GDPR compliance commitments.
ShadowMap processes personal data of EU and UK data subjects in two capacities — as controller for the people who deal with us, and as processor for everything inside a customer's tenant. A monitoring platform also holds material about people who never chose to deal with either of us. This page addresses all three.
1. Our commitment
ShadowMap is operated by Security Brigade InfoSec Private Limited ("Security Brigade"), a company incorporated in India with its registered office in Mumbai and offices in the United Kingdom, the United States and Singapore. We are committed to complying with Regulation (EU) 2016/679 (the "GDPR") and the UK General Data Protection Regulation as incorporated by the Data Protection Act 2018.
Although we are established in India, we offer the platform to organisations in the European Economic Area and the United Kingdom and monitor estates located there, so the GDPR applies to us under Article 3(2). We have implemented a compliance programme that applies across all our operations rather than only to European customers, because maintaining two standards inside one platform is how mistakes happen.
2. Controller and processor roles
Our role changes with the data, and the distinction matters more here than it does for a consulting firm.
- Controller. Website visitors, demo and enquiry contacts, prospective customer representatives, billing and commercial contacts, and our own record of who holds accounts in which tenant. We decide the purposes and means, so we are the controller.
- Processor. Everything inside a customer's ShadowMap tenant — discovered assets, exposed services, leaked code and secrets, brand-abuse cases, credential and dark-web exposure attributed to the customer, vendor exposure, validation evidence, workflow and audit history. This is processed on the customer's documented instructions against a scope the customer authorises, under our Data Processing Agreement. The customer is the controller.
The practical difference from a point-in-time security engagement is duration and standing state. A penetration test touches client data for a fortnight and stops. ShadowMap keeps a live, continuously refreshed model of the customer's external estate, and retains history so that today's finding can be compared against how the estate looked before. Our processor obligations therefore run for the whole subscription, and our deletion obligations are calendar-bound rather than engagement-bound (Section 14).
3. Third-party data in exposure intelligence
Some of the material ShadowMap collects concerns people who are neither our customers nor their employees. The clearest case is infostealer output: malware on someone's machine exfiltrates credentials, session cookies and tokens, autofill entries, browser history, payment and wallet artefacts, and machine information, and that data circulates in criminal markets. ShadowMap collects that material and reconstructs it into device-level compromise cases, because a security team that sees only a list of leaked passwords cannot tell a stale personal password from a live session against its own cloud tenant.
That processing is real and we will not describe it euphemistically. Here is how it is constrained:
- Lawful basis. We rely on legitimate interests under Article 6(1)(f). Recital 49 GDPR expressly recognises processing strictly necessary and proportionate for ensuring network and information security as constituting a legitimate interest, and detecting compromised credentials before they are used against a monitored estate is squarely within that. We have carried out and documented a balancing assessment for this activity.
- Attribution gates disclosure. A customer tenant surfaces only material correlated to that customer's identities and assets. The platform is not a searchable index over the corpus and cannot be used to look up an arbitrary individual or an unrelated organisation.
- Purpose limitation. The material is used to detect, evidence and help remediate exposure. It is not sold, not licensed as a data product, not used for marketing or profiling, and not used to enrich any contact database.
- Special categories. We do not seek Article 9 data. Where it is incidentally present in collected material, it is not extracted, indexed or used, and it is subject to the same access controls as everything else.
- Credentials are for revocation, not use. Recovered credentials are reported as compromised for rotation or revocation. They are tested only against a customer's own authorised in-scope estate, never against a third party.
- No transfer to model providers. Customer personal data is not transmitted to third-party large language model providers. That is a contractual commitment in our Data Processing Agreement.
If you are an individual whose data appears in this material, write to [email protected]. Where the material sits in a customer tenant we act as processor and will forward your request to that customer as controller, telling you we have done so. Where the request concerns the underlying corpus we hold, we handle it directly under Section 6.
4. Legal bases (Art. 6)
Acting as controller, we rely on:
- Performance of a contract (Art. 6(1)(b)). Provisioning tenants and user accounts, delivering onboarding and support, and administering the subscription.
- Legitimate interests (Art. 6(1)(f)). Direct marketing to enterprise prospects, product and website analytics, fraud prevention, securing our own network and services, and maintaining the exposure corpus described in Section 3. Legitimate Interest Assessments are carried out for each and records are maintained. You may object at any time (Section 6).
- Consent (Art. 6(1)(a)). Non-essential cookies and marketing subscriptions. Consent is obtained by clear affirmative action and can be withdrawn at any time, through the unsubscribe link in any marketing email or by writing to us.
- Legal obligation (Art. 6(1)(c)). Tax, corporate and statutory reporting obligations, including CERT-In incident reporting under Indian law.
Acting as processor we do not select a legal basis: we process on the controller's documented instructions and the controller determines the basis for the underlying processing.
5. Data we process about EU and UK data subjects
As controller, typically:
- business contact details — name, job title, company, work email, telephone number;
- the content of enquiries, including the apex domain submitted for an evaluation and any free-text message;
- platform account data — user name, work email, role assignment, session records and in-product activity and audit logs;
- correspondence, meeting notes and onboarding configuration decisions;
- commercial records — order forms, invoices and billing contacts;
- website usage data — IP address, browser type, pages visited, referral source.
We do not intentionally process special categories of personal data under Article 9 in this capacity, and we do not purchase contact data or enrich what you give us from third-party data brokers.
6. Data subject rights
Under the GDPR you have the following rights. They are not absolute and are subject to the exemptions in applicable law.
- Access (Art. 15) — confirmation of whether we process your data, a copy of it, and information about purposes, categories, recipients, retention and source.
- Rectification (Art. 16) — correction of inaccurate data and completion of incomplete data.
- Erasure (Art. 17) — deletion where the data is no longer necessary, where consent is withdrawn, or where you object and no overriding legitimate grounds apply.
- Restriction (Art. 18) — pausing processing while accuracy is verified or an objection is assessed.
- Portability (Art. 20) — receiving data processed by automated means on the basis of consent or contract, in a structured, machine-readable format.
- Objection (Art. 21) — to processing based on legitimate interests, and unconditionally to direct marketing, which we stop immediately on request.
- Automated decision-making (Art. 22) — see Section 7.
Contact [email protected]. We verify identity before acting and respond within one calendar month, extendable by two further months for complex or numerous requests with reasons given inside the first month.
Where we act as processor, we forward the request to the controller and do not respond substantively ourselves, other than to acknowledge receipt and direct you to the controller, as Article 28(3)(e) requires. For customers, we acknowledge data-subject-related requests within forty-eight hours and respond substantively within ten business days, faster where a customer's own statutory deadline requires it.
Erasure of exposure evidence may be constrained where the material is needed to evidence a security incident, to satisfy a statutory retention obligation, or to establish or defend a legal claim. Where we restrict or refuse, we explain why.
7. AI Review and Article 22
ShadowMap uses automated analysis to triage findings — scoring them, tagging them, and routing low-confidence results out of the working queue so analysts see what matters. Because that is automated processing applied to material that can include personal data, we set out how it works rather than leaving it implied.
- Automated review acts on findings about exposure, not on people. It does not evaluate, score or make decisions about individuals.
- Filtered findings are not deleted. They move to a filtered queue where they remain visible, searchable and auditable, with their verdict, score and tags attached.
- An analyst can return anything from that queue to the working workflow at any time, and an analyst decision always overrides the automated verdict.
- Every workflow state change is recorded in the audit log, so the decision trail is inspectable.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22. If that ever changes, this page will change first and appropriate safeguards will be described here.
8. Data Protection Officer
Data Protection Officer
Security Brigade InfoSec Private Limited
Email: [email protected]
Initial response: within 5 business days
9. International transfers
Personal data of EU and UK data subjects may be transferred to and processed in India, the United States, Singapore and the United Arab Emirates, where we operate. None of those is currently the subject of an adequacy decision covering our processing under Article 45. We therefore rely on the Article 46 safeguards below:
- Standard Contractual Clauses. The European Commission's SCCs (Implementing Decision (EU) 2021/914), Module Two, controller to processor, incorporated by reference into our Data Processing Agreement. The optional docking clause (Clause 7) and the independent-dispute-resolution option under Clause 11(a) are not selected.
- UK International Data Transfer Addendum. Version B1.0, in force 21 March 2022, for personal data subject to the UK GDPR.
- Transfer impact assessments. Consistent with Schrems II (Case C-311/18), we assess the legal framework of the receiving country and implement supplementary technical measures where an assessment calls for them.
- Supplementary measures. Encryption in transit and at rest, strict access control, and pseudonymisation where it does not defeat the security purpose.
Residency is configurable. Where a customer elects data localisation we configure storage and backup locations accordingly. Regions currently available are Mumbai, Paris, Singapore and Dubai, with further regions on request, and a customer-specific private-cloud deployment is available where region-level separation is insufficient. For an EU or UK customer, electing an EU region substantially narrows the transfer question at source.
10. Data Processing Agreement
Our standard DPA complies with Article 28 and is published in full — no form, no gate. Read or download the DPA. It covers:
- subject matter, duration, nature and purpose of processing, and the categories of data and data subjects;
- processing only on documented instructions;
- confidentiality obligations binding all personnel with access;
- technical and organisational measures under Article 32, set out in full in Annex B;
- the sub-processor regime, including thirty days' prior notice of any addition or replacement and a right to object on reasonable data-protection grounds;
- assistance with data subject rights, breach notification, DPIAs and prior consultation;
- deletion or return on termination, with the destruction windows in Section 14;
- audit and inspection rights, including on-site inspection where documentation is insufficient.
We also accept customer-provided DPAs. Send redlines or your draft to [email protected].
11. Sub-processors
Our current sub-processors, as recorded in Annex C of the DPA, are:
| Sub-processor | Role | Region |
|---|---|---|
| Cloudflare, Inc. | CDN, DNS, edge security, WAF | Global edge |
| Amazon Web Services, Inc. | Encrypted backup storage | Region-locked per customer election |
| SendGrid (Twilio Inc.) | Transactional email | United States |
| Mailtrap | Transactional email (non-production) | European Union |
| Twilio Inc. | Voice and SMS to customer-designated contacts | United States / global |
| Exotel Techcom Pvt. Ltd. | Voice to Indian-jurisdiction contacts | India |
| Microsoft Corporation | Operational email (Microsoft 365) | European Union / India |
| Google LLC | Operational email (Google Workspace) | European Union / India |
Each is bound by written obligations no less protective than those we owe our customers, and their security posture is reviewed annually. Deliberately not sub-processors: our source control, error tracking, internal audit management and CRM run self-hosted on our own infrastructure; large language model providers, because customer personal data is not transmitted to them; colocation operators, which provide physical hosting only and whose names are disclosed under non-disclosure on request; and background-check vendors, which process our own personnel data.
12. Breach notification
In the event of a personal data breach as defined in Article 4(12):
- As processor — we notify the customer as controller without undue delay and in any event within 72 hours of becoming aware, providing what the controller needs to meet its own Article 33 and 34 obligations. Where the full picture is not available at once, information follows in phases without further delay.
- As controller — we notify the competent supervisory authority within 72 hours of becoming aware where the breach is likely to result in a risk to the rights and freedoms of natural persons (Art. 33), and notify affected data subjects without undue delay where the risk is high (Art. 34).
Notifications describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. We also comply with CERT-In's mandatory incident reporting requirements under Indian law, including the six-hour reporting window in the directive of 28 April 2022, where the incident falls within its scope.
13. Data protection impact assessments
We conduct DPIAs under Article 35 before initiating processing likely to result in a high risk to data subjects, including new collection capabilities, material changes to how exposure material is processed, and new categories of customer deployment. Records are maintained and made available to supervisory authorities on request, and we assist customers with their own DPIAs and Article 36 consultations under the DPA.
14. Retention and erasure
Full retention periods are set out in our Privacy Policy. In summary: customer tenant data is retained for the subscription term, then destroyed within thirty days for live production systems and within ninety days for backup and archival systems; data retained under a statutory or regulatory obligation is kept for the shorter of the required period and seven years; and dark-web source material is retained on a permanent basis as a research corpus held outside customer tenants, because historical reprocessing against new identifiers is what makes an old compromise visible at all. Destruction follows standards consistent with NIST SP 800-88, and written certification is available on request.
15. Right to lodge a complaint
If you believe our processing infringes the GDPR you may complain to a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement (Art. 77). UK data subjects may complain to the Information Commissioner's Office at ico.org.uk.
We would rather you came to us first at [email protected] — it is usually faster, and we would rather fix the problem than argue about it.
16. Contact
Data Protection Officer
Security Brigade InfoSec Private Limited
Registered Office: Mumbai, Maharashtra, India
Email: [email protected]
Privacy enquiries: [email protected]
Contractual and legal enquiries: [email protected]
Security reports: [email protected]
Bring us your DPIA and your questionnaire.
Our DPA, sub-processor list and control documentation are published rather than gated. Where your review needs more, our DPO answers directly — and the technical walkthrough is still 30 minutes and an apex domain.