본문 바로가기Skip to main content
Back to Home

Privacy Policy

Effective date: 2026-07-01

1. Scope

(1) This Policy applies to the website, admin console, and online services (licensing, updates, remote support, and AI) operated by Anexton ("Anexton", "we").

(2) For data on a Host Server a customer installs, and for personal data of end users the customer has us process, the customer is the controller and Anexton processes it as a processor within the scope the customer sets. Requests from those data subjects are handled by the customer.

(3) The Service is not offered in the European Union, the European Economic Area, the United Kingdom, or Switzerland.

2. Purposes and Data

(1) [Processed without consent] Legal basis: PIPA Art.15(1)(iv) (performance of a contract) and Art.15(1)(vi) (legitimate interests).

(2) Account: email, password (encrypted), Google sign-in identifier (if you sign up with Google), display name (optional), organization name (at licence issuance). Display name and organization name are not collected at signup.

(3) Access security: request IP, User-Agent, sign-in time.

(4) Licensing and device management: licence ID, host ID, installation ID, software version, hardware fingerprint (hashed), device status, CPU/memory/disk usage.

(5) Billing: plan, billing cycle, payment status, tax-invoice details. Card details are processed by the payment provider and are not stored by Anexton.

(6) Support and remote support: support messages, support history, and commands, output, recordings, and consent records of remote-support sessions.

(7) Console technical support (help desk): message contents, the console screen the question was opened from, the email address of the signed-in account, and device identifiers (host ID, hardware ID, hostname, OS details). Processed on the basis of the service relationship; conversations are sent to Slack (United States) so a support engineer can reply, on a channel separate from sales inquiries. Passwords and tokens are masked before sending on a best-effort basis; because masking cannot catch every form, the input field tells you not to enter them.

(8) Enterprise onsite installation and maintenance: contact details, visit schedules, device identifiers, disk/storage work records. User file contents are viewed only with customer authorization and to the extent the work requires.

(9) AI features: questions, conversation contents, retrieved document passages. Processed on servers Anexton operates in Korea.

(10) [Processed with consent] Each item is consented to separately and can be withdrawn at any time in account settings or the cookie banner.

(11) Cross-border transfer to external AI: questions, selected conversation turns, retrieved passages, model name, and token counts. Sent to OpenAI only when the licence holder has consented to cross-border transfer and an organization administrator allows external AI.

(12) Marketing: email, organization name, consent and withdrawal records.

(13) Web analytics cookies: analytics events (Google Analytics).

(14) Website chat: message contents (including any company name or contact details you send), the page where the chat started, a session identifier, and the consent record. Processed only after you agree to the notice shown before starting. Where automatic replies use external AI (OpenAI) or the conversation is sent to Slack (United States) so a person can reply, the pre-chat notice says so.

(15) Automatically collected items and how to refuse: we automatically collect sign-in and security cookies and access records (request IP, User-Agent, sign-in time). You can decline or withdraw analytics cookies in the cookie banner and block cookies in your browser settings. Blocking strictly necessary cookies prevents you from staying signed in.

3. Host Server Data and Central Processing

(1) VMs, original files, SMB shares, and local accounts on a Host Server are stored on that Host Server.

(2) AI search index: when in-house AI search is on, text passages, vectors, and the file inventory (path, name, hash, size) are kept in the SSD storage of the Host Server. To build the index or run a search, passages and questions may be sent to AI on servers Anexton runs in Korea to compute vectors; they are used only while the vectors are computed and are not stored. An administrator can turn this off, and the Host Server then computes the vectors itself. When you delete a file, its passages, vectors, and inventory entries are also deleted from the Host Server.

(3) Licensing, device monitoring, updates, remote support, incident analysis, and external AI send the data described in this Policy to Central or to processors.

4. Google User Data (Gmail, Drive, and Calendar Integration)

(1) This section applies only when a user connects their own Google account from the host console. For mail, Anexton requests openid, email, and these Gmail permissions: https://www.googleapis.com/auth/gmail.modify (read your mail, apply the clean-up you asked for and confirmed — report spam, archive, mark read, star, apply labels — and send the messages you chose to send) and https://www.googleapis.com/auth/gmail.settings.basic (create or remove the auto-sorting rules you asked for). Every mailbox change is shown on screen before it runs and happens only after you confirm it. Sending is used only for messages you wrote and chose to send, the sender is always your own linked account, and there is no path by which the AI sends mail on its own. Anexton does not request the full-access scope https://mail.google.com/ .

(2) If you connect Google Drive on the Files screen, Anexton requests https://www.googleapis.com/auth/drive.readonly (list your files and folders, open them, and download them) and https://www.googleapis.com/auth/drive.file (only files you pick or this app created — to save an AI result to your Drive or update a file you picked, when you ask). Anexton does not change or delete files you did not pick and this app did not create, and does not request the full Drive scope https://www.googleapis.com/auth/drive .

(3) If you connect Google Calendar on the Calendar screen, Anexton requests https://www.googleapis.com/auth/calendar.events (see your events, and create, change, or delete the events you confirmed on screen) and https://www.googleapis.com/auth/calendar.calendarlist.readonly (see the list of calendars you subscribe to). Every calendar change is shown on screen before it runs and happens only after you confirm it; there is no path by which the AI changes a calendar on its own. Anexton does not request https://www.googleapis.com/auth/calendar , which would also change the settings and sharing of your calendars.

(4) What we access: the email address of the connected Google account, the subject, sender, recipients, received time, labels, and body of Gmail messages together with the message change history used to detect new mail, your label list and the auto-sorting rules you asked us to create, — if you connect Drive — the list of your Drive files and folders, the contents of the files you open, and the files you pick or this app created, and — if you connect Calendar — your calendar names and colours and the title, time, location, organiser, and guests of the events inside the range being displayed.

(5) How we use it: only for features that are visible and prominent in the product interface — listing your mailbox, opening a message, producing the summary or answer you asked for, applying the mailbox clean-up you confirmed on screen, opening or downloading Drive files, saving to Drive or updating a file you picked when you ask, drawing your calendar, and making the calendar changes you confirmed on screen. We do not use it for advertising, profiling, sale to third parties, or training AI models.

(6) How we store it: the refresh token is encrypted and stored on the customer Host Server and is not transmitted to Anexton Central Server. Message subjects, addresses, and bodies are used only for as long as the request being served needs them, are not stored separately, and are excluded from AI query audit records. Drive files you open are held on the Host Server only for as long as the download or preview needs them and are then discarded. Event titles, locations, and guests are used only while the calendar is on screen; they are not stored and never appear in logs. Audit records for clean-up actions keep only the kind of action and the number of messages — never addresses, subjects, or bodies.

(7) Whether we share it: to produce the summary or answer you asked for, the message body is transmitted to Anexton-operated AI servers in Korea, used only for as long as that request needs it, and not stored separately. Transmission to an external LLM provider (OpenAI) happens only where the licence holder has given separate consent to cross-border transfer for the organization and the sensitivity policy permits it. If that consent cannot be confirmed, no transfer occurs — the default is no consent.

(8) Human access: Anexton personnel do not read Gmail data. The only exceptions are when the user has given affirmative agreement to view specific messages, when it is necessary for security purposes, or when it is necessary to comply with applicable law.

(9) Disconnecting and deletion: disconnecting the integration in the product immediately discards the stored token and asks Google to revoke it. You can also revoke access at any time at https://myaccount.google.com/permissions.

(10) Anexton’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

5. Retention and Deletion

(1) Account data is kept until account deletion.

(2) Under Korean law we keep contract, withdrawal, and payment records for 5 years, consumer complaint and dispute records for 3 years, advertising records for 6 months, access logs for 3 months, and tax records for 5 years. Retained records are stored separately from other personal data.

(3) Host audit logs are kept for 365 days; records needed for integrity verification may be kept longer. Performance metrics are kept for 30 days and anonymized or pseudonymized telemetry for 12 months.

(4) Website chat transcripts and console help desk transcripts are automatically purged one year after the last activity. Copies sent to Slack follow the Anexton Slack workspace retention policy and are outside that automatic purge.

(5) Consent and withdrawal records are kept as long as needed for dispute handling.

(6) When the retention period ends or the purpose is achieved, data is destroyed without delay: electronic files by methods that prevent recovery, paper by shredding or incineration.

6. Disclosure to Third Parties

We provide personal data to third parties only where the law allows it, such as with the data subject's consent or under a specific legal provision.

7. Processors and International Transfers

(1) Processors: Cloudflare (CDN, security, storage), Resend (email delivery), Google (sign-in, web analytics), a GeoIP provider (country lookup), OpenAI (external AI, website chat auto-replies, remote-support AI assistance), Slack (website chat agent relay, console technical support), and payment providers (billing).

(2) Each processor's task, transferred data, country, timing and method, retention period, and how to refuse are listed at /sub-processors, which forms part of this Policy.

(3) If an external partner or hardware supplier is used for Enterprise onsite work, we disclose it in the contract or statement of work before the work begins.

(4) Transfer bases: sending an organization's questions to external AI relies on the licence holder's separate consent under PIPA Art.28-8(1)(i), which can be withdrawn in account settings. End-user data processed on a customer's appliance relies on PIPA Art.28-8(1)(iii) (processing or storage needed to perform the contract, with the Art.28-8(2) items disclosed in this Policy). Neither basis is bundled into a consent checkbox.

8. Your Rights

(1) You may request access, correction, deletion, suspension of processing, or withdrawal of consent in account settings or at privacy@anexton.com, directly or through a legal representative or authorized agent.

(2) We act within the period set by law and may refuse or limit a request where the law allows. Where the law of your country gives you further rights, contact us to exercise them.

(3) Children under 14 cannot sign up, and we do not collect their personal data without parental consent.

9. Security Measures

(1) We maintain an internal management plan, access-right management, access control, encryption of personal data (one-way hashing of passwords), retention and review of access logs, security software, and physical access restrictions.

(2) Passwords, tokens, API keys, and similar credentials are not stored or logged in plaintext.

(3) If we become aware of a personal-data breach, we notify affected data subjects and report to the authorities within 72 hours where the law requires it.

10. Privacy Officer and Remedies

(1) Controller: Anexton · Representative Woo Gyu Jang · Business registration no. 679-07-03836 · Address Creative Enterprise Support Center, Keimyung College University Industry-Academic Cooperation Foundation, 675 Dalseo-daero, Dalseo-gu, Daegu, Republic of Korea

(2) Privacy officer: Woo Gyu Jang · Email privacy@anexton.com · Phone +82-10-5959-9909

(3) Korean users may contact the Personal Information Dispute Mediation Committee, the KISA privacy infringement center, the Supreme Prosecutors' Office, or the National Police Agency.

11. Changes

(1) This Policy took effect on July 1, 2026.

(2) We post any change and its effective date on the website.