ShieldWave Pro — Web Security Scanner Ensomedia
---
This Privacy Policy ("Policy") explains how Ensomedia, ul. Chorwacka 33/42, 51-107 Wroclaw, Poland ("Ensomedia", "we", "us", or "our"), collects, uses, stores, shares, and protects personal data in connection with the ShieldWave Pro web security scanning platform available at shieldwave.io ("Service").
ShieldWave Pro is a SaaS platform for automated web security scanning, including OWASP Top 10, XSS, SQLi, SSRF, misconfigurations, API security, WordPress, and SPA vulnerability detection. We are committed to protecting the privacy and security of all data processed through our Service in full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Polish Act on Personal Data Protection of 10 May 2018, and all applicable data protection legislation.
By creating an account or using the Service, you acknowledge that you have read and understood this Policy.
---
The data controller for the personal data processed through the Service is:
Ensomedia ul. Chorwacka 33/42 51-107 Wroclaw, Poland Email: contact@ensomedia.pl
For all privacy-related inquiries, please contact us at contact@ensomedia.pl.
---
When you register for ShieldWave Pro, we collect:
When you subscribe to a paid plan (Pro or Enterprise), payment is processed exclusively through Stripe, Inc. We do not store full credit card numbers, CVV codes, or bank account details on our servers. We receive and store from Stripe:
When you configure security scans, we process:
After each scan, we store:
Important: ShieldWave Pro does not store the full content of scanned websites. We retain only vulnerability metadata, proof-of-concept snippets, and scan results.
We automatically collect:
When you contact our support or interact with us:
Please refer to our separate [Cookie Policy](/cookie-policy) for details on cookies and similar tracking technologies.
---
| Purpose | Legal Basis (GDPR) | |---|---| | Providing and maintaining the Service (account management, scan execution, report generation) | Performance of a contract (Art. 6(1)(b)) | | Processing payments and managing subscriptions | Performance of a contract (Art. 6(1)(b)) | | Sending transactional emails (scan completion, security alerts, billing receipts) | Performance of a contract (Art. 6(1)(b)) | | AI-powered vulnerability analysis and remediation suggestions | Performance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) | | Improving the Service, analytics, and feature development | Legitimate interest (Art. 6(1)(f)) | | Preventing abuse, fraud detection, and enforcing Terms of Service | Legitimate interest (Art. 6(1)(f)) | | Marketing communications and newsletters (only with opt-in) | Consent (Art. 6(1)(a)) | | Cookie-based analytics and website performance monitoring | Consent (Art. 6(1)(a)) for non-essential cookies | | Compliance with legal obligations (tax records, law enforcement requests) | Legal obligation (Art. 6(1)(c)) |
---
ShieldWave Pro uses artificial intelligence (powered by third-party large language model providers) to:
Data sent to AI providers: When AI analysis is triggered, we transmit vulnerability metadata, proof-of-concept data, and scan context to our AI subprocessor. We do not send your personal account information, payment data, or the full content of scanned websites to AI providers.
AI providers process this data under strict data processing agreements and do not use your data to train their models. See our [Subprocessor List](/subprocessors) for the current AI provider(s).
The optional ShieldWave Security plugin for WordPress runs inside your own site and, by default, sends nothing externally. When you enable its intelligence features, up to three data flows may occur:
Groq processes these excerpts under a data processing agreement and does not use them to train its models. See our [Subprocessor List](/subprocessors).
---
We share personal data only with the following categories of recipients, each bound by appropriate data processing agreements:
We use third-party service providers to operate the Service. A current list is maintained in our [Subprocessor List](/subprocessors), including:
If you configure integrations (Slack, Microsoft Teams, webhooks), scan results and notification data are transmitted to those third-party services at your direction.
We may disclose personal data if required to do so by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of Ensomedia, our users, or the public.
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity. We will notify affected users before their data is transferred and becomes subject to a different privacy policy.
We do not sell personal data to third parties. We do not share personal data for advertising purposes.
---
Ensomedia is based in the European Economic Area (EEA). Where we transfer personal data outside the EEA (for example, to subprocessors in the United States), we ensure appropriate safeguards are in place, including:
You may request a copy of the applicable transfer safeguards by contacting us at contact@ensomedia.pl.
---
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy:
| Data Category | Retention Period | |---|---| | Account data | Duration of account + 30 days after deletion request | | Billing and payment data | Duration of account + 5 years (tax/legal obligations) | | Scan results and reports | Duration of account; deleted within 30 days of account deletion. Free plan: results retained for 90 days. | | Scan configuration data | Duration of account | | Usage and technical data | 26 months from collection | | Communication data (support) | 3 years from last interaction | | Marketing consent records | Until consent is withdrawn + 3 years for proof |
Upon account deletion, we will delete or anonymize all personal data within 30 days, except where longer retention is required by law (e.g., tax and accounting records).
---
As a data subject, you have the following rights:
Send your request to contact@ensomedia.pl with the subject line "GDPR Request". We will respond within 30 days. We may request verification of your identity before processing the request.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland:
Prezes Urzedu Ochrony Danych Osobowych ul. Stawki 2, 00-193 Warszawa, Poland Website: https://uodo.gov.pl
---
We implement appropriate technical and organizational measures to protect personal data, including:
---
ShieldWave Pro is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at contact@ensomedia.pl.
---
The Service may contain links to third-party websites or services. This Policy does not apply to third-party sites. We encourage you to review the privacy policies of any third-party service before providing personal data.
---
We may update this Policy from time to time. We will notify you of material changes by:
The updated Policy will indicate the "Last updated" date at the bottom. Continued use of the Service after changes constitutes acceptance of the revised Policy.
---
For any questions, concerns, or requests regarding this Privacy Policy or our data processing practices:
Ensomedia ul. Chorwacka 33/42 51-107 Wroclaw, Poland Email: contact@ensomedia.pl
---
Last updated: February 2026