Legal
Privacy Policy
Effective date: August 6, 2026
This policy explains how Korix collects, uses, shares, and protects personal data when you visit our website or use the Korix gateway.
1. Scope
This policy applies to Korix websites, applications, and gateway services. It does not apply to third-party apps, AI clients, or other services you connect to Korix; those providers handle data under their own privacy policies.
If you use Korix through an organization, that organization may be the controller of personal data processed through its workspace. Korix processes that data on the organization's instructions. Please contact your organization first for questions about its use of your data.
2. Data we collect
We may collect the following categories of data:
- Account data: name, email address, profile image, authentication identifiers, and organization membership.
- Workspace data: organization structure, integrations, tool definitions, policies, approval decisions, and other configuration data.
- Service data: tool requests, arguments, results, file metadata, audit events, error records, and usage data. The exact content depends on the tools your organization connects.
- Connected-account data: authorization tokens and identifiers needed to access services you choose to connect. Where possible, credentials are stored and handled by the relevant integration or identity provider.
- Device and website data: IP address, browser and device type, pages viewed, referring page, and approximate usage times collected through logs and analytics technologies.
- Communications: information you provide when you request a demo, ask for support, or otherwise contact us.
3. How we use data
We use personal data to:
- provide, maintain, secure, and troubleshoot Korix;
- authenticate users and enforce organization access policies;
- route authorized requests to connected services and return their results;
- support approvals, audit logs, and usage reporting;
- respond to questions and communicate about the service;
- understand usage and improve performance and features; and
- comply with law and protect our users, Korix, and others.
Where data-protection law requires a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing Korix, compliance with legal obligations, or consent, as appropriate.
4. How we share data
We may share data with:
- Your organization: workspace administrators and authorized members may see account, configuration, approval, audit, and usage information.
- Connected services: we send the information needed to perform requests you or your organization initiate.
- Service providers: companies that provide hosting, databases, authentication, analytics, communications, security, and integration infrastructure on our behalf.
- Legal and safety recipients: authorities or other parties when reasonably necessary to comply with law, enforce our terms, or protect rights and safety.
- Business transaction recipients: parties to a merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards.
We do not sell personal data or use customer workspace content for targeted advertising.
5. Cookies and analytics
Korix uses local storage, cookies, and similar technologies to keep you signed in, remember settings such as theme preference, secure the service, and understand website and product usage. You can control cookies through your browser, but blocking essential technologies may prevent parts of Korix from working.
6. Data retention
We retain personal data for as long as needed to provide Korix, fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary based on the type of data, workspace settings, the length of the customer relationship, and legal requirements. We may retain de-identified or aggregated information where it no longer identifies you.
7. Security
We use administrative, technical, and organizational safeguards designed to protect personal data. These include access controls, server-side credential handling, policy checks, and audit logging. No online service is completely secure, so we cannot guarantee absolute security.
8. International transfers
Korix and its service providers may process data in countries other than where you live. Where required, we use recognized safeguards for international transfers, such as adequacy decisions or standard contractual clauses.
9. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent. You may also have the right to complain to a data-protection authority.
You can update some account information in Korix. For organization-controlled data, submit requests to your organization administrator. We may need to verify your identity before acting on a request, and some rights are subject to legal exceptions.
10. Children
Korix is intended for business users and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, please contact us so we can take appropriate action.
11. Changes to this policy
We may update this policy as Korix and privacy laws change. We will post the updated policy here and revise the effective date. If a change materially affects your rights, we will provide additional notice where required.
12. Contact
To ask a privacy question or exercise your rights, contact us through the contact or demo form on the Korix website. You can also review the Terms of Service that apply to Korix.