ShieldCore — powered by Verona
Terms of usePrivacy notice
LEGAL / PRIVACY

Privacy notice

How personal data is handled when ShieldCore members and authorised collaborators use the internal workspace.

Effective
16 September 2026
Service
ShieldCore Intra
Operator
ShieldCore L.L.C-FZ

1. Controller and contact

ShieldCore L.L.C-FZ is the controller for personal data processed in ShieldCore Intra.

Meydan Grandstand, 6th floor
Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates
Formation number: 2650857

Portal and privacy enquiries: antti.nokka@shieldcore-dc.com

2. Scope

This notice applies to intra.shieldcore-dc.com. The service is a restricted internal workspace. It is not a public website, customer portal or marketing service.

Microsoft 365, SharePoint and Pipedrive have their own privacy notices. Intra links to those services but does not automatically copy the Pipedrive CRM database into Intra.

3. Personal data processed

  • Identity and access: Microsoft Entra user ID, name, company email address, membership status and assigned portal roles.
  • Authentication and security: hashed session tokens, encrypted Microsoft token cache, sign-in events, access changes, audit events and relevant timestamps.
  • Work records: content a user creates or edits, including meeting notes, decisions, actions, due dates, workspace links, review history and revision history.
  • Directory information: colleague name, work email address and business phone number where supplied.
  • Business contact information: names, roles, contact details and meeting context concerning customers, suppliers or other professional contacts when an authorised user records them in legitimate company work.
  • Files and media: SharePoint file names, links and metadata returned for the signed-in user, plus authorised local previews and company media that may depict identifiable people.
  • Technical information: limited request, error and security information generated by the application and hosting infrastructure.

4. Sources

Data comes from the user, ShieldCore administrators and colleagues, the company’s Microsoft Entra tenant, Microsoft Graph and SharePoint, and legitimate business communications or source material entered into a workspace. SharePoint results are returned according to the signed-in user’s existing Microsoft permissions.

5. Purposes and legal grounds

PurposeGround
Authenticate approved users and maintain access controlsPerformance of company arrangements, security and legitimate operational interests
Provide knowledge, customer-work coordination, meetings, actions, directories and file accessPerformance of company arrangements and legitimate interests in operating the business
Maintain revisions, audit trails, backups and incident evidenceSecurity, accountability, legal obligations and establishment or defence of legal claims
Comply with law and respond to authorised requestsLegal obligation and applicable public-interest requirements

Where applicable law requires consent for a specific activity, ShieldCore will request it separately. A Microsoft permission screen controls delegated technical access; it is not used as a substitute for the legal ground required for personal-data processing.

6. Microsoft permissions

Normal sign-in requests basic profile information and delegated permission to read files the signed-in account can already access. A user with the publisher role may separately grant delegated write permission to create or replace approved PDF files in SharePoint. ShieldCore has not granted the portal application-only file access or organisation-wide file access.

Revoking a delegated permission may stop the related SharePoint feature from working. It does not automatically erase records already lawfully retained in Intra or SharePoint.

7. Cookies

Intra uses only cookies required to sign in and keep the service secure:

  • shieldcore_auth: temporary Microsoft sign-in state, up to 10 minutes.
  • shieldcore_session: authenticated portal session, up to 8 hours. It is HttpOnly, Secure in production and SameSite=Lax.

Intra does not use advertising, behavioural-tracking or analytics cookies.

8. Recipients and service providers

Personal data is available only to authorised ShieldCore users according to their roles and record permissions, and to administrators or infrastructure operators where needed to operate, secure or recover the service.

Service-provider categories include Microsoft for Entra ID, Microsoft Graph and SharePoint, and the infrastructure provider that hosts the private application and PostgreSQL services. Providers process data under their applicable agreements and instructions. Data may also be disclosed when required by law or necessary to establish, exercise or defend legal claims.

Pipedrive is a separate CRM. Opening a Pipedrive link transfers the user to Pipedrive; Intra does not perform an automatic CRM data sync.

9. Storage and international transfers

Portal records, permissions, revisions, audit entries and encrypted session material are stored in ShieldCore’s managed PostgreSQL service on its production VPS. Original working files remain in Microsoft SharePoint. Protected database backups are held for service recovery.

ShieldCore is established in the United Arab Emirates and uses providers that may process data in other countries. Where transfer rules apply, ShieldCore uses the provider’s applicable contractual and organisational safeguards and any additional safeguard required by law.

10. Retention

  • Sign-in transactions expire after 10 minutes.
  • Portal sessions expire after 8 hours; signing out deletes the active portal session.
  • Deactivating a member blocks access and deletes that member’s active sessions.
  • Work records, revisions and audit entries remain while needed for active business, accountability, contractual obligations, legal requirements or legal claims. Records may be archived before removal.
  • SharePoint files follow the retention and version-history settings applied in Microsoft 365.
  • Backups remain until replaced or deleted under the operational backup schedule.

Retention may be extended when necessary for an investigation, dispute, legal hold or mandatory recordkeeping.

11. Security

Measures include approved membership, role and record-level permissions, HTTPS, a private database network, hashed session tokens, encrypted Microsoft token caches, security headers, audit records and protected backups. Users must still avoid placing sensitive personal information in Intra unless it is necessary, authorised and appropriate for the selected access level.

12. Individual rights

Depending on the law that applies, a person may request access, correction, erasure, restriction, objection, portability or information about the processing of their personal data. A person may also withdraw consent where consent is the ground used. These rights can be limited by legal duties, the rights of others, security requirements and the need to establish or defend legal claims.

Send a request to antti.nokka@shieldcore-dc.com. ShieldCore may need to verify identity before acting. Requests will be handled within the period required by applicable law.

A person may also raise a concern with the UAE Data Office. Where the EU General Data Protection Regulation applies, a person may contact the data-protection authority for their habitual residence, place of work or the alleged infringement through the European Data Protection Board’s authority directory.

13. Automated decisions and children

Intra does not use personal data for automated decisions, profiling or advertising. The service is intended for authorised professional users and is not directed to children.

14. Changes

This notice will be updated when the service, its providers or its processing practices materially change. The effective date at the top identifies the current version.

SHIELDCORE L.L.C-FZ · FORMATION NO. 2650857Return to sign in →