Data Processing Agreement

Version of 29 September 2026

This agreement sets out how we process personal data on your behalf when you use ShieldWave, as Article 28 of Regulation (EU) 2016/679 (GDPR) requires. It follows the structure of the standard contractual clauses in Commission Implementing Decision (EU) 2021/915, in our own words.

1. Parties and conclusion

1.1. The parties are the customer ("you") and Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG), "ENSOMEDIA" or "we" below. Contact for everything under this agreement:

1.2. We conclude this agreement with every business customer and every sole trader with consumer rights as defined in the Terms of Service. A consumer who checks a site only for personal or household purposes is outside the GDPR for that activity (Article 2(2)(c)) and does not conclude it.

1.3. The agreement is concluded when you accept the Terms of Service, of which it is a part. Electronic form meets Article 28(9) GDPR, so no signature is needed. Towards customers who accepted the Terms of Service before 29 September 2026 we apply this agreement as our commitment from 29 September 2026; as a contract it binds them from the day the new version of the Terms binds them.

1.4. The agreement applies as long as we process data on your behalf, also after the contract ends, until the data is deleted under section 12.

2. Precedence and terms used

2.1. In matters of personal data, this agreement prevails over the Terms of Service, and the standard contractual clauses in section 10.4, where they apply, prevail over this agreement. The Terms of Service govern everything else.

2.2. Terms defined in the GDPR have the same meaning here. A "subprocessor" is a further processor: a company whose services we use and which processes data covered by this agreement. "EEA" means the European Economic Area.

3. Roles

3.1. You decide which sites we check, how often, and what happens with the results. For the personal data in those checks, you are the controller and we are the processor.

3.2. If you check your client's sites, for example as an agency, your client is usually the controller, you are its processor and we are a further processor. Section 14.3 then sets out your duties.

3.3. This agreement does not cover data we process as controller for our own purposes: account and payment data, security and abuse logs, our usage events, the demonstration check and the free tools, statements of authorisation to check a site, and correspondence with us. The Privacy Policy describes them.

3.4. You instruct us to create aggregate statistics on website security from results; before we store them we remove domains and personal data, so that no site or person can be recognised in them. From the WordPress plugin we keep file fingerprints (sha256, md5) with the AI verdict, without the site name, and reuse them for the same file on other sites. Neither identifies a person. We also record that a file with that fingerprint appeared on a site identified by a salted hash; we delete that record after 12 months.

4. Instructions

4.1. We process data only on your documented instructions: the Terms of Service and this agreement; your settings and actions in the account (sites, checks, schedules, alerts, webhooks, reports, the plugin connection); and instructions e-mailed to support@shieldwave.io from the address registered to your account.

4.2. If Union or Member State law requires other processing, we tell you first, unless that law forbids this on important grounds of public interest.

4.3. If we consider that an instruction infringes data protection law, we tell you at once and may suspend it until you confirm or change it.

4.4. If ShieldWave's functions cannot carry out an instruction, we tell you, and you may end the contract under the Terms of Service.

4.5. We do not use your data for our own purposes, except under section 3.4, and we do not give the results of your checks to other customers.

5. Confidentiality

5.1. Only the owner of ENSOMEDIA has access to data processed on your behalf. Any other person we authorise will first commit in writing to confidentiality, lasting after the cooperation ends, and will get only the access their tasks need.

5.2. We disclose the data only to the subprocessors under section 7 and to the recipients you choose, and to public authorities only when the law requires it, telling you unless the law forbids it.

5.3. Confidentiality continues after this agreement ends.

6. Security

6.1. We apply the measures in Annex II, chosen under Article 32 GDPR with regard to the state of the art, the costs, the nature, scope, context and purposes of the processing, and the risk to people.

6.2. We may change these measures if the level of protection does not fall. Annex II always shows the current measures.

6.3. You are responsible for your side: your login details and API keys, whom you invite to your team, and keeping your webhook addresses private.

7. Subprocessors

7.1. You give us general authorisation to use subprocessors. Table 1 of the list Subprocessors and recipients, which is Annex III, names the current ones.

7.2. We announce a new or replacement subprocessor at least 14 days ahead, by e-mail to the address registered to your account and on the list page.

7.3. Within that period you may object by e-mail to support@shieldwave.io, giving data protection reasons. We will try to meet the objection, for example by not passing your data to the new subprocessor. If we cannot, you may end the contract before the change takes effect, and we refund the fee paid in advance for the unused period.

7.4. Each subprocessor is bound by contract to the same data protection obligations as in this agreement, in particular to appropriate security measures (Article 28(4) GDPR). We are liable to you for its acts as for our own.

7.5. Subprocessors may use their own subcontractors under the processing terms linked in the list. On request we name the full chain and send a copy of the data protection terms of our contract with a subprocessor, with commercial details removed.

7.6. Slack, Microsoft Teams, Discord and your own webhook are recipients you choose, not our subprocessors; your own contract with them governs.

8. Help with requests and assessments

8.1. If a person contacts us about data from your checks, we pass the request to you without undue delay and do not answer it on the merits without your instruction.

8.2. You can export results (a JSON file in your profile) and delete the account yourself. What these tools cannot do, for example deleting or correcting specific data in results, we do on your instruction without undue delay, so that the person can be answered within the one month the GDPR allows.

8.3. We help you meet Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation) with the information we hold about the processing and our measures, also for supply-chain questions under the Polish National Cybersecurity System Act or other NIS2 laws.

8.4. Help is free of charge within reason. For work beyond the normal running of the service, we agree the cost with you first.

9. Personal data breach

9.1. We notify you of a breach affecting data processed on your behalf without undue delay, where possible within 48 hours and no later than 72 hours after we learn of it, by e-mail to the address registered to your account.

9.2. As far as we know it, the notice describes the breach, the categories and approximate number of people and records concerned, a contact point, the likely consequences, and the measures taken or proposed. Missing information follows in stages without further delay.

9.3. We limit the effects and document every breach: the facts, the effects and the remedial action. As controller, you decide whether to notify the supervisory authority and the people concerned. On your instruction we help you prepare those notices.

10. Transfers outside the EEA

10.1. We store the data in the European Union, in Google Cloud's europe-west1 region (Belgium). Some subprocessors process data outside the EEA, mainly in the USA; the list shows who, where and on what basis.

10.2. We transfer data outside the EEA only with a safeguard under Chapter V GDPR. We rely on the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) where the recipient is certified, and otherwise on standard contractual clauses (Commission Implementing Decision (EU) 2021/914). We send a copy of the safeguards on request.

10.3. You agree to the transfers in the list. We announce a new transfer as we announce a new subprocessor (section 7).

10.4. If you are established outside the EEA in a country without a Commission adequacy decision, Module Four (processor to controller) of the standard contractual clauses in Decision 2021/914 applies to the data we pass to you (results, reports, e-mails, notifications) and forms part of this agreement. We are the exporter, you are the importer, Annex I describes the transfer, Clause 7 does not apply, Clause 17 chooses Polish law and Clause 18 the Polish courts.

11. Information and audits

11.1. We make available the information needed to show that we meet Article 28 GDPR: this agreement, its annexes, the list of subprocessors, and answers to your written questions within a reasonable time.

11.2. If this is not enough, you may carry out an audit once a year, remotely or on site, at your own cost, announced by e-mail at least 30 days ahead, yourself or through an independent auditor bound by confidentiality who is not our competitor. This limit does not apply to supervisory authorities.

11.3. An audit takes place on working days in business hours and gives no access to other customers' data or to safeguards whose disclosure would weaken protection. For our subprocessors, we share the documents they give us, as far as they allow.

11.4. Audit results are confidential. You give us the audit report free of charge.

12. Deletion and return

12.1. During the contract, we delete data automatically within the periods in Annex I.

12.2. Before deleting your account, you can download your results (JSON export in your profile) and PDF reports. On request made before deletion, we also hand over the other data processed on your behalf, for example data of sites connected through the plugin, in a machine-readable format.

12.3. When the account is deleted, by you or by us under the Terms of Service, we delete the data processed on your behalf at once. Data in backups and our providers' logs disappears within 30 days.

12.4. We keep data longer only where Union or Polish law requires it, protected under this agreement and used only for that purpose.

12.5. On request we confirm the deletion by e-mail.

13. Liability

13.1. The Terms of Service govern liability under this agreement. For business customers their limits apply: up to the fees paid in the 12 months before the event, and not for lost profits. These limits never apply to damage caused intentionally or by gross negligence, or to liability that the law does not allow to be limited. We do not apply them to sole traders with consumer rights.

13.2. This agreement does not change liability towards the people whose data is concerned, the split of liability between us under Article 82 GDPR, or the rules on administrative fines.

14. Your duties

14.1. You have a legal basis for the data you entrust to us, you inform people as the law requires, and you give us no more data than needed.

14.2. You order checks only of sites that are yours or whose owner has allowed you to check them, and you confirm this when adding a site or ordering a check. We keep that statement as evidence, as the Terms of Service describe. We run full checks, with test inputs sent to forms, only for domains whose control you have confirmed (a DNS record, a file, a meta tag or a connected plugin); other domains get the basic check.

14.3. If you check a client's sites as its processor, you ensure that the client has allowed the checks and that your contract with it allows further processors, including us. You pass our list and change notices on to the client, and its objections and instructions on to us. We take the client's instructions only through you.

14.4. You do not enter special categories of data (Article 9 GDPR) or data on criminal convictions and offences (Article 10 GDPR) into ShieldWave, for example in site names, logos, report contact details or webhook addresses. You run checks behind a login only with test accounts that give no access to real people's data, above all health data.

14.5. You keep a current e-mail address in your account, where our notices under this agreement go. You tell us without undue delay about processing errors you notice and about impact assessments that concern our processing.

15. Law and courts

15.1. This agreement is governed by Polish law and the GDPR.

15.2. Disputes with a business customer go to the courts of Wrocław. Disputes with a sole trader with consumer rights go to the court that has jurisdiction under the general rules.

15.3. The supervisory authority for ENSOMEDIA is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

16. Changes to this agreement

16.1. We announce a change to this agreement by e-mail at least 30 days before it takes effect. If you do not agree, you may end the contract before that day under the Terms of Service.

16.2. Changes to the list of subprocessors follow section 7, and to Annex II section 6.2.

Annex I. Description of the processing

I.1 Subject matter

Personal data found and stored by the checks ordered from your account, and data you give us to run the checks and deliver their results.

I.2 Nature and purpose

The purpose is to provide ShieldWave under the Terms of Service. The processing covers:

I.3 Kinds of data

We do not look for special categories of data. They can appear only if published on, or leaking from, the checked site.

I.4 Categories of people

I.5 Duration and deletion periods

The processing lasts for the term of the contract and then until deletion under section 12. You may order earlier deletion of specific data at any time.

DataHow long
Results on the Free planshown for 7 days, deleted no later than 90 days after the check
Results on the Pro and Enterprise plans12 months
A check with a bought one-off report90 days
Uptime monitoring results, monitoring alerts and assets found around a site (subdomains, addresses, files)12 months (assets: from when they were last seen), or until the account is deleted
Notifications in the account60 days
Webhook delivery logs90 days
Team invitations7 days; once expired they are deleted by the daily clean-up
Login details for a check behind a loginonly for that check
Data of sites connected through the pluginuntil you remove the site or delete the account
Settings and data for reports with your logountil you change them or delete the account
Cache of AI textsup to 1 hour in memory, 24 hours in the database
Data at the AI providernot stored, except up to 30 days when it investigates a reliability problem or suspected abuse
Backups and providers' logsup to 30 days

I.6 Subprocessors

See Annex III.

Annex II. Technical and organisational measures

II.1 Encryption

II.2 Access and authentication

II.3 Protection of the service

II.4 Hosting

II.5 Accountability and deletion

II.6 Limiting the data sent to AI

II.7 Organisational measures

Annex III. Subprocessors

On the date of this version we use these subprocessors:

Table 1 of the list Subprocessors and recipients gives the details. The list in force when the agreement is concluded forms part of it; changes follow section 7.

Change history