Theori Privacy Policy
Effective Date: August 4, 2026 (Consolidated Ver. 1.0)
Theori — comprising Theori Korea and Theori, Inc. (collectively "Theori," "we," "us," or "our") — is a security company, and we take responsibility for protecting your personal data. We comply with all applicable data protection laws, including the Korean Personal Information Protection Act ("PIPA," 개인정보보호법), the EU General Data Protection Regulation ("GDPR"), and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). We are transparent about how we collect, use, store, and delete your data.
We wrote this policy so that anyone can read and understand it. If you have questions, contact us anytime at privacy@theori.io.
1. Purpose of This Privacy Policy
This policy communicates four things clearly:
- What We Collect and Why — We explain what personal data we collect, why we need it, who we share it with, and when we delete it.
- Your Rights — We describe your rights to access, correct, delete, or restrict processing of your data, and how to exercise them. Our B2C service (Dreamhack) applies each country's minimum age requirement. Children under that age cannot register without parental consent. Our B2B SaaS products (Xint, aprism) are provided through enterprise accounts and do not accept individual sign-ups.
- What to Do If Something Goes Wrong — We provide contact information for filing complaints or reporting data protection concerns.
- You Control Your Data — We make clear the rights and obligations between you and Theori so you can actively exercise control over your data.
2. Personal Data We Collect
We collect only the minimum personal data necessary to provide our services and operate our business. Below, we describe what we collect and why, organized by user type.
Table category key:
[Required] — Necessary for service delivery. We cannot provide the service without this data.
[Optional] — Not required for service use. You may decline to provide this data without any disadvantage.
[Customer-Provided] — Business data that B2B customers directly input or upload during service use. Processing is governed by the DPA[1], not by consent.
[Automatic] — Usage records that the system collects automatically during service use.
2.1. Service Users (Customers)
(a) Theori Website — Business Inquiries (https://theori.io)
Personal data collected through the inquiry form on the Theori website.
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Business Inquiry [Required] | Name, email, phone number, company name, job title, inquiry details | Responding to inquiries and business communications | 1 year after inquiry resolution |
| Business Inquiry [Optional] | Service type, budget range | Improving consultation quality | 1 year after inquiry resolution |
| Marketing [Optional] | Name, email | Sending newsletters and marketing communications | Until consent is withdrawn |
(b) Xint Landing (https://xint.io)
Personal data collected through the demo request page for Xint, our AI-powered security testing solution.
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Inquiry Form [Required] | Company name, name, email, phone number, inquiry details | Demo request handling and sales consultation | 1 year after inquiry resolution |
| Inquiry Form [Optional] | Job role, whether responsible for vulnerability testing, security testing methods, reason for evaluating Xint | Improving consultation quality | 1 year after inquiry resolution |
| Marketing Consent [Optional] | Company name, name, email, phone number | Marketing and promotional communications | Until consent is withdrawn |
(c) Xint Web SaaS (https://app.xint.io)
Personal data collected by our AI-powered application security testing SaaS.
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Registration [Required] | Email, nickname, company name | Account creation, B2B customer identification, contract entity verification (nickname auto-generated from email local part if not provided) | Deleted upon account termination |
| Registration [Optional] | Profile photo | In-service profile display | Deleted upon account termination |
| Social Login — Google [Optional] | Email, name, profile photo received from Google | Social login authentication | Deleted upon account termination |
| Enterprise SSO — Okta [Optional] | Email, name, profile photo received from the customer's identity provider (Okta) | B2B enterprise SSO authentication | Deleted upon account termination |
Social login and Enterprise SSO are optional authentication methods. We collect the data above only when you choose to use them.
(d) Xint Code (https://code.xint.io/login)
Personal data collected by our AI-powered source code security analysis SaaS.
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Registration [Required] | Email (magic link authentication) | Account creation and authentication | Deleted upon account termination |
| Commit metadata [Customer-Provided] | Git commit metadata (developer name, email) | Embedded in the repositories the Customer submits for analysis, and processed alongside the code | Deleted within 30 days after contract termination (DPA Section 8.2) |
For non-personal data processing details such as source code and scan results, see the DPA[1].
Note: Code data submitted for AI inference is processed through external AI services that apply Zero Data Retention (ZDR) policies. This data is never used for AI model training.
(e) aprism Landing (https://aprism.io)
Personal data collected through the demo request page for aprism, our LLM guard and monitoring solution. The form is hosted by Typeform SL (Spain; servers in the United States).
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Demo Request [Required] | Name, phone number, email, company name | Contact identification, scheduling introductions and demos | 1 year after inquiry resolution |
(f) aprism SaaS (https://app.aprism.io)
Personal data collected by the aprism SaaS service. The data collected differs between SaaS and on-premise deployments.
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| SaaS Account Registration [Required] | Email, password, TOTP secret key | User identification, authentication, and two-factor authentication for SaaS | Deleted upon account termination |
| On-Premise Account Registration [Required] | ID, password, TOTP secret key | User identification, authentication, and two-factor authentication for on-premise | Deleted upon account termination |
| Analysis Data [Customer-Provided] | Employee LLM prompts, uploaded files | AI security guardrail (DLP) service delivery | Deleted within 30 days after contract termination (DPA Section 8.2) |
(g) Dreamhack (https://dreamhack.io)
Personal data collected by Dreamhack, our security education platform.
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Registration [Required] | Email, username (nickname), profile information | User identification and service delivery | Deleted immediately upon account termination |
| Additional Profile [Optional] | Date of birth, phone number, nationality, gender, career history, education, awards | Personalized service delivery | Deleted immediately upon account termination |
| Profile Social Links [Optional] | GitHub URL, LinkedIn URL, Facebook URL, X (Twitter) URL | Displaying external social links on user profile page | Deleted immediately upon account termination |
| Social Login — Google [Optional] | Email, name, profile photo | Simplified authentication via Google account | Deleted immediately upon account termination |
| Identity Verification [Required] | Name, date of birth, gender, nationality, phone number, CI (Connecting Information), DI (Duplication Information) — received from the identity verification agency (NICE Information Service) | Identity verification and duplicate registration check | Deleted immediately after verification |
| Payment [Required] | Product name, payment amount, nationality, date of birth, payment method details | Paid service delivery and contract performance | 5 years (E-Commerce Act) |
| Prize Delivery [Required] | Name, email, phone number, address | Delivering CTF prizes and event rewards | 3 years after delivery (E-Commerce Act dispute records) |
| Marketing [Optional] | Email, phone number | CTF event announcements, promotional information | Until consent is withdrawn |
| Service Usage [Automatic] | Course records, CTF participation records | Personalized content recommendations and service improvement | Deleted immediately upon account termination |
| Enterprise Inquiry [Required] | Contact person information (name, email, phone number, role, title), company name | Enterprise service adoption inquiry response and post-sales support | 1 year after inquiry resolution |
Profile Social Links vs. Social Login:
- Profile Social Links — You manually enter URLs for external social accounts to display on your profile page. This is unrelated to login.
- Social Login (Google) — Authentication via Google OAuth. Your email, name, and profile photo are collected automatically only when you choose Google login.
(h) ChainLight (https://chainlight.io)
Personal data collected when you inquire about ChainLight, our Web3 security service. The data collected varies by inquiry type (Smart Contract Audit, DART, Relic Protocol, Other).
Common Data (All Inquiry Types)
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Common [Required] | Email, preferred contact method (Email/Telegram/Phone call), how you heard about us | Inquiry handling and communication | 1 year after inquiry resolution |
Smart Contract Audit Inquiry
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Smart Contract Audit [Required] | Project name, X/Twitter URL, GitHub URL, desired audit completion date, budget | Security audit consultation and project evaluation | 1 year after inquiry resolution |
| Smart Contract Audit [Optional] | Additional message | Consultation reference | 1 year after inquiry resolution |
DART (Digital Asset Risk Tracker) Inquiry
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| DART [Required] | Project name, X/Twitter URL, types of risk concerns | DART adoption consultation | 1 year after inquiry resolution |
| DART [Optional] | Additional message | Consultation reference | 1 year after inquiry resolution |
Relic Protocol Inquiry
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Relic Protocol [Required] | X/Twitter URL, service category | Relic Protocol consultation | 1 year after inquiry resolution |
| Relic Protocol [Optional] | Additional message | Consultation reference | 1 year after inquiry resolution |
Other Inquiry
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Other [Required] | X/Twitter URL, service category | General consultation | 1 year after inquiry resolution |
| Other [Optional] | Additional message | Consultation reference | 1 year after inquiry resolution |
These items are collected via inquiry forms hosted on Paperform (Australian company; servers in the United States). Fields marked
*are [Required]; fields marked(optional)are [Optional].Retention: B2B sales inquiry data is retained for up to 1 year after inquiry resolution. We delete it without delay once the retention period expires.
2.2. Job Applicants
Personal data of people who apply through our careers site (https://careers.theori.io). Application intake and hiring management are handled by Doodlin Inc. (GreetingHR) on our behalf — see Section 1 of our Service Providers list.
| Category | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Job Application [Required] | Name, email, contact details, résumé | Evaluating applicants and running the hiring process | Until the hire is confirmed or 90 days from receipt, whichever is earlier |
Employee data. We process personnel and payroll data of our employees to perform their employment contracts and to meet statutory obligations. For details of the categories processed and how long we keep them, contact privacy@theori.io.
2.3. Office Video Surveillance (CCTV)
We operate video surveillance at our Seoul office for facility security and crime prevention. It covers employees and authorized visitors who enter that office in person, and does not apply to users of our online services. Footage is retained for 15 days from the recording date.
- Where: inside the Seoul office (work areas and the corridor serving them). We do not install cameras in restrooms, changing rooms, break rooms, or anywhere else that would significantly infringe on personal privacy.
- Hours: 24 hours, continuous.
- Storage and disposal: a designated controlled area within the server room; deleted automatically when the retention period expires.
- Access: limited to the minimum personnel whose roles require it, with approval from the Chief Privacy Officer.
- Notice: signs are posted in every area under surveillance.
- No monitoring of staff: we do not use it for attendance tracking, work monitoring, or performance evaluation.
- Requesting footage of yourself: contact privacy@theori.io. We respond within 10 days, and will give reasons in writing where a statutory ground for restriction applies.
2.4. Data Automatically Generated and Collected During Service Use
When you use our online services, we automatically collect the following data:
| Data Collected | Description |
|---|---|
| Service usage records | Visit timestamps, page views, clicks, feature usage logs |
| Access logs | Connection timestamps, IP addresses, access environment |
| Device information | OS, browser type and version, screen resolution, language settings |
| Cookies | Cookies for session management, personalization, and analytics (see Section 11) |
2.5. How We Collect Personal Data
We collect personal data through the following methods:
- Direct input by users during website registration and service use
- Submission of inquiry forms (Typeform, Paperform, HubSpot)
- Profile information received through social login (Google) integration
- Data received from customer systems via API integration (B2B services)
- Automatic generation and collection during service use (access logs, cookies, device information)
- CCTV recording
3. How We Use Your Data
We use personal data only for the purposes listed below.
| Purpose of Processing | Legal Basis | GDPR |
|---|---|---|
| Service delivery and contract performance | Performance of a contract | Art. 6(1)(b) |
| Account management and identity verification | Performance of a contract | Art. 6(1)(b) |
| Recruitment | Pre-contractual steps taken at the applicant's request | Art. 6(1)(b) |
| Customer support and complaint resolution | Legitimate interests | Art. 6(1)(f) |
| Service improvement and analytics | Legitimate interests | Art. 6(1)(f) |
| Safety and security | Legitimate interests | Art. 6(1)(f) |
| CCTV video recording (Seoul office only) | Legitimate interests — facility safety and crime prevention | Art. 6(1)(f) |
| Marketing and promotions | Consent | Art. 6(1)(a) |
| Advertising cookies and behavioral data | Consent | Art. 6(1)(a) |
| Legal compliance | Compliance with a legal obligation | Art. 6(1)(c) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal, and withdrawing it does not restrict your access to the core service. Where we rely on legitimate interests, you may object to the processing (GDPR Art. 21).
For jurisdiction-specific legal bases, see the relevant policy:
- Korea: PIPA (개인정보보호법) Article 15 and related provisions
- EEA/UK: GDPR Policy — based on GDPR Art. 6(1)
- B2B Customers: DPA[1]
- Service Delivery and Contract Performance — Account registration, identity verification and authentication, service feature delivery, billing and payment for paid services, content delivery, contract-related notices
- Account Management — User identification, verification of registration intent, age verification, prevention of fraudulent or unauthorized use, record-keeping for complaints and disputes
- Customer Support — Responding to inquiries, technical support, delivering notices, handling complaints and grievances
- Marketing and Promotions — Sending event, advertising, and newsletter information (only with separate consent)
- Service Improvement and Analytics — Developing new services, improving existing services, analyzing usage statistics, personalized content recommendations
- Safety and Security — Detecting security threats, blocking unauthorized access, ensuring system stability
- Facility Security (CCTV) — Office facility security, crime prevention, fire prevention, evidence preservation
- Recruitment — Processing applications, managing applicants, and communications
- Legal Compliance — Fulfilling obligations under applicable laws and resolving disputes
3.1. Data Processing Principles for AI-Powered Services
As a security company, Theori makes the following commitments regarding data processing in our AI services:
| Principle | Details |
|---|---|
| No Training on Customer Data | We never use customer-provided source code, binaries, or analysis data to train any AI/ML model. |
| Zero Data Retention | When using external AI services for inference, the provider's ZDR policy applies so data is not retained on provider servers (see table below). |
| Customer Control | B2B customers can choose whether to enable AI features as part of their contract. |
| Auditability | You can verify our AI data processing practices at our Trust Center. |
These principles apply to Xint Web, Xint Code, and aprism.
Terms applied to each external AI provider
| AI Service Provider | ZDR | Excluded from Model Training |
|---|---|---|
| Anthropic PBC (Claude) | Yes | Yes |
| OpenAI, Inc. (GPT) | Yes | Yes |
| AWS Bedrock (Amazon) | Yes | Yes |
| Google LLC (Gemini) | Yes | Yes |
The specific models used may vary by service and feature, always within the providers listed above.
Intended Use and Data Processed
| Item | Details |
|---|---|
| Applicable services | Xint Web (application security testing) · Xint Code (source code security analysis) · aprism (LLM traffic guard and monitoring) |
| Intended use | Detecting and analyzing security vulnerabilities and explaining the results. We do not use these services to evaluate or profile individuals, or to make determinations affecting a data subject's rights or obligations. |
| Inputs (prompts) | Source code, binaries, and configuration files submitted by the customer for analysis; for aprism, the LLM request and response traffic the customer routes to us. We do not separately collect or extract personal data beyond what the analysis requires. |
| Generated outputs | Vulnerability findings and reports. These are stored within the customer's tenant and deleted per DPA Section 8.2. |
| Retention of inputs and outputs | Inputs and outputs sent to external AI services are not retained on provider servers under their ZDR policies. Retention of our own copies follows Section 8.1. |
| Separate retention for AI training | None. We retain no data for training purposes. |
| Legal basis | PIPA Article 15(1)(4) (performance of a contract); GDPR Art. 6(1)(b). For customer data we act as a processor on the customer's (controller's) instructions — see the DPA. |
Opt-Out and the Scope of Your Control
- We do not use customer-provided data to train any AI/ML model, whether our own or a third party's. There is therefore no separate training opt-out to exercise: your data is excluded from training whether or not you object.
- We secure the same no-training condition contractually from our external AI providers (see the provider table above).
- Because we do not train on this data, the situation where a specific person's data cannot be separated or deleted from an already-trained model does not arise.
- B2B customers may choose contractually whether to enable AI features. Where they are disabled, no data is sent to external AI services.
Reporting Problematic Output
If AI analysis output improperly includes personal data or is otherwise erroneous, report it to privacy@theori.io or through the in-product support channel. We will review it without undue delay and correct or delete the output.
Automated Decision-Making. We perform AI-based automated analysis in Xint Code, Xint Web, and aprism, but we do not make solely automated decisions that produce legal effects or similarly significant effects on data subjects; a human is involved in final determinations (GDPR Art. 22; PIPA §37-2). You may nonetheless request an explanation of the criteria and procedures behind such automated processing and request human review (see Section 9.1).
4. Disclosure to Third Parties
We do not disclose your personal data to third parties without your consent, except in the following circumstances:
- You have given prior consent
- Disclosure is required by law or by a lawful request from an investigative authority following legally prescribed procedures
- Disclosure is necessary for statistical or academic research purposes, and the data is provided in a form that does not identify any specific individual
Apart from the advertising and analytics disclosures described in Section 9.5(a) and Section 11, we do not currently provide personal data to third parties for their own purposes.
Business Transitions: If Theori undergoes a merger, acquisition, or asset sale, your personal data may be transferred as part of that transaction. In such cases, we will notify you in advance of the transfer, including the categories of data transferred, the identity of the recipient, and the purpose of the transfer. We will obtain your consent where required by law.
5. Additional Use and Disclosure
We may use or disclose personal data for purposes reasonably related to the original collection purpose. When doing so, we consider the following factors:
- Relevance to the original purpose of collection
- Whether additional use or disclosure is foreseeable given the context and practices under which the data was collected
- Whether the additional use or disclosure unfairly infringes on the data subject's interests
- Whether appropriate safeguards such as pseudonymization or encryption have been applied
6. Pseudonymized Data
We do not currently process pseudonymized data. If this changes, we will update this policy in accordance with applicable law.
7. Service Providers and International Data Transfers
We engage external service providers to process personal data where necessary for service delivery. Our service provider agreements include all safeguards required by applicable law.
Where your data is processed. Theori operates from the Republic of Korea (Seoul) and the United States (Austin), and serves users worldwide. Depending on the service you use, your personal data may be processed in either country and by the providers in our Service Providers and International Transfers list, in the locations shown. Section 7.2 sets out the safeguards that apply to each destination.
7.1. Processing Activities We Entrust
We entrust the following processing activities to external providers. The names of the providers performing each activity, together with the transfer details (recipient, country, data categories, purpose, and retention period), are set out in our Service Providers and International Transfers list, which forms part of this policy and has the same effect as the policy itself.
| Processing Activity | Applicable Services | Provider Location |
|---|---|---|
| Cloud infrastructure and data storage | All services | Republic of Korea, United States |
| Inter-entity transfers within the group | All services | Republic of Korea, United States |
| Authentication (social login, enterprise SSO, mobile identity verification) | Dreamhack, Xint Web | Republic of Korea, United States |
| Email delivery and messaging | All services | United States |
| Customer management (CRM, sales, communications) | All services | United States |
| Cookie consent management | All services | Denmark |
| Form hosting | Xint, aprism, ChainLight | Spain, Australia (servers: United States) |
| Payment processing | Dreamhack | Republic of Korea, United States |
| AI-powered security analysis | Xint Web, Xint Code, aprism | Republic of Korea, United States |
| Web and product analytics | All services | United States |
| Error tracking and infrastructure monitoring | All services | United States |
| Advertising and marketing | Theori website and blog, Xint Landing, Dreamhack | United States |
| Security and bot prevention | All services | United States |
| Business tools and HR | Company-wide | United States |
| Web font delivery (CDN) | All services | United States, Europe, and other edge locations |
| Customer support (live chat) | Xint Web | Republic of Korea |
| Corporate blog platform | Theori blog | Republic of Korea |
| Recruitment intake and applicant tracking | Theori careers | Republic of Korea |
| Delivery of CTF prizes and event rewards | Dreamhack | Republic of Korea |
Why the list is separate. Service provider arrangements change as our services evolve. Keeping the detailed list on its own page lets us publish changes without amending the body of this policy. Every item required by Articles 26(2) and 28-8(2) of the Korean Personal Information Protection Act, GDPR Art. 13(1)(e), and the CCPA appears in the linked list, which is published continuously on the same domain as this policy.
7.2. Transfer Safeguards
Personal data is transmitted over encrypted network channels and encrypted at rest. In addition, the following safeguards apply by destination:
| Where data is processed | Safeguard |
|---|---|
| Republic of Korea | European Commission adequacy decision for the Republic of Korea (Implementing Decision (EU) 2022/254) for personal data originating in the EEA |
| United States | For our US-based service providers, EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with encryption in transit and at rest and access controls. Some providers additionally participate in the EU-US Data Privacy Framework |
- Requesting a copy. You may request a copy of the Standard Contractual Clauses or other transfer safeguards we rely on by emailing privacy@theori.io.
- If you are in the EEA or the UK, see GDPR Policy Section 9 for the full international transfer disclosure, and GDPR Policy Section 4.2 for the contact details of our EU and UK representatives.
- If you are a California resident, see Section 9.5(a) for the categories of personal information disclosed and the categories of third parties they are disclosed to.
When we change or add a service provider, we update the Service Providers and International Transfers list. Section 15 explains how we announce those updates.
8. Retention and Deletion
We delete personal data without delay once the purpose of collection and use has been fulfilled.
8.1. Retention Periods by Data Type
We apply consistent retention periods for each data type across all services. Each period follows the strictest standard among applicable laws.
| Data Type | Applicable Service | Retention Period | Legal Basis |
|---|---|---|---|
| Account information (email, nickname, profile) | Xint Web, Xint Code, aprism, Dreamhack | Deleted without delay upon account termination | PIPA §21(1); GDPR Art. 17(1) |
| B2B sales inquiries (demo requests, inquiry forms) | Xint, aprism, ChainLight, Theori (Corporate) | 1 year after the inquiry is resolved | GDPR Art. 5(1)(e) storage limitation; ICO Direct Marketing Guidance (24-month recommendation) |
| Marketing consent information | All Services | Until consent is withdrawn; we reconfirm opt-in status every 2 years | Network Act (정보통신망법) Section 50(8), Enforcement Decree Section 62-3; CNIL: 3 years from last contact |
| B2B customer data (source code, binaries, scan results) | Xint Web, Xint Code, aprism | Per DPA contract terms | DPA contract terms; GDPR Art. 28(3)(g) |
| Audit logs (access and activity records) | Xint Web, Xint Code, aprism | Per customer contract terms | Customer contract terms |
| Job application data | Theori careers site | Until the hire is confirmed or 90 days from receipt, whichever is earlier | Minimum retention after the hiring process ends |
| Office CCTV footage | Theori Office (Seoul) | 15 days from recording date | Theori's own standard |
| Payment and contract records | Dreamhack | 5 years | E-Commerce Act (전자상거래법) Enforcement Decree Section 6 |
| Consumer complaint and dispute records | Dreamhack | 3 years | E-Commerce Act Enforcement Decree Section 6 |
| Web analytics data (GA4) | All Services | 12 months | Tool retention setting · GDPR Policy Section 5.7 |
| Product analytics data (PostHog) | All Services | 12 months | Tool retention setting · GDPR Policy Section 5.7 |
| Error tracking data (Sentry) | All Services | 90 days | Tool retention setting · GDPR Policy Section 5.7 |
8.2. Mandatory Retention Under Applicable Law
When the law requires retention after the original purpose has been fulfilled, we store the data in segregated storage and protect it securely for the required period.
(a) Republic of Korea
| Retained Data | Applicable Services | Applicable Law | Retention Period |
|---|---|---|---|
| Records related to contracts or withdrawal of offers | Dreamhack | E-Commerce Act (전자상거래법) Enforcement Decree Section 6 | 5 years |
| Records related to payment and supply of goods | Dreamhack | E-Commerce Act Enforcement Decree Section 6 | 5 years |
| Records related to consumer complaints or dispute resolution | Dreamhack | E-Commerce Act Enforcement Decree Section 6 | 3 years |
| Records related to labeling and advertising | Dreamhack | E-Commerce Act Enforcement Decree Section 6 | 6 months |
| Communications confirmation data (website access logs) | All Services | Protection of Communications Secrets Act (통신비밀보호법) Section 15-2 and Enforcement Decree Section 41(2) | 3 months |
| Tax-related records | Company-wide | Framework Act on National Taxes (국세기본법) Section 85-3 | 5 years |
Retention duties under the Act on Consumer Protection in Electronic Commerce apply to mail-order sellers, and therefore apply only to Dreamhack, where paid transactions take place.
(b) EU/EEA (GDPR)
| Principle | Details | Legal Basis |
|---|---|---|
| Right to Erasure | We delete data within one month of request. Exceptions apply for legal obligations, public interest, and legal defense purposes. | GDPR Art. 17, Art. 17(3) |
| Storage Limitation | We retain data only for the minimum period necessary to fulfill the processing purpose, then delete or anonymize it. | GDPR Art. 5(1)(e) |
| Inactive Accounts | We recommend deletion or anonymization after 2 years of inactivity. | CNIL Inactive Account Guidance |
For detailed retention principles applicable to EEA/UK users, see the GDPR Policy.
(c) United States (CCPA/CPRA)
| Principle | Details | Legal Basis |
|---|---|---|
| Retention Period Disclosure | We disclose the planned retention period or the criteria for determining it for each category of personal information. | Cal. Civ. Code §1798.100(a)(3) |
| Proportionality | We do not retain data beyond the period reasonably necessary for the disclosed purposes. | CPRA Data Minimization Principle |
8.3. Deletion Procedures and Methods
- Deletion Procedure: When the retention period expires or the processing purpose is fulfilled, we delete personal data without delay, subject to the Chief Privacy Officer's approval. Where the law requires continued retention, we transfer the data to segregated storage.
- Cloud Environment (SaaS): We delete database records, and backup copies are automatically purged after the backup retention cycle (up to 30 days). In AWS environments, we use cryptographic erasure or storage lifecycle policies to render data unrecoverable.
- Paper Documents: We shred or incinerate paper records.
- Deletion Records: We record the date, scope, method, and responsible person for each deletion.
9. Your Rights and How to Exercise Them
9.1. Your Rights
As a data subject, you may exercise the following rights regarding your personal data at any time:
- Right to Access — You may request access to the personal data we hold about you.
- Right to Correction and Deletion — You may request correction or deletion of your personal data if it is inaccurate or if you want it deleted. However, we cannot delete data that is required to be retained by other applicable laws.
- Right to Restrict Processing — You may request that we stop processing your personal data.
- Right to Explanation and Human Review of Automated Processing — For the automated processing in our AI-powered services (Xint Code, Xint Web, aprism), you may request an explanation of the criteria and procedures used and request human review. (We do not make fully automated decisions that produce significant effects on data subjects.)
- Right to Data Portability — You may request that your personal data be transmitted to yourself or another controller in a structured, commonly used, and machine-readable format, to the extent technically feasible (GDPR Art. 20). We provide this to all users as a matter of policy.
How quickly we respond. If you are in the EEA or the UK, we respond within one month (GDPR Art. 12(3)). If you are a California resident, we respond within 45 days, extendable once by a further 45 days (Section 9.5(a)). Where the Korean Personal Information Protection Act applies, we provide access within 10 days. Where more than one applies, we use the shortest.
9.2. How to Exercise Your Rights
Our Information Security Team processes requests to access, correct, delete, or restrict processing of personal data.
- Email: privacy@theori.io
- Mail: 9F, 14 Teheran-ro 4-gil, Gangnam-gu, Seoul 06232, Republic of Korea — Attn: Theori Information Security Team
- Online: You can process certain requests directly through each service's account settings (account termination, profile updates, etc.)
You may also exercise your rights through a legal representative or authorized agent. In such cases, a power of attorney must be submitted in accordance with applicable law.
9.3. Children Under 14
We do not collect personal data from children under 14 years of age, and we restrict registration by children under 14. If we discover that we have collected personal data from a child under 14, we will delete it without delay.
- Exceptionally, where processing a child's personal data under 14 is unavoidable, we obtain parental consent.
- Consent Method: We verify consent through parental email verification or mobile identity verification.
- Verification: We confirm the parent or legal guardian's name, contact information, and relationship to the child.
- Personal data collected from children without parental consent will be deleted without delay.
9.4. Limitations on Rights
We respond to rights requests without delay. However, we may limit the exercise of certain rights in the following circumstances:
- Where specifically provided by law or where compliance with a legal obligation makes limitation unavoidable
- Where there is a risk of harm to the life or body of another person, or of unfair infringement on the property or interests of another person
9.5. Additional Disclosures for Residents of Specific Jurisdictions
(a) California Residents (CCPA/CPRA)
- We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age (11 CCR §7011(e)(1)(G); Cal. Civ. Code §1798.120(c)).
- We do not sell your personal information for monetary consideration. We do, however, use advertising cookies and tracking technologies (Google Ads and AdSense, LinkedIn Insight, embedded video), which may constitute sharing for cross-context behavioral advertising under Cal. Civ. Code §1798.140(ah). Those cookies are activated only with your prior consent, and you may withdraw consent or block them through your browser settings at any time (see Section 11.3 and our Cookie Policy).
- We do not deny service, charge different prices, or provide different quality based on your exercise of rights under this policy.
- We use Sensitive Personal Information only to the extent reasonably necessary for service delivery.
- We treat a Global Privacy Control (GPC) signal as an opt-out of sharing: when we receive one, we do not activate advertising cookies in that browser.
California Consumer Rights (CCPA/CPRA Section 1798.100–Section 1798.125)
California residents may exercise the following rights:
- Right to Know (Section 1798.100/Section 1798.110): The right to request the categories, sources, purposes, and third-party sharing of personal information we have collected about you during the preceding 12 months.
- Right to Delete (Section 1798.105): The right to request deletion of personal information we have collected.
- Right to Correct (Section 1798.106): The right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing (Section 1798.120): The right to opt out of the sale of personal information or its sharing for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information (Section 1798.121): The right to limit the use and disclosure of sensitive personal information.
- Right to Non-Discrimination (Section 1798.125): The right not to be denied service or charged differently for exercising your rights.
To exercise your rights, contact privacy@theori.io. We will respond within 45 days of receiving your request (extendable by an additional 45 days).
You may also designate an authorized agent to submit a request on your behalf. We may require verification of your identity and confirmation that you authorized the agent. See Section 9.2 for general details on exercising rights through a representative.
We do not offer financial incentives for the collection, sale, retention, or deletion of personal information.
CCPA Personal Information Categories — Collection and Sharing Disclosure
The table below summarizes our collection and sharing practices by personal information category as defined in Cal. Civ. Code §1798.140. We do not sell personal information for monetary consideration. Disclosures made through advertising cookies may constitute sharing under Section 1798.140(ah) and occur only with your prior consent.
| CCPA Category | Collected | Examples | Collection Source | Disclosed for Business Purpose | Purpose of Use | Sold or Shared |
|---|---|---|---|---|---|---|
| A. Identifiers | Yes | Email, name, username, IP address, account ID | Direct from user; social login; automatic collection | Yes | Account creation and authentication, service delivery, customer support | Shared (advertising cookies, with prior consent) |
| B. Customer Records (Section 1798.80(e)) | Yes | Name, phone number, company name, job title, payment method | Direct from user; payment service providers | Yes | Contract performance, payment processing | No |
| C. Protected Classification Characteristics | Partial | Date of birth, gender, nationality (Dreamhack optional fields) | Direct from user | No | Identity verification, age verification | No |
| D. Commercial Information | Yes | Product name, payment amount, subscription history (Dreamhack) | Direct from user; payment systems | Yes | Paid service delivery, refund processing | No |
| E. Biometric Information | No | — | — | — | — | No |
| F. Internet/Network Activity | Yes | Visit timestamps, page views, clicks, access logs, browser/OS information | Automatic collection (GA4, PostHog, Sentry, etc.) | Yes | Service improvement and analytics, error tracking, security | Shared (advertising cookies, with prior consent) |
| G. Geolocation Data | Partial | Approximate location based on IP address (no precise location collected) | Automatic collection | No | Security and unauthorized access detection | No |
| H. Sensory Data | No | — | — | — | — | No |
| I. Professional/Employment Information | Yes | Company name, job title, job role (business inquiries) | Direct from user | No | Sales consultation, demo request handling | No |
| J. Education Information | Partial | Education history (Dreamhack optional field) | Direct from user | No | User profile display | No |
| K. Inferences | No | — | — | — | We do not generate inferences for the purpose of creating consumer profiles | No |
| L. Sensitive Personal Information | Partial | Account login credentials, CI/DI (deleted immediately after verification) | Direct from user; CI/DI from the identity verification agency | No | Account authentication, identity verification | No |
- "Disclosed for a Business Purpose" refers to engagement of service providers necessary for service delivery. See our Service Providers and International Transfers list.
- Retention periods by category (11 CCR Section 7012(e)(4)) — A, B, I, J, L: until account deletion or completion of the inquiry (inquiries: 1 year after completion). C, D: the statutory retention period (Section 8.2). F, G: 12 months per analytics tool; 90 days for error tracking (Section 8.1). E, H, K: not collected. Where a period cannot be stated in advance, we use the criterion of the minimum time necessary to achieve the purpose and delete the data without undue delay once it has elapsed.
- We use Sensitive Personal Information only to the extent reasonably necessary for service delivery, in accordance with Cal. Civ. Code §1798.121.
(b) Residents of Japan (個人情報保護法 / APPI)
The following provisions apply when we process retained personal data (保有個人データ) subject to the Act on the Protection of Personal Information ("APPI," 個人情報保護法) of Japan.
Data Subject Rights (APPI Section 33–Section 35)
- Right to Access (Section 33): You may request access to your retained personal data. We will provide it in electronic format as a general rule.
- Right to Correction, Addition, or Deletion (Section 34): You may request correction, addition, or deletion of inaccurate retained personal data.
- Right to Suspend Use, Erase, or Cease Third-Party Provision (Section 35): You may request suspension of use where data was unlawfully collected or used, or where continued use is no longer necessary.
International Data Transfers (APPI Section 28)
We may transfer personal data of Japanese residents internationally. When doing so, we take the following measures in accordance with APPI Section 28:
- Transfer destinations: Republic of Korea (contractual safeguards including DPA applied), United States (contractual safeguards including DPA applied)
- We ensure an adequate level of protection through contractual safeguards (DPA, SCCs) and by confirming that the transfer destination country maintains a data protection framework comparable to APPI.
- For detailed service provider and transfer information, see our Service Providers and International Transfers list.
Pseudonymously Processed Information / Anonymously Processed Information
We do not currently process pseudonymously processed information (仮名加工情報) or anonymously processed information (匿名加工情報).
Breach Reporting (APPI Section 26)
In the event of a personal data breach, we will promptly report to the Personal Information Protection Commission (PPC) of Japan and notify affected data subjects. For detailed procedures, see Section 12.4(d).
(c) Residents of Singapore (Personal Data Protection Act / PDPA)
The following provisions apply when we process personal data subject to the Personal Data Protection Act ("PDPA") of Singapore.
Consent Framework (PDPA Section 13–Section 17)
We obtain consent before collecting, using, or disclosing personal data. You may withdraw your consent at any time (Section 16), and we will stop future processing upon withdrawal. However, if processing is essential for service delivery, withdrawing consent may limit your ability to use the service.
Data Subject Rights
- Right of Access (Section 21): You may request access to your personal data. We will respond within 30 days. A reasonable fee may apply.
- Right of Correction (Section 22): You may request correction of inaccurate or incomplete personal data.
- Data Portability (Section 26H): You may request your data in a commonly used format (JSON, CSV).
Data Breach Notification (PDPA Section 26A–Section 26E)
In the event of a Notifiable Data Breach, we will:
- Notify the Personal Data Protection Commission (PDPC) of Singapore within 3 calendar days of becoming aware of the breach
- Notify affected data subjects without delay where significant harm is likely
Do Not Call (DNC) Registry (PDPA Part 9, Section 39–Section 45)
Before sending marketing messages by phone, text, or fax, we check the Singapore DNC Registry. We do not send marketing messages to registered numbers.
International Data Transfers (PDPA Section 26)
In compliance with the Transfer Limitation Obligation, we verify that the recipient country provides a level of protection comparable to the PDPA before transferring personal data of Singapore residents internationally. For transfer destinations and safeguards, see our Service Providers and International Transfers list.
10. Location Data
We do not currently collect or use precise location data (for example, GPS). For security and access analysis, an approximate location (country or city level) may be inferred from your IP address; see Section 11 and Section 9.5(a). If this changes, we will obtain your prior consent and update this policy accordingly.
11. Behavioral Data and Cookies
We collect and use behavioral data (online activity information) to improve our services and deliver personalized experiences.
11.1. Behavioral Data We Collect
| Collection Tool | Data Collected | Purpose | Retention Period |
|---|---|---|---|
| Google Analytics (GA4) | Page views, clicks, sessions, IP address, device/browser information | Web usage statistical analysis | 12 months |
| PostHog | Page views, clicks, sessions, feature usage patterns | Product analytics and UX improvement | 12 months |
| Sentry | IP address, device information, stack traces upon error | Error tracking | 90 days |
| Datadog | Service logs, IP address, page views and session data | Infrastructure and real-user (RUM) monitoring | 12 months |
| Microsoft Clarity | Page views, on-screen interactions such as clicks and scrolling | Usage pattern analysis and UX improvement | 12 months |
| RudderStack | Page views, clicks, events | Event collection and data integration (careers site) | 12 months |
| Inblog | Page views, referral sources, sessions | Blog usage statistics | 12 months |
| Google reCAPTCHA | User behavior data | Bot prevention | Until service agreement terminates |
| HubSpot | Page views, clicks, cookies | CRM and product analytics | 12 months |
| Google Ads and AdSense | Cookies, behavioral data | Targeted advertising, conversion tracking, and ad delivery | Until the processing agreement ends |
| LinkedIn Insight Tag | Cookies, behavioral data | Targeted advertising and lead tracking | Until the processing agreement ends |
| YouTube (embedded video) | Viewing history, cookies | Embedded video playback and viewing-based recommendations or advertising | Until the processing agreement ends |
The advertising tools above (Google Ads and AdSense, LinkedIn Insight Tag, embedded YouTube) are activated only where you have given prior consent. See Section 11.3 to opt out.
11.2. Use of Cookies
We use cookies to operate our services and improve your experience. A cookie is a small text file that a server sends to your browser and stores on your device.
Cookie Categories
| Category | Description |
|---|---|
| Essential Cookies | Required for core service functions such as login, session management, and security |
| Functional Cookies | Store user preferences such as language, theme, and layout |
| Analytics Cookies | Analyze service usage statistics, page views, and click patterns |
| Marketing Cookies | Enable targeted advertising, conversion tracking, and retargeting |
For detailed information about cookie categories, third-party service providers, and consent management, see our Cookie Policy. On websites where our consent management platform (Cookiebot) is deployed, individual cookie names, expiration periods, and descriptions are available in the "Show details" section of the consent banner.
11.3. Your Cookie Controls
You can refuse or delete cookies at any time. However, blocking essential cookies may limit your ability to use certain features, such as login.
Browser Cookie Settings:
| Browser | Cookie Settings Path |
|---|---|
| Chrome | Settings → Privacy and Security → Third-party Cookies |
| Safari | Preferences → Privacy → Manage Website Data |
| Firefox | Settings → Privacy & Security → Cookies and Site Data |
| Edge | Settings → Cookies and Site Permissions → Manage and Delete Cookies and Site Data |
Advertising Opt-Out:
| Tool | Opt-Out Method |
|---|---|
| Google Analytics | Google Analytics Opt-out Browser Add-on |
| Google Ads | Google Ad Settings |
| LinkedIn Ad Settings | |
| General Opt-Out | Digital Advertising Alliance (DAA) |
Mobile Advertising Identifier:
- Android: Settings → Google → Ads → Delete Advertising ID
- iOS: Settings → Privacy & Security → Tracking → Toggle off "Allow Apps to Request to Track"
12. How Theori Protects Your Data
We implement the following measures to protect your personal data.
12.1. Administrative Safeguards
- Internal Management Plan: We maintain and implement an internal management plan for the secure processing of personal data.
- Dedicated Team: Our Information Security Team is responsible for personal data protection.
- Regular Training: We provide regular data protection training to all employees who handle personal data.
- Quarterly Audits: We conduct quarterly internal audits to review personal data processing practices.
- Least-Privilege Access: We restrict access to personal data to the minimum number of personnel necessary.
- Third-Party Certifications and Attestations: We hold and maintain the following certifications from independent third-party auditors. A SOC 2 Type II examination is currently in progress; SOC 2 results in an attestation report rather than a certification. You can view our current security certifications and control compliance status at our Trust Center:
- ISO/IEC 27001:2022 (Information Security Management System)
- ISO/IEC 27017:2015 (Cloud Service Information Security)
- SOC 2 Type II (Security, Availability, Confidentiality) — examination in progress (expected to complete in August 2026)
12.2. Technical Safeguards
- Encryption: We store passwords using one-way hashing and encrypt sensitive data both in transit and at rest.
- Secure Communications: We apply HTTPS (SSL/TLS) encrypted communications across all services.
- Access Controls: We assign personal data access privileges by role and retain and review personal information processing system access logs for at least 1 year under Article 8 of the Korean Standards for Securing Personal Information. Access logs for Dreamhack, which processes the personal data of 50,000 or more data subjects, are retained for at least 2 years. These are distinct from the communications confirmation data in Section 8.2(a) (website access logs, 3 months) and the audit logs in Section 8.1 (per customer agreement).
- Security Systems: We operate security systems to defend against external intrusions and conduct regular vulnerability assessments.
12.3. Physical Safeguards
- Access Control: We control physical access to server rooms and data storage areas containing personal data.
- Access Records: We periodically review access records for physical storage locations.
12.4. Data Breach Response
In the event of a personal data breach, we respond promptly in accordance with applicable law.
(a) Republic of Korea
We treat not only loss, theft, and leakage of personal data but also its forgery, alteration, or damage (together, a "breach") as triggering notification and reporting.
- We notify affected data subjects within 72 hours of becoming aware of a breach, including: (i) the categories of data affected, (ii) the timing and circumstances of the breach, (iii) specific steps you can take to minimize harm (including account protection measures such as changing your password), (iv) our response measures and remedies available, (v) our contact information (privacy@theori.io, +82-70-8864-1337), and (vi) your legal rights and how to exercise them, including damages under Article 39, statutory damages under Article 39-2, and dispute mediation under Article 43 of the Korean Personal Information Protection Act.
- We report breaches affecting 1,000 or more data subjects immediately to the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA).
- Where the breach involves sensitive information or unique identifiers, or results from unauthorized external access (e.g., hacking), we report immediately regardless of the number of data subjects affected.
- Notification at the "possible breach" stage: Even before a breach is confirmed, where we detect unauthorized access to our personal information processing systems or otherwise conclude a breach may have occurred, we notify the data subjects who may be affected of what they can do to limit harm. This follows Article 34(2) of the amended Korean Personal Information Protection Act (Act No. 21445), which takes effect on September 11, 2026; the detailed conditions and required contents will be set by Presidential Decree, and we will update this policy once that decree is finalized.
- Legal basis: PIPA Article 34; Enforcement Decree Articles 39 and 40. Item (vi) and the possible-breach notification derive from Act No. 21445 (effective September 11, 2026), which we apply ahead of that date.
(b) EU/EEA (GDPR)
- We notify the relevant Supervisory Authority within 72 hours of becoming aware of the breach.
- Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, we notify them without delay.
- Legal Basis: GDPR Art. 33, Art. 34
(c) United States (CCPA/CPRA and State Laws)
- For breaches involving unencrypted personal information of California residents, we notify affected individuals without unreasonable delay.
- For breaches affecting 500 or more California residents, we notify the California Attorney General.
- Legal Basis: Cal. Civ. Code §1798.82; CCPA §1798.150
(d) Japan (APPI)
- We submit a preliminary report to the Personal Information Protection Commission promptly upon becoming aware of the breach, followed by a full report within 30 days (or 60 days for breaches involving wrongful intent).
- We notify affected data subjects without delay.
- Legal Basis: APPI Section 26, Enforcement Rules Section 8
(e) Singapore (PDPA)
- For significant data breaches (likely to cause significant harm or affecting 500 or more individuals), we notify the PDPC within 3 calendar days.
- We notify affected individuals as soon as reasonably practicable.
- We assess whether a breach is notifiable within 30 days of becoming aware of it.
- Legal Basis: PDPA Section 26A, Section 26C, Section 26D
We analyze the root cause of every breach and implement preventive measures to avoid recurrence.
You can review our active security controls and real-time compliance status at our Trust Center.
13. Privacy Contacts
We designate the following officers and teams to handle data protection matters and resolve complaints.
Chief Privacy Officer
| Detail | Contact Information |
|---|---|
| Name | Kenny Kwansoon Park (박관순) |
| Title | CISO / CPO / DPO |
| privacy@theori.io | |
| Phone | +82-70-8864-1337 |
Data Protection Team
| Detail | Contact Information |
|---|---|
| Team | Information Security Team |
| privacy@theori.io | |
| Phone | +82-70-8864-1337 |
If you have questions, complaints, or need assistance with a data protection issue, contact us at the information above. We will respond without delay.
EU/EEA and UK Representatives (GDPR Art. 27)
If you are located in the EEA or the UK, you may also contact our appointed GDPR representative directly. See GDPR Policy §4 for the role of the representatives and the basis of their appointment.
EU Representative (Art. 27, EU GDPR)
| Field | Details |
|---|---|
| Name | Euverify Ltd (Ireland), company no. 781168 |
| EU Member State | Ireland |
| Address | Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland |
| Contact | gdpr@euverify.com |
UK Representative (Art. 27, UK GDPR)
| Field | Details |
|---|---|
| Name | Euverify Ltd (UK), company no. 16146525 |
| Location | United Kingdom (London) |
| Address | 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom |
| Contact | gdpr@euverify.com |
Submitting a DSAR or other GDPR request
You can submit a Data Subject Access Request (DSAR), an erasure request, or any other GDPR request directly through our representative's secure portal. The same page confirms our appointed representative, and requests submitted there are logged and tracked.
You can review our security certifications, data protection policies, and compliance documents at our Trust Center (https://trust.theori.io).
If you need to file a complaint or seek consultation regarding a data protection violation, you may contact the following authorities:
| Authority | Where it applies | Contact |
|---|---|---|
| California Privacy Protection Agency | California, USA | cppa.ca.gov |
| California Attorney General | California, USA | oag.ca.gov |
| Your national data protection authority | EEA | Directory at edpb.europa.eu |
| Information Commissioner's Office (ICO) | United Kingdom | ico.org.uk |
| Personal Information Dispute Mediation Committee | Republic of Korea | 1833-6972 · www.kopico.go.kr |
| Personal Information Infringement Report Center (KISA) | Republic of Korea | 118 · privacy.kisa.or.kr |
If you are in the EEA or the UK, see GDPR Policy Section 13 for how to lodge a complaint, and GDPR Policy Section 4.2 for the contact details of our EU and UK representatives.
14. Scope of This Policy
This policy applies to the following services operated by Theori Korea and Theori, Inc. (United States):
| Service | URL | Type |
|---|---|---|
| Theori Website | https://theori.io | Corporate website |
| Theori Blog | https://theori.io/blog | Corporate blog (technical and security content) |
| Theori Careers | https://careers.theori.io | Careers site |
| Theori Trust Center | https://trust.theori.io | Security certifications and compliance status |
| Xint Landing | https://xint.io | AI-powered security testing solution landing page |
| Xint Web SaaS | https://app.xint.io | AI-powered application security testing (B2B SaaS) |
| Xint Code SaaS | https://code.xint.io/login | AI-powered source code security analysis (B2B SaaS) |
| aprism Landing | https://aprism.io | LLM guard and monitoring solution landing page |
| aprism SaaS | https://app.aprism.io | LLM guard and monitoring (B2B SaaS) |
| Dreamhack | https://dreamhack.io | Security education platform (B2C) |
| ChainLight | https://chainlight.io | Web3 security audit service |
Google API Services User Data Policy Compliance
Our services (Xint Web, Dreamhack) offer social login via Google OAuth. During this process, we receive your email, name, and profile photo through the Google API. We use this data solely for authentication and account creation. Our use of, and transfer to any other app of, information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell data received through Google APIs, use it for advertising, or transfer it to third parties for purposes unrelated to service delivery.
Supplementary Documents
The following supplementary documents form part of this policy:
| Annex | Document | Scope |
|---|---|---|
| — | Service Providers and International Transfers | Part of Section 7 — per-provider processing activities and transfer details |
| A | EEA/UK GDPR Policy | Data subjects in the EEA/UK |
| B | Data Processing Addendum (DPA) | B2B SaaS customers |
| — | Cookie Policy | Website visitors (cookies and tracking technologies) |
[1] DPA (Data Processing Addendum): A contract between Theori and our B2B SaaS customers that defines the scope of personal data processing, security measures, and data retention and deletion procedures. The full text is available in Annex B: DPA.
15. Changes to This Policy
When we update this policy, we will announce the changes at least 7 days before the effective date through website or service notifications. Where such changes exceed the scope of previously obtained consent, we will obtain separate consent in accordance with Articles 15 and 17 of the Personal Information Protection Act.
- Material changes — Where the categories of personal data collected, the purposes of processing, retention periods, third-party disclosures, or the destination countries for international transfers change, we present the change in a form that lets you compare the previous and revised text.
- Minor changes — Where a service provider is changed or added while the entrusted activity stays the same, we update the Service Providers and International Transfers list and may announce those updates in batches covering periods of up to four weeks on the Previous Policies page. In that case we also record when each provider's engagement started and ended.
Language
This policy is published in Korean and English. The Korean version is the authoritative text for disclosures required by the Korean Personal Information Protection Act and for data subjects in the Republic of Korea; the English version is the authoritative text for data subjects in the EEA, the United Kingdom and other jurisdictions. We maintain both versions in substantive alignment. If you identify any discrepancy, please contact privacy@theori.io and we will correct it without delay. Neither version limits any right guaranteed to you by applicable law, and where the versions differ, the version more favorable to the data subject applies.
Supplementary Provisions
This Consolidated Privacy Policy v1.0 takes effect on the date shown at the top of this document. All previous privacy policies can be found on our consolidated Previous Versions page: