PRIVACY POLICY
개인정보와 서비스 데이터가 어떻게 수집, 이용, 보호 및 처리되는지 INNORIX 개인정보 처리방침에서 확인하세요.
INNORIX processes personal information and service data necessary for the use of its website and the INNORIX Platform.
This Privacy Policy explains what information INNORIX processes and how it is used when you use the INNORIX website, Account, Cloud Service, Software, API, and related services.
Where INNORIX processes Personal Data as a Processor on behalf of a Customer, the Data Processing Addendum (DPA) may apply together with this Privacy Policy.
The information INNORIX processes depends on how the Services are used.
When you visit the INNORIX website, the following information may be processed.
IP address
Browser and device information
Pages visited
Referrer information
Cookie and preference information
Website interaction information
This information is used for website operation, security, performance analysis, and improving the user experience.
More information about Cookies is available in the Cookie Policy.
When you create an INNORIX Account or join an organization, the following information may be processed.
Name
Business email address
Organization
User identifier
Role and permissions
Account settings
Authentication information
If you sign in through Google or another supported Identity Provider, that Provider may provide INNORIX with information required for authentication.
INNORIX uses this information for Account creation, authentication, permission management, and customer support.
When a Server, PC, VM, Kubernetes Node, Object Storage, or other Endpoint is connected to INNORIX, Device information required to operate the Service may be processed.
For example:
Device ID
Device name
Operating system
Software version
IP address
Connection status
Device type
Last connection information
Workspace or organization association
This information is used to identify Devices, maintain connection status, execute transfer operations, and monitor operational status.
When file transfers and automation are executed, Metadata required for Service operation may be generated.
For example:
Source and destination identifiers
Run ID
Transfer ID
Flow information
Transfer status
Start and completion time
File transfer result
File size
Error and retry information
Audit information
Where required by product functionality, this may include information such as File names or paths.
INNORIX uses this information for transfer execution, Monitoring, Audit, troubleshooting, and Service operation.
When using INNORIX's Direct Transfer configuration, files move directly between the connected Source and Destination.
In this architecture, INNORIX Cloud is not used as intermediate storage for file transfers.
Instead, the INNORIX Control Plane manages operational information such as the following.
Connected Devices
Transfer instructions
Policies
Transfer status
Results
Operational metadata
The actual data path may vary depending on the customer's Deployment, Routing, and additional service configuration.
When Object Storage is connected, INNORIX may process authentication and connection information required to operate that Connection.
INNORIX does not store Raw Credentials in Metering or Billing records.
Credentials or security References required for Service operation may be used, while usage records contain only the necessary identifying information.
The customer's Cloud Account, Storage permissions, and Bucket permissions are managed by the customer and the applicable Cloud or Storage Provider.
When the API is used, the following information may be processed.
API credential identifier
Organization and Workspace information
Request information
API operation
Request time
Response status
Security and rate-limit information
API request records may be used for authentication, security, troubleshooting, Usage management, and Audit.
INNORIX processes Usage information to operate Subscriptions and measure usage.
For example:
Active Devices
Additional Device usage
Successfully delivered payload volume
API usage
Run and Transfer counts
Log usage
Applicable Plan and entitlement information
The Metering system primarily processes information required for Service operation and usage calculation.
File contents, Passwords, Raw Access Tokens, and Raw Storage Credentials are not stored as usage data.
When using a paid Subscription, the following Billing information may be processed.
Organization and billing account
Legal or business name
Billing address
Country
Tax information
Subscription
Currency
Invoice information
Purchase Order information
Payment status
Credits and adjustments
When Card Payment is used, Payment Card processing may be handled through an external Payment Provider.
INNORIX may process Payment Provider References and Transaction information required for Service operation.
When a customer contacts INNORIX or requests technical support, the following information may be processed.
Contact information
Support request
Communications
Relevant Device or Transfer identifiers
Error information
Logs provided by the customer
Other diagnostic information provided for troubleshooting
Customers should avoid including personal or confidential information in Support materials when it is not necessary for troubleshooting.
INNORIX uses collected information for the following purposes.
Create and operate Accounts
Connect Devices
Execute file transfers
Run automation
Provide API access
Display operational status
Maintain transfer history
Authenticate users and systems
Protect Accounts and Devices
Detect unauthorized access
Apply security controls
Investigate suspicious activity
Maintain audit records
Monitor performance
Diagnose errors
Maintain reliability
Analyze service usage
Improve product operation
Measure usage
Apply Plan entitlements
Generate invoices
Process payments
Manage credits and adjustments
Prevent billing errors and abuse
Respond to inquiries
Investigate technical problems
Restore service operation
Communicate with administrators
INNORIX may process or retain information where necessary to comply with applicable:
laws
tax requirements
accounting requirements
regulatory obligations
valid legal requests
Where applicable law requires a legal basis for processing Personal Data, INNORIX may rely on one or more of the following:
performance of a contract
steps requested before entering into a contract
legitimate interests in operating and securing the Services
compliance with legal obligations
consent where required
Where INNORIX processes Customer Personal Data solely on behalf of a Customer, the Customer determines the legal basis for that processing and INNORIX acts according to the applicable DPA.
INNORIX may process Personal Data in different roles depending on the context.
INNORIX generally determines the purposes of processing for information such as:
INNORIX Account administration
Website operations
Billing administration
Security of INNORIX services
Communications with INNORIX customers
Where Customer Personal Data is processed through the Services according to a Customer's instructions, INNORIX may act as a Processor on behalf of that Customer.
The applicable Processing terms are described in the DPA.
INNORIX does not disclose Personal Data except as necessary for legitimate business and service purposes, including the circumstances described below.
INNORIX may use external providers to support functions such as:
Cloud infrastructure
Service operations
Authentication
Communications
Payment processing
Customer support
Monitoring
Providers that process Customer Personal Data on behalf of INNORIX are managed according to applicable contractual and data protection requirements.
The relevant providers can be found in the Subprocessor List.
Information may be transferred as part of:
merger
acquisition
corporate restructuring
financing
sale of business assets
where permitted by applicable law and subject to appropriate confidentiality and data protection requirements.
INNORIX may disclose information when reasonably necessary to:
comply with applicable law
respond to valid legal process
protect INNORIX, customers or others
investigate fraud or security incidents
enforce applicable agreements
Where legally permitted, INNORIX may notify the affected customer of a government request involving Customer Personal Data.
INNORIX operates across multiple regions and may use service providers located in different countries.
Personal Data may therefore be processed outside the country in which it was originally collected.
Where applicable law requires safeguards for international data transfers, INNORIX uses legally recognized transfer mechanisms as applicable to the relevant processing.
Additional terms governing Customer Personal Data are described in the DPA.
The location in which information is processed may depend on:
Service
Deployment
Cloud region
Customer configuration
Subprocessor
support requirements
On-Premises, Hybrid, Sovereign Cloud and Air-Gapped deployments may provide different data-processing architectures.
A specific data residency commitment applies only where it is part of the selected Service or applicable customer agreement.
INNORIX retains information for the period reasonably necessary for the purpose for which it is processed.
Different categories of information have different retention periods.
Account information is retained while necessary to operate the Customer Account and applicable Services.
Searchable operational log retention depends on the applicable Plan and configuration.
Invoice, payment, tax and contract records may be retained after service termination where necessary for accounting, tax, legal or dispute-resolution purposes.
Support communications and diagnostic information may be retained for support, service improvement, security and audit purposes.
When a paid Subscription ends, INNORIX may provide a limited Read-only Grace Period under the applicable Terms.
During this period, available information such as:
Logs
Receipts
Configuration
Operational records
may remain accessible for review or export.
After the applicable Grace Period, INNORIX begins deletion of active service data that is no longer required.
Information that must be retained for legal, tax, accounting, security or dispute purposes may be retained for the applicable period.
Information that has been deleted from active systems may remain temporarily in Backup copies until removed through normal Backup Rotation.
Backup data is maintained for recovery and continuity purposes and is protected from ordinary active use.
INNORIX uses technical and organizational safeguards appropriate to the Services to protect information against unauthorized access, loss, alteration or disclosure.
Security controls include protections relating to areas such as:
Access control
Authentication
Data transmission
Device security
Audit
Monitoring
Operational security
Backup and recovery
More information is available on the Security page.
Depending on applicable law and the context in which INNORIX processes Personal Data, individuals may have rights to:
access Personal Data
correct inaccurate information
request deletion
restrict certain processing
object to certain processing
receive portable data
withdraw consent where processing is based on consent
Some rights may be subject to legal limitations or exceptions.
Where Personal Data is processed by INNORIX on behalf of a Customer, individuals should generally direct privacy requests to the organization that controls that data.
INNORIX assists Customers with applicable requests according to the DPA and available Service functionality.
Users can manage certain Account and Organization information directly through available product settings.
Where information cannot be managed through the product, privacy-related requests may be submitted through INNORIX's website contact channels.
INNORIX may need to verify identity or authority before completing a request.
INNORIX uses Cookies and similar technologies where necessary to operate its website and, where applicable, understand website usage or remember preferences.
Users can manage non-essential Cookies through Cookie Preferences.
Where INNORIX sends optional marketing communications, recipients can use the unsubscribe option provided in the communication.
Unsubscribing from marketing does not prevent INNORIX from sending operational or contractual communications necessary for an Account or Service.
Customers may connect INNORIX with third-party services such as:
Cloud providers
Object storage
Identity providers
Monitoring services
SIEM platforms
Collaboration tools
Personal Data processed directly by those providers is also subject to their own privacy policies and contractual terms.
Customers are responsible for selecting and configuring third-party services they connect to INNORIX.
For Customer-managed deployments, the Customer controls its own:
Infrastructure
Storage
Network
Operating systems
Local databases
access permissions
Personal Data stored exclusively in Customer-managed Infrastructure remains under the Customer's direct technical control unless it is transmitted to an INNORIX-managed Service.
Air-Gapped deployments may operate without routine online communication with INNORIX Cloud.
Information may still be provided to INNORIX when the Customer chooses to submit:
support information
license information
signed usage information
diagnostic data
Such information is handled according to this Privacy Policy and applicable agreements.
INNORIX Services are designed for organizations and business use and are not directed to children as consumer services.
INNORIX may update this Privacy Policy to reflect changes in:
Services
data-processing practices
legal requirements
Material changes will be communicated through appropriate website, Account or contractual channels where required.
Questions concerning this Privacy Policy or INNORIX's processing of Personal Data can be submitted through the Contact channel provided on the INNORIX website.
Where the request concerns Customer Personal Data processed on behalf of an INNORIX Customer, the request should generally be directed to that Customer first.
Security
Security architecture and safeguards for INNORIX Services.
Data Processing Addendum
Terms governing Customer Personal Data processed by INNORIX on behalf of Customers.
Subprocessors
Service providers involved in processing data for eligible INNORIX Services.
Cookie Policy
Information about Cookies and similar technologies.
Cookie Preferences
Controls for non-essential Cookies.
Terms
General terms governing use of INNORIX Services.