Shield by Assets Flow
English · עברית · Home

Privacy Policy

Version: 1.0 | Effective Date: July 27, 2026 | Governing Law: State of Israel (with US + UK carve-outs per AssetsFlow ToS §19)

Contracting Entity: Assets Flow Ltd. (the "Company," "we," "us," or "our") Last Updated: August 6, 2026 Product: Shield (shield.assetsflow.work) — the due-diligence information product

HOUSE OF BRANDS NOTICE. This Privacy Policy applies to Shield only. The AssetsFlow portfolio tracker at assetsflow.work has its own Privacy Policy at https://assetsflow.work/legal/privacy. Capitalized terms used but not defined here have the meaning given in the AssetsFlow and Shield Terms of Service v3.0.

STATUS NOTICE — IN-HOUSE DRAFT FOR OUTSIDE-COUNSEL REVIEW. This Privacy Policy was drafted in-house from the Shani review dated 2026-07-04 and the IL reverse-search opinion dated 2026-07-10. Sections flagged [FOR COUNSEL REVIEW] require sign-off by EU DPA-level counsel and IL privacy counsel before being relied upon in commerce for EU/UK/IL customers.


1. What This Policy Covers

This Privacy Policy describes how Assets Flow Ltd. collects, uses, retains, and shares personal data when you use Shield (the "Free Scan" / "Rung 0", Quick Flag, Contract Report, Sponsor Report, or Forensic Diligence Report).

This Policy does not cover:


2. Data We Collect

2.1 Data You Provide

CategoryExamplesPurpose
Account authEmail address, Firebase Auth UIDAccount creation, login, report delivery
Search queriesEntity name, brand URL, domain, CIK, company number, addressThe input to the Shield report you purchased
Clickwrap consentsToS acceptance timestamp, ToS versionContract formation proof
Free Scan acceptancePer-scan clickwrap timestampPer Section 1.1 of ToS, each Free Scan requires affirmative acceptance
(Optional) Contact emailsshield-support@assetsflow.work correspondenceSupport, refund processing

2.2 Data We Generate

CategoryExamplesPurpose
Shield Report contentAggregated citations to public records, source URLs, retrieval timestampsThe deliverable
Search historyWhat entity you investigated, when, from what IPAbuse prevention, rate limiting, defense retention
Audit logsAPI call timestamps, source-URL hits, cache hits/missesOperational, debugging, defense

2.3 Data We Receive From Public Sources (Director Network Data)

For entity-level Shield Reports, Shield queries public-record sources and receives names, roles, and identifiers of officers, directors, principals, or authorized persons ("Director Network Data"). Sources include:

Director Network Data is about the sponsor entity's principals, not about you (the Shield customer). Your relationship to Director Network Data is as a recipient, not a data subject. The principals' rights with respect to Director Network Data are described in Section 6.

2.4 Data We Do NOT Collect


3. Lawful Basis for Processing (GDPR)

For EU/UK users, we process personal data under the following lawful bases:

Data categoryLawful basis (GDPR Art. 6)Reference
Account auth, clickwrap consents(b) Contract performance — necessary to deliver the Shield report you purchasedArt. 6(1)(b)
Search queries(b) Contract performanceArt. 6(1)(b)
Shield Report content (delivered)(b) Contract performance + (f) Legitimate interest (defense retention per Section 8)Art. 6(1)(b) + 6(1)(f)
Director Network Data(f) Legitimate interest — aggregate publicly-filed affiliations to enable customer due diligenceArt. 6(1)(f); LIA on file
Audit logs, search history(f) Legitimate interest — abuse prevention, rate limiting, defenseArt. 6(1)(f)
(Optional) Contact emails(a) Consent — you emailed usArt. 6(1)(a)

A Legitimate Interests Assessment (LIA) is on file for each Art. 6(1)(f) basis. [FOR COUNSEL REVIEW] — the LIA has not been independently reviewed by EU DPA-level counsel.


4. How We Use Data

We use personal data to:

  1. Deliver Shield reports you purchase (contract performance).
  2. Prevent abuse — rate limiting (50 reports/user/hour for Premium), CAPTCHA detection, spam prevention.
  3. Retain for defense — see Section 8 (Retention).
  4. Comply with legal obligations — tax records, court orders, regulator requests.
  5. Improve source coverage — aggregate, anonymized analytics on which sources return data vs. fail (NOT on which entities you investigate).

We do not use personal data to:


5. Data Sharing

5.1 Paddle (Merchant of Record)

For Shield paid purchases, Paddle.com Market Limited is the legal seller. Paddle receives: your email, payment details (we never see the card), billing country, and the product ID purchased. Paddle's Privacy Policy governs payment data: https://www.paddle.com/legal/privacy.

5.2 Public-Record Sources

When you query Shield, we make outbound requests to public-record APIs and websites (SEC, OFAC, CourtListener, etc.). These sources may log the fact of the query (entity name searched, timestamp, our server IP). They do not receive your identity — they see Assets Flow Ltd. as the requester.

5.3 Service Providers

We use the following service providers to operate Shield:

ProviderPurposeData accessed
Google Cloud Platform / FirebaseHosting, Firestore database, AuthAll Shield data
PaddlePayment processingEmail, billing country (via MoR flow)
CloudflareCDN, DDoS protection, Pages hosting for shield.assetsflow.workIP addresses, request metadata
Sentry (production only)Error monitoringStack traces (PII scrubbed before send)

We do not use any provider for advertising, behavioral tracking, or data resale.

5.4 Cross-User Prohibition — Shield Customers

Shield customer data is confidential. We do not share, sell, rent, or barter Shield customer identities, contact information, or search history with any third party, including:

This is both a legal protection and the Burned-LP trust signal — Shield customers investigate sponsors precisely because they cannot trust the syndication network. Shield customer data is retained solely for: (1) delivering the purchased report; (2) the defense-retention purposes in Section 8; (3) cross-user cache (Section 5.5).

5.5 Cross-User Source Cache (shieldExternalCache)

To provide reasonable response times and rate-limit our queries against public sources, Shield maintains a cross-user cache of public-record query results in Firestore (shieldExternalCache collection). This cache contains only public-record data about sponsor entities — never Shield customer identities, never search history, never the fact that "Customer X searched Entity Y."

When customer B searches "Acme LLC," the system may serve a cached result from customer A's earlier search for the same entity. The cache entry is not attributable to customer A.

Cache TTL: 7 days default (varies per source; some sources override per their ToS).


6. Director Network Data — Data Subject Rights

Director Network Data describes principals of sponsor entities — not Shield customers. These data subjects have the following rights under GDPR / UK GDPR / IL PPL:

Data subjects may exercise these rights by emailing privacy@assetsflow.work. We respond within 30 days (GDPR Art. 12(3)).

Mirror-only mechanism: Where the underlying public source still hosts the data, Shield's cached copy is not the authoritative record. Rectification requests are forwarded to the source; we re-mirror when the source updates.

[FOR COUNSEL REVIEW] — the mirror-only mechanism has not been reviewed for Art. 5(1)(d) accuracy compliance.


7. Cross-Border Transfers

7.1 Storage Location

Shield data is stored on Google Cloud Platform (europe-west1 region by default; some failover in us-central1). Firebase Authentication stores user identifiers globally for performance.

7.2 EU/UK → Israel Transfer

Assets Flow Ltd. is incorporated in Israel. EU/UK personal data is transferred to Israel for processing. Lawful basis: Israel-EU adequacy decision (2023) and Israel-UK adequacy regulations (2022). No Standard Contractual Clauses are required.

7.3 Israel → US Transfer (for US-source data)

When Shield queries US public-record sources (SEC, OFAC, etc.), the response data is stored in europe-west1. If Director Network Data concerns a US person, that data is processed in europe-west1 but the data subject's home jurisdiction (US) does not restrict the transfer.

7.4 Cloudflare CDN

shield.assetsflow.work is served via Cloudflare's global CDN. Cloudflare may serve content from edge locations worldwide; IP addresses of visitors are processed by Cloudflare per their Privacy Policy.

7.5 Israeli Database Registration (PPL §8א)

The Firestore shieldExternalCache collection, where it caches Israeli-sourced Director Network Data (ISA registrar data, broker registry data), may constitute a "database" under Israeli Privacy Protection Law §2(9) and §8א, triggering mandatory registration with the Israeli Privacy Protection Authority.

Status: Registration is pending. Shield does not currently query Israeli sources for EU/UK/IL customers; when Israeli sources are activated, registration will be completed first. [FOR COUNSEL REVIEW]


8. Data Retention

8.1 Retention Schedule

Data categoryRetention periodLegal basis
Shield Report content (delivered)7 years from deliveryDefense — defamation limitation IL 1yr oral / 3yr written; US states up to 2-3yr; UK 1yr
Source URLs in delivered reportsSame as report — 7 yearsDefense: ability to reproduce exact report as-delivered
Payment records (via Paddle)7 yearsIL tax law (7-year floor)
Consent records (ToS acceptance, clickwrap)IndefiniteDefense — contract formation proof
Account auth data (email, uid)Until account closure + 30 daysOperational
Search history (what entity you investigated)Until account closure + 30 daysHighest-sensitivity datum — deleted promptly post-closure (Shani Q3 ruling 2026-08-06)
Cross-user cache (shieldExternalCache)Per-source TTL (default 7 days)Operational; not user-attributable
Person-level background results (cache layer)Linked to source retentionGDPR Art. 5(1)(e) storage-limitation

8.2 Account Closure

When you close your account:

8.3 Defense Retention

If a defamation, negligence, or consumer-protection claim is asserted against Assets Flow Ltd. arising from a Shield Report, the relevant Report, its source URLs, and its delivery timestamp are retained until 7 years after final resolution of the claim (regardless of the schedule above).

8.4 Verification

Within 30 days of any deletion request under Section 9, Shield verifies that retained data cannot be re-identified back to you. Payment records post-deletion are keyed by Paddle order ID, not by your email. no-reidentification.spec.ts (engineering trip-wire) is the verification mechanism.


9. Your Rights

Depending on your jurisdiction, you may have the following rights:

RightGDPR refCCPA refIL PPL ref
AccessArt. 15§1798.100, §1798.110§1
RectificationArt. 16§1798.106§11
ErasureArt. 17§1798.105§11
Object / opt-outArt. 21§1798.120§11
PortabilityArt. 20§1798.130
Withdraw consentArt. 7(3)§11

9.1 How to Exercise Rights

Email privacy@assetsflow.work with:

9.2 Response Window

9.3 What Survives Deletion

The following survive a deletion request (with notice to you):

9.4 Non-Discrimination

We do not discriminate against users who exercise privacy rights. Shield's pricing and availability are the same regardless of whether you exercise a privacy right.


10. Data Security

10.1 Measures

10.2 Breach Notification

In the event of a personal-data breach affecting EU/UK data subjects, we notify the supervisory authority within 72 hours (GDPR Art. 33). For IL data subjects, we comply with PPL §17E breach-notification requirements. For US data subjects, we comply with applicable state breach-notification laws.

10.3 No Absolute Security

No system is perfectly secure. We do not warrant absolute security. The measures in Section 10.1 are reasonable but not exhaustive.


11. Children's Privacy

Shield is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe we have collected data from a child under 16, email privacy@assetsflow.work and we will delete it.

Shield reports on entities (not individuals); the FCRA Option B architecture means Shield is not used for the kinds of eligibility decisions (employment, housing, credit) that typically implicate children's-data rules.


12. FCRA Notice

Shield is not a consumer reporting agency and Shield Reports are not consumer reports under the Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.) or any equivalent state law. This is the cornerstone Option B Information-Only architecture described in ToS §5.

You may not use Shield data for any purpose covered by FCRA §604 (employment, credit, insurance, tenant screening) or equivalent state laws. See ToS §3.4 for the FCRA permissible-purpose prohibition.


13. Changes to This Policy

We may update this Privacy Policy. Material changes will:

We will not retroactively apply material changes to data already collected under a prior version.


14. Contact Us

TopicEmail
Privacy requests (access, deletion, objection)privacy@assetsflow.work
Shield support (refund, report defect)shield-support@assetsflow.work
Security (vulnerability disclosure, breach)security@assetsflow.work
Legal (counsel, regulators)legal@assetsflow.work
Generalservice@assetsflow.work

Data Protection Officer (informal): Until a formal DPO is appointed under GDPR Art. 37, privacy requests are handled by the founder (Victor Bar) at privacy@assetsflow.work.

Lead supervisory authority (EU): Pending — will be the Irish DPC once EU customers are onboarded.

Israeli Privacy Protection Authority: Registration pending per Section 7.5.


15. Map to Terms of Service

This Privacy Policy is incorporated by reference into the AssetsFlow and Shield Terms of Service v3.0. Material modifications to either document require re-acceptance under ToS §20.

Privacy sectionToS section
§2.3 Director Network DataToS §16.2 (GDPR lawful basis)
§5.4 Cross-user prohibitionToS §14.5 (Shield carve-out)
§5.5 Cross-user cacheToS §6.4 (Shield retention carve-out)
§6 Director Network Data subject rightsToS §16.4
§7.5 IL database registrationToS §16.5
§8 Retention scheduleToS §6.4
§12 FCRA NoticeToS §3.4 + §5

Prepared 2026-08-06 as in-house draft V1.0 for outside-counsel review. Status of counsel review tracked in Documents/Legal/TOS_V3_HANDOFF_MEMO_2026-07-04.md.