
AxiPass Privacy Policy
Effective date: June 19, 2026

AxiPass is an Identity Provider for B2B SaaS teams. The AxiPass SWA Chrome extension has a single purpose: helping users sign in securely to approved business applications. This policy explains what data the extension and AxiPass service process, what they do not collect, and how the data is protected.
Extension data use principles
AxiPass complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Information processed by the extension is used only to provide or improve approved automatic login and security audit features. It is not used for personalized advertising, data sales, credit-worthiness decisions, or unrelated tracking.
1.Single purpose of the extension
The AxiPass SWA Chrome extension only helps users securely auto-fill approved account information on business SaaS login pages registered by a tenant administrator and records the login attempt for audit purposes.
2.Personal data we collect and how
AxiPass collects the minimum personal data needed to provide the service, gathering the items below depending on the service type and usage stage.
a. Items collected
- Sign-up and account (required): email, name, password (stored one-way encrypted), tenant membership, roles and groups
- Social login (Google): email, name, profile image, social provider identifiers (provider, uid)
- Multi-factor authentication (MFA): TOTP seed and recovery codes (stored with column encryption)
- Organization and tenant: tenant identifier (slug), domain and domain verification token, plan, policy settings (language, time zone, MFA enforcement, etc.)
- Authentication and access records: SSO and SWA login attempts and success/failure events, access IP, User-Agent, device and browser information, session identifiers
- SCIM provisioning: user attributes synchronized by the customer's IdP (email, name, active status, groups, etc.)
- App integration: OAuth/OIDC client_id and client_secret, SAML SP registration data, SCIM bearer tokens (secrets are column-encrypted)
- Audit logs: actor, event type, processing time (stored in UTC), target resource, access information
- SWA (automatic login): registered business app identifiers, auto-fill credentials (column-encrypted), one-time grab tokens
- Inquiries and support: name, email, inquiry content (when a user requests customer support)
- Automatically collected: IP address, User-Agent, cookies and visit identifiers (visitor_id), visit times and pages, referrer, access logs
b. Collection methods
- Direct entry: entered by the user during sign-up, login, MFA registration, or inquiries
- Administrator registration: member invitation and registration by a tenant administrator (individually or via CSV bulk import)
- External integration: SCIM provisioning sync from the customer's IdP and Google social login
- Automatic generation: cookies, logs, and access records collected automatically during service use
3.Information we do not collect
The extension does not collect a user's full browsing history, page content, advertising identifiers, payment information, address book, files, screen contents, or form values unrelated to the approved business app login. Page access is limited to domains and elements required for the SWA login feature initiated by the user.
4.Purpose of collecting and using personal data
AxiPass uses collected personal data only for the following purposes, and obtains prior consent when use beyond these purposes is needed or the purpose changes. The Company processes data on legal bases including performance of a contract (Personal Information Protection Act, Art. 15(1)4), the data subject's consent (Art. 15(1)1), and compliance with legal obligations (Art. 15(1)2).
- Service delivery and contract performance: SSO and OIDC/OAuth2/SAML authentication, SWA automatic login, SCIM provisioning, and management of tenants, members, groups, and app access policies
- Identity verification and account management: verifying intent to join and identity, account identification, password and session management, member invitation and permission granting
- Security and abuse prevention: MFA enforcement, access control, detection and blocking of abnormal logins and abuse, and security incident investigation
- Audit and legal compliance: recording and providing audit logs, producing security reports such as ISMS-P, and meeting obligations under laws such as the Act on E-Commerce
- Customer support and operations: handling inquiries, responding to incidents and security events, and delivering service change and policy notices
- Service improvement (statistics or separate consent): usage statistics analysis that does not identify individuals, and new feature development and quality improvement
5.Retention and use period of personal data
As a rule, AxiPass destroys personal data without delay once the purpose of collection and use is achieved. However, the following data is retained for the specified periods, keeping only the minimum items needed for the retention purpose, stored separately.
a. Retention under internal policy
- Member account information: until member withdrawal or tenant termination (deleted immediately)
- Audit and security event logs: for the period needed for security incident response and customer audit support
- Abuse records: 1 year (abuse prevention)
b. Retention under applicable law
- Records on contracts and withdrawal of subscription: 5 years (Enforcement Decree of the Act on Consumer Protection in Electronic Commerce, Art. 6)
- Records on payment and supply of goods: 5 years (Enforcement Decree of the Act on Consumer Protection in Electronic Commerce, Art. 6)
- Records on consumer complaints or disputes: 3 years (Enforcement Decree of the Act on Consumer Protection in Electronic Commerce, Art. 6)
- Records on labeling and advertising: 6 months (Enforcement Decree of the Act on Consumer Protection in Electronic Commerce, Art. 6)
- Website visit (access) records: 3 months (Protection of Communications Secrets Act, Art. 15-2)
6.Procedure and method for destroying personal data
AxiPass destroys personal data without delay once it is no longer needed because the retention period has elapsed or the purpose has been achieved. The procedure and method are as follows.
a. Destruction procedure
- When the retention period elapses or the purpose is achieved, data is classified for destruction and destroyed after confirmation by the data protection officer.
- Information that must be retained by law is stored separately and destroyed once the retention period elapses.
b. Destruction method
- Electronic files: deleted by irreversible technical methods (permanent deletion after soft delete); secret columns are deleted while encrypted or anonymized.
- Printed materials: personal data printed on paper is shredded or incinerated.
7.Provision to third parties
As a rule, AxiPass does not provide users' personal data to outside parties, and does not sell or provide it to advertising networks, data brokers, or information resellers. The following are exceptions.
- When the user or customer organization has given prior consent
- When based on law, or upon a request from an investigative authority through lawful procedures
- When provided in a form that cannot identify specific individuals, for statistics or security research
8.Entrustment of processing
To provide a stable service, AxiPass entrusts personal data processing as below. Under each entrustment contract, in accordance with Article 26 of the Personal Information Protection Act, the Company specifies in writing matters such as the prohibition of processing beyond the entrusted purpose, technical and administrative safeguards, restrictions on re-entrustment, supervision of the processor, and liability including damages, and supervises whether the processor handles personal data safely. If the entrusted work or processor changes, the Company discloses it without delay through this policy.
- Amazon Web Services, Inc. — server and database (cloud) infrastructure hosting / personal data stored for service operation
- Contabo GmbH — server infrastructure hosting / personal data stored for service operation
- Polar Software, Inc. — payment and Merchant of Record for paid subscriptions, invoicing and tax handling / buyer's name, email, phone number, billing address, business name and tax/registration number, card type and last 4 digits, purchase and subscription history, access information. Payment processing involves Polar's sub-processors; the full list is available at https://polar.sh/legal/sub-processors.
- Stripe, Inc. (Polar's payment sub-processor) — card payment authorization, settlement, refunds, and fraud prevention / payment card information, billing address, email, payment transaction records
9.Overseas transfer of personal data
AxiPass transfers some personal data overseas as listed below (item / purpose / time and method / retention). Users may refuse the overseas transfer, but doing so may limit the use of the relevant features (such as social login); to refuse, contact [email protected].
- Amazon Web Services, Inc. (USA) / personal data stored on servers / infrastructure hosting / transmitted over the network at the time of service use or authentication / retained for the service period
- Contabo GmbH (Germany) / personal data stored on servers / infrastructure hosting / transmitted over the network at the time of service use or authentication / retained for the service period
- Google LLC (USA) / email, name, profile / Google social login / transmitted over the network at login / retained per Google's policy
- Polar Software, Inc. (USA) / buyer's name, email, phone number, billing address, business name and tax/registration number, card type and last 4 digits, purchase and subscription history, access information / payment and Merchant of Record for paid subscriptions (tax handling and invoicing) / transmitted over the network at the time of checkout / for the duration of the account and as necessary to fulfill legal obligations and resolve disputes
- Stripe, Inc. (USA) / payment card information, billing address, email, payment transaction records / card payment authorization, settlement, refunds, and fraud prevention / transmitted via Polar at the time of payment / payment and settlement records and as required by applicable law
10.Data subject rights and how to exercise them
Users (data subjects) may exercise the following rights regarding their personal data. Requests can be made through in-service features, the organization's AxiPass administrator, or [email protected], and are handled after verifying the requester is the data subject or a duly authorized agent. For managed tenants, some rights may be handled according to the organization administrator's policy.
- Request to access personal data
- Request to correct or delete errors
- Request to suspend processing (handled within 10 days unless there is a justified reason otherwise)
- Withdrawal of consent and request to withdraw the account
- Rights may also be exercised through a legal representative or a duly authorized agent.
- Requests to access or suspend processing may be limited under Articles 35(4) and 37(2) of the Personal Information Protection Act, and personal data specified as a collection target by other laws cannot be requested for deletion.
11.Cookies and automatic collection
AxiPass uses cookies and visit identifiers and other automatic collection tools to keep users signed in and for service usage analytics and security.
- Purpose: maintaining login sessions, analyzing visit frequency and usage statistics, security and abuse prevention
- How to refuse: you can refuse cookie storage in your browser settings, but refusing may limit some features such as staying signed in
12.Measures to ensure data security
AxiPass takes the following administrative, technical, and physical measures to prevent personal data from being lost, stolen, leaked, altered, or damaged.
- Administrative: minimizing personal data handling privileges and separating them by role, with regular internal reviews
- Technical: column encryption (Lockbox) of secrets (OAuth client_secret, TOTP seeds, SCIM tokens, SWA credentials, etc.), one-way password encryption, TLS for data in transit, and no plaintext secrets in audit logs
- Access control: tenant- and role-based access control (multi-tenancy isolation), management of operational access rights, and retention of access logs
- Physical: entry control and security facilities of the cloud data centers
13.Data protection officer
In accordance with Article 30 of the Personal Information Protection Act, AxiPass establishes and discloses this policy and designates the following data protection officer who oversees personal data processing and handles user complaints and remedies. — Name: Jeong Eun-ho / Title: Representative / Phone: 010-3140-2180 / Email: [email protected]. Privacy questions and complaints may be submitted to the officer, and the Company responds promptly and in good faith.
14.Personal data of children under 14
AxiPass is a B2B workplace service adopted and managed by customer organizations. It does not target children under the age of 14 and does not collect the personal data of children under 14.
15.Remedies for rights infringement
If you need to report or consult about a personal data infringement, you may contact the Korean authorities below.
- Privacy Infringement Report Center (KISA): 118 / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Supreme Prosecutors' Office Cyber Investigation: 1301
- National Police Agency Cyber Bureau: 182 / ecrm.police.go.kr
16.Changes to this policy
This privacy policy applies from its effective date. If it changes due to law or company policy, we will announce the change in-service or by email at least 7 days before it takes effect (30 days for material or unfavorable changes).
17.Contact
For privacy questions, extension data handling, deletion requests, or security vulnerability reports, contact [email protected]. Users in managed tenants may also ask their organization's AxiPass administrator for access changes or account deletion.
Business information
- Company
- 액시멈주식회사
- Representative
- 정은호
- Business registration no.
- 445-87-02954
- Mail-order business filing
- No. 2026-Bucheon Wonmi-1246
- Address
- (14598) 경기도 부천시 원미구 송내대로73번길 46, 7층 D2호
- Phone
- 010-3140-2180
- [email protected]
This document applies to the AxiPass service and the AxiPass SWA Chrome extension. For inquiries, contact [email protected].