Privacy Policy
Version 2026-07-28 · Effective 2026-07-28
This Policy explains how HandOff collects and uses personal information during signup/auth, workspace use, AI processing, and connector integrations.
1. Controller
The controller of personal information for HandOff is ITROUNDER. - Address: 2F 203-D303, 15 Gyeryong-ro 105beon-gil, Yuseong-gu, Daejeon, Republic of Korea - Email: itrounder.korea@gmail.com - Business registration no.: 420-08-02950 Related Vietnam entity: Cong ty TNHH Big mouth / manager@bigmouth.vn
2. Information We Collect
We may collect: 1. Registration/auth: email, name, account type (personal/company), (company) company name, contact name, phone, agreed Terms/Privacy versions, locale 2. Service use: chat/request content, Task/approval/automation records, agent/skill/connector settings, artifact metadata and files, permission/audit logs, device/browser data, access logs 3. Billing/support (if applicable): contact details and inquiry content 4. Automatically: cookies, local storage, and similar identifiers (session, language, security)
3. Purposes of Use
1. Identify users, authenticate via email magic link (OTP), and provide accounts/workspaces 2. Deliver Agentic AI workflows (planning, tool execution, approvals, result storage) 3. Manage connectors/skills, access control, security monitoring, and incident response 4. Customer support, product improvement, and important notices 5. Legal compliance and dispute handling
4. Legal Bases
We process personal data based on contract performance, user consent (for optional features/marketing), legitimate interests (security and improvement, unless overridden by user rights), and legal obligations.
5. Retention
1. Account data: until deletion, unless longer retention is required by law 2. Pending signup data: until verification completes or expires (short-term) 3. Tasks, chats, artifacts: until deleted by the user or workspace/account removal; backups are removed after the recovery cycle 4. Access/security logs: for a reasonable period needed for security and disputes
6. Sharing and Processors
We do not sell personal data. We may use processors such as: 1. Cloud DB/auth/storage (e.g., Supabase) 2. Email delivery for signup/login links 3. AI model providers processing user inputs and execution context 4. Hosting, infrastructure, and monitoring providers Only necessary data is shared under protective contracts. Data sent through user-connected connectors (e.g., Microsoft 365, Google, Slack) is also subject to those providers' policies.
7. International Transfers
Depending on infrastructure and AI/cloud providers, personal data may be transferred and processed outside your country. We apply safeguards required by applicable law and provide additional notice when required.
8. AI Processing Notice
HandOff uses AI for request analysis, agent selection, tool calls, and document/code generation. Your inputs, files, and connector-sourced data may be included in AI processing. AI outputs can be incorrect; review them before important decisions. Check your organization's policy before submitting sensitive or confidential information.
9. Your Rights
You may request access, correction, deletion, restriction, withdrawal of consent, and portability where applicable. Contact itrounder.korea@gmail.com. We will respond within a reasonable time. Deleting an account may limit service availability.
10. Destruction
When retention ends or the purpose is achieved, we destroy personal data without undue delay using irrecoverable deletion for electronic files and shredding/incineration for paper. Data retained by law is segregated and destroyed after the required period.
11. Security Measures
We apply reasonable measures such as access control, HTTPS, token protection, permission separation, audit logs, and vulnerability response. No internet service can guarantee absolute security; users should also protect their accounts.
12. Cookies
We may use cookies and similar technologies for sessions, language settings, security, and usability. You can refuse cookies in browser settings, but some features (such as staying signed in) may not work.
13. Children
The Service is not directed to children under 14. We do not knowingly collect their personal data and will delete it promptly if discovered.
14. Changes
When this Policy changes, we will post or link the update in the Service and may provide advance notice for material changes. The revised Policy takes effect on the stated effective date.
15. Contact
Privacy inquiries: itrounder.korea@gmail.com The Policy version shown in the Service controls.