Last updated: 2026-08-01. XimTier complies with Korea PIPA and EU GDPR.
1. Information We Collect
XimTier collects the following information to provide its services.
- Demo requests: name, email, company, role, industry, data description, optional file, preferred time
- Contact inquiries: name, email, company, industry, message
- IR downloads: name, email, company, role
- Auto-collected: web server access logs (IP, timestamp, request path) — for security and troubleshooting
We use Google Analytics 4 to collect anonymized aggregate statistics such as visit counts, country, referral source, and device; IP addresses are anonymized.
2. Purpose of Collection
- Responding to demo requests and inquiries; scheduling
- Sending IR deck download links
- Legal compliance (e-commerce law, information & communications network act)
3. Retention Period
- Demo requests: 1 year after the meeting concludes (completed or cancelled)
- Inquiries: 1 year after submission
- IR deck requests: 1 year after submission. The download link itself expires 24 hours after issuance.
- Case gallery comments: published comments are retained until deletion is requested
- Web server access logs: deleted automatically after 14 days
- Google Analytics data: deleted automatically after 14 months
Records past these periods are purged automatically every day.
4. Third-party Sharing
XimTier does not share personal information with third parties, except:
- Required by law or investigation
- Service operation processing (Postmark/SendGrid for email — announced after domain confirmation)
- Google LLC (Google Analytics 4 — web usage analytics, transferred internationally to the United States)
5. User Rights
You may exercise the following rights at any time.
- Access, correct, or delete your personal information
- Withdraw consent and stop processing
- GDPR additional rights (EU residents): data portability, object to automated decisions
Rights requests: contact@ximtier.io
6. Cookie Policy
XimTier uses cookies required to run the service and analytics cookies.
- Session cookie: keeps you signed in. Removed when you close your browser.
- Remember-me cookie: issued only if you tick "Remember me" at sign-in.
Expires after 2 weeks, and is removed immediately when you sign out.
- Like cookie: a random identifier that prevents duplicate likes in the case gallery.
Expires after 30 days. It does not identify you or track you across other sites.
- Analytics cookie (_ga): a visitor-distinguishing identifier issued by Google Analytics 4.
It expires after 2 years and does not identify individuals.
We do not use advertising cookies.
7. Security Measures
- In transit: TLS 1.2/1.3 (HTTPS enforced)
- Passwords: stored as irreversible hashes (not readable by anyone, including admins)
- Access control: Admin role separation, Rack::Attack rate limit
8. Officer + Contact
- Privacy Officer: Kang Seung-sik (CTO)
- Contact: contact@ximtier.io
- Dispute resolution: Korea PIPC (privacy.go.kr) / EU local DPA