Privacy Policy
We take privacy as seriously as security. This policy explains what we collect, why, and the rights you have. Last updated: 2026.
This policy is provided for general information and does not constitute legal advice. If you have questions about how your data is handled, contact our data protection team at [email protected].
1. Who we are
CyberShield Security ("CyberShield", "we", "us") is a threat-intelligence and anti-abuse company. For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is CyberShield Security, operating from our EMEA headquarters at Neue Mainzer Straße 75, 60311 Frankfurt am Main, Germany, and our Americas headquarters at 1717 Pennsylvania Ave NW, Suite 1025, Washington, DC 20006, United States.
2. Data we collect
- Abuse-report submissions. When you report a domain or URL, we collect the submitted domain, any category or notes you add, and, if you provide it, your email address. Submitting an email is optional.
- Contact requests. When you use our contact form, we collect your name, email address and message.
- Technical data. Our servers automatically log IP address, user-agent, timestamps and request metadata to operate the service securely and prevent abuse.
- Cookies. We use only strictly necessary cookies. We do not run advertising or cross-site tracking cookies (see Section 8).
3. Why we use your data and our legal bases
- To investigate and remove online threats, our legitimate interest, and the public interest in a safer internet (GDPR Art. 6(1)(f)).
- To respond to your contact requests, to take steps at your request and, where relevant, with your consent (GDPR Art. 6(1)(a) and 6(1)(b)).
- To keep our service secure and prevent misuse, our legitimate interest (GDPR Art. 6(1)(f)).
- To meet legal obligations, where the law requires us to retain or disclose information (GDPR Art. 6(1)(c)).
4. How abuse-report submissions are used
Domains and URLs you submit are analyzed by our detection engine and reviewed by our analysts. Where a submission is confirmed malicious, the relevant indicators may be shared with registrars, hosting providers, content delivery networks, national CERTs and, where appropriate, law enforcement, in order to have the threat removed. We handle every submission in good faith and verify before enforcement.
5. Sharing your data
We do not sell personal data. We share data only with: (a) registrars, hosts, CDNs, CERTs and law-enforcement bodies as needed to action a confirmed threat; (b) service providers who process data on our behalf under contract (for example, cloud hosting); and (c) authorities where we are legally required to do so.
6. International transfers
As we operate in both the EU and the US, personal data may be transferred between these regions. Where personal data of individuals in the European Economic Area is transferred outside it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. Retention
We keep abuse-report and case data for as long as necessary to investigate threats, maintain an evidence trail and meet legal obligations, typically up to 24 months, after which records are anonymized or deleted. Contact-form data is retained for up to 12 months. Server logs are retained for up to 90 days unless needed for a security investigation.
8. Cookies
We use only essential cookies required for the site to function and to protect against abuse. We do not use advertising, profiling or third-party tracking cookies, and the site does not load third-party analytics or ad networks.
9. Your rights
Subject to applicable law, you have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on it. EU/EEA residents may also lodge a complaint with a supervisory authority. To exercise any right, contact [email protected].
10. Security
We protect personal data with encryption in transit, access controls, network segmentation and continuous monitoring. Our own operations are designed to the standards we recommend to clients.
11. Contact
Questions about this policy or your data can be sent to our data protection team at [email protected], or by post to either office listed in Section 1.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page.