted by row-level security so each company sees only its own data, and secrets are stored server-side. No system is perfectly secure, but we work to protect your information.
8. Your rights
Subject to applicable law, you may access, correct, export, or delete your personal data, and object to or restrict certain processing. Contact us to exercise these rights.
9. International transfers
Where data is transferred across borders, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
10. Changes & contact
We may update this policy and will revise the date above. Questions? Email privacy@shieldflow.com.
See also our Terms of Service.