Privacy Policy
Zero to One Flow (021flow, the “Company”) values your privacy and processes personal data in accordance with applicable law. This policy applies to the heimdallX service.
1. Data Controller
- Trade Name: Zero to One Flow (021flow)
- Representative: Sungtae Ryu
- Email: [email protected]
- Data Protection Officer: the Representative (Sungtae Ryu) [TODO: Confirm whether a separate DPO is appointed and add contact].
2. Personal Data We Collect
- Account data: email, name or nickname, login identifier.
- Authentication data: social login (Google/Apple, etc.) provider identifiers, token-related metadata.
- Payment-related data: payment status, subscription plan, billing date, receipt/order identifiers, Paddle customer ID or transaction ID. (The Company does not directly store payment-instrument data such as card numbers or CVC.)
- Service usage data: access logs, IP address, browser/device information, usage, error logs.
- Support data: inquiry content, email, attachments, conversation records.
- Information collected via cookies and similar technologies.
- Scan targets and content you input into the Service.
3. Purposes of Use
- Account registration and management.
- Providing the Service and verifying paid/subscription status.
- Payment, billing, refunds, and tax/accounting.
- Customer support and notices.
- Security, fraud prevention, and incident response.
- Service improvement, statistics, and analytics.
- Compliance with legal obligations.
4. Third-Party Sharing & Processors
To provide the Service, the Company may entrust or share personal data as below. This table is kept up to date with the providers actually in use.
| Processor / Recipient | Data Processed | Purpose | Retention | Overseas Transfer |
|---|---|---|---|---|
| Paddle.com | Payment status, order/transaction identifiers, billing data | Payment processing, taxes, receipts, refunds, payment-related support | Per applicable law and Paddle policy | Yes ([TODO: confirm country]) |
| Hosting provider | Data needed to operate the Service | Infrastructure operation | [TODO] | [TODO: confirm provider] |
| Email service | Email address, message content | Transactional/notice emails | [TODO] | [TODO] |
| Analytics | Usage logs, device info | Service analytics & improvement | [TODO] | [TODO] |
| Authentication provider | Social login identifiers | Login & authentication | [TODO] | [TODO] |
| AI API provider | Data needed for scan/analysis | AI analysis & remediation guidance | [TODO] | [TODO] |
| Database/storage provider | Service data | Data storage | [TODO] | [TODO] |
[TODO: Confirm the names of the hosting, email, analytics, authentication, AI API and storage providers, and each provider's data items, retention periods, and transfer countries.]
5. Overseas Transfers
Because the Company uses overseas providers (Paddle, cloud infrastructure, AI APIs, analytics), personal data may be transferred internationally. The recipient, destination country, data items, purpose, timing/method, and retention period for each provider are maintained together with the table in Section 4. [TODO: Confirm per-provider overseas-transfer details (country, retention).] You may refuse consent to overseas transfer, but some Service features may then be limited.
6. Retention
- On account closure, collected personal data is deleted without undue delay, as a general principle.
- However, payment/transaction/dispute records subject to statutory retention obligations may be kept for the legally required period.
- Backup data is deleted on a rolling basis according to the backup cycle.
- Minimum records needed to prevent abuse may be retained for the period permitted by law.
7. Your Rights
You may at any time request access to, correction or deletion of, or suspension of processing of your personal data, withdraw consent, or close your account. Exercise your rights via [email protected]; the Company will act without undue delay in accordance with applicable law.
8. Cookie Policy
- The Company uses cookies and similar technologies to keep you signed in, store preferences, and analyze the Service.
- Essential cookies are required to provide the Service; analytics/marketing cookies are optional.
- You can refuse cookies via your browser settings, but some features may then be limited.
- [TODO: Confirm whether a cookie consent banner is used and add a settings link.]
9. Security Measures
- Least-privilege access and administrator access controls.
- Encryption in transit and of key data.
- Access logging and backups.
- Regular security updates.
10. Children's Privacy
heimdallX is intended for security professionals and business (B2B) use and is not directed at children under 14. The Company does not knowingly collect personal data from children under 14 and will delete it without delay if discovered.
11. Changes to This Policy
This policy may be amended to reflect legal or service changes. For material changes, the Company will provide in-service notice or email before the effective date.
Effective Date: [TODO: Month Day], 2026