Theori GDPR Policy

Effective Date: August 4, 2026 (Ver. 1.0)

This policy supplements Theori's Privacy Policy and provides additional rights and information for data subjects residing in the European Union (EU) and European Economic Area (EEA) under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").

Where this policy conflicts with the Privacy Policy, this policy takes precedence for EU/EEA data subjects.

1. GDPR Overview

1.1 What Is the GDPR?

The General Data Protection Regulation (Regulation (EU) 2016/679, fully applicable since May 25, 2018) is the EU's comprehensive data protection law governing the processing of personal data of individuals within the European Union and European Economic Area.

1.2 Why the GDPR Applies to Theori

Theori, Inc. ("Theori," "we," "us," or "our") and its Korean affiliate Theori Korea do not have an establishment in the EU/EEA. However, under GDPR Art. 3(2), the GDPR applies when either of the following conditions is met. We satisfy both.

(a) Offering Goods or Services to EU Residents (Art. 3(2)(a))

We offer the following services directly to EU/EEA residents:

(a) Offering Goods or Services to EU Residents (Art. 3(2)(a))
Service URL Indicators of Intent to Offer Services to EU Residents
Xint Web https://app.xint.io English interface, global B2B customers, security scanning for EU enterprises
Xint Code https://code.xint.io/login English interface, AI code analysis for global developers
aprism https://app.aprism.io English interface, GenAI security solution for global enterprises
ChainLight https://chainlight.io English interface, security audits for global Web3 projects
Theori (Corporate) https://theori.io English corporate website, accepting job applications from EU residents

Per Recital 23, mere accessibility of a website does not trigger GDPR applicability. However, actively marketing to EU enterprises, providing English-language B2B services, and accepting job applications from EU residents are objective indicators of an "intention to offer" services to EU residents.

Note on Dreamhack (https://dreamhack.io): Dreamhack is a global cybersecurity education and CTF competition platform that is not specifically targeted at EU/EEA residents. While the platform is accessible worldwide with an English interface, it does not intentionally target EU residents as its primary audience. Nonetheless, EU/EEA residents who use Dreamhack are afforded the protections described in this policy.

(b) Monitoring the Behavior of EU Residents (Art. 3(2)(b))

We monitor the online behavior of EU/EEA residents through the following tools:

(b) Monitoring the Behavior of EU Residents (Art. 3(2)(b))
Monitoring Tool Data Collected Applicable Services Monitoring Type
Google Analytics 4 (GA4) Page views, clicks, sessions, IP addresses, device info Dreamhack, Xint, aprism, Theori (Corporate) Web analytics / profiling
PostHog Page views, clicks, sessions, feature usage patterns Dreamhack, Xint Web Product analytics / behavioral tracking
Sentry IP addresses, device info, error logs Dreamhack, Xint Web, aprism Error tracking
Google reCAPTCHA User behavioral data Dreamhack, Theori (Corporate) Bot prevention (behavioral analysis)
Google Ads and AdSense Cookies, behavioral data Xint Landing, Theori website and blog, Dreamhack Targeted advertising / conversion tracking / ad delivery
LinkedIn Insight Tag Cookies, behavioral data Xint Landing Ad / lead tracking
HubSpot Page views, clicks, cookies Xint Landing CRM analytics
Microsoft Clarity Page views, on-screen interactions such as clicks and scrolling Dreamhack Usage pattern analysis / session replay
RudderStack Page views, clicks, events Theori careers site Event collection / data integration
Datadog (RUM) IP addresses, page views and session data Dreamhack, aprism, Theori careers site Real-user monitoring
Inblog Page views, referral sources, sessions Theori blog Blog usage statistics
YouTube (embedded video) Viewing history, cookies Theori blog Viewing-based recommendations / advertising

Per Recital 24, tracking individuals on the internet to create profiles or analyze behavioral patterns constitutes "monitoring."

1.3 Scope of the GDPR

Material Scope (Art. 2)

The GDPR applies to the processing of personal data wholly or partly by automated means and to the processing by non-automated means of personal data that forms part of, or is intended to form part of, a filing system.

The following activities fall within the material scope:

Territorial Scope (Art. 3)

Territorial Scope (Art. 3)
Basis GDPR Article Applicability to Theori
Processing in the context of an EU establishment Art. 3(1) Not applicable (no EU establishment)
Offering goods or services to EU residents Art. 3(2)(a) Applicable (Xint Web, Xint Code, aprism, ChainLight, Theori Corporate)
Monitoring behavior of EU residents Art. 3(2)(b) Applicable (GA4, PostHog)

Theori is therefore subject to the extraterritorial application of the EU GDPR and UK GDPR under Art. 3(2)(a) and Art. 3(2)(b) and must appoint both an EU representative and a UK representative under EU GDPR Art. 27 and UK GDPR Art. 27.

UK GDPR: The UK Data Protection Act 2018 (incorporating the UK GDPR) applies to Theori's processing of personal data of UK residents on the same basis as described above. References to "GDPR" in this policy include the UK GDPR where applicable, and references to "EU/EEA" include the United Kingdom.

2. Controller and Processor Information

2.1 Controller (Art. 4(7))

The controller determines the purposes and means of processing personal data. The processing covered by this policy—directed at EU/EEA and UK residents through Theori's overseas business (Xint, aprism, ChainLight, the Theori corporate website) and overseas recruitment—is operated by the U.S. entity Theori, Inc. Accordingly, the controller under the EU GDPR and UK GDPR is Theori, Inc.

Controller: Theori, Inc.

Controller: Theori, Inc.
Field Details
Entity Name Theori, Inc.
Country of Registration United States (Delaware)
Address PO Box 40033, Austin, TX 78704, USA
Contact privacy@theori.io / +82-70-8864-1337
Role Determines the purposes and means of processing for EU/UK-facing services and overseas recruitment

2.2 Group Controller Structure (Theori Korea / Theori, Inc.)

The Theori group operates on a market-based structure of independent controllers. Each entity acts as an independent controller determining the purposes and means of processing for the market it operates, and there is no processing that the two entities jointly determine with respect to EU/UK data subjects.

2.2 Group Controller Structure (Theori Korea / Theori, Inc.)
Entity Market Applicable Law Governing Policy
Theori, Inc. (United States, Delaware) Overseas (incl. U.S.) business and recruitment; EU/EEA and UK data subjects EU GDPR · UK GDPR · U.S. state laws This GDPR Policy
Theori Korea (Republic of Korea) Domestic Korean services and Korean recruitment Korea's Personal Information Protection Act (PIPA) Global Privacy Policy
Theori Korea (Republic of Korea) Data subjects in the EEA and the UK who use Dreamhack EU GDPR · UK GDPR This GDPR Policy

2.3 Processor (Art. 4(8))

A processor processes personal data on behalf of the controller. For our B2B SaaS services, the roles between Theori and our customers are defined as follows:

B2B SaaS Role Allocation

B2B SaaS Role Allocation
Service Theori's Role Customer's Role Data Processed
Xint Web (app.xint.io) Processor Controller Security vulnerability data from web applications designated by the customer for scanning
Xint Code (code.xint.io/login) Processor Controller Source code submitted by the customer for analysis, Git commit metadata (developer names, emails), scan results
aprism (app.aprism.io) Processor Controller LLM prompts and responses uploaded by the customer, policy-violation detection records, analysis results

Note: For personal data related to service operations—such as account information, billing, and customer support—Theori acts as the controller. The processor role applies only to data provided by the customer for analysis.

DPA (Data Processing Addendum) Requirements

Under GDPR Art. 28(3), processing by a processor must be governed by a written contract (DPA). We enter into DPAs with our B2B SaaS customers that include the following terms:

DPA (Data Processing Addendum) Requirements
DPA Required Terms (Art. 28(3)) Details
Subject matter and duration of processing Security analysis of customer-provided data for the duration of the contract
Nature and purpose of processing Security vulnerability scanning, AI-based code analysis, LLM traffic analysis and guardrails
Types of personal data Git commit metadata (developer names, emails), technical logs
Categories of data subjects Developers and contributors within the customer's organization
Controller's obligations and rights Processing instructions, audit rights, cooperation on data subject requests
Sub-processors See DPA Annex — prior notice required for changes
Data handling upon termination Return or deletion at customer's request
Security measures (Art. 32) Encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, availability measures, periodic reviews

If you are a customer with an EU/EEA establishment, you may need to enter into a DPA with us to fulfill your own GDPR obligations. We provide a standard DPA template. Contact privacy@theori.io to request a copy.

3. Data Protection Officer (DPO)

3.1 DPO Appointment (Art. 37–39)

Under GDPR Art. 37, DPO appointment is mandatory for: (1) public authorities, (2) organizations engaged in large-scale regular and systematic monitoring, and (3) organizations processing special categories of data at scale. While Theori may not currently meet the mandatory appointment criteria, we have voluntarily appointed a DPO to strengthen our data protection governance and build trust with data subjects. The DPO concurrently heads our information security function. We have therefore documented a case-by-case conflict-of-interest assessment under GDPR Art. 38(6), applying the standard in CJEU Case C-453/21: decisions that determine the purposes and means of security-related processing are taken by the Information Security Team's operational leads rather than by the DPO, who acts in an advisory and monitoring capacity. The DPO reports directly to top management and cannot be dismissed or penalized for performing DPO tasks (Art. 38(3)).

3.1 DPO Appointment (Art. 37–39)
Field Details
Name Kenny Kwansoon Park (박관순)
Title Chief Information Security Officer (CISO / CPO / DPO)
Email privacy@theori.io
Phone +82-70-8864-1337
Organization Theori Information Security Team

3.2 DPO Responsibilities (Art. 39)

The DPO performs the following duties under GDPR Art. 39:

  1. Informing and advising — Providing information and advice to the controller, processor, and their employees on GDPR obligations.
  2. Monitoring compliance — Monitoring GDPR compliance through internal policies, staff training, and audits.
  3. DPIA advisory — Advising on Data Protection Impact Assessments (Art. 35).
  4. Supervisory authority liaison — Serving as the contact point for the supervisory authority.
  5. Data subject contact point — Serving as the point of contact for data subjects wishing to exercise their GDPR rights (Art. 38(4)).

Data subjects may contact the DPO at any time regarding any matter related to the processing of their personal data or the exercise of their rights under the GDPR.

4. EU and UK Representatives (Art. 27)

4.1 Obligation to Appoint a Representative

Under EU GDPR Art. 27(1) and UK GDPR Art. 27, a controller or processor that falls within Art. 3(2)—that is, one without an establishment in the EU/UK but processing personal data of EU/UK residents—must designate a representative in writing in the EU and in the UK respectively.

Because Theori, Inc., as controller, is subject to the EU GDPR and UK GDPR under Art. 3(2)(a) and (b), we are required to appoint both an EU representative and a UK representative under Art. 27.

4.2 Current Status

EU & UK Representative Designation Status

Theori, Inc. has appointed Euverify as its EU and UK representatives under EU GDPR Art. 27 and UK GDPR Art. 27 (appointment effective July 29, 2026). EU/EEA data subjects and supervisory authorities may contact the EU representative; UK data subjects and the ICO may contact the UK representative. We also operate privacy@theori.io as a single intake channel.

If you are located in the EU or the UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative below.

EU Representative (Art. 27, EU GDPR)

EU Representative (Art. 27, EU GDPR)
Field Details
Name Euverify Ltd (Ireland), company no. 781168
EU Member State Ireland
Address Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland
Contact gdpr@euverify.com

UK Representative (Art. 27, UK GDPR)

UK Representative (Art. 27, UK GDPR)
Field Details
Name Euverify Ltd (UK), company no. 16146525
Location United Kingdom (London)
Address 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom
Contact gdpr@euverify.com

Submitting a DSAR or other GDPR request

You can submit a Data Subject Access Request (DSAR), an erasure request, or any other GDPR request directly through our representative's secure portal. The same page confirms our appointed representative. Requests submitted there are logged and tracked, and we respond within the time limits set out in Section 7.2.

GDPR Article 27 EU & UK Representative — verified by Euverify

4.3 Role of the Representatives

Under Art. 27(4), each representative acts in addition to, or instead of, the controller or processor with respect to:

4.4 Exemption Review

We have assessed the exemption grounds under Art. 27(2):

4.4 Exemption Review
Exemption Ground Applicable? Basis
Public authority or body No Theori is a private company
Occasional processing with no large-scale special category data and low risk to rights and freedoms No Our processing is not occasional (we operate always-on services)

Conclusion: No exemption applies. Theori has appointed EU and UK representatives (Euverify) in accordance with its Art. 27 obligation.

5.1 Overview of Lawful Bases

GDPR Art. 6(1) establishes six legal bases for the lawful processing of personal data. Every processing activity must rely on at least one of these bases.

5.1 Overview of Lawful Bases
Basis Article Description
(a) Consent Art. 6(1)(a) The data subject has consented to processing for one or more specific purposes
(b) Contract Art. 6(1)(b) Processing is necessary to perform a contract with the data subject or to take pre-contractual steps at the data subject's request
(c) Legal obligation Art. 6(1)(c) Processing is necessary to comply with a legal obligation under EU or Member State law
(d) Vital interests Art. 6(1)(d) Processing is necessary to protect the vital interests of the data subject or another natural person
(e) Public task Art. 6(1)(e) Processing is necessary for a task carried out in the public interest or in the exercise of official authority
(f) Legitimate interests Art. 6(1)(f) Processing is necessary for the legitimate interests of the controller or a third party, unless overridden by the data subject's fundamental rights and freedoms (particularly where the data subject is a child)

Note: Bases (d) vital interests and (e) public task do not apply to Theori's services. The sections below describe the four legal bases we rely on.

Definition and Requirements

Consent is defined in Art. 4(11). For consent to be valid under the GDPR, it must satisfy all four of the following requirements:

Definition and Requirements
Requirement Description How Theori Complies
Freely given No detriment for refusal; consent for unnecessary processing cannot be bundled with service access Marketing consent is separate from registration; refusing does not affect service access
Specific Separate consent must be obtained for each distinct processing purpose Individual consent for newsletters, targeted advertising, event notifications, etc.
Informed The data subject must be informed of the controller's identity, processing purposes, data categories, and right to withdraw before consenting All required information is included in consent forms
Unambiguous indication Pre-ticked boxes and implicit consent are not permitted; the data subject must take a clear affirmative action (check, click) Opt-in checkbox (unchecked by default)
Consent-Based Processing by Service
Processing Activity Service Data Collected How to Withdraw Consent
Marketing newsletters Theori (Corporate), Xint Email, name Unsubscribe link in emails or privacy@theori.io
CTF event and promotional communications Dreamhack Email, phone number Marketing preference settings in-service or privacy@theori.io
Targeted advertising / conversion tracking (Google Ads and AdSense, LinkedIn) Xint Landing, Theori website and blog, Dreamhack Cookies, behavioral data Cookie consent banner or browser settings

Withdrawal of consent: You may withdraw your consent at any time (Art. 7(3)). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

5.3 (b) Contract — Art. 6(1)(b)

Definition

This basis applies when processing is necessary to perform a contract with the data subject or to take pre-contractual steps at the data subject's request.

Contract-Based Processing by Service

Contract-Based Processing by Service
Processing Activity Service Contract Type Data Collected Why Processing Is Necessary
Account creation Dreamhack, Xint Web, Xint Code, aprism Terms of Service Email, username, profile information User identification and authentication for service delivery
Paid service billing Dreamhack E-commerce agreement Payment info, nationality, date of birth Delivering paid content and billing
B2B SaaS service delivery Xint Web, Xint Code, aprism SaaS subscription agreement Account info, service usage data Security scanning, code analysis, and LLM guardrail services per the contract
Security audit services ChainLight Security audit service agreement Contact person info, project details Performing security audits and delivering reports
CTF prize fulfillment Dreamhack Event participation terms Name, address, phone number, email Shipping prizes
Recruitment process Theori (Corporate) Pre-contractual steps Name, email, phone, resume Evaluating applicants and conducting the hiring process
Responding to inquiries Theori (Corporate), ChainLight, Xint, aprism Pre-contractual steps Name, email, company name, inquiry details Providing service information and quotes

Definition

This basis applies when processing is necessary to comply with a legal obligation under EU or Member State law. Theori's Korean affiliate, Theori Korea, is subject to retention obligations under Korean law, which apply primarily to its domestic Korean services as set out below. (For the treatment of third-country legal obligations under the GDPR, see the note below.)

Legal basis for third-country statutory obligations: "Legal obligation" under GDPR Art. 6(1)(c) covers only obligations arising under EU or Member State law. Retention obligations under Korean law therefore do not themselves constitute an Art. 6(1)(c) basis; where such processing falls within the scope of the GDPR, we rely on Art. 6(1)(f) legitimate interests (compliance with applicable law in order to handle disputes and preserve legal claims), and we assess the balance against data subjects' rights in Section 5.6 (Legitimate Interest Assessment). The tables below list the statutory obligations applicable in each jurisdiction.

Republic of Korea (Theori Korea) — Korean domestic services; Art. 6(1)(f) where the GDPR applies

For detailed Korean-law retention periods, see Privacy Policy Section 8.

Republic of Korea (Theori Korea) — Korean domestic services; Art. 6(1)(f) where the GDPR applies
Legal Obligation Legal Basis Data Retained Retention Period
E-commerce contract and withdrawal records Act on Consumer Protection in Electronic Commerce ("E-Commerce Act," 전자상거래법) Contract and withdrawal records 5 years
Payment and supply records E-Commerce Act Payment and supply records 5 years
Consumer complaint and dispute records E-Commerce Act Complaint and dispute records 3 years
Advertising records E-Commerce Act Advertising records 6 months
Access logs Protection of Communications Secrets Act (통신비밀보호법) Section 15-2, Enforcement Decree Section 41(2) Website visit logs 3 months
Tax records Framework Act on National Taxes (국세기본법) Section 85-3 Tax-related records 5 years

EU/EEA (GDPR Direct Application)

For international data transfer safeguards (SCCs, UK Addendum, Swiss Addendum), see DPA Annex 2.

EU/EEA (GDPR Direct Application)
Legal Obligation Legal Basis Data Retained Retention Period
Records of processing activities GDPR Art. 30 Records of Processing Activities (ROPA) Duration of processing + supervisory authority request period
Data subject rights request records GDPR Art. 12–22 Access, erasure, and rectification request and response records 3 years after request completion (for accountability purposes)
Consent records GDPR Art. 7(1) Date, method, and content of consent obtained Until consent withdrawal or end of processing

5.5 (f) Legitimate Interests — Art. 6(1)(f)

Definition

This basis applies when processing is necessary for the legitimate interests of the controller or a third party, unless overridden by the data subject's interests, fundamental rights, and freedoms (particularly where the data subject is a child).

Reliance on this basis requires a Legitimate Interest Assessment (LIA)—a three-part balancing test.

Legitimate Interest-Based Processing by Service

Legitimate Interest-Based Processing by Service
Processing Activity Service Data Collected Legitimate Interest
Web analytics (GA4) Dreamhack, Xint, aprism, Theori (Corporate) Page views, clicks, sessions, IP addresses, device info Service quality improvement and usability optimization
Product analytics (PostHog) Dreamhack, Xint Web Page views, clicks, feature usage patterns UX improvement and product roadmap prioritization
Error tracking (Sentry) Dreamhack, Xint Web, aprism IP addresses, device info, error logs Service stability and rapid incident response
Bot prevention (reCAPTCHA) Dreamhack, Theori (Corporate) User behavioral data Service integrity protection and automated attack defense
Infrastructure and real-user (RUM) monitoring (Datadog) Dreamhack, aprism, Theori careers site Service logs, IP addresses, page views and session data IT infrastructure stability and performance optimization
CRM analytics (HubSpot) Xint Landing Page views, clicks, cookies Customer relationship management and service improvement

5.6 Legitimate Interest Assessment (LIA) Summary

We have conducted a three-part balancing test (Purpose Test, Necessity Test, Balancing Test) for each processing activity relying on Art. 6(1)(f). The table below summarizes the results. Full LIA documentation is maintained internally and is available upon request to the DPO (privacy@theori.io).

5.6 Legitimate Interest Assessment (LIA) Summary
Processing Activity Legitimate Interest Key Safeguards Conclusion
Web Analytics (GA4) Service quality improvement and usability optimization IP anonymization, 12-month retention, opt-out mechanism Legitimate interests not overridden
Product Analytics (PostHog) UX improvement and product roadmap prioritization 12-month retention, cookie consent, minimized identification Legitimate interests not overridden
Error Tracking (Sentry) Service stability and rapid incident response 90-day retention, PII scrubbing, minimized access Legitimate interests not overridden
Bot Prevention (reCAPTCHA) Service integrity and automated attack defense reCAPTCHA v3 (no user interaction), disclosed in policy Legitimate interests not overridden
Infrastructure Monitoring (Datadog) IT infrastructure stability and performance 12-month retention, PII scrubbing, minimized access Legitimate interests not overridden
CRM Analytics (HubSpot) Customer relationship management and service improvement 12-month retention, cookie consent, minimized identification Legitimate interests not overridden
Retention under Korean law (Section 5.4) Handling disputes and preserving legal claims through compliance with applicable law Retention limited to the statutory minimum, no use beyond the retention purpose, minimized access, deletion without delay on expiry Legitimate interests not overridden
Event Collection and Data Integration (RudderStack) Stable operation of the recruitment application process and error detection 12-month retention, cookie consent, minimized identification, no use beyond recruitment purposes Legitimate interests not overridden
Blog Usage Statistics (Inblog) Content improvement and referral-source analysis 12-month retention, cookie consent, aggregated use only Legitimate interests not overridden

The table below maps each of Theori's major processing activities to the applicable GDPR legal basis.

5.7 Comprehensive Legal Basis Mapping
Processing Activity Service Legal Basis Retention Period Notes
Account creation Dreamhack, Xint Web, Xint Code, aprism (b) Contract Deleted upon account termination
Service functionality All Services (b) Contract Duration of service use
Paid service billing Dreamhack (b) Contract 5 years (E-Commerce Act)
B2B SaaS service delivery Xint Web, Xint Code, aprism (b) Contract Contract duration + 30 days See DPA Section 8.2
Security audits ChainLight (b) Contract Contract duration
Recruitment Theori (Corporate) (b) Pre-contractual steps Until the hiring decision or 90 days after submission, whichever is earlier
Responding to inquiries All Services (b) Pre-contractual steps 1 year after the inquiry is resolved See Privacy Policy Section 8.1
CTF prize fulfillment Dreamhack (b) Contract 3 years after delivery (E-Commerce Act dispute records)
OAuth social login Dreamhack, Xint Web (b) Contract Duration of account
Marketing newsletters Theori (Corporate), Xint (a) Consent Until consent withdrawal
CTF event and promotional communications Dreamhack (a) Consent Until consent withdrawal
Targeted advertising / conversion tracking (Google Ads and AdSense, LinkedIn) Xint Landing, Theori website and blog, Dreamhack (a) Consent Until consent withdrawal
Web analytics (GA4) All Services (a) Consent / (f) Legitimate interests 12 months (a) for cookies; (f) for server-side
Product analytics (PostHog) Dreamhack, Xint Web (a) Consent / (f) Legitimate interests Up to 12 months (a) for cookies; (f) for server-side
Error tracking (Sentry) Dreamhack, Xint Web, aprism (a) Consent / (f) Legitimate interests 90 days (a) for cookies; (f) for server-side
Bot prevention (reCAPTCHA) Dreamhack, Theori (Corporate) (f) Legitimate interests End of session
Infrastructure and real-user (RUM) monitoring (Datadog) Dreamhack, aprism, Theori careers site (a) Consent / (f) Legitimate interests Up to 12 months (a) for cookies; (f) for server-side
CRM analytics (HubSpot) Xint Landing (a) Consent / (f) Legitimate interests Up to 12 months (a) for cookies; (f) for server-side
Usage pattern analysis and session replay (Microsoft Clarity) Dreamhack (a) Consent Up to 12 months
Event collection and data integration (RudderStack) Theori careers site (a) Consent / (f) Legitimate interests Up to 12 months (a) for cookies; (f) for server-side
Blog usage statistics (Inblog) Theori blog (a) Consent / (f) Legitimate interests Up to 12 months (a) for cookies; (f) for server-side
E-commerce record retention Dreamhack (f) Legitimate interests 5 years (E-Commerce Act) Korean statutory retention — see Section 5.4 for the GDPR basis
Access log retention All Services (f) Legitimate interests 3 months (Protection of Communications Secrets Act) Korean statutory retention — see Section 5.4 for the GDPR basis
Records of processing and consent All Services (c) Legal obligation GDPR Art. 30 and Art. 7(1) Obligation under EU law
Tax record retention Theori (Corporate) (f) Legitimate interests 5 years (Framework Act on National Taxes) Korean statutory retention — see Section 5.4 for the GDPR basis

6. Data Subject Rights (Art. 12–22)

The GDPR grants data subjects extensive control over their personal data. We respect all of the rights listed below and respond to data subject requests transparently and promptly.

General principle (Art. 12): We provide all information related to the exercise of data subject rights in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.

6.1 Right to Be Informed — Art. 13, 14

Data subjects have the right to receive information when their personal data is collected and processed.

(a) Data Collected Directly from the Data Subject (Art. 13)

When we collect personal data directly from the data subject, we provide the following information at the time of collection:

(a) Data Collected Directly from the Data Subject (Art. 13)
Information Provided Example
Identity and contact details of the controller Theori, Inc., privacy@theori.io
DPO contact details privacy@theori.io
Purposes of processing Service delivery, contract performance, marketing (see Section 5)
Legal basis for processing Contract (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), consent (Art. 6(1)(a)), legal obligation (Art. 6(1)(c)) (see Sections 5.2–5.5)
Legitimate interests pursued (when Art. 6(1)(f) applies) Service security, fraud prevention, service improvement
Recipients or categories of recipients See Section 9 (International Transfers)
International transfers and appropriate safeguards Transfers to US-based sub-processors — SCCs (Standard Contractual Clauses). See Section 9.2 for transfers to Theori, Inc.
Retention period or criteria for determining it Varies by service (see Section 5.7)
Data subject rights Access, rectification, erasure, restriction of processing, portability, objection, and rights related to automated decision-making
Right to withdraw consent (for consent-based processing) You may withdraw consent at any time; withdrawal does not affect the lawfulness of prior processing
Right to lodge a complaint with a supervisory authority Supervisory authority of your country of residence (e.g., PIPC, ICO, CNIL)
Whether data provision is a statutory or contractual requirement, and consequences of non-provision Failure to provide mandatory data may limit your use of our services
Existence of automated decision-making (including profiling) No ADM under Art. 22. Profiling under Art. 4(4) — see Section 6.8

(b) Data Not Collected Directly from the Data Subject (Art. 14)

When we collect personal data indirectly from a third party (e.g., Git commit metadata in Xint Code), we provide the following in addition to the Art. 13 disclosures:

(b) Data Not Collected Directly from the Data Subject (Art. 14)
Additional Information Details
Categories of personal data concerned Git commit metadata (developer names, emails)
Source of the personal data Code repositories connected by the customer
Whether the data came from publicly accessible sources Applicable for public repositories

Timing of disclosure: For indirect collection, we provide this information within a reasonable period (no later than one month) after obtaining the data or at the point of first contact with the data subject, whichever is earlier.

6.2 Right of Access — Art. 15

Data subjects have the right to obtain confirmation as to whether we process their personal data. If we do, they may access that data and the following related information:

Information Provided upon Access Request

  1. Purposes of processing — The specific purposes for which personal data is processed
  2. Categories of personal data — The types of personal data being collected and processed
  3. Recipients or categories of recipients — To whom the data has been or will be disclosed (particularly recipients in third countries or international organizations)
  4. Retention period — The envisaged retention period or, where not possible, the criteria used to determine it
  5. Rights to rectification, erasure, restriction, and objection
  6. Right to lodge a complaint with a supervisory authority
  7. Source of the data — Where the data was not collected directly from the data subject
  8. Automated decision-making (including profiling) — Where applicable, meaningful information about the logic involved, significance, and envisaged consequences

Copy of Personal Data

Limitation: Where the right of access would adversely affect the rights and freedoms of others (including trade secrets and intellectual property), we may adjust the scope of disclosure with appropriate balancing considerations.

6.3 Right to Rectification — Art. 16

Data subjects have the right to obtain the rectification of inaccurate personal data without undue delay. They may also request the completion of incomplete personal data, including by providing a supplementary statement.

6.3 Right to Rectification — Art. 16
Aspect Details
Scope Inaccurate or incomplete personal data
Process The data subject provides correct information → we rectify without undue delay
Notification to recipients If personal data has been disclosed to third parties, we notify those recipients of the rectification (unless impossible or involving disproportionate effort)
Channels In-service profile settings page or email (privacy@theori.io)

6.4 Right to Erasure ("Right to Be Forgotten") — Art. 17

Data subjects have the right to request erasure of their personal data when any of the following grounds apply, and we will erase the data without undue delay.

Grounds for Erasure

  1. The data is no longer necessary for the purpose for which it was collected or processed
  2. The data subject withdraws consent (where consent was the legal basis) and no other legal basis applies
  3. The data subject objects under Art. 21(1) and there are no overriding legitimate grounds for processing
  4. The data subject objects to direct marketing processing under Art. 21(2)
  5. The data has been unlawfully processed
  6. Erasure is required to comply with a legal obligation under EU or Member State law
  7. The data was collected in relation to information society services offered to a child under Art. 8(1)

Exceptions to Erasure

We may continue processing despite an erasure request where necessary for:

Notification to recipients: Where we have made the personal data public, we take reasonable steps to inform other controllers processing that data of the erasure request, to the extent technically feasible.

6.5 Right to Restriction of Processing — Art. 18

Data subjects may request restriction of processing in any of the following circumstances:

Conditions for Restriction

Conditions for Restriction
Condition Description Duration of Restriction
① Accuracy contested The data subject contests the accuracy of the personal data The period during which we verify accuracy
② Unlawful processing + erasure refused Processing is unlawful, but the data subject requests restriction instead of erasure Until the data subject requests lifting of restriction
③ Purpose ended + legal claims needed We no longer need the data for processing purposes, but the data subject requires it for the establishment, exercise, or defense of legal claims Until legal proceedings conclude
④ Objection pending The data subject has objected under Art. 21(1) The period during which we verify whether our legitimate grounds override the data subject's grounds

Effect of Restriction

6.6 Right to Data Portability — Art. 20

Data subjects have the right to receive their personal data in a portable format when all of the following conditions are met:

Requirements

  1. Processing is based on consent (Art. 6(1)(a) or Art. 9(2)(a)) or contract performance (Art. 6(1)(b))
  2. Processing is carried out by automated means

Scope of Portability

Scope of Portability
Aspect Details
Data format Structured, commonly used, and machine-readable format (e.g., JSON, CSV, XML)
Direct receipt Data subjects may receive their personal data and transmit it to another controller
Direct transfer request Where technically feasible, data subjects may request that we transmit the data directly to another controller

Portability by Service

Portability by Service
Service Examples of Portable Data
Dreamhack Profile information, course completion records, CTF participation records
Xint Web / Xint Code Account information, scan result reports
aprism Account information, analysis results

Limitation: Exercising the right to portability does not affect the right to erasure (Art. 17). This right does not apply where it would adversely affect the rights and freedoms of others.

6.7 Right to Object — Art. 21

(a) Objection to Legitimate Interest-Based Processing (Art. 21(1))

Data subjects have the right to object at any time, on grounds relating to their particular situation, to processing based on legitimate interests (Art. 6(1)(f)) or public interest (Art. 6(1)(e)), including profiling.

(b) Objection to Direct Marketing (Art. 21(2)–(3))

Where a data subject objects to processing for direct marketing purposes, we immediately stop processing for that purpose. This right is absolute—we cannot override it by asserting legitimate grounds.

(b) Objection to Direct Marketing (Art. 21(2)–(3))
Aspect Legitimate Interest-Based Objection Direct Marketing Objection
Legal basis Art. 21(1) Art. 21(2)–(3)
Nature Qualified (balancing test required) Absolute (no balancing test)
Our response May continue processing if compelling legitimate grounds are demonstrated Processing stops immediately, no exceptions
Theori examples Security log analysis Newsletters, event notification emails

Disclosure obligation: We clearly present the right to object to data subjects at the point of first contact, separately from other information.

Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects them.

Theori's Current Status

We do not currently engage in automated decision-making (ADM) that produces legal effects or similarly significant effects on data subjects.

Theori's Current Status
Service AI / Automation Feature ADM Applicable?
Xint Web AI-based application vulnerability analysis Not applicable — Results are advisory only; final decisions are made by the user
Xint Code AI-based code vulnerability analysis Not applicable — Results are advisory only; final decisions are made by the user
aprism GenAI LLM traffic analysis Not applicable — It is an analysis tool and does not produce automated decisions with legal or significant consequences

If we introduce automated decision-making in the future, we will comply with GDPR Art. 22(1)–(4) by providing prior notice to data subjects and guaranteeing their right to obtain human intervention, express their point of view, and contest the decision.

Profiling Disclosure (Art. 4(4))

Although Theori does not engage in ADM under Art. 22, the following tools involve profiling as defined in Art. 4(4) (automated processing of personal data to evaluate certain personal aspects):

Profiling Disclosure (Art. 4(4))
Tool Profiling Activity Purpose Legal Basis
Google Analytics 4 (GA4) Aggregation of browsing behavior, device data, and session patterns to create audience segments Web analytics and service improvement Art. 6(1)(a) Consent (via cookie banner)
PostHog Tracking of feature usage patterns and user flows to create behavioral profiles Product improvement and UX optimization Art. 6(1)(a) Consent / Art. 6(1)(f) Legitimate interests

These profiling activities do not produce legal effects or similarly significant effects on data subjects. Data subjects may exercise their right to object to profiling under Art. 21(1) by contacting privacy@theori.io.

7. How to Exercise Your Rights

7.1 Request Channels

You may submit a rights request through any of the following channels:

7.1 Request Channels
Channel Details
Email privacy@theori.io
Mail 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea — Theori Information Security Team
Online Account settings pages within each service (profile edits, account deletion, marketing opt-out, etc.)

To help us respond promptly, please include the specific right you wish to exercise, the details of your request, and your contact information.

7.2 Response Timeline

7.2 Response Timeline
Stage Timeframe Notes
Initial response Within 1 month of receiving the request We send an acknowledgment within 72 hours where possible
Extension Up to 2 additional months (3 months total) Only where requests are complex or numerous
Extension notice Within the initial 1-month period We inform the data subject of the extension and the reasons
Refusal Within the initial 1-month period We provide the reasons for refusal and inform the data subject of their right to lodge a complaint with a supervisory authority

7.3 Fees

7.4 Identity Verification

We verify the identity of individuals submitting rights requests through the following procedures:

7.4 Identity Verification
Request Method Verification Procedure
Email request Verification that the request was sent from the registered email address; additional verification information may be requested
Written request Submission of a copy of identification (destroyed immediately after verification)
Request by agent Power of attorney and agent identity verification
In-service request Login authentication

Data minimization: Information collected solely for identity verification is destroyed without delay after verification and is not used for any other purpose.

7.5 Right to Lodge a Complaint with a Supervisory Authority

If you are dissatisfied with how we process your personal data, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement (Art. 77).

7.5 Right to Lodge a Complaint with a Supervisory Authority
Supervisory Authority Jurisdiction Website
Personal Information Protection Commission (PIPC) Republic of Korea https://www.pipc.go.kr
ICO (Information Commissioner's Office) United Kingdom https://ico.org.uk
CNIL France https://www.cnil.fr
BfDI Germany https://www.bfdi.bund.de

For a full list of EEA supervisory authorities: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en

8. Children's Personal Data

8.1 General Principle

We do not direct our services to children under 16 years of age and do not knowingly collect personal data from children under 16.

Under GDPR Art. 8(1), the age of consent for information society services is 16 by default, though Member States may lower it to 13. We apply the strictest standard of 16 years.

8.2 Age Requirements by Service

8.2 Age Requirements by Service
Service Minimum Age Legal Basis
Dreamhack 14+ (domestic Korea), 16+ (EEA/UK) PIPA (개인정보보호법, domestic), GDPR Art. 8(1) (EEA/UK)
Xint Web / Xint Code 16+ (B2B — enterprise customers) GDPR Art. 8(1)
aprism 16+ (B2B — enterprise customers) GDPR Art. 8(1)
ChainLight 16+ (corporate inquiries) GDPR Art. 8(1)
Theori (Corporate) 16+ GDPR Art. 8(1)

8.3 Actions When Children's Data Is Discovered

If we become aware that we have collected personal data from a child under 16, we take the following actions without undue delay:

  1. Immediately delete the personal data.
  2. Notify the child or their holder of parental responsibility of the deletion.
  3. Request deletion from any third parties to whom the data was disclosed.

Where processing of a child's personal data under 16 is unavoidable, we obtain consent from the holder of parental responsibility and make reasonable efforts to verify that consent was given or authorized by the holder of parental responsibility (Art. 8(2)).

9. International Data Transfers

Theori may transfer personal data collected in the EU/EEA to countries outside the EEA to deliver our global services. For all international transfers, we apply appropriate safeguards under GDPR Chapter V (Art. 44–49) to ensure that data subjects' personal data receives a level of protection essentially equivalent to that within the EU/EEA.

9.1 Transfers Based on an Adequacy Decision (Art. 45)

The European Commission may adopt an adequacy decision recognizing that a specific country ensures an adequate level of data protection. Transfers to countries covered by an adequacy decision do not require additional safeguards.

Republic of Korea — Adequacy Decision

Republic of Korea — UK Adequacy Regulations

Note: Adequacy decisions and regulations are reviewed periodically by the European Commission and the UK government respectively. We continuously monitor their validity.

9.2 Transfers Based on Standard Contractual Clauses (SCCs) (Art. 46)

For transfers to countries without an adequacy decision (e.g., the United States), we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission (Commission Implementing Decision (EU) 2021/914).

Transfers subject to the UK GDPR: EU SCCs cannot be used as-is for transfers governed by UK law. Where a Chapter V transfer from the UK to a country without UK adequacy regulations occurs, we enter into the ICO-approved UK Addendum to the EU SCCs. Its operative terms are set out in advance in DPA Annex 2, Part 2 and take effect when the Customer accepts the DPA. Because Theori, Inc. is not certified under the DPF, we do not rely on the UK Extension to the DPF.

In addition to SCCs, we conduct Transfer Impact Assessments (TIAs) to evaluate the legal environment of the destination country and determine whether supplementary measures are needed. As explained below, SCCs cannot be used for transfers to Theori, Inc.; for transfers to our US-based sub-processors we rely on SCCs, and several of those sub-processors are certified under the EU-U.S. Data Privacy Framework (DPF), providing additional protection. Theori, Inc. is not currently DPF-certified.

Key Sub-processors Receiving International Transfers

What counts as a "transfer". Where an EU/EEA data subject provides personal data directly to Theori, Inc. — for example by signing up for a service or contacting or applying to us directly — this is not a "transfer" within the meaning of Chapter V of the GDPR, following EDPB Guidelines 05/2021; the GDPR applies directly to that processing under Art. 3(2).

For routes that do constitute a Chapter V transfer (an exporter in the EU to an importer in a third country), the safeguards below apply. However, the current Standard Contractual Clauses (Implementing Decision (EU) 2021/914) cannot be used for an importer whose processing falls within the scope of the GDPR under Art. 3(2) (see recital (7) of that Decision). We will adopt the European Commission's Standard Contractual Clauses for that scenario as soon as they are published. In the meantime, the technical and organisational safeguards set out in this policy and in our intra-group data processing and transfer agreement continue to apply.

The table below lists the key sub-processors to which we transfer personal data collected in the EU/EEA. We apply the EU Standard Contractual Clauses to U.S. sub-processors whose receipt constitutes a Chapter V transfer. As explained above, Theori, Inc. is directly subject to the GDPR under Art. 3(2) and is therefore outside the scope of the current SCCs; our intra-group data processing and transfer agreement and the technical and organisational safeguards in this policy apply instead.

Key Sub-processors Receiving International Transfers
Recipient Destination Data Transferred Purpose Safeguards Service
Theori, Inc. United States Recruitment and corporate inquiry data Overseas business operations (Theori, Inc.) Directly subject to the GDPR under Art. 3(2) — intra-group data processing and transfer agreement + encryption in transit and at rest + access controls Theori (Corporate)
Amazon Web Services, Inc. United States Service data Cloud infrastructure and data storage SCCs + AES-256 encryption in transit and at rest Xint Code
Amazon Web Services Korea LLC Republic of Korea (Seoul) Service data Cloud infrastructure and data storage Adequacy decision + AES-256 encryption in transit and at rest Xint Web, aprism, Dreamhack, ChainLight
Google LLC United States OAuth profile, cookies, service usage records, IP addresses, email, work documents OAuth authentication, web analytics (GA4), business communications (Google Workspace), bot prevention (reCAPTCHA) SCCs + DPF participation + IP anonymization (GA4) All Services
PostHog, Inc. United States Cookies, service usage records Product analytics SCCs + data minimization Xint Web, Dreamhack
Functional Software, Inc. (Sentry) United States IP addresses, device info, error logs Error tracking and performance monitoring SCCs + 90-day automatic deletion Xint Web, aprism, Dreamhack
HubSpot, Inc. United States Name, company, email, phone CRM and email marketing SCCs + DPF participation + access controls Xint Landing
Anthropic PBC United States Code, prompts AI-based security analysis SCCs + Zero Data Retention (ZDR) — data deleted immediately after processing; not used for model training Xint Web, Xint Code, aprism
OpenAI, Inc. United States Code, prompts AI-based security analysis SCCs + Zero Data Retention (ZDR) — data deleted immediately after processing; not used for model training Xint Web, Xint Code, aprism
Google LLC (Gemini API) United States Code, prompts AI-based security analysis SCCs + Zero Data Retention (ZDR) — data deleted immediately after processing; not used for model training Xint Web, Xint Code, aprism
Amazon Web Services, Inc. (Bedrock) United States (Virginia) Code, prompts AI-based security analysis SCCs + ZDR (not used for model training) Xint Web, Xint Code, aprism
Amazon Web Services Korea LLC (Bedrock) Republic of Korea (Seoul) Code, prompts AI-based security analysis Adequacy decision + ZDR (not used for model training) Xint Web, Xint Code, aprism
Stripe, Inc. United States Payment information (card number, amount, etc.) International payment processing SCCs + PCI DSS Level 1 certification + tokenization Dreamhack
Slack Technologies, LLC United States Name, email, inquiry details Customer inquiry support SCCs + in-transit encryption Xint Web, Dreamhack, aprism
Channel Corporation (Channel Talk) Republic of Korea (Seoul) Name, email, chat transcripts, IP address, device info, behavioral data Customer support (live chat) Adequacy decision + ISO 27001/27701/ISMS certification + in-transit encryption Xint Web
Gusto, Inc. United States Employee name, contact info, salary, bank account HR / payroll / recruitment management SCCs + SOC 2 Type II certification + data encryption Theori US Ops
Salesforce, Inc. United States Name, email, company name Marketing / CRM SCCs + DPF participation + Salesforce Shield encryption Theori US Ops
Postmark (ActiveCampaign, LLC) United States Email address Email delivery SCCs + TLS encryption in transit Xint Web
Twilio Inc. United States Phone number, verification code Identity verification SMS SCCs + DPF participation Dreamhack
Twilio SendGrid United States Email address Email delivery SCCs + TLS encryption in transit Dreamhack
Datadog, Inc. United States IP addresses, service logs, page views and session data Infrastructure and real-user (RUM) monitoring SCCs + encryption at rest Dreamhack, aprism, Theori careers site
Microsoft Corporation (Clarity) United States Cookies, on-screen interaction records, IP addresses Usage pattern analysis and UX improvement SCCs + activated only with prior consent Dreamhack
RudderStack, Inc. United States Cookies, event records, IP addresses Event collection and data integration SCCs Theori careers site
Cloudflare, Inc. United States IP addresses, request metadata, bot management cookies Bot prevention and traffic protection SCCs + encryption in transit Theori blog, Xint
LinkedIn Corporation United States Cookies, behavioral data Ad / lead tracking SCCs + DPF participation Xint Landing
Webflow, Inc. United States Website access information Website hosting SCCs + CDN encryption Xint Landing
Intuit Inc. (QuickBooks) United States Payment / accounting data Accounting and payment processing SCCs + SOC 1/2 certification Theori US Ops
Google LLC (Google Ads and AdSense) United States Cookies, behavioral data Targeted advertising / conversion tracking / ad delivery SCCs + activated only with prior consent Xint Landing, Theori website and blog, Dreamhack
Google LLC (embedded YouTube) United States Viewing history, cookies Embedded video playback and viewing-based recommendations or advertising SCCs + activated only with prior consent Theori blog
Okta, Inc. United States OIDC profile (email, name, profile photo) Enterprise SSO authentication SCCs + SOC 2 Type II attestation + encryption at rest Xint Web
Amazon Web Services, Inc. (SES) United States Email address Email delivery SCCs + TLS encryption in transit Theori (Corporate), Xint Code, Dreamhack

9.3 Other International Transfers

9.3 Other International Transfers
Recipient Destination Data Transferred Purpose Safeguards Service
Typeform SL United States (AWS Virginia) Name, phone, email, company, inquiry details Form hosting SCCs aprism Landing
Paperform Pty Ltd United States Email, project name, URL, budget, preferred contact method Form hosting SCCs ChainLight

9.4 Requesting a Copy of SCCs

Data subjects may request a copy of the Standard Contractual Clauses (SCCs) that we have entered into with our sub-processors. Trade secrets and confidential information may be appropriately redacted.

How to request:

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies in accordance with the EU ePrivacy Directive (Directive 2002/58/EC, Art. 5(3)). Cookies other than those strictly necessary for service delivery are placed only after obtaining the data subject's prior opt-in consent, managed through our consent management platform.

We classify our cookies into the following four categories:

10.2 Cookie Categories
Category Description Consent Required? Examples
Strictly Necessary Essential cookies for core service functionality, including login session management, CSRF protection, and security authentication No consent required (Art. 5(3) exemption) Session ID, CSRF token, authentication token
Functional Cookies that remember user preferences to enhance functionality, such as language settings, theme, and layout Prior consent required Language preference cookie, UI settings cookie
Analytics Cookies that analyze service usage patterns for service improvement, including aggregated statistics and UX optimization (some tools include replay of on-screen interactions) Prior consent required Google Analytics, PostHog, HubSpot, Microsoft Clarity, Sentry, RudderStack, Datadog, Inblog
Marketing Cookies for targeted advertising, conversion tracking, and ad performance measurement, including retargeting and cross-site tracking Prior consent required Google Ads and AdSense, LinkedIn Insight Tag, embedded YouTube

For detailed information about cookie categories, third-party service providers, and consent management, see our Cookie Policy.

10.4 Managing Cookies through Browser Settings

You can refuse the storage of cookies or delete existing cookies through your web browser settings.

10.4 Managing Cookies through Browser Settings
Browser Cookie Settings Path
Chrome Settings → Privacy and security → Third-party cookies
Safari Preferences → Privacy → Manage Website Data
Firefox Settings → Privacy & Security → Cookies and Site Data
Edge Settings → Cookies and site permissions → Manage and delete cookies and site data

Note: Disabling cookies may prevent certain service features—such as login and shopping carts—from functioning properly.

11. Data Protection Impact Assessment (DPIA)

Under GDPR Art. 35, where processing is likely to result in a high risk to the rights and freedoms of data subjects, a Data Protection Impact Assessment (DPIA) must be carried out before processing begins.

A DPIA is mandatory for the following types of processing (Art. 35(3)):

11.2 Theori's DPIA Candidates

We are evaluating the need for DPIAs for the following processing activities:

11.2 Theori's DPIA Candidates
Processing Activity Applicable Type Risk Assessment DPIA Status
AI-based security analysis (Xint Web, Xint Code, aprism) Art. 35(1) — Processing using new technologies (none of the Art. 35(3) criteria apply: as stated in Section 6.8, we do not carry out automated decision-making producing legal or similarly significant effects) Customer source code is submitted to AI models for automated analysis. Git commit metadata (developer names, emails) may be collected indirectly Under evaluation

11.3 DPIA Methodology

We reference the CNIL PIA (Privacy Impact Assessment) tool when conducting DPIAs and include the following elements required by GDPR Art. 35(7):

Art. 35(7) DPIA Required Components:

  1. Systematic description of processing operations

    • Processing purposes, legal basis (including legitimate interests)
    • Description of envisaged processing operations and data flows
  2. Necessity and proportionality assessment

    • Determining whether collection and processing are necessary relative to the stated purposes
    • Compliance with the data minimization principle
  3. Risk assessment for data subjects' rights and freedoms

    • Evaluating the source, nature, specificity, and severity of risks
    • Analyzing potential impacts on data subjects
  4. Risk mitigation measures

    • Safeguards, security mechanisms, and technical and organizational measures to mitigate risks
    • Mechanisms to demonstrate protection of data subjects' rights

Reference: The CNIL PIA tool is available free of charge at https://www.cnil.fr/en/privacy-impact-assessment-pia and provides a systematic methodology for conducting DPIAs.

11.4 Prior Consultation

If a DPIA indicates that processing would result in a high risk that cannot be mitigated through safeguards, we will request prior consultation with the competent supervisory authority under GDPR Art. 36.

12. Personal Data Breach Notification

12.1 Notification to Supervisory Authority (Art. 33)

In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach.

If notification within 72 hours is not feasible, we will provide the reasons for the delay.

Notification content (Art. 33(3)):

12.2 Notification to Data Subjects (Art. 34)

Where a personal data breach is likely to result in a high risk to data subjects' rights and freedoms, we will notify the affected data subjects without undue delay.

However, individual notification to data subjects may be waived under the following conditions (Art. 34(3)):

12.3 Incident Response Process

We maintain an Incident Response Plan for systematic breach response. Key steps include:

  1. Detection and initial response — Breach detection through security monitoring systems and initial containment measures
  2. Impact assessment — Evaluating the scope, type of data, number of data subjects, and risk level
  3. Supervisory authority notification — Notification within 72 hours to the competent supervisory authority
  4. Data subject notification — Notification to data subjects without undue delay when high risk is identified
  5. Root cause analysis and prevention — Root cause analysis and implementation of corrective and preventive measures
  6. Record retention — Retaining records of all breach incidents, including facts, effects, and remedial actions taken (Art. 33(5))

Breach reporting contacts:

13. Filing Complaints with Supervisory Authorities

13.1 Right to Lodge a Complaint (Art. 77)

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or the Member State where the alleged infringement occurred.

13.2 Supervisory Authority Contact Information

A complete list of EU/EEA supervisory authorities and their contact details is available on the European Data Protection Board (EDPB) website:

13.3 Theori DPO Contact

Before filing a complaint with a supervisory authority, we encourage you to contact our DPO first so we can work to resolve your concern promptly.

14. Theori's Commitment to GDPR Compliance

Theori is committed to complying with the GDPR and all applicable data protection laws. To this end:

15. Policy Changes

15.1 Advance Notice

When we update this GDPR Policy, we will provide at least 7 days' advance notice through website notifications.

15.2 Material Changes

For changes that materially affect data subjects' rights, we may request renewed consent:

Change Log

Change Log
Version Effective Date Changes
v1.0 August 4, 2026 Initial publication

Data Protection Officer (DPO) Contact

Data Protection Officer (DPO) Contact
Detail Contact Information
Name Kenny Kwansoon Park (박관순)
Email privacy@theori.io
Phone +82-70-8864-1337
Address 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea

Language

This policy is published in Korean and English. The Korean version is the authoritative text for disclosures required by the Korean Personal Information Protection Act and for data subjects in the Republic of Korea; the English version is the authoritative text for data subjects in the EEA, the United Kingdom and other jurisdictions. We maintain both versions in substantive alignment. If you identify any discrepancy, please contact privacy@theori.io and we will correct it without delay. Neither version limits any right guaranteed to you by applicable law, and where the versions differ, the version more favorable to the data subject applies.


Supplementary Provisions

This GDPR Supplemental Policy v1.0 takes effect on the date shown at the top of this document.

All previous privacy policies can be found on our consolidated Previous Versions page: