HenKaiPan Privacy Policy

Effective date: August 25, 2026 · Governing law: Argentine Republic (Ley 25.326 and Decreto 746/2024)
Draft for review. This policy describes what personal data HenKaiPan processes. It is drafted to meet Argentine requirements (Ley 25.326, Decreto 746/2024, and AAIP guidance) and is designed to be GDPR-ready for future European customers. Confirm the legal entity ([legal entity, CUIT]) and datacenter/subprocessor details before publishing. "Business hours" means Monday–Friday, 09:00–18:00, Argentina time.

1. Who we are and data controller

HenKaiPan Cloud and Enterprise are provided by [Dyallab — legal entity, CUIT, registered address in Argentina] ("we", "us", "Provider"), the data controller for the account and telemetry data described below (sections 3 and 5), and a data processor acting on behalf of each Customer for data that Customer loads into the Service (section 4).

Delegate (Responsable) details registered with the AAIP National Register of Personal Databases: [registration number/s, pending registration before offering the Service in Argentina].

2. What this policy covers

This policy applies to the HenKaiPan Cloud and Enterprise managed services. It does not govern self-hosted deployments, where each organization is responsible for its own data as data controller under its own policies.

3. Data we process as controller (account and telemetry)

CategoryExamplesPurpose
Account data Name, username, work email, password hash Create and manage accounts, authenticate, provide the Service
Billing data Billing contact email, invoice data to the extent provided by the Customer Invoicing and payments
Telemetry Anonymous counts (scans, findings, projects), installation instance_id Product health, usage, and reliability
Support Emails and metadata you send to support Resolve requests

Legal bases: consent (Art. 5, Ley 25.326), performance of a contract, and legitimate interests of operating the Service. Telemetry can be disabled as described in section 6.

4. Data we process as processor (Customer environment data)

When Customer uses the Service to scan repositories and manage findings, we process the following on Customer's behalf, subject to the Data Processing Agreement (DPA) that forms part of the Customer's order:

For this data, Customer is the data controller and decides the purposes and means of processing. We process it solely on Customer's documented instructions. If we are required by law to process this data for another purpose, we will inform Customer unless the law prohibits it.

5. Telemetry and instance identification

6. Data we do not process

The HenKaiPan marketing site collects no personal data: there are no forms, no analytics, no cookies, and all conversion occurs via mailto: links. The self-hosted deployment can run fully offline with local AI (Ollama), in which case no finding data ever leaves the Customer's infrastructure.

7. Sub-processors and international transfers

Consent for international transfers (Art. 12, Ley 25.326). Some categories of data are processed by providers located outside of Argentina, including in the United States. By accepting these terms and using the Service, you consent to these transfers. Where the GDPR applies, transfers to providers rely on Standard Contractual Clauses (SCCs).
ProcessorPurposeLocation
ContaboDedicated VPS hosting per customer (backups/snapshots retained on the provider's infrastructure)United States — US Central, St. Louis (MO). EU data centers available for EU clients.
CloudflareTelemetry Worker, D1 storage, observability; edge/CDNUnited States / global edge
OpenRouter / Cloudflare Workers AIAI-assisted remediation and finding validation (when enabled)United States
GitHubVersion checks and PAT validationUnited States
Brevo (SMTP)Email delivery (notifications, digests) via smtp-relay.brevo.com[confirm Brevo data region]
Client-configured servicesJira, webhooks, custom integrations chosen by CustomerVaries by Customer configuration

We maintain an up-to-date list of sub-processors. We will notify Customers before adding or replacing a sub-processor materially involved in processing Customer data, with a right to object (DPA).

Sub-processor DPAs. Contabo (a German company subject to the GDPR) makes a data processing agreement available through its Customer Control Panel, which we have concluded for the hosting of customer instances. We likewise rely on the standard contractual frameworks of our other sub-processors.

8. Retention

DataRetention
Account and billing dataDuration of the contract plus tax/legal retention period
Customer environment dataAs long as needed to provide the Service; deleted on termination per the DPA
Audit logsUntil purged by the retention policy (12 months)
Webhook delivery logsUntil purged by the retention policy (12 months)
Telemetry pingsPurged 12–24 months after collection

Logs are rotated and jobs exist or will be enabled to purge expired data automatically.

9. Your rights (ARCO)

Under Ley 25.326 you have the right to Access, Rectify, Cancel (delete), and Oppose processing of your personal data ("ARCO rights"). For account data, we provide export and deletion; to exercise any ARCO right, email henkaipan@dyallab.com.ar or use the product's account deletion feature. We will respond within the period required by law (Art. 14, Reglamentación; Decreto 746/2024). For EU residents, corresponding rights apply under the GDPR.

If you believe data was processed unlawfully, you may file a claim with the Argentine data protection authority (AAIP).

10. Security

We apply technical and organizational measures to protect personal data, including: bcrypt password hashing, AES-256-GCM encryption of secrets at rest (SECRET_ENCRYPTION_KEY), HttpOnly session cookies, TLS in transit, least-privilege non-root containers, and per-customer dedicated infrastructure. Further detail is available in the DPA.

11. Data breach

In the event of a personal data breach likely to risk the rights of data subjects, we will notify affected Customers without undue delay and within 72 hours where the GDPR applies, and notify the relevant authorities as required by Argentine law and the AAIP.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified with reasonable notice (30 days) before they take effect.

13. Contact and data protection

Privacy inquiries: henkaipan@dyallab.com.ar. [Appoint an EU representative under GDPR Art. 27 when serving EU clients.] Provider: [legal entity, CUIT, registered address].