Skip to main content
Back to Home

Privacy Policy

Effective date: 2026-07-01 · Last updated: 2026-09-02

1. Scope and Regional Framework

This Privacy Policy applies to the Gleezor public website, Central Server, host registration, licensing, updates, remote support, remote CLI, and AI assistance features. VM disks, files, local accounts, and local AI data stored on customer on-premises Host Servers are generally controlled by the customer.

For users in Korea, this Policy is written to address the Korean Personal Information Protection Act, the Act on Consumer Protection in Electronic Commerce, and related Korean requirements, including PIPA Articles 26, 28-8, and 30.

For global users, including EEA/UK users, GDPR/UK GDPR and other mandatory local data-protection rules may apply in addition. The global legal bases, international-transfer, and data-subject rights sections apply to those users.

2. Controller and Contact

Controller: Gleezor. Representative: Woo Gyu Jang. Business registration no.: 679-07-03836. Address: Creative Enterprise Support Center, Keimyung College University Industry-Academic Cooperation Foundation, 675 Dalseo-daero, Dalseo-gu, Daegu, Republic of Korea.

Privacy officer: Woo Gyu Jang. Privacy requests: [email protected]. General support: [email protected]. Phone: +82-10-5959-9909. Mail-order sales registration no.: 2026-Daegu Dalseo-0854.

If a formal EEA/UK representative or DPO becomes mandatory, that information will be added to this page and the sub-processor list.

3. Purposes, Categories, and Legal Bases

Account creation and authentication: name or display name, email, password hash, organization, and Google OAuth identifiers. Legal bases: contract performance and user consent.

Licensing and host management: license_id, host_id, installation ID, software version, hashed hardware fingerprint, host status, CPU/memory/disk usage, request IP, User-Agent, and security logs. Legal bases: contract performance, security, and legitimate interests.

Customer support, remote support, and remote CLI: support messages, support history, approved remote CLI commands, limited PTY output, session recordings, and audit logs. Remote CLI and session recording are processed only with required permissions and per-session consent.

Enterprise onsite installation and maintenance: business contact details, visit schedules, device identifiers, disk/storage work records, and support history. User file contents are not viewed beyond customer authorization and work necessity.

Glezz AI (Gleezor AI) assistance: L1/L2 AI is processed locally in the customer environment. If an administrator enables L3 external LLM use and the user opts in per request or workspace, prompts, selected conversation turns, retrieved snippets, and minimal model/token metadata may be transmitted to external providers.

Billing and subscriptions: checkout session, selected plan, billing cycle, payment status, and tax/accounting records. Sensitive payment-card details are processed by payment providers and are not stored by Gleezor.

Marketing: email, organization, and marketing consent/withdrawal records. Marketing is based on optional consent and can be withdrawn at any time.

Location data: Gleezor does not collect precise personal location data such as GPS through the public website or Central service. For security, billing-region, and statistical purposes, request IP may be resolved to an approximate region such as country code, but raw IP is not retained beyond that purpose.

Cookies and analytics: login sessions, CSRF prevention, language settings, and analytics events only where consented. We do not use third-party advertising or behavioral tracking cookies.

Website chat: message contents, the page where the chat started, a session identifier, and the consent record. If you ask about adopting Gleezor, any details you choose to send — company name, contact name, phone number, email address — are part of the message contents and are stored with them. Used to answer inquiries and guide you through the product, and processed only after you agree to the notice shown before starting. Automatic replies are processed on Gleezor servers by default; where the external AI (OpenAI) engine is configured, the pre-chat notice says so. Where the agent-relay feature is enabled, the conversation is sent to Slack (United States) so a person can reply, and the pre-chat notice says so as well. While the feature is off, nothing is sent.

4. On-Premises Data and Central Exceptions

Gleezor is a Converged Edge Workspace Infrastructure product. VM disks, user files, SMB share contents, local user accounts, and local AI indexes remain on the customer Host Server and are not routinely transmitted to Gleezor Central Server.

Exceptions apply when licensing, host monitoring, updates, security audits, support requests, incident analysis, remote CLI, or opt-in L3 AI features are used. In those cases, the metadata, logs, and support context described in this Policy may be transmitted to Central or relevant sub-processors.

Gleezor generally does not view or store remote-display screen, input, or audio content while relaying a session. Commands, output, recordings, and audit logs from user-approved support or CLI sessions may be retained for security, dispute handling, and compliance.

5. Google User Data (Gmail Integration)

This section applies only when a user connects their own Google account from the host console. Gleezor requests exactly three permissions: openid, email, and https://www.googleapis.com/auth/gmail.readonly. The Gmail permission is read-only; Gleezor does not request permission to send, modify, delete, or change settings on your mail.

What we access: the email address of the connected Google account, and the subject, sender, recipients, received time, labels, and body of Gmail messages, together with the message change history used to detect new mail.

How we use it: only for features that are visible and prominent in the product interface — listing your mailbox, opening a message, and producing the summary or answer you asked for. We do not use it for advertising, profiling, sale to third parties, or training AI models.

How we store it: the refresh token is encrypted and stored on the customer Host Server and is not transmitted to Gleezor Central Server. Message subjects, addresses, and bodies are used only for as long as the request being served needs them, are not stored separately, and are excluded from AI query audit records.

Whether we share it: in the default configuration Gmail data never leaves the customer Host Server and is processed by local AI. Transmission to an external LLM happens only to provide the summary or answer the user requested, and only where the data subject has given separate consent to cross-border transfer and the data-residency and sensitivity policies permit it. If that consent cannot be confirmed, no transfer occurs — the default is no consent.

Human access: Gleezor personnel do not read Gmail data. The only exceptions are when the user has given affirmative agreement to view specific messages, when it is necessary for security purposes, or when it is necessary to comply with applicable law.

Disconnecting and deletion: disconnecting the integration in the product immediately discards the stored token and asks Google to revoke it. You can also revoke access at any time at https://myaccount.google.com/permissions.

Gleezor’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

6. Sub-Processors

To provide the service, Gleezor may use Cloudflare (CDN, DDoS protection, tunnel, R2 storage), Resend (email), Google (OAuth sign-in, and Google Analytics web analytics with cookie consent), ip-api.com or equivalent GeoIP providers (country-code lookup), OpenAI and Anthropic (optional L3 AI; OpenAI also for website chat auto-replies only when the openai engine is selected), Slack (website chat agent relay when enabled), and payment providers when billing is enabled.

The purpose, data categories, location, and transfer status of each sub-processor are published at /sub-processors. Material changes to sub-processors or purposes will be notified through this page, email, or another reasonable method.

If an external partner or hardware supplier is used for Enterprise onsite work, Gleezor will disclose the processor and scope through the contract, statement of work, or this Policy before the work begins.

Gleezor requires processor terms addressing purpose limitation, security measures, sub-processing controls, incident notice, return/deletion, oversight, and liability where applicable.

7. Third-Party Sharing and International Transfers

Gleezor does not sell or rent personal data for advertising. We do not share personal data with third parties outside legal obligations, user consent, contract performance, processing/storage needed for the service, payment, security, and support.

International transfers are disclosed at /sub-processors under PIPA Article 28-8(2), and that page forms part of this Policy. Transfers are managed with the safeguards and complaint-handling measures required by the enforcement decree.

For EEA/UK data transferred outside the EEA/UK, Gleezor relies on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, DPAs, encryption in transit, access controls, and data minimization. External LLM providers may apply their own retention and training terms under their DPA/ZDR settings.

8. Retention and Deletion

Account information is retained until account deletion. Contract/withdrawal and payment records may be retained for 5 years, consumer complaint/dispute records for 3 years, display/advertising records for 6 months, access logs for 3 months, and tax/accounting records for legally required periods.

Host audit logs are retained for 90 days by default; performance metrics for 30 days by default; anonymized or pseudonymized raw telemetry events for 12 months by default before deletion or aggregation. Website chat transcripts are automatically purged one year after the last activity. Where the agent-relay feature is enabled, the copy sent to Slack follows the Gleezor Slack workspace retention policy; the automatic purge above covers the records held on Gleezor servers. Consent and withdrawal records may be retained as compliance evidence and for dispute handling.

After account deletion, records that must be retained by law are stored separately from active account data and are deleted without delay when the retention purpose ends.

When retention is no longer required, electronic records are deleted using methods designed to prevent recovery and paper records are shredded or destroyed.

9. Data Subject Rights and Children

You may request access, correction, deletion, suspension of processing, withdrawal of consent, processing-history confirmation, and data portability through [email protected] or account settings.

Korean users may exercise rights under PIPA Articles 35-39. EEA/UK users may exercise GDPR/UK GDPR rights, including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.

Gleezor accounts are intended for users aged 14 or older. If personal data of a child under 14 must be processed, Gleezor will process it only after completing legally required parental-consent procedures.

10. Security Measures

Gleezor applies access minimization, RBAC, session timeouts, progressive account lockout, HTTPS/TLS, DTLS, mTLS, Argon2 password hashing, audit logging, network firewalls, DLP masking, encrypted storage, security training, and incident-response procedures under PIPA Article 29 and GDPR Article 32.

Passwords, tokens, API keys, and similar credentials are not stored or logged in plaintext. Request, response, and error logs are masked or excluded where such credentials may appear.

Remote CLI and AI assistance features add RBAC, per-session consent, command whitelisting, sandboxing, audit logs, hash chains, and sensitive-data masking.

If Gleezor becomes aware of a personal-data breach, it operates procedures to mitigate harm and, where legally required, notify affected users and report to competent authorities within 72 hours.

11. Automated Decision-Making

Gleezor does not use personal data for solely automated decisions that produce legal or similarly significant effects on users. AI assistant outputs are advisory and are not used to automatically create, suspend, terminate, or deny billing for user accounts.

12. Remedies

Korean users may contact the Personal Information Dispute Mediation Committee, the KISA privacy infringement center, the Supreme Prosecutors Office, or the National Police Agency Cyber Bureau.

EEA/UK users may lodge a complaint with the supervisory authority in their place of residence, work, or alleged infringement.

13. Changes

This Policy is effective as of July 1, 2026. Minor wording corrections may be posted immediately. Material changes affecting collection categories, purposes, third-party sharing, international transfers, or user rights will be announced at least 30 days before taking effect by website notice or email. The revision history is published alongside the /sub-processors page.