Personal Data Protection Policy
This document fulfils the obligation under Article 17(k) of Law 1581 of 2012 and Article 13 of Decree 1377 of 2013 for the Controller to adopt an information processing policy.
1. Identification of the Controller
- Data Controller: Diego Alexander Carvajal (natural person), founder of ShieldLink.
- Identification: C.C. No. 1.144.171.850.
- Domicile: Bogotá D.C., Colombia.
- Email: protecciondedatos@shieldlink.cloud
- Area responsible for handling requests, consultations, and complaints: the Controller, via the email above.
2. Definitions (Law 1581, Art. 3)
- Personal data: any information linked to or associable with a specific or identifiable natural person.
- Sensitive data: data affecting the data subject's privacy or whose misuse may lead to discrimination (health, racial origin, biometrics, orientation, etc.).
- Data subject: the natural person whose data is processed.
- Processing: any operation on personal data (collection, storage, use, circulation, deletion).
- Controller / Processor: the party that decides on the processing / the party that carries it out on the Controller's behalf.
- Authorization: the data subject's prior, express, and informed consent.
3. Guiding principles
ShieldLink applies the principles of legality, purpose, freedom, truthfulness/quality, transparency, restricted access and circulation, security, and confidentiality (Law 1581, Art. 4), and the GDPR principles of lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
4. Processing and purposes
Data is processed solely for the purposes stated in the Privacy Policy, summarized as:
- Provide the anti-phishing protection of the extension (transient analysis of URLs and, upon suspicion, of a screen capture).
- Manage licensing: activate, validate, renew, block, and reactivate licenses.
- Administer the paid subscription: reconcile charges with Mercado Pago and send the license by email.
- Security and fraud/abuse prevention.
- Produce aggregated security reports (with no identifiable personal data).
- Handle requests, support, and legal obligations.
No processing is carried out for purposes other than or incompatible with the above.
5. Sensitive data
ShieldLink does not deliberately request or collect sensitive data. In visual analysis (AEGIS Vision), a screen capture could incidentally contain sensitive information visible at that moment; such capture is used only for the security verdict, is not retained, and no information is extracted from it. The data subject may disable visual analysis at any time. The data subject is not obligated to authorize the processing of sensitive data.
6. Data subject rights
Law 1581 (Art. 8): access, update, and rectify their data; request proof of authorization; be informed of the use given; file complaints with the SIC; revoke authorization and/or request deletion when there is no legal duty to retain; and access their data free of charge.
GDPR (Arts. 15–22): access, rectification, erasure, restriction, portability, objection, and not to be subject to automated decisions; and to lodge a complaint with the supervisory authority.
7. Controller's duties (Law 1581, Art. 17)
Guarantee the data subject the exercise of their rights; request and retain the authorization; inform the purpose; keep information under security conditions; process consultations and complaints within legal terms; update and rectify data; and use data only for authorized purposes.
8. Data subject's authorization
Authorization is obtained, depending on the context, through:
- The installation and activation of the extension and acceptance of this policy and the Privacy Policy.
- The subscription to a paid plan (acceptance upon contracting).
- Verifiable means that evidence prior, express, and informed consent.
The data subject may revoke it at any time by writing to protecciondedatos@shieldlink.cloud, unless a legal or contractual duty to retain the data exists.
9. Procedure for consultations and complaints
Single channel: protecciondedatos@shieldlink.cloud.
- Consultations (Law 1581, Art. 14): handled within a maximum of ten (10) business days. If not possible, the interested party is informed and it is handled within the following five (5) business days.
- Complaints (Law 1581, Art. 15): processed within a maximum of fifteen (15) business days from the day after receipt. If not possible, the interested party is informed and it is resolved within the following eight (8) business days. If the complaint is incomplete, the interested party is required to complete it within 5 days; after one month without a response, it is deemed withdrawn.
- GDPR requests: generally handled within one (1) month, extendable to two (2) months in complex cases, informing the interested party.
The data subject may only turn to the SIC once the process before the Controller has been exhausted (Law 1581, Art. 16).
10. Information security
ShieldLink adopts reasonable technical, human, and administrative measures to protect data against unauthorized access, loss, alteration, or fraudulent use: encryption in transit (HTTPS/TLS) and at rest, data minimization, access control, signature verification of payment notifications, and security testing, static code analysis, and capacity testing prior to each production deployment.
11. International transfers and transmissions
Some processors (Mercado Pago, Resend, VirusTotal, Anthropic) are located outside Colombia/the EU. Transfers and transmissions are carried out with appropriate safeguards (standard contractual clauses or other valid mechanisms) in accordance with Law 1581, Decree 1377, and the SIC guidelines, and Chapter V of the GDPR.
12. Processors
Mercado Pago (payments), Resend (email), VirusTotal (URL reputation), Anthropic (AI), crt.sh (domain age), and Umami (site analytics). They act on the Controller's behalf, under confidentiality and for authorized purposes.
13. National Database Registry (RNBD)
Should the Controller become subject to the obligation to register with the SIC under current regulations, it will register its databases in the RNBD and keep the information up to date.
14. Term
- Policy term: in force from its adoption (August 19, 2026) and remains in force until amended.
- Database term: data will be retained as long as the processing purpose subsists and/or the legal duty of retention exists (see "Retention" in the Privacy Policy).
15. Amendments
Any material change will be communicated by reasonable means before it takes effect, and the current version will be published at shieldlink.cloud.
Drafted as a technical-legal draft. Validation by a data protection lawyer is recommended before formal adoption.