Privacy Policy
Last updated: 17 August 2026
This Privacy Policy explains how [LEGAL ENTITY NAME] sp. z o.o. ("Package Shield", "we", "us") collects, uses, and protects personal data when you use the Package Shield platform and websites (the "Service").
We are the controller of the personal data described here. We process data in accordance with the EU General Data Protection Regulation (GDPR) and Polish data-protection law.
1. Who we are
The data controller is [LEGAL ENTITY NAME] sp. z o.o., [ul. ____, 00-000 ____, Poland] ([KRS 0000000000], NIP [0000000000]).
For any privacy matter, contact us at [email protected]. We have not appointed a Data Protection Officer; privacy requests are handled by the contact above.
2. Data we collect
Account and identity data
Your name, email address, hashed password, organization name, role, and team-membership details.
Billing data
Payments are processed by Stripe. We do not store full card numbers. We retain billing metadata such as your Stripe customer identifier, plan, subscription status, billing country, and VAT identifier where provided.
Cloud connection metadata
Configuration needed to operate your gateway: cloud account identifiers (e.g. AWS account ID and role ARN, or Google Cloud project ID and service-account email), region, and the CodeArtifact domain. We assume a role you grant us; we do not store long-lived cloud credentials or secret keys.
Package and usage metadata
Names, versions, and ecosystems of Packages routed through the Service, quarantine and approval decisions, policy configuration, and audit logs recording who performed which action and when.
Technical and communication data
IP address, browser/user-agent, session and authentication cookies, server logs, and the content of any messages you send to support or sales.
3. How we collect it
- Directly from you when you register, connect a Cloud Account, configure policies, or contact us.
- Automatically as you use the Service (logs, cookies, usage metadata).
- From Stripe, our payment processor, for billing status and metadata.
4. Why we process it (purposes and legal bases)
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide and operate the Service; manage your Account and Cloud Accounts; process Packages | Performance of a contract - Art. 6(1)(b) |
| Process payments and manage subscriptions | Performance of a contract - Art. 6(1)(b) |
| Secure the Service, prevent abuse and fraud, maintain audit logs, improve and develop the product | Legitimate interests - Art. 6(1)(f) |
| Keep accounting and tax records | Legal obligation - Art. 6(1)(c) |
| Send product/marketing communications (where applicable) | Consent - Art. 6(1)(a), or legitimate interest for existing customers |
Where we rely on legitimate interests, we balance them against your rights and freedoms. You may object at any time (see "Your rights").
7. International transfers
Some subprocessors may process data outside the European Economic Area (e.g. in the United States). Where they do, transfers are safeguarded by appropriate measures such as the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. You may request details of the safeguards in place.
8. Data retention
- Account and configuration data - for as long as your Account is active, and a reasonable period afterward to handle wind-down and disputes.
- Audit logs - retained for the period applicable to your plan and our security needs.
- Billing and accounting records - retained for the period required by Polish tax law (generally 5 years from the end of the relevant year).
- After the applicable period, we delete or anonymize the data.
9. How we protect data
- Encryption of data in transit (TLS).
- Role-based access controls and the principle of least privilege.
- We never store long-lived cloud credentials - access to your Cloud Account is obtained by assuming a role you grant, scoped to what the Service needs.
- Operational logging and monitoring to detect and respond to incidents.
No system is perfectly secure, but we take appropriate technical and organizational measures proportionate to the risk.
10. Your rights
Under the GDPR you have the right to:
- access your personal data and obtain a copy;
- rectify inaccurate or incomplete data;
- erasure ("right to be forgotten") in the circumstances provided by law;
- restrict or object to processing, including processing based on legitimate interests;
- data portability - receive your data in a structured, commonly used format;
- withdraw consent at any time, without affecting prior lawful processing.
To exercise any right, email [email protected]. You also have the right to lodge a complaint with the supervisory authority: President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, Poland (https://uodo.gov.pl).
11. Automated decision-making
The Service applies the screening and approval policies you configure for your Packages. We do not make decisions producing legal or similarly significant effects concerning you that are based solely on automated processing within the meaning of Art. 22 GDPR.
12. Children's data
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
13. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material, we will give reasonable notice (for example, by email or in-product). The "Last updated" date above reflects the latest version.
14. Contact
Privacy questions or requests: [email protected]. Postal address: [LEGAL ENTITY NAME] sp. z o.o., [ul. ____, 00-000 ____, Poland].
