Subprocessors and recipients

Version of 29 September 2026

1. What this list covers

1.1. This list is kept by Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG), "ENSOMEDIA" or "we" below.

1.2. Table 1 names our subprocessors, meaning the companies that process data our customers entrust to us. It is Annex III to the Data Processing Agreement. Tables 2 to 4 show who else receives data, and when. The Privacy Policy explains more.

1.3. Send questions, and requests for a copy of the safeguards for transfers outside the European Economic Area (EEA), to support@shieldwave.io.

2. How to follow changes

2.1. Every change means a new version of this page with a new date and an entry in the change history.

2.2. We announce a new or replacement subprocessor in Table 1 by e-mail to the customers bound by the Data Processing Agreement at least 14 days before the change, at the address registered to their account. Customers may object during that period (section 7.3 of the Data Processing Agreement).

2.3. The processing terms linked in Table 1 show the subcontractors our subprocessors use themselves.

3. Subprocessors for customer data

3.1. Table 1: companies that process data from the checks our customers order.

Entity and countryWhat it does for usWhich dataWhere it processesBasis for transfer outside the EEAProcessing termsOn the list since
Google Cloud EMEA Limited, IrelandApplication servers, database, storage of keys, logsAll data covered by the Data Processing AgreementRegion europe-west1 (Belgium)Data stored in the EU. Where Google companies in the USA have access: Data Privacy Framework and standard contractual clausesCloud Data Processing Addendum29 September 2026
Cloudflare, Inc., USAProtection against attacks, DNS, content delivery, encryption of connectionsEvery request to shieldwave.io and its response, with the IP address, including results and reports shownUSA and Cloudflare's network of data centres worldwideData Privacy Framework and standard contractual clausesData Processing Addendum29 September 2026
Groq UK Limited, United Kingdom (contracting party)AI analysis of findings and the plugin's second opinionDomain, technical findings with up to 500 characters of evidence, homepage excerpt up to 3,000 characters, plugin file excerpt up to 6,000 charactersUSAStandard contractual clauses (Modules 2 and 3) in Groq's terms; no Data Privacy FrameworkCustomer Data Processing AddendumFebruary 2026 (then as Groq, Inc.)
Hostido.pl Gałązka Spółka jawna, ul. Kartuska 5, 80-103 Gdańsk, Poland (KRS 0000872620)Mailboxes and sending the service's e-mail: check results, monitoring alerts, reports on requestRecipient's e-mail address, domain, results in the messagePolandNot applicableTerms29 September 2026

3.2. Our AI provider is contractually barred from using this data to train models. It does not store it, except for up to 30 days when it investigates a reliability problem or suspected abuse. We use no other AI provider. A new one will appear on this list first, announced under section 2.2.

3.3. During a check the scanner also asks public sources about the checked domain: crt.sh (certificate logs), Google's public DNS (dns.google), hstspreload.org, URLhaus (malicious addresses) and public DNS-based blocklists. They receive only the domain name, as in any public query, and do not process data on our behalf.

4. Services for our own purposes

4.1. Table 2: here we are the controller. The Privacy Policy gives the details.

Entity and countryWhat forWhich dataBasis for transfer outside the EEATerms
Stripe Payments Europe, Limited, IrelandPayments and subscriptions. Stripe is also a separate controller for fraud prevention and its own legal dutiesE-mail address, user name, account identifier, payment details entered on Stripe's pages (we never see card numbers)Stripe, LLC (USA): Data Privacy Framework and standard contractual clausesStripe Data Processing Agreement, Stripe Privacy Center
Google Ireland Limited, IrelandGoogle Tag Manager and Google Analytics 4 only after consent to analytics; the marketing tags named in the consent window only after consent to marketingIdentifiers in cookies, IP address, pages visited, eventsGoogle LLC (USA): Data Privacy Framework and standard contractual clausesGoogle Ads Data Processing Terms
Hostido.pl Gałązka Spółka jawna, Gdańsk, PolandBusiness mailbox: correspondence with customersE-mail addresses, content of correspondenceNot applicableTerms

4.2. The providers in Table 1 also handle data for which we are responsible ourselves, for example account data and security logs. Invoices go to our accounting office and to the Polish national e-invoice system (KSeF). We give data to public authorities when the law requires it.

5. Recipients the customer chooses

5.1. Table 3: data goes here only when you set up the integration in your account yourself. These are not our subprocessors: your own contract with the provider governs their processing.

RecipientWhat we send
SlackDomain, score, severity and number of problems, with an HMAC signature
Microsoft TeamsAs above
DiscordAs above
Your own webhookAs above, to the address you give

6. Connections of the WordPress plugin

6.1. Table 4: the plugin "Ensomedia Security powered by shieldwave.io" runs on your server and connects to other servers from your site, not from ours. It sends e-mail through your site's own mail.

Where toWhenWhat it sends
WordPress.org (api.wordpress.org, downloads.wordpress.org; WordPress Foundation, Automattic infrastructure)By default, on every scanThe WordPress version and language, folder names and versions of plugins and themes, to fetch checksums. WordPress adds the site's address to its client identification (user agent)
ShieldWave: known-vulnerability lookup, protection rules, AI second opinionOnly when the site's administrator switches these functions onThe WordPress version, folder names and versions of plugins and themes; when fetching rules (about every 3 hours) the plugin version; for the second opinion an excerpt of the file of up to 6,000 characters without passwords, keys, e-mail addresses and the host name, sha256 and md5 fingerprints, size, folder name, rule identifiers, language, plugin version and a salted hash of the site
ShieldWave: account connectionOnly after an API key is pasted; hourly signal and sync after each scan on the Pro and Enterprise plansSite identifier, domain and address, versions of the plugin, WordPress and PHP, theme, language, score, list of problems (title, description, fix, path, address, line, CVE; a description can contain an account name), plugins and themes with versions

6.2. With every connection to WordPress.org and to ShieldWave, the recipient sees your server's IP address. We process the data from the account connection on the customer's behalf under the Data Processing Agreement, and for a consumer as controller under our contract with them.

Change history