Contracting Entity: Assets Flow Ltd. (the "Company," "we," "us," or "our")
Last Updated: August 6, 2026
Product: Shield (shield.assetsflow.work) — the due-diligence information product
HOUSE OF BRANDS NOTICE. This Privacy Policy applies to Shield only. The AssetsFlow portfolio tracker at
assetsflow.workhas its own Privacy Policy athttps://assetsflow.work/legal/privacy. Capitalized terms used but not defined here have the meaning given in the AssetsFlow and Shield Terms of Service v3.0.
STATUS NOTICE — IN-HOUSE DRAFT FOR OUTSIDE-COUNSEL REVIEW. This Privacy Policy was drafted in-house from the Shani review dated 2026-07-04 and the IL reverse-search opinion dated 2026-07-10. Sections flagged
[FOR COUNSEL REVIEW]require sign-off by EU DPA-level counsel and IL privacy counsel before being relied upon in commerce for EU/UK/IL customers.
This Privacy Policy describes how Assets Flow Ltd. collects, uses, retains, and shares personal data when you use Shield (the "Free Scan" / "Rung 0", Quick Flag, Contract Report, Sponsor Report, or Forensic Diligence Report).
This Policy does not cover:
| Category | Examples | Purpose |
|---|---|---|
| Account auth | Email address, Firebase Auth UID | Account creation, login, report delivery |
| Search queries | Entity name, brand URL, domain, CIK, company number, address | The input to the Shield report you purchased |
| Clickwrap consents | ToS acceptance timestamp, ToS version | Contract formation proof |
| Free Scan acceptance | Per-scan clickwrap timestamp | Per Section 1.1 of ToS, each Free Scan requires affirmative acceptance |
| (Optional) Contact emails | shield-support@assetsflow.work correspondence | Support, refund processing |
| Category | Examples | Purpose |
|---|---|---|
| Shield Report content | Aggregated citations to public records, source URLs, retrieval timestamps | The deliverable |
| Search history | What entity you investigated, when, from what IP | Abuse prevention, rate limiting, defense retention |
| Audit logs | API call timestamps, source-URL hits, cache hits/misses | Operational, debugging, defense |
For entity-level Shield Reports, Shield queries public-record sources and receives names, roles, and identifiers of officers, directors, principals, or authorized persons ("Director Network Data"). Sources include:
Director Network Data is about the sponsor entity's principals, not about you (the Shield customer). Your relationship to Director Network Data is as a recipient, not a data subject. The principals' rights with respect to Director Network Data are described in Section 6.
For EU/UK users, we process personal data under the following lawful bases:
| Data category | Lawful basis (GDPR Art. 6) | Reference |
|---|---|---|
| Account auth, clickwrap consents | (b) Contract performance — necessary to deliver the Shield report you purchased | Art. 6(1)(b) |
| Search queries | (b) Contract performance | Art. 6(1)(b) |
| Shield Report content (delivered) | (b) Contract performance + (f) Legitimate interest (defense retention per Section 8) | Art. 6(1)(b) + 6(1)(f) |
| Director Network Data | (f) Legitimate interest — aggregate publicly-filed affiliations to enable customer due diligence | Art. 6(1)(f); LIA on file |
| Audit logs, search history | (f) Legitimate interest — abuse prevention, rate limiting, defense | Art. 6(1)(f) |
| (Optional) Contact emails | (a) Consent — you emailed us | Art. 6(1)(a) |
A Legitimate Interests Assessment (LIA) is on file for each Art. 6(1)(f) basis. [FOR COUNSEL REVIEW] — the LIA has not been independently reviewed by EU DPA-level counsel.
We use personal data to:
We do not use personal data to:
For Shield paid purchases, Paddle.com Market Limited is the legal seller. Paddle receives: your email, payment details (we never see the card), billing country, and the product ID purchased. Paddle's Privacy Policy governs payment data: https://www.paddle.com/legal/privacy.
When you query Shield, we make outbound requests to public-record APIs and websites (SEC, OFAC, CourtListener, etc.). These sources may log the fact of the query (entity name searched, timestamp, our server IP). They do not receive your identity — they see Assets Flow Ltd. as the requester.
We use the following service providers to operate Shield:
| Provider | Purpose | Data accessed |
|---|---|---|
| Google Cloud Platform / Firebase | Hosting, Firestore database, Auth | All Shield data |
| Paddle | Payment processing | Email, billing country (via MoR flow) |
| Cloudflare | CDN, DDoS protection, Pages hosting for shield.assetsflow.work | IP addresses, request metadata |
| Sentry (production only) | Error monitoring | Stack traces (PII scrubbed before send) |
We do not use any provider for advertising, behavioral tracking, or data resale.
Shield customer data is confidential. We do not share, sell, rent, or barter Shield customer identities, contact information, or search history with any third party, including:
This is both a legal protection and the Burned-LP trust signal — Shield customers investigate sponsors precisely because they cannot trust the syndication network. Shield customer data is retained solely for: (1) delivering the purchased report; (2) the defense-retention purposes in Section 8; (3) cross-user cache (Section 5.5).
shieldExternalCache)To provide reasonable response times and rate-limit our queries against public sources, Shield maintains a cross-user cache of public-record query results in Firestore (shieldExternalCache collection). This cache contains only public-record data about sponsor entities — never Shield customer identities, never search history, never the fact that "Customer X searched Entity Y."
When customer B searches "Acme LLC," the system may serve a cached result from customer A's earlier search for the same entity. The cache entry is not attributable to customer A.
Cache TTL: 7 days default (varies per source; some sources override per their ToS).
Director Network Data describes principals of sponsor entities — not Shield customers. These data subjects have the following rights under GDPR / UK GDPR / IL PPL:
Data subjects may exercise these rights by emailing privacy@assetsflow.work. We respond within 30 days (GDPR Art. 12(3)).
Mirror-only mechanism: Where the underlying public source still hosts the data, Shield's cached copy is not the authoritative record. Rectification requests are forwarded to the source; we re-mirror when the source updates.
[FOR COUNSEL REVIEW] — the mirror-only mechanism has not been reviewed for Art. 5(1)(d) accuracy compliance.
Shield data is stored on Google Cloud Platform (europe-west1 region by default; some failover in us-central1). Firebase Authentication stores user identifiers globally for performance.
Assets Flow Ltd. is incorporated in Israel. EU/UK personal data is transferred to Israel for processing. Lawful basis: Israel-EU adequacy decision (2023) and Israel-UK adequacy regulations (2022). No Standard Contractual Clauses are required.
When Shield queries US public-record sources (SEC, OFAC, etc.), the response data is stored in europe-west1. If Director Network Data concerns a US person, that data is processed in europe-west1 but the data subject's home jurisdiction (US) does not restrict the transfer.
shield.assetsflow.work is served via Cloudflare's global CDN. Cloudflare may serve content from edge locations worldwide; IP addresses of visitors are processed by Cloudflare per their Privacy Policy.
The Firestore shieldExternalCache collection, where it caches Israeli-sourced Director Network Data (ISA registrar data, broker registry data), may constitute a "database" under Israeli Privacy Protection Law §2(9) and §8א, triggering mandatory registration with the Israeli Privacy Protection Authority.
Status: Registration is pending. Shield does not currently query Israeli sources for EU/UK/IL customers; when Israeli sources are activated, registration will be completed first. [FOR COUNSEL REVIEW]
| Data category | Retention period | Legal basis |
|---|---|---|
| Shield Report content (delivered) | 7 years from delivery | Defense — defamation limitation IL 1yr oral / 3yr written; US states up to 2-3yr; UK 1yr |
| Source URLs in delivered reports | Same as report — 7 years | Defense: ability to reproduce exact report as-delivered |
| Payment records (via Paddle) | 7 years | IL tax law (7-year floor) |
| Consent records (ToS acceptance, clickwrap) | Indefinite | Defense — contract formation proof |
| Account auth data (email, uid) | Until account closure + 30 days | Operational |
| Search history (what entity you investigated) | Until account closure + 30 days | Highest-sensitivity datum — deleted promptly post-closure (Shani Q3 ruling 2026-08-06) |
Cross-user cache (shieldExternalCache) | Per-source TTL (default 7 days) | Operational; not user-attributable |
| Person-level background results (cache layer) | Linked to source retention | GDPR Art. 5(1)(e) storage-limitation |
When you close your account:
If a defamation, negligence, or consumer-protection claim is asserted against Assets Flow Ltd. arising from a Shield Report, the relevant Report, its source URLs, and its delivery timestamp are retained until 7 years after final resolution of the claim (regardless of the schedule above).
Within 30 days of any deletion request under Section 9, Shield verifies that retained data cannot be re-identified back to you. Payment records post-deletion are keyed by Paddle order ID, not by your email. no-reidentification.spec.ts (engineering trip-wire) is the verification mechanism.
Depending on your jurisdiction, you may have the following rights:
| Right | GDPR ref | CCPA ref | IL PPL ref |
|---|---|---|---|
| Access | Art. 15 | §1798.100, §1798.110 | §1 |
| Rectification | Art. 16 | §1798.106 | §11 |
| Erasure | Art. 17 | §1798.105 | §11 |
| Object / opt-out | Art. 21 | §1798.120 | §11 |
| Portability | Art. 20 | §1798.130 | — |
| Withdraw consent | Art. 7(3) | — | §11 |
Email privacy@assetsflow.work with:
The following survive a deletion request (with notice to you):
We do not discriminate against users who exercise privacy rights. Shield's pricing and availability are the same regardless of whether you exercise a privacy right.
security@assetsflow.work.In the event of a personal-data breach affecting EU/UK data subjects, we notify the supervisory authority within 72 hours (GDPR Art. 33). For IL data subjects, we comply with PPL §17E breach-notification requirements. For US data subjects, we comply with applicable state breach-notification laws.
No system is perfectly secure. We do not warrant absolute security. The measures in Section 10.1 are reasonable but not exhaustive.
Shield is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe we have collected data from a child under 16, email privacy@assetsflow.work and we will delete it.
Shield reports on entities (not individuals); the FCRA Option B architecture means Shield is not used for the kinds of eligibility decisions (employment, housing, credit) that typically implicate children's-data rules.
Shield is not a consumer reporting agency and Shield Reports are not consumer reports under the Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.) or any equivalent state law. This is the cornerstone Option B Information-Only architecture described in ToS §5.
You may not use Shield data for any purpose covered by FCRA §604 (employment, credit, insurance, tenant screening) or equivalent state laws. See ToS §3.4 for the FCRA permissible-purpose prohibition.
We may update this Privacy Policy. Material changes will:
legal-doc-version meta tag in the deployed HTML.We will not retroactively apply material changes to data already collected under a prior version.
| Topic | |
|---|---|
| Privacy requests (access, deletion, objection) | privacy@assetsflow.work |
| Shield support (refund, report defect) | shield-support@assetsflow.work |
| Security (vulnerability disclosure, breach) | security@assetsflow.work |
| Legal (counsel, regulators) | legal@assetsflow.work |
| General | service@assetsflow.work |
Data Protection Officer (informal): Until a formal DPO is appointed under GDPR Art. 37, privacy requests are handled by the founder (Victor Bar) at privacy@assetsflow.work.
Lead supervisory authority (EU): Pending — will be the Irish DPC once EU customers are onboarded.
Israeli Privacy Protection Authority: Registration pending per Section 7.5.
This Privacy Policy is incorporated by reference into the AssetsFlow and Shield Terms of Service v3.0. Material modifications to either document require re-acceptance under ToS §20.
| Privacy section | ToS section |
|---|---|
| §2.3 Director Network Data | ToS §16.2 (GDPR lawful basis) |
| §5.4 Cross-user prohibition | ToS §14.5 (Shield carve-out) |
| §5.5 Cross-user cache | ToS §6.4 (Shield retention carve-out) |
| §6 Director Network Data subject rights | ToS §16.4 |
| §7.5 IL database registration | ToS §16.5 |
| §8 Retention schedule | ToS §6.4 |
| §12 FCRA Notice | ToS §3.4 + §5 |
Prepared 2026-08-06 as in-house draft V1.0 for outside-counsel review. Status of counsel review tracked in Documents/Legal/TOS_V3_HANDOFF_MEMO_2026-07-04.md.