At this stage, the SDK and its associated backend are operated by an independent developer or development team (hereinafter, “we”), not yet incorporated as a legal entity.
Once the company is established, this Privacy Policy will be updated to include the full corporate name, address, and tax information.
During SDK integration and use, we do not collect or store directly identifiable personal data, such as name, email, or phone number of end users.
However, the SDK may process technical data necessary to provide its security functionalities. These may include:
- IP address (anonymized or encrypted)
- Device or app identifiers (e.g., UUID, app ID)
- Connection times, performance metrics
- Encrypted traffic logs or session tokens (depending on configuration)
All this information is processed temporarily and securely, solely for technical or statistical purposes.
The SDK processes the above data exclusively to:
- Ensure the integrity and authenticity of communications
- Detect malicious use, fraud, or anomalies
- Monitor SDK performance
- Enable advanced security features (encryption, integrity control, etc.)
- We do not use data for profiling, marketing, or share it with third parties.
The legal basis for data processing is the legitimate interest of the Client (developer integrating the SDK) in protecting their application, in accordance with Article 6.1.f of the GDPR.
If the Client wishes to use the SDK to process personal data of their end users, it is the Client’s responsibility to obtain the necessary consents or ensure another valid legal basis.
At this stage, the technical data processed by the SDK is not shared with third parties. It may be temporarily hosted on servers of European cloud infrastructure providers (e.g., AWS, Hetzner, etc.), under contractual clauses compliant with the GDPR.
By default, we aim to keep all data within the European Union. If any transfer outside the EEA is made, it will be carried out in accordance with Chapter V of the GDPR, using standard contractual clauses approved by the European Commission.
Personal data is not retained longer than necessary to provide the service. In general, technical logs are automatically purged within less than 30 days, unless the Client configures a different period in their dashboard (if applicable).
As developers or data controllers, Clients must ensure the rights of their end users under the GDPR:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
Data subjects may exercise these rights by contacting the Client who integrated the SDK, as we do not directly identify end users.
We apply appropriate technical and organizational measures to ensure the confidentiality, integrity, and availability of the data processed by the SDK, including:
- End-to-end TLS encryption
- Data minimization
- Access logging and control
- Audit controls
We reserve the right to modify this Privacy Policy to reflect future legal, technical, or business changes. The updated version will be published on the project website or notified to Clients via email.
Once the team behind ShieldCert is legally incorporated as a company, this Policy will be updated to reflect the Controller’s information in accordance with Article 13 of the GDPR.
For inquiries about this Policy or data processing, you can contact:
🌐 [shieldcert.com]