Privacy Policy
This Privacy Policy explains how EaaS ("Expansion-as-a-Service", "we", "us") processes personal data when you or your organisation uses our multi-tenant AI workforce platform. It is written for transparency under the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and applies to all users of the EaaS platform.
1. Who we are
EaaS is operated by Kenny (Kwang-Yong) Jung, currently as a sole proprietor in the Republic of Korea, transitioning to a German GmbH with seat in Munich during 2026. Until incorporation completes, the Korean sole proprietorship is the legal operator and your point of contact.
- Contact (controller of platform-level data): gyjong@gmail.com
- Postal address: Postal address pending German GmbH formation — Munich seat
- Data Protection Officer: Not appointed. EaaS qualifies for the small-team derogation under Art. 37 GDPR (no large-scale processing of special categories; no large-scale systematic monitoring as core activity). Contact the controller directly for all data-protection matters.
2. Controller / processor split
EaaS is processor under Art. 28 GDPR for the contacts, signals, meeting notes and Gmail metadata that your tenant organisation imports. Your organisation is the controller of that content and is required to sign a Data Processing Agreement (DPA) with us before production use. The DPA is being finalised; until executed, tenants operate under this Privacy Policy and the Terms of Service as the interim baseline.
EaaS is controller for platform-level data: your Clerk user identity, audit logs of your actions on the platform, billing data (Phase B), and the legal-consent records we retain to demonstrate compliance.
3. What we collect and the legal basis
| Category | Examples | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Identity / account | Email, name, Clerk user id, IP + user-agent captured at consent | Art. 6(1)(b) — contract performance |
| Tenant content (you upload) | Contact name, email, phone, employer, LinkedIn URL, meeting notes, Gmail thread metadata (subjects, senders, timestamps) | Art. 6(1)(b) on behalf of your tenant controller, per Art. 28 processor instructions |
| Behavioural / audit | Action type, target object id, timestamp, IP address | Art. 6(1)(f) — legitimate interest in platform security and auditability; Art. 6(1)(c) where required by HGB §257 record retention |
| OAuth tokens | Google Gmail OAuth access + refresh tokens (read scope only) | Art. 6(1)(b) — necessary to deliver the integration you requested |
| Network enrichment | Public-record professional data sourced from Proxycurl | Art. 6(1)(f) — legitimate interest in completing tenant-provided records with publicly available professional information; balancing test documented |
| Marketing communications | Email address for product updates | Art. 6(1)(a) — explicit consent; withdrawable at any time |
We do not ingest Gmail message bodies in Stage 1. Bodies will only be ingested in Phase B, and only after the controller and the affected data subject (the mailbox owner) give explicit opt-in.
We do not process special categories of personal data (Art. 9 GDPR) and the service is not designed to. Do not upload health, biometric, religious or political data.
4. Purposes of processing
- Operating the platform you contracted for (drafting briefings, surfacing relationship signals, preparing outreach material for human review).
- Routing AI inference requests to the model provider you or your tenant chose (Anthropic Claude by default; tenant-selectable Ollama / vLLM self-hosted alternative).
- Security, integrity and abuse prevention (audit logging, anomaly detection).
- Billing and contract management (Phase B).
- Product improvement using aggregated, de-identified usage signals. Your tenant content is never used to train AI models — see §9.
- Legal compliance (HGB record retention; responding to lawful authority requests; GDPR rights fulfilment).
5. Sub-processors
We rely on a small, deliberately curated set of sub-processors. The current list, their roles, processing regions and links to their respective DPAs is published at /legal/subprocessors and is kept current as part of this Privacy Policy.
We notify controllers at least 30 days in advance of adding or replacing a sub-processor, allowing time to object under Art. 28(2) GDPR.
6. International data transfers
Most processing happens inside the EEA:
- Database (Neon Postgres):
eu-central-1(Frankfurt, Germany) - Application functions (Vercel):
fra1(Frankfurt, Germany) - Object storage (Vercel Blob): inherits Vercel project region (EU)
Some sub-processors are established outside the EEA:
- Republic of Korea — the controller (Kenny Jung) is currently Korean-resident. Korea holds an adequacy decision from the European Commission (Commission Implementing Decision (EU) 2022/254 of 17 December 2021), so transfers do not require additional safeguards.
- United States — Anthropic, Vercel (corporate entity), Neon (corporate entity), Clerk, Resend, Inngest, Google (Gmail OAuth). Transfers rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as set out in each provider's DPA. Where applicable, the EU-US Data Privacy Framework provides an additional safeguard for certified recipients.
- Singapore — Nubela Pte Ltd (Proxycurl). Transfers rely on Standard Contractual Clauses per Nubela's DPA.
Transfer-impact assessments are documented internally and available to controllers on request.
7. Storage and retention
| Data | Retention |
|---|---|
| Tenant content (contacts, notes, metadata) | Lifetime of subscription + 30-day grace period after termination. Right-to-erasure requests honoured within 30 days. |
| Audit log | 3 years (aligned with HGB §257 commercial-record minimum). Pseudonymised within 30 days after the subject's deletion request. |
legal_consents records (proof of Art. 7(1) consent) | Retained for the lifetime of the platform as evidence of lawful basis. Pseudonymised after account deletion. |
| Encrypted backups | Rotated on a 30-day cycle. |
| OAuth tokens | Revoked and deleted on disconnect or account termination. |
8. Your rights as a data subject
You have the following rights under the GDPR:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure / right to be forgotten (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21)
- Not to be subject to a decision based solely on automated processing (Art. 22)
- Withdrawal of consent at any time (Art. 7(3)), without affecting the lawfulness of prior processing
Self-service rights endpoints are being built this sprint. Until they are live, contact gyjong@gmail.com with your request. We will acknowledge within 5 working days and complete within 30 days, in line with Art. 12(3) GDPR.
You also have the right to lodge a complaint with a supervisory authority:
- Pending GmbH formation: the relevant German DPA will be the Bavarian State Office for Data Protection Supervision (BayLDA) for private-sector controllers in Bavaria, or the Federal Commissioner for Data Protection (BfDI) for any federal-level matters.
- Current operator (sole proprietorship in Korea): the Personal Information Protection Commission (PIPC) of the Republic of Korea.
9. Automated decision-making and AI disclosure
The platform uses AI (Claude by Anthropic by default; tenant-selectable Ollama / vLLM self-hosted alternatives) to generate drafts, summaries and briefing material. We disclose this in accordance with Art. 50 EU AI Act (Regulation 2024/1689):
- Every artefact the platform produces is AI-generated under human supervision.
- No outbound communication is sent automatically. A human user must review and execute every outbound touch. This is enforced by the platform's MANIFEST §Sacred boundary as a product feature.
- We do not make decisions solely by automated means that produce legal or similarly significant effects on you (Art. 22 GDPR).
- Tenants may opt to route inference to self-hosted Ollama / vLLM to keep prompts and completions inside their own infrastructure.
- The default Anthropic configuration sets
no training on customer data. We verify this contractual setting periodically.
10. Cookies and similar technologies
We use only strictly necessary cookies (Clerk session, theme preference). No analytics, no advertising, no cross-site tracking pixels. Because we set only strictly necessary cookies, no consent banner is required under §25(2) TTDSG. If we add non-essential cookies later, we will request consent through a banner before they fire.
11. Children
The service is B2B and not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe we hold data from a minor, contact gyjong@gmail.com and we will delete it.
12. Security
- Encryption in transit: TLS 1.2 or higher for all client-server and server-server traffic.
- Encryption at rest: Database storage encrypted by Neon; Gmail OAuth tokens encrypted at application layer with AES-256-GCM before persistence.
- Tenant isolation: Postgres Row-Level Security (RLS) enforced and
FORCE-applied, verified by automated test suite. - Audit log: append-only, tamper-evident.
- Access control: least-privilege admin access; multi-factor authentication required for operator accounts.
- Incident response: controllers will be notified without undue delay and within 72 hours of becoming aware of a personal data breach affecting their data (Art. 33 GDPR).
13. Changes to this Policy
We will publish updates here and, for material changes, notify registered users by email at least 14 days before the change takes effect. The effectiveDate and version in the frontmatter of this document indicate the active version.
14. Contact
For any privacy question, complaint, or data-subject request:
gyjong@gmail.com EaaS — Kenny (Kwang-Yong) Jung Postal address pending German GmbH formation — Munich seat
This document is preparation material drafted for review by qualified German legal counsel. It is not legal advice. Kenny must engage a Munich-based Rechtsanwalt with IP/IT and GDPR expertise before relying on this Privacy Policy in dealings with paying clients.
Privacy Policy · version 1.0.0 · effective 27 May 2026. This document is published by EaaS and reviewed periodically. For questions, contact gyjong@gmail.com.