Back to Home
Sub-processors & International Transfers
Last updated: 2026-08-24
Published under PIPA Article 26 (processor disclosure) and Article 28-8 (international transfers). EEA transfers are protected through DPAs, Standard Contractual Clauses, encryption, and access controls.
| Recipient · Contact | Purpose | Data Items | Country | Timing & Method | Retention | Basis / Safeguard |
|---|---|---|---|---|---|---|
| Cloudflare, Inc.[email protected] | CDN, DDoS protection, web security, Cloudflare Tunnel, R2 release/attachment storage | IP addresses, HTTP request metadata, security logs, release-download metadata | United States | Continuous network transfer at access time (TLS encrypted) | For the duration of the processing engagement (until contract ends) | Processing/storage necessary for contract performance (PIPA art. 28-8(1)3); SCC/DPA |
| Resend, Inc. (Plus Five Five, Inc.)[email protected] | Transactional email delivery (verification, notifications) | Email addresses, message content | United States | API transfer at email send time (TLS encrypted) | For the duration of the processing engagement (until contract ends) | Processing necessary for contract performance (PIPA art. 28-8(1)3); SCC/DPA |
| Google LLC — OAuth 로그인https://policies.google.com/privacyOptional | Google OAuth login and signup | Google account identifier, email address, display name, OAuth metadata | United States | Transferred when the user chooses Google sign-in (TLS encrypted) | Until account deletion or unlinking | User-selected OAuth integration; Google terms and DPA |
| Google LLC — Google Analytics(웹 분석)https://policies.google.com/privacyOptional | Website usage analytics (only with cookie consent) | Online identifiers (cookies), anonymized IP, page-usage events | United States | Transferred at page use only after analytics-cookie consent (TLS encrypted) | Until consent withdrawal (analytics data per Google Analytics retention settings) | Opt-in consent via cookie banner; Google terms and DPA |
| ip-api.com 또는 동등 GeoIP 제공자https://ip-api.com | Resolve connection IP to country code for regional checkout and notices | IP address (lookup request), country/region code (response) | United States or provider location | One lookup at access time; the IP is not stored after country-code resolution | Not retained after immediate country-code resolution | Minimized processing for security and regional display |
| OpenAI, L.L.C.https://openai.com/policies/privacy-policyOptional | Optional L3 external LLM inference (admin-enabled and user opt-in only); website chat auto-replies only when the openai engine is selected (default processing stays on Gleezor servers) | Opted-in prompts, selected conversation turns, retrieved snippets, model name, token counts; website chat messages only when the openai engine is selected | United States | API transfer at opted-in request time (TLS encrypted); source files are never sent | Not used for training by default; abuse-monitoring logs kept up to 30 days per OpenAI policy | User opt-in consent; DPA/ZDR configuration; SCCs |
| Slack Technologies, LLC (Salesforce)https://slack.com/trust/privacy/privacy-policyOptional | Routing website chat to a human agent, only when the agent-relay feature is enabled (no transfer while it is off) | Website chat messages, the page where the chat started, and a conversation identifier. Visitor names, emails, and phone numbers are neither collected nor sent | United States | API transfer at the time of the conversation (TLS encrypted) | Per the Gleezor Slack workspace retention policy | User consent to the pre-chat notice; DPA; SCCs |
| Anthropic, PBChttps://www.anthropic.com/legal/privacyOptional | Optional L3 external LLM inference and AI Remote CLI assistance (opt-in only) | Opted-in prompts, selected conversation turns, support context, limited PTY output, model name, token counts | United States | API transfer at opted-in request time (TLS encrypted); source files are never sent | Inputs/outputs auto-deleted within 30 days per Anthropic policy; ZDR available | User opt-in consent; DPA/ZDR configuration; SCCs |
| 결제대행사 (Stripe, Inc. / 토스페이먼츠㈜)https://stripe.com/privacy · https://www.tosspayments.com | Paid plan checkout, receipts, refunds, tax/accounting processing | Checkout session, amount, currency, payment status, billing metadata (Gleezor does not store card numbers) | Korea (Toss Payments), United States (Stripe) | Transferred through the checkout window at payment time (TLS encrypted) | Statutory retention periods (e.g., 5 years for transaction records) | Payment contract performance and statutory retention duties |
Refusing International Transfers
How to refuse international transfers, and the effect: you may object by contacting [email protected]. Refusing transfers essential to contract performance (web security via Cloudflare, verification email via Resend, payments) may limit signup, email notices, or checkout. Optional features such as web analytics, Google sign-in, and external L3 AI transfer nothing unless you opt in, and refusing them does not limit the core service.
Change Log
- 2026-08-24 — Expanded transfer disclosures: timing/method, recipient contact, retention period, and refusal method/effect. Added Google Analytics (web analytics).
- 2026-07-01 — Confirmed mail-order registration details and added Enterprise onsite processor-disclosure standard
For privacy inquiries: [email protected]