Privacy Policy

Last updated: July 24, 2026 · Version 1.1

In case of divergence between language versions, the Portuguese version prevails.

1. Data Controller

Eter Growth, Lda., a company incorporated under Portuguese law, is the data controller for the personal data collected through the EterShield platform:

This channel is the single point of contact for exercising data subject rights and for any question about this processing. It is monitored and responses follow the deadlines set out in Article 12 GDPR.

2. Data Collected

CategoryDataOrigin
IdentificationName, email, job titleProvided by the user at registration
AuthenticationPassword (bcrypt hash), OAuth tokensGenerated automatically
BillingBilling email, Stripe ID (no card data)Stripe, Inc. (processor)
UsageAction logs, IP address, user agentLogged automatically
ContentData entered into the platform (risks, policies, etc.)Provided by the Customer — owned by the Customer

We do not collect special category data (health, ethnic origin, political opinions, etc.) or data belonging to minors under 18.

3. Purposes and Legal Bases

PurposeLegal Basis (GDPR)
Provision of the EterShield ServicePerformance of a contract (Art. 6(1)(b))
Billing and subscription managementPerformance of a contract (Art. 6(1)(b))
Security, fraud detection, and auditLegitimate interests (Art. 6(1)(f))
Service communications (alerts, invoices)Performance of a contract (Art. 6(1)(b))
Marketing communications (newsletters)Consent (Art. 6(1)(a)) — explicit opt-in
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

4. Processors

We rely on the following processors to deliver the Service. This list is current as of July 24, 2026; any change is announced 30 days in advance:

ProcessorFunctionLocation
OVH SAS (Kimsufi)Hosting, servers, database, cache and file storageFrance — European Union
Cloudflare, Inc.DNS, CDN and TLS proxy for the domainUS, with European nodes for EU traffic — SCCs
Stripe Payments Europe, Ltd.Payment processing and billingIreland (EU), with access by Stripe, Inc. in the US under SCCs
Anthropic PBCLanguage models (Claude) powering the AI featuresUS — SCCs; no retention and no model training on customer data
Resend (Plain Text, Inc.)Transactional email delivery (alerts, invitations, account recovery)US — SCCs
Google Ireland Ltd. (Google Drive)Off-site storage of encrypted backupsEU/US — SCCs; backups are AES-256 encrypted before upload and the key is not shared
Proton AGMailbox for the privacy and security contact channelsSwitzerland — European Commission adequacy decision

EterShield hosting, databases and file storage are located entirely within the European Union: customer data is not transferred outside the EEA for hosting purposes. Backups are AES-256 encrypted on the server itself before being replicated to off-site storage, so the storage provider has no access to their contents. Remaining transfers to third countries are limited to the processors listed above and rely on Standard Contractual Clauses (Implementing Decision (EU) 2021/914) together with supplementary measures. We do not rely on the EU-US Data Privacy Framework as a transfer mechanism.

The live processor list, published policies and compliance posture are available in the Trust Center.

5. Data Retention

6. Data Subject Rights

Under the GDPR, the data subject has the right to:

To exercise these rights, contact [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the CNPD (National Data Protection Commission).

7. Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, namely:

In the event of a data breach likely to result in a risk to the rights of data subjects, we will notify the CNPD within 72 hours and affected data subjects without undue delay.

8. Cookies

We only use cookies that are strictly necessary for session authentication and maintaining the application state. We do not use tracking, advertising, or third-party analytics cookies.

We log application errors for reliability purposes. That logging runs on our own infrastructure, with no third-party service involved: it does not collect IP address, user agent, cookies or any user identifier, and the page path is normalised — query strings, tokens and identifiers are stripped — before being written.

9. Changes to this Policy

Material changes will be communicated by email 30 days in advance. The current version is always available at etershield.com/privacy.

10. Contact

Data Controller: [email protected]
Eter Growth, Lda. — NIPC 519099761
Rua de Fundões 151, 3700-121 São João da Madeira, Portugal