Theori Privacy Policy

Effective Date: August 4, 2026 (Consolidated Ver. 1.0)

Theori — comprising Theori Korea and Theori, Inc. (collectively "Theori," "we," "us," or "our") — is a security company, and we take responsibility for protecting your personal data. We comply with all applicable data protection laws, including the Korean Personal Information Protection Act ("PIPA," 개인정보보호법), the EU General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). We are transparent about how we collect, use, store, and delete your data.

We wrote this policy so that anyone can read and understand it. If you have questions, contact us anytime at privacy@theori.io.

1. Purpose of This Privacy Policy

This policy communicates four things clearly:

2. Personal Data We Collect

We collect only the minimum personal data necessary to provide our services and operate our business. Below, we describe what we collect and why, organized by user type.

Table category key:

  • [Required] — Necessary for service delivery. We cannot provide the service without this data.

  • [Optional] — Not required for service use. You may decline to provide this data without any disadvantage.

  • [Customer-Provided] — Business data that B2B customers directly input or upload during service use. Processing is governed by the DPA[1], not by consent.

  • [Automatic] — Usage records that the system collects automatically during service use.

2.1. Service Users (Customers)

(a) Theori Website — Business Inquiries (https://theori.io)

Personal data collected through the inquiry form on the Theori website.

(a) Theori Website — Business Inquiries (https://theori.io)
Category Data Collected Purpose Retention Period
Business Inquiry [Required] Name, email, phone number, company name, job title, inquiry details Responding to inquiries and business communications 1 year after inquiry resolution
Business Inquiry [Optional] Service type, budget range Improving consultation quality 1 year after inquiry resolution
Marketing [Optional] Name, email Sending newsletters and marketing communications Until consent is withdrawn

(b) Xint Landing (https://xint.io)

Personal data collected through the demo request page for Xint, our AI-powered security testing solution.

(b) Xint Landing (https://xint.io)
Category Data Collected Purpose Retention Period
Inquiry Form [Required] Company name, name, email, phone number, inquiry details Demo request handling and sales consultation 1 year after inquiry resolution
Inquiry Form [Optional] Job role, whether responsible for vulnerability testing, security testing methods, reason for evaluating Xint Improving consultation quality 1 year after inquiry resolution
Marketing Consent [Optional] Company name, name, email, phone number Marketing and promotional communications Until consent is withdrawn

(c) Xint Web SaaS (https://app.xint.io)

Personal data collected by our AI-powered application security testing SaaS.

(c) Xint Web SaaS (https://app.xint.io)
Category Data Collected Purpose Retention Period
Registration [Required] Email, nickname, company name Account creation, B2B customer identification, contract entity verification (nickname auto-generated from email local part if not provided) Deleted upon account termination
Registration [Optional] Profile photo In-service profile display Deleted upon account termination
Social Login — Google [Optional] Email, name, profile photo received from Google Social login authentication Deleted upon account termination
Enterprise SSO — Okta [Optional] Email, name, profile photo received from the customer's identity provider (Okta) B2B enterprise SSO authentication Deleted upon account termination

Social login and Enterprise SSO are optional authentication methods. We collect the data above only when you choose to use them.

(d) Xint Code (https://code.xint.io/login)

Personal data collected by our AI-powered source code security analysis SaaS.

(d) Xint Code (https://code.xint.io/login)
Category Data Collected Purpose Retention Period
Registration [Required] Email (magic link authentication) Account creation and authentication Deleted upon account termination
Commit metadata [Customer-Provided] Git commit metadata (developer name, email) Embedded in the repositories the Customer submits for analysis, and processed alongside the code Deleted within 30 days after contract termination (DPA Section 8.2)

For non-personal data processing details such as source code and scan results, see the DPA[1].

Note: Code data submitted for AI inference is processed through external AI services that apply Zero Data Retention (ZDR) policies. This data is never used for AI model training.

(e) aprism Landing (https://aprism.io)

Personal data collected through the demo request page for aprism, our LLM guard and monitoring solution. The form is hosted by Typeform SL (Spain; servers in the United States).

(e) aprism Landing (https://aprism.io)
Category Data Collected Purpose Retention Period
Demo Request [Required] Name, phone number, email, company name Contact identification, scheduling introductions and demos 1 year after inquiry resolution

(f) aprism SaaS (https://app.aprism.io)

Personal data collected by the aprism SaaS service. The data collected differs between SaaS and on-premise deployments.

(f) aprism SaaS (https://app.aprism.io)
Category Data Collected Purpose Retention Period
SaaS Account Registration [Required] Email, password, TOTP secret key User identification, authentication, and two-factor authentication for SaaS Deleted upon account termination
On-Premise Account Registration [Required] ID, password, TOTP secret key User identification, authentication, and two-factor authentication for on-premise Deleted upon account termination
Analysis Data [Customer-Provided] Employee LLM prompts, uploaded files AI security guardrail (DLP) service delivery Deleted within 30 days after contract termination (DPA Section 8.2)

(g) Dreamhack (https://dreamhack.io)

Personal data collected by Dreamhack, our security education platform.

(g) Dreamhack (https://dreamhack.io)
Category Data Collected Purpose Retention Period
Registration [Required] Email, username (nickname), profile information User identification and service delivery Deleted immediately upon account termination
Additional Profile [Optional] Date of birth, phone number, nationality, gender, career history, education, awards Personalized service delivery Deleted immediately upon account termination
Profile Social Links [Optional] GitHub URL, LinkedIn URL, Facebook URL, X (Twitter) URL Displaying external social links on user profile page Deleted immediately upon account termination
Social Login — Google [Optional] Email, name, profile photo Simplified authentication via Google account Deleted immediately upon account termination
Identity Verification [Required] Name, date of birth, gender, nationality, phone number, CI (Connecting Information), DI (Duplication Information) — received from the identity verification agency (NICE Information Service) Identity verification and duplicate registration check Deleted immediately after verification
Payment [Required] Product name, payment amount, nationality, date of birth, payment method details Paid service delivery and contract performance 5 years (E-Commerce Act)
Prize Delivery [Required] Name, email, phone number, address Delivering CTF prizes and event rewards 3 years after delivery (E-Commerce Act dispute records)
Marketing [Optional] Email, phone number CTF event announcements, promotional information Until consent is withdrawn
Service Usage [Automatic] Course records, CTF participation records Personalized content recommendations and service improvement Deleted immediately upon account termination
Enterprise Inquiry [Required] Contact person information (name, email, phone number, role, title), company name Enterprise service adoption inquiry response and post-sales support 1 year after inquiry resolution

Profile Social Links vs. Social Login:

  • Profile Social Links — You manually enter URLs for external social accounts to display on your profile page. This is unrelated to login.
  • Social Login (Google) — Authentication via Google OAuth. Your email, name, and profile photo are collected automatically only when you choose Google login.

(h) ChainLight (https://chainlight.io)

Personal data collected when you inquire about ChainLight, our Web3 security service. The data collected varies by inquiry type (Smart Contract Audit, DART, Relic Protocol, Other).

Common Data (All Inquiry Types)

Common Data (All Inquiry Types)
Category Data Collected Purpose Retention Period
Common [Required] Email, preferred contact method (Email/Telegram/Phone call), how you heard about us Inquiry handling and communication 1 year after inquiry resolution

Smart Contract Audit Inquiry

Smart Contract Audit Inquiry
Category Data Collected Purpose Retention Period
Smart Contract Audit [Required] Project name, X/Twitter URL, GitHub URL, desired audit completion date, budget Security audit consultation and project evaluation 1 year after inquiry resolution
Smart Contract Audit [Optional] Additional message Consultation reference 1 year after inquiry resolution

DART (Digital Asset Risk Tracker) Inquiry

DART (Digital Asset Risk Tracker) Inquiry
Category Data Collected Purpose Retention Period
DART [Required] Project name, X/Twitter URL, types of risk concerns DART adoption consultation 1 year after inquiry resolution
DART [Optional] Additional message Consultation reference 1 year after inquiry resolution

Relic Protocol Inquiry

Relic Protocol Inquiry
Category Data Collected Purpose Retention Period
Relic Protocol [Required] X/Twitter URL, service category Relic Protocol consultation 1 year after inquiry resolution
Relic Protocol [Optional] Additional message Consultation reference 1 year after inquiry resolution

Other Inquiry

Other Inquiry
Category Data Collected Purpose Retention Period
Other [Required] X/Twitter URL, service category General consultation 1 year after inquiry resolution
Other [Optional] Additional message Consultation reference 1 year after inquiry resolution

These items are collected via inquiry forms hosted on Paperform (Australian company; servers in the United States). Fields marked * are [Required]; fields marked (optional) are [Optional].

Retention: B2B sales inquiry data is retained for up to 1 year after inquiry resolution. We delete it without delay once the retention period expires.

2.2. Job Applicants

Personal data of people who apply through our careers site (https://careers.theori.io). Application intake and hiring management are handled by Doodlin Inc. (GreetingHR) on our behalf — see Section 1 of our Service Providers list.

2.2. Job Applicants
Category Data Collected Purpose Retention Period
Job Application [Required] Name, email, contact details, résumé Evaluating applicants and running the hiring process Until the hire is confirmed or 90 days from receipt, whichever is earlier

Employee data. We process personnel and payroll data of our employees to perform their employment contracts and to meet statutory obligations. For details of the categories processed and how long we keep them, contact privacy@theori.io.

2.3. Office Video Surveillance (CCTV)

We operate video surveillance at our Seoul office for facility security and crime prevention. It covers employees and authorized visitors who enter that office in person, and does not apply to users of our online services. Footage is retained for 15 days from the recording date.

2.4. Data Automatically Generated and Collected During Service Use

When you use our online services, we automatically collect the following data:

2.4. Data Automatically Generated and Collected During Service Use
Data Collected Description
Service usage records Visit timestamps, page views, clicks, feature usage logs
Access logs Connection timestamps, IP addresses, access environment
Device information OS, browser type and version, screen resolution, language settings
Cookies Cookies for session management, personalization, and analytics (see Section 11)

2.5. How We Collect Personal Data

We collect personal data through the following methods:

3. How We Use Your Data

We use personal data only for the purposes listed below.

3. How We Use Your Data
Purpose of Processing Legal Basis GDPR
Service delivery and contract performance Performance of a contract Art. 6(1)(b)
Account management and identity verification Performance of a contract Art. 6(1)(b)
Recruitment Pre-contractual steps taken at the applicant's request Art. 6(1)(b)
Customer support and complaint resolution Legitimate interests Art. 6(1)(f)
Service improvement and analytics Legitimate interests Art. 6(1)(f)
Safety and security Legitimate interests Art. 6(1)(f)
CCTV video recording (Seoul office only) Legitimate interests — facility safety and crime prevention Art. 6(1)(f)
Marketing and promotions Consent Art. 6(1)(a)
Advertising cookies and behavioral data Consent Art. 6(1)(a)
Legal compliance Compliance with a legal obligation Art. 6(1)(c)

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal, and withdrawing it does not restrict your access to the core service. Where we rely on legitimate interests, you may object to the processing (GDPR Art. 21).

For jurisdiction-specific legal bases, see the relevant policy:

  • Korea: PIPA (개인정보보호법) Article 15 and related provisions
  • EEA/UK: GDPR Policy — based on GDPR Art. 6(1)
  • B2B Customers: DPA[1]

3.1. Data Processing Principles for AI-Powered Services

As a security company, Theori makes the following commitments regarding data processing in our AI services:

3.1. Data Processing Principles for AI-Powered Services
Principle Details
No Training on Customer Data We never use customer-provided source code, binaries, or analysis data to train any AI/ML model.
Zero Data Retention When using external AI services for inference, the provider's ZDR policy applies so data is not retained on provider servers (see table below).
Customer Control B2B customers can choose whether to enable AI features as part of their contract.
Auditability You can verify our AI data processing practices at our Trust Center.

These principles apply to Xint Web, Xint Code, and aprism.

Terms applied to each external AI provider

Terms applied to each external AI provider
AI Service Provider ZDR Excluded from Model Training
Anthropic PBC (Claude) Yes Yes
OpenAI, Inc. (GPT) Yes Yes
AWS Bedrock (Amazon) Yes Yes
Google LLC (Gemini) Yes Yes

The specific models used may vary by service and feature, always within the providers listed above.

Intended Use and Data Processed

Intended Use and Data Processed
Item Details
Applicable services Xint Web (application security testing) · Xint Code (source code security analysis) · aprism (LLM traffic guard and monitoring)
Intended use Detecting and analyzing security vulnerabilities and explaining the results. We do not use these services to evaluate or profile individuals, or to make determinations affecting a data subject's rights or obligations.
Inputs (prompts) Source code, binaries, and configuration files submitted by the customer for analysis; for aprism, the LLM request and response traffic the customer routes to us. We do not separately collect or extract personal data beyond what the analysis requires.
Generated outputs Vulnerability findings and reports. These are stored within the customer's tenant and deleted per DPA Section 8.2.
Retention of inputs and outputs Inputs and outputs sent to external AI services are not retained on provider servers under their ZDR policies. Retention of our own copies follows Section 8.1.
Separate retention for AI training None. We retain no data for training purposes.
Legal basis PIPA Article 15(1)(4) (performance of a contract); GDPR Art. 6(1)(b). For customer data we act as a processor on the customer's (controller's) instructions — see the DPA.

Opt-Out and the Scope of Your Control

Reporting Problematic Output

If AI analysis output improperly includes personal data or is otherwise erroneous, report it to privacy@theori.io or through the in-product support channel. We will review it without undue delay and correct or delete the output.

Automated Decision-Making. We perform AI-based automated analysis in Xint Code, Xint Web, and aprism, but we do not make solely automated decisions that produce legal effects or similarly significant effects on data subjects; a human is involved in final determinations (GDPR Art. 22; PIPA §37-2). You may nonetheless request an explanation of the criteria and procedures behind such automated processing and request human review (see Section 9.1).

4. Disclosure to Third Parties

We do not disclose your personal data to third parties without your consent, except in the following circumstances:

Apart from the advertising and analytics disclosures described in Section 9.5(a) and Section 11, we do not currently provide personal data to third parties for their own purposes.

Business Transitions: If Theori undergoes a merger, acquisition, or asset sale, your personal data may be transferred as part of that transaction. In such cases, we will notify you in advance of the transfer, including the categories of data transferred, the identity of the recipient, and the purpose of the transfer. We will obtain your consent where required by law.

5. Additional Use and Disclosure

We may use or disclose personal data for purposes reasonably related to the original collection purpose. When doing so, we consider the following factors:

  1. Relevance to the original purpose of collection
  2. Whether additional use or disclosure is foreseeable given the context and practices under which the data was collected
  3. Whether the additional use or disclosure unfairly infringes on the data subject's interests
  4. Whether appropriate safeguards such as pseudonymization or encryption have been applied

6. Pseudonymized Data

We do not currently process pseudonymized data. If this changes, we will update this policy in accordance with applicable law.

7. Service Providers and International Data Transfers

We engage external service providers to process personal data where necessary for service delivery. Our service provider agreements include all safeguards required by applicable law.

Where your data is processed. Theori operates from the Republic of Korea (Seoul) and the United States (Austin), and serves users worldwide. Depending on the service you use, your personal data may be processed in either country and by the providers in our Service Providers and International Transfers list, in the locations shown. Section 7.2 sets out the safeguards that apply to each destination.

7.1. Processing Activities We Entrust

We entrust the following processing activities to external providers. The names of the providers performing each activity, together with the transfer details (recipient, country, data categories, purpose, and retention period), are set out in our Service Providers and International Transfers list, which forms part of this policy and has the same effect as the policy itself.

7.1. Processing Activities We Entrust
Processing Activity Applicable Services Provider Location
Cloud infrastructure and data storage All services Republic of Korea, United States
Inter-entity transfers within the group All services Republic of Korea, United States
Authentication (social login, enterprise SSO, mobile identity verification) Dreamhack, Xint Web Republic of Korea, United States
Email delivery and messaging All services United States
Customer management (CRM, sales, communications) All services United States
Cookie consent management All services Denmark
Form hosting Xint, aprism, ChainLight Spain, Australia (servers: United States)
Payment processing Dreamhack Republic of Korea, United States
AI-powered security analysis Xint Web, Xint Code, aprism Republic of Korea, United States
Web and product analytics All services United States
Error tracking and infrastructure monitoring All services United States
Advertising and marketing Theori website and blog, Xint Landing, Dreamhack United States
Security and bot prevention All services United States
Business tools and HR Company-wide United States
Web font delivery (CDN) All services United States, Europe, and other edge locations
Customer support (live chat) Xint Web Republic of Korea
Corporate blog platform Theori blog Republic of Korea
Recruitment intake and applicant tracking Theori careers Republic of Korea
Delivery of CTF prizes and event rewards Dreamhack Republic of Korea

Why the list is separate. Service provider arrangements change as our services evolve. Keeping the detailed list on its own page lets us publish changes without amending the body of this policy. Every item required by Articles 26(2) and 28-8(2) of the Korean Personal Information Protection Act, GDPR Art. 13(1)(e), and the CCPA appears in the linked list, which is published continuously on the same domain as this policy.

7.2. Transfer Safeguards

Personal data is transmitted over encrypted network channels and encrypted at rest. In addition, the following safeguards apply by destination:

7.2. Transfer Safeguards
Where data is processed Safeguard
Republic of Korea European Commission adequacy decision for the Republic of Korea (Implementing Decision (EU) 2022/254) for personal data originating in the EEA
United States For our US-based service providers, EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with encryption in transit and at rest and access controls. Some providers additionally participate in the EU-US Data Privacy Framework

When we change or add a service provider, we update the Service Providers and International Transfers list. Section 15 explains how we announce those updates.

8. Retention and Deletion

We delete personal data without delay once the purpose of collection and use has been fulfilled.

8.1. Retention Periods by Data Type

We apply consistent retention periods for each data type across all services. Each period follows the strictest standard among applicable laws.

8.1. Retention Periods by Data Type
Data Type Applicable Service Retention Period Legal Basis
Account information (email, nickname, profile) Xint Web, Xint Code, aprism, Dreamhack Deleted without delay upon account termination PIPA §21(1); GDPR Art. 17(1)
B2B sales inquiries (demo requests, inquiry forms) Xint, aprism, ChainLight, Theori (Corporate) 1 year after the inquiry is resolved GDPR Art. 5(1)(e) storage limitation; ICO Direct Marketing Guidance (24-month recommendation)
Marketing consent information All Services Until consent is withdrawn; we reconfirm opt-in status every 2 years Network Act (정보통신망법) Section 50(8), Enforcement Decree Section 62-3; CNIL: 3 years from last contact
B2B customer data (source code, binaries, scan results) Xint Web, Xint Code, aprism Per DPA contract terms DPA contract terms; GDPR Art. 28(3)(g)
Audit logs (access and activity records) Xint Web, Xint Code, aprism Per customer contract terms Customer contract terms
Job application data Theori careers site Until the hire is confirmed or 90 days from receipt, whichever is earlier Minimum retention after the hiring process ends
Office CCTV footage Theori Office (Seoul) 15 days from recording date Theori's own standard
Payment and contract records Dreamhack 5 years E-Commerce Act (전자상거래법) Enforcement Decree Section 6
Consumer complaint and dispute records Dreamhack 3 years E-Commerce Act Enforcement Decree Section 6
Web analytics data (GA4) All Services 12 months Tool retention setting · GDPR Policy Section 5.7
Product analytics data (PostHog) All Services 12 months Tool retention setting · GDPR Policy Section 5.7
Error tracking data (Sentry) All Services 90 days Tool retention setting · GDPR Policy Section 5.7

8.2. Mandatory Retention Under Applicable Law

When the law requires retention after the original purpose has been fulfilled, we store the data in segregated storage and protect it securely for the required period.

(a) Republic of Korea

(a) Republic of Korea
Retained Data Applicable Services Applicable Law Retention Period
Records related to contracts or withdrawal of offers Dreamhack E-Commerce Act (전자상거래법) Enforcement Decree Section 6 5 years
Records related to payment and supply of goods Dreamhack E-Commerce Act Enforcement Decree Section 6 5 years
Records related to consumer complaints or dispute resolution Dreamhack E-Commerce Act Enforcement Decree Section 6 3 years
Records related to labeling and advertising Dreamhack E-Commerce Act Enforcement Decree Section 6 6 months
Communications confirmation data (website access logs) All Services Protection of Communications Secrets Act (통신비밀보호법) Section 15-2 and Enforcement Decree Section 41(2) 3 months
Tax-related records Company-wide Framework Act on National Taxes (국세기본법) Section 85-3 5 years

Retention duties under the Act on Consumer Protection in Electronic Commerce apply to mail-order sellers, and therefore apply only to Dreamhack, where paid transactions take place.

(b) EU/EEA (GDPR)

(b) EU/EEA (GDPR)
Principle Details Legal Basis
Right to Erasure We delete data within one month of request. Exceptions apply for legal obligations, public interest, and legal defense purposes. GDPR Art. 17, Art. 17(3)
Storage Limitation We retain data only for the minimum period necessary to fulfill the processing purpose, then delete or anonymize it. GDPR Art. 5(1)(e)
Inactive Accounts We recommend deletion or anonymization after 2 years of inactivity. CNIL Inactive Account Guidance

For detailed retention principles applicable to EEA/UK users, see the GDPR Policy.

(c) United States (CCPA/CPRA)

(c) United States (CCPA/CPRA)
Principle Details Legal Basis
Retention Period Disclosure We disclose the planned retention period or the criteria for determining it for each category of personal information. Cal. Civ. Code §1798.100(a)(3)
Proportionality We do not retain data beyond the period reasonably necessary for the disclosed purposes. CPRA Data Minimization Principle

8.3. Deletion Procedures and Methods

9. Your Rights and How to Exercise Them

9.1. Your Rights

As a data subject, you may exercise the following rights regarding your personal data at any time:

  1. Right to Access — You may request access to the personal data we hold about you.
  2. Right to Correction and Deletion — You may request correction or deletion of your personal data if it is inaccurate or if you want it deleted. However, we cannot delete data that is required to be retained by other applicable laws.
  3. Right to Restrict Processing — You may request that we stop processing your personal data.
  4. Right to Explanation and Human Review of Automated Processing — For the automated processing in our AI-powered services (Xint Code, Xint Web, aprism), you may request an explanation of the criteria and procedures used and request human review. (We do not make fully automated decisions that produce significant effects on data subjects.)
  5. Right to Data Portability — You may request that your personal data be transmitted to yourself or another controller in a structured, commonly used, and machine-readable format, to the extent technically feasible (GDPR Art. 20). We provide this to all users as a matter of policy.

How quickly we respond. If you are in the EEA or the UK, we respond within one month (GDPR Art. 12(3)). If you are a California resident, we respond within 45 days, extendable once by a further 45 days (Section 9.5(a)). Where the Korean Personal Information Protection Act applies, we provide access within 10 days. Where more than one applies, we use the shortest.

9.2. How to Exercise Your Rights

Our Information Security Team processes requests to access, correct, delete, or restrict processing of personal data.

You may also exercise your rights through a legal representative or authorized agent. In such cases, a power of attorney must be submitted in accordance with applicable law.

9.3. Children Under 14

We do not collect personal data from children under 14 years of age, and we restrict registration by children under 14. If we discover that we have collected personal data from a child under 14, we will delete it without delay.

9.4. Limitations on Rights

We respond to rights requests without delay. However, we may limit the exercise of certain rights in the following circumstances:

9.5. Additional Disclosures for Residents of Specific Jurisdictions

(a) California Residents (CCPA/CPRA)

California Consumer Rights (CCPA/CPRA Section 1798.100–Section 1798.125)

California residents may exercise the following rights:

  1. Right to Know (Section 1798.100/Section 1798.110): The right to request the categories, sources, purposes, and third-party sharing of personal information we have collected about you during the preceding 12 months.
  2. Right to Delete (Section 1798.105): The right to request deletion of personal information we have collected.
  3. Right to Correct (Section 1798.106): The right to request correction of inaccurate personal information.
  4. Right to Opt-Out of Sale/Sharing (Section 1798.120): The right to opt out of the sale of personal information or its sharing for cross-context behavioral advertising.
  5. Right to Limit Use of Sensitive Personal Information (Section 1798.121): The right to limit the use and disclosure of sensitive personal information.
  6. Right to Non-Discrimination (Section 1798.125): The right not to be denied service or charged differently for exercising your rights.

To exercise your rights, contact privacy@theori.io. We will respond within 45 days of receiving your request (extendable by an additional 45 days).

You may also designate an authorized agent to submit a request on your behalf. We may require verification of your identity and confirmation that you authorized the agent. See Section 9.2 for general details on exercising rights through a representative.

We do not offer financial incentives for the collection, sale, retention, or deletion of personal information.

CCPA Personal Information Categories — Collection and Sharing Disclosure

The table below summarizes our collection and sharing practices by personal information category as defined in Cal. Civ. Code §1798.140. We do not sell personal information for monetary consideration. Disclosures made through advertising cookies may constitute sharing under Section 1798.140(ah) and occur only with your prior consent.

(a) California Residents (CCPA/CPRA)
CCPA Category Collected Examples Collection Source Disclosed for Business Purpose Purpose of Use Sold or Shared
A. Identifiers Yes Email, name, username, IP address, account ID Direct from user; social login; automatic collection Yes Account creation and authentication, service delivery, customer support Shared (advertising cookies, with prior consent)
B. Customer Records (Section 1798.80(e)) Yes Name, phone number, company name, job title, payment method Direct from user; payment service providers Yes Contract performance, payment processing No
C. Protected Classification Characteristics Partial Date of birth, gender, nationality (Dreamhack optional fields) Direct from user No Identity verification, age verification No
D. Commercial Information Yes Product name, payment amount, subscription history (Dreamhack) Direct from user; payment systems Yes Paid service delivery, refund processing No
E. Biometric Information No No
F. Internet/Network Activity Yes Visit timestamps, page views, clicks, access logs, browser/OS information Automatic collection (GA4, PostHog, Sentry, etc.) Yes Service improvement and analytics, error tracking, security Shared (advertising cookies, with prior consent)
G. Geolocation Data Partial Approximate location based on IP address (no precise location collected) Automatic collection No Security and unauthorized access detection No
H. Sensory Data No No
I. Professional/Employment Information Yes Company name, job title, job role (business inquiries) Direct from user No Sales consultation, demo request handling No
J. Education Information Partial Education history (Dreamhack optional field) Direct from user No User profile display No
K. Inferences No We do not generate inferences for the purpose of creating consumer profiles No
L. Sensitive Personal Information Partial Account login credentials, CI/DI (deleted immediately after verification) Direct from user; CI/DI from the identity verification agency No Account authentication, identity verification No
  • "Disclosed for a Business Purpose" refers to engagement of service providers necessary for service delivery. See our Service Providers and International Transfers list.
  • Retention periods by category (11 CCR Section 7012(e)(4)) — A, B, I, J, L: until account deletion or completion of the inquiry (inquiries: 1 year after completion). C, D: the statutory retention period (Section 8.2). F, G: 12 months per analytics tool; 90 days for error tracking (Section 8.1). E, H, K: not collected. Where a period cannot be stated in advance, we use the criterion of the minimum time necessary to achieve the purpose and delete the data without undue delay once it has elapsed.
  • We use Sensitive Personal Information only to the extent reasonably necessary for service delivery, in accordance with Cal. Civ. Code §1798.121.

(b) Residents of Japan (個人情報保護法 / APPI)

The following provisions apply when we process retained personal data (保有個人データ) subject to the Act on the Protection of Personal Information ("APPI," 個人情報保護法) of Japan.

Data Subject Rights (APPI Section 33–Section 35)

International Data Transfers (APPI Section 28)

We may transfer personal data of Japanese residents internationally. When doing so, we take the following measures in accordance with APPI Section 28:

Pseudonymously Processed Information / Anonymously Processed Information

We do not currently process pseudonymously processed information (仮名加工情報) or anonymously processed information (匿名加工情報).

Breach Reporting (APPI Section 26)

In the event of a personal data breach, we will promptly report to the Personal Information Protection Commission (PPC) of Japan and notify affected data subjects. For detailed procedures, see Section 12.4(d).

(c) Residents of Singapore (Personal Data Protection Act / PDPA)

The following provisions apply when we process personal data subject to the Personal Data Protection Act ("PDPA") of Singapore.

Consent Framework (PDPA Section 13–Section 17)

We obtain consent before collecting, using, or disclosing personal data. You may withdraw your consent at any time (Section 16), and we will stop future processing upon withdrawal. However, if processing is essential for service delivery, withdrawing consent may limit your ability to use the service.

Data Subject Rights

Data Breach Notification (PDPA Section 26A–Section 26E)

In the event of a Notifiable Data Breach, we will:

Do Not Call (DNC) Registry (PDPA Part 9, Section 39–Section 45)

Before sending marketing messages by phone, text, or fax, we check the Singapore DNC Registry. We do not send marketing messages to registered numbers.

International Data Transfers (PDPA Section 26)

In compliance with the Transfer Limitation Obligation, we verify that the recipient country provides a level of protection comparable to the PDPA before transferring personal data of Singapore residents internationally. For transfer destinations and safeguards, see our Service Providers and International Transfers list.

10. Location Data

We do not currently collect or use precise location data (for example, GPS). For security and access analysis, an approximate location (country or city level) may be inferred from your IP address; see Section 11 and Section 9.5(a). If this changes, we will obtain your prior consent and update this policy accordingly.

11. Behavioral Data and Cookies

We collect and use behavioral data (online activity information) to improve our services and deliver personalized experiences.

11.1. Behavioral Data We Collect

11.1. Behavioral Data We Collect
Collection Tool Data Collected Purpose Retention Period
Google Analytics (GA4) Page views, clicks, sessions, IP address, device/browser information Web usage statistical analysis 12 months
PostHog Page views, clicks, sessions, feature usage patterns Product analytics and UX improvement 12 months
Sentry IP address, device information, stack traces upon error Error tracking 90 days
Datadog Service logs, IP address, page views and session data Infrastructure and real-user (RUM) monitoring 12 months
Microsoft Clarity Page views, on-screen interactions such as clicks and scrolling Usage pattern analysis and UX improvement 12 months
RudderStack Page views, clicks, events Event collection and data integration (careers site) 12 months
Inblog Page views, referral sources, sessions Blog usage statistics 12 months
Google reCAPTCHA User behavior data Bot prevention Until service agreement terminates
HubSpot Page views, clicks, cookies CRM and product analytics 12 months
Google Ads and AdSense Cookies, behavioral data Targeted advertising, conversion tracking, and ad delivery Until the processing agreement ends
LinkedIn Insight Tag Cookies, behavioral data Targeted advertising and lead tracking Until the processing agreement ends
YouTube (embedded video) Viewing history, cookies Embedded video playback and viewing-based recommendations or advertising Until the processing agreement ends

The advertising tools above (Google Ads and AdSense, LinkedIn Insight Tag, embedded YouTube) are activated only where you have given prior consent. See Section 11.3 to opt out.

11.2. Use of Cookies

We use cookies to operate our services and improve your experience. A cookie is a small text file that a server sends to your browser and stores on your device.

Cookie Categories
Category Description
Essential Cookies Required for core service functions such as login, session management, and security
Functional Cookies Store user preferences such as language, theme, and layout
Analytics Cookies Analyze service usage statistics, page views, and click patterns
Marketing Cookies Enable targeted advertising, conversion tracking, and retargeting

For detailed information about cookie categories, third-party service providers, and consent management, see our Cookie Policy. On websites where our consent management platform (Cookiebot) is deployed, individual cookie names, expiration periods, and descriptions are available in the "Show details" section of the consent banner.

You can refuse or delete cookies at any time. However, blocking essential cookies may limit your ability to use certain features, such as login.

Browser Cookie Settings:

Browser Cookie Settings:
Browser Cookie Settings Path
Chrome Settings → Privacy and Security → Third-party Cookies
Safari Preferences → Privacy → Manage Website Data
Firefox Settings → Privacy & Security → Cookies and Site Data
Edge Settings → Cookies and Site Permissions → Manage and Delete Cookies and Site Data

Advertising Opt-Out:

Advertising Opt-Out:
Tool Opt-Out Method
Google Analytics Google Analytics Opt-out Browser Add-on
Google Ads Google Ad Settings
LinkedIn LinkedIn Ad Settings
General Opt-Out Digital Advertising Alliance (DAA)

Mobile Advertising Identifier:

12. How Theori Protects Your Data

We implement the following measures to protect your personal data.

12.1. Administrative Safeguards

12.2. Technical Safeguards

12.3. Physical Safeguards

12.4. Data Breach Response

In the event of a personal data breach, we respond promptly in accordance with applicable law.

(a) Republic of Korea

We treat not only loss, theft, and leakage of personal data but also its forgery, alteration, or damage (together, a "breach") as triggering notification and reporting.

(b) EU/EEA (GDPR)

(c) United States (CCPA/CPRA and State Laws)

(d) Japan (APPI)

(e) Singapore (PDPA)

We analyze the root cause of every breach and implement preventive measures to avoid recurrence.

You can review our active security controls and real-time compliance status at our Trust Center.

13. Privacy Contacts

We designate the following officers and teams to handle data protection matters and resolve complaints.

Chief Privacy Officer

Chief Privacy Officer
Detail Contact Information
Name Kenny Kwansoon Park (박관순)
Title CISO / CPO / DPO
Email privacy@theori.io
Phone +82-70-8864-1337

Data Protection Team

Data Protection Team
Detail Contact Information
Team Information Security Team
Email privacy@theori.io
Phone +82-70-8864-1337

If you have questions, complaints, or need assistance with a data protection issue, contact us at the information above. We will respond without delay.

EU/EEA and UK Representatives (GDPR Art. 27)

If you are located in the EEA or the UK, you may also contact our appointed GDPR representative directly. See GDPR Policy §4 for the role of the representatives and the basis of their appointment.

EU Representative (Art. 27, EU GDPR)

EU Representative (Art. 27, EU GDPR)
Field Details
Name Euverify Ltd (Ireland), company no. 781168
EU Member State Ireland
Address Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland
Contact gdpr@euverify.com

UK Representative (Art. 27, UK GDPR)

UK Representative (Art. 27, UK GDPR)
Field Details
Name Euverify Ltd (UK), company no. 16146525
Location United Kingdom (London)
Address 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom
Contact gdpr@euverify.com

Submitting a DSAR or other GDPR request

You can submit a Data Subject Access Request (DSAR), an erasure request, or any other GDPR request directly through our representative's secure portal. The same page confirms our appointed representative, and requests submitted there are logged and tracked.

You can review our security certifications, data protection policies, and compliance documents at our Trust Center (https://trust.theori.io).

If you need to file a complaint or seek consultation regarding a data protection violation, you may contact the following authorities:

13. Privacy Contacts
Authority Where it applies Contact
California Privacy Protection Agency California, USA cppa.ca.gov
California Attorney General California, USA oag.ca.gov
Your national data protection authority EEA Directory at edpb.europa.eu
Information Commissioner's Office (ICO) United Kingdom ico.org.uk
Personal Information Dispute Mediation Committee Republic of Korea 1833-6972 · www.kopico.go.kr
Personal Information Infringement Report Center (KISA) Republic of Korea 118 · privacy.kisa.or.kr

If you are in the EEA or the UK, see GDPR Policy Section 13 for how to lodge a complaint, and GDPR Policy Section 4.2 for the contact details of our EU and UK representatives.

14. Scope of This Policy

This policy applies to the following services operated by Theori Korea and Theori, Inc. (United States):

14. Scope of This Policy
Service URL Type
Theori Website https://theori.io Corporate website
Theori Blog https://theori.io/blog Corporate blog (technical and security content)
Theori Careers https://careers.theori.io Careers site
Theori Trust Center https://trust.theori.io Security certifications and compliance status
Xint Landing https://xint.io AI-powered security testing solution landing page
Xint Web SaaS https://app.xint.io AI-powered application security testing (B2B SaaS)
Xint Code SaaS https://code.xint.io/login AI-powered source code security analysis (B2B SaaS)
aprism Landing https://aprism.io LLM guard and monitoring solution landing page
aprism SaaS https://app.aprism.io LLM guard and monitoring (B2B SaaS)
Dreamhack https://dreamhack.io Security education platform (B2C)
ChainLight https://chainlight.io Web3 security audit service

Google API Services User Data Policy Compliance

Our services (Xint Web, Dreamhack) offer social login via Google OAuth. During this process, we receive your email, name, and profile photo through the Google API. We use this data solely for authentication and account creation. Our use of, and transfer to any other app of, information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell data received through Google APIs, use it for advertising, or transfer it to third parties for purposes unrelated to service delivery.

Supplementary Documents

The following supplementary documents form part of this policy:

Supplementary Documents
Annex Document Scope
Service Providers and International Transfers Part of Section 7 — per-provider processing activities and transfer details
A EEA/UK GDPR Policy Data subjects in the EEA/UK
B Data Processing Addendum (DPA) B2B SaaS customers
Cookie Policy Website visitors (cookies and tracking technologies)

[1] DPA (Data Processing Addendum): A contract between Theori and our B2B SaaS customers that defines the scope of personal data processing, security measures, and data retention and deletion procedures. The full text is available in Annex B: DPA.

15. Changes to This Policy

When we update this policy, we will announce the changes at least 7 days before the effective date through website or service notifications. Where such changes exceed the scope of previously obtained consent, we will obtain separate consent in accordance with Articles 15 and 17 of the Personal Information Protection Act.

Language

This policy is published in Korean and English. The Korean version is the authoritative text for disclosures required by the Korean Personal Information Protection Act and for data subjects in the Republic of Korea; the English version is the authoritative text for data subjects in the EEA, the United Kingdom and other jurisdictions. We maintain both versions in substantive alignment. If you identify any discrepancy, please contact privacy@theori.io and we will correct it without delay. Neither version limits any right guaranteed to you by applicable law, and where the versions differ, the version more favorable to the data subject applies.

Supplementary Provisions

This Consolidated Privacy Policy v1.0 takes effect on the date shown at the top of this document. All previous privacy policies can be found on our consolidated Previous Versions page: