Skip to content
ShieldTrust

Privacy Policy

Last updated: July 31, 2026

This Privacy Policy explains how Kheiron Ventures S.L. ("Kheiron", "we") collects and processes personal data through the website shieldtrust.ai (the "Website"), in particular when you join the ShieldTrust early access waitlist.

We apply the principle of data minimisation: we collect only the data necessary for the purpose described, and we do not sell your personal data. This policy is provided for transparency in accordance with Regulation (EU) 2016/679 (GDPR) and the Spanish Data Protection Act (LOPDGDD). It does not constitute a contract or legal advice.

1. Who is responsible for your data

The controller of the personal data processed through this Website is:

We have not appointed a Data Protection Officer (DPO), as it is not mandatory for our activity; you may raise any data protection matter at hello@shieldtrust.ai.

2. Scope of this policy and product status

ShieldTrust is currently in a pre-launch stage. The Website's purpose is to present the product and let you join the early access waitlist; there is not yet an operating product that processes data on behalf of customers.

This policy covers only the personal data we process as controller in connection with this Website: the data you give us when joining the early access waitlist, and aggregate analytics about how the Website is used. Once ShieldTrust is operating as a live product, processing of your own end users' data will be governed by a customer agreement and, where applicable, a separate Data Processing Agreement (DPA), not by this policy.

3. What data we collect

Early access form. When you join the early access waitlist, we collect the email address you provide, which is required, and, where you choose to share them, your first and last name, organization, phone number and role. Providing these additional fields is voluntary.

Usage and technical data. When you visit the Website, our hosting provider processes limited technical data (such as your IP address and browser type) for security and service-operation purposes. Our audience analytics does not use cookies or personal identifiers (see section 4 and our Cookie Policy).

4. Why we process your data and on what legal basis

We process your personal data for the following purposes and legal bases under Article 6.1 GDPR:

We do not use your data for automated decisions that produce legal or similarly significant effects, and we do not carry out profiling for advertising purposes.

5. Who we share data with

We do not sell your personal data. We only share it with service providers (processors) that help us operate the Website and manage the early access waitlist, under contracts that require them to protect your data and use it only on our instructions:

We may also disclose data to public authorities where required by law.

6. International data transfers

Our providers (Vercel and Resend) are established, and may process data, in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards under Chapter V GDPR, such as the EU Standard Contractual Clauses and, where applicable, certification under the EU-U.S. Data Privacy Framework.

You can request more information about these safeguards by writing to hello@shieldtrust.ai.

7. How long we keep your data

We retain your early access request data for as long as needed to manage the early access process and any related follow-up, and afterwards for as long as required to comply with our legal obligations or handle potential claims, after which it is deleted or anonymised. If you decide not to proceed, you may request deletion of your data at any time.

8. Your rights

You have the right to access, rectify, erase, restrict and object to the processing of your personal data, to data portability, and to withdraw any consent you have given at any time (without affecting processing already carried out). To exercise these rights, write to hello@shieldtrust.ai; we may need to verify your identity.

If you believe your rights have not been respected, you may lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or your local supervisory authority.

9. How we protect your data

We apply technical and organisational measures appropriate to the risk, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

ShieldTrust is not currently certified against ISO/IEC 27001, ISO/IEC 42001 or SOC 2, and references to regulatory frameworks on this Website describe the product's design intent, not a certification or a guarantee of legal compliance.

10. Minors

The Website is aimed at a professional, business audience and not at minors. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, please contact us so we can delete it.

11. Changes to this policy

We may update this Privacy Policy to reflect changes in our practices, in the product's status, or in applicable law. We will publish the updated version here and revise the "Last updated" date shown above.

Back to shieldtrust.ai