Privacy notice status — draft
Controlled-preview status: the public privacy notice is under legal and operational review and is not yet effective.
Controlled-preview documentation
Shielda is not generally available. Source code, fixtures, tests, version labels, plans, and historical checklists do not establish live availability, compatibility, compliance, or contract terms.
DRAFT — NOT EFFECTIVE — LEGAL AND PRIVACY APPROVAL PENDING. This page is a public status note, not an approved privacy notice. It does not establish legal bases, processing roles, retention periods, transfer mechanisms, data-residency promises, or response deadlines.
Draft source reviewed: July 12, 2026
Effective date: Not established
Product status: Controlled preview
Website request data
The Shielda website request form asks for a name and email address. Company, request type, and message are optional. When the form is configured, those fields and a page-source label are sent to Shielda's request mailbox.
Do not submit passwords, API keys, source code, exploit payloads, customer data, or other sensitive information through the website form.
Candidate product data
Depending on an approved preview workflow, candidate data can include account and organization information, connected-service metadata, agent health, service inventory, scanner output, findings, evidence, model usage records, audit events, and support communications. This is an engineering inventory, not a statement that every category is collected in every deployment.
Shielda makes no blanket promise that all data remains in the customer environment. The actual data flow can depend on the connector, model policy, provider, workflow, and deployment configuration.
What remains under review
Before an effective notice is published, Shielda must reconcile and approve:
- the legal entity, privacy roles, contacts, and applicable jurisdictions;
- each live data store, processor, provider, purpose, and data category;
- processing and support locations, international transfers, and safeguards;
- retention, deletion, backup, export, and legal-hold behavior;
- data-subject request intake, identity verification, exceptions, and timing;
- browser storage, necessary cookies, optional analytics, and consent behavior;
- model-provider data handling, training, retention, and customer controls.
Optional website analytics
Google Analytics is off by default on the public website and its script loads only after a visitor allows optional analytics. Shielda's site-event layer limits events to allowlisted page and interaction fields. It does not send request-form contents, names, email addresses, URL queries, hashes, or referrers. A browser Do Not Track or Global Privacy Control signal keeps optional analytics off.
If enabled, Google can still receive and process network, browser, and device data as part of delivering the analytics service. This implementation description is not a complete cookie notice, provider contract statement, or legal-basis decision.
Browser replay, browser error/performance telemetry, and browser CSP reporting are not enabled by this analytics choice.
Current next step
Use the public privacy status page or contact Shielda for a deployment-specific question. Where a controlled preview requires privacy or data-processing terms, those terms must be agreed for that evaluation before product data is supplied.