Subprocessors and recipients
Version of 29 September 2026
1. What this list covers
1.1. This list is kept by Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG), "ENSOMEDIA" or "we" below.
1.2. Table 1 names our subprocessors, meaning the companies that process data our customers entrust to us. It is Annex III to the Data Processing Agreement. Tables 2 to 4 show who else receives data, and when. The Privacy Policy explains more.
1.3. Send questions, and requests for a copy of the safeguards for transfers outside the European Economic Area (EEA), to support@shieldwave.io.
2. How to follow changes
2.1. Every change means a new version of this page with a new date and an entry in the change history.
2.2. We announce a new or replacement subprocessor in Table 1 by e-mail to the customers bound by the Data Processing Agreement at least 14 days before the change, at the address registered to their account. Customers may object during that period (section 7.3 of the Data Processing Agreement).
2.3. The processing terms linked in Table 1 show the subcontractors our subprocessors use themselves.
3. Subprocessors for customer data
3.1. Table 1: companies that process data from the checks our customers order.
| Entity and country | What it does for us | Which data | Where it processes | Basis for transfer outside the EEA | Processing terms | On the list since |
|---|---|---|---|---|---|---|
| Google Cloud EMEA Limited, Ireland | Application servers, database, storage of keys, logs | All data covered by the Data Processing Agreement | Region europe-west1 (Belgium) | Data stored in the EU. Where Google companies in the USA have access: Data Privacy Framework and standard contractual clauses | Cloud Data Processing Addendum | 29 September 2026 |
| Cloudflare, Inc., USA | Protection against attacks, DNS, content delivery, encryption of connections | Every request to shieldwave.io and its response, with the IP address, including results and reports shown | USA and Cloudflare's network of data centres worldwide | Data Privacy Framework and standard contractual clauses | Data Processing Addendum | 29 September 2026 |
| Groq UK Limited, United Kingdom (contracting party) | AI analysis of findings and the plugin's second opinion | Domain, technical findings with up to 500 characters of evidence, homepage excerpt up to 3,000 characters, plugin file excerpt up to 6,000 characters | USA | Standard contractual clauses (Modules 2 and 3) in Groq's terms; no Data Privacy Framework | Customer Data Processing Addendum | February 2026 (then as Groq, Inc.) |
| Hostido.pl Gałązka Spółka jawna, ul. Kartuska 5, 80-103 Gdańsk, Poland (KRS 0000872620) | Mailboxes and sending the service's e-mail: check results, monitoring alerts, reports on request | Recipient's e-mail address, domain, results in the message | Poland | Not applicable | Terms | 29 September 2026 |
3.2. Our AI provider is contractually barred from using this data to train models. It does not store it, except for up to 30 days when it investigates a reliability problem or suspected abuse. We use no other AI provider. A new one will appear on this list first, announced under section 2.2.
3.3. During a check the scanner also asks public sources about the checked domain: crt.sh (certificate logs), Google's public DNS (dns.google), hstspreload.org, URLhaus (malicious addresses) and public DNS-based blocklists. They receive only the domain name, as in any public query, and do not process data on our behalf.
4. Services for our own purposes
4.1. Table 2: here we are the controller. The Privacy Policy gives the details.
| Entity and country | What for | Which data | Basis for transfer outside the EEA | Terms |
|---|---|---|---|---|
| Stripe Payments Europe, Limited, Ireland | Payments and subscriptions. Stripe is also a separate controller for fraud prevention and its own legal duties | E-mail address, user name, account identifier, payment details entered on Stripe's pages (we never see card numbers) | Stripe, LLC (USA): Data Privacy Framework and standard contractual clauses | Stripe Data Processing Agreement, Stripe Privacy Center |
| Google Ireland Limited, Ireland | Google Tag Manager and Google Analytics 4 only after consent to analytics; the marketing tags named in the consent window only after consent to marketing | Identifiers in cookies, IP address, pages visited, events | Google LLC (USA): Data Privacy Framework and standard contractual clauses | Google Ads Data Processing Terms |
| Hostido.pl Gałązka Spółka jawna, Gdańsk, Poland | Business mailbox: correspondence with customers | E-mail addresses, content of correspondence | Not applicable | Terms |
4.2. The providers in Table 1 also handle data for which we are responsible ourselves, for example account data and security logs. Invoices go to our accounting office and to the Polish national e-invoice system (KSeF). We give data to public authorities when the law requires it.
5. Recipients the customer chooses
5.1. Table 3: data goes here only when you set up the integration in your account yourself. These are not our subprocessors: your own contract with the provider governs their processing.
| Recipient | What we send |
|---|---|
| Slack | Domain, score, severity and number of problems, with an HMAC signature |
| Microsoft Teams | As above |
| Discord | As above |
| Your own webhook | As above, to the address you give |
6. Connections of the WordPress plugin
6.1. Table 4: the plugin "Ensomedia Security powered by shieldwave.io" runs on your server and connects to other servers from your site, not from ours. It sends e-mail through your site's own mail.
| Where to | When | What it sends |
|---|---|---|
| WordPress.org (api.wordpress.org, downloads.wordpress.org; WordPress Foundation, Automattic infrastructure) | By default, on every scan | The WordPress version and language, folder names and versions of plugins and themes, to fetch checksums. WordPress adds the site's address to its client identification (user agent) |
| ShieldWave: known-vulnerability lookup, protection rules, AI second opinion | Only when the site's administrator switches these functions on | The WordPress version, folder names and versions of plugins and themes; when fetching rules (about every 3 hours) the plugin version; for the second opinion an excerpt of the file of up to 6,000 characters without passwords, keys, e-mail addresses and the host name, sha256 and md5 fingerprints, size, folder name, rule identifiers, language, plugin version and a salted hash of the site |
| ShieldWave: account connection | Only after an API key is pasted; hourly signal and sync after each scan on the Pro and Enterprise plans | Site identifier, domain and address, versions of the plugin, WordPress and PHP, theme, language, score, list of problems (title, description, fix, path, address, line, CVE; a description can contain an account name), plugins and themes with versions |
6.2. With every connection to WordPress.org and to ShieldWave, the recipient sees your server's IP address. We process the data from the account connection on the customer's behalf under the Data Processing Agreement, and for a consumer as controller under our contract with them.
Change history
- 29 September 2026: replaces the list of February 2026. Removed: DigitalOcean (not used) and the unnamed mail provider. Added: Google Cloud, Cloudflare, Hostido.pl Gałązka Spółka jawna and the plugin's connections. Groq is named by its contracting party, Groq UK Limited. Slack and Microsoft Teams moved to the recipients the customer chooses, with Discord and custom webhooks. Stripe and Google Analytics are services for our own purposes.