This is a short policy for a small product, and we have tried to write it so you can actually read it. If anything here is unclear, or you want the specifics behind a claim, ask us and we will answer in plain language.
Who we are
Zombie License Hunter ("we", "us") is operated by AK Labs, LLC. For any privacy question, contact [email protected].
Two different roles
We handle personal data in two distinct capacities, and the distinction matters because it determines who you should contact:
- As the controller, for this website. We decide what this marketing site collects, which is deliberately almost nothing.
- As a processor, for the service. When a customer connects their identity provider and applications to Zombie License Hunter, that customer decides what is collected and why. We process it on their instructions. If you are an employee of one of our customers and want to exercise a privacy right, the customer is the party to contact — we will assist them, but they direct us.
What this website collects
This site is static. It sets no cookies, and runs no analytics, no advertising code and no tracking pixels. It loads its web fonts from Google's font CDN; as with any font loaded that way, this discloses the IP address and browser user agent of everyone who visits to Google. That is the only third-party request this site makes.
Our hosting and CDN providers keep standard server logs (IP address, user agent, timestamp, requested path) as part of serving any website. We use these only for security, abuse prevention and capacity planning.
What the service processes
Zombie License Hunter exists to find SaaS accounts that are still being paid for but are no longer used. To do that, it processes:
- Account data — the name, email address and organisation of people who sign up to use the service.
- Authentication data — credentials and session information for signing in, handled by our own authentication service. We do not use an external identity provider for our own logins.
- Integration credentials — the API tokens or keys you supply so we can read from your identity provider and SaaS applications. These are encrypted at rest with AES-GCM and are decrypted only to make the API calls you have asked us to make.
- Directory and usage data from the systems you connect — typically user names, email addresses, account status, last-login timestamps, and licence or subscription assignments. This is the data the product is built to analyse: it is how we identify an account that has been suspended upstream yet still holds a paid seat.
You are responsible for having the authority to connect the systems you connect, and for ensuring your own notices cover the processing you ask us to perform on your behalf.
Why we process it
To provide the service you have asked for: connecting to the systems you nominate, scanning for unused and orphaned accounts, and reporting what we find. Where data protection law requires a legal basis, we rely on performance of our contract with the customer, our legitimate interests in operating and securing the service, and your consent where we ask for it.
Cookies
This website sets none. The application sets a single session cookie so that you stay signed in; it is strictly necessary, it is marked HttpOnly and SameSite=Lax, and it is sent over HTTPS only. We do not use cookies to advertise or to track you across other sites.
Where your data is stored
Application data and our encrypted object storage are hosted on Hetzner Online GmbH infrastructure in Falkenstein, Germany. Backups are written to Backblaze B2. Traffic to and from the service is proxied through Cloudflare, which means Cloudflare necessarily handles data in transit in order to route it.
Who else touches it
We do not sell personal data and we do not share it for advertising. Our subprocessors are:
- Hetzner Online GmbH (Germany) — application hosting and encrypted object storage.
- Cloudflare, Inc. (United States) — DNS, content delivery, and the tunnel that fronts the application.
- Backblaze, Inc. (United States) — encrypted backup storage.
We will list any addition here before it starts handling customer data, and we keep this list short on purpose.
How long we keep it
Customer data is kept for as long as the subscription is active. When a subscription ends, we delete or return it according to the agreement with that customer. Encrypted backups expire on their own rotation cycle rather than instantly, so a deletion may persist in a backup until that cycle completes. Our audit archive — the tamper-evident record of who did what inside the service, which is a security feature rather than a marketing one — is retained on a fixed schedule and then purged by an automated retention job.
How we protect it
Integration credentials are encrypted at rest with AES-GCM. Each customer's data is isolated from every other customer's. Sign-in is handled by authentication infrastructure we run ourselves. Backups are encrypted, and the audit archive is sealed and hash-chained so that tampering is detectable after the fact. Access to production is restricted to the people who operate the service.
No system is perfect, and we would rather say that plainly than promise otherwise. If we ever suffer a breach affecting your personal data, we will notify affected customers without undue delay and tell them what we know.
Your rights
Depending on where you live, you may have the right to be told what personal data we hold about you, to have it corrected, to have it deleted, to receive a copy in a portable form, and to object to or restrict certain processing. Contact us at [email protected] and we will respond within the period the law allows. If you are in the European Economic Area and you believe we have handled your data badly, you also have the right to complain to your national supervisory authority.
If your enquiry concerns data a customer of ours connected, we will refer you to that customer and support them in answering you, because they are the controller for it.
Enterprise customers
We do not currently publish a standalone data processing addendum. If you need one to satisfy your own review, contact us and we will work through it with you rather than pretend a generic document settles it.
Children
This service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes
If we change this policy we will update the date at the top, and if the change is substantial we will tell customers directly rather than relying on them re-reading this page.