Privacy Policy
Effective date: 2026-07-01 · Last updated: 2026-09-06
1. Scope and Regional Framework
This Privacy Policy applies to the Anexton public website, Central Server, host registration, licensing, updates, remote support, remote CLI, and AI assistance features. VM disks, files, local accounts, and local AI data stored on customer on-premises Host Servers are generally controlled by the customer.
For users in Korea, this Policy is written to address the Korean Personal Information Protection Act, the Act on Consumer Protection in Electronic Commerce, and related Korean requirements, including PIPA Articles 26, 28-8, and 30.
For global users, including EEA/UK users, GDPR/UK GDPR and other mandatory local data-protection rules may apply in addition. The global legal bases, international-transfer, and data-subject rights sections apply to those users.
2. Controller and Contact
Controller: Anexton. Representative: Woo Gyu Jang. Business registration no.: 679-07-03836. Address: Creative Enterprise Support Center, Keimyung College University Industry-Academic Cooperation Foundation, 675 Dalseo-daero, Dalseo-gu, Daegu, Republic of Korea.
Privacy officer: Woo Gyu Jang. Privacy requests: [email protected]. General support: [email protected]. Phone: +82-10-5959-9909. Mail-order sales registration no.: 2026-Daegu Dalseo-0854.
If a formal EEA/UK representative or DPO becomes mandatory, that information will be added to this page and the sub-processor list.
3. Purposes, Categories, and Legal Bases
[Processed without consent] Account creation and sign-in: email, password hash. Legal basis: PIPA Art.15(1)(iv) (performance of a contract with the data subject and steps taken at the data subject’s request prior to entering into a contract) and GDPR Art.6(1)(b). These two items are not subject to consent, and we do not ask for consent for them.
[Processed without consent] Access security records: request IP, User-Agent, and sign-in time. Legal bases: PIPA Art.15(1)(iv) (service delivery) and Art.15(1)(vi) (legitimate interests, abuse prevention); GDPR Art.6(1)(f). How to refuse is described under "Automatically collected items and how to refuse" below.
[Processed with consent] Marketing messages and cross-border AI transfer. Each is consented to separately, and declining either places no restriction on signing up or using the service (PIPA Art.22(5)). You can turn them on or off at any time in account settings after signing up.
Display name and organization are not collected at signup. The display name is optional on first entry to the console, and the organization name is collected when it is actually needed, such as at licence issuance (PIPA Art.16(1), data minimisation).
Other account attributes: Google OAuth identifier (when you sign up or link with Google).
Licensing and host management: license_id, host_id, installation ID, software version, hashed hardware fingerprint, host status, CPU/memory/disk usage, request IP, User-Agent, and security logs. Legal bases: contract performance, security, and legitimate interests.
Customer support, remote support, and remote CLI: support messages, support history, approved remote CLI commands, limited PTY output, session recordings, and audit logs. Remote CLI and session recording are processed only with required permissions and per-session consent.
Enterprise onsite installation and maintenance: business contact details, visit schedules, device identifiers, disk/storage work records, and support history. User file contents are not viewed beyond customer authorization and work necessity.
Glezz AI (Anexton AI) assistance: L1 runs on the customer Host Server; L2 runs on Gleezor-operated servers in Korea. If an administrator enables L3 external LLM use and the user opts in per request or workspace, prompts, selected conversation turns, retrieved snippets, and minimal model/token metadata may be transmitted to external providers.
Billing and subscriptions: checkout session, selected plan, billing cycle, payment status, and tax/accounting records. Sensitive payment-card details are processed by payment providers and are not stored by Anexton.
Marketing: email, organization, and marketing consent/withdrawal records. Marketing is based on optional consent and can be withdrawn at any time.
Location data: Anexton does not collect precise personal location data such as GPS through the public website or Central service. For security, billing-region, and statistical purposes, request IP may be resolved to an approximate region such as country code, but raw IP is not retained beyond that purpose.
Cookies and analytics: login sessions, CSRF prevention, language settings, and analytics events only where consented. We do not use third-party advertising or behavioral tracking cookies.
Automatically collected items and how to refuse: we automatically collect cookies and access records (request IP, User-Agent, sign-in time) for sign-in sessions and security. Analytics cookies can be declined in the cookie consent banner shown on your first visit, and you can withdraw a previous acceptance by reopening the same banner. You can also block or delete cookies in your browser settings. Blocking the strictly necessary cookies used for sign-in sessions and CSRF protection will prevent you from staying signed in.
Website chat: message contents, the page where the chat started, a session identifier, and the consent record. If you ask about adopting Anexton, any details you choose to send — company name, contact name, phone number, email address — are part of the message contents and are stored with them. Used to answer inquiries and guide you through the product, and processed only after you agree to the notice shown before starting. Automatic replies are processed on Anexton servers by default; where the external AI (OpenAI) engine is configured, the pre-chat notice says so. Where the agent-relay feature is enabled, the conversation is sent to Slack (United States) so a person can reply, and the pre-chat notice says so as well. While the feature is off, nothing is sent.
4. On-Premises Data and Central Exceptions
Anexton is a Converged Edge Workspace Infrastructure product. VM disks, the original user files and SMB share contents, and local user accounts remain on the customer Host Server.
The AI search index is different. When in-house AI search is enabled, the text passages extracted from your documents, their vectors, the document structure, and the file inventory (path, name, hash, size) are stored as copies on Anexton Central Server so that search and answer generation can run. That storage is purpose-limited (search, inference, document generation, operations) and is never used to train models. When you delete a file, the passages and vectors are removed immediately; the structure and inventory entries stop being searchable at once and are fully deleted after 7 days. A configuration that keeps the index on the customer Host Server only is in preparation; hosts where it applies say so in the admin console.
For documents with almost no extractable text, such as scans, the original file may pass through Central Server so that page images can be produced. The original exists only while that processing runs and is not stored, and documents classified as sensitive are excluded from this path.
Exceptions apply when licensing, host monitoring, updates, security audits, support requests, incident analysis, remote CLI, or opt-in L3 AI features are used. In those cases, the metadata, logs, and support context described in this Policy may be transmitted to Central or relevant sub-processors.
Anexton generally does not view or store remote-display screen, input, or audio content while relaying a session. Commands, output, recordings, and audit logs from user-approved support or CLI sessions may be retained for security, dispute handling, and compliance.
5. Google User Data (Gmail, Drive, and Calendar Integration)
This section applies only when a user connects their own Google account from the host console. For mail, Anexton requests openid, email, and these Gmail permissions: https://www.googleapis.com/auth/gmail.readonly (read your mail), https://www.googleapis.com/auth/gmail.modify (apply the clean-up you asked for and confirmed — report spam, archive, mark read, star, apply labels), https://www.googleapis.com/auth/gmail.settings.basic (create or remove the auto-sorting rules you asked for), and https://www.googleapis.com/auth/gmail.labels (see and edit label names). Every mailbox change is shown on screen before it runs and happens only after you confirm it. If you choose to send a reply or a new message from the Mail screen, Anexton requests https://www.googleapis.com/auth/gmail.send (send mail) at that moment as a separate, incremental permission. It is used only for messages you wrote and chose to send, the sender is always your own linked account, and there is no path by which the AI sends mail on its own. Anexton does not request the full-access scope https://mail.google.com/ .
If you connect Google Drive on the Files screen, Anexton additionally requests https://www.googleapis.com/auth/drive.readonly . It is read-only and is used to list your files and folders, open them, and download them; Anexton does not request permission to create, modify, or delete Drive files.
If you connect Google Calendar on the Calendar screen, Anexton requests https://www.googleapis.com/auth/calendar.events.readonly (see the events on your calendars) and https://www.googleapis.com/auth/calendar.calendarlist.readonly (see the list of calendars you subscribe to). Those two are all the first connection asks for, and both are read-only — someone who only wants to see their schedule is never shown a consent screen that says their events can be deleted. If you choose to create or change an event on the Calendar screen, Anexton requests https://www.googleapis.com/auth/calendar.events.owned (see, create, change, and delete events on calendars you own) at that moment as a separate, incremental permission. It is the narrowest scope that writing an event accepts and it does not reach calendars you do not own. Anexton does not request https://www.googleapis.com/auth/calendar or https://www.googleapis.com/auth/calendar.events , which would cover every calendar. Every calendar change is shown on screen before it runs and happens only after you confirm it; there is no path by which the AI changes a calendar on its own.
What we access: the email address of the connected Google account, the subject, sender, recipients, received time, labels, and body of Gmail messages together with the message change history used to detect new mail, your label list and the auto-sorting rules you asked us to create, — if you connect Drive — the list of your Drive files and folders and the contents of the files you open, and — if you connect Calendar — your calendar names and colours and the title, time, location, organiser, and guests of the events inside the range being displayed.
How we use it: only for features that are visible and prominent in the product interface — listing your mailbox, opening a message, producing the summary or answer you asked for, applying the mailbox clean-up you confirmed on screen, opening or downloading Drive files, drawing your calendar, and making the calendar changes you confirmed on screen. We do not use it for advertising, profiling, sale to third parties, or training AI models.
How we store it: the refresh token is encrypted and stored on the customer Host Server and is not transmitted to Anexton Central Server. Message subjects, addresses, and bodies are used only for as long as the request being served needs them, are not stored separately, and are excluded from AI query audit records. Drive files you open are held on the Host Server only for as long as the download or preview needs them and are then discarded. Event titles, locations, and guests are used only while the calendar is on screen; they are not stored and never appear in logs. Audit records for clean-up actions keep only the kind of action and the number of messages — never addresses, subjects, or bodies.
Whether we share it: to produce the summary or answer you asked for, the message body is transmitted to Gleezor-operated AI servers in Korea, used only for as long as that request needs it, and not stored separately. Transmission to an external LLM provider happens only where the data subject has given separate consent to cross-border transfer and the data-residency and sensitivity policies permit it. If that consent cannot be confirmed, no transfer occurs — the default is no consent.
Human access: Anexton personnel do not read Gmail data. The only exceptions are when the user has given affirmative agreement to view specific messages, when it is necessary for security purposes, or when it is necessary to comply with applicable law.
Disconnecting and deletion: disconnecting the integration in the product immediately discards the stored token and asks Google to revoke it. You can also revoke access at any time at https://myaccount.google.com/permissions.
Anexton’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
6. Sub-Processors
To provide the service, Anexton may use Cloudflare (CDN, DDoS protection, tunnel, R2 storage), Resend (email), Google (OAuth sign-in, and Google Analytics web analytics with cookie consent), ip-api.com or equivalent GeoIP providers (country-code lookup), OpenAI and Anthropic (optional L3 AI; OpenAI also for website chat auto-replies only when the openai engine is selected), Slack (website chat agent relay when enabled), and payment providers when billing is enabled.
The purpose, data categories, location, and transfer status of each sub-processor are published at /sub-processors. Material changes to sub-processors or purposes will be notified through this page, email, or another reasonable method.
If an external partner or hardware supplier is used for Enterprise onsite work, Anexton will disclose the processor and scope through the contract, statement of work, or this Policy before the work begins.
Anexton requires processor terms addressing purpose limitation, security measures, sub-processing controls, incident notice, return/deletion, oversight, and liability where applicable.
7. Third-Party Sharing and International Transfers
Anexton does not sell or rent personal data for advertising. We do not share personal data with third parties outside legal obligations, user consent, contract performance, processing/storage needed for the service, payment, security, and support.
International transfers are disclosed at /sub-processors under PIPA Article 28-8(2), and that page forms part of this Policy. Transfers are managed with the safeguards and complaint-handling measures required by the enforcement decree.
There are two bases for international transfer. Sending a member’s own questions to external AI relies on PIPA Article 28-8(1)(i) (the data subject’s separate consent), which can be turned on or off at any time in console account settings. End-user data processed on a customer’s own appliance relies on PIPA Article 28-8(1)(iii) (processing/storage necessary to perform the contract, with Article 28-8(2) items disclosed in this Policy). Neither is bundled into a consent checkbox; each follows the method its basis requires.
For EEA/UK data transferred outside the EEA/UK, Anexton relies on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, DPAs, encryption in transit, access controls, and data minimization. External LLM providers may apply their own retention and training terms under their DPA/ZDR settings.
8. Retention and Deletion
Account information is retained until account deletion. Contract/withdrawal and payment records may be retained for 5 years, consumer complaint/dispute records for 3 years, display/advertising records for 6 months, access logs for 3 months, and tax/accounting records for legally required periods.
Host audit logs are retained for 365 days by default, and records already linked into the hash chain are kept for integrity verification; performance metrics for 30 days by default; anonymized or pseudonymized raw telemetry events for 12 months by default before deletion or aggregation. Website chat transcripts are automatically purged one year after the last activity. Where the agent-relay feature is enabled, the copy sent to Slack follows the Anexton Slack workspace retention policy; the automatic purge above covers the records held on Anexton servers. Consent and withdrawal records may be retained as compliance evidence and for dispute handling.
After account deletion, records that must be retained by law are stored separately from active account data and are deleted without delay when the retention purpose ends.
When retention is no longer required, electronic records are deleted using methods designed to prevent recovery and paper records are shredded or destroyed.
9. Data Subject Rights and Children
You may request access, correction, deletion, suspension of processing, withdrawal of consent, processing-history confirmation, and data portability through [email protected] or account settings.
Korean users may exercise rights under PIPA Articles 35-39. EEA/UK users may exercise GDPR/UK GDPR rights, including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
Anexton accounts are intended for users aged 14 or older. If personal data of a child under 14 must be processed, Anexton will process it only after completing legally required parental-consent procedures.
10. Security Measures
Anexton applies access minimization, RBAC, session timeouts, progressive account lockout, HTTPS/TLS, DTLS, mTLS, Argon2 password hashing, audit logging, network firewalls, DLP masking, encrypted storage, security training, and incident-response procedures under PIPA Article 29 and GDPR Article 32.
Passwords, tokens, API keys, and similar credentials are not stored or logged in plaintext. Request, response, and error logs are masked or excluded where such credentials may appear.
Remote CLI and AI assistance features add RBAC, per-session consent, command whitelisting, sandboxing, audit logs, hash chains, and sensitive-data masking.
If Anexton becomes aware of a personal-data breach, it operates procedures to mitigate harm and, where legally required, notify affected users and report to competent authorities within 72 hours.
11. Automated Decision-Making
Anexton does not use personal data for solely automated decisions that produce legal or similarly significant effects on users. AI assistant outputs are advisory and are not used to automatically create, suspend, terminate, or deny billing for user accounts.
12. Remedies
Korean users may contact the Personal Information Dispute Mediation Committee, the KISA privacy infringement center, the Supreme Prosecutors Office, or the National Police Agency Cyber Bureau.
EEA/UK users may lodge a complaint with the supervisory authority in their place of residence, work, or alleged infringement.
13. Changes
This Policy is effective as of July 1, 2026. Minor wording corrections may be posted immediately. Material changes affecting collection categories, purposes, third-party sharing, international transfers, or user rights will be announced at least 30 days before taking effect by website notice or email. The revision history is published alongside the /sub-processors page.



