Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Legal

Privacy Policy

Last updated: August 2026

Shards Cybersecurity (“we”, “us”, “our”) is committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Slovak data protection law.

1. Data controller

Shards Cybersecurity s.r.o.
Kopčianska 3756/10
851 01 Bratislava
Slovak Republic
IČO: 55151531 · IČ DPH: SK2121900253
privacy@shardscybersecurity.io

2. What data we collect, and where

We collect personal data at the point where you choose to give it to us — always with a notice at the form itself. On this site, that happens when you:

  • Send us a message via the contact form — name, work email, company name, your role, optional phone number, and the content of your message (including any supplier-context details you choose to share).
  • Apply for the pilot on the pilot page — name, work email, company name, role, supplier-portfolio size, and what brought you to us.
  • Ask for your readiness-check results by email on the NIS2 readiness check — email address, optional name, and a summary of your answers and score. The check itself runs entirely in your browser; nothing is sent to us unless you submit that form.
  • Request the supplier checklist on the supplier checklist page — email address, optional name, and a summary of your selections.
  • Join a waitlist or request a guide via the short email forms on sector and country pages — email address only.
  • Book a call — our booking link takes you to a Microsoft Bookings page operated on Microsoft 365. The details you enter there (name, email, chosen slot) are processed by Microsoft on our behalf, under Microsoft's privacy statement, and land in our calendar and mailbox.
  • Enter into an agreement with us — the contact and billing details needed to perform the contract.

If a future form collects something not listed here, the form itself will say so at the point of collection.

We also collect anonymised page-view counts via Cloudflare Web Analytics, a cookieless beacon that runs on every page. It does not set cookies, does not fingerprint your browser, and does not collect personal data — so no consent is required for it under GDPR.

On the /contact page, a Google Maps view of the office location and the Microsoft Bookings calendar are available as click-to-load embeds — no data is exchanged with Google or Microsoft unless you choose to load them. Google Maps is subject to Google's privacy policy. These third-party services are listed in more detail on our trust page and cookie policy.

3. Legal basis for processing

We process your data on the following legal bases (GDPR Article 6):

  • Contract — to perform the services you have engaged us for.
  • Legitimate interest — to respond to your enquiries.
  • Consent — where you tick a box asking us to contact you or send you a resource (readiness-check results, the supplier checklist, waitlists). You can withdraw consent at any time. Our web analytics is cookieless and collects no personal data, so it does not rely on consent.

4. How we use your data

We use your data solely to respond to enquiries, deliver contracted services, and (with your consent) send relevant communications. We do not sell or rent your data to third parties.

5. Data retention

We retain enquiry data for up to 24 months. Accounting and contract records are retained for 10 years in accordance with the Slovak Accounting Act (Act No. 431/2002 Coll., §35).

6. Your rights

Under GDPR you have the right to: access, rectify, erase, restrict processing of, and port your data. You may also object to processing and withdraw consent at any time. Contact us at privacy@shardscybersecurity.io to exercise any right. You may also lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR).

7. Cookies

See our Cookie Policy.