Draft — pending legal review This text is published for review. It describes how we intend to operate, but it has not been signed off by counsel and may still change. For a binding version, or for a data processing agreement, write to hello@shielda.io.
Legal
Privacy Policy
Last updated 29 July 2026
ShieldAI is a compliance-training and AI-safety platform sold to companies. This policy explains what we do with personal data on this website, and what we do with it inside the platform on behalf of the companies that use it.
The short version
| What we process | Why | How long |
|---|---|---|
| Contact form: name, e-mail, company, message, page language | To answer your enquiry and, if it becomes one, to prepare an offer | 24 months after the last exchange |
| Server logs: IP address, browser, requested URL, timestamp | To keep the site running and to defend it against abuse | Up to 30 days |
| Platform accounts: name, work e-mail, department, progress, quiz results, certificates | To deliver the training and produce the completion records the employer needs | For the term of the customer's contract |
| Prompt Shield input: the text an employee pastes in for checking | To detect and mask sensitive data before it reaches an external AI tool | For that one request; never used as training data |
Who we are
ShieldAI operates this website and the ShieldAI platform. For anything in this policy — including a request to exercise your rights — write to hello@shielda.io, or to support@shielda.io if you already use the platform.
The formal controller entity, its registered address and, where one is required, the data protection officer will be named here before this policy leaves draft.
Two different roles
On this website we act as controller: we decide what happens with the data you send through the contact form.
Inside the platform we act as processor for our customers. Your employer decides who is enrolled, what is assigned and how long records are kept; we act on their documented instructions under a data processing agreement. If you are an employee of a ShieldAI customer and want your data corrected or deleted, start with your employer.
Data we process on this website
The contact form sends us your name, e-mail address, optionally your company, your message, and the language of the page you were on. There is one hidden field that only automated scripts fill in; if it is filled, the message is discarded.
Our web server records the usual technical log data: IP address, browser user agent, the URL requested and a timestamp.
This site sets no cookies, runs no analytics and embeds no advertising or social pixels. Typefaces are loaded from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address for that request.
Data we process inside the platform
For each learner: name, work e-mail address, department, assigned trainings, progress through the chapters, quiz attempts and results, and the certificates issued.
For administrators: the same data, plus the views built from it — completion rates, overdue enrolments and per-department risk.
For Prompt Shield: the text pasted in is analysed to find and mask personal and sensitive data. It is processed to answer that single request and is not used to train models.
Legal bases
For contact-form data: our legitimate interest in answering business enquiries and, once a contract is in sight, steps taken at your request before entering into it — Article 6(1)(f) and 6(1)(b) GDPR.
For platform data: we process on the customer's documented instructions. The customer relies on its own legal basis, usually the performance of the employment relationship and compliance with a legal obligation such as Article 4 of the EU AI Act.
How long we keep it
Contact enquiries: up to 24 months after the last message, unless the exchange turns into a contract, in which case commercial retention rules apply.
Server logs: up to 30 days.
Platform data: for as long as the customer's contract runs. On termination the data is returned or deleted according to the customer's instruction, within the agreed period.
Hosting and sub-processors
This website and the platform are hosted inside the European Union. We use a small number of sub-processors — hosting, e-mail delivery, and the sensitive-data detection service behind Prompt Shield, which runs on our own infrastructure.
The current list of sub-processors is available on request and will be published here before this policy leaves draft. Customers are notified before a new sub-processor is added.
Transfers outside the EEA
We aim to keep all processing inside the EEA. Where a transfer cannot be avoided, it takes place on the basis of an adequacy decision or the European Commission's standard contractual clauses, together with whatever additional measures the case requires.
Security
Access to personal data is limited to the people who need it, over encrypted connections, with authentication and audit logging. Backups are encrypted. Access rights are reviewed regularly, and affected customers are notified without undue delay if a personal data breach occurs.
Your rights
Under the GDPR you may request access to your personal data, its correction or erasure, restriction of processing, and portability, and you may object to processing based on legitimate interest.
Write to hello@shielda.io. We answer within one month. If you are an employee of a customer, we forward the request to your employer, who decides on it.
You also have the right to lodge a complaint with your national supervisory authority.
Changes to this policy
We update this page when the platform or our processing changes. The date at the top always reflects the current version, and material changes are communicated to customers directly.