Last updated: 2026-07-16. XimTier complies with Korea PIPA and EU GDPR.
1. Information We Collect
XimTier collects the following information to provide its services.
- Demo requests: name, email, company, role, industry, data description, optional file, preferred time
- Contact inquiries: name, email, company, industry, message
- IR downloads: name, email, company, role
- Auto-collected: web server access logs (IP, timestamp, request path) — for security and troubleshooting
We do not use visitor tracking or behavioural analytics tools.
2. Purpose of Collection
- Responding to demo requests and inquiries; scheduling
- Sending IR deck download links
- Legal compliance (e-commerce law, information & communications network act)
3. Retention Period
- Demo requests: 1 year after the meeting concludes (completed or cancelled), or until you close your account
- Inquiries: 1 year after submission
- IR deck requests: 1 year after submission. The download link itself expires 24 hours after issuance.
- Web server access logs: deleted automatically after 14 days
Records past these periods are purged automatically every day.
4. Third-party Sharing
XimTier does not share personal information with third parties, except:
- Required by law or investigation
- Service operation processing (Postmark/SendGrid for email — announced after domain confirmation)
5. User Rights
You may exercise the following rights at any time.
- Access, correct, or delete your personal information
- Withdraw consent and stop processing
- GDPR additional rights (EU residents): data portability, object to automated decisions
Closing your account: sign in and use "Close account" at the bottom of your dashboard.
Your account details, demo requests, uploaded data files, and comments are
deleted immediately with no grace period.
Other requests: contact@ximtier.io
6. Cookie Policy
XimTier uses only the cookies required to run the service.
- Session cookie: keeps you signed in. Removed when you close your browser.
- Remember-me cookie: issued only if you tick "Remember me" at sign-in.
Expires after 2 weeks, and is removed immediately when you sign out.
- Like cookie: a random identifier that prevents duplicate likes in the case gallery.
Expires after 30 days. It does not identify you or track you across other sites.
We do not use advertising or behavioural analytics cookies.
7. Security Measures
- In transit: TLS 1.2/1.3 (HTTPS enforced)
- Passwords: stored as irreversible hashes (not readable by anyone, including admins)
- Access control: Admin role separation, Rack::Attack rate limit
8. Officer + Contact
- Privacy Officer: Kang Seung-sik (CTO)
- Contact: contact@ximtier.io
- Dispute resolution: Korea PIPC (privacy.go.kr) / EU local DPA