Privacy Policy
Effective date: 2026.10.01
SKAI Worldwide Co., Ltd. (the "Company") regards the protection of users' personal information as a matter of great importance, and makes every effort to protect the personal information users provide to the Company in order to use the services the Company offers. In accordance with the Personal Information Protection Act and related laws on the protection of personal information, the Company processes users' personal information lawfully and manages it securely. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and discloses this Privacy Policy in order to inform users of the procedures and standards concerning the processing and protection of personal information, and to enable related grievances to be handled promptly and smoothly.
The Company continuously discloses this Privacy Policy on the first screen of the site so that users may readily check the procedures and standards for the processing of personal information at any time.
This Privacy Policy may be changed in accordance with relevant laws and the Company's internal policies. Where it is amended, version control is applied so that the amendments can be easily identified.
Article 1. Purposes of Processing Personal Information
The Company processes users' personal information for the following purposes. Personal information being processed is not used for any purpose other than those below, and where the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.
- 1. Inquiries
- Responding to and handling inquiries
- 2. Provision of goods or services
- Customer verification
- Service management and provision, including the establishment, maintenance, and termination of commercial relationships such as document and program downloads
- Preventing fraudulent use and providing services safely
- Statistics and analysis of service use, and provision of new and customized services
- 3. Events and promotions
- Providing event and promotion information, benefits, and opportunities to participate
- Event participation, prize delivery, and related notices
- Marketing based on analysis of demographic characteristics and users' service usage records
- 4. Grievance handling
- Verifying the identity of the complainant and the details of the complaint
- Contact and notification for fact-finding, and notification of the outcome
- Remedy for damage and handling of complaints
- 5. Provision of a generative AI chatbot service
- Analyzing the content of user queries using artificial intelligence (AI) technology in order to provide information and respond to inquiries about the Company and its products and services
- Analyzing conversation content to review and improve response quality, including the accuracy and appropriateness of chatbot responses
- Checking for errors in the chatbot service, preventing misuse, and operating the service stably
※ The Company does not use the content users enter in the chatbot conversation window, or the responses generated by the chatbot, to train (retrain or fine-tune) artificial intelligence (AI) models.
Article 2. Personal Information Items Processed
The Company collects and uses personal information only to the minimum extent necessary to achieve its purposes.
Pursuant to Article 15(1)1 and Article 24(1)1 of the Personal Information Protection Act, the Company obtains users' consent and collects and uses the following minimum personal information for the establishment, maintenance, performance, and management of commercial transactions and for the provision of services.
| Category | Purpose of processing | Legal basis | Items collected and used |
|---|---|---|---|
| Inquiries | Replying to inquiries | Article 15(1)1 (consent of the data subject) and Article 15(1)4 (performance of a contract) of the Personal Information Protection Act | Company name, department, title, name, email, mobile phone number |
| Provision of goods or services | Customer verification, document and product downloads, service provision | Article 15(1)1 (consent of the data subject) and Article 15(1)4 (performance of a contract) of the Personal Information Protection Act | Company name, department, title, name, email, mobile phone number |
| Events and promotions | Event participation | Article 15(1)1 (consent of the data subject) and Article 15(1)4 (performance of a contract) of the Personal Information Protection Act | Name, company name, department, title/position, email, mobile phone number |
| Running events and promotions | Article 15(1)1 (consent of the data subject) and Article 15(1)4 (performance of a contract) of the Personal Information Protection Act | Name, company name, department, title/position, email, mobile phone number | |
| Event prize awards | Article 15(1)1 (consent of the data subject), Article 15(1)2 (where prescribed by law or necessary to comply with legal obligations), and Article 15(1)4 (performance of a contract) of the Personal Information Protection Act | Name, company name, department, title/position, email, mobile phone number [Where a physical prize is provided] Address [Where taxes and public charges are payable] Copy of identification document ** The items collected and used may differ depending on the event, and consent to collection and use is obtained for the items collected in each event. |
|
| Grievance handling | Inquiries relating to commercial transactions | Article 15(1)1 (consent of the data subject), Article 15(1)2 (where prescribed by law or necessary to comply with legal obligations), and Article 15(1)4 (performance of a contract) of the Personal Information Protection Act | Name, company name, department, title/position, email, mobile phone number |
| Provision of the AI chatbot service | Chatbot consultation responses; review and improvement of response quality | Article 15(1)1 (consent of the data subject) and Article 15(1)4 (performance of a contract) of the Personal Information Protection Act | Text entered directly by the user in the conversation window (questions, prompts, and conversation content) and the personal information contained therein, responses generated by the chatbot, session identifiers, access date and time, IP address, device and browser information, and service usage records |
※ Because the chatbot service allows users to enter text freely, users are asked to take particular care not to enter their own or another person's sensitive information (such as health or medical information), unique identifying information (such as resident registration numbers, passport numbers, or driver's license numbers), financial information such as account or card numbers, or confidential information into the conversation window. The Company does not collect sensitive information or unique identifying information for the provision of the chatbot service.
Article 3. Processing and Retention Periods of Personal Information
① The Company processes and retains personal information within the processing and retention period prescribed by law, or within the processing and retention period consented to by the user at the time of collection.
② The processing and retention period for each type of personal information is as follows.
- 1. Inquiries: until three months after the reply to and handling of the customer inquiry is complete. However, information that must be preserved under relevant laws is preserved in accordance with Paragraph 3, Item 1.
- 2. Provision of goods or services: until five years after the goods or services are provided. However, information that must be preserved under relevant laws is preserved in accordance with Paragraph 3, Item 1.
- 3. Events: until three months after the relevant event ends
- 4. Grievance handling: three years after the grievance is resolved. However, information that must be preserved under relevant laws is preserved in accordance with Paragraph 3, Item 1.
- 5. Generative AI chatbot service: processed and retained separately by purpose, as follows
- a. For the purpose of responding to inquiries: until three months from the date the conversation ends
- b. For the purpose of reviewing and improving response quality: until one year after the period in item (a) has elapsed
③ In the following cases, the Company processes and retains personal information until the relevant grounds cease, in order to comply with legal obligations. However, where the processing and retention periods prescribed in Paragraph 2 and in this Paragraph differ, the longest period applies.
- 1. Where grounds prescribed by the following relevant laws apply, until the end of the relevant period
Relevant law Records to be preserved and period Act on the Consumer Protection in Electronic Commerce Records on contracts or withdrawal of subscription: 5 years Records on payment and the supply of goods: 5 years Records on consumer complaints or dispute resolution: 3 years Records on labeling and advertising: 6 months Electronic Financial Transactions Act Records on electronic financial transactions: 5 years Framework Act on National Taxes; Corporate Tax Act Books and supporting documents for all transactions prescribed by tax law: 5 years Act on Reporting and Using Specified Financial Transaction Information Customer due diligence information: 5 years Protection of Communications Secrets Act Login records: 3 months - 2. Where an investigation or inquiry into a violation of relevant laws is under way, until that investigation or inquiry is concluded
- 3. Where credit or debt relations arising from use of the service remain outstanding, until the credit or debt is settled
- 4. Where legal dispute proceedings such as litigation are ongoing between the user and the Company, until the conclusion of those proceedings is confirmed
Article 4. Destruction of Personal Information
① Where personal information becomes unnecessary, such as when the retention period has elapsed or the purpose of processing has been achieved, the Company destroys it without delay.
② Where personal information must continue to be preserved under relevant laws even though the retention period consented to by the user has elapsed or the purpose of processing has been achieved, the Company transfers that personal information to a separate database (DB) or stores it in a different location. Details of personal information preserved under relevant laws can be found in Article 3 (Processing and Retention Periods of Personal Information).
③ Under the destruction procedure, the Company identifies the personal information for which grounds for destruction have arisen — such as elapse of the retention period or achievement of the purpose of processing — and destroys it through automatic system deletion or with the approval of the Chief Privacy Officer or equivalent.
④ Personal information is destroyed as follows.
- 1. Personal information stored in electronic file form is permanently deleted so that the records cannot be recovered.
- 2. Personal information recorded and stored on paper is shredded or incinerated.
Article 5. Provision of Personal Information to Third Parties
① The Company processes users' personal information only within the scope specified in Article 1 (Purposes of Processing Personal Information) of this Privacy Policy, and provides personal information to third parties only where Article 17 (Provision of Personal Information) or Article 18 (Restrictions on Use and Provision of Personal Information Beyond the Purpose) of the Personal Information Protection Act applies — such as with the consent of the data subject, where there are special provisions in law, or where it is unavoidable in order to comply with legal obligations.
② The Company provides the following personal information to third parties with the prior consent of the user. The recipients may change without notice depending on the nature of partner services and contracts.
③ The Company does not provide or sell information entered by users in the chatbot conversation window, or responses generated by the chatbot, to external companies or third parties for the training of artificial intelligence (AI) models without the user's explicit prior consent.
Article 6. Criteria for Additional Use or Provision
① In the course of providing services, the Company may use or provide personal information without the user's consent pursuant to Article 15(3) or Article 17(4) of the Personal Information Protection Act.
| Recipient | Purpose of provision | Items provided | Retention and use period |
|---|---|---|---|
| Courts or public institutions | Resolution of grievances or disputes arising in the course of service use | Service usage records | Retained in accordance with the laws under the jurisdiction of each institution |
② In order to use or provide personal information additionally without the user's consent under Paragraph 1, the Company has considered the following criteria.
- 1. Whether it is related to the original purpose of collection
- 2. Whether the additional use or provision of personal information was foreseeable in light of the circumstances of collection or processing practices
- 3. Whether it unfairly infringes the interests of the user
- 4. Whether measures necessary to ensure safety, such as pseudonymization or encryption, have been taken
Article 7. Outsourcing of Personal Information Processing
① The Company outsources some of the work required to provide its services to external companies, and where an entrusted company processes personal information in the course of performing that work, the Company manages and supervises it pursuant to Article 26 of the Personal Information Protection Act so that personal information is processed safely.
② The Company outsources personal information processing work as follows.
| Entrusted company | Scope of outsourced work |
|---|---|
| Formspree | Operation of a CRM system for managing user information; operation and management of web services |
| Stibee | Operation of a CRM system for managing user information; operation of the inquiry system |
| Cafe24 | Storage of user information and system operation data |
| HubSpot Inc. | Provision of a CRM system for managing user information, transmission of data for handling inquiries and consultations, and handling of CRM system technical support requests |
| Anthropic PBC | Generation and processing of generative AI chatbot responses through the Claude API (processing of user input and conversation context, and return of generated results) |
Article 8. Transfer of Personal Information Overseas
The Company transfers personal information overseas as follows.
In order to provide its services, the Company entrusts the processing and storage of personal information to overseas companies under contract pursuant to Article 28-8(1)3(a) of the Personal Information Protection Act, and manages and supervises them so that the entrusted personal information is processed safely. Users may refuse the overseas transfer through the department stated in Article 13. However, where a user refuses the overseas transfer under 1 (HubSpot Inc.) below, use of related services such as inquiries may be restricted, and where a user refuses the overseas transfer under 2 (Anthropic PBC) below, use of the chatbot function will be restricted.
1. HubSpot Inc. (CRM and inquiry consultation services)
| Company name | HubSpot Inc. |
|---|---|
| Country of transfer | United States |
| Contact for the person responsible for information protection | HubSpot Inc. / https://preferences.hubspot.com/privacy |
| Date and method of transfer | Transmitted over the network when the user uses the service |
| Personal information items transferred | Name, contact number, email, inquiry content |
| Purpose of use | Provision of a CRM system for managing user information, transmission of data for handling inquiries and consultations, and handling of CRM system technical support requests |
| Retention and use period | Retained until the service ends, after which the information is destroyed without delay |
2. Anthropic PBC (AI chatbot service)
| Company name | Anthropic PBC |
|---|---|
| Country of transfer | United States (USA) |
| Contact for the person responsible for information protection | privacy@anthropic.com (Privacy Policy: https://www.anthropic.com/legal/privacy) |
| Date and method of transfer | Transmitted in encrypted form (TLS) over the information and communications network at the point the user enters and sends a query in the chatbot conversation window |
| Personal information items transferred | Text entered by the user in the conversation window (questions, prompts, and conversation content) and the personal information contained therein, the conversation context, and the generated responses |
| Purpose of use | Analysis of user requests and generation and return of chatbot responses through the Claude API; service security and error prevention |
| Retention and use period | Retained until the purpose of the outsourcing is achieved, and destroyed without delay in accordance with the procedures set out in the contract when the outsourcing contract ends |
※ Anthropic PBC may use subprocessors to provide the service. The list of subprocessors is available at https://www.anthropic.com/subprocessors.
Article 9. Measures to Ensure the Security of Personal Information
In processing users' personal information, the Company takes the following technical and administrative measures to ensure security, so that personal information is not lost, stolen, leaked, altered, or damaged.
- 1. Establishment and implementation of an internal management plan
- The Company establishes and implements an internal management plan for the safe processing of personal information.
- Through its in-house personal information protection body and similar means, the Company verifies the implementation of personal information protection measures and compliance by responsible staff, and requires immediate corrective action where a problem is found.
- 2. Installation and operation of access control systems
- The Company controls unauthorized external access using an intrusion prevention system, and endeavors to put in place every possible technical device to secure the system.
- 3. Measures to prevent forgery or alteration of access records
- The Company retains and manages records of access to the personal information processing system, and uses security functions to ensure that access records are not forged or altered.
- 4. Encryption of personal information
- Users' personal information is protected by passwords. It is stored and managed with files and transmitted data encrypted or with file lock functions applied, and important data is protected through separate security functions.
- 5. Measures against hacking and similar threats
- The Company uses antivirus software to prevent damage from computer viruses. The antivirus software is updated periodically, and where a virus appears suddenly, the antivirus update is applied as soon as it is released, preventing infringement of personal information.
- The Company employs a security device (SSL) that uses cryptographic algorithms to transmit personal information safely over the network.
- To guard against hacking and other external intrusion, each server is protected using intrusion prevention systems, vulnerability analysis systems, and similar measures.
- Personal information is not stored together with general data; it is stored separately on a dedicated server.
- 6. Minimizing and training staff who handle personal information
- The Company limits access rights to users' personal information to those who carry out marketing work directly with users, the Chief Privacy Officer and staff who carry out personal information management work, and others for whom handling personal information is unavoidable in the course of their duties.
- Regular in-house training and externally commissioned training are provided to staff who handle personal information, covering the acquisition of new security techniques and obligations regarding the protection of personal information.
- A security pledge is obtained from all employees on joining, to prevent information leakage by individuals in advance, and internal procedures are in place to audit the implementation of the personal information protection policy and employees' compliance with it.
- Handover of duties among those who handle personal information is carried out thoroughly under maintained security, and responsibility for personal information incidents on joining and after leaving the Company is clearly defined.
- The computer room, data storage room, and similar areas are designated as specially protected zones with controlled access.
Article 10. Installation and Operation of Devices that Automatically Collect Personal Information, and Refusal Thereof
The following information may be generated and additionally collected in the course of using the services the Company provides. The Company uses "cookies" and similar means, which store and retrieve user information from time to time. A cookie is a very small text file sent to the user's browser by the server operating the website, and it is stored on the hard disk of the user's computer.
1) Purposes of using cookies and similar means
To analyze the access frequency and visit times of members and non-members, to determine visit counts, and to support a faster web environment for users through "sessions".
2) Refusing the installation and operation of cookies
Users have a choice about the installation of cookies. By setting options in the web browser, users may allow all cookies, be asked to confirm each time a cookie is stored, or refuse the storage of all cookies. However, if users refuse the installation of cookies, there may be difficulties in providing the service. (Settings can be changed as follows.)
- Edge: Settings menu on the right of the browser > Cookies and site permissions on the left of the screen
- Chrome: Settings menu on the right of the browser > Show advanced settings at the bottom of the screen > Content settings under Privacy > Cookies
- Firefox: Options menu > Privacy > History – custom settings > Cookie level settings
- Safari: Preferences menu > Privacy tab > Cookie and website data level settings
- Internet Explorer: Tools at the top of the browser > Internet Options > Privacy > Settings
Article 11. Rights and Obligations of Users and Legal Representatives, and How to Exercise Them
① Users may at any time exercise rights against the Company such as requesting access to, correction of, deletion of, or suspension of the processing of their personal information, or withdrawing consent to the processing of personal information. However, the exercise of rights such as requesting access, correction, deletion, or suspension of processing, or withdrawing consent, may be restricted in accordance with relevant laws, including the proviso to Article 35(4), the proviso to Article 36(1), and the provisos to Article 37(2) and (3) of the Personal Information Protection Act.
② Users may exercise their rights in writing, by email, by fax, or by similar means pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will act on them without delay.
③ Where a user objects to the Company's action on a request for access, correction, deletion, or suspension of processing, or on the withdrawal of consent, the user may file an objection within 10 days of the date of that action, by the means set out in Paragraph 2.
④ The rights under Paragraph 1 may be exercised through a representative, such as the user's legal representative or a person duly authorized by the user. In that case, a power of attorney in the form of Appendix No. 11 of the Public Notice on Methods of Processing Personal Information must be submitted.
⑤ Where personal information is specified as subject to collection under another law, its deletion cannot be requested when requesting correction or deletion of personal information.
⑥ When a user exercises the right to request access, correction, deletion, or suspension of processing, or withdraws consent, the Company verifies whether the person making the request is the user or a duly authorized representative.
⑦ Users may exercise the rights under this Article through Article 13 (Department Responsible for Access to Personal Information). The Company will endeavor to handle the exercise of users' rights promptly.
⑧ Users' rights in relation to the AI chatbot service, and how to exercise them, are as follows.
- 1. The Company does not use the content users enter in the chatbot conversation window, or the responses generated by the chatbot, to train (retrain or fine-tune) artificial intelligence (AI) models, and the entrusted companies under Article 7 are likewise prohibited by their outsourcing contracts from using it to train their own artificial intelligence (AI) models.
- 2. Users may request access to, correction of, deletion of, or suspension of the processing of chatbot conversation content under Paragraphs 1 through 8 above. However, if a user requests deletion or suspension of processing, the chatbot service may thereafter be restricted.
- 3. The Company processes chatbot conversation records for a maximum of 24 hours for the purpose of maintaining the flow of the conversation; after the user closes the conversation window or the session ends, the records are automatically deleted without delay. However, records may be retained for the period separately prescribed by law.
Article 12. Chief Privacy Officer and Responsible Department
① The Company designates the following department and Chief Privacy Officer in order to protect users' personal information and to handle complaints relating to personal information.
| Category | Chief Privacy Officer | Personal Information Protection Officer |
|---|---|---|
| Name | Yonghyun Noh | Jaewon Jang |
| Position | Chief Privacy Officer | Personal Information Protection Officer |
| Department | Management Planning Division | Management Support Team, Management Planning Division |
| yhno1129@skaiworldwide.com | jwjang@skaiworldwide.com | |
| Phone number | 070-4800-3517 | 070-4800-3517 |
② Any complaint relating to the protection of personal information arising in the course of using the Company's services may be directed to the Chief Privacy Officer or the responsible department. The Company will respond to and handle users' inquiries.
Article 13. Department Responsible for Access to Personal Information
Users may submit a request for access to personal information under Article 35 of the Personal Information Protection Act to the department below.
| Department | Management Planning Division |
|---|---|
| management@skaiworldwide.com | |
| Phone number | 070-4800-3517 |
Article 14. Remedies for Infringement of Rights
If you require remedy for damage or consultation regarding an infringement of personal information, you may contact the following organizations.
| Organization | Website | Phone |
|---|---|---|
| Privacy Infringement Report Center (operated by the Korea Internet & Security Agency) | privacy.kisa.or.kr | 118 (no area code) |
| Personal Information Dispute Mediation Committee | www.kopico.go.kr | 1833-6972 (no area code) |
| Supreme Prosecutors' Office | www.spo.go.kr | 1301 (no area code) |
| National Police Agency, Cyber Investigation Bureau | ecrm.police.go.kr | 182 (no area code) |
Article 15. Responsibility for Linked Sites
The Company may provide users with links to other external sites. In such cases the Company has no control over the external site, and therefore cannot be held responsible for, or guarantee, the usefulness, truthfulness, or legality of the services or materials the user receives from that external site. The privacy policy of a linked external site is unrelated to the Company, so please check the policy of the external site concerned.
Article 16. Changes to the Privacy Policy
Where the Company changes this Privacy Policy, it will continuously disclose the timing of the change and its effective date together with the amended content, and will disclose the content before and after the change side by side so that users can easily identify what has changed.
Addendum
This Privacy Policy applies from 1 Oct, 2026.
The previous Privacy Policy is available below.