• Home
  • Privacy Policy

Privacy Policy

Last updated: July 29, 2026

  • 1. Controller and EU Representative

    This privacy policy applies to the processing of personal data by Netcube, Inc. on the npass.io website and services. The controller is :

    Netcube, Inc. (a stock corporation under the laws of the Republic of Korea)
    #608, 204 Gasan digital 1-ro, Geumcheon-gu, Seoul, Republic of Korea
    Email: npass.io@netcube.com
    Data Protection Officer: dpo@netcube.com

    Identity and contact details of the nominated representative in the EU (Art. 27 GDPR) :
    OBSECOM GmbH
    Königstr. 40
    70173 Stuttgart, Germany
    Tel.: +49 711 4605025-40
    Email: netcube@obsecom.eu
    Website: www.obsecom.eu

    You may address any GDPR-related inquiry to our EU representative instead of, or in addition to, contacting us directly. Data subjects and supervisory authorities may also submit inquiries via OBSECOM's Trust & Reporting Portal: report.obsecom.eu.

  • 2. Our Two Roles: Controller and Processor

    npass.io is a cloud-based 802.1X network authentication service offered exclusively to businesses. We process personal data in two distinct roles :

    • As controller — for data described in this policy: website visitor data, business contact and account data of our customers' administrators, and billing-related data.
    • As processor — for personal data of our customers' end users processed inside the service (authentication logs, device identifiers such as MAC addresses, network access events, audit trails). For this data, our customer is the controller and processing is governed by our Data Processing Agreement, not by this policy. End users should direct privacy inquiries to their organization's administrator.
  • 3. Website Visitors

    3.1 Server Logs

    When you visit npass.io, our servers automatically record: IP address, browser type and version, operating system, pages visited and time spent, date and time of request, and referrer URL.

    • Legal basis: legitimate interest in website security and performance (Art. 6(1)(f) GDPR)
    • Retention: 90 days

    3.2 Google Analytics 4

    With your consent, we use Google Analytics 4 ("GA4"), a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). GA4 uses cookies to help us understand, in aggregate, how visitors use our website.

    • Legal basis : your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG), given via our cookie banner. GA4 is not loaded unless you consent.
    • Configuration : ad personalization and Google Signals are disabled. GA4 does not log or store individual IP addresses.
    • Recipients and transfers : data collected by GA4 may be processed by Google LLC on servers in the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework; Standard Contractual Clauses apply as a fallback.
    • Retention : GA4 event data is retained for 14 months. Cookie lifetimes are listed in our Cookie Policy.
    • Withdrawal : you can withdraw consent at any time via the "Cookie Settings" link in the footer. Withdrawal does not affect the lawfulness of processing before withdrawal.

    3.3 Cookies

    Details on all cookies we use are in our Cookie Policy.

  • 4. Account and Business Contact Data

    To use npass.io, your organization creates an account. We collect: full name, business email address, company/organization name, password (stored only as a salted hash), and optionally a phone number.

    • Legal basis: performance of contract (Art. 6(1)(b) GDPR)
    • Retention: for the duration of the account and 30 days after deletion, except where longer statutory retention periods (e.g., commercial and tax law) require us to retain specific records.
  • 5. Payment and Billing Data

    All payments are processed by Lemon Squeezy LLC (a Stripe company), acting as Merchant of Record. Lemon Squeezy collects and processes your payment data (payment method details, billing address, transaction data) as an independent controller under its own privacy policy. Lemon Squeezy is located in the United States; transfers are safeguarded by its EU-U.S. Data Privacy Framework certification and/or Standard Contractual Clauses. We receive from Lemon Squeezy only the data needed to manage your subscription (e.g., subscription status, invoice references) — we do not receive full payment card details.

  • 6. Recipients
    • Amazon Web Services (AWS) — infrastructure hosting in Frankfurt, Germany (eu-central-1); processor under a Data Processing Agreement.
    • Google (GA4) — web analytics, only with your consent (see Section 3.2).
    • Lemon Squeezy (Stripe) — Merchant of Record; independent controller (see Section 5).
    • Google Cloud (optional) — identity provider federation relay, only if your organization enables SSO; processor under Standard Contractual Clauses.
  • 7. International Data Transfers

    Customer data processed in the npass.io service is hosted exclusively in the European Union (AWS Frankfurt, eu-central-1). The following transfers of personal data outside the EEA occur :

    • Republic of Korea : our operations and support teams in Seoul may access personal data remotely for service operation, maintenance, and technical support. This transfer is based on the European Commission's adequacy decision for the Republic of Korea of 17 December 2021 (Art. 45 GDPR). Access is role-based, logged, and limited to what is necessary.
    • United States — Lemon Squeezy (payment and billing data only) : safeguarded by the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses (see Section 5).
    • United States — Google LLC (GA4 analytics data, only with consent) : safeguarded by the EU-U.S. Data Privacy Framework (see Section 3.2).

    No other transfers outside the EEA take place. Service data of your end users is never transferred to a third country other than as described above.

  • 8. Your Rights

    Under GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you have the right to withdraw consent at any time (Art. 7(3)), without affecting the lawfulness of processing before withdrawal.

    To exercise your rights, contact dpo@netcube.com or our EU representative.

  • 9. Right to Lodge a Complaint

    You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence or place of work (Art. 77 GDPR). A list of EU supervisory authorities is available at edpb.europa.eu.

  • 10. Automated Decision-Making

    We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.

  • 11. Changes to This Policy

    We may update this privacy policy from time to time. The current version is always available on this page. If we make material changes, we will notify account holders by email before the changes take effect.

  • 12. Language

    This privacy policy is provided in English, which is the authoritative version. A German courtesy translation is available upon request.