1. Controller and contact
ShieldCore L.L.C-FZ is the controller for personal data processed in ShieldCore Intra.
Meydan Grandstand, 6th floorMeydan Road, Nad Al Sheba
Dubai, United Arab Emirates
Formation number: 2650857
Portal and privacy enquiries: antti.nokka@shieldcore-dc.com
2. Scope
This notice applies to intra.shieldcore-dc.com. The service is a restricted internal workspace. It is not a public website, customer portal or marketing service.
Microsoft 365, SharePoint and Pipedrive have their own privacy notices. Intra links to those services but does not automatically copy the Pipedrive CRM database into Intra.
3. Personal data processed
- Identity and access: Microsoft Entra user ID, name, company email address, membership status and assigned portal roles.
- Authentication and security: hashed session tokens, encrypted Microsoft token cache, sign-in events, access changes, audit events and relevant timestamps.
- Work records: content a user creates or edits, including meeting notes, decisions, actions, due dates, workspace links, review history and revision history.
- Directory information: colleague name, work email address and business phone number where supplied.
- Business contact information: names, roles, contact details and meeting context concerning customers, suppliers or other professional contacts when an authorised user records them in legitimate company work.
- Files and media: SharePoint file names, links and metadata returned for the signed-in user, plus authorised local previews and company media that may depict identifiable people.
- Technical information: limited request, error and security information generated by the application and hosting infrastructure.
4. Sources
Data comes from the user, ShieldCore administrators and colleagues, the company’s Microsoft Entra tenant, Microsoft Graph and SharePoint, and legitimate business communications or source material entered into a workspace. SharePoint results are returned according to the signed-in user’s existing Microsoft permissions.
5. Purposes and legal grounds
Where applicable law requires consent for a specific activity, ShieldCore will request it separately. A Microsoft permission screen controls delegated technical access; it is not used as a substitute for the legal ground required for personal-data processing.
6. Microsoft permissions
Normal sign-in requests basic profile information and delegated permission to read files the signed-in account can already access. A user with the publisher role may separately grant delegated write permission to create or replace approved PDF files in SharePoint. ShieldCore has not granted the portal application-only file access or organisation-wide file access.
Revoking a delegated permission may stop the related SharePoint feature from working. It does not automatically erase records already lawfully retained in Intra or SharePoint.
7. Cookies
Intra uses only cookies required to sign in and keep the service secure:
- shieldcore_auth: temporary Microsoft sign-in state, up to 10 minutes.
- shieldcore_session: authenticated portal session, up to 8 hours. It is HttpOnly, Secure in production and SameSite=Lax.
Intra does not use advertising, behavioural-tracking or analytics cookies.
8. Recipients and service providers
Personal data is available only to authorised ShieldCore users according to their roles and record permissions, and to administrators or infrastructure operators where needed to operate, secure or recover the service.
Service-provider categories include Microsoft for Entra ID, Microsoft Graph and SharePoint, and the infrastructure provider that hosts the private application and PostgreSQL services. Providers process data under their applicable agreements and instructions. Data may also be disclosed when required by law or necessary to establish, exercise or defend legal claims.
Pipedrive is a separate CRM. Opening a Pipedrive link transfers the user to Pipedrive; Intra does not perform an automatic CRM data sync.
9. Storage and international transfers
Portal records, permissions, revisions, audit entries and encrypted session material are stored in ShieldCore’s managed PostgreSQL service on its production VPS. Original working files remain in Microsoft SharePoint. Protected database backups are held for service recovery.
ShieldCore is established in the United Arab Emirates and uses providers that may process data in other countries. Where transfer rules apply, ShieldCore uses the provider’s applicable contractual and organisational safeguards and any additional safeguard required by law.
10. Retention
- Sign-in transactions expire after 10 minutes.
- Portal sessions expire after 8 hours; signing out deletes the active portal session.
- Deactivating a member blocks access and deletes that member’s active sessions.
- Work records, revisions and audit entries remain while needed for active business, accountability, contractual obligations, legal requirements or legal claims. Records may be archived before removal.
- SharePoint files follow the retention and version-history settings applied in Microsoft 365.
- Backups remain until replaced or deleted under the operational backup schedule.
Retention may be extended when necessary for an investigation, dispute, legal hold or mandatory recordkeeping.
11. Security
Measures include approved membership, role and record-level permissions, HTTPS, a private database network, hashed session tokens, encrypted Microsoft token caches, security headers, audit records and protected backups. Users must still avoid placing sensitive personal information in Intra unless it is necessary, authorised and appropriate for the selected access level.
12. Individual rights
Depending on the law that applies, a person may request access, correction, erasure, restriction, objection, portability or information about the processing of their personal data. A person may also withdraw consent where consent is the ground used. These rights can be limited by legal duties, the rights of others, security requirements and the need to establish or defend legal claims.
Send a request to antti.nokka@shieldcore-dc.com. ShieldCore may need to verify identity before acting. Requests will be handled within the period required by applicable law.
A person may also raise a concern with the UAE Data Office. Where the EU General Data Protection Regulation applies, a person may contact the data-protection authority for their habitual residence, place of work or the alleged infringement through the European Data Protection Board’s authority directory.
13. Automated decisions and children
Intra does not use personal data for automated decisions, profiling or advertising. The service is intended for authorised professional users and is not directed to children.
14. Changes
This notice will be updated when the service, its providers or its processing practices materially change. The effective date at the top identifies the current version.
