Contracting Entity: Assets Flow Ltd. (the "Company," "we," "us," or "our")
Last Updated: August 6, 2026
Product: Shield (shield.assetsflow.work) — the due-diligence information product
HOUSE OF BRANDS NOTICE. This Privacy Policy applies to Shield only. The AssetsFlow portfolio tracker at
assetsflow.workhas its own Privacy Policy athttps://assetsflow.work/legal/privacy. Capitalized terms used but not defined here have the meaning given in the AssetsFlow and Shield Terms of Service v3.0.
STATUS NOTICE — IN-HOUSE DRAFT FOR OUTSIDE-COUNSEL REVIEW. This Privacy Policy was drafted in-house from the Shani review dated 2026-07-04 and the IL reverse-search opinion dated 2026-07-10. Sections flagged
[FOR COUNSEL REVIEW]require sign-off by EU DPA-level counsel and IL privacy counsel before being relied upon in commerce for EU/UK/IL customers.
This Privacy Policy describes how Assets Flow Ltd. collects, uses, retains, and shares personal data when you use Shield (the "Free Scan" / "Rung 0", Quick Flag, Contract Report, Sponsor Report, or Forensic Diligence Report).
This Policy does not cover:
| Category | Examples | Purpose |
|---|---|---|
| Account auth | Email address, Firebase Auth UID | Account creation, login, report delivery |
| Search queries | Entity name, brand URL, domain, CIK, company number, address | The input to the Shield report you purchased |
| Clickwrap consents | ToS acceptance timestamp, ToS version | Contract formation proof |
| Free Scan acceptance | Per-scan clickwrap timestamp | Per Section 1.1 of ToS, each Free Scan requires affirmative acceptance |
| Free Scan additional info (optional) | Up to 200 characters of free text you choose to add (e.g. an address or principal's name); cross-checked against that scan's own findings | Flags which findings match information you already have |
| (Optional) Contact emails | [email protected] correspondence | Support, refund processing |
| Category | Examples | Purpose |
|---|---|---|
| Shield Report content | Aggregated citations to public records, source URLs, retrieval timestamps | The deliverable |
| Search history | What entity you investigated, when, from what IP | Abuse prevention, rate limiting, defense retention |
| Free Scan carry-over | Random browser identifier (no name, no email), sponsor entity + state searched, scan result, any optional additional-info text (≤200 chars) | Reopen your free results from the same browser; enforce free-scan abuse caps (Section 8.1) |
| Audit logs | API call timestamps, source-URL hits, cache hits/misses | Operational, debugging, defense |
For entity-level Shield Reports, Shield queries public-record sources and receives names, roles, and identifiers of officers, directors, principals, or authorized persons ("Director Network Data"). Sources include:
Director Network Data is about the sponsor entity's principals, not about you (the Shield customer). Your relationship to Director Network Data is as a recipient, not a data subject. The principals' rights with respect to Director Network Data are described in Section 6.
For EU/UK users, we process personal data under the following lawful bases:
| Data category | Lawful basis (GDPR Art. 6) | Reference |
|---|---|---|
| Account auth, clickwrap consents | (b) Contract performance — necessary to deliver the Shield report you purchased | Art. 6(1)(b) |
| Search queries | (b) Contract performance | Art. 6(1)(b) |
| Shield Report content (delivered) | (b) Contract performance + (f) Legitimate interest (defense retention per Section 8) | Art. 6(1)(b) + 6(1)(f) |
| Director Network Data | (f) Legitimate interest — aggregate publicly-filed affiliations to enable customer due diligence | Art. 6(1)(f); LIA on file |
| Audit logs, search history | (f) Legitimate interest — abuse prevention, rate limiting, defense | Art. 6(1)(f) |
| Free Scan carry-over (anonymous visitors) | (f) Legitimate interest — let visitors reopen their own free results; prevent free-scan abuse | Art. 6(1)(f); LIA on file |
| (Optional) Contact emails | (a) Consent — you emailed us | Art. 6(1)(a) |
A Legitimate Interests Assessment (LIA) is on file for each Art. 6(1)(f) basis. [FOR COUNSEL REVIEW] — the LIA has not been independently reviewed by EU DPA-level counsel.
We use personal data to:
We do not use personal data to:
For Shield paid purchases, Paddle.com Market Limited is the legal seller. Paddle receives: your email, payment details (we never see the card), billing country, and the product ID purchased. Paddle's Privacy Policy governs payment data: https://www.paddle.com/legal/privacy.
When you query Shield, we make outbound requests to public-record APIs and websites (SEC, OFAC, CourtListener, etc.). These sources may log the fact of the query (entity name searched, timestamp, our server IP). They do not receive your identity — they see Assets Flow Ltd. as the requester.
We use the following service providers to operate Shield:
| Provider | Purpose | Data accessed |
|---|---|---|
| Google Cloud Platform / Firebase | Hosting, Firestore database, Auth | All Shield data |
| Paddle | Payment processing | Email, billing country (via MoR flow) |
| Cloudflare | CDN, DDoS protection, Pages hosting for shield.assetsflow.work | IP addresses, request metadata |
| Sentry (production only) | Error monitoring | Stack traces (PII scrubbed before send) |
We do not use any provider for advertising, behavioral tracking, or data resale.
Shield customer data is confidential. We do not share, sell, rent, or barter Shield customer identities, contact information, or search history with any third party, including:
This is both a legal protection and the Burned-LP trust signal — Shield customers investigate sponsors precisely because they cannot trust the syndication network. Shield customer data is retained solely for: (1) delivering the purchased report; (2) the defense-retention purposes in Section 8; (3) cross-user cache (Section 5.5).
shieldExternalCache)To provide reasonable response times and rate-limit our queries against public sources, Shield maintains a cross-user cache of public-record query results in Firestore (shieldExternalCache collection). This cache contains only public-record data about sponsor entities — never Shield customer identities, never search history, never the fact that "Customer X searched Entity Y."
When customer B searches "Acme LLC," the system may serve a cached result from customer A's earlier search for the same entity. The cache entry is not attributable to customer A.
Cache TTL: 7 days default (varies per source; some sources override per their ToS).
Director Network Data describes principals of sponsor entities — not Shield customers. These data subjects have the following rights under GDPR / UK GDPR / IL PPL:
Data subjects may exercise these rights by emailing [email protected]. We respond within 30 days (GDPR Art. 12(3)).
Mirror-only mechanism: Where the underlying public source still hosts the data, Shield's cached copy is not the authoritative record. Rectification requests are forwarded to the source; we re-mirror when the source updates.
[FOR COUNSEL REVIEW] — the mirror-only mechanism has not been reviewed for Art. 5(1)(d) accuracy compliance.
Shield data is stored on Google Cloud Platform (europe-west1 region by default; some failover in us-central1). Firebase Authentication stores user identifiers globally for performance.
Assets Flow Ltd. is incorporated in Israel. EU/UK personal data is transferred to Israel for processing. Lawful basis: Israel-EU adequacy decision (2023) and Israel-UK adequacy regulations (2022). No Standard Contractual Clauses are required.
When Shield queries US public-record sources (SEC, OFAC, etc.), the response data is stored in europe-west1. If Director Network Data concerns a US person, that data is processed in europe-west1 but the data subject's home jurisdiction (US) does not restrict the transfer.
shield.assetsflow.work is served via Cloudflare's global CDN. Cloudflare may serve content from edge locations worldwide; IP addresses of visitors are processed by Cloudflare per their Privacy Policy.
The Firestore shieldExternalCache collection, where it caches Israeli-sourced Director Network Data (ISA registrar data, broker registry data), may constitute a "database" under Israeli Privacy Protection Law §2(9) and §8א, triggering mandatory registration with the Israeli Privacy Protection Authority. The shieldRung0Scans collection (free-scan carry-over records) draws on US-only sources and contains no Israeli-sourced Director Network Data; it may contain optional visitor-provided free text (up to 200 characters), which is user input rather than systematically collected Director Network Data and raises no additional registration trigger. It is included in the pending registration census for completeness.
Status: Registration is pending. Shield does not currently query Israeli sources for EU/UK/IL customers; when Israeli sources are activated, registration will be completed first. [FOR COUNSEL REVIEW]
| Data category | Retention period | Legal basis |
|---|---|---|
| Shield Report content (delivered) | 7 years from delivery | Defense — defamation limitation IL 1yr oral / 3yr written; US states up to 2-3yr; UK 1yr |
| Source URLs in delivered reports | Same as report — 7 years | Defense: ability to reproduce exact report as-delivered |
| Payment records (via Paddle) | 7 years | IL tax law (7-year floor) |
| Consent records (ToS acceptance, clickwrap) | Indefinite | Defense — contract formation proof |
| Account auth data (email, uid) | Until account closure + 30 days | Operational |
| Search history (what entity you investigated) | Until account closure + 30 days | Highest-sensitivity datum — deleted promptly post-closure (Shani Q3 ruling 2026-08-06) |
| Free Scan results — not linked to an account | 30 days from the scan (automatic deletion may lag up to ~72 hours after expiry), including any optional additional-info text | Operational — reopen window for anonymous visitors; Art. 5(1)(e) storage-limitation |
| Free Scan results — linked to an account (claimed) | Treated as delivered content: 7 years from delivery (Section 8.2, 8.3), including any optional additional-info text | Defense — same basis as delivered Shield Reports |
Cross-user cache (shieldExternalCache) | Per-source TTL (default 7 days) | Operational; not user-attributable |
| Person-level background results (cache layer) | Linked to source retention | GDPR Art. 5(1)(e) storage-limitation |
When you close your account:
If a defamation, negligence, or consumer-protection claim is asserted against Assets Flow Ltd. arising from a Shield Report, the relevant Report, its source URLs, and its delivery timestamp are retained until 7 years after final resolution of the claim (regardless of the schedule above).
Within 30 days of any deletion request under Section 9, Shield verifies that retained data cannot be re-identified back to you. Payment records post-deletion are keyed by Paddle order ID, not by your email. no-reidentification.spec.ts (engineering trip-wire) is the verification mechanism.
Depending on your jurisdiction, you may have the following rights:
| Right | GDPR ref | CCPA ref | IL PPL ref |
|---|---|---|---|
| Access | Art. 15 | §1798.100, §1798.110 | §1 |
| Rectification | Art. 16 | §1798.106 | §11 |
| Erasure | Art. 17 | §1798.105 | §11 |
| Object / opt-out | Art. 21 | §1798.120 | §11 |
| Portability | Art. 20 | §1798.130 | — |
| Withdraw consent | Art. 7(3) | — | §11 |
Email [email protected] with:
Anonymous visitors (Free Scans only, no account): your free results are keyed to a random browser identifier, not to your identity. Clearing this site's browser data (cookies + local storage) immediately disassociates them from your browser; unclaimed results are auto-deleted ~30 days after the scan. To request erasure of a specific free scan without clearing site data, email [email protected] with the sponsor entity name and scan date.
The following survive a deletion request (with notice to you):
We do not discriminate against users who exercise privacy rights. Shield's pricing and availability are the same regardless of whether you exercise a privacy right.
[email protected].In the event of a personal-data breach affecting EU/UK data subjects, we notify the supervisory authority within 72 hours (GDPR Art. 33). For IL data subjects, we comply with PPL §17E breach-notification requirements. For US data subjects, we comply with applicable state breach-notification laws.
No system is perfectly secure. We do not warrant absolute security. The measures in Section 10.1 are reasonable but not exhaustive.
Shield is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe we have collected data from a child under 16, email [email protected] and we will delete it.
Shield reports on entities (not individuals); the FCRA Option B architecture means Shield is not used for the kinds of eligibility decisions (employment, housing, credit) that typically implicate children's-data rules.
Shield is not a consumer reporting agency and Shield Reports are not consumer reports under the Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.) or any equivalent state law. This is the cornerstone Option B Information-Only architecture described in ToS §5.
You may not use Shield data for any purpose covered by FCRA §604 (employment, credit, insurance, tenant screening) or equivalent state laws. See ToS §3.4 for the FCRA permissible-purpose prohibition.
We may update this Privacy Policy. Material changes will:
legal-doc-version meta tag in the deployed HTML.We will not retroactively apply material changes to data already collected under a prior version.
| Topic | |
|---|---|
| Privacy requests (access, deletion, objection) | [email protected] |
| Shield support (refund, report defect) | [email protected] |
| Security (vulnerability disclosure, breach) | [email protected] |
| Legal (counsel, regulators) | [email protected] |
| General | [email protected] |
Data Protection Officer (informal): Until a formal DPO is appointed under GDPR Art. 37, privacy requests are handled by the founder (Victor Bar) at [email protected].
Lead supervisory authority (EU): Pending — will be the Irish DPC once EU customers are onboarded.
Israeli Privacy Protection Authority: Registration pending per Section 7.5.
This Privacy Policy is incorporated by reference into the AssetsFlow and Shield Terms of Service v3.0. Material modifications to either document require re-acceptance under ToS §20.
| Privacy section | ToS section |
|---|---|
| §2.3 Director Network Data | ToS §16.2 (GDPR lawful basis) |
| §5.4 Cross-user prohibition | ToS §14.5 (Shield carve-out) |
| §5.5 Cross-user cache | ToS §6.4 (Shield retention carve-out) |
| §6 Director Network Data subject rights | ToS §16.4 |
| §7.5 IL database registration | ToS §16.5 |
| §8 Retention schedule | ToS §6.4 |
| §12 FCRA Notice | ToS §3.4 + §5 |
Prepared 2026-08-06 as in-house draft V1.0 for outside-counsel review. Status of counsel review tracked in Documents/Legal/TOS_V3_HANDOFF_MEMO_2026-07-04.md.