1. Data Controller
- Trade Name: Zero to One Flow (021flow)
- Representative: Sungtae Ryu
- Email: [email protected]
- Data Protection Officer: [TODO: Designate a DPO (for a sole proprietor, confirm whether this is the representative)]
2. Personal Data We Collect
- Account data: email, name or nickname, login identifier
- Authentication data: social login provider identifiers, token-related metadata
- Payment-related data: payment status, plan, billing date, receipt/order identifiers, Paddle customer ID or transaction ID (we do not store sensitive payment-instrument data such as card numbers or CVC)
- Usage data: access logs, IP address, browser/device information, usage metrics, error logs
- Support data: inquiry contents, email, attachments, conversation records
- Information collected via cookies and similar technologies
- Settings and content you enter into the service (e.g., agent configuration)
3. Purposes of Processing
- Registration and account management
- Providing and operating the service
- Verifying paid plan and subscription status
- Payment, billing, refunds, and tax/accounting
- Customer support and notices
- Security, fraud prevention, and incident response
- Service improvement, statistics, and analytics
- Compliance with legal obligations
4. Third-Party Sharing & Sub-Processors
To provide the service, the Company engages the following processors / recipients. Each processes personal data only within the scope of the engagement.
| Recipient / Processor | Data | Purpose | Retention | Overseas Transfer |
|---|---|---|---|---|
| Paddle.com | Payment status, subscription/order data, billing email | Payment processing, tax, receipts, refunds, payment support (Merchant of Record) | Per law and Paddle policy | Yes [TODO: confirm country] |
| Hosting provider | Data needed to operate the service | Infrastructure / hosting | Until end of engagement | [TODO: provider/country] |
| Email delivery service | Email address, delivery metadata | Transactional & support email | Until end of engagement | [TODO: provider/country] |
| Analytics tools | Access/usage logs, device info | Usage statistics & improvement | [TODO: confirm retention] | [TODO: provider/country] |
| Authentication provider | Social login identifiers | Login / authentication | While account is active | [TODO: provider/country] |
| AI API providers | Data included in analysis requests | AI analysis features | As needed to process requests | [TODO: provider/country] |
| Database / storage provider | Operational service data | Data storage | Until end of engagement | [TODO: provider/country] |
[TODO: Fill the table with the actual providers in use (Vercel/AWS/Cloudflare, Resend/SendGrid/SES, GA/PostHog, Google/Apple/GitHub, OpenAI/Anthropic/Google, MongoDB Atlas/S3, etc.) and confirmed retention periods]
5. Overseas Transfers
Because the Company uses overseas providers (Paddle, cloud infrastructure, AI APIs, analytics), personal data may be transferred abroad. The recipient, destination country, data transferred, purpose, timing/method, and retention follow the table above and each provider’s policy. You may object to overseas transfers, though doing so may limit parts of the service.
[TODO: Confirm per-provider overseas-transfer details (country, timing, method, retention)]
6. Retention
- As a rule, personal data is deleted without undue delay upon account closure.
- Records related to payments, transactions, and disputes may be retained for statutory periods where required by law (e.g., e-commerce regulations).
- Backups are deleted on a defined cycle, and minimal records may be kept for a limited period to prevent abuse.
[TODO: Confirm statutory retention periods per data type and the backup deletion cycle]
7. Your Rights
You may request access to, correction of, deletion of, or suspension of processing of your personal data, withdraw consent, and close your account. Requests can be sent to [email protected] and will be handled without undue delay as required by law.
8. Cookies
- We may use cookies and similar technologies to keep you signed in, store preferences, and analyze usage.
- Essential cookies are required to provide the service; analytics/marketing cookies are used for statistics and improvement.
- You can refuse cookies in your browser settings, though some features may be limited.
[TODO: Confirm whether a cookie banner/preferences tool will be used, and link it]
9. Security Measures
- Least-privilege access and access controls
- Encryption in transit and at rest
- Access logging and review
- Regular backups and security updates
- Administrative access controls
10. Children’s Privacy
The service is intended for adults and business users and does not knowingly register children under 14 (or the applicable age in your country). If we learn that we have collected such data, we delete it without delay.
11. Changes to this Policy
We may update this policy due to legal or service changes and will give advance notice of material changes via an in-service notice or email.
Effective Date: (Effective date pending), 2026
