Legal
Privacy Policy
Effective date:
This policy explains how Korix collects, obtains, uses, shares, retains, and protects personal data when you visit our website or use the Korix gateway. It also explains the choices and rights available to people in the European Economic Area and elsewhere.
1. Scope, controller, and customer roles
This policy applies to Korix websites, applications, and gateway services. It does not apply to third-party apps, AI clients, or other services you connect to Korix; those providers handle data under their own privacy notices.
Korix is the controller of personal data used to operate its website, administer accounts and commercial relationships, communicate with users, secure the service, and meet its own legal obligations. The Korix contracting entity identified in an applicable order form is the relevant Korix entity for that customer relationship.
When an organization uses Korix to process workspace content, that organization is normally the controller and Korix acts as its processor under the organization's instructions and any applicable data-processing agreement. Korix may remain an independent controller for limited account, security, billing, and compliance records needed to operate the service responsibly. Contact your organization first for questions about its decisions concerning workspace data.
2. Data we collect and where it comes from
We may process the following categories of data:
- Account data: name, email address, profile image, authentication identifiers, organization membership, role, and account settings.
- Workspace data: organization structure, integrations, tool definitions, policies, approval decisions, knowledge records, and other configuration or content supplied by the customer and its users.
- Service and audit data: tool requests, arguments, results, file metadata, approval history, audit events, error records, and usage data. The exact content depends on the tools and features your organization enables.
- Connected-account data: authorization tokens, connection identifiers, and account information needed to access services you choose to connect. Where possible, credentials are stored and handled by the relevant integration or identity provider.
- Device and website data: IP address, browser and device type, pages or product features used, referring page, approximate timestamps, and security diagnostics collected through server logs and product analytics.
- Communications and commercial data: information you provide when you request a demonstration, negotiate an order, ask for support, exercise a privacy right, or otherwise contact us.
We obtain data directly from you, from administrators and other users in your organization, from identity and integration providers, from connected services when an authorized request is performed, and from your browser or device when you use Korix.
3. Purposes and legal bases
We use personal data for the following purposes and legal bases:
- Providing the service: creating accounts, authenticating users, applying organization policies, routing authorized requests, returning results, and providing support. We rely on performance of a contract or steps requested before entering into a contract.
- Security and reliability: preventing unauthorized access, investigating abuse, recording audit events, troubleshooting, and protecting Korix, customers, and connected services. We rely on our legitimate interests in operating a secure and reliable business service and, where applicable, on legal obligations.
- Administration and communication: managing the customer relationship, responding to requests, and sending service notices. We rely on contract performance and our legitimate interests in administering the relationship.
- Product improvement and analytics: understanding feature usage, diagnosing performance, and improving Korix. We rely on legitimate interests where permitted and on consent where consent is required for a particular technology.
- Legal compliance and protection: meeting legal, accounting, tax, regulatory, and law-enforcement obligations; establishing or defending legal claims; and enforcing agreements. We rely on legal obligations and legitimate interests.
- Consent-based processing: where we specifically ask for consent, we rely on that consent. You may withdraw it at any time without affecting processing that occurred before withdrawal.
When we rely on legitimate interests, we consider the necessity of the processing and balance those interests against the rights and reasonable expectations of the people affected.
4. How we share data
We may disclose data to the following categories of recipients:
- Your organization: workspace administrators and authorized members may see account, configuration, approval, audit, knowledge, and usage information according to their permissions.
- Connected services: we send the information needed to perform requests initiated by you or your organization.
- Service providers and subprocessors: companies providing hosting, databases, authentication, analytics, communications, security, file handling, and integration infrastructure under contractual safeguards.
- Professional advisers: auditors, insurers, lawyers, accountants, and advisers where reasonably necessary and subject to confidentiality obligations.
- Legal and safety recipients: authorities or other parties when reasonably necessary to comply with law, respond to valid legal process, enforce our terms, or protect rights and safety.
- Business transaction recipients: parties involved in a merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards.
We do not sell personal data and do not use customer workspace content for targeted advertising.
5. Cookies, local storage, and analytics
Korix uses cookies, local storage, and similar technologies that are needed to keep you signed in, remember settings such as theme preference, protect sessions, and operate requested features. Authenticated product events and pseudonymous account identifiers may also be used to understand reliability and feature usage. Korix does not use advertising trackers or automatic recording of customer workspace content for advertising.
Where applicable law requires consent before using a non-essential technology, that technology must not be used until the required consent has been obtained. Browser controls can block or remove stored data, although blocking essential technologies may prevent parts of Korix from working.
Korix uses PostHog's EU service for product analytics and error tracking. Error reports use pseudonymous account identifiers and a limited set of technical fields. Korix removes exception messages, request data, source-code context, local variables, and URL query strings before browser and application-server reports are sent. Backend function errors may also be sent by Convex using an opaque authentication identifier. Korix does not enable session recording or console recording for this purpose.
6. Data retention
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the service, maintaining security and auditability, complying with law, resolving disputes, and enforcing agreements. We consider the type and sensitivity of the data, customer settings, the length of the relationship, security needs, limitation periods, and legal requirements.
Current service defaults retain detailed audit history for 180 days, personal-memory records for 365 days, and prepared offboarding exports for 7 days. Organization administrators can configure supported retention periods. Connected credentials are retained until the connection is removed or the relevant account or organization is deleted. Active legal holds may suspend deletion where preservation is required. We may retain aggregated or irreversibly de-identified data that no longer identifies a person.
7. International transfers
Korix and its service providers may process data in countries outside the country where you live, including outside the European Economic Area. Where European data-protection law requires a transfer mechanism, we use an adequacy decision, approved standard contractual clauses, or another recognized safeguard and assess supplementary measures where appropriate. You may request information about the relevant safeguard and how to obtain a copy through the contact method below.
8. Security
We use administrative, technical, and organizational measures designed to protect personal data. These include role-based access controls, server-side credential handling, encryption where appropriate, policy checks, audit logging, tenant separation, and procedures for revoking access and deleting data. No online service is completely secure, so we cannot guarantee absolute security.
9. Your EEA data-protection rights
Subject to the conditions and exceptions in applicable law, people in the European Economic Area may ask us to:
- confirm whether we process their personal data and provide access;
- correct inaccurate or incomplete data;
- delete data that is no longer lawfully needed;
- restrict processing in specified circumstances;
- provide data they supplied in a structured, commonly used, machine-readable format and, where feasible, transmit it elsewhere;
- stop processing based on legitimate interests where their rights outweigh our grounds, and stop direct marketing at any time; or
- withdraw consent where consent is the legal basis.
You may also lodge a complaint with the data-protection supervisory authority in the EEA country where you live or work, or where you believe an infringement occurred. These rights are not absolute, and we may retain data where another lawful basis requires or permits it.
10. Exercising your rights
You can update some account information inside Korix. For workspace data controlled by an organization, send your request to that organization first; we support our customers in responding to valid requests. For data controlled by Korix, use the privacy contact in your order form or contact us through the Korix website.
We may request information needed to verify your identity and locate the relevant data. Requests are ordinarily free of charge. We aim to respond within one month where the GDPR applies, subject to the extensions and limitations it permits. If we cannot act on a request, we will explain the reason and available complaint options where required.
11. Required data and automated decisions
Account and authentication data are required to create and secure an account. Workspace and connected-service data are required only when you or your organization chooses the related feature. If required data is not provided, we may be unable to provide that account, connection, or feature.
Korix may automatically enforce access and approval rules configured by your organization. Korix does not use website or account data to make solely automated decisions about individuals that produce legal or similarly significant effects. Your organization is responsible for reviewing the policies it configures and for any separate decisions it makes using Korix outputs.
12. Children
Korix is intended for business users and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, please contact us so we can take appropriate action.
13. Changes to this policy
We may update this policy as Korix, our processing, or applicable law changes. We will post the updated policy here and revise the effective date. If a change materially affects your rights, we will provide additional notice where required.
14. Contact
To ask a privacy question or exercise a right, use the privacy contact identified in your organization's order form or data-processing agreement, or contact us through the Korix website. You can also review the Terms of Service.