HenKaiPan Privacy Policy
1. Who we are and data controller
HenKaiPan Cloud and Enterprise are provided by [Dyallab — legal entity, CUIT, registered address in Argentina] ("we", "us", "Provider"), the data controller for the account and telemetry data described below (sections 3 and 5), and a data processor acting on behalf of each Customer for data that Customer loads into the Service (section 4).
Delegate (Responsable) details registered with the AAIP National Register of Personal Databases: [registration number/s, pending registration before offering the Service in Argentina].
2. What this policy covers
This policy applies to the HenKaiPan Cloud and Enterprise managed services. It does not govern self-hosted deployments, where each organization is responsible for its own data as data controller under its own policies.
3. Data we process as controller (account and telemetry)
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, username, work email, password hash | Create and manage accounts, authenticate, provide the Service |
| Billing data | Billing contact email, invoice data to the extent provided by the Customer | Invoicing and payments |
| Telemetry | Anonymous counts (scans, findings, projects), installation instance_id | Product health, usage, and reliability |
| Support | Emails and metadata you send to support | Resolve requests |
Legal bases: consent (Art. 5, Ley 25.326), performance of a contract, and legitimate interests of operating the Service. Telemetry can be disabled as described in section 6.
4. Data we process as processor (Customer environment data)
When Customer uses the Service to scan repositories and manage findings, we process the following on Customer's behalf, subject to the Data Processing Agreement (DPA) that forms part of the Customer's order:
- Repository metadata (URLs, commit data), and contents of
findings.raw,code_snippet, anddescriptionfields, which may contain personal data (e.g., emails, IP addresses) present in scanned code; - Integration credentials (encrypted at rest) used to connect GitHub, Jira, webhooks, and email;
- SSO identity data (
sso_provider,sso_subject) for Enterprise login; - Audit logs, including the acting user's identifier, IP address, and before/after snapshots; and
- Webhook delivery logs (
payload,response_body).
For this data, Customer is the data controller and decides the purposes and means of processing. We process it solely on Customer's documented instructions. If we are required by law to process this data for another purpose, we will inform Customer unless the law prohibits it.
5. Telemetry and instance identification
- HenKaiPan collects anonymous, aggregate telemetry (counts only, no email addresses or IP addresses) to operate and improve the product. For self-hosted instances this uses a random installation UUID.
-
For Cloud and Enterprise, the installation identifier (
instance_id) is set to the Customer's tenant slug and may be linked to the account record. -
Telemetry can be disabled: for self-hosted via the
HENKAIPAN_TELEMETRY_ENABLEDenvironment variable; for Cloud and Enterprise it is on by default and can be turned off on request (we will configure the instance accordingly).
6. Data we do not process
The HenKaiPan marketing site collects no personal data: there are no forms, no
analytics, no cookies, and all conversion occurs via mailto: links.
The self-hosted deployment can run fully offline with local AI (Ollama), in which
case no finding data ever leaves the Customer's infrastructure.
7. Sub-processors and international transfers
| Processor | Purpose | Location |
|---|---|---|
| Contabo | Dedicated VPS hosting per customer (backups/snapshots retained on the provider's infrastructure) | United States — US Central, St. Louis (MO). EU data centers available for EU clients. |
| Cloudflare | Telemetry Worker, D1 storage, observability; edge/CDN | United States / global edge |
| OpenRouter / Cloudflare Workers AI | AI-assisted remediation and finding validation (when enabled) | United States |
| GitHub | Version checks and PAT validation | United States |
| Brevo (SMTP) | Email delivery (notifications, digests) via smtp-relay.brevo.com | [confirm Brevo data region] |
| Client-configured services | Jira, webhooks, custom integrations chosen by Customer | Varies by Customer configuration |
We maintain an up-to-date list of sub-processors. We will notify Customers before adding or replacing a sub-processor materially involved in processing Customer data, with a right to object (DPA).
Sub-processor DPAs. Contabo (a German company subject to the GDPR) makes a data processing agreement available through its Customer Control Panel, which we have concluded for the hosting of customer instances. We likewise rely on the standard contractual frameworks of our other sub-processors.
8. Retention
| Data | Retention |
|---|---|
| Account and billing data | Duration of the contract plus tax/legal retention period |
| Customer environment data | As long as needed to provide the Service; deleted on termination per the DPA |
| Audit logs | Until purged by the retention policy (12 months) |
| Webhook delivery logs | Until purged by the retention policy (12 months) |
| Telemetry pings | Purged 12–24 months after collection |
Logs are rotated and jobs exist or will be enabled to purge expired data automatically.
9. Your rights (ARCO)
Under Ley 25.326 you have the right to Access, Rectify, Cancel (delete), and Oppose processing of your personal data ("ARCO rights"). For account data, we provide export and deletion; to exercise any ARCO right, email henkaipan@dyallab.com.ar or use the product's account deletion feature. We will respond within the period required by law (Art. 14, Reglamentación; Decreto 746/2024). For EU residents, corresponding rights apply under the GDPR.
If you believe data was processed unlawfully, you may file a claim with the Argentine data protection authority (AAIP).
10. Security
We apply technical and organizational measures to protect personal data, including:
bcrypt password hashing, AES-256-GCM encryption of secrets at rest
(SECRET_ENCRYPTION_KEY), HttpOnly session cookies, TLS in transit,
least-privilege non-root containers, and per-customer dedicated infrastructure.
Further detail is available in the DPA.
11. Data breach
In the event of a personal data breach likely to risk the rights of data subjects, we will notify affected Customers without undue delay and within 72 hours where the GDPR applies, and notify the relevant authorities as required by Argentine law and the AAIP.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified with reasonable notice (30 days) before they take effect.
13. Contact and data protection
Privacy inquiries: henkaipan@dyallab.com.ar. [Appoint an EU representative under GDPR Art. 27 when serving EU clients.] Provider: [legal entity, CUIT, registered address].