본문 바로가기Skip to main content

Legal

Sub-processors & international transfers

Last updated:

Published under PIPA Article 26 (processor disclosure) and Article 28-8 (international transfers). EEA transfers are protected through DPAs, Standard Contractual Clauses, encryption, and access controls.

  1. Cloudflare, Inc.

    privacyquestions@cloudflare.com

    Purpose
    CDN, DDoS protection, web security, Cloudflare Tunnel, R2 release/attachment storage
    Data items
    IP addresses, HTTP request metadata, security logs, release-download metadata
    Country
    United States
    Timing & method
    Continuous network transfer at access time (TLS encrypted)
    Retention
    For the duration of the processing engagement (until contract ends)
    Basis & safeguards
    Processing/storage necessary for contract performance (PIPA art. 28-8(1)3); SCC/DPA
  2. Resend, Inc. (Plus Five Five, Inc.)

    support@resend.com

    Purpose
    Transactional email delivery (verification, notifications)
    Data items
    Email addresses, message content
    Country
    United States
    Timing & method
    API transfer at email send time (TLS encrypted)
    Retention
    For the duration of the processing engagement (until contract ends)
    Basis & safeguards
    Processing necessary for contract performance (PIPA art. 28-8(1)3); SCC/DPA
  3. Google LLC — OAuth 로그인

    Optional

    https://policies.google.com/privacy

    Purpose
    Google OAuth login and signup
    Data items
    Google account identifier, email address, display name, OAuth metadata
    Country
    United States
    Timing & method
    Transferred when the user chooses Google sign-in (TLS encrypted)
    Retention
    Until account deletion or unlinking
    Basis & safeguards
    User-selected OAuth integration; Google terms and DPA
  4. Google LLC — Google Analytics(웹 분석)

    Optional

    https://policies.google.com/privacy

    Purpose
    Website usage analytics (only with cookie consent)
    Data items
    Online identifiers (cookies), anonymized IP, page-usage events
    Country
    United States
    Timing & method
    Transferred at page use only after analytics-cookie consent (TLS encrypted)
    Retention
    Until consent withdrawal (analytics data per Google Analytics retention settings)
    Basis & safeguards
    Opt-in consent via cookie banner; Google terms and DPA
  5. ip-api.com 또는 동등 GeoIP 제공자

    https://ip-api.com

    Purpose
    Resolve connection IP to country code for regional checkout and notices
    Data items
    IP address (lookup request), country/region code (response)
    Country
    United States or provider location
    Timing & method
    One lookup at access time; the IP is not stored after country-code resolution
    Retention
    Not retained after immediate country-code resolution
    Basis & safeguards
    Minimized processing for security and regional display
  6. OpenAI, L.L.C.

    Optional

    https://openai.com/policies/privacy-policy

    Purpose
    Optional L3 external LLM inference (only for organisations whose licence holder has agreed to cross-border transfer on the company’s behalf); website chat auto-replies only when the openai engine is selected (default processing stays on Anexton servers)
    Data items
    Opted-in prompts, selected conversation turns, retrieved snippets, model name, token counts; website chat messages only when the openai engine is selected
    Country
    United States
    Timing & method
    API transfer at opted-in request time (TLS encrypted); source files are never sent
    Retention
    Content sent through the API is not used for model training; sent with response storage turned off (store=false); abuse-monitoring logs kept up to 30 days, longer only where required by law or needed to protect services or third parties from harm (OpenAI policy)
    Basis & safeguards
    Cross-border transfer consent of the customer (controller), given by the licence holder (PIPA Art. 26(6), 28-8); OpenAI standard terms; DPA; SCCs
  7. Slack Technologies, LLC (Salesforce)

    Optional

    https://slack.com/trust/privacy/privacy-policy

    Purpose
    Routing website chat to a human agent, only when the agent-relay feature is enabled (no transfer while it is off)
    Data items
    Website chat messages, the page where the chat started, and a conversation identifier. Visitor names, emails, and phone numbers are neither collected nor sent
    Country
    United States
    Timing & method
    API transfer at the time of the conversation (TLS encrypted)
    Retention
    Per the Anexton Slack workspace retention policy
    Basis & safeguards
    User consent to the pre-chat notice; DPA; SCCs
  8. Anthropic, PBC

    Optional

    https://www.anthropic.com/legal/privacy

    Purpose
    AI Remote CLI assistance (opt-in only) — not used as the external AI (L3) for in-house AI questions
    Data items
    Opted-in prompts, selected conversation turns, support context, limited PTY output, model name, token counts
    Country
    United States
    Timing & method
    API transfer at opted-in request time (TLS encrypted); source files are never sent
    Retention
    Inputs/outputs auto-deleted within 30 days per Anthropic policy; ZDR available
    Basis & safeguards
    User opt-in consent; DPA/ZDR configuration; SCCs
  9. 결제대행사 (Stripe, Inc. / 토스페이먼츠㈜)

    https://stripe.com/privacy · https://www.tosspayments.com

    Purpose
    Paid plan checkout, receipts, refunds, tax/accounting processing
    Data items
    Checkout session, amount, currency, payment status, billing metadata (Anexton does not store card numbers)
    Country
    Korea (Toss Payments), United States (Stripe)
    Timing & method
    Transferred through the checkout window at payment time (TLS encrypted)
    Retention
    Statutory retention periods (e.g., 5 years for transaction records)
    Basis & safeguards
    Payment contract performance and statutory retention duties

Refusing international transfers

How to refuse international transfers, and the effect: you may object by contacting privacy@anexton.com. Refusing transfers essential to contract performance (web security via Cloudflare, verification email via Resend, payments) may limit signup, email notices, or checkout. Optional features such as web analytics, Google sign-in, and external L3 AI transfer nothing unless you opt in, and refusing them does not limit the core service.

Change log

  • 2026-08-24 — Expanded transfer disclosures: timing/method, recipient contact, retention period, and refusal method/effect. Added Google Analytics (web analytics).
  • 2026-07-01 — Confirmed mail-order registration details and added Enterprise onsite processor-disclosure standard

For privacy inquiries: privacy@anexton.com