ShieldWave

Privacy Policy

ShieldWave Pro — Web Security Scanner Ensomedia

---

1. Introduction

This Privacy Policy ("Policy") explains how Ensomedia, ul. Chorwacka 33/42, 51-107 Wroclaw, Poland ("Ensomedia", "we", "us", or "our"), collects, uses, stores, shares, and protects personal data in connection with the ShieldWave Pro web security scanning platform available at shieldwave.io ("Service").

ShieldWave Pro is a SaaS platform for automated web security scanning, including OWASP Top 10, XSS, SQLi, SSRF, misconfigurations, API security, WordPress, and SPA vulnerability detection. We are committed to protecting the privacy and security of all data processed through our Service in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Polish Act on Personal Data Protection of 10 May 2018, and all applicable data protection legislation.

By creating an account or using the Service, you acknowledge that you have read and understood this Policy.

---

2. Data Controller

The data controller for the personal data processed through the Service is:

Ensomedia ul. Chorwacka 33/42 51-107 Wroclaw, Poland Email: contact@ensomedia.pl

For all privacy-related inquiries, please contact us at contact@ensomedia.pl.

---

3. Categories of Personal Data We Collect

3.1 Account Data

When you register for ShieldWave Pro, we collect:

3.2 Billing and Payment Data

When you subscribe to a paid plan (Pro or Enterprise), payment is processed exclusively through Stripe, Inc. We do not store full credit card numbers, CVV codes, or bank account details on our servers. We receive and store from Stripe:

3.3 Scan Configuration Data

When you configure security scans, we process:

3.4 Scan Results Data

After each scan, we store:

Important: ShieldWave Pro does not store the full content of scanned websites. We retain only vulnerability metadata, proof-of-concept snippets, and scan results.

3.5 Usage and Technical Data

We automatically collect:

3.6 Communication Data

When you contact our support or interact with us:

3.7 Cookie and Tracking Data

Please refer to our separate [Cookie Policy](/cookie-policy) for details on cookies and similar tracking technologies.

---

4. Purposes and Legal Bases for Processing

| Purpose | Legal Basis (GDPR) | |---|---| | Providing and maintaining the Service (account management, scan execution, report generation) | Performance of a contract (Art. 6(1)(b)) | | Processing payments and managing subscriptions | Performance of a contract (Art. 6(1)(b)) | | Sending transactional emails (scan completion, security alerts, billing receipts) | Performance of a contract (Art. 6(1)(b)) | | AI-powered vulnerability analysis and remediation suggestions | Performance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) | | Improving the Service, analytics, and feature development | Legitimate interest (Art. 6(1)(f)) | | Preventing abuse, fraud detection, and enforcing Terms of Service | Legitimate interest (Art. 6(1)(f)) | | Marketing communications and newsletters (only with opt-in) | Consent (Art. 6(1)(a)) | | Cookie-based analytics and website performance monitoring | Consent (Art. 6(1)(a)) for non-essential cookies | | Compliance with legal obligations (tax records, law enforcement requests) | Legal obligation (Art. 6(1)(c)) |

---

5. AI-Powered Processing

ShieldWave Pro uses artificial intelligence (powered by third-party large language model providers) to:

Data sent to AI providers: When AI analysis is triggered, we transmit vulnerability metadata, proof-of-concept data, and scan context to our AI subprocessor. We do not send your personal account information, payment data, or the full content of scanned websites to AI providers.

AI providers process this data under strict data processing agreements and do not use your data to train their models. See our [Subprocessor List](/subprocessors) for the current AI provider(s).

5.1 ShieldWave Security WordPress Plugin

The optional ShieldWave Security plugin for WordPress runs inside your own site and, by default, sends nothing externally. When you enable its intelligence features, up to three data flows may occur:

Groq processes these excerpts under a data processing agreement and does not use them to train its models. See our [Subprocessor List](/subprocessors).

---

6. Data Sharing and Recipients

We share personal data only with the following categories of recipients, each bound by appropriate data processing agreements:

6.1 Subprocessors

We use third-party service providers to operate the Service. A current list is maintained in our [Subprocessor List](/subprocessors), including:

6.2 Your Integrations

If you configure integrations (Slack, Microsoft Teams, webhooks), scan results and notification data are transmitted to those third-party services at your direction.

6.3 Legal and Regulatory

We may disclose personal data if required to do so by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of Ensomedia, our users, or the public.

6.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity. We will notify affected users before their data is transferred and becomes subject to a different privacy policy.

We do not sell personal data to third parties. We do not share personal data for advertising purposes.

---

7. International Data Transfers

Ensomedia is based in the European Economic Area (EEA). Where we transfer personal data outside the EEA (for example, to subprocessors in the United States), we ensure appropriate safeguards are in place, including:

You may request a copy of the applicable transfer safeguards by contacting us at contact@ensomedia.pl.

---

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy:

| Data Category | Retention Period | |---|---| | Account data | Duration of account + 30 days after deletion request | | Billing and payment data | Duration of account + 5 years (tax/legal obligations) | | Scan results and reports | Duration of account; deleted within 30 days of account deletion. Free plan: results retained for 90 days. | | Scan configuration data | Duration of account | | Usage and technical data | 26 months from collection | | Communication data (support) | 3 years from last interaction | | Marketing consent records | Until consent is withdrawn + 3 years for proof |

Upon account deletion, we will delete or anonymize all personal data within 30 days, except where longer retention is required by law (e.g., tax and accounting records).

---

9. Your Rights Under GDPR

As a data subject, you have the following rights:

How to Exercise Your Rights

Send your request to contact@ensomedia.pl with the subject line "GDPR Request". We will respond within 30 days. We may request verification of your identity before processing the request.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland:

Prezes Urzedu Ochrony Danych Osobowych ul. Stawki 2, 00-193 Warszawa, Poland Website: https://uodo.gov.pl

---

10. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

---

11. Children's Privacy

ShieldWave Pro is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at contact@ensomedia.pl.

---

12. Third-Party Links

The Service may contain links to third-party websites or services. This Policy does not apply to third-party sites. We encourage you to review the privacy policies of any third-party service before providing personal data.

---

13. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes by:

The updated Policy will indicate the "Last updated" date at the bottom. Continued use of the Service after changes constitutes acceptance of the revised Policy.

---

14. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our data processing practices:

Ensomedia ul. Chorwacka 33/42 51-107 Wroclaw, Poland Email: contact@ensomedia.pl

---

Last updated: February 2026