We treat client and learner data as sensitive by default. Assessment findings, engagement artefacts and lab activity are handled under least-privilege access controls and contractual confidentiality.

01 Information We Collect

We collect only what is necessary to deliver and secure our services:

  • Account and contact data — name, business email, phone number, company, job role and billing address.
  • Engagement data — scope documents, in-scope asset lists, authorisation letters, technical findings and remediation correspondence.
  • Training data — enrolment records, course progress, lab activity, assessment results and certificates issued.
  • Technical data — IP address, device and browser characteristics, pages viewed, referring URLs and security event logs.
  • Communications — support tickets, webinar registrations and email correspondence.

We do not intentionally collect special-category personal data and ask that you do not submit it to us.

02 How We Use Information

  • Deliver, schedule and support contracted security services and training programs.
  • Authenticate users, provision lab environments and prevent abuse or fraud.
  • Produce reports, invoices, certificates and required records.
  • Respond to enquiries, incidents and vulnerability disclosures.
  • Improve service quality, curriculum and platform reliability.
  • Meet legal, tax, export-control and regulatory obligations.
  • Send service messages and, where permitted, relevant marketing you may opt out of.

We process personal data on the bases of contract performance, legitimate interests (security, service improvement), consent (optional cookies and marketing) and legal obligation.

03 Cookies

We use essential cookies for session integrity and security, and optional analytics and marketing cookies only after you consent through our cookie banner. You may change or withdraw consent at any time. See our Cookie Policy for full detail.

04 Analytics

Where analytics are enabled with your consent, we review aggregated metrics such as page views, traffic sources and course engagement. We use analytics to improve content and performance, not to make automated decisions with legal effects about you.

05 Payment Information

Payments are processed by PCI-DSS compliant third-party payment processors. Full card numbers are submitted directly to the processor and are never stored on ShieldCore Security systems. We retain transaction identifiers, amounts, billing contact details and invoices for accounting, tax and dispute-handling purposes.

06 Third-Party Services

We use vetted providers for hosting, email delivery, payment processing, scheduling, ticketing, video conferencing and learning-platform delivery. Providers act on documented instructions under contractual confidentiality and security terms. We do not sell personal information.

Our sites may link to external resources. We are not responsible for the privacy practices of third-party sites you choose to visit.

07 Data Security

  • Encryption in transit using current TLS configurations.
  • Role-based, least-privilege access with multi-factor authentication for staff.
  • Segregated environments for client engagement data and training labs.
  • Logging, monitoring and defined incident-response procedures.
  • Background-checked practitioners bound by confidentiality obligations.

No method of transmission or storage is completely secure, and we do not claim absolute security. We retain personal data only as long as needed for the purposes above or as required by law, then delete or anonymise it.

08 User Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, port, restrict or object to the processing of your personal data, to withdraw consent, and to lodge a complaint with your supervisory authority. Where applicable law provides them, you may also opt out of sale or sharing of personal information and of targeted advertising.

Submit requests to privacy@shieldcoresec.com. We verify requests before acting and respond within the timeframe required by applicable law. Where we process data as a processor on behalf of a client, we refer the request to that client.

09 International Users

ShieldCore Security is headquartered in the United States and serves clients globally. Your information may be transferred to and processed in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer safeguards such as standard contractual clauses. Services are also subject to our Export Restrictions & Compliance terms.

10 Children's Privacy

Our services are intended for business users and adult learners. We do not knowingly collect personal information from children under 16. If you believe a minor has provided us information, contact us and we will delete it promptly.

11 Changes to This Policy

We may update this policy to reflect changes in our services, technology or legal obligations. We will revise the effective date above and, for material changes, provide additional notice. Continued use after the effective date constitutes acceptance.

12 Contact Information

ShieldCore Security · 350 Fifth Ave, New York, NY 10001, USA
Privacy: privacy@shieldcoresec.com
Legal: legal@shieldcoresec.com
Security disclosure: disclosure@shieldcoresec.com

This page is maintained by ShieldCore Security to describe our current practices. It is provided for information only, is not legal advice, and does not constitute independent certification or verification of any control. Where a signed master services agreement, statement of work, or data processing agreement exists, that document governs.