Data Processing Addendum (DPA)
Effective Date: August 4, 2026 (Ver. 1.0) · Applicable Services: Xint (Web · Code), aprism
This Data Processing Addendum ("DPA") is entered into by and between Theori Korea and Theori, Inc. (collectively, "Processor," "Theori," "we," "us," or "our") and the customer using our services ("Controller" or "Customer").
This DPA applies automatically when a Customer agrees to our Terms of Service. This DPA applies alongside our Privacy Policy and GDPR Policy.
1. Definitions
| Term | Definition |
|---|---|
| Customer Data | Any Personal Data that the Customer uploads, transmits, or submits to the Services |
| Processing | Any operation performed on Customer Data, including collection, recording, storage, analysis, transmission, and deletion |
| Sub-processor | A third party engaged by Theori to Process Customer Data on Theori's behalf |
| Data Protection Laws | The General Data Protection Regulation (EU) 2016/679 ("GDPR"), UK GDPR, the Personal Information Protection Act ("PIPA," 개인정보보호법), and any other applicable data protection legislation |
| Personal Data | Any information relating to an identified or identifiable natural person, as defined under the applicable Data Protection Laws |
| Data Subject | The identified or identifiable natural person to whom Personal Data relates |
| Services | The services listed in Section 2.2 |
| Security Incident | Any unauthorized access to, or disclosure, alteration, destruction, or loss of, Customer Data |
2. Scope and Roles
2.1. Roles
| Party | Role | Description |
|---|---|---|
| Customer | Controller | Determines the purposes and means of Processing Customer Data |
| Theori | Processor | Processes Customer Data on the Customer's documented instructions |
2.2. Applicable Services
This DPA applies to the following Services:
| Service | URL | Data Processed |
|---|---|---|
| Xint Web | https://app.xint.io | Scan target URLs, vulnerability scan results, web application metadata |
| Xint Code | https://code.xint.io/login | Source code, binaries, static analysis results, commit metadata |
| aprism | https://app.aprism.io | LLM request/response traffic, prompt logs, policy violation detection records |
3. Purpose and Scope of Processing
3.1. Purpose of Processing
We Process Customer Data solely for the following purposes:
| Service | Processing Purpose |
|---|---|
| Xint Web | Web application security vulnerability scanning and delivery of scan results |
| Xint Code | Static security analysis of source code and generation of vulnerability reports |
| aprism | LLM traffic monitoring, prompt injection detection, and policy violation filtering |
3.2. Processing Restrictions
We will not:
- Process Customer Data without the Customer's documented instructions, except where processing is required by law applicable to Theori (including the laws of the Republic of Korea and the United States), in which case we will, to the extent permitted by Data Protection Laws, inform the Customer of that legal requirement before processing, unless such law prohibits such information on important grounds of public interest
- Use Customer Data for our own purposes (e.g., marketing, AI model training)
- Sell, share, or lease Customer Data to any third party
- Retain Customer Data beyond the period necessary to provide the Services
If we determine that a Customer's instruction would violate Data Protection Laws, we will suspend execution of that instruction and immediately notify the Customer.
Access requests from public authorities. Where a court, law enforcement body, or other public authority requests access to Customer Data, we follow the procedure set out in Clauses 14 and 15 of the EU Standard Contractual Clauses in Part 1 of Annex 2. Specifically, we will (i) notify the Customer of the request without undue delay unless legally prohibited from doing so, (ii) challenge the request where we consider it unlawful, (iii) disclose only the minimum information required, and (iv) keep records of such requests and make them available to the Customer on request. Where notification is prohibited, we will use reasonable efforts to obtain a waiver of that prohibition and will notify the Customer as soon as we are permitted to do so.
4. Customer Obligations
The Customer warrants that:
- It has a lawful basis for collecting all data uploaded to the Services
- It has provided all required notices to (and obtained consents from, where applicable) Data Subjects
- Its Processing instructions to Theori comply with applicable Data Protection Laws
5. Confidentiality
- We impose confidentiality obligations on all employees and contractors who access Customer Data.
- All such personnel are bound by a written non-disclosure agreement (NDA) or statutory confidentiality duty.
- We provide regular data protection training to all personnel with access to Customer Data.
6. Security Measures
6.1. Technical and Organizational Measures
We maintain the following technical and organizational measures to protect Customer Data:
- Encryption in Transit: TLS 1.2 or higher for all communication channels
- Encryption at Rest: AES-256 encryption for stored data
- Access Controls: Role-based access control (RBAC) and multi-factor authentication (MFA)
- Logging: Access logs and audit trail management
- Vulnerability Management: Regular security scans and timely patch application
- Network Security: Firewalls, IDS/IPS, network segmentation
- Physical Security: Data center access controls
- Personnel Security: Security awareness training and background checks
For a complete list of security controls and real-time compliance status, visit our Trust Center.
6.2. Certifications
We maintain the following security certifications:
| Certification | Scope | Status |
|---|---|---|
| ISO/IEC 27001:2022 | Information Security Management System | Active |
| ISO/IEC 27017:2015 | Cloud Service Information Security | Active |
| SOC 2 Type II | Xint and aprism Services | Examination in progress (SOC 2 results in an attestation report, not a certification) — Request Engagement Letter |
Certification copies and the SOC 2 report are available for download via the Trust Center or upon request under NDA.
7. Sub-processors
7.1. Current Sub-processor List
We engage Sub-processors to Process Customer Data. The current Sub-processor list is available on our Trust Center.
7.2. Sub-processor Change Notification
- When we add or change a Sub-processor, we publish the change to the Sub-processor list on our Trust Center at least 10 days before the new Sub-processor begins processing Customer Data.
- Customers may subscribe to change notifications on the Trust Center; subscribers also receive the notice by email within the same period. Where a Customer has not subscribed, publication on the Trust Center constitutes notice.
- Customers may object in writing (privacy@theori.io) within 10 days of the notice, provided they state reasonable grounds. Where an objection is raised, we will not begin processing Customer Data through that Sub-processor until the objection has been resolved.
- If a Customer does not object within the objection period, the Customer is deemed to have approved the change.
- If an objection is not resolved through discussion, the Customer may terminate the affected portion of the Services without penalty, and we will refund prepaid fees for the period after termination on a pro-rata basis.
Urgent replacement. Where a Sub-processor must be replaced immediately to maintain the security or continuity of the Services (for example, a security incident at the Sub-processor, or the suspension, discontinuation, or termination of its service), the advance notice period above does not apply. In that case we will notify the Customer of the replacement and the reason for it without undue delay after the change, and the Customer's right to object and to terminate as set out above is unaffected. An urgently engaged Sub-processor is subject to the same obligations under Section 7.3.
8. Data Retention and Deletion
8.1. Retention Periods
| Data Type | Retention Period | Notes |
|---|---|---|
| Scan target data (source code, URLs) | Duration of the Services | Retained for re-analysis after scan completion |
| Scan results and reports | Duration of the Services | Accessible via the Customer dashboard |
| Access logs and audit logs | Per Customer contract terms | Stored in immutable (WORM) storage |
8.2. Post-Termination Processing
- Return or Deletion: After termination of the Services agreement, at the Customer's election, we will either return all Customer Data to the Customer in a structured, commonly used, and machine-readable format, or delete all Customer Data using irreversible methods, within the period agreed upon with the Customer. Upon completion of deletion, we will provide a Certificate of Destruction. If no specific period is agreed, we will delete Customer Data within 30 days.
- Export: Customers may download their data using the in-service export feature before termination.
- Exceptions: Data that must be retained under applicable law will be held in segregated storage for the legally required period and then destroyed.
9. Security Incident Notification
9.1. Notification Procedure
Upon becoming aware of a Security Incident, we will notify the Customer (as Controller) according to the following procedure. "Security Incident" covers not only the loss, theft, or leakage of Customer Data but also its forgery, alteration, or damage, and includes cases where we identify the possibility of such an incident before it is confirmed.
| Phase | Deadline | Content |
|---|---|---|
| ① Initial Notification | Within 48 hours of awareness | Incident summary, estimated scope of impact, immediate remediation steps |
| ①-1 Possible-Incident Notification | Within 48 hours of identifying the possibility | The basis for concluding an incident may have occurred, the potentially affected scope, and the steps the Customer can take |
| ② Detailed Report | Within a reasonable period | Affected data categories, number of Data Subjects affected, root cause analysis, additional remediation plan |
| ③ Final Report | Within 30 business days of incident closure | Root cause analysis, recurrence prevention measures, final impact assessment |
Legal Benchmarks:
- Processor → Controller notification (this DPA): GDPR Art. 33(2) requires notification "without undue delay," and PIPA §26(8) applies Section 34 (breach notification and reporting) to processors. This DPA gives that effect by setting a 48-hour deadline from becoming aware of the incident, so that the Customer can meet its own statutory deadlines (72 hours).
- Controller → Data Subject notification: PIPA Enforcement Decree Section 39 — within 72 hours
- Controller → Supervisory Authority (PIPC) report: PIPA Enforcement Decree Section 40 — within 72 hours (applies when 1,000+ individuals, sensitive data, or external intrusion is involved)
- GDPR Art. 33(1): Controller → Supervisory Authority within 72 hours
- Possible-breach notification (PIPA Article 34(2), as amended by Act No. 21445, effective September 11, 2026): applied to processors through PIPA Article 26(8). We apply phase ①-1 ahead of that date so the Customer can meet its statutory deadline.
9.2. Customer Obligations
- The Customer is responsible for notifying the competent supervisory authority and affected Data Subjects directly.
- We will cooperate with the Customer to the extent reasonably necessary to fulfill its notification obligations.
10. Data Subject Rights
- If a Data Subject contacts us directly to exercise their rights, we will promptly forward the request to the Customer.
- We will provide reasonable technical assistance to support the Customer in responding to Data Subject rights requests (access, rectification, deletion, portability, etc.) in accordance with the Customer's instructions.
- The Customer, as Controller, retains final decision-making authority over all Data Subject rights requests.
11. Data Protection Impact Assessment Support
- We will provide the Customer with reasonably necessary information when the Customer conducts a Data Protection Impact Assessment (DPIA) or a Privacy Impact Assessment.
- If the Customer engages in prior consultation with a supervisory authority (GDPR Art. 36), we will cooperate to a reasonable extent.
12. International Data Transfers and Applicable Law
12.1. Applicable Laws
This DPA operates against the obligations that the following laws impose on processors. Which laws apply depends on the location of Customer Data and the residence of Data Subjects:
| Law | Jurisdiction | Applicability |
|---|---|---|
| PIPA (개인정보보호법) | Republic of Korea | Data Subjects residing in Korea — home-base law |
| GDPR (EU 2016/679) | EU/EEA | Data Subjects residing in the EEA |
| UK GDPR | United Kingdom | Data Subjects residing in the UK (ICO jurisdiction) |
| CCPA/CPRA (Cal. Civ. Code §1798.100 et seq.) | United States (California) | Consumers residing in California |
| PDPA (Personal Data Protection Act 2012) | Singapore | Data Subjects residing in Singapore |
| APPI (個人情報保護法) | Japan | Data Subjects residing in Japan |
- We do not sell Customer Data. Under the CCPA, we act as a "Service Provider" and Process data solely for the Customer's business purposes.
- If Data Protection Laws of jurisdictions not listed above apply, we will conduct additional reviews upon Customer request.
12.2. International Data Transfer Safeguards
| Transfer Route | Safeguard |
|---|---|
| EEA → Republic of Korea | EU adequacy decision (Commission Implementing Decision (EU) 2022/254) |
| UK → Republic of Korea | UK adequacy regulations (Data Protection (Adequacy) (Republic of Korea) Regulations 2022; UK GDPR Art. 45A) |
| EEA/UK → Japan | EU adequacy decision (Commission Implementing Decision (EU) 2019/419) |
| EEA/UK → United States | Standard Contractual Clauses (SCCs, EU Commission Implementing Decision (EU) 2021/914) apply. We may additionally rely on any other transfer mechanism valid under Chapter V of the GDPR at the relevant time |
| Republic of Korea → United States | PIPA §28-8(1)3(a) — processing entrustment or storage necessary for performance of a contract, disclosed in the privacy policy |
| Japan → Republic of Korea / United States | Contractual safeguards under APPI Art. 28 (this DPA and Annex 2) |
| Singapore → Republic of Korea / United States | PDPA Section 26 Transfer Limitation Obligation — contractual safeguards |
Theori's engagement with the Global CBPR Forum is a matter of international interoperability only and is not a lawful basis for cross-border transfers under this DPA. Transfers rely on the grounds set out in the table above.
12.3. Data Locations
| Service | Primary Data Location | Region | Notes |
|---|---|---|---|
| Xint Web | AWS Seoul | ap-northeast-2 | Web scan results and Customer Data |
| Xint Code | AWS Virginia | us-east-1 | Source code analysis |
| aprism | AWS Seoul | ap-northeast-2 | LLM traffic monitoring |
The locations above are where Customer Data is stored. When Xint Web, Xint Code, or aprism runs an AI analysis, the input is sent to the providers below for processing and is deleted immediately after processing under Zero Data Retention (ZDR) terms — it is not stored there. These are therefore transient processing locations, not data residency locations.
Where AI inference takes place
| AI provider | Processing location | Retention |
|---|---|---|
| Anthropic PBC (Claude API) | United States | ZDR — deleted immediately after processing; not used for model training |
| OpenAI, Inc. (GPT API) | United States | ZDR — deleted immediately after processing; not used for model training |
| Google LLC (Gemini API) | United States | ZDR — deleted immediately after processing; not used for model training |
| Amazon Web Services, Inc. (Bedrock) | United States (us-east-1) | ZDR — deleted immediately after processing; not used for model training |
| Amazon Web Services Korea LLC (Bedrock) | Republic of Korea (ap-northeast-2) | ZDR — deleted immediately after processing; not used for model training |
Which provider is used may vary by service and feature, always within the list above. See Annex III for their status as Sub-processors and the applicable contractual terms.
13. Audit Rights
13.1. Report-Based Audits (From First Provision of the SOC 2 Type II Report)
Following our SOC 2 Type II report, we will provide the following certification documents as the primary means of audit:
| Certification | Availability |
|---|---|
| SOC 2 Type II Report | Available upon request via the Trust Center (NDA required) |
| ISO/IEC 27001:2022 Certificate | Available for download on the Trust Center |
| ISO/IEC 27017:2015 Certificate | Available for download on the Trust Center |
The Customer agrees that the above certification documents satisfy its audit obligations. However, the Customer may request an additional audit under Section 13.2 for specific matters that the certification documents do not address.
13.2. Direct Audits
- Until we first make a SOC 2 Type II report available to the Customer: The Customer may request an audit to verify compliance with this DPA once per year.
- From the date we first make a SOC 2 Type II report available to the Customer: The Customer may request one additional audit per year, limited to matters not addressed by the documents listed in Section 13.1, provided the Customer submits written justification with reasonable grounds.
- Audit requests must be submitted in writing at least 30 days in advance.
- Audits must be conducted during business hours and must not disrupt Theori's normal operations.
13.3. Compliance Information
We will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and GDPR Art. 28, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. The frequency, notice period, and manner of such audits are governed by Sections 13.1 and 13.2. These limits do not apply to audits ordered by a supervisory authority or otherwise required by Data Protection Laws.
14. Limitation of Liability and Indemnification
14.1. General Limitation
- Except as set forth in Section 14.2, Theori's aggregate liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.
- We are not liable for Data Protection Law violations caused by the Customer's instructions.
14.2. Carve-outs
The limitation of liability in Section 14.1 does not apply to:
- (a) Theori's willful misconduct or gross negligence in Processing Customer Data;
- (b) Theori's breach of confidentiality obligations under Section 5;
- (c) Theori's unauthorized Processing of Customer Data outside the scope of the Customer's documented instructions (Section 3); and
- (d) Theori's indemnification obligations under Section 14.3.
14.3. Mutual Indemnification
- (a) Theori shall indemnify, defend, and hold harmless the Customer from and against any third-party claims, regulatory fines, penalties, and reasonable costs (including legal fees) arising directly from Theori's breach of this DPA, including but not limited to unauthorized processing, failure to implement required security measures (Section 6), or failure to provide timely breach notification (Section 9).
- (b) The Customer shall indemnify, defend, and hold harmless Theori from and against any third-party claims, regulatory fines, penalties, and reasonable costs (including legal fees) arising directly from the Customer's breach of this DPA, including unlawful processing instructions.
14.4. Regulatory Fine Allocation
In the event a supervisory authority imposes a fine or penalty related to the Processing of Customer Data under this DPA, this Section 14.4 prevails over Section 14.3.
- (a) Each party shall bear responsibility for fines directly attributable to its own breach of Data Protection Laws.
- (b) Where a fine is attributable to the actions or omissions of both parties, the parties shall allocate responsibility in proportion to each party's contribution to the violation.
- (c) The parties shall cooperate in good faith to respond to any supervisory authority investigation or enforcement action.
14.5. Breach Notification Costs
If a Security Incident (Section 9) requires notification to Data Subjects or supervisory authorities:
- (a) Theori shall bear the costs of notification, credit monitoring, and remediation to the extent the incident resulted from Theori's breach of its obligations under this DPA.
- (b) The Customer shall bear such costs to the extent the incident resulted from the Customer's instructions or the Customer's breach of this DPA.
15. Term and Termination
- This DPA remains in effect for the duration of the Customer's use of the Services.
- This DPA terminates automatically upon termination of the Services agreement.
- Sections 8 (Data Retention and Deletion), 9 (Security Incident Notification), and 14 (Limitation of Liability) survive termination of this DPA.
15.1. Order of Precedence
If this DPA conflicts with other contractual documents, the following order of precedence applies:
- EU Standard Contractual Clauses (SCCs) or other statutory transfer mechanisms
- This DPA
- Terms of Service
- Privacy Policy
Where provisions within this DPA conflict, the interpretation that does not fall below the minimum standard required by Data Protection Laws prevails; to that extent, Section 13.3 (compliance information and audit cooperation) prevails over Section 13.1, and Section 14.4 (allocation of regulatory fines) prevails over Section 14.3.
15.2. Language
This DPA is executed in Korean and English. As between the Customer and Theori, the version in the language in which this DPA was presented to and accepted by the Customer prevails. Accordingly, the English version prevails for Customers contracting with Theori, Inc., and the Korean version prevails for Customers contracting with Theori Korea in Korean; in each case the prevailing version is construed consistently with the governing law in Section 16. Where the prevailing version cannot be determined, the interpretation more favorable to the Customer applies.
This Section does not apply to the EU Standard Contractual Clauses in Part 1 of Annex 2, for which each official EU language version published under Commission Implementing Decision (EU) 2021/914 is equally authentic, and does not affect Clause 5 (Conflict) thereof. The English version of the UK Addendum in Part 2 of Annex 2 is authoritative.
16. Governing Law and Dispute Resolution
The governing law and jurisdiction for this DPA are determined by the Theori entity with which the Customer has contracted:
| Contracting Entity | Governing Law | Jurisdiction |
|---|---|---|
| Theori Korea | Laws of the Republic of Korea | Seoul Central District Court |
| Theori, Inc. | Laws of the State of Delaware, USA | Federal or state courts located in Delaware |
- For EU/EEA Customers, the authority of the competent GDPR supervisory authority is not affected regardless of the contracting entity.
- Customers in other jurisdictions are subject to the governing law specified in the Terms of Service.
17. Contact Information
For inquiries related to this DPA:
| Item | Details |
|---|---|
| DPO | Kenny Kwansoon Park (박관순) |
| privacy@theori.io | |
| Phone | +82-70-8864-1337 |
| Address (KR) | 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea |
| Address (US) | Theori, Inc., PO Box 40033, Austin, TX 78704, USA |
Annex 1: Processing Details
(i) Categories of Data Subjects
| Service | Categories of Data Subjects |
|---|---|
| Xint Web | End users of the Customer's web applications (whose data may appear in metadata collected during scans) |
| Xint Code | Customer's developers (where included in commit metadata); Data Subjects whose Personal Data is hardcoded in source code |
| aprism | End users of the Customer's LLM-powered services (where Personal Data is included in prompts or responses) |
(ii) Categories of Personal Data Processed
| Service | Categories of Personal Data |
|---|---|
| Xint Web | URLs, domain information, HTTP request/response headers, cookie names, web application metadata |
| Xint Code | Personal Data embedded in source code (if hardcoded), Git commit author information (name, email), binary metadata |
| aprism | Personal Data contained in LLM prompts/responses (where entered by users), policy violation detection records |
(iii) Sensitive Data and Safeguards
| Service | Sensitive Data Processing | Safeguards |
|---|---|---|
| Xint Web | Not intentionally Processed (the Customer is responsible for sensitive data that may be present in the scanned web application) | RBAC, encryption in transit and at rest, audit logging |
| Xint Code | Not intentionally Processed (the Customer is responsible for Personal Data hardcoded in source code) | RBAC, encryption in transit and at rest, audit logging |
| aprism | Not intentionally Processed (the Customer is responsible for Personal Data included in prompts) | RBAC, encryption in transit and at rest, audit logging |
(iv) Frequency of Processing
| Service | Frequency |
|---|---|
| Xint Web | On-demand (each time the Customer initiates a scan) |
| Xint Code | On-demand (upon code upload and analysis execution) |
| aprism | Continuous real-time processing (LLM traffic monitoring) |
(v) Nature and Purpose of Processing
Nature of Processing: Automated processing operations necessary for service delivery, including collection, recording, storage, analysis, transmission, and deletion.
(vi) Retention Period
| Data Type | Retention Period |
|---|---|
| Scan target data | Duration of the Services |
| Scan results and reports | Duration of the Services |
| Post-termination | Deleted using irreversible methods within 30 days |
This Annex 1 forms an integral part of DPA v1.0 and takes effect on the same date as the main body.
Annex 2: International Data Transfer Safeguards
Annex 2 to the Data Processing Addendum (DPA) v1.0
Applicable Services: Xint (Web · Code), aprism (same as the main body)
Incorporation by Reference: The parties to this Annex incorporate by reference the full text of the Standard Contractual Clauses ("SCCs") set out in the EU Commission Implementing Decision (EU) 2021/914. The official text of the SCCs is available at EUR-Lex. Annexes I, II, and III of this Annex serve as the annexes to the SCCs.
Part 1: EU Standard Contractual Clauses (SCCs)
This Part 1 constitutes the Annexes to the Standard Contractual Clauses ("SCCs") pursuant to EU Commission Implementing Decision (EU) 2021/914.
The SCCs apply under Module 2 (Controller-to-Processor) by default. Module 3 (Processor-to-Processor) applies where the Customer, acting as a Processor on behalf of its own Controller, transfers Personal Data to Theori.
Transfer Relationships
| Item | Module 2 (C2P) | Module 3 (P2P) |
|---|---|---|
| Data Exporter | Customer (Controller) | Customer (Processor, acting on behalf of its Controller) |
| Data Importer | Theori (Processor) | Theori (Sub-processor) |
| When Applicable | Customer is the Controller of the Personal Data | Customer is a Processor transferring data on behalf of a third-party Controller |
Optional Clauses
| Clause | Applicability | Description |
|---|---|---|
| Clause 7 — Docking Clause | Applicable | Third parties may accede to the SCCs after execution |
| Clause 9(a) — Option 2 (General Written Authorisation) | Applicable | General written authorisation for Sub-processors adopted. Advance notice period: 10 days; the manner of notice is set out in DPA Section 7.2 |
| Clause 11(a) — Optional Redress Mechanism | Not applicable | No independent dispute resolution body designated |
| Clause 17 — Governing Law | Option 1 applicable | EU Member State law (see Annex I.C below) |
| Clause 18(b) — Forum for Disputes | See Annex I.C below |
Annex I — Parties and Transfer Details
Annex I.A — List of Parties
Data Exporter
| Item | Details |
|---|---|
| Name | Customer (the entity or natural person that has entered into the DPA) |
| Address | As specified in the Services agreement |
| Contact Person | As specified in the Services agreement |
| Role | Module 2: Controller / Module 3: Processor |
| Signature and Date | Date of Customer's acceptance of the DPA |
Data Importer
| Item | Details |
|---|---|
| Name | The Theori entity identified in the Services agreement (Theori Korea or Theori, Inc.); where not specified, Theori Korea |
| Address | (KR) 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea / (US) Theori, Inc., PO Box 40033, Austin, TX 78704, USA |
| Contact Person | Kenny Kwansoon Park (박관순), DPO, privacy@theori.io |
| Role | Module 2: Processor / Module 3: Sub-processor |
| Signature and Date | DPA Effective Date |
| Data Protection Activities | Processing of Customer Data — security vulnerability scanning, source code analysis, and LLM traffic monitoring services |
Annex I.B — Description of Transfer
The details of the transfer (including categories of data subjects, categories of personal data, sensitive data, frequency, nature and purpose of processing, and retention periods) are identical to the details set forth in Annex 1 (Processing Details) of this DPA and are incorporated herein by reference.
Annex I.C — Competent Supervisory Authority
| Item | Details |
|---|---|
| Module 2 | The supervisory authority of the EU/EEA Member State in which the Data Exporter (Customer) is established |
| Module 3 | The supervisory authority of the EU/EEA Member State in which the Data Exporter's (Customer's) Controller is established |
| Governing Law (Clause 17) | The law of the EU/EEA Member State in which the Data Exporter is established. If not established in the EU/EEA, Irish law applies |
| Forum for Disputes (Clause 18) | The courts of the EU/EEA Member State whose law governs |
Annex II — Technical and Organisational Measures
The technical and organisational measures implemented by the Data Importer are described in DPA Section 6 (Security Measures) and Section 6.2 (Certifications). For a complete list of security controls and real-time compliance status, visit the Trust Center.
Annex III — List of Sub-processors
1. General Written Authorisation
The Data Exporter (Customer) grants the Data Importer (Theori) General Written Authorisation to engage Sub-processors in accordance with SCCs Clause 9(a), Option 2.
2. Current Sub-processor List
The current Sub-processor list is maintained on the Trust Center and is updated in real time.
3. Sub-processor Change Procedure
Per DPA Section 7.2:
- We publish the addition or change on the Trust Center at least 10 days before processing begins; Customers who have subscribed to change notifications also receive it by email
- The Customer may submit a written objection to privacy@theori.io within 10 days of the notice. Where an objection is raised, processing through that Sub-processor is held until the objection is resolved
- If the Customer does not object within the objection period, approval is deemed granted
- If the objection is not resolved, the Customer may terminate the affected portion of the Services without penalty, with prepaid fees refunded pro rata
- The advance notice period does not apply to an urgent replacement needed to maintain security or continuity; in that case we notify without undue delay after the change
Part 2: UK Addendum to the EU SCCs
This Part 2 is drafted in accordance with the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (ICO) (Version B1.0, in force March 21, 2022). It takes effect when the Customer accepts this DPA, and only to the extent a Chapter V transfer under the UK GDPR actually occurs.
Table 1: Parties
| Item | Details |
|---|---|
| Start Date | Effective Date of this DPA |
| Exporter | Customer (the entity or natural person that has entered into the DPA) |
| Importer | The Theori entity identified in the Services agreement (Theori Korea or Theori, Inc.). Where the Services agreement does not specify, the Data Importer is Theori Korea. |
| Key Contact (Exporter) | As specified in the Services agreement |
| Key Contact (Importer) | Kenny Kwansoon Park (박관순), DPO, privacy@theori.io |
Table 2: Selected SCCs, Modules, and Clauses
| Item | Details |
|---|---|
| Addendum EU SCCs | The EU SCCs attached in Part 1 of this Annex |
| Applicable Module | Module 2 (C2P) by default / Module 3 (P2P) where applicable |
| Selected Clauses | As specified in Part 1 |
Table 3: Appendix Information
| UK Addendum Appendix | Corresponding EU SCCs Annex |
|---|---|
| Appendix 1: List of Parties | Annex I.A |
| Appendix 2: Description of Transfer | Annex I.B |
| Appendix 3: Technical and Organisational Measures | Annex II |
| Appendix 4: List of Sub-processors | Annex III |
Table 4: Ending this Addendum
If the ICO issues a revised Approved Addendum, either party may terminate this Addendum. The Importer will provide reasonable notice and propose alternative safeguards upon termination.
UK Addendum — Additional Terms
- Competent Supervisory Authority: UK Information Commissioner's Office (ICO)
- Governing Law: The laws of England and Wales
- Forum for Disputes: The courts of England and Wales
- In the event of any conflict between the EU SCCs and this UK Addendum, this UK Addendum prevails for UK-related transfers
Part 3: Swiss Addendum (Federal Act on Data Protection)
Where the Swiss Federal Act on Data Protection ("FADP") applies, the EU SCCs in Part 1 apply subject to the following modifications:
| EU SCCs Clause | Swiss Addendum Modification |
|---|---|
| References to GDPR | Interpreted as references to the Swiss FADP |
| References to "EU," "Union," "Member State" | Interpreted as references to "Switzerland" |
| Clause 13(a) / Annex I.C — Competent Supervisory Authority | The Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB) |
| Clause 17 — Governing Law | Swiss law |
| Clause 18(b) — Forum for Disputes | Swiss courts |
| Scope of Data Subjects | Includes both natural persons and legal entities (within the scope of the FADP) |
Note: The Republic of Korea is not currently listed on Switzerland's adequacy list. Accordingly, the SCCs (including this Swiss Addendum) apply to transfers from Switzerland to Korea.
Part 4: Summary of Transfer Safeguards by Route
| Transfer Route | Applicable Safeguard | Notes |
|---|---|---|
| EEA → Republic of Korea | EU adequacy decision (EU) 2022/254 | The adequacy decision suffices; no additional safeguards are required |
| EEA → United States | SCCs (Module 2) under this Annex | Theori, Inc. is not currently DPF-certified. This entry will be updated upon certification |
| UK → Republic of Korea | UK adequacy regulations (UK GDPR Art. 45A) | The adequacy regulations suffice. The UK Addendum applies only to transfers to countries without adequacy regulations |
| UK → United States | UK Addendum under this Annex | Not DPF-certified — UK Addendum applies |
| Switzerland → Republic of Korea | SCCs + Swiss Addendum under this Annex | Not on Switzerland's adequacy list |
| Switzerland → United States | SCCs + Swiss Addendum under this Annex | Not DPF-certified — SCCs apply |
Data Locations
See DPA Section 12.3 for data location details.
This Annex 2 forms an integral part of DPA v1.0 and takes effect on the same date as the main body.
Annex 3: US State Privacy Laws Addendum
Annex 3 to the Data Processing Addendum (DPA)
1. Purpose and Scope
1.1. Purpose
This Addendum ("US Addendum") supplements DPA Section 12 and sets forth additional obligations and conditions governing the Processing of Personal Information subject to US state privacy laws.
1.2. Applicable Laws
This US Addendum applies to Personal Information subject to US state privacy laws, including the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA") and other applicable state data privacy legislation. This US Addendum also applies, to the extent reasonably practicable, to any US state privacy laws enacted or effective after the date of this DPA.
For a comprehensive list of enacted US state privacy laws, refer to the IAPP US State Privacy Legislation Tracker.
1.3. Applicable Services
This US Addendum applies to the Services listed in DPA Section 2.2.
2. Definitions and Mapping
| US State Privacy Law Term | Corresponding DPA Term | Definition |
|---|---|---|
| Business | Controller / Customer | An entity that determines the purposes and means of Processing consumers' Personal Information |
| Service Provider | Processor / Theori | An entity that Processes Personal Information on behalf of a Business for business purposes |
| Consumer | Data Subject | A natural person residing in the applicable state |
| Personal Information | Personal Data | Information that identifies, relates to, or could reasonably be linked to a particular Consumer |
| Sale | — | Providing Personal Information to a third party for monetary consideration |
| Share | — | Providing Personal Information to a third party for cross-context behavioral advertising purposes |
Our Role: Under all applicable US state privacy laws, we act exclusively as a Service Provider or Processor on behalf of the Customer. We do not assume the role of an independent Controller or Business.
3. Service Provider Obligations
3.1. No Sale or Sharing
We do not Sell or Share Personal Information received from the Customer. (Cal. Civ. Code §1798.140(ad), Section 1798.140(ah))
3.2. No Data Combination
We do not combine Personal Information received from the Customer with Personal Information from other sources, except as necessary to (a) perform the business purposes specified in the DPA and Terms of Service, (b) follow the Customer's documented instructions, or (c) comply with applicable law. (Cal. Civ. Code §1798.140(ag)(1)(A)(iv))
3.3. No Processing Beyond Instructions
We Process Personal Information only in accordance with the Customer's documented instructions. (Cal. Civ. Code §1798.140(ag)(1)(A)(i))
3.4. Compliance Certification
Upon the Customer's reasonable request, we will certify that we understand and will comply with the obligations set forth in this US Addendum. (Cal. Civ. Code §1798.100(d)(1))
3.5. Inability-to-Comply Notification
If we can no longer meet our obligations under this US Addendum, we will promptly notify the Customer. (Cal. Civ. Code §1798.100(d)(3))
3.6. Consent Withdrawal and Opt-Out Support
When the Customer forwards a Consumer's opt-out request to us, we will cease Processing that Consumer's Personal Information within a reasonable period.
3.7. Global Privacy Control (GPC) Signal
We technically recognize GPC signals and treat them as equivalent to opt-out requests. (Cal. Civ. Code §1798.135(e), 11 CCR §7025)
3.8. Audit Cooperation
The scope, schedule, and cost allocation for audits are governed by DPA Section 13 (Audit Rights).
3.9. Sub-processor Management
We require all Sub-processors to enter into written agreements that include obligations equivalent to those set forth in this US Addendum.
4. Consumer Rights Support
4.1. Right to Know / Right to Access
Upon the Customer's request, we will provide the Customer with the categories of Personal Information held, the Processing purposes, and the specific data items pertaining to a given Consumer within 15 business days.
4.2. Right to Delete
After receiving the Customer's deletion instruction, we will delete the relevant Personal Information using irreversible methods within 30 days and instruct all Sub-processors to do the same.
4.3. Right to Correct
After receiving the Customer's correction instruction, we will correct the relevant Personal Information within a reasonable period, to the extent technically feasible.
4.4. Response Deadlines
We will support the Customer in meeting the applicable response deadline under each state law (typically 45 days, with one 45-day extension upon notice to the Consumer).
5. Sensitive Personal Information
We do not intentionally collect or Process Sensitive Personal Information as defined in Cal. Civ. Code §1798.140(ae). The Customer is responsible for ensuring that data uploaded to the Services does not contain Sensitive Personal Information.
6. De-identified and Aggregate Data
If we generate de-identified data, we will not attempt to re-identify it and will maintain safeguards to preserve its de-identified status, in accordance with CCPA §1798.140(m).
7. Non-discrimination
We will not discriminate against any Consumer for exercising rights under applicable US state privacy laws. (CCPA §1798.125)
8. Conflict of Laws — Order of Precedence
If this US Addendum conflicts with the DPA, this US Addendum prevails with respect to the Processing of Personal Information subject to US state privacy laws. Where multiple US state privacy laws apply simultaneously, we will follow the law that provides the highest level of Consumer protection.
This Annex 3 forms an integral part of DPA v1.0 and takes effect on the same date as the main body.
Change Log
| Version | Effective Date | Changes |
|---|---|---|
| v1.0 | August 4, 2026 | Initial publication (applying to the main text and Annex 1, 2, 3) |
Supplementary Provisions
This DPA v1.0 and its Annexes take effect on the date shown at the top of this document.
All previous privacy policies and addendums can be found on our consolidated Previous Versions page: