Theori GDPR Policy
Effective Date: August 4, 2026 (Ver. 1.0)
This policy supplements Theori's Privacy Policy and provides additional rights and information for data subjects residing in the European Union (EU) and European Economic Area (EEA) under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
Where this policy conflicts with the Privacy Policy, this policy takes precedence for EU/EEA data subjects.
1. GDPR Overview
1.1 What Is the GDPR?
The General Data Protection Regulation (Regulation (EU) 2016/679, fully applicable since May 25, 2018) is the EU's comprehensive data protection law governing the processing of personal data of individuals within the European Union and European Economic Area.
1.2 Why the GDPR Applies to Theori
Theori, Inc. ("Theori," "we," "us," or "our") and its Korean affiliate Theori Korea do not have an establishment in the EU/EEA. However, under GDPR Art. 3(2), the GDPR applies when either of the following conditions is met. We satisfy both.
(a) Offering Goods or Services to EU Residents (Art. 3(2)(a))
We offer the following services directly to EU/EEA residents:
| Service | URL | Indicators of Intent to Offer Services to EU Residents |
|---|---|---|
| Xint Web | https://app.xint.io | English interface, global B2B customers, security scanning for EU enterprises |
| Xint Code | https://code.xint.io/login | English interface, AI code analysis for global developers |
| aprism | https://app.aprism.io | English interface, GenAI security solution for global enterprises |
| ChainLight | https://chainlight.io | English interface, security audits for global Web3 projects |
| Theori (Corporate) | https://theori.io | English corporate website, accepting job applications from EU residents |
Per Recital 23, mere accessibility of a website does not trigger GDPR applicability. However, actively marketing to EU enterprises, providing English-language B2B services, and accepting job applications from EU residents are objective indicators of an "intention to offer" services to EU residents.
Note on Dreamhack (https://dreamhack.io): Dreamhack is a global cybersecurity education and CTF competition platform that is not specifically targeted at EU/EEA residents. While the platform is accessible worldwide with an English interface, it does not intentionally target EU residents as its primary audience. Nonetheless, EU/EEA residents who use Dreamhack are afforded the protections described in this policy.
(b) Monitoring the Behavior of EU Residents (Art. 3(2)(b))
We monitor the online behavior of EU/EEA residents through the following tools:
| Monitoring Tool | Data Collected | Applicable Services | Monitoring Type |
|---|---|---|---|
| Google Analytics 4 (GA4) | Page views, clicks, sessions, IP addresses, device info | Dreamhack, Xint, aprism, Theori (Corporate) | Web analytics / profiling |
| PostHog | Page views, clicks, sessions, feature usage patterns | Dreamhack, Xint Web | Product analytics / behavioral tracking |
| Sentry | IP addresses, device info, error logs | Dreamhack, Xint Web, aprism | Error tracking |
| Google reCAPTCHA | User behavioral data | Dreamhack, Theori (Corporate) | Bot prevention (behavioral analysis) |
| Google Ads and AdSense | Cookies, behavioral data | Xint Landing, Theori website and blog, Dreamhack | Targeted advertising / conversion tracking / ad delivery |
| LinkedIn Insight Tag | Cookies, behavioral data | Xint Landing | Ad / lead tracking |
| HubSpot | Page views, clicks, cookies | Xint Landing | CRM analytics |
| Microsoft Clarity | Page views, on-screen interactions such as clicks and scrolling | Dreamhack | Usage pattern analysis / session replay |
| RudderStack | Page views, clicks, events | Theori careers site | Event collection / data integration |
| Datadog (RUM) | IP addresses, page views and session data | Dreamhack, aprism, Theori careers site | Real-user monitoring |
| Inblog | Page views, referral sources, sessions | Theori blog | Blog usage statistics |
| YouTube (embedded video) | Viewing history, cookies | Theori blog | Viewing-based recommendations / advertising |
Per Recital 24, tracking individuals on the internet to create profiles or analyze behavioral patterns constitutes "monitoring."
1.3 Scope of the GDPR
Material Scope (Art. 2)
The GDPR applies to the processing of personal data wholly or partly by automated means and to the processing by non-automated means of personal data that forms part of, or is intended to form part of, a filing system.
The following activities fall within the material scope:
- Automated processing of registration, payment, and service usage data through online services
- Automated collection of behavioral data through web analytics tools (GA4, PostHog)
- Structured management of customer information through CRM systems (HubSpot, Salesforce)
Territorial Scope (Art. 3)
| Basis | GDPR Article | Applicability to Theori |
|---|---|---|
| Processing in the context of an EU establishment | Art. 3(1) | Not applicable (no EU establishment) |
| Offering goods or services to EU residents | Art. 3(2)(a) | Applicable (Xint Web, Xint Code, aprism, ChainLight, Theori Corporate) |
| Monitoring behavior of EU residents | Art. 3(2)(b) | Applicable (GA4, PostHog) |
Theori is therefore subject to the extraterritorial application of the EU GDPR and UK GDPR under Art. 3(2)(a) and Art. 3(2)(b) and must appoint both an EU representative and a UK representative under EU GDPR Art. 27 and UK GDPR Art. 27.
UK GDPR: The UK Data Protection Act 2018 (incorporating the UK GDPR) applies to Theori's processing of personal data of UK residents on the same basis as described above. References to "GDPR" in this policy include the UK GDPR where applicable, and references to "EU/EEA" include the United Kingdom.
2. Controller and Processor Information
2.1 Controller (Art. 4(7))
The controller determines the purposes and means of processing personal data. The processing covered by this policy—directed at EU/EEA and UK residents through Theori's overseas business (Xint, aprism, ChainLight, the Theori corporate website) and overseas recruitment—is operated by the U.S. entity Theori, Inc. Accordingly, the controller under the EU GDPR and UK GDPR is Theori, Inc.
Controller: Theori, Inc.
| Field | Details |
|---|---|
| Entity Name | Theori, Inc. |
| Country of Registration | United States (Delaware) |
| Address | PO Box 40033, Austin, TX 78704, USA |
| Contact | privacy@theori.io / +82-70-8864-1337 |
| Role | Determines the purposes and means of processing for EU/UK-facing services and overseas recruitment |
2.2 Group Controller Structure (Theori Korea / Theori, Inc.)
The Theori group operates on a market-based structure of independent controllers. Each entity acts as an independent controller determining the purposes and means of processing for the market it operates, and there is no processing that the two entities jointly determine with respect to EU/UK data subjects.
| Entity | Market | Applicable Law | Governing Policy |
|---|---|---|---|
| Theori, Inc. (United States, Delaware) | Overseas (incl. U.S.) business and recruitment; EU/EEA and UK data subjects | EU GDPR · UK GDPR · U.S. state laws | This GDPR Policy |
| Theori Korea (Republic of Korea) | Domestic Korean services and Korean recruitment | Korea's Personal Information Protection Act (PIPA) | Global Privacy Policy |
| Theori Korea (Republic of Korea) | Data subjects in the EEA and the UK who use Dreamhack | EU GDPR · UK GDPR | This GDPR Policy |
- Domestic Korean services and Korean recruitment are handled independently by Theori Korea through separate systems in Korea and fall outside the scope of this policy (EU/UK GDPR).
- For data subjects in the EEA and the UK who use Dreamhack, Theori Korea is the controller, and this GDPR Policy applies to them in the same way. The appointment of our EU/UK representative (Euverify) under Section 4 was entered into by Theori, Inc. but covers both group entities, including Theori Korea; the Art. 27 appointment therefore applies to Theori Korea as well.
- Centralized security and data-protection functions: Theori's security and data-protection functions (including the DPO) are centralized in Korea. Accordingly, EU/UK personal data of the controller (Theori, Inc.) may be processed within the group by Theori's Korea-based Information Security Team, which acts on the controller's instructions. An intra-group data processing and transfer agreement applies between the two entities, reflecting the requirements of GDPR Art. 28 (purpose and duration of processing, confidentiality, security measures, control of sub-processors, cooperation with audits, and return or deletion of data on termination).
- Where transfers of personal data between the entities are necessary, they are carried out under the lawful transfer mechanisms set out in Section 9 (International Transfers). Transfers to Korea rely on the EU adequacy decision. Theori, Inc. is directly subject to the GDPR under Art. 3(2) and is therefore outside the scope of the current Standard Contractual Clauses; our intra-group data processing and transfer agreement and the safeguards in this policy apply instead (see Section 9.2).
- Single point of contact for data subjects: EU/UK data subjects may use privacy@theori.io as a single intake channel and may also contact the EU/UK representatives (Section 4).
2.3 Processor (Art. 4(8))
A processor processes personal data on behalf of the controller. For our B2B SaaS services, the roles between Theori and our customers are defined as follows:
B2B SaaS Role Allocation
| Service | Theori's Role | Customer's Role | Data Processed |
|---|---|---|---|
| Xint Web (app.xint.io) | Processor | Controller | Security vulnerability data from web applications designated by the customer for scanning |
| Xint Code (code.xint.io/login) | Processor | Controller | Source code submitted by the customer for analysis, Git commit metadata (developer names, emails), scan results |
| aprism (app.aprism.io) | Processor | Controller | LLM prompts and responses uploaded by the customer, policy-violation detection records, analysis results |
Note: For personal data related to service operations—such as account information, billing, and customer support—Theori acts as the controller. The processor role applies only to data provided by the customer for analysis.
DPA (Data Processing Addendum) Requirements
Under GDPR Art. 28(3), processing by a processor must be governed by a written contract (DPA). We enter into DPAs with our B2B SaaS customers that include the following terms:
| DPA Required Terms (Art. 28(3)) | Details |
|---|---|
| Subject matter and duration of processing | Security analysis of customer-provided data for the duration of the contract |
| Nature and purpose of processing | Security vulnerability scanning, AI-based code analysis, LLM traffic analysis and guardrails |
| Types of personal data | Git commit metadata (developer names, emails), technical logs |
| Categories of data subjects | Developers and contributors within the customer's organization |
| Controller's obligations and rights | Processing instructions, audit rights, cooperation on data subject requests |
| Sub-processors | See DPA Annex — prior notice required for changes |
| Data handling upon termination | Return or deletion at customer's request |
| Security measures (Art. 32) | Encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, availability measures, periodic reviews |
If you are a customer with an EU/EEA establishment, you may need to enter into a DPA with us to fulfill your own GDPR obligations. We provide a standard DPA template. Contact privacy@theori.io to request a copy.
3. Data Protection Officer (DPO)
3.1 DPO Appointment (Art. 37–39)
Under GDPR Art. 37, DPO appointment is mandatory for: (1) public authorities, (2) organizations engaged in large-scale regular and systematic monitoring, and (3) organizations processing special categories of data at scale. While Theori may not currently meet the mandatory appointment criteria, we have voluntarily appointed a DPO to strengthen our data protection governance and build trust with data subjects. The DPO concurrently heads our information security function. We have therefore documented a case-by-case conflict-of-interest assessment under GDPR Art. 38(6), applying the standard in CJEU Case C-453/21: decisions that determine the purposes and means of security-related processing are taken by the Information Security Team's operational leads rather than by the DPO, who acts in an advisory and monitoring capacity. The DPO reports directly to top management and cannot be dismissed or penalized for performing DPO tasks (Art. 38(3)).
| Field | Details |
|---|---|
| Name | Kenny Kwansoon Park (박관순) |
| Title | Chief Information Security Officer (CISO / CPO / DPO) |
| privacy@theori.io | |
| Phone | +82-70-8864-1337 |
| Organization | Theori Information Security Team |
3.2 DPO Responsibilities (Art. 39)
The DPO performs the following duties under GDPR Art. 39:
- Informing and advising — Providing information and advice to the controller, processor, and their employees on GDPR obligations.
- Monitoring compliance — Monitoring GDPR compliance through internal policies, staff training, and audits.
- DPIA advisory — Advising on Data Protection Impact Assessments (Art. 35).
- Supervisory authority liaison — Serving as the contact point for the supervisory authority.
- Data subject contact point — Serving as the point of contact for data subjects wishing to exercise their GDPR rights (Art. 38(4)).
Data subjects may contact the DPO at any time regarding any matter related to the processing of their personal data or the exercise of their rights under the GDPR.
4. EU and UK Representatives (Art. 27)
4.1 Obligation to Appoint a Representative
Under EU GDPR Art. 27(1) and UK GDPR Art. 27, a controller or processor that falls within Art. 3(2)—that is, one without an establishment in the EU/UK but processing personal data of EU/UK residents—must designate a representative in writing in the EU and in the UK respectively.
Because Theori, Inc., as controller, is subject to the EU GDPR and UK GDPR under Art. 3(2)(a) and (b), we are required to appoint both an EU representative and a UK representative under Art. 27.
4.2 Current Status
EU & UK Representative Designation Status
Theori, Inc. has appointed Euverify as its EU and UK representatives under EU GDPR Art. 27 and UK GDPR Art. 27 (appointment effective July 29, 2026). EU/EEA data subjects and supervisory authorities may contact the EU representative; UK data subjects and the ICO may contact the UK representative. We also operate privacy@theori.io as a single intake channel.
If you are located in the EU or the UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative below.
EU Representative (Art. 27, EU GDPR)
| Field | Details |
|---|---|
| Name | Euverify Ltd (Ireland), company no. 781168 |
| EU Member State | Ireland |
| Address | Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland |
| Contact | gdpr@euverify.com |
UK Representative (Art. 27, UK GDPR)
| Field | Details |
|---|---|
| Name | Euverify Ltd (UK), company no. 16146525 |
| Location | United Kingdom (London) |
| Address | 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom |
| Contact | gdpr@euverify.com |
Submitting a DSAR or other GDPR request
You can submit a Data Subject Access Request (DSAR), an erasure request, or any other GDPR request directly through our representative's secure portal. The same page confirms our appointed representative. Requests submitted there are logged and tracked, and we respond within the time limits set out in Section 7.2.
4.3 Role of the Representatives
Under Art. 27(4), each representative acts in addition to, or instead of, the controller or processor with respect to:
- Serving as the contact point for the supervisory authority (EU supervisory authorities and the UK ICO)
- Receiving inquiries and rights requests from data subjects
- Maintaining records of processing activities under Art. 30
4.4 Exemption Review
We have assessed the exemption grounds under Art. 27(2):
| Exemption Ground | Applicable? | Basis |
|---|---|---|
| Public authority or body | No | Theori is a private company |
| Occasional processing with no large-scale special category data and low risk to rights and freedoms | No | Our processing is not occasional (we operate always-on services) |
Conclusion: No exemption applies. Theori has appointed EU and UK representatives (Euverify) in accordance with its Art. 27 obligation.
5. Legal Bases for Processing (Art. 6(1))
5.1 Overview of Lawful Bases
GDPR Art. 6(1) establishes six legal bases for the lawful processing of personal data. Every processing activity must rely on at least one of these bases.
| Basis | Article | Description |
|---|---|---|
| (a) Consent | Art. 6(1)(a) | The data subject has consented to processing for one or more specific purposes |
| (b) Contract | Art. 6(1)(b) | Processing is necessary to perform a contract with the data subject or to take pre-contractual steps at the data subject's request |
| (c) Legal obligation | Art. 6(1)(c) | Processing is necessary to comply with a legal obligation under EU or Member State law |
| (d) Vital interests | Art. 6(1)(d) | Processing is necessary to protect the vital interests of the data subject or another natural person |
| (e) Public task | Art. 6(1)(e) | Processing is necessary for a task carried out in the public interest or in the exercise of official authority |
| (f) Legitimate interests | Art. 6(1)(f) | Processing is necessary for the legitimate interests of the controller or a third party, unless overridden by the data subject's fundamental rights and freedoms (particularly where the data subject is a child) |
Note: Bases (d) vital interests and (e) public task do not apply to Theori's services. The sections below describe the four legal bases we rely on.
5.2 (a) Consent — Art. 6(1)(a)
Definition and Requirements
Consent is defined in Art. 4(11). For consent to be valid under the GDPR, it must satisfy all four of the following requirements:
| Requirement | Description | How Theori Complies |
|---|---|---|
| Freely given | No detriment for refusal; consent for unnecessary processing cannot be bundled with service access | Marketing consent is separate from registration; refusing does not affect service access |
| Specific | Separate consent must be obtained for each distinct processing purpose | Individual consent for newsletters, targeted advertising, event notifications, etc. |
| Informed | The data subject must be informed of the controller's identity, processing purposes, data categories, and right to withdraw before consenting | All required information is included in consent forms |
| Unambiguous indication | Pre-ticked boxes and implicit consent are not permitted; the data subject must take a clear affirmative action (check, click) | Opt-in checkbox (unchecked by default) |
Consent-Based Processing by Service
| Processing Activity | Service | Data Collected | How to Withdraw Consent |
|---|---|---|---|
| Marketing newsletters | Theori (Corporate), Xint | Email, name | Unsubscribe link in emails or privacy@theori.io |
| CTF event and promotional communications | Dreamhack | Email, phone number | Marketing preference settings in-service or privacy@theori.io |
| Targeted advertising / conversion tracking (Google Ads and AdSense, LinkedIn) | Xint Landing, Theori website and blog, Dreamhack | Cookies, behavioral data | Cookie consent banner or browser settings |
Withdrawal of consent: You may withdraw your consent at any time (Art. 7(3)). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
5.3 (b) Contract — Art. 6(1)(b)
Definition
This basis applies when processing is necessary to perform a contract with the data subject or to take pre-contractual steps at the data subject's request.
Contract-Based Processing by Service
| Processing Activity | Service | Contract Type | Data Collected | Why Processing Is Necessary |
|---|---|---|---|---|
| Account creation | Dreamhack, Xint Web, Xint Code, aprism | Terms of Service | Email, username, profile information | User identification and authentication for service delivery |
| Paid service billing | Dreamhack | E-commerce agreement | Payment info, nationality, date of birth | Delivering paid content and billing |
| B2B SaaS service delivery | Xint Web, Xint Code, aprism | SaaS subscription agreement | Account info, service usage data | Security scanning, code analysis, and LLM guardrail services per the contract |
| Security audit services | ChainLight | Security audit service agreement | Contact person info, project details | Performing security audits and delivering reports |
| CTF prize fulfillment | Dreamhack | Event participation terms | Name, address, phone number, email | Shipping prizes |
| Recruitment process | Theori (Corporate) | Pre-contractual steps | Name, email, phone, resume | Evaluating applicants and conducting the hiring process |
| Responding to inquiries | Theori (Corporate), ChainLight, Xint, aprism | Pre-contractual steps | Name, email, company name, inquiry details | Providing service information and quotes |
5.4 (c) Legal Obligation — Art. 6(1)(c)
Definition
This basis applies when processing is necessary to comply with a legal obligation under EU or Member State law. Theori's Korean affiliate, Theori Korea, is subject to retention obligations under Korean law, which apply primarily to its domestic Korean services as set out below. (For the treatment of third-country legal obligations under the GDPR, see the note below.)
Legal basis for third-country statutory obligations: "Legal obligation" under GDPR Art. 6(1)(c) covers only obligations arising under EU or Member State law. Retention obligations under Korean law therefore do not themselves constitute an Art. 6(1)(c) basis; where such processing falls within the scope of the GDPR, we rely on Art. 6(1)(f) legitimate interests (compliance with applicable law in order to handle disputes and preserve legal claims), and we assess the balance against data subjects' rights in Section 5.6 (Legitimate Interest Assessment). The tables below list the statutory obligations applicable in each jurisdiction.
Republic of Korea (Theori Korea) — Korean domestic services; Art. 6(1)(f) where the GDPR applies
For detailed Korean-law retention periods, see Privacy Policy Section 8.
| Legal Obligation | Legal Basis | Data Retained | Retention Period |
|---|---|---|---|
| E-commerce contract and withdrawal records | Act on Consumer Protection in Electronic Commerce ("E-Commerce Act," 전자상거래법) | Contract and withdrawal records | 5 years |
| Payment and supply records | E-Commerce Act | Payment and supply records | 5 years |
| Consumer complaint and dispute records | E-Commerce Act | Complaint and dispute records | 3 years |
| Advertising records | E-Commerce Act | Advertising records | 6 months |
| Access logs | Protection of Communications Secrets Act (통신비밀보호법) Section 15-2, Enforcement Decree Section 41(2) | Website visit logs | 3 months |
| Tax records | Framework Act on National Taxes (국세기본법) Section 85-3 | Tax-related records | 5 years |
EU/EEA (GDPR Direct Application)
For international data transfer safeguards (SCCs, UK Addendum, Swiss Addendum), see DPA Annex 2.
| Legal Obligation | Legal Basis | Data Retained | Retention Period |
|---|---|---|---|
| Records of processing activities | GDPR Art. 30 | Records of Processing Activities (ROPA) | Duration of processing + supervisory authority request period |
| Data subject rights request records | GDPR Art. 12–22 | Access, erasure, and rectification request and response records | 3 years after request completion (for accountability purposes) |
| Consent records | GDPR Art. 7(1) | Date, method, and content of consent obtained | Until consent withdrawal or end of processing |
5.5 (f) Legitimate Interests — Art. 6(1)(f)
Definition
This basis applies when processing is necessary for the legitimate interests of the controller or a third party, unless overridden by the data subject's interests, fundamental rights, and freedoms (particularly where the data subject is a child).
Reliance on this basis requires a Legitimate Interest Assessment (LIA)—a three-part balancing test.
Legitimate Interest-Based Processing by Service
| Processing Activity | Service | Data Collected | Legitimate Interest |
|---|---|---|---|
| Web analytics (GA4) | Dreamhack, Xint, aprism, Theori (Corporate) | Page views, clicks, sessions, IP addresses, device info | Service quality improvement and usability optimization |
| Product analytics (PostHog) | Dreamhack, Xint Web | Page views, clicks, feature usage patterns | UX improvement and product roadmap prioritization |
| Error tracking (Sentry) | Dreamhack, Xint Web, aprism | IP addresses, device info, error logs | Service stability and rapid incident response |
| Bot prevention (reCAPTCHA) | Dreamhack, Theori (Corporate) | User behavioral data | Service integrity protection and automated attack defense |
| Infrastructure and real-user (RUM) monitoring (Datadog) | Dreamhack, aprism, Theori careers site | Service logs, IP addresses, page views and session data | IT infrastructure stability and performance optimization |
| CRM analytics (HubSpot) | Xint Landing | Page views, clicks, cookies | Customer relationship management and service improvement |
5.6 Legitimate Interest Assessment (LIA) Summary
We have conducted a three-part balancing test (Purpose Test, Necessity Test, Balancing Test) for each processing activity relying on Art. 6(1)(f). The table below summarizes the results. Full LIA documentation is maintained internally and is available upon request to the DPO (privacy@theori.io).
| Processing Activity | Legitimate Interest | Key Safeguards | Conclusion |
|---|---|---|---|
| Web Analytics (GA4) | Service quality improvement and usability optimization | IP anonymization, 12-month retention, opt-out mechanism | Legitimate interests not overridden |
| Product Analytics (PostHog) | UX improvement and product roadmap prioritization | 12-month retention, cookie consent, minimized identification | Legitimate interests not overridden |
| Error Tracking (Sentry) | Service stability and rapid incident response | 90-day retention, PII scrubbing, minimized access | Legitimate interests not overridden |
| Bot Prevention (reCAPTCHA) | Service integrity and automated attack defense | reCAPTCHA v3 (no user interaction), disclosed in policy | Legitimate interests not overridden |
| Infrastructure Monitoring (Datadog) | IT infrastructure stability and performance | 12-month retention, PII scrubbing, minimized access | Legitimate interests not overridden |
| CRM Analytics (HubSpot) | Customer relationship management and service improvement | 12-month retention, cookie consent, minimized identification | Legitimate interests not overridden |
| Retention under Korean law (Section 5.4) | Handling disputes and preserving legal claims through compliance with applicable law | Retention limited to the statutory minimum, no use beyond the retention purpose, minimized access, deletion without delay on expiry | Legitimate interests not overridden |
| Event Collection and Data Integration (RudderStack) | Stable operation of the recruitment application process and error detection | 12-month retention, cookie consent, minimized identification, no use beyond recruitment purposes | Legitimate interests not overridden |
| Blog Usage Statistics (Inblog) | Content improvement and referral-source analysis | 12-month retention, cookie consent, aggregated use only | Legitimate interests not overridden |
5.7 Comprehensive Legal Basis Mapping
The table below maps each of Theori's major processing activities to the applicable GDPR legal basis.
| Processing Activity | Service | Legal Basis | Retention Period | Notes |
|---|---|---|---|---|
| Account creation | Dreamhack, Xint Web, Xint Code, aprism | (b) Contract | Deleted upon account termination | |
| Service functionality | All Services | (b) Contract | Duration of service use | |
| Paid service billing | Dreamhack | (b) Contract | 5 years (E-Commerce Act) | |
| B2B SaaS service delivery | Xint Web, Xint Code, aprism | (b) Contract | Contract duration + 30 days | See DPA Section 8.2 |
| Security audits | ChainLight | (b) Contract | Contract duration | |
| Recruitment | Theori (Corporate) | (b) Pre-contractual steps | Until the hiring decision or 90 days after submission, whichever is earlier | |
| Responding to inquiries | All Services | (b) Pre-contractual steps | 1 year after the inquiry is resolved | See Privacy Policy Section 8.1 |
| CTF prize fulfillment | Dreamhack | (b) Contract | 3 years after delivery (E-Commerce Act dispute records) | |
| OAuth social login | Dreamhack, Xint Web | (b) Contract | Duration of account | |
| Marketing newsletters | Theori (Corporate), Xint | (a) Consent | Until consent withdrawal | |
| CTF event and promotional communications | Dreamhack | (a) Consent | Until consent withdrawal | |
| Targeted advertising / conversion tracking (Google Ads and AdSense, LinkedIn) | Xint Landing, Theori website and blog, Dreamhack | (a) Consent | Until consent withdrawal | |
| Web analytics (GA4) | All Services | (a) Consent / (f) Legitimate interests | 12 months | (a) for cookies; (f) for server-side |
| Product analytics (PostHog) | Dreamhack, Xint Web | (a) Consent / (f) Legitimate interests | Up to 12 months | (a) for cookies; (f) for server-side |
| Error tracking (Sentry) | Dreamhack, Xint Web, aprism | (a) Consent / (f) Legitimate interests | 90 days | (a) for cookies; (f) for server-side |
| Bot prevention (reCAPTCHA) | Dreamhack, Theori (Corporate) | (f) Legitimate interests | End of session | |
| Infrastructure and real-user (RUM) monitoring (Datadog) | Dreamhack, aprism, Theori careers site | (a) Consent / (f) Legitimate interests | Up to 12 months | (a) for cookies; (f) for server-side |
| CRM analytics (HubSpot) | Xint Landing | (a) Consent / (f) Legitimate interests | Up to 12 months | (a) for cookies; (f) for server-side |
| Usage pattern analysis and session replay (Microsoft Clarity) | Dreamhack | (a) Consent | Up to 12 months | |
| Event collection and data integration (RudderStack) | Theori careers site | (a) Consent / (f) Legitimate interests | Up to 12 months | (a) for cookies; (f) for server-side |
| Blog usage statistics (Inblog) | Theori blog | (a) Consent / (f) Legitimate interests | Up to 12 months | (a) for cookies; (f) for server-side |
| E-commerce record retention | Dreamhack | (f) Legitimate interests | 5 years (E-Commerce Act) | Korean statutory retention — see Section 5.4 for the GDPR basis |
| Access log retention | All Services | (f) Legitimate interests | 3 months (Protection of Communications Secrets Act) | Korean statutory retention — see Section 5.4 for the GDPR basis |
| Records of processing and consent | All Services | (c) Legal obligation | GDPR Art. 30 and Art. 7(1) | Obligation under EU law |
| Tax record retention | Theori (Corporate) | (f) Legitimate interests | 5 years (Framework Act on National Taxes) | Korean statutory retention — see Section 5.4 for the GDPR basis |
6. Data Subject Rights (Art. 12–22)
The GDPR grants data subjects extensive control over their personal data. We respect all of the rights listed below and respond to data subject requests transparently and promptly.
General principle (Art. 12): We provide all information related to the exercise of data subject rights in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.
6.1 Right to Be Informed — Art. 13, 14
Data subjects have the right to receive information when their personal data is collected and processed.
(a) Data Collected Directly from the Data Subject (Art. 13)
When we collect personal data directly from the data subject, we provide the following information at the time of collection:
| Information Provided | Example |
|---|---|
| Identity and contact details of the controller | Theori, Inc., privacy@theori.io |
| DPO contact details | privacy@theori.io |
| Purposes of processing | Service delivery, contract performance, marketing (see Section 5) |
| Legal basis for processing | Contract (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), consent (Art. 6(1)(a)), legal obligation (Art. 6(1)(c)) (see Sections 5.2–5.5) |
| Legitimate interests pursued (when Art. 6(1)(f) applies) | Service security, fraud prevention, service improvement |
| Recipients or categories of recipients | See Section 9 (International Transfers) |
| International transfers and appropriate safeguards | Transfers to US-based sub-processors — SCCs (Standard Contractual Clauses). See Section 9.2 for transfers to Theori, Inc. |
| Retention period or criteria for determining it | Varies by service (see Section 5.7) |
| Data subject rights | Access, rectification, erasure, restriction of processing, portability, objection, and rights related to automated decision-making |
| Right to withdraw consent (for consent-based processing) | You may withdraw consent at any time; withdrawal does not affect the lawfulness of prior processing |
| Right to lodge a complaint with a supervisory authority | Supervisory authority of your country of residence (e.g., PIPC, ICO, CNIL) |
| Whether data provision is a statutory or contractual requirement, and consequences of non-provision | Failure to provide mandatory data may limit your use of our services |
| Existence of automated decision-making (including profiling) | No ADM under Art. 22. Profiling under Art. 4(4) — see Section 6.8 |
(b) Data Not Collected Directly from the Data Subject (Art. 14)
When we collect personal data indirectly from a third party (e.g., Git commit metadata in Xint Code), we provide the following in addition to the Art. 13 disclosures:
| Additional Information | Details |
|---|---|
| Categories of personal data concerned | Git commit metadata (developer names, emails) |
| Source of the personal data | Code repositories connected by the customer |
| Whether the data came from publicly accessible sources | Applicable for public repositories |
Timing of disclosure: For indirect collection, we provide this information within a reasonable period (no later than one month) after obtaining the data or at the point of first contact with the data subject, whichever is earlier.
6.2 Right of Access — Art. 15
Data subjects have the right to obtain confirmation as to whether we process their personal data. If we do, they may access that data and the following related information:
Information Provided upon Access Request
- Purposes of processing — The specific purposes for which personal data is processed
- Categories of personal data — The types of personal data being collected and processed
- Recipients or categories of recipients — To whom the data has been or will be disclosed (particularly recipients in third countries or international organizations)
- Retention period — The envisaged retention period or, where not possible, the criteria used to determine it
- Rights to rectification, erasure, restriction, and objection
- Right to lodge a complaint with a supervisory authority
- Source of the data — Where the data was not collected directly from the data subject
- Automated decision-making (including profiling) — Where applicable, meaningful information about the logic involved, significance, and envisaged consequences
Copy of Personal Data
- We provide one copy free of charge.
- For additional copies, we may charge a reasonable fee based on administrative costs.
- When the request is made electronically, we provide the data in a commonly used electronic format (e.g., CSV, JSON, PDF) unless otherwise requested.
Limitation: Where the right of access would adversely affect the rights and freedoms of others (including trade secrets and intellectual property), we may adjust the scope of disclosure with appropriate balancing considerations.
6.3 Right to Rectification — Art. 16
Data subjects have the right to obtain the rectification of inaccurate personal data without undue delay. They may also request the completion of incomplete personal data, including by providing a supplementary statement.
| Aspect | Details |
|---|---|
| Scope | Inaccurate or incomplete personal data |
| Process | The data subject provides correct information → we rectify without undue delay |
| Notification to recipients | If personal data has been disclosed to third parties, we notify those recipients of the rectification (unless impossible or involving disproportionate effort) |
| Channels | In-service profile settings page or email (privacy@theori.io) |
6.4 Right to Erasure ("Right to Be Forgotten") — Art. 17
Data subjects have the right to request erasure of their personal data when any of the following grounds apply, and we will erase the data without undue delay.
Grounds for Erasure
- The data is no longer necessary for the purpose for which it was collected or processed
- The data subject withdraws consent (where consent was the legal basis) and no other legal basis applies
- The data subject objects under Art. 21(1) and there are no overriding legitimate grounds for processing
- The data subject objects to direct marketing processing under Art. 21(2)
- The data has been unlawfully processed
- Erasure is required to comply with a legal obligation under EU or Member State law
- The data was collected in relation to information society services offered to a child under Art. 8(1)
Exceptions to Erasure
We may continue processing despite an erasure request where necessary for:
- Exercising the right of freedom of expression and information
- Compliance with a legal obligation under EU or Member State law (e.g., transaction records required by the E-Commerce Act)
- Reasons of public interest in public health (Art. 9(2)(h), (i) and Art. 9(3))
- Archiving, scientific or historical research, or statistical purposes in the public interest (Art. 89(1)), where erasure would render impossible or seriously impair the achievement of processing objectives
- The establishment, exercise, or defense of legal claims
Notification to recipients: Where we have made the personal data public, we take reasonable steps to inform other controllers processing that data of the erasure request, to the extent technically feasible.
6.5 Right to Restriction of Processing — Art. 18
Data subjects may request restriction of processing in any of the following circumstances:
Conditions for Restriction
| Condition | Description | Duration of Restriction |
|---|---|---|
| ① Accuracy contested | The data subject contests the accuracy of the personal data | The period during which we verify accuracy |
| ② Unlawful processing + erasure refused | Processing is unlawful, but the data subject requests restriction instead of erasure | Until the data subject requests lifting of restriction |
| ③ Purpose ended + legal claims needed | We no longer need the data for processing purposes, but the data subject requires it for the establishment, exercise, or defense of legal claims | Until legal proceedings conclude |
| ④ Objection pending | The data subject has objected under Art. 21(1) | The period during which we verify whether our legitimate grounds override the data subject's grounds |
Effect of Restriction
- Restricted personal data may only be processed—apart from storage—with the data subject's consent, or for legal claims, protection of others' rights, or important reasons of EU/Member State public interest.
- We notify the data subject before lifting any restriction.
6.6 Right to Data Portability — Art. 20
Data subjects have the right to receive their personal data in a portable format when all of the following conditions are met:
Requirements
- Processing is based on consent (Art. 6(1)(a) or Art. 9(2)(a)) or contract performance (Art. 6(1)(b))
- Processing is carried out by automated means
Scope of Portability
| Aspect | Details |
|---|---|
| Data format | Structured, commonly used, and machine-readable format (e.g., JSON, CSV, XML) |
| Direct receipt | Data subjects may receive their personal data and transmit it to another controller |
| Direct transfer request | Where technically feasible, data subjects may request that we transmit the data directly to another controller |
Portability by Service
| Service | Examples of Portable Data |
|---|---|
| Dreamhack | Profile information, course completion records, CTF participation records |
| Xint Web / Xint Code | Account information, scan result reports |
| aprism | Account information, analysis results |
Limitation: Exercising the right to portability does not affect the right to erasure (Art. 17). This right does not apply where it would adversely affect the rights and freedoms of others.
6.7 Right to Object — Art. 21
(a) Objection to Legitimate Interest-Based Processing (Art. 21(1))
Data subjects have the right to object at any time, on grounds relating to their particular situation, to processing based on legitimate interests (Art. 6(1)(f)) or public interest (Art. 6(1)(e)), including profiling.
- We will stop processing the personal data upon objection.
- However, we may continue processing if we demonstrate compelling legitimate grounds that override the data subject's interests, rights, and freedoms, or if processing is necessary for the establishment, exercise, or defense of legal claims.
(b) Objection to Direct Marketing (Art. 21(2)–(3))
Where a data subject objects to processing for direct marketing purposes, we immediately stop processing for that purpose. This right is absolute—we cannot override it by asserting legitimate grounds.
| Aspect | Legitimate Interest-Based Objection | Direct Marketing Objection |
|---|---|---|
| Legal basis | Art. 21(1) | Art. 21(2)–(3) |
| Nature | Qualified (balancing test required) | Absolute (no balancing test) |
| Our response | May continue processing if compelling legitimate grounds are demonstrated | Processing stops immediately, no exceptions |
| Theori examples | Security log analysis | Newsletters, event notification emails |
Disclosure obligation: We clearly present the right to object to data subjects at the point of first contact, separately from other information.
6.8 Rights Related to Automated Decision-Making — Art. 22
Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them.
Theori's Current Status
We do not currently engage in automated decision-making (ADM) that produces legal effects or similarly significant effects on data subjects.
| Service | AI / Automation Feature | ADM Applicable? |
|---|---|---|
| Xint Web | AI-based application vulnerability analysis | Not applicable — Results are advisory only; final decisions are made by the user |
| Xint Code | AI-based code vulnerability analysis | Not applicable — Results are advisory only; final decisions are made by the user |
| aprism | GenAI LLM traffic analysis | Not applicable — It is an analysis tool and does not produce automated decisions with legal or significant consequences |
If we introduce automated decision-making in the future, we will comply with GDPR Art. 22(1)–(4) by providing prior notice to data subjects and guaranteeing their right to obtain human intervention, express their point of view, and contest the decision.
Profiling Disclosure (Art. 4(4))
Although Theori does not engage in ADM under Art. 22, the following tools involve profiling as defined in Art. 4(4) (automated processing of personal data to evaluate certain personal aspects):
| Tool | Profiling Activity | Purpose | Legal Basis |
|---|---|---|---|
| Google Analytics 4 (GA4) | Aggregation of browsing behavior, device data, and session patterns to create audience segments | Web analytics and service improvement | Art. 6(1)(a) Consent (via cookie banner) |
| PostHog | Tracking of feature usage patterns and user flows to create behavioral profiles | Product improvement and UX optimization | Art. 6(1)(a) Consent / Art. 6(1)(f) Legitimate interests |
These profiling activities do not produce legal effects or similarly significant effects on data subjects. Data subjects may exercise their right to object to profiling under Art. 21(1) by contacting privacy@theori.io.
7. How to Exercise Your Rights
7.1 Request Channels
You may submit a rights request through any of the following channels:
| Channel | Details |
|---|---|
| privacy@theori.io | |
| 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea — Theori Information Security Team | |
| Online | Account settings pages within each service (profile edits, account deletion, marketing opt-out, etc.) |
To help us respond promptly, please include the specific right you wish to exercise, the details of your request, and your contact information.
7.2 Response Timeline
| Stage | Timeframe | Notes |
|---|---|---|
| Initial response | Within 1 month of receiving the request | We send an acknowledgment within 72 hours where possible |
| Extension | Up to 2 additional months (3 months total) | Only where requests are complex or numerous |
| Extension notice | Within the initial 1-month period | We inform the data subject of the extension and the reasons |
| Refusal | Within the initial 1-month period | We provide the reasons for refusal and inform the data subject of their right to lodge a complaint with a supervisory authority |
7.3 Fees
- Exercising your rights is free of charge as a general rule.
-
However, we may charge a reasonable fee based on administrative costs or refuse to act if a request is:
- Manifestly unfounded
- Excessive (particularly if repetitive)
-
The burden of demonstrating that a request is manifestly unfounded or excessive lies with Theori.
7.4 Identity Verification
We verify the identity of individuals submitting rights requests through the following procedures:
| Request Method | Verification Procedure |
|---|---|
| Email request | Verification that the request was sent from the registered email address; additional verification information may be requested |
| Written request | Submission of a copy of identification (destroyed immediately after verification) |
| Request by agent | Power of attorney and agent identity verification |
| In-service request | Login authentication |
Data minimization: Information collected solely for identity verification is destroyed without delay after verification and is not used for any other purpose.
7.5 Right to Lodge a Complaint with a Supervisory Authority
If you are dissatisfied with how we process your personal data, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement (Art. 77).
| Supervisory Authority | Jurisdiction | Website |
|---|---|---|
| Personal Information Protection Commission (PIPC) | Republic of Korea | https://www.pipc.go.kr |
| ICO (Information Commissioner's Office) | United Kingdom | https://ico.org.uk |
| CNIL | France | https://www.cnil.fr |
| BfDI | Germany | https://www.bfdi.bund.de |
For a full list of EEA supervisory authorities: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
8. Children's Personal Data
8.1 General Principle
We do not direct our services to children under 16 years of age and do not knowingly collect personal data from children under 16.
Under GDPR Art. 8(1), the age of consent for information society services is 16 by default, though Member States may lower it to 13. We apply the strictest standard of 16 years.
8.2 Age Requirements by Service
| Service | Minimum Age | Legal Basis |
|---|---|---|
| Dreamhack | 14+ (domestic Korea), 16+ (EEA/UK) | PIPA (개인정보보호법, domestic), GDPR Art. 8(1) (EEA/UK) |
| Xint Web / Xint Code | 16+ (B2B — enterprise customers) | GDPR Art. 8(1) |
| aprism | 16+ (B2B — enterprise customers) | GDPR Art. 8(1) |
| ChainLight | 16+ (corporate inquiries) | GDPR Art. 8(1) |
| Theori (Corporate) | 16+ | GDPR Art. 8(1) |
8.3 Actions When Children's Data Is Discovered
If we become aware that we have collected personal data from a child under 16, we take the following actions without undue delay:
- Immediately delete the personal data.
- Notify the child or their holder of parental responsibility of the deletion.
- Request deletion from any third parties to whom the data was disclosed.
8.4 Parental Consent
Where processing of a child's personal data under 16 is unavoidable, we obtain consent from the holder of parental responsibility and make reasonable efforts to verify that consent was given or authorized by the holder of parental responsibility (Art. 8(2)).
9. International Data Transfers
Theori may transfer personal data collected in the EU/EEA to countries outside the EEA to deliver our global services. For all international transfers, we apply appropriate safeguards under GDPR Chapter V (Art. 44–49) to ensure that data subjects' personal data receives a level of protection essentially equivalent to that within the EU/EEA.
9.1 Transfers Based on an Adequacy Decision (Art. 45)
The European Commission may adopt an adequacy decision recognizing that a specific country ensures an adequate level of data protection. Transfers to countries covered by an adequacy decision do not require additional safeguards.
Republic of Korea — Adequacy Decision
- Decision: Commission Implementing Decision (EU) 2022/254 (adopted December 17, 2021)
- Significance: The European Commission recognized that the Republic of Korea provides a level of data protection essentially equivalent to that of the EU GDPR through its Personal Information Protection Act ("PIPA," 개인정보보호법) and related laws.
- Effect: Transfers from the EU/EEA to the Republic of Korea are permitted under GDPR Art. 45 without additional safeguards. Accordingly, data transfers to Theori Korea are lawfully carried out under the adequacy decision.
Republic of Korea — UK Adequacy Regulations
- Basis: Data Protection (Adequacy) (Republic of Korea) Regulations 2022 (in force 19 December 2022)
- Significance: This was the UK's first adequacy regulation following its withdrawal from the EU, and its scope is broader than the EU adequacy decision in that it also covers transfers of credit information.
- Effect: Transfers from the UK to the Republic of Korea are permitted under UK GDPR Art. 45A (formerly Art. 45; restructured by the Data (Use and Access) Act 2025 s.85 and Schedule 7, in force 5 February 2026) without additional safeguards.
Note: Adequacy decisions and regulations are reviewed periodically by the European Commission and the UK government respectively. We continuously monitor their validity.
9.2 Transfers Based on Standard Contractual Clauses (SCCs) (Art. 46)
For transfers to countries without an adequacy decision (e.g., the United States), we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission (Commission Implementing Decision (EU) 2021/914).
Transfers subject to the UK GDPR: EU SCCs cannot be used as-is for transfers governed by UK law. Where a Chapter V transfer from the UK to a country without UK adequacy regulations occurs, we enter into the ICO-approved UK Addendum to the EU SCCs. Its operative terms are set out in advance in DPA Annex 2, Part 2 and take effect when the Customer accepts the DPA. Because Theori, Inc. is not certified under the DPF, we do not rely on the UK Extension to the DPF.
In addition to SCCs, we conduct Transfer Impact Assessments (TIAs) to evaluate the legal environment of the destination country and determine whether supplementary measures are needed. As explained below, SCCs cannot be used for transfers to Theori, Inc.; for transfers to our US-based sub-processors we rely on SCCs, and several of those sub-processors are certified under the EU-U.S. Data Privacy Framework (DPF), providing additional protection. Theori, Inc. is not currently DPF-certified.
Key Sub-processors Receiving International Transfers
What counts as a "transfer". Where an EU/EEA data subject provides personal data directly to Theori, Inc. — for example by signing up for a service or contacting or applying to us directly — this is not a "transfer" within the meaning of Chapter V of the GDPR, following EDPB Guidelines 05/2021; the GDPR applies directly to that processing under Art. 3(2).
For routes that do constitute a Chapter V transfer (an exporter in the EU to an importer in a third country), the safeguards below apply. However, the current Standard Contractual Clauses (Implementing Decision (EU) 2021/914) cannot be used for an importer whose processing falls within the scope of the GDPR under Art. 3(2) (see recital (7) of that Decision). We will adopt the European Commission's Standard Contractual Clauses for that scenario as soon as they are published. In the meantime, the technical and organisational safeguards set out in this policy and in our intra-group data processing and transfer agreement continue to apply.
The table below lists the key sub-processors to which we transfer personal data collected in the EU/EEA. We apply the EU Standard Contractual Clauses to U.S. sub-processors whose receipt constitutes a Chapter V transfer. As explained above, Theori, Inc. is directly subject to the GDPR under Art. 3(2) and is therefore outside the scope of the current SCCs; our intra-group data processing and transfer agreement and the technical and organisational safeguards in this policy apply instead.
| Recipient | Destination | Data Transferred | Purpose | Safeguards | Service |
|---|---|---|---|---|---|
| Theori, Inc. | United States | Recruitment and corporate inquiry data | Overseas business operations (Theori, Inc.) | Directly subject to the GDPR under Art. 3(2) — intra-group data processing and transfer agreement + encryption in transit and at rest + access controls | Theori (Corporate) |
| Amazon Web Services, Inc. | United States | Service data | Cloud infrastructure and data storage | SCCs + AES-256 encryption in transit and at rest | Xint Code |
| Amazon Web Services Korea LLC | Republic of Korea (Seoul) | Service data | Cloud infrastructure and data storage | Adequacy decision + AES-256 encryption in transit and at rest | Xint Web, aprism, Dreamhack, ChainLight |
| Google LLC | United States | OAuth profile, cookies, service usage records, IP addresses, email, work documents | OAuth authentication, web analytics (GA4), business communications (Google Workspace), bot prevention (reCAPTCHA) | SCCs + DPF participation + IP anonymization (GA4) | All Services |
| PostHog, Inc. | United States | Cookies, service usage records | Product analytics | SCCs + data minimization | Xint Web, Dreamhack |
| Functional Software, Inc. (Sentry) | United States | IP addresses, device info, error logs | Error tracking and performance monitoring | SCCs + 90-day automatic deletion | Xint Web, aprism, Dreamhack |
| HubSpot, Inc. | United States | Name, company, email, phone | CRM and email marketing | SCCs + DPF participation + access controls | Xint Landing |
| Anthropic PBC | United States | Code, prompts | AI-based security analysis | SCCs + Zero Data Retention (ZDR) — data deleted immediately after processing; not used for model training | Xint Web, Xint Code, aprism |
| OpenAI, Inc. | United States | Code, prompts | AI-based security analysis | SCCs + Zero Data Retention (ZDR) — data deleted immediately after processing; not used for model training | Xint Web, Xint Code, aprism |
| Google LLC (Gemini API) | United States | Code, prompts | AI-based security analysis | SCCs + Zero Data Retention (ZDR) — data deleted immediately after processing; not used for model training | Xint Web, Xint Code, aprism |
| Amazon Web Services, Inc. (Bedrock) | United States (Virginia) | Code, prompts | AI-based security analysis | SCCs + ZDR (not used for model training) | Xint Web, Xint Code, aprism |
| Amazon Web Services Korea LLC (Bedrock) | Republic of Korea (Seoul) | Code, prompts | AI-based security analysis | Adequacy decision + ZDR (not used for model training) | Xint Web, Xint Code, aprism |
| Stripe, Inc. | United States | Payment information (card number, amount, etc.) | International payment processing | SCCs + PCI DSS Level 1 certification + tokenization | Dreamhack |
| Slack Technologies, LLC | United States | Name, email, inquiry details | Customer inquiry support | SCCs + in-transit encryption | Xint Web, Dreamhack, aprism |
| Channel Corporation (Channel Talk) | Republic of Korea (Seoul) | Name, email, chat transcripts, IP address, device info, behavioral data | Customer support (live chat) | Adequacy decision + ISO 27001/27701/ISMS certification + in-transit encryption | Xint Web |
| Gusto, Inc. | United States | Employee name, contact info, salary, bank account | HR / payroll / recruitment management | SCCs + SOC 2 Type II certification + data encryption | Theori US Ops |
| Salesforce, Inc. | United States | Name, email, company name | Marketing / CRM | SCCs + DPF participation + Salesforce Shield encryption | Theori US Ops |
| Postmark (ActiveCampaign, LLC) | United States | Email address | Email delivery | SCCs + TLS encryption in transit | Xint Web |
| Twilio Inc. | United States | Phone number, verification code | Identity verification SMS | SCCs + DPF participation | Dreamhack |
| Twilio SendGrid | United States | Email address | Email delivery | SCCs + TLS encryption in transit | Dreamhack |
| Datadog, Inc. | United States | IP addresses, service logs, page views and session data | Infrastructure and real-user (RUM) monitoring | SCCs + encryption at rest | Dreamhack, aprism, Theori careers site |
| Microsoft Corporation (Clarity) | United States | Cookies, on-screen interaction records, IP addresses | Usage pattern analysis and UX improvement | SCCs + activated only with prior consent | Dreamhack |
| RudderStack, Inc. | United States | Cookies, event records, IP addresses | Event collection and data integration | SCCs | Theori careers site |
| Cloudflare, Inc. | United States | IP addresses, request metadata, bot management cookies | Bot prevention and traffic protection | SCCs + encryption in transit | Theori blog, Xint |
| LinkedIn Corporation | United States | Cookies, behavioral data | Ad / lead tracking | SCCs + DPF participation | Xint Landing |
| Webflow, Inc. | United States | Website access information | Website hosting | SCCs + CDN encryption | Xint Landing |
| Intuit Inc. (QuickBooks) | United States | Payment / accounting data | Accounting and payment processing | SCCs + SOC 1/2 certification | Theori US Ops |
| Google LLC (Google Ads and AdSense) | United States | Cookies, behavioral data | Targeted advertising / conversion tracking / ad delivery | SCCs + activated only with prior consent | Xint Landing, Theori website and blog, Dreamhack |
| Google LLC (embedded YouTube) | United States | Viewing history, cookies | Embedded video playback and viewing-based recommendations or advertising | SCCs + activated only with prior consent | Theori blog |
| Okta, Inc. | United States | OIDC profile (email, name, profile photo) | Enterprise SSO authentication | SCCs + SOC 2 Type II attestation + encryption at rest | Xint Web |
| Amazon Web Services, Inc. (SES) | United States | Email address | Email delivery | SCCs + TLS encryption in transit | Theori (Corporate), Xint Code, Dreamhack |
9.3 Other International Transfers
| Recipient | Destination | Data Transferred | Purpose | Safeguards | Service |
|---|---|---|---|---|---|
| Typeform SL | United States (AWS Virginia) | Name, phone, email, company, inquiry details | Form hosting | SCCs | aprism Landing |
| Paperform Pty Ltd | United States | Email, project name, URL, budget, preferred contact method | Form hosting | SCCs | ChainLight |
- Typeform SL is incorporated in Barcelona, Spain, but Standard plan data is processed and stored in the United States (AWS Virginia). We apply SCCs accordingly.
- Paperform Pty Ltd is an Australian company, but data is stored on servers in the United States (AWS). The United States is not currently covered by an EU adequacy decision, so we apply SCCs to ensure appropriate safeguards.
9.4 Requesting a Copy of SCCs
Data subjects may request a copy of the Standard Contractual Clauses (SCCs) that we have entered into with our sub-processors. Trade secrets and confidential information may be appropriately redacted.
How to request:
- Email: privacy@theori.io
- Mail: 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea — Theori Information Security Team
- Response time: Within 30 days of receiving the request
10. Cookies and Tracking Technologies
10.1 Legal Basis
We use cookies and similar tracking technologies in accordance with the EU ePrivacy Directive (Directive 2002/58/EC, Art. 5(3)). Cookies other than those strictly necessary for service delivery are placed only after obtaining the data subject's prior opt-in consent, managed through our consent management platform.
10.2 Cookie Categories
We classify our cookies into the following four categories:
| Category | Description | Consent Required? | Examples |
|---|---|---|---|
| Strictly Necessary | Essential cookies for core service functionality, including login session management, CSRF protection, and security authentication | No consent required (Art. 5(3) exemption) | Session ID, CSRF token, authentication token |
| Functional | Cookies that remember user preferences to enhance functionality, such as language settings, theme, and layout | Prior consent required | Language preference cookie, UI settings cookie |
| Analytics | Cookies that analyze service usage patterns for service improvement, including aggregated statistics and UX optimization (some tools include replay of on-screen interactions) | Prior consent required | Google Analytics, PostHog, HubSpot, Microsoft Clarity, Sentry, RudderStack, Datadog, Inblog |
| Marketing | Cookies for targeted advertising, conversion tracking, and ad performance measurement, including retargeting and cross-site tracking | Prior consent required | Google Ads and AdSense, LinkedIn Insight Tag, embedded YouTube |
For detailed information about cookie categories, third-party service providers, and consent management, see our Cookie Policy.
10.3 Consent Management
- Opt-in principle: We place cookies other than strictly necessary cookies only after obtaining prior consent.
- Opt-out: You may withdraw cookie consent at any time. After withdrawal, the relevant cookies are no longer placed.
- Consent Management Platform (CMP): Theori uses Cookiebot (Usercentrics A/S) as its Consent Management Platform, which complies with the ePrivacy Directive, GDPR, and applicable Member State laws. The Cookiebot consent banner is displayed automatically upon first visit to the services where it is deployed and allows you to accept or reject non-essential cookies by category (analytics, marketing, functional). Cookiebot is deployed on every service that uses advertising or analytics cookies; you may also delete cookies in your browser to have the consent banner reappear, or manage cookies through your browser settings.
10.4 Managing Cookies through Browser Settings
You can refuse the storage of cookies or delete existing cookies through your web browser settings.
| Browser | Cookie Settings Path |
|---|---|
| Chrome | Settings → Privacy and security → Third-party cookies |
| Safari | Preferences → Privacy → Manage Website Data |
| Firefox | Settings → Privacy & Security → Cookies and Site Data |
| Edge | Settings → Cookies and site permissions → Manage and delete cookies and site data |
Note: Disabling cookies may prevent certain service features—such as login and shopping carts—from functioning properly.
11. Data Protection Impact Assessment (DPIA)
11.1 Legal Requirements
Under GDPR Art. 35, where processing is likely to result in a high risk to the rights and freedoms of data subjects, a Data Protection Impact Assessment (DPIA) must be carried out before processing begins.
A DPIA is mandatory for the following types of processing (Art. 35(3)):
- (a) Systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing, including profiling, that produces legal effects or similarly significant effects
- (b) Large-scale processing of special categories of data (Art. 9(1)) or criminal conviction and offense data (Art. 10)
- (c) Systematic monitoring of a publicly accessible area on a large scale
11.2 Theori's DPIA Candidates
We are evaluating the need for DPIAs for the following processing activities:
| Processing Activity | Applicable Type | Risk Assessment | DPIA Status |
|---|---|---|---|
| AI-based security analysis (Xint Web, Xint Code, aprism) | Art. 35(1) — Processing using new technologies (none of the Art. 35(3) criteria apply: as stated in Section 6.8, we do not carry out automated decision-making producing legal or similarly significant effects) | Customer source code is submitted to AI models for automated analysis. Git commit metadata (developer names, emails) may be collected indirectly | Under evaluation |
11.3 DPIA Methodology
We reference the CNIL PIA (Privacy Impact Assessment) tool when conducting DPIAs and include the following elements required by GDPR Art. 35(7):
Art. 35(7) DPIA Required Components:
-
Systematic description of processing operations
- Processing purposes, legal basis (including legitimate interests)
- Description of envisaged processing operations and data flows
-
Necessity and proportionality assessment
- Determining whether collection and processing are necessary relative to the stated purposes
- Compliance with the data minimization principle
-
Risk assessment for data subjects' rights and freedoms
- Evaluating the source, nature, specificity, and severity of risks
- Analyzing potential impacts on data subjects
-
Risk mitigation measures
- Safeguards, security mechanisms, and technical and organizational measures to mitigate risks
- Mechanisms to demonstrate protection of data subjects' rights
Reference: The CNIL PIA tool is available free of charge at https://www.cnil.fr/en/privacy-impact-assessment-pia and provides a systematic methodology for conducting DPIAs.
11.4 Prior Consultation
If a DPIA indicates that processing would result in a high risk that cannot be mitigated through safeguards, we will request prior consultation with the competent supervisory authority under GDPR Art. 36.
12. Personal Data Breach Notification
12.1 Notification to Supervisory Authority (Art. 33)
In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach.
If notification within 72 hours is not feasible, we will provide the reasons for the delay.
Notification content (Art. 33(3)):
- The nature of the personal data breach, including the categories and approximate number of data subjects affected
- The name and contact details of the DPO
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach
12.2 Notification to Data Subjects (Art. 34)
Where a personal data breach is likely to result in a high risk to data subjects' rights and freedoms, we will notify the affected data subjects without undue delay.
However, individual notification to data subjects may be waived under the following conditions (Art. 34(3)):
- The breached data was protected by appropriate technical measures (e.g., encryption) rendering it unintelligible to unauthorized persons
- Subsequent measures have been taken that ensure the high risk is no longer likely to materialize
- Individual notification would involve disproportionate effort, in which case a public communication of equivalent effectiveness is made instead
12.3 Incident Response Process
We maintain an Incident Response Plan for systematic breach response. Key steps include:
- Detection and initial response — Breach detection through security monitoring systems and initial containment measures
- Impact assessment — Evaluating the scope, type of data, number of data subjects, and risk level
- Supervisory authority notification — Notification within 72 hours to the competent supervisory authority
- Data subject notification — Notification to data subjects without undue delay when high risk is identified
- Root cause analysis and prevention — Root cause analysis and implementation of corrective and preventive measures
- Record retention — Retaining records of all breach incidents, including facts, effects, and remedial actions taken (Art. 33(5))
Breach reporting contacts:
- Email: security@theori.io / privacy@theori.io
- Phone: +82-70-8864-1337
13. Filing Complaints with Supervisory Authorities
13.1 Right to Lodge a Complaint (Art. 77)
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or the Member State where the alleged infringement occurred.
13.2 Supervisory Authority Contact Information
A complete list of EU/EEA supervisory authorities and their contact details is available on the European Data Protection Board (EDPB) website:
13.3 Theori DPO Contact
Before filing a complaint with a supervisory authority, we encourage you to contact our DPO first so we can work to resolve your concern promptly.
- Name: Kenny Kwansoon Park (박관순)
- Title: Chief Information Security Officer (CISO / CPO / DPO)
- Email: privacy@theori.io
- Phone: +82-70-8864-1337
- Address: 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Theori Korea
14. Theori's Commitment to GDPR Compliance
Theori is committed to complying with the GDPR and all applicable data protection laws. To this end:
- DPO appointment: We are not subject to mandatory designation under GDPR Art. 37, but have voluntarily appointed a Data Protection Officer (see Section 3.1).
- Regular audits: We conduct periodic internal audits of our personal data processing activities.
- Employee training: We provide regular GDPR and data protection training to all employees.
- Records of processing: We maintain Records of Processing Activities (ROPA) as required by Art. 30.
- Privacy by Design: We embed data protection into the design phase of our services in accordance with Art. 25.
15. Policy Changes
15.1 Advance Notice
When we update this GDPR Policy, we will provide at least 7 days' advance notice through website notifications.
15.2 Material Changes
For changes that materially affect data subjects' rights, we may request renewed consent:
- Changes to the categories of personal data collected
- Changes to or additions of processing purposes
- Material changes to international transfer destinations or sub-processors
- Changes to data subject rights exercise procedures
Change Log
| Version | Effective Date | Changes |
|---|---|---|
| v1.0 | August 4, 2026 | Initial publication |
Data Protection Officer (DPO) Contact
| Detail | Contact Information |
|---|---|
| Name | Kenny Kwansoon Park (박관순) |
| privacy@theori.io | |
| Phone | +82-70-8864-1337 |
| Address | 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea |
Language
This policy is published in Korean and English. The Korean version is the authoritative text for disclosures required by the Korean Personal Information Protection Act and for data subjects in the Republic of Korea; the English version is the authoritative text for data subjects in the EEA, the United Kingdom and other jurisdictions. We maintain both versions in substantive alignment. If you identify any discrepancy, please contact privacy@theori.io and we will correct it without delay. Neither version limits any right guaranteed to you by applicable law, and where the versions differ, the version more favorable to the data subject applies.
Supplementary Provisions
This GDPR Supplemental Policy v1.0 takes effect on the date shown at the top of this document.
All previous privacy policies can be found on our consolidated Previous Versions page: